Skip to main content
Has your work email already leaked?Run the 10-second check
SOC cost for MSPs

What a SOC costs an MSP
in six variables.

No price on this page, and no range either. What is here is the set of inputs that actually move the figure, so you can model your own before asking anyone to quote it.

SOC cost for an MSP is driven by six inputs: endpoints and identities in scope, log volume, retention period, response mandate, coverage hours, and onboarding effort. Endpoint count anchors most estimates but log volume and retention usually decide the bill. Model those six and the plausible range narrows before you speak to any provider.

The six drivers

In rough order of impact.

01
Endpoints and identities in scope

The headline variable, and the one everyone counts first. Identities matter as much as machines now, because that is where intrusions progress, and estates often have far more identities than they assume once service accounts are included.

02
Log volume

How much telemetry the estate actually produces, which correlates poorly with its size. Chatty cloud infrastructure and verbose applications generate more than large fleets of quiet laptops. This is the input most likely to be underestimated.

03
Retention

How long searchable history is kept. It determines whether an investigation can reconstruct what happened or has to guess. Regulated clients usually have a floor, and that floor is a cost input rather than a preference.

04
Response mandate

Whether the provider notifies, recommends, or acts. Pre-authorized containment costs more to supply than alerting, and it is the difference between an incident that ends overnight and one that waits for your morning.

05
Coverage hours

Business hours, extended hours, or genuinely continuous. The last one is the expensive one and the only one that matches when intrusions actually happen. Partial coverage is cheaper in the way a night shift with nobody on it is cheaper.

06
Onboarding and tuning

Connecting sources and tuning detections to an environment is real effort, charged or absorbed. A provider who absorbs it has priced it somewhere, and a provider who charges it separately is at least being explicit.

Build versus buy

Assemble the comparison honestly.

Most build-versus-buy models understate building. If you are running the numbers, these are the lines that usually go missing.

Three shifts, not three people

Continuous coverage means rotas, holiday cover and sickness cover. A team small enough to be affordable is a team too small to be continuous.

Detection engineering

Content has to be written, tuned and maintained as the estate and the threat landscape change. It is a standing function, not a setup task.

Recruitment and attrition

Analysts are scarce and mobile. The cost of replacing one, and of the coverage gap while the seat is empty, belongs in the model.

Platform and retention

Licensing, storage and the ingest cost of the telemetry you decided to keep. This scales with the estate whichever way you go.

Escalation depth

Who handles the incident the tier-one analyst cannot. Either you employ that person or you buy access to them.

The cost of partial coverage

The hardest line to price and the one that matters: what an incident costs when it lands in a window nobody was watching.

A method

How to model it yourself.

No figures here, because yours will not match anyone else's. What follows is the order to work in, so that when you do get quotes you can tell whether they are comparable.

01
Count the estate properly

Endpoints, then identities including service accounts, then anything with a control plane. Most estates have considerably more identities than machines, and the gap is where the surprise sits.

02
Estimate telemetry, not headcount

Ask your existing tooling what it ingests per day. If you cannot answer that, you cannot compare per-gigabyte quotes to per-endpoint ones, and the two will look wildly different for no visible reason.

03
Fix the retention requirement first

Start from what regulated clients contractually need, not from what feels affordable. Retention set below the investigation horizon saves money and removes the ability to answer questions later.

04
Decide the response mandate

Notification, recommendation or action. Write down which actions may happen without a call. This single decision changes both the price and what the service is worth on a bad night.

05
Price the coverage you actually want

Continuous costs more than business hours because it requires rotas rather than goodwill. Compare like for like, and be suspicious of continuous coverage priced close to office hours.

06
Add onboarding once, per client

It is real effort whether it appears as a line item or is absorbed into the rate. A quote that omits it entirely has either priced it invisibly or has not thought about it.

07
Then compare quotes on scope, not headline

Two numbers are only comparable once the six inputs above match. Most of the spread between proposals turns out to be scope rather than margin.

Common questions.

How much does a SOC cost for an MSP?

There is no single number, because the inputs differ by an order of magnitude between practices. The honest answer is that cost is driven by how many endpoints and identities are in scope, how much log data they generate, how long it is retained, how far the provider is permitted to go on response, and whether coverage is business hours or genuinely continuous. Model those five and the range narrows quickly.

Why do providers not publish a price?

Some do, usually per endpoint, and it is worth reading what that figure excludes. Where rates sit behind verification it is normally because the commercial model is built for partners to mark up, and publishing partner rates undercuts the partners selling on them. Either way the published number is rarely the number, because scope moves it.

What are the common pricing models?

Per endpoint is the most common and the easiest to forecast. Per user or per identity suits estates where people outnumber machines. Per gigabyte of ingested data shows up wherever a SIEM is central, and is the model most likely to surprise you. Flat platform fees plus a variable component are common at the larger end. Each is defensible; each hides different costs.

What is the most common budgeting mistake?

Modelling on endpoint count alone. Endpoints are visible and easy to count, so they anchor the estimate, while log volume and retention quietly drive the bill. A client with modest endpoint numbers and chatty cloud infrastructure can cost more to monitor than one with far more machines.

Does data retention really move the number that much?

Yes, and it is worth deciding deliberately rather than accepting a default. Retention is what makes investigation possible after the fact, so cutting it to save money removes the ability to answer the questions an incident raises. Regulated clients often have a required minimum, which sets a floor regardless of preference.

How should I price this to my clients?

That is your decision and the SOC does not have a view on it. What partners typically model is a per-seat or per-endpoint security line item priced to cover the service plus the account handling it creates, rather than passing through at cost. The service is built to be marked up.

What hidden costs should I look for?

Onboarding and tuning effort, which is real work whoever performs it. Charges for adding sources beyond the initial scope. Data egress or extended retention as a separate line. Whether incident response beyond containment is included or billed. And the internal time your team spends on whatever the provider hands back rather than resolves.

Is it cheaper to build a SOC in-house?

Rarely, below a certain scale, once the cost is honestly assembled. Continuous coverage means three shifts, not three people, and that is before detection engineering, platform licensing and the recruitment cost of replacing analysts who leave. The comparison also tends to omit what partial coverage costs when an incident lands outside it.

Does the cost scale linearly as I add clients?

Roughly, on the variable inputs, which is the point of buying rather than building. Fixed costs sit with the provider, so adding a client adds their endpoints and their data rather than a step change in your staffing. That is what makes the line item predictable against the book.

How do I get an actual figure?

The pricing path is self-service and does not require a call. It asks about your practice and the shape of your estate, verifies you are a partner, and shows rates. If your situation is unusual enough that the wizard cannot place it, it routes to somebody who can scope it properly.

Next step

See the actual rates.
Without a sales call.

The pricing path is self-service. It asks about your practice, verifies you are a partner, and shows rates. Nothing to book.