IT Budget Planning Build a Number You Can Defend
An IT budget is the documented plan for what an organization will spend on technology over a fiscal year, broken into the categories that actually drive the total: people, recurring licenses and subscriptions, hardware refresh, security and compliance, and a reserve for the work nobody scheduled. IT budget planning is the annual process of producing that number from evidence rather than from last year's spreadsheet plus a guess. This page covers what belongs in an IT budget, how to size one, a reusable IT budget template you can adapt, and the IT budget management practices that keep the plan honest after the fiscal year starts.
Key Takeaways
- An IT budget has five load-bearing categories: staffing and outsourced support, recurring software and subscriptions, hardware and lifecycle refresh, security and compliance, and a contingency reserve. A budget missing any one of them will be wrong by the second quarter.
- Three sizing methods exist and they answer different questions. Percent of revenue tests whether your spend is plausible for your industry. Cost per employee makes the number scale with headcount. Zero-based budgeting justifies each line from scratch and is the only method that finds waste.
- You cannot budget for assets you have not inventoried. A current IT asset inventory is the input that turns a hardware refresh line from a guess into a schedule.
- Compliance obligations are budget line items, not overhead. CMMC, HIPAA, PCI DSS, SOC 2, and the FTC Safeguards Rule each carry assessment fees, tooling, remediation, and documentation costs that arrive whether or not anyone planned for them.
- Petronella Technology Group, Inc. has been building technology budgets with Raleigh and Triangle businesses since April 2002, through virtual CIO services that turn a spreadsheet exercise into a multi-year roadmap tied to real asset and compliance data.
Before You Open the Spreadsheet
- Pull last year's actuals, not last year's budget. The gap between the two is the most useful document in the entire process, and it is the one most companies never look at.
- Find the shadow spending first. Software bought on departmental credit cards rarely appears in the IT line, and it is often a meaningful share of true technology cost.
- Separate run from change. Keeping the lights on and funding new capability are different conversations, and merging them lets routine cost growth quietly eat every improvement project.
- Get the compliance calendar before you get the quotes. An assessment window that lands in Q3 changes what has to be funded in Q1.
What Is an IT Budget?
The plain definition, and the distinction that determines whether the number survives the year.
An IT budget is a documented, time-bound plan for an organization's technology spending, usually covering one fiscal year, organized into categories that map to how the money is actually committed. It is not a single number. A useful IT budget shows what is contractually locked in, what is discretionary, what is scheduled but not yet ordered, and what has been deliberately held in reserve.
The distinction that matters more than any other is between operating expenditure and capital expenditure. Operating spend recurs: managed services fees, per-user software licenses, cloud consumption, connectivity, support contracts, security monitoring. Capital spend is lumpy and periodic: servers, network equipment, laptop fleets, a phone system replacement. Operating spend is predictable and grows quietly with headcount. Capital spend is unpredictable in any single year but entirely predictable across five, provided somebody is tracking asset age.
Most small and midsize technology budgets fail for one of two reasons. Either they treat capital as a surprise, so a fleet of five-year-old laptops all fail in the same quarter and the request goes to the board as an emergency, or they treat operating growth as fixed, so the subscription line grows fifteen percent a year and nobody notices until it has doubled.
IT Budget vs IT Roadmap vs IT Strategy
These three artifacts are related and frequently confused. An IT strategy states what technology is supposed to accomplish for the business over the next several years. An IT roadmap sequences the projects that deliver that strategy and assigns them to quarters. The IT budget prices the roadmap and funds it. Producing a budget without the other two is how organizations end up spending steadily and improving slowly. Petronella Technology Group, Inc. treats these as one engagement rather than three, which is the core of IT strategy consulting work.
What Belongs in an IT Budget
Five categories. Every line item in a defensible budget lands in one of them.
1. People and Support
Salaries and benefits for internal technology staff, plus every outsourced support arrangement: managed services agreements, help desk contracts, project labor, and specialist consulting. For most organizations under two hundred employees this is the single largest category, and it is where the structural decision lives. Fully internal, fully outsourced, and co-managed IT models produce very different cost curves at different headcounts, and the crossover points are worth modeling rather than assuming.
Budget the total cost of an internal hire, not the salary. Benefits, payroll taxes, training, certification renewals, tooling licenses, and the coverage gap when that person takes vacation are all real costs that a managed services line already absorbs.
2. Recurring Software and Subscriptions
Per-user productivity suites, line-of-business applications, cloud infrastructure consumption, backup services, collaboration tools, and every subscription the company has quietly accumulated. This category deserves its own audit before it gets a number. Per-user pricing means this line grows automatically with hiring, so it should be budgeted as a rate multiplied by projected headcount rather than as last year's total plus a percentage.
Cloud consumption is the item most often underestimated, because it is metered rather than licensed. A workload that grew steadily through the year exits December costing considerably more per month than it did in January, and budgeting off the January figure produces a shortfall.
3. Hardware and Lifecycle Refresh
Workstations, laptops, servers, networking equipment, firewalls, phones, printers, and peripherals. The correct way to budget this category is a rolling replacement schedule derived from your asset inventory: if laptops are on a four-year cycle, one quarter of the fleet is funded every year, forever. That converts an unpredictable capital request into a flat, defensible line.
Organizations without an inventory cannot do this, which is why an IT asset inventory is a budgeting prerequisite rather than a security nicety. Procurement lead times also belong in the plan. Equipment ordered in the last week of a fiscal year frequently arrives in the next one, and the accounting for that needs deciding in advance rather than in a hurry. IT procurement support exists partly to keep that timing from becoming a problem.
4. Security and Compliance
Endpoint protection and managed detection and response, email security, security awareness training, vulnerability scanning, penetration testing, log retention, incident response readiness, cyber insurance premiums, and the direct costs of whichever compliance regime applies. This category is the one most likely to be treated as optional and is the one where deferral compounds fastest.
Compliance costs in particular are lumpy and calendar-driven. A CMMC assessment, a SOC 2 Type II observation window, a HIPAA risk analysis, or a PCI DSS validation each carry a defined cost and a defined date, and both are knowable a year ahead. Budgeting them as they arrive is how organizations end up funding compliance out of the contingency reserve and then having no reserve. Petronella Technology Group, Inc. builds these into the plan directly, using the ComplianceArmor® platform to keep documentation costs from becoming a recurring consulting expense.
5. Contingency and Project Reserve
A named reserve for the unplanned: a failed server, an acquisition that doubles the user count, a security incident, a vendor that discontinues a product you depend on, a regulatory change. Reserve is not padding, and it should not be hidden inside other lines. A visible reserve is defensible to a finance team; padding discovered inside a hardware line is not, and it damages credibility for every subsequent budget cycle.
How Much Should a Business Spend on IT?
Three methods, three different questions. Use all three and reconcile the answers.
There is no universal correct percentage, and any advisor who offers one without asking about your industry, regulatory exposure, and technology dependence is selling a number rather than analyzing one. What does exist is a set of methods that triangulate a plausible range, and a discipline of using more than one so an outlier gets caught.
Method 1: Percent of Revenue
Total technology spend expressed as a share of gross revenue. Analyst benchmarks published for this metric vary widely by sector: technology-dependent industries such as software, financial services, and healthcare information systems sit substantially higher than construction, distribution, or professional services. The value of the method is not precision but sanity checking. If your peers cluster in a range and you are at a third of it, you are either unusually efficient or accumulating risk, and it is worth knowing which.
The method's weakness is that revenue and technology need are only loosely coupled. A high-revenue distributor with forty employees genuinely needs less technology than a low-revenue defense subcontractor with forty employees and a CMMC obligation.
Method 2: Cost per Employee per Month
Total annual technology spend divided by headcount, then by twelve. This is the most useful internal metric for a growing company, because it makes the budget scale honestly. When someone asks what it costs to add fifteen people, a per-employee figure answers immediately and credibly.
It also exposes drift. If cost per employee climbs year over year while headcount is flat, something is growing that nobody chose: unused licenses, an oversized cloud footprint, overlapping tools bought by different departments. That is a finding worth acting on, and it is invisible when only the total is tracked.
Method 3: Zero-Based Budgeting
Every line starts at zero and must be justified for the coming year rather than inherited from the last one. It is the most time-consuming method and the only one that reliably finds waste. Running it every year is impractical for most teams. Running it every third year, or for a single category such as software subscriptions, captures most of the benefit at a fraction of the effort.
Reconciling the Three
Build the budget bottom-up from actual line items, then test the total against the percent-of-revenue range for your sector and against your own cost-per-employee trend. When the three disagree materially, the disagreement is the analysis. A bottom-up number far below the sector range usually means deferred hardware refresh or unfunded security. A number far above it usually means duplicated tooling or a support model that no longer fits the size of the company.
How to Build an IT Budget in Six Stages
A repeatable IT budget planning sequence, from evidence gathering to approval.
Collect Actuals and Contracts
Start with what was really spent, pulled from the general ledger rather than from memory or from last year's plan. Then collect every technology contract with its renewal date, notice period, and auto-renewal terms. This stage routinely surfaces two things: subscriptions nobody can identify an owner for, and renewal dates that quietly passed the cancellation window months ago. Both are budget decisions, and both are invisible until someone assembles the list.
Reconcile Against the Asset Inventory
Match spending to assets. Every device in the inventory should map to a support cost, a license, and a position in the refresh cycle; every recurring charge should map to something that exists and is used. The mismatches in both directions are the finding. Assets with no support cost are unmanaged risk. Charges with no matching asset are money leaving for nothing, and in a company that has been through any growth this is rarely zero.
Project Headcount and Growth
Get hiring plans from the leadership team, by quarter if possible. Per-user costs, onboarding hardware, and license tiers all move with headcount, and tiered pricing means growth is rarely linear. Crossing a licensing threshold or a support tier boundary can move a line materially in one month. Ask about office changes, acquisitions, and any new location as part of the same conversation, because each carries connectivity and equipment costs that have long lead times.
Price the Compliance Calendar
List every assessment, audit, renewal, and attestation due in the budget year with its date and its cost. For a defense contractor that means the CMMC assessment cycle, System Security Plan maintenance, and any remediation identified in the last gap analysis. For a medical practice it means the annual HIPAA risk analysis and workforce training. For a business handling cardholder data it means PCI DSS validation. These dates do not move to suit a cash flow forecast, so they belong in the plan before discretionary projects do.
Sequence Projects Against Capacity
Rank the discretionary work by business value and by dependency, then check the sequence against the capacity of the people who have to deliver it. Most budgets are over-committed not on money but on attention: a plan containing four major projects and a team that can realistically run one at a time will underspend the budget and still miss every deadline. Cutting the list to what can actually be delivered produces a more accurate number and a better year.
Present in Business Terms
Take the finished plan to leadership framed as outcomes and risk, not as equipment. A line reading "firewall replacement" invites a challenge. The same line described as maintaining the perimeter controls that a cyber insurance policy and a client contract both require does not, because it names what is lost by deferring it. Show the deferral consequence for every item you expect to be questioned, and bring the multi-year view so this year's capital request is visibly part of a cycle rather than an isolated ask.
IT Budget Template: Line Items to Copy
A reusable IT budget sample structure. Adapt the categories, keep the discipline of naming the cost driver for each line.
The value of an IT budget template is not the arithmetic, which any spreadsheet does. It is the completeness check. Most budgets are wrong because a category was forgotten, not because a number was miscalculated. Use the structure below as a checklist, and record the cost driver next to every line so that next year's revision takes an hour instead of a week.
| Category | Representative Line Items | Cost Driver to Record | Type |
|---|---|---|---|
| People and Support | Internal IT salaries and benefits, managed services agreement, help desk contract, project labor, specialist consulting | Headcount supported, devices supported, contracted service level | Operating |
| Software and Subscriptions | Productivity suite, line-of-business applications, collaboration tools, backup service, cloud infrastructure consumption | Users multiplied by rate, storage or compute consumed, license tier boundaries | Operating |
| Hardware Refresh | Workstations and laptops, servers, network switches, firewalls, wireless access points, phones, peripherals | Asset count divided by refresh cycle length, procurement lead time | Capital |
| Connectivity and Facilities | Internet circuits, failover connection, colocation or rack space, cabling, uninterruptible power supplies | Sites, bandwidth committed, contract term | Operating |
| Security | Managed detection and response, email security, security awareness training, vulnerability scanning, penetration testing, log retention, cyber insurance | Endpoints protected, users trained, retention period required | Operating |
| Compliance | Assessment and audit fees, remediation work, policy and documentation maintenance, evidence collection tooling | Framework, assessment date, scope boundary size | Mixed |
| Projects | Migrations, replacements, new capability rollouts, office moves, integration work | Scope, sequencing, internal capacity available | Mixed |
| Contingency Reserve | Unplanned replacement, incident response, growth beyond forecast, vendor discontinuation | Percentage of total, set by risk tolerance and asset age | Mixed |
Two additions make this template considerably more useful than a flat list. First, add a column for the renewal or decision date on every contracted line, so the budget doubles as a procurement calendar. Second, add a deferral consequence column on capital and project lines that records what happens if the item is cut. That column is what makes the conversation with finance productive, because it moves the discussion from cost to trade-off.
Three Ways to Fund IT, Compared
The support model you choose determines the shape of the budget, not just its size.
| Dimension | Break-Fix | Fully Managed Services | Co-Managed IT |
|---|---|---|---|
| Budget predictability | Low. Cost tracks failures, so the worst months are the ones you cannot forecast. | High. A flat recurring fee covers defined scope, and variance sits mostly in projects. | Moderate to high. The contracted layer is fixed, internal staffing is known, project work varies. |
| Cost behavior as you grow | Rises unevenly. More devices means more failures and more hourly labor. | Scales with users or devices at a known rate, so growth is straightforward to model. | Scales on the contracted layer only. Internal capacity is a separate, deliberate decision. |
| Incentive alignment | Weak. Revenue is earned when systems break. | Strong. Prevention reduces the provider's cost and yours at the same time. | Strong on the contracted scope, with internal ownership of institutional knowledge. |
| Security and compliance coverage | Usually out of scope. Monitoring and documentation are billed separately if offered. | Typically bundled or available as a defined tier, with continuous coverage. | Split by agreement, which needs writing down precisely to avoid gaps at the boundary. |
| Best fit | Very small offices with low technology dependence and high tolerance for downtime. | Organizations without internal IT staff, or with regulatory obligations and no compliance specialist. | Companies with capable internal staff who need depth in security, compliance, or after-hours coverage. |
The comparison that matters when budgeting is not simply which model is cheapest in a single year. It is which model produces a number you can forecast. A break-fix arrangement can look inexpensive in a good year and then consume the contingency reserve in a bad one, and the bad year is precisely when cash is least available. A flat managed IT services agreement trades some best-case savings for a number that finance can plan around, and it moves prevention costs into the recurring line where they belong. Co-managed IT is the middle path for organizations that already have competent internal staff and need specific depth rather than full coverage, and it is increasingly the model that fits growing Triangle companies with one or two internal technologists.
Whichever model applies, the budget should show what is inside the contracted scope and what is not. Items assumed to be covered and then billed separately are the most common source of variance in a first-year managed services relationship, and the fix is a scope review at budget time rather than a dispute at invoice time. Outsourced IT arrangements vary widely in what a base fee includes, and reading the exclusions is worth more than negotiating the rate.
IT Budget Management After Approval
The plan is a hypothesis. Management is the part that keeps it true through four quarters.
Approval is the midpoint of the process, not the end. IT budget management is the ongoing discipline of tracking commitment against plan, catching drift while it is still small, and re-forecasting when the assumptions change. Organizations that skip it discover the variance in month eleven, when nothing can be done about it.
Track Commitments, Not Just Invoices
A signed three-year agreement commits budget across three fiscal years even though the first invoice is one month's worth. Tracking only what has been paid understates true position and makes the fourth quarter look far healthier than it is. Record the commitment when the contract is signed.
Review Quarterly and Re-Forecast Honestly
A quarterly review comparing plan to actual, by category, catches the two failure patterns early: a subscription line growing faster than headcount, and a project line underspending because work has not started. The second is more dangerous than it looks, because underspend in Q1 and Q2 usually means the project arrives compressed into Q4 or slips entirely, and neither outcome was the plan.
Attach Every Change to a Reason
When a line moves, record why in one sentence. Over a year this produces the single most valuable input to the next budget cycle: a documented list of what you did not anticipate. That list is what turns the following year's contingency figure from a round number into an evidence-based one.
Watch the Subscription Line Specifically
Per-user software is the category that grows without a decision. Licenses assigned to departed employees, tools retained after their replacement was purchased, and tiers upgraded for a one-time need all persist by default. A twice-yearly license reconciliation against your identity provider and your asset inventory is a small task that reliably returns more than it costs.
Treat Security Findings as Budget Events
A vulnerability scan, a penetration test, or a tabletop exercise produces findings that cost money to remediate. Those findings should flow into the budget process rather than sitting in a report, and the remediation should be scheduled and funded rather than absorbed. Managed detection and response coverage and patch management reduce the volume of surprise remediation considerably, which is itself a budgeting argument.
"Craig takes the time to understand our business model, not just our technology stack. It makes his recommendations more strategic and tailored to our actual goals."
Daniel Lee, verified TrustIndex reviewSix IT Budget Planning Mistakes That Repeat Every Year
Patterns visible across two decades of budget conversations with regulated businesses.
Budgeting Last Year Plus a Percentage
The fastest method and the least defensible. It carries forward every error in the prior year, including the categories that were forgotten, and it cannot answer the only question leadership will actually ask, which is what would happen if the number were smaller.
Treating Security as a Project
Security funded as an occasional project rather than a recurring line produces a sawtooth: heavy investment after an incident or a failed audit, then years of erosion. Monitoring, training, patching, and testing are operating costs with a cadence, and budgeting them that way is both cheaper and more effective than funding them in response to events.
Ignoring the End-of-Support Calendar
Operating systems, hypervisors, database versions, firewall firmware, and business applications all reach end of support on published dates. Those dates are known years in advance and they are non-negotiable, because running unsupported software fails security questionnaires, breaches insurance conditions, and shows up as a finding in nearly every compliance framework. A budget built without checking them is a budget with a hole in it.
Forgetting the Cost of Growth Itself
Hiring plans get into the salary budget and rarely into the technology budget. Each new employee needs a device, licenses, onboarding time, and a share of support capacity, and those costs land in the month they start rather than being averaged across the year. A budget that assumes flat headcount in a growing company will be short by exactly the amount of the growth.
Underfunding the Boring Middle
Backup verification, documentation, log retention, and configuration management attract no enthusiasm and are the first cuts proposed. They are also what determines whether a bad day is an inconvenience or a business interruption. Restoring from a backup nobody tested is where the real cost of that saving appears.
Presenting Only One Scenario
A single number invites a single response, which is to reduce it. Bringing a baseline, a constrained version, and a version that funds the roadmap changes the conversation from negotiation to prioritization, and it lets leadership own the trade-off explicitly rather than delegating it back to the technology team by cutting a total.
Budgeting for Compliance Obligations
Regulated organizations carry costs that are scheduled, mandatory, and frequently unplanned.
For a business subject to a compliance framework, a meaningful share of the technology budget is not discretionary at all. It is driven by a standard, a contract clause, or a regulator, and the timing is set by someone else. Treating those obligations as a distinct budget category rather than scattering them across other lines makes both the total and the trade-offs visible.
Defense Contractors and CMMC
Organizations handling Controlled Unclassified Information carry costs across several lines simultaneously: scoping and gap analysis, technical remediation of the NIST SP 800-171 controls that are not yet met, System Security Plan and Plan of Action maintenance, evidence collection, and the assessment itself. The largest and most frequently underestimated item is remediation, because its size depends entirely on the gap analysis result. Sequencing matters: a gap analysis in one budget year and an assessment in the next spreads the cost and produces a better outcome than compressing both. Craig Petronella, CMMC Registered Practitioner and author of the CMMC 2.0 Certification Guide, works these plans with contractors across the Triangle and nationwide; the CMMC compliance guide covers the control set in detail.
Healthcare and HIPAA
The annual risk analysis, workforce training, business associate agreement management, audit log retention, and encryption for data at rest and in transit each carry a cost and a cadence. Risk analysis is a recurring obligation rather than a one-time project, and budgeting it annually rather than reactively is both cheaper and considerably easier to evidence when it is examined. Craig Petronella, author of "How HIPAA Can Crush Your Medical Practice" and NC Licensed Digital Forensics Examiner, has worked with medical practices on exactly this since the compliance practice launched.
Everyone Else
SOC 2 Type II requires an observation window, which means the controls must be operating and evidenced for months before the report is issued, and the budget has to fund that period. PCI DSS validation scales with how the environment is scoped, and scope reduction work often pays for itself. The FTC Safeguards Rule reaches many financial institutions that did not consider themselves regulated at all, and the first year of compliance is the expensive one.
Across all of these, documentation maintenance is the cost that recurs quietly forever. Policies drift out of date, evidence has to be re-collected, and each assessment cycle regenerates work that was done before. Petronella Technology Group, Inc. built the ComplianceArmor® platform to keep that from being a recurring consulting line, generating and maintaining the documentation set rather than rebuilding it each cycle.
How Petronella Technology Group Approaches Budget Planning
What the engagement looks like, and what you leave with.
Petronella Technology Group, Inc. has been planning technology spending with Raleigh, Durham, Cary, Chapel Hill, and Apex businesses since April 2002, and nationwide for regulated clients. The work is delivered through virtual CIO services, which is the model that fits organizations needing executive-level technology planning a few times a year rather than a full-time technology executive on payroll.
An engagement typically runs in four parts. First, a discovery pass that builds or refreshes the asset inventory and pulls the contract register, because a budget cannot be better than its inputs. Second, a gap and risk review that identifies what is unfunded: aging hardware, unsupported software, missing security controls, and compliance obligations arriving in the budget year. Third, the budget model itself, built bottom-up with the three sizing methods reconciled and presented in baseline, constrained, and roadmap scenarios. Fourth, the multi-year view, so that this year's capital request sits inside a visible refresh cycle rather than appearing as an isolated demand.
What clients keep is the model, not just a report. The spreadsheet, the asset and contract registers behind it, and the assumptions are handed over, so the following year is a revision rather than a rebuild. For organizations that also want the security and compliance conversation held by the same people, the distinction between a virtual CIO and a virtual CISO engagement is worth understanding before choosing, and the vCISO and vCIO comparison explains where the two roles diverge.
Craig Petronella has written about the buying side of this for years, including in "IT Buyers Guide," which covers the questions worth asking before signing any technology contract. The full set is on the books page, and budgeting, vendor selection, and technology strategy come up regularly on the Encrypted Ambition podcast.
IT Budget Questions, Answered
The questions that come up most in budget season.
What is an IT budget?
How much should a small business spend on IT?
What should be included in an IT budget?
What is the difference between an IT budget and IT budget planning?
Do I need an IT budget template or custom-built model?
How do I budget for cybersecurity separately from IT?
How often should an IT budget be reviewed?
How do compliance requirements change the budget?
Build a Technology Budget You Can Defend
Petronella Technology Group, Inc. has been planning technology spending with regulated businesses since April 2002. CyberAB Registered Provider Organization #1449, BBB A+ rated since 2003, rated 4.7 across 92 verified TrustIndex reviews. We will review your current spending, find what is unfunded, and build a budget model you keep.
Petronella Technology Group, Inc. · 5540 Centerview Dr., Suite 200, Raleigh, NC 27606 · 919-348-4912
Last Updated: August 11, 2026