77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
IT security costs in 2026: What an effective ISMS really costs in medium-sized businesses
IT Security & NIS-2

IT security costs in 2026: What an effective ISMS really costs in medium-sized businesses

21 July 202612 min readBy Lena Vogt
CIVAC

IT security rarely costs less than 50,000 euros per year in medium-sized businesses. The article breaks down the costs into setup, operation and audit, compares the internal model with officer-as-a-service and provides a template for budget plausibility to management and the supervisory board.

The BSI law, the federal government's NIS 2 implementation and the ISO/IEC 27001:2022 standard will require an estimated 29,500 companies in Germany to have demonstrably effective information security management from October 2026. The fines for essential facilities range up to ten million euros or two percent of group sales, and for important facilities up to seven million euros or 1.4 percent of group sales. This means that IT security is no longer an investment question for affected companies, but rather a cost question: not whether to invest, but to what extent and with what effectiveness.

This article is aimed at commercial management, management and ISB managers in medium-sized companies with 50 to 5,000 employees who need to set up a resilient budget for IT security. You will find out which cost blocks really arise, how setup costs differ from operating costs, when an internal ISB is more economical than an external officer-as-a-service, what typical bandwidths apply in practice and how the CIVAC compliance platform and officer-as-a-service reduce audit preparation from typically three months to a few weeks. The text does not replace an individual cost-effectiveness calculation, but rather provides the framework for the internal discussion. Anyone who adheres to this structure before submitting the first investment application will save themselves from later additions, which are not welcomed by the supervisory board.

Key Takeaways

  • An effective ISMS according to ISO/IEC 27001:2022 causes typical full costs for medium-sized companies of between 80,000 and 350,000 euros in the first year, depending on size and level of maturity.
  • Officer-as-a-Service with an external information security officer typically reduces the overall costs by thirty to fifty percent compared to an internal full-time position.
  • The number one cost trap in medium-sized businesses is the inadequate separation between setup and operating costs, which leads to follow-up investments without budget approval.

The five cost blocks of IT security at a glance

IT security can be broken down into five cost blocks that can be budgeted separately. First, the personnel costs for the information security officer, internal or external, with training and representation. Second, the technology costs for endpoint protection, identity and access management, backup and disaster recovery, logging and monitoring, and secure network design. Third, the consulting and audit costs for the initial ISO/IEC 27001:2022 certification and annual monitoring. Fourth, the training and awareness costs for all employees. Fifth, the insurance and reserve costs in the event of damage, especially the cyber insurance premium.

This separation into five blocks is important because the block shares shift with the level of maturity. Personnel and consulting costs dominate in the first year. From the second year onwards, the proportions shift to technology and training. From the third year onwards, the costs stabilize at a lower level, provided there are no significant organisational changes or regulatory tightening.

If you do not separate the cost blocks, you risk a budget trap: The management releases 150,000 euros for the first year in the investment application, but forgets the follow-up costs in years two and three, such as the annual monitoring audit with 8,000 to 18,000 euros or the annual one Cyber insurance premium of 10,000 to 50,000 euros. Proper multi-year planning reveals these follow-up costs right from the start. The Information Security Officer in the CIVAC version delivers the multi-year planning as a standard template in the workspace, so that management knows the status of the annual burden at all times. A clean list also includes the non-monetary costs in the form of effort from the specialist departments, training times and audit support hours. These are rarely reflected correctly in internal billing, but they account for between fifteen and twenty-five percent of the total burden.

Personnel costs: ISB internal, external or hybrid

The information security officer is the most expensive single personnel position in the IT security budget. An internal full-time position with sufficient qualifications in Germany costs between 95,000 and 140,000 euros in full costs per year, including employer contributions, training, workplace equipment and vacation replacement. However, this full-time position is only economical in companies with a high level of maturity or high risk exposure, typically with 1,000 employees or more or if they are classified as an NIS 2 essential facility.

In medium-sized companies with 50 to 500 employees, the full-time position is usually overstaffed. An hourly quota of between 200 and 800 hours per year is sufficient, depending on the level of maturity and the industry. An external ISB with this hourly quota costs between 16,000 and 65,000 euros annually, depending on the senior level and industry specialization. The external ISB has the advantage of specialised experience across multiple mandates and reduces the single point of failure problem of a single internal position.

The hybrid variant combines an internal IT security coordinator with part-time capacity and an external ISB as an appointment person with an appointment document, task description and reporting line to management. In practice, this variant is the most common structure in medium-sized companies because it combines operational availability and external expertise. CIVAC offers all three models and adapts the appointment certificate to the respective configuration. The appointment certificate, signed, filed, verifiable. The choice between internal, external and hybrid is a question of maturity, client structure and the desired audit security, not just a question of cost. A cost calculation without taking into account availability in the event of an incident is incomplete. Anyone who puts the appointment certificate in the filing cabinet without testing the reporting line has spent the money on an extra role. An annual exercise with a simulated incident proves the functionality and protects the management in the fine proceedings.

Technology Costs: From Endpoint to SIEM

The technology costs can be divided into five clusters. Endpoint protection with a modern EDR solution costs between 35 and 80 euros per device per year. With 200 devices, that amounts to 7,000 to 16,000 euros per year. Identity and access management with multi-factor authentication, single sign-on and privileged access management costs between 80 and 240 euros per user per year, i.e. 16,000 to 48,000 euros for 200 users. Backup and disaster recovery with immutable backups and tested recovery processes costs between 30 and 90 euros per terabyte of secured data volume per month, depending on the retention period and recovery requirements.

Logging and monitoring via a SIEM or a managed detection and response service is the item with the widest range. A self-operated SIEM costs barely less than 60,000 euros per year for licences, hardware and personnel in medium-sized businesses. A managed detection and response service costs between 25,000 and 120,000 euros annually, depending on the number of monitored sources and the speed of response. Secure network design with segmentation, firewalls and zero trust components is often already part of the existing IT infrastructure and accounts for 15,000 to 60,000 euros in the annual security budget.

The total technology costs in medium-sized companies with 200 employees are typically between 80,000 and 220,000 euros annually. This range regularly surprises management because many components are distributed in existing IT budgets. A consolidated view across all five clusters is the first step towards reliable budget planning. The ISB in the CIVAC workspace manages the technology landscape in an asset register that is automatically linked to the 93 controls according to ISO/IEC 27001:2022. Audit-proof, documented, ISO-proof.

Certification costs ISO/IEC 27001:2022: initial audit and monitoring

Certification according to ISO/IEC 27001:2022 runs in a three-year cycle. In the first year, the initial audit takes place in two stages: Stage 1 checks the document situation, Stage 2 checks the effectiveness of the controls during ongoing operations. The audit days are calculated according to the IAF MD 5 standard based on the number of employees. For a company with 200 employees, there are typically 12 to 18 audit days; with a daily rate of between 1,400 and 2,200 euros, this results in 17,000 to 40,000 euros for the initial audit.

Surveillance audits follow in years two and three, each with a third of the audit days of the initial audit, i.e. typically 4 to 6 days per year 6,000 to 14,000 euros. In the fourth year, the cycle begins with a re-certification audit, which usually amounts to around two thirds of the initial audit effort. Over three years, the pure audit costs add up to 30,000 to 70,000 euros for a 200-person company.

The internal preparation and accompanying costs are often underestimated. An initial certification requires a preparation phase of typically six to twelve months with the creation of guidelines, risk analysis, statement of applicability, action plan and internal audit round. The internal effort is 200 to 600 hours, with consulting services an additional 12,000 to 60,000 euros. CIVAC offers the 490 ready-to-use audit templates as part of the workspace, which typically reduces the preparation effort by fifty percent. The auditor calls, the evidence is ready. because the templates can be exported directly from the workspace and the level of maturity is transparently documented. Others run compliance like a filing cabinet. We run it like software.

Training and awareness: the underestimated lever

Training and awareness measures are the block with the highest effectiveness-to-cost ratio. Annual compulsory training per employee costs between 8 and 25 euros per person with an e-learning solution. With 200 employees, this amounts to 1,600 to 5,000 euros per year. Phishing simulations and targeted awareness campaigns increase costs by a further 4,000 to 18,000 euros annually, but their effectiveness can be measured by the falling click rate on simulated phishing emails.

Beyond basic training, certain roles require in-depth training. IT administrators typically need eight days of training per year for 1,200 to 2,400 euros per day. The management and the supervisory board need an annual cyber risk briefing session with an external expert, estimated at 2,500 to 8,000 euros per session. The ISB itself has to refresh its qualification every year, which can be calculated at 1,500 to 4,500 euros per year.

The total training costs for medium-sized companies are between 10,000 and 45,000 euros per year. This investment is statistically proven to be effective: A study published by the Federal Ministry of Economics in 2026 shows that companies with annual phishing simulations have a 70 percent lower success rate of social engineering attacks. The ISB plans the training program annually, documents the participants and stores the evidence of effectiveness in the workspace. The clock starts on awareness. In the CIVAC workspace, this deadline is automatically recorded in the onboarding task list. A lack of training is one of the most common complaints in the audit with a direct connection to Section 130 OWiG supervisory obligation. The effectiveness can also be proven by key figures such as click rates in phishing simulations and rates of passing knowledge tests.

Cyber ​​insurance: what it costs and what it doesn't replace

Cyber ​​insurance typically covers three risk areas. First-party losses include forensic, recovery, crisis communications and business interruption costs. Third-party damages include liability towards affected customers, business partners and data subjects. In addition, ransom payments in the event of ransomware incidents are covered in many policies, although with increasing restrictions and deductibles.

Premiums have risen sharply in the past three years. In medium-sized companies with 200 employees and an annual turnover of 50 million euros, the premium for a policy with 5 million euros in coverage is typically between 12,000 and 45,000 euros annually, depending on the level of maturity and the industry. Insurers are now actively checking the ISMS maturity level and granting premium discounts for certified companies.

Important: Cyber ​​insurance does not replace an effective ISMS. Insurers will reduce benefits or deny them entirely if basic security measures have not been followed, such as a lack of multi-factor authentication, a lack of tested backups or a lack of training. A ruling by the Cologne Higher Regional Court dated July 14, 2025 (ref. 9 U 167/24) confirmed that the insurance may reduce the amount if gross negligence is proven. Anyone who combines an effective ISMS and cyber insurance has full protection. Those who rely on insurance alone often have nothing in the event of damage. The ISB documents the security measures in the workspace and provides the evidence upon request from the insurance company. In the event of a claim, these receipts are the difference between a payout and a reduction. An annual insurance declaration confirming the security measures should be included in the compliance calendar. The declaration is signed by the ISB together with the policy and stored in the workspace so that the chain of receipts is immediately available when a claim is reported.

NIS-2: the additional costs from October 2026

The NIS 2 implementation in Germany tightens the requirements for risk management, supply chain due diligence and incident reporting. Essential facilities and important facilities must maintain documented risk management, implement technical and organisational measures from ten subject areas and provide early warning of security incidents within 24 hours and report them to the BSI with a follow-up report within 72 hours. The management is personally liable for the effectiveness of these measures.

The additional costs compared to a classic ISO/IEC 27001:2022 ISMS lie in three areas. Firstly, supply chain due diligence, which requires a documented security assessment for direct suppliers. The annual costs for this are between 5,000 and 40,000 euros, depending on the number of suppliers. Secondly, the operational reporting requirement within 24 hours, which requires the ISB or an equivalent service to be available 24/7. Thirdly, the annual management training, which is explicitly required in the NIS 2 guideline and must be verifiably documented.

The total additional costs of NIS 2 implementation for medium-sized companies are 15,000 to 70,000 euros annually compared to an existing ISMS. If you don't yet have an ISMS, you also have to plan for the setup costs. CIVAC offers the 24/72 reporting path in the workspace as a technical routing object that automatically starts the deadline and prepares the associated templates. The NIS-2 reporting path is served by the external ISB, which guarantees 24-hour availability via the SLA agreement. Licence the workspace for your internal representatives, or have our representatives order it. The current overview of NIS 2 implementation describes the areas of application and threshold values ​​in detail. If you are not sure whether your company is classified as essential or important, you can clarify the question in a 30-minute appointment with the CIVAC-ISB. The classification follows from the sector annexes to the directive and is decisive for the amount of the fine and the reporting deadlines.

Officer-as-a-Service versus full internal costs: the honest comparison

The direct cost comparison between an internal ISB and an external officer-as-a-service model depends on the level of maturity and size. For a company with 200 employees without an existing ISMS, the typical comparison looks like this. Internal model: an internal ISB as a full-time position with 110,000 euros in full costs, plus 35,000 euros for external advice in the development phase, plus 28,000 euros for the initial audit. Total construction year: 173,000 euros. In subsequent operation: 110,000 euros ISB plus 10,000 euros monitoring audit, i.e. 120,000 euros annually.

External model with CIVAC Officer-as-a-Service: an external ISB with 32,000 euros annual retainer, workspace licence with 18,000 euros, plus 28,000 euros initial audit. Total construction year: 78,000 euros. In subsequent operation: 32,000 euros ISB plus 18,000 euros workspace plus 10,000 euros monitoring audit, i.e. 60,000 euros annually. The difference is 95,000 euros in the year of establishment and 60,000 euros in the subsequent operation, i.e. around half.

This comparative calculation is a rough guide, not a binding calculation. In companies with very high risk exposure or special regulatory obligations, an internal ISB may be mandatory. In all other cases, the external variant is economically superior without compromising audit security. The external ISB in the CIVAC workspace has access to 25 mandates in parallel and therefore has a significantly greater breadth of experience than a single internal position. Licence the workspace for your internal representatives, or have our representatives order it. The CIVAC SLA of two working days for the order instead of the traditional two to six weeks complements the cost advantage with a time advantage during implementation. The supervisory board can equate this time saving in the budget discussion with a risk reduction.

From reading to a resilient budget: the next step

Anyone who has read the article up to this point knows the five cost blocks, the typical ranges in medium-sized companies, the follow-up cost traps, the additional costs of NIS 2 implementation and the honest comparison between internal full cost accounting and Officer-as-a-Service. The next step is to take stock: Which cost blocks are included in your current budget planning? Which items are missing? Which follow-up costs are included in the multi-year plan? How do the regulator and cyber insurance see your current level of maturity?

CIVAC works as a compliance platform and officer-as-a-service. The workspace maintains the asset register, the 93 controls according to ISO/IEC 27001:2022, the 490 audit templates, the 24/72 reporting path according to NIS-2 and the training certificates in a common system with EU data residency. Licence the workspace for your internal representatives, or have our representatives order it. In the Officer-as-a-Service variant, the external information security officers take over the order, the annual reporting line and the preparation of external audits, usually within two working days after the order is placed.

Turn reading into a mandate. A short email to info@civac.de with the industry, number of employees and current ISMS status is enough for the first appointment. If you prefer to use the contact form, you can find it linked via the FAQ page. What you don't get: a generic offer without clear items. What you get: a concrete cost breakdown with the five blocks, the multi-year planning and a comparison calculation between your current model and the Officer-as-a-Service variant. Verifiable, documented, with appointment certificate as soon as the basis for the order is in place. If you don't want to make an appointment directly, you can request a calculation template in Excel with the five cost blocks and pre-assigned bandwidths. The template is suitable for internal discussions with management before the initial meeting.

FAQ

What minimum budget does a 200-person company have to expect?

A company with 200 employees without an existing ISMS typically has to budget between 80,000 and 180,000 euros in the development year, depending on the level of maturity, the industry and the model variant chosen. In subsequent operation, the annual costs stabilize between 55,000 and 130,000 euros. Officer-as-a-Service is typically in the lower third of this range, while an internal full-cost solution is in the upper third.

Are the costs of ISO/IEC 27001:2022 certification tax deductible?

Yes, both personnel costs and consulting and audit costs are fully deductible as business expenses. The workspace licence is booked as a current expense; larger hardware investments are depreciated over their respective useful life. The tax treatment must be agreed with the tax advisor on a case-by-case basis, especially in the case of funding programs such as BMWK's Digital Now. Funding quotas reduce the deductible expense base accordingly.

Is an external ISB also worthwhile for large companies with several thousand employees?

From a size of around 1,000 to 1,500 employees, an internal full-time ISB position is generally more economical than an external solution, provided there are no special specialization requirements. However, hybrid models with an internal headquarters and external specialization for individual topics such as KRITIS sectors or international corporate regulations often remain the most economical option, even when the company is large.

What costs can be expected when switching from the old ISO 27001:2017 to the new 2022 version?

The transition requires an update of the Statement of Applicability to the new 93 Annex A controls, a risk analysis update and a transition audit. The costs are typically between 8,000 and 22,000 euros for a 200-person company. The transition period ends on October 31, 2026. Without a timely transition, the certification will expire. The CIVAC workspace already reflects the new controls in the 2022 structure.

How high is the typical cyber insurance premium in relation to the coverage amount?

The premium is typically between 0.2 and 1.2 percent of the coverage amount, depending on the level of maturity and industry. For a 5 million euro policy in medium-sized businesses with a certified ISMS, an annual premium of 12,000 to 25,000 euros is realistic; without ISMS or with proven gaps, the same policies can cost 40,000 to 60,000 euros or simply cannot be offered. ISMS proof is the most important premium lever.

Which funding programs reduce IT security costs in medium-sized businesses?

The Federal Ministry of Economics's Digital Now program promotes investments in IT security with up to 50 percent subsidies for SMEs. The individual federal states offer additional programs, such as NRW.Innovationsgutscheine or the Bavarian funding program Digitalbonus. The funding levels vary between 5,000 and 50,000 euros per project. CIVAC accompanies the application and provides the required evidence from the workspace.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles