
Email encryption cost for a small business depends first on which Microsoft 365 plan you already pay for, because Microsoft Purview Message Encryption is included in some plans and absent from others, and second on whether a regulator, a customer or a counterparty pushes you toward a third-party gateway or certificate-based encryption on top. For many businesses the license cost is already covered, and the real spend is the configuration, the rules that make encryption happen automatically, and the support that follows. NetSys implements email encryption per business and quotes it after looking at the tenant, month to month. This guide explains what is included where, what a gateway adds, and what to budget beyond the license.
Is email encryption already included in Microsoft 365?
| Option | What it does | What it costs |
|---|---|---|
| Transport encryption (TLS) | Protects mail between servers in transit | Included with every plan; it is connection protection, not message protection |
| Microsoft Purview Message Encryption | Encrypts individual messages and attachments; recipients on any email service can open them | Included with Business Premium and the enterprise E3 and E5 suites; an add-on for Business Basic and Business Standard |
| Sensitivity labels | Users or rules tag mail and files as confidential, applying encryption and restrictions | Included with the same plans; the cost is configuration and training |
| Data loss prevention rules | Detect account numbers, patient identifiers or Social Security numbers and encrypt automatically | Included with Business Premium and the enterprise suites; the cost is tuning |
| S/MIME | Certificate-based encryption and signing for counterparties that require it | Certificates per user, plus setup labor |
| Third-party encryption gateway | A separate service that encrypts, hosts a recipient portal and adds its own policies | Per user per month, plus integration |
Microsoft's licensing documentation is the source for which plans include which feature, and it changes, so confirm against the current page before budgeting. The pattern has held for several years: Business Premium and the enterprise suites carry message encryption and the information protection features around it; the lower business plans do not without an add-on.
What does message encryption in Microsoft 365 do, and where does it fall short?
Purview Message Encryption protects a message and its attachments so that only the intended recipient can read them, and it works for recipients on Gmail, Yahoo or any other service, who open the mail through a secure link or, if they use Outlook with a Microsoft account, in place. It can be triggered by the sender choosing an option in Outlook, by a sensitivity label, or automatically by a mail flow or DLP rule that spots sensitive content. For most small businesses that covers the compliance requirement and the customer expectation at no additional license cost.
Where it falls short is at the edges. Some counterparties, particularly in government contracting and parts of financial services, require S/MIME with certificates they can verify. Some regulated firms want a branded recipient portal, message recall, expiry and audit trails beyond what Microsoft provides. Some businesses run mail systems other than Microsoft 365. Those cases are what third-party gateways and certificates exist for, and they are where cost climbs.
When does a third-party email encryption gateway make sense?
An encryption gateway sits in the mail path and applies its own policies, portal and reporting. Vendors price it per user per month, usually as part of a broader email security bundle, and their public pricing pages are where current figures live. It makes sense when a regulator or a large customer dictates specific features, when the business needs one encryption experience across several mail platforms, or when the existing email security provider bundles encryption cheaply enough that the tenant-native route is more work than it is worth.
It costs more than the tenant-native route in three ways: the subscription itself, the integration work to route mail through the gateway without breaking authentication (SPF, DKIM and DMARC records have to be updated, as our email authentication FAQ explains), and the second administration console someone has to learn and watch. For a firm already on Business Premium with no counterparty demanding otherwise, the gateway is usually a duplicate purchase.
What compliance rules drive the cost?
HIPAA's Security Rule requires covered entities and business associates to address encryption of electronic protected health information in transit, and unencrypted email of patient details is a hard position to defend in an investigation. The FTC Safeguards Rule requires encryption of customer information in transit and at rest for the financial institutions it covers, which include auto dealers, mortgage brokers and tax preparers. New York's Department of Financial Services regulation requires encryption of nonpublic information in transit for covered entities, and the state's SHIELD Act expects reasonable safeguards for private information.
Each of those turns encryption from optional into required, and each adds a documentation requirement: policies that say when mail is encrypted, rules that make it happen, and evidence that the rules work. The documentation is the part most businesses under-budget. It is also what an insurer or an auditor asks for, and it is included in how NetSys sets encryption up, described on our HIPAA compliance and FTC Safeguards Rule pages.
What does setup cost, and what is the ongoing work?
Setup is labor: deciding which content must be encrypted, building the DLP and mail flow rules that detect it, configuring labels and the recipient experience, branding the portal, testing with real external recipients, and writing the policy. A small tenant with one or two content types (patient identifiers, account numbers) is a short project. A firm with many departments, several data types and counterparties requiring S/MIME is a longer one.
Ongoing work is smaller and never zero. DLP rules produce false positives that need tuning. New staff need to know how it works. Recipients who cannot open a message call your help desk, not Microsoft. Certificates expire. Rules need a review when a regulation changes. In a managed agreement this sits inside Microsoft 365 management; as a standalone project it should be budgeted as a few hours a quarter.
What hidden costs show up after rollout?
- Help desk volume. The first month generates calls from recipients and staff. Budget support time, and send a short note to frequent external contacts before switching rules on.
- Over-encryption. Rules tuned too broadly encrypt routine mail, and staff start working around them. Tuning is cheaper than the workaround.
- Secure file exchange. Large attachments and shared folders need a companion answer in SharePoint or OneDrive with sensitivity labels, or the encryption rule becomes a reason to use personal email.
- Retention and discovery. Encrypted mail must remain searchable for legal hold and records requests; confirm it is before an auditor asks.
- Mobile devices. Reading protected mail on phones depends on the Outlook app and device management, which is its own line.
Frequently asked questions
How much does email encryption cost for a small business?
For a business on Microsoft 365 Business Premium or an enterprise suite, the encryption license is already paid for, and the cost is the setup and the ongoing tuning, which NetSys quotes per business, month to month. Businesses on Business Basic or Business Standard pay for an add-on or upgrade the seats that send sensitive mail. Third-party gateways and S/MIME certificates add per-user subscription and certificate costs published by their vendors, and are worth buying only when a rule or a counterparty requires them.
Is Microsoft 365 email encrypted by default?
In transit between servers, yes: Microsoft 365 uses TLS whenever the receiving server supports it, which covers most mail. That protects the connection, not the message. A message forwarded, misdelivered or opened on a compromised account is readable. Message-level encryption, through Purview Message Encryption, a sensitivity label or an automatic rule, is what protects the content itself and what regulators mean when they ask whether email is encrypted.
Do we need email encryption for HIPAA?
If your practice or business emails protected health information, treat it as required. The Security Rule lists encryption as an addressable safeguard, meaning you must implement it or document why an equivalent measure is reasonable, and investigators rarely accept the second answer for email. The practical approach is an automatic rule that detects patient identifiers and encrypts, so compliance does not depend on a busy front desk remembering. Our HIPAA IT checklist covers the surrounding controls.
Can recipients without Microsoft 365 open encrypted email?
Yes. Purview Message Encryption sends recipients on other services a secure link, and they read the message in a browser after signing in with their own account or a one-time passcode. Outlook users on Microsoft 365 open it in place. The experience is the main source of first-week support calls, so testing with a few real external contacts before rollout, and giving them a short heads-up, saves the help desk hours.
Getting encryption set up with NetSys
NetSys configures email encryption in Microsoft 365 so that it happens automatically, tests it with real recipients, and documents it for HIPAA, FTC Safeguards, NY DFS and cyber insurance reviews, quoted per business and delivered month to month. See our email encryption page, and for the plainer questions owners ask first, our email encryption FAQ. The data loss prevention page covers the rules that make encryption automatic.
Sources and further reading
- Microsoft Purview Message Encryption, Microsoft's documentation including plan availability.
- HIPAA Security Rule.
- FTC Safeguards Rule: What Your Business Needs to Know.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



