Join our Newsletter — 33% off our NHI Course

Run Spend

Run spend is the budget needed to keep existing operations functioning day to day. In identity programmes, it covers recurring control work such as access reviews, renewals and administrative maintenance that must continue even when no new technology is being introduced.

What Run Spend Means in Practice

Run spend is the recurring budget that keeps current operations functioning. It is the cost of steady-state work, not new investment, and in identity programmes it often includes the ongoing effort needed to keep access controls accurate and usable.

How Run Spend Differs from Change Spend

Run spend supports continuity: keeping the lights on, preserving service quality, and maintaining controls that must be repeated over time. Change spend funds new capabilities, transformations, or redesigns. The distinction matters because organisations often understate run spend while still expecting the same control coverage and operational reliability.

In security and identity operations, the line between the two can blur. A one-time system rollout may create a lasting obligation for reviews, renewals, exception handling, and administrative upkeep, so the budget impact does not stop when implementation ends.

Why Run Spend Matters for Control Maintenance

Recurring control work is often the least visible part of a security programme, but it is what makes governance sustainable. Access recertification, account renewal, credential upkeep, policy exceptions, and administrative overhead all consume run spend because they must happen continuously rather than only during a project.

When run spend is not explicitly planned, controls tend to degrade into manual shortcuts, deferred reviews, or incomplete ownership. That creates a gap between the written control design and the actual operating model, which is where many programmes lose effectiveness.

Budgeting Run Spend for Operational Stability

A useful way to think about run spend is to treat it as the cost of preserving a known security baseline. That includes the people, process, and tooling needed to operate existing controls at their expected cadence, absorb normal exceptions, and keep administrative work from becoming backlog.

For identity-heavy environments, run spend is not optional overhead. It is part of the control architecture itself, because ongoing maintenance is what keeps entitlements current, access decisions defensible, and recurring administrative work from accumulating into operational risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.PO-01 — Cybersecurity Policy Run spend is a budgeting and governance issue for sustaining ongoing security operations.
Recommendation — Budget recurring control operations as a governed part of the cybersecurity programme.
NIST SP 800-53 Rev 5 PM-3 — Information Security Resources Run spend directly concerns the resources required to operate and maintain security controls over time.
Recommendation — Allocate recurring resources to sustain control operation and maintenance.
ISO/IEC 27001:2022 A.5.36 — Compliance with policies, rules and standards for information security Run spend supports the continuing effort needed to keep controls aligned with policy and standards.
Recommendation — Fund the ongoing work needed to keep security controls operating in line with policy.