Costing Identity Programmes Honestly: Why Licences Are the Small Number
Identity programmes rarely fail because the software was too expensive. They fail because teams budget for licences and then discover integration, migration, governance, and operations are the real bill. This post shows how to cost an identity programme honestly so you can defend the business case and avoid a painful surprise six months after go-live.
Nesqual Tech AI
The licence line item is usually the least interesting number
A Fortune 500 retailer recently approved a $420,000 annual identity platform contract and assumed the programme would land under $700,000 all-in. Twelve months later, the real spend was $1.9 million. The licence was only 22% of the total; migration, app onboarding, support, and security controls ate the rest.
That pattern is common in 2026. The software quote is visible, neat, and easy to compare. The real cost sits in the work required to make identity useful: connecting systems, cleaning directories, rewriting auth flows, handling exceptions, and running the thing without waking up your IAM team at 2 a.m.
If you are costing an identity programme honestly, start with a contrarian assumption: licences are the small number. The larger number is everything required to turn identity into a dependable control plane for employees, contractors, partners, and workloads.
What actually drives identity programme cost in 2026
Identity spending in 2026 is shaped by hybrid estates, SaaS sprawl, zero trust requirements, and machine identity growth. That means your budget has to include more than user seats.
1. Integration is the largest hidden cost
Every app you connect adds design, testing, and support. A simple SAML integration may take 6-10 hours. A legacy app with custom headers, LDAP sync, and brittle MFA handling can take 3-5 days.
A realistic enterprise with 180 applications often sees:
- 40% of onboarding effort spent on application discovery and owner chasing
- 25% on protocol translation and claim mapping
- 20% on testing and rollback planning
- 15% on change management and documentation
If your target is 50 apps in year one, budget for 300-600 engineering hours before you count business approvals.
2. Migration is a project, not a toggle
Moving from one IdP to another, or consolidating directories, is where costs multiply. You may need to migrate password hashes, re-enrol MFA, reissue tokens, or rebuild federation trust.
Example: a healthcare provider with 28,000 staff moved from a legacy AD FS setup to a cloud IdP in 2026. Licence spend was $310,000 per year. Migration services, test automation, and cutover support cost $1.1 million. The cutover itself lasted 11 hours, but the preparation consumed 14 weeks.
3. Governance and policy design consume senior time
Identity is not just plumbing. You need policy decisions on joiner/mover/leaver flows, privileged access, access reviews, and exception handling.
A good access model usually requires:
- role engineering workshops
- entitlement rationalisation
- SoD rule design
- approval workflow mapping
- audit evidence design
Expect architects, security leads, HR, and application owners to spend real time here. If you ignore that time, the programme looks cheap until the first audit.
4. Operations and support never stop
Once identity is live, the cost shifts to run-state work: failed logins, lockouts, token issues, app onboarding, access recertification, and incident response.
A mature identity team supporting 20,000 users often handles:
- 120-250 identity tickets per week
- 8-15 privileged access requests per day
- 1-3 federation incidents per month
- quarterly certification campaigns that create a temporary 2-4x workload spike
If you do not budget for steady-state operations, your programme will steal time from platform engineering and security teams.
Build a cost model that reflects reality, not procurement
The fastest way to underbudget identity is to treat it like a software purchase. It is a programme with software inside it.
Use five cost buckets
Model the programme in five buckets:
- Licences and subscriptions
- Implementation and integration
- Migration and cutover
- Operations and support
- Governance, training, and change management
A practical split for a mid-sized enterprise in 2026 often looks like this:
- Licences: 15-30%
- Implementation: 25-35%
- Migration: 10-20%
- Operations: 20-30%
- Governance and change: 10-15%
If licences are more than 40% of the total, you are probably missing labour, or you have a very narrow pilot.
Example budget model
Here is a simple way to frame the numbers for a 15,000-user rollout with 60 applications:
Licences: $260,000
Implementation partner: $420,000
Internal engineering: $310,000
Migration and testing: $290,000
Governance and training: $120,000
Operations year one: $240,000
-------------------------------------
Total: $1,640,000
That model is not exaggerated. It is often conservative if you include legacy app remediation or privileged access management.
Cost per app matters more than total app count
A useful benchmark is cost per onboarded application. In 2026, enterprises commonly see:
- $2,500-$7,500 for a straightforward SaaS app
- $8,000-$25,000 for a moderately complex internal app
- $30,000+ for a legacy app needing custom work
That is why a 60-app programme can cost less than a 25-app programme if the 25 apps are ancient and fragile.
How to estimate licence spend without fooling yourself
Licence costs still matter. They just do not explain the whole programme.
Count the right identities
Do not price only employees. Include:
- contractors
- partners and suppliers
- service accounts
- workload identities
- admin accounts
- B2B guest users
A manufacturing company in 2026 had 18,400 employees but 41,000 total identities once machines, APIs, and external collaborators were counted. Their initial licence model was off by 37% because it ignored non-human identities.
Watch the pricing unit
Identity vendors may price by:
- monthly active user
- total directory object
- authentication volume
- privileged account
- API call volume
- tenant or environment
The cheapest-looking contract can become expensive if your growth pattern does not match the pricing unit. If your partner ecosystem is expanding 30% year over year, per-guest pricing can outgrow a flat enterprise tier very quickly.
Model three scenarios
Use low, expected, and high adoption cases.
scenario_model:
users:
low: 12000
expected: 18000
high: 26000
apps_onboarded:
low: 25
expected: 60
high: 95
annual_license_cost_usd:
low: 180000
expected: 310000
high: 520000
implementation_cost_usd:
low: 450000
expected: 780000
high: 1250000
This prevents the classic mistake of budgeting for pilot scale and calling it enterprise-ready.
A practical architecture approach that lowers total cost
The cheapest identity programme is not the one with the lowest licence fee. It is the one with the fewest exceptions.
Standardise around a small set of patterns
In 2026, most enterprises lower cost by standardising on:
- OIDC for modern apps
- SAML only where needed for legacy SaaS
- SCIM for provisioning
- passwordless authentication for workforce access where risk allows
- just-in-time privileged access for admin roles
Every extra pattern adds support burden. A mixed estate with OIDC, SAML, LDAP, RADIUS, and custom headers costs more to operate than one with three standard patterns.
Architecture sketch
[HR System] ---> [Identity Governance] ---> [IdP] ---> [Apps]
| | | |
| | | +--> SaaS via OIDC/SAML
| | +-------------> PAM / admin access
| +-------------------------------> Provisioning via SCIM
+--------------------------------------------------> Joiner/Mover/Leaver events
This kind of architecture reduces manual account creation, shortens onboarding time, and cuts ticket volume. One global logistics firm reduced access-related tickets by 41% after moving HR-driven provisioning to SCIM for 38 apps.
Measure the operational payoff
Identity cost should be compared against measurable savings:
- password reset tickets down 30-60%
- onboarding time reduced from days to hours
- access review effort reduced by 25-50%
- privileged access audit prep reduced by 40%+
If the programme cannot show those outcomes, the business case is weak no matter how attractive the licence discount looks.
Common Pitfalls
The same budgeting mistakes keep repeating because teams focus on procurement instead of delivery.
Pitfall 1: Treating implementation as a fixed fee
A fixed-fee statement of work often excludes app remediation, stakeholder delays, and test cycles. Ask what happens when an app owner is unavailable for three weeks.
Avoid it: Require a work breakdown structure with assumptions, exclusions, and change-order triggers.
Pitfall 2: Ignoring legacy authentication debt
Old apps often need password sync, agent deployment, or custom federation. Those costs are real and usually non-trivial.
Avoid it: Inventory auth methods before you sign the contract. Count LDAP, Kerberos, RADIUS, header-based SSO, and local accounts.
Pitfall 3: Underfunding operations
Identity is a service, not a one-time project. If you cut the run budget, the platform degrades quickly.
Avoid it: Reserve at least 20% of total programme spend for year-one operations and support.
Pitfall 4: Forgetting non-human identities
Service accounts and workloads often outnumber humans. They also create security exposure if unmanaged.
Avoid it: Include machine identities in scope from day one and assign ownership.
Pitfall 5: Buying features you cannot absorb
Some teams pay for advanced governance, risk scoring, or AI-driven recommendations before they have clean entitlement data.
Avoid it: Sequence capability adoption. Start with provisioning, authentication, and access reviews before advanced analytics.
A simple way to defend the budget in front of finance
Finance teams do not need identity jargon. They need a defensible model tied to risk and labour.
Use this structure:
-
Baseline the current cost
- help desk tickets
- manual provisioning time
- audit preparation hours
- incident response time
-
Estimate the future state
- fewer tickets
- faster onboarding
- lower audit effort
- lower privileged access risk
-
Show payback by category
- productivity gain
- risk reduction
- compliance efficiency
- platform consolidation
A European financial services firm built this model in 2026 and found that identity automation saved 11,400 labour hours annually. At a blended cost of $68/hour, that was $775,200 in recoverable time, before counting risk reduction.
If your model only says "licences cost $300,000," finance will push back. If it says "total cost is $1.6 million and we remove $775,200 in annual labour plus audit drag," the conversation changes.
Key Takeaways
- Treat identity as a programme, not a software purchase; licences are usually the smallest cost bucket.
- Budget explicitly for integration, migration, governance, and operations, not just subscriptions.
- Model cost per app and cost per identity type, including contractors, partners, service accounts, and workloads.
- Standardise on fewer auth patterns to reduce support and engineering overhead.
- Keep at least 20% of year-one spend for run-state operations and support.
- Defend the business case with labour savings, audit reduction, and ticket deflection, not licence discounts alone.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Written by
Nesqual Tech AI
Nesqual Tech
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI