Most IT budgets fail for the same reason. They are built from last year's number plus a percentage, rather than from what the organisation actually owns and owes. That works until a core switch dies, an audit lands, or a licence renewal arrives at three times the expected price. Then the budget is not a plan, it is a fiction that someone has to explain.

IT budgeting and planning done properly is not complicated. It is mostly the discipline of writing down what you have, when it expires, and what happens if you do nothing.

Start with what you own, not what you spent

Every defensible IT budget begins with an inventory. Not a spreadsheet of purchase orders, but a current-state list of assets with three attributes attached to each: what it is, how old it is, and when it stops being supported.

That single exercise usually surfaces two things nobody expected. First, equipment already past end of support that is quietly carrying production load. Second, licences being paid for that nobody uses. Both are budget items, and both are invisible if you plan from last year's total.

The three-year lifecycle view

Hardware fails on a schedule that is broadly predictable. Endpoints run four to five years, servers and network gear five to seven, depending on how hard they work and how tolerant you are of risk. Once you know the age of everything, replacement stops being a surprise and becomes a line you can smooth across three budget cycles instead of absorbing in one.

The six categories a complete IT budget covers

Budgets that only cover the first three are the ones that get blown.

  1. Recurring operations. Managed services or internal staff, monitoring, help desk, connectivity.
  2. Hardware lifecycle. Scheduled replacement of endpoints, servers, network and peripherals.
  3. Software and licensing. Including the renewals that reprice, which is increasingly all of them.
  4. Security and compliance. Tooling, assessments, remediation, and the cost of evidence for whatever framework applies to you.
  5. Projects and change. Migrations, new sites, system replacements. The work that gets deferred first and costs most when deferred.
  6. Contingency. A real number, not a rounding error. Something will break that you did not forecast.
Good to know: the category most often missing entirely is compliance. Organisations subject to CMMC, HIPAA or CJIS routinely budget for the technology and forget the assessment, documentation and remediation effort, which is frequently the larger number.

How to plan an IT budget in five steps

  1. Inventory everything. Assets, licences, contracts, renewal dates. If you cannot produce this, an IT assessment is the fastest route to it.
  2. Map the expiry curve. Plot when each asset and contract runs out over the next 36 months.
  3. Layer in obligations. Compliance deadlines, insurance requirements, contractual security commitments.
  4. Add the plans. New sites, headcount changes, system replacements the business has already decided on.
  5. Price it and rank it. Every line gets a cost and a consequence-of-deferral. The ranking is the conversation with finance.

Long-term IT budget planning and ROI

The hardest part of IT budgeting is rarely the arithmetic. It is defending the number to people who experience IT as a cost centre. The move that works is to tie each line to avoided cost or enabled capacity rather than to the technology itself.

Weak framingDefensible framing
Replace ageing serversRemove the single points of failure behind an estimated X hours of annual downtime
Buy an EDR platformMeet the endpoint control our cyber insurance renewal now requires
Upgrade the networkSupport the additional sites and headcount already approved for next year
Compliance toolingClose the audit findings that currently put contract eligibility at risk

Anything you cannot express in the right-hand column is worth questioning before it reaches the budget. For a view of what the left-hand column actually costs when it goes wrong, see the hidden costs of downtime.

On benchmarks and percentages

The question we hear most is what percentage of revenue IT should represent. Published benchmarks exist and they vary enormously by sector, headcount and regulatory load. Using one as a target rather than a sanity check is a common mistake: it produces a number that is easy to defend and unrelated to what your environment actually needs.

Build bottom-up from your assets, obligations and plans. Then compare the result to a benchmark to see whether it is plausible. If your number is wildly below sector norms, that is not efficiency, it is usually deferred maintenance you have not written down yet.

Key takeaways
  • Build the budget from a current asset and contract inventory, not from last year plus a percentage.
  • Plan spend annually and lifecycle over three years, so replacement is scheduled rather than urgent.
  • Six categories, and the two most often missed are compliance effort and a real contingency line.
  • Tie every line to avoided cost or enabled capacity, or expect to lose the argument with finance.

Frequently asked questions

What should an IT budget include?

Six categories: recurring operations, hardware lifecycle replacement, software and licensing, security and compliance, projects and change, and contingency. Budgets that cover only the first three are the ones that get blown by a single failure or renewal.

How far ahead should IT budget planning look?

One year for spend and three years for lifecycle. The three-year view is what turns a hardware failure from an emergency into a scheduled line item, because most servers, switches and endpoints have predictable replacement windows.

How do you show ROI on IT spending?

Tie each line to avoided cost or enabled capacity rather than to the technology itself. Downtime hours avoided, staff hours returned, audit findings closed, and insurance or contract requirements met are all defensible positions. Anything you cannot express that way is worth questioning.

What percentage of revenue should go to IT?

Published benchmarks vary widely by sector and headcount, and treating one as a target rather than a sanity check is a common mistake. Build bottom-up from your actual assets, obligations and plans, then compare to a benchmark to test whether the number is plausible.

Keep exploring

Ready for a clear path forward?

Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.

Start with a Clarity Conversation