Skip to content

Total Cost of Ownership

What this is and who it’s for

This runbook shows you how to calculate the real multi-year cost of a system — not the year-one sticker price or the contract value on the page in front of you. It’s for the agency CIO, senior tech lead, or budget owner who is about to commit to a build or a vendor and wants the number that survives five years of operation. The core message is simple: decisions made on year-one cost are usually wrong, because year one is the cheapest year a system will ever have. Decide on total cost of ownership (TCO) instead. This is the costing engine behind Build vs. Buy and the Modernization Roadmap; both consume the model you build here.

Prerequisites

  • A defined option or scope to cost. TCO compares concrete options (“build it on our existing platform” vs. “license Vendor X”); it cannot cost a vague intention. Define the scope first.
  • You have read Build vs. Buy if this costing feeds a build/buy decision. That runbook frames the decision; this one supplies the numbers.
  • You have a five-year planning horizon in mind. If your decision only looks at the current contract term, you will miss the costs that matter most.

The practice

Build a five-year cost model for each option, summing every recurring and one-time cost across all five years, then compare the totals — not the year-one figures. The work is in finding the costs that get left out, putting them on a multi-year timeline, and presenting the result in a form a budget owner trusts. The sections below walk that in order: the cost categories people miss, the time horizon, one-time vs. recurring, the cost of doing nothing, the apples-to-apples comparison, and the conversation with finance.

The cost categories that get missed

Most cost estimates capture the acquisition or license line and stop. The categories below are the ones that turn a “cheap” option into the expensive one by year three. Cost each of them, for each option, across all five years.

Acquisition / build cost

The upfront price to obtain the system. For buy, this is the initial license, setup fees, and any first-year platform charges. For build, this is the engineering effort to ship the first working version — fully loaded staff cost, not just contractor day rates. This is the only cost most estimates capture well, and it is usually the smallest line in the five-year total.

Implementation & integration

The work to make the system usable in your environment: data migration, integration with existing agency systems, identity and single sign-on wiring, and configuration. This is frequently larger than the acquisition cost and is almost always underestimated. A “Xlicense"with"X license" with "3X integration” is common and routinely missed.

Licensing & subscription growth (scaling cost)

The recurring fee, and critically, how it scales. Per-seat, per-monthly-active-user (MAU), and consumption-based pricing all grow with usage — the year-one quote assumes year-one volume. Model the fee at year-five usage, not today’s. A per-seat tool that is affordable for a pilot can become the largest line in the model once the whole agency is on it.

Hosting & infrastructure

Compute, storage, network, and managed-service charges to run the system. For cloud-hosted builds this is a direct recurring bill that scales with load; for SaaS it may be bundled into the subscription, in which case note that explicitly so the comparison is fair. Include non-production environments (staging, test) and backup/disaster-recovery capacity.

Operations, support & maintenance

Keeping the system running after launch: monitoring, incident response, patching, dependency upgrades, and vendor support contracts. For a build, this is the team that owns the system in perpetuity. For a buy, this is the premium-support tier plus the internal staff who manage the relationship and the integrations.

Security & compliance

The recurring cost of staying authorized and audit-ready: the Authority to Operate (ATO) effort, vulnerability scanning, penetration testing, security tooling, and the staff time to respond to findings and pass audits. State systems carry continuous compliance obligations, so this is recurring, not one-time. A build inherits the full ATO burden; a buy may inherit some of it through the vendor’s existing authorizations — verify which.

Staffing & training

The people cost: hiring or reallocating staff to operate the system, plus training existing staff and end users. Include onboarding for new operators over the five years as turnover happens. Training is not a one-time launch event — it recurs with every staffing change and major version.

Exit & migration cost

The cost to leave: extracting your data, migrating to a replacement, and decommissioning. This is the line that makes vendor lock-in visible. If it is expensive or technically hard to leave, that constraint is a real cost even if you never exercise it — it caps your future leverage and your ability to change. Estimate it; do not leave it blank.

The time value across a five-year horizon

A cost in year five is not worth the same as a cost in year one, and a five-year view changes which option wins. Lay every cost on a year-by-year timeline (Year 1 through Year 5) rather than collapsing it to a single number, so growth and timing are visible. Apply your jurisdiction’s standard discount rate if finance requires net-present-value figures [VERIFY: Maryland / agency standard discount rate]. Even without discounting, the year-by-year view exposes the option whose costs balloon after the introductory term ends.

One-time vs. recurring costs

Separate the two explicitly in your model, because they behave differently in a budget and in a comparison.

One-time costs

Costs incurred once: initial build effort, implementation and integration, initial data migration, and exit cost at end of life. These hit a single year and do not repeat. They dominate year one and can mislead a reader who only looks at the first column.

Recurring costs

Costs incurred every year: licensing and subscription, hosting, operations and support, security and compliance, and ongoing training. These compound across the horizon and usually decide the five-year total. An option with a low one-time cost and high recurring cost loses to the reverse over five years — which is exactly why year-one comparisons mislead.

The cost of not modernizing

The baseline option is rarely “spend nothing” — it is “keep carrying the legacy system,” and that carries its own cost. Put it in the model as its own column so the comparison is honest. Carrying legacy means accumulating risk: rising breach exposure on unpatched software, growing maintenance cost on aging dependencies, and the opportunity cost of being unable to change the system when the mission changes. A breach, an outage, or a mandate the legacy system cannot meet are real and often large costs that belong in this baseline. “Do nothing” is a decision with a price tag; cost it like any other option.

Building an apples-to-apples comparison

Cost every option against the same scope, the same horizon, the same usage assumptions, and the same category list — so the only thing that differs is the option. This is the engine behind Build vs. Buy: the decision is sound only when the alternatives are costed identically. Where one option bundles a cost that another itemizes (hosting inside a SaaS subscription, say), note it so a reviewer does not read a bundled line as a missing line. The reference implementation below gives you the side-by-side structure.

Presenting TCO to budget and finance audiences

Lead with the five-year total per option and the recommendation; put the year-by-year detail underneath for the reader who wants it. Finance audiences trust a model they can interrogate, so show the category breakdown and state every assumption (usage growth, rates, discount rate) in plain text beside the numbers. Name the recurring commitment explicitly — a multi-year subscription is a multi-year budget line, and state appropriations cycles may not let you commit beyond the current cycle without specific authority [VERIFY: Maryland budget cycle and multi-year commitment authority]. Frame the cost of doing nothing as a number too, so the recommendation is a comparison of priced options rather than a request for new spend.

Reference implementation

Fork this five-year TCO model. Replace every number — the figures below are illustrative placeholders to show the structure, not real Maryland figures. Cost two options side by side against the same scope, then compare the totals row, not the Year 1 row.

FIVE-YEAR TCO MODEL — ILLUSTRATIVE PLACEHOLDER NUMBERS ONLY (NOT REAL)
Scope: [FILL IN: the defined system/scope being costed]
Usage assumption: [FILL IN: e.g. 200 seats yr1 growing to 800 by yr5]
Discount rate applied: [VERIFY: rate, or "none — nominal dollars"]
OPTION A — Buy (per-seat SaaS)
| Cost category | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 | Total |
|---------------------------|---------|---------|---------|---------|---------|---------|
| Acquisition / license | 50,000 | 55,000 | 66,000 | 79,000 | 95,000 | 345,000 |
| Implementation & integ. | 120,000 | 0 | 0 | 0 | 0 | 120,000 |
| Hosting & infra (bundled) | 0 | 0 | 0 | 0 | 0 | 0 |
| Operations & support | 30,000 | 31,000 | 32,000 | 33,000 | 34,000 | 160,000 |
| Security & compliance | 40,000 | 20,000 | 20,000 | 20,000 | 20,000 | 120,000 |
| Staffing & training | 25,000 | 10,000 | 10,000 | 12,000 | 12,000 | 69,000 |
| Exit & migration cost | 0 | 0 | 0 | 0 | 60,000 | 60,000 |
| Option A total | 265,000 | 116,000 | 128,000 | 144,000 | 216,000 | 874,000 |
OPTION B — Build (on existing platform)
| Cost category | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 | Total |
|-------------------------|---------|---------|---------|---------|---------|-----------|
| Build (initial effort) | 300,000 | 0 | 0 | 0 | 0 | 300,000 |
| Implementation & integ. | 80,000 | 0 | 0 | 0 | 0 | 80,000 |
| Hosting & infra | 36,000 | 40,000 | 44,000 | 48,000 | 52,000 | 220,000 |
| Operations & support | 90,000 | 95,000 | 100,000 | 105,000 | 110,000 | 500,000 |
| Security & compliance | 60,000 | 30,000 | 30,000 | 30,000 | 30,000 | 180,000 |
| Staffing & training | 40,000 | 20,000 | 20,000 | 22,000 | 22,000 | 124,000 |
| Exit & migration cost | 0 | 0 | 0 | 0 | 20,000 | 20,000 |
| Option B total | 606,000 | 185,000 | 194,000 | 205,000 | 234,000 | 1,424,000 |
BASELINE — Do nothing (carry legacy)
| Cost category | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 | Total |
|------------------------|---------|---------|---------|---------|---------|-----------|
| Maintenance (rising) | 80,000 | 95,000 | 115,000 | 140,000 | 170,000 | 600,000 |
| Risk / breach exposure* | 50,000 | 60,000 | 75,000 | 95,000 | 120,000 | 400,000 |
| Opportunity cost* | 40,000 | 50,000 | 60,000 | 70,000 | 80,000 | 300,000 |
| Baseline total | 170,000 | 205,000 | 250,000 | 305,000 | 370,000 | 1,300,000 |
* Risk and opportunity costs are estimated expected values — state the
method beside them so finance can challenge the assumption.
READ THE TOTAL COLUMN, NOT YEAR 1. Option A is cheapest in year 1
(265k) but the comparison decision is made on the five-year total.

Use this checklist of commonly-missed costs to audit any model before you present it:

### Commonly-missed cost checklist
Confirm each line is present (or N/A) per option.
- [ ] Implementation & integration (often larger than acquisition)
- [ ] Scaling cost modeled at YEAR-5 usage, not year-1 (per-seat / per-MAU / consumption)
- [ ] Hosting & infrastructure, including non-prod and DR/backup
- [ ] Operations, support & maintenance for all five years
- [ ] Security & compliance: ATO, scanning, pen test, audit response (recurring)
- [ ] Internal staffing line (not just contractor/vendor cost)
- [ ] Training as recurring, covering turnover and major versions
- [ ] Exit & migration cost (makes lock-in visible — never leave blank)
- [ ] "Do nothing" baseline costed as its own column
- [ ] Build operations costed for the FULL horizon (you own it forever)
- [ ] Bundled costs noted where one option itemizes what another bundles

Common pitfalls

  • The decision is made on the year-one or license sticker price. If the winning option is the one with the smallest first-year number, the model wasn’t used. Compare the five-year totals; year one is the cheapest year every system has.
  • Scaling cost is ignored. A per-seat, per-MAU, or consumption price quoted at pilot volume balloons at full rollout. Model the fee at year-five usage; if you can’t, flag the model as incomplete.
  • Exit and migration cost is left blank, so lock-in is invisible. A missing exit line reads as “free to leave,” which is never true. Estimate it — the number is the price of your lock-in and a real input to the decision.
  • There’s no line for internal staffing or operations. Vendor and contractor costs are easy to find; the agency staff who run, integrate, and support the system are easy to forget. Add the internal people line for every option, including buy.
  • The cost of doing nothing is omitted. Without a “carry legacy” baseline, every option looks like new spend rather than a comparison. Cost the baseline — rising maintenance, risk, and opportunity cost — as its own column.
  • A build’s cost is treated as one-time. “We’ll build it once” ignores that you operate, patch, secure, and staff it for as long as you run it. Cost a build’s operations across the full horizon; you own it forever.

Procurement notes

TCO should drive both the Statement of Work and the evaluation criteria — not just the budget request. Require bidders to quote against your five-year usage assumptions and your full category list, including scaling, support, security, and exit terms, so bids are comparable on TCO rather than on year-one license price. Build the cost-category list and the year-five usage assumption into the SOW directly; see How to Write a Good SOW for the language and structure. Score evaluations on five-year TCO, and require the exit/data-portability terms to be priced and contractual so lock-in is bounded. Confirm your authority to commit to a multi-year subscription within the appropriations cycle before signing [VERIFY: Maryland budget cycle and multi-year commitment authority].

Maintenance

Owner: [FILL IN: runbook owner] · Last reviewed: 2026-05-31 · Next review: 2026-08-31