How MSPs can price SOC services without leaving money on the table

How MSPs can price SOC services without leaving money on the table

Loading the Elevenlabs Text to Speech AudioNative Player...

About Author

Mark Duke

Mark Duke is CTO and co-founder of enhanced.io. He designed the company's SOC architecture and oversees all technical delivery.

enhanced.io, the channel-only Open XDR SOCaaS for MSPs

TL;DR

  • There are three main SOC pricing models: per-user, per-endpoint and flat-fee retainer. Each has a different margin profile and a different risk of mispricing.

  • Per-user pricing is the most defensible for MSPs serving SMB clients because it maps directly to how headcount-based costs already work.

  • The margin conversation MSPs avoid is the one that matters most: pricing for value delivered rather than cost incurred.

  • enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. The per-user pricing model is transparent and scales predictably.

  • Modular tiers let you enter at a lower price point and progress to higher-value services as the client relationship develops.

The three most common SOC pricing models (and their tradeoffs)

There are three pricing structures MSPs use for SOC services. Each has different margin characteristics and a different failure mode when applied to the wrong client type.

Per-user pricing assigns a fixed monthly cost per named user in the client environment. The cost input is stable because headcount changes slowly. The revenue input is stable for the same reason. Margin is calculable in advance and consistent at any seat count. For most SMB clients, this is the most operationally simple model to run.

Per-endpoint pricing charges based on device count rather than user count. This is more accurate for environments where the device-to-user ratio is high, such as manufacturing or healthcare environments with workstations, servers and IoT devices alongside relatively few staff. The tradeoff is that device counts change more frequently than headcount, which introduces billing variability and creates scope conversations during renewals.

Flat-fee retainer pricing offers the client a fixed monthly figure regardless of activity or scope. This is appealing as a sales conversation but creates unpredictable margin outcomes. In a low-activity month the margin is strong. In a month with a significant incident requiring analyst hours, the margin compresses. At scale, flat fees require actuarial modeling of expected activity levels to price correctly. Most MSPs do not have that data.

What per-user pricing means for gross margin

The margin model for per-user SOCaaS is straightforward to build. Take the platform cost per user per month. Add estimated delivery overhead per user per month. The sum is the cost floor. Price above that floor by the target margin percentage and the result is the billing rate. That rate applies consistently across all clients on the same service tier.

What this means in practice is that quoting a new client does not require a custom margin calculation. The rate is set, the margin is known, and the only variable is the client's user count. This is the same structure MSPs already use for per-user licensing of Microsoft 365 and RMM tools. Applying it to security removes the pricing uncertainty that makes some MSPs reluctant to quote security services at all.

The question to ask before setting the rate is not "what is the market charging." It is "what does this service cost me per user per month and what margin does the practice require to be sustainable." The answer to the second question is the floor. The market rate is a ceiling check. If the floor exceeds the ceiling, the delivery model needs adjustment before pricing is viable.

What tends to happen when MSPs run this calculation for the first time is that they find they have been pricing below the sustainable margin threshold, not because the product is cheap but because they were anchoring to competitive rates rather than their own unit economics.

How to build modular SOC tiers your clients will pay for

The tier structure that works most consistently is three levels: core detection and monitoring, a mid-tier adding compliance reporting and QBR delivery, and a premium tier adding vCISO access and advanced incident response support. Each tier has a defined scope and a defined price. The sales conversation starts at the entry tier.

Starting at the entry tier reduces the barrier to first engagement. A client who is not yet committed to managed security will approve a core monitoring service before they will approve a full vCISO engagement. Once the client is live and receiving value, moving to the mid-tier is a scope expansion conversation rather than a new sale. The commercial logic of the progression is straightforward: additional capability at each tier justifies additional monthly billing.

enhanced.io's platform supports this structure because the capability is modular. Core detection, compliance reporting, Fractional Security Director access and advanced threat hunting are all available as separate layers. An MSP can start a client on the entry tier and add layers as the relationship matures without changing the underlying platform or renegotiating a new contract.

The pricing conversation MSP owners avoid (and shouldn't)

The conversation most MSP owners avoid is the value-based pricing conversation. The tendency is to price by adding a margin to the cost, then check whether the result looks competitive. The problem with cost-plus pricing for security services is that the cost does not reflect the value. A 24/7 SOC monitoring a 100-user client is providing risk mitigation that the client cannot replicate internally at any comparable cost. Pricing from cost undervalues that.

The question to ask instead is: what is the financial consequence to this client of a breach the SOC would have detected and prevented? For a 100-user professional services firm, a ransomware incident has measurable costs in remediation, downtime, client notification and reputational impact. Against that figure, the monthly SOC fee is a small fraction of the insured risk. The conversation frames security as risk economics rather than a line item in the IT budget.

The framing that tends to move the conversation is: what does a month of 24/7 monitoring cost compared to what one undetected incident costs? The answer makes the pricing straightforward. Clients who have experienced a security incident rarely challenge security pricing. Those who have not yet had an incident are the ones most likely to treat it as a commodity.

What the numbers look like with enhanced.io's model

enhanced.io's per-user pricing is structured to support healthy MSP gross margins at a selling price in the $15 to $25 per user per month range. The cost per user is fixed and predictable. Delivery overhead is estimable from the MSP's existing operational model. The margin is the difference between billing rate and total cost per user.

Free onboarding means the first month is margin-positive. There is no setup cost to recover. At 200 seats billing at $20 per user, that is $4,000 per month in security MRR. At 500 seats at the same rate, it is $10,000. In both cases, the margin profile is set by the billing rate and the platform cost, both of which are known in advance.

The partner program includes a margin modeling tool that runs the calculation with an MSP's specific inputs. The output is a seat-count-to-margin table that makes the pricing decision straightforward before any client conversation is opened.

About enhanced.io

enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. enhanced.io does not sell directly to end clients. The platform connects to the security tools MSPs already run, including SentinelOne, Fortinet, Microsoft 365, ConnectWise and N-able, and adds a vendor-agnostic Open XDR correlation layer above them. A human-led 24/7 SOC monitors, triages and escalates threats across all integrated surfaces. The delivery model is channel-only and white-label: MSP partners deliver enhanced.io’s capabilities under their own brand.

enhanced.io also provides Fractional Security Director services that help MSPs translate security operations into client-facing business narratives, compliance evidence and QBR content. enhanced.io serves MSPs and MSSPs working with organizations in the 10 to 1,000 employee range. The business was built channel-only from day one and has no direct sales motion to end clients.

FAQ

How do MSPs price SOC services for SMB clients?

The starting point is unit economics, not market rates. Calculate platform cost per user per month plus delivery overhead per user per month. Add the target gross margin percentage. The result is the floor price for the entry tier. From there, each tier in the service structure adds defined capability at a defined price increment. Market rates are a ceiling check, not a starting point. Pricing below the sustainable margin threshold is not competitive. It is a path to a practice that does not scale.

What are the benefits of modular SOC services for growing MSSPs?

How can MSPs build recurring revenue from managed security services?

What is per-user pricing for SOCaaS and how does it affect MSP margins?

How does enhanced.io's pricing model compare to traditional MDR pricing?

What is the difference between per-user and per-endpoint SOCaaS pricing?