Essential Eight costing has stopped being guesswork. As at 2026, enough Australian providers publish component-level pricing that an SME can build a defensible budget before talking to anyone: an assessment in the low thousands, tooling priced per device and per user, and an ongoing management line that scales with headcount. A 25-person business can now walk into a procurement conversation with a number it derived itself and check every quote against it.
The useful finding in those published bands is not the headline total. It is where the money sits. Licences are the smallest part. The cost is in remediation — the legacy application that will not tolerate application control, the local admin rights nobody has revoked, the backup that has never been restore-tested — and in the evidence trail that proves the controls are actually running month after month.
The published 2026 cost bands
The ACSC Essential Eight is a baseline written for organisations generally, from small businesses through to large enterprises, and it is increasingly used as the de facto baseline in Australian supply-chain and tender questionnaires. The costs of getting there now break down roughly as follows for a business of 10 to 30 staff, according to 2026 Australian cost guidance:
| Component | Typical cost |
|---|---|
| Gap assessment | $2,000 – $5,000 one-off |
| MFA deployment (software) | $500 – $2,000 |
| MFA deployment (hardware keys) | $2,000 – $5,000 |
| Patch management tooling (ML1) | $2 – $5 per device/month |
| Patch management tooling (ML2) | $5 – $10 per device/month |
| Application control | $0 with built-in tooling; $3 – $8 per device/month for advanced |
| Backup | $5 – $15 per user/month; $10 – $25 for immutable |
| Ongoing MSP management (ML1) | $20 – $50 per user/month |
| Ongoing MSP management (ML2) | $40 – $80 per user/month |
Those same figures produce a year-one total of $12,000 to $25,000 for Maturity Level 1 and $30,000 to $60,000 for Level 2 in a 20-user business. A separate mid-market guide covering 10 to 50 employees splits it differently but lands in a compatible place: assessment $2,000–$5,000, ML1 implementation $5,000–$15,000, ML2 implementation $15,000–$30,000, and $5,000–$10,000 per year ongoing. A 2026 synthesis of multiple sources puts first-year Essential Eight spend for a 25 to 75 person business with a reasonably modern environment at between $15,000 and $60,000, and another 2026 estimate frames it as $15,000–$40,000 a year for businesses of 1 to 20 employees.
Three independent sources converging on a $12k–$60k year-one range for a small business is about as much pricing certainty as this market offers.
The licence line is small, and that surprises people
The most common assumption in a first Essential Eight conversation is that Business Premium already covers it. Microsoft 365 Business Premium lists at AU$32.90 per user per month on an annual commitment, or AU$39.48 monthly, and Australian licensing commentary notes that Business Premium pricing was held in Microsoft's 1 July 2026 price round. Defender for Business, which is bundled into Business Premium, costs AU$4.50 per user per month as a standalone SKU.
So the licence component for 25 users is roughly $10,000 a year, and most of that was already being spent. It buys you the capability to satisfy several of the eight controls. It does not buy the configuration, the exception handling, the tested restore, or the dated evidence that an auditor or a prime contractor will ask for.
That is where the second set of numbers comes in. The same 2026 analysis that gives the $15k–$60k first-year figure separates out remediation projects — replacing legacy systems, tightening administrative privileges — at $10,000 to $100,000-plus depending on scope, and ongoing maintenance including patch verification, backup testing and evidence collection at $1,000 to $10,000-plus per month. Remediation is the variable nobody can quote accurately without looking at your environment first, which is exactly why the gap assessment is a separate line item rather than a free sales call.
A worked example: 25 users, 40 devices
Take a professional services firm with 25 staff, 40 endpoints (laptops plus a handful of shared desktops and a couple of servers), already on Business Premium, targeting Maturity Level 1 because a government client asked for it in a tender.
One-off, year one
- Gap assessment: $2,000 – $5,000
- MFA hardening and rollout, software-based: $500 – $2,000
- Remediation: unknown until the assessment lands. Budget a contingency; if there is a line-of-business application that breaks under application control or a server still running an unsupported OS, this is the line that moves.
Recurring, annualised
- Patch management tooling at $2–$5 per device: $960 – $2,400
- Application control at $0 (Windows built-in) to $8 per device: $0 – $3,840
- Backup at $5–$15 per user: $1,500 – $4,500
- Ongoing management at $20–$50 per user: $6,000 – $15,000
Year one, excluding remediation, sits between roughly $11,000 and $33,000. That brackets the published $12,000–$25,000 ML1 band neatly, and it tells you something useful: about two-thirds of the recurring spend is the management line, not the tools. You are buying someone to run the controls and produce the evidence, and the ongoing patch verification, restore testing and evidence collection is precisely the managed security and compliance work that a maturity claim rests on. Tooling with nobody accountable for it produces dashboards, not compliance.
Note the shape of the numbers if you are device-heavy. Patching and application control price per device; backup and management price per user. A warehouse, clinic or manufacturer running 25 staff against 60 or 70 devices pays materially more than the per-user headline suggests. Run both models across your own asset list before comparing proposals — two quotes at the same "per user" rate can differ by thousands once device count is applied.
The Level 1 to Level 2 step
Maturity Level 2 is not a 20 per cent uplift. In the published bands, ongoing MSP management roughly doubles, from $20–$50 to $40–$80 per user per month, and patch tooling moves from $2–$5 to $5–$10 per device. Implementation cost roughly triples in the mid-market figures, from $5,000–$15,000 to $15,000–$30,000.
For our 25-user, 40-device firm, the recurring management line alone moves from $6,000–$15,000 to $12,000–$24,000 a year. That is the price of shorter patch windows, tighter privileged access management, application control that is actually enforced rather than audited, and a testing cadence that generates evidence continuously instead of annually.
The decision is commercial, not technical. Level 2 is worth funding if a contract, an insurer or a regulator requires it, or if you handle data where the recovery scenario is genuinely existential. Otherwise, reaching Level 1 across all eight controls beats reaching Level 2 across three of them. Uneven maturity is the most common finding in a first assessment and the least defensible position in a tender response.
Reading a proposal against these numbers
The gap between a $110 per user per month managed IT quote and a $180 one is usually the security and compliance layer. Australian pricing guides for 2026 put fully managed IT in a broad $35–$300 per user per month range, with full managed plus security at $140–$300, and co-managed arrangements at $45–$175 per user per month, where the security-led tiers explicitly include Essential Eight Maturity Level 1 to 2 work.
Three questions separate a real Essential Eight offer from a security bundle with the words attached:
- Which maturity level does the standard package reach, control by control? A provider that cannot answer per control is answering per brochure.
- Is application control included, and enforced or audit-only? This is the single most common exclusion, and the most common source of a year-one cost overrun.
- What evidence do we receive each month, and would it survive a client's due diligence questionnaire? Patch compliance reports, restore test results and privileged access reviews, dated.
The comparison against downside is worth making once and then setting aside. Australian breach cost commentary cites an average of $4.26 million and $176 per compromised record across businesses generally, and SME-focused commentary treats $56,571 as a floor rather than a full accounting for smaller entities. The Notifiable Data Breaches scheme formally binds entities over $3 million in annual turnover, but contractual pressure now reaches well below that threshold. For most SMEs the stronger argument is simpler: Essential Eight alignment is increasingly a condition of winning work, and the revenue it protects is easier to quantify than the incident it prevents.
Where to start
Build the asset list first. Count users and devices separately, note which endpoints are outside Intune or your RMM, list every application that needs local admin to run, and find out when the last successful restore test was and who witnessed it. That list is what turns the bands above into your number rather than an industry average, and it is the first thing any assessor will ask for.
When you want that priced properly, Precision IT runs an Essential Eight assessment that scores your current maturity control by control, identifies which gaps are configuration and which are genuine remediation projects, and returns a costed path to Maturity Level 1 or 2 with the recurring management figure stated separately from the one-off work. If the honest answer is that your existing licences and a tighter operating rhythm get you most of the way, you will get that answer too, in writing, with the residual gaps named.