Anand Technologies Bot

What Essential Eight Compliance Actually Costs an Australian Small Business

Essential Eight compliance costs for Australian small businesses

Ask three providers what Essential Eight compliance will cost and you will get three very different numbers, none of which explain themselves. The spread is real, but it is not arbitrary. It comes down to how much of the framework your existing licences already cover, and how much of your environment has to change to satisfy the two controls that do most of the damage to a budget.

This is a breakdown of what Australian small and medium businesses actually spend reaching Essential Eight Maturity Level 2, where the money goes, and which variables move the total most.

The short answer

For a typical Australian business of 20 to 50 staff already running Microsoft 365, reaching Maturity Level 2 usually costs $12,000 to $40,000 in the first year, then $25 to $60 per user per month to hold.

That first-year figure covers an assessment, a remediation project and ongoing management. Businesses starting from a well-managed environment land at the bottom of the range. Businesses with ageing servers, unmanaged devices and no patching discipline land above it.

Cost area Typical range Type
Gap assessment $2,000 – $6,000 Once-off
Licensing uplift $0 – $15 per user / month Ongoing
Remediation project $8,000 – $30,000 Once-off
Ongoing management $25 – $60 per user / month Ongoing
Independent audit (optional) $5,000 – $15,000 Once-off / periodic

Where the money actually goes

Gap assessment: $2,000 to $6,000

Every project starts by scoring all eight controls against the current maturity model, with evidence. This is not a questionnaire. A proper assessment inspects your patching cadence, enumerates privileged accounts, checks whether backups have ever been restored, and reviews application control and macro settings on real devices.

The price varies with environment size and complexity rather than headcount. A 30-person business on one site with cloud-only infrastructure sits at the lower end. The same headcount across three sites with an on-premises server and mixed device ownership sits at the top.

Skipping the assessment is a false economy. Without it you will spend money on controls that were already adequate and miss the one scoring zero.

Licensing: often $0

This surprises people. If you are already on Microsoft 365 Business Premium, most of what Level 2 requires is included and simply switched off — Conditional Access, Defender for Business, Intune device compliance, macro policy and application control tooling are all there.

Costs appear when you are on a lower tier. Moving from Business Standard to Business Premium is the single most common licensing change, and for many businesses it is the only one. If you are on Business Basic or a mix of tiers, expect a larger uplift.

Separate line items that often need adding regardless of tier:

  • Third-party backup — Microsoft 365 and Google Workspace are not backups. Point-in-time recovery is a separate product, typically $3 to $8 per user per month.
  • Patch management tooling — usually bundled into a managed service rather than bought separately.
  • Log retention — Level 2 requires event logging. Longer retention may push you up a tier.

Remediation: $8,000 to $30,000

This is the variable that decides your total, and two controls dominate it.

Application control is the expensive one. Building an allowlist means discovering everything that runs across your fleet, deciding what is legitimate, running in audit mode for weeks, then enforcing. If your team runs a narrow, predictable set of software this is straightforward. If everyone installs their own tools, expect a longer rollout and genuine internal resistance.

Administrative privilege restructuring is the disruptive one. Separating privileged accounts from daily accounts, stripping standing local admin rights, and blocking privileged accounts from email and web browsing changes how people work. The technical effort is modest. The change management is not.

The rest — MFA, macro settings, browser hardening, backup permissions — is largely configuration and moves quickly.

Ongoing management: $25 to $60 per user per month

Essential Eight is not a project with an end date. Level 2 measures ongoing discipline: patching within two weeks (48 hours for internet-facing services with known exploits), reviewing privileged access, testing restores, retaining logs.

This is why most businesses fold it into a managed IT arrangement rather than running it internally. The lower end of the range reflects security uplift added to an existing managed contract; the upper end reflects a fuller service including monitoring and response.

What it costs by business size

Size Year one (indicative) Main driver
5 – 15 staff $6,000 – $15,000 Usually cloud-only; assessment plus configuration
15 – 50 staff $12,000 – $40,000 Application control and privilege restructuring
50 – 150 staff $35,000 – $90,000 Multiple sites, legacy systems, formal evidence

Treat these as planning figures, not quotes. Two businesses of identical headcount can differ by a factor of three depending on how their environment was built.

Four things that inflate the number

Unsupported operating systems. Level 2 requires vendor-supported systems. An out-of-support server turns a security project into a hardware replacement, and that cost dwarfs everything else on this page.

Staff-owned devices. Application control and patching on devices you do not own is difficult. Businesses running a genuine bring-your-own-device culture usually have to buy managed devices or accept a lower score.

Line-of-business software that demands admin rights. Older industry applications sometimes require local administrator privileges to run. That directly conflicts with Control 4 and forces either a vendor conversation, an application upgrade, or a documented exception.

No documentation. If nobody knows what is installed, what is licensed or how the network is configured, discovery takes longer and costs more.

What it costs to do nothing

The Australian Cyber Security Centre puts the average cost of a cybercrime incident for a small business at over $46,000. That is the direct cost — downtime, recovery, investigation — and excludes the contracts you lose afterwards.

The commercial cost is now more immediate than the risk. Cyber insurers require documented evidence of MFA, tested backups and patching cadence before they will quote or renew, and premiums increasingly reflect demonstrated maturity. Government tenders specify minimum maturity levels, and enterprise buyers cascade the same requirement through their supply chains.

For many Australian SMBs the honest framing is not risk reduction. It is that Essential Eight has become a condition of bidding for certain work.

How to keep the cost down

  1. Assess before you buy anything. Most businesses already own more capability than they use.
  2. Do the configuration controls first. MFA, macro settings, browser hardening and backup permissions cost little and lift several controls quickly.
  3. Phase application control. Run in audit mode for several weeks before enforcing. Rushing it creates outages and internal resistance that cost more than the tooling.
  4. Fold ongoing work into an existing managed contract. Paying separately for patching, monitoring and backup testing is almost always more expensive.
  5. Fix documentation early. An accurate asset and licence register reduces effort in every subsequent phase.

For the control-by-control detail behind these costs, see our guide to what Essential Eight Maturity Level 2 actually requires.

Frequently asked questions

How much does Essential Eight compliance cost in Australia?

For a business of 20 to 50 staff, budget $12,000 to $40,000 in the first year to reach Maturity Level 2, then $25 to $60 per user per month to maintain it. Smaller cloud-only businesses can achieve it for $6,000 to $15,000. The largest variables are application control and administrative privilege restructuring.

Do we need new software licences for Essential Eight?

Often not. Microsoft 365 Business Premium already includes most of what Maturity Level 2 requires, and the capability is simply not enabled. The most common licensing change is moving from Business Standard to Business Premium. Third-party backup is usually the one genuinely new purchase.

Is Essential Eight a one-off cost?

No. There is a once-off assessment and remediation cost, then an ongoing cost. Level 2 measures continuing discipline — patching cadence, privilege reviews, tested restores and log retention — so a business that stops maintaining those controls drops back down the maturity scale.

Can we reach Maturity Level 2 without a managed IT provider?

Yes, if you have internal capacity to sustain the patching cadence, privilege reviews and restore testing indefinitely. Most Australian SMBs find that outsourcing the ongoing discipline is cheaper than the internal time it consumes, which is why the ongoing cost is usually expressed per user per month.

Will Essential Eight compliance reduce our cyber insurance premium?

It can, and increasingly it determines whether you are offered cover at all. Underwriters ask for evidence of specific controls, and documented maturity strengthens your position at renewal. Speak to your broker about how your insurer weights it, as approaches differ.

The bottom line

Essential Eight compliance is not a single price. It is an assessment, a remediation project sized by how far your environment sits from the standard, and an ongoing operating cost. The businesses that spend least are the ones that assess honestly first and phase the disruptive controls rather than rushing them.

We deliver Essential Eight uplift as part of our managed IT services, combining advanced endpoint protection with the patching and backup discipline the framework measures. For businesses starting out, essential antivirus and anti-malware protection covers the baseline while you plan the wider uplift.

For a fixed-price gap assessment and a costed roadmap for your environment, get in touch.

Comments are closed.