Nobody can give you a number, and anyone who quotes one without seeing your estate is selling something. What can be described reliably is the shape of the cost: which strategies dominate, where the spend is one-off versus ongoing, and which costs consistently surprise people.
That shape is what you need to build a defensible budget.
Where the effort actually goes
Across most uplift programmes the distribution is lopsided:
- Application control — typically the largest single line. Not the tooling; the discovery, rule construction, piloting and exception handling. Plan in quarters.
- Restrict administrative privileges — second. Separate environments and jump servers are architectural change, and the human resistance costs time.
- Patching — high ongoing cost, low setup cost. The tempo is what you pay for, forever.
- Backups, macros, hardening — modest, unless discovery reveals dependencies.
- MFA — cheap at Level One, expensive at Level Two, where phishing-resistant authentication brings hardware or platform authenticators into scope.
Cost shape by level
Level Zero to Level One
Dominated by application control and by removing unsupported software. The second is the wildcard: if end-of-life systems are propping up a business process, you are funding a migration, not a security control. Most other Level One items are configuration.
Level One to Level Two
This is where recurring cost appears, because Level Two introduces central logging across four strategies. Log ingestion and retention is an ongoing line item that scales with your estate and never goes away. Add jump server infrastructure and a faster patch tempo. Budget for a platform decision, not a configuration change.
Level Two to Level Three
Driven mainly by just-in-time administration, which usually means tooling and process redesign, and by the reach of the remaining requirements. Note that phishing-resistant MFA lands at Level Two, not here, so the authenticator spend belongs in the previous step. Application control extends to every server, and logs must become tamper-resistant, which is an architecture change rather than a setting.
Cost the gap before you budget for it
GRC Copilot assesses against each maturity level and shows exactly which requirements are unmet, so the business case is built on a gap list rather than an estimate.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The costs that surprise people
- Log retention. Central logging is easy to switch on and expensive to keep. Model volume and retention before choosing a platform, not after.
- Licensing tiers. Several requirements — application control management, conditional access, credential protection — sit in higher licence tiers of platforms you already own. A per-user uplift across the organisation dwarfs most project costs.
- Application migration. Unsupported software must go. If it cannot go, you are funding a replacement.
- Second devices or virtual environments for privileged users.
- Assessment itself, especially if evidence is disorganised — a poorly prepared assessment costs more in assessor days than a well-prepared one.
- Ongoing operations. Application control rulesets, exceptions, patch tempo and access revalidation are permanent work, not project work. This is the line most business cases omit entirely.
The single most common budgeting error is treating the Essential Eight as a project. Levels are maintained, not achieved — an unfunded operational tail is how organisations quietly slide back a level between assessments.
Building the business case
- Assess first, budget second. A gap list per requirement turns an estimate into a costed plan and is far harder to dismiss.
- Separate one-off from recurring explicitly. Finance treats them differently, and hiding the recurring tail inside a project number is what gets programmes defunded in year two.
- Lead with the commercial driver where one exists. A named tender, contract clause or regulatory obligation converts a security request into a revenue or compliance one.
- Sequence by rating impact. Because maturity is the minimum across eight strategies, money spent anywhere but the weakest strategy does not move the number. That is a genuinely useful prioritisation rule and an easy one to explain.
- Be honest about what a level buys. Level Two resists a materially more capable adversary than Level One. Level Three defends against targeted, adaptive attackers — real, but not every organisation faces them, and ASD does not say everyone should target it.
Choosing a target level
Pick based on the adversaries you expect and the obligations you carry, not on ambition. A fully met Level Two is worth more than a partial Level Three — partial assesses as the lower level anyway, so the extra spend buys nothing measurable. For most Australian organisations without government or critical infrastructure exposure, a genuinely complete Level One is a bigger risk reduction per dollar than anything else available.
Frequently asked questions
Can we do this without new tooling?
Level One frequently yes, using platform capabilities you already license. Level Two usually needs a logging destination. Level Three generally needs hardware authenticators and just-in-time tooling.
What is the cheapest way to raise our rating?
Fix the weakest strategy, because the rating is the minimum across all eight. And close evidence gaps before control gaps — a working control you cannot prove is a cheap fix with the same effect on the number.
How long does an uplift take?
Level Zero to One is typically a quarter or two, dominated by application control. One to Two is roughly a quarter if Level One is genuinely complete. Two to Three is longer, driven by the authenticator rollout.
Is a third-party assessment worth paying for?
If a customer or regulator asks for one, it is not optional. Otherwise self-assess first and buy the external assessment when you believe you are close — paying an assessor to find gaps you could have found yourself is expensive.
Key takeaways
- Application control dominates the effort; logging retention dominates the recurring cost.
- Licensing tier uplifts can exceed the entire project budget — check before scoping.
- Money spent on anything but your weakest strategy does not move the rating.
- Levels are maintained, not achieved; fund the operational tail or you will slide back.