We use cookies to understand how the site is used and to improve your experience. Privacy policy

    Skip to main content

    6 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)

    SOC as a Service and MSSP Pricing: The Eight Things That Drive the Cost

    Managed security quotes come in three pricing models and arrive with very different totals for what looks like the same service. This guide explains the models, the drivers behind the number, and the line items that only show up after you sign. No price list from us; every programme is scoped individually.

    The three pricing models

    Managed security is sold per asset, per data or per control. Per asset means a monthly fee per endpoint, server, user or identity, which is how most MDR services are priced. Per data means a fee based on log volume or events per second ingested into the SIEM, which is how most SOC as a service offerings are priced and where cost surprises usually come from. Per control means a fee per managed service: a firewall, an email security platform, a vulnerability management programme, each with its own line. Full MSSP contracts mix all three.

    None of the models is better in the abstract. Per asset is predictable and scales with headcount. Per data is cheaper for small estates and expensive for chatty environments. Per control is transparent but adds up. The right model is the one whose growth variable you can forecast.

    The eight cost drivers

    Every quote is a function of these. Ask how each is counted before you compare totals.

    1. Coverage hours and response commitment

    Business hours monitoring with next-day response and true 24/7 monitoring with a committed containment time are different services at different prices. The response commitment is the single largest driver after scope.

    2. Number of endpoints, identities and users

    The base unit for MDR and most MSSP tiers. Clarify whether servers, workstations, mobile devices, service accounts and cloud identities count the same, and what happens when the count grows mid-contract.

    3. Log volume and sources

    For SIEM-based services, gigabytes per day or events per second ingested, and the number of distinct sources. Firewalls, cloud audit logs and identity providers are the heavy sources. Retention length multiplies the number.

    4. Technology ownership

    A provider that brings its own EDR, SIEM and SOAR bundles the licences into the fee. A provider that manages yours charges less but you pay the vendors. Ask for both versions of the quote.

    5. Threat hunting and detection engineering

    Proactive hunting, custom detection rules for your environment and purple-team validation are either included in a higher tier or sold as add-ons. They are also what separates a service that finds attackers from one that forwards alerts.

    6. Response scope

    Notification only, guided response, or hands-on containment by the provider. Each step up adds analyst time and liability, and each is priced accordingly.

    7. Compliance reporting and evidence

    Reports mapped to ISO 27001, SOC 2, NIS2 or DORA, audit support and attestation letters cost analyst and management time. Cheap tiers give you a dashboard; compliance tiers give you documents an auditor accepts.

    8. Onboarding and integration

    Agent deployment, log source integration, playbook design and tuning are usually a one-time fee. Underestimated onboarding is the most common reason the first invoice does not match the quote.

    Where the hidden line items hide

    Items that often appear after signature. Ask about each one up front.

    Line itemTypical triggerHow to contain it
    Log overageA new source or a verbose firewall pushes you past the ingestion tierCap and alert on volume; agree a per-GB overage rate in the contract
    Incident response beyond containmentA real incident needs forensics, eradication and recoveryAgree an IR retainer or an hourly rate before you need it
    Additional sources or integrationsNew SaaS, new cloud account, new sitePrice list for source types in the contract
    Retention extensionAuditor asks for twelve months of logs, tier includes threeMatch retention to your compliance need from day one
    Custom detection rulesYour environment needs rules the provider's catalogue lacksInclude a quarterly tuning allowance
    Reporting customisationBoard or regulator wants a format the platform does not produceAgree report templates during onboarding
    Exit and data exportYou switch providerExport format, period and cost stated in the contract

    How to compare two managed security quotes

    Normalise both quotes on these before looking at the total.

    • Same coverage hours and the same containment commitment, by severity
    • Same count of endpoints, identities and users, with the same definition of each
    • Same log sources and retention, with the overage rate stated
    • Same response scope: notify, guide or contain
    • Same reporting: which frameworks, which cadence, which deliverables
    • Onboarding fee and timeline stated separately
    • Licences included or excluded, listed per product
    • Exit terms: notice, transition, data export

    What moves the price down without weakening the service

    Three levers work in most environments. Reduce log noise before onboarding, because you pay for every event whether it matters or not. Consolidate identity into one provider, because identity telemetry is both the most valuable and the cheapest source per detection. Start with MDR on endpoints and identities and add SIEM-based SOC coverage only for the sources that produce detections, instead of ingesting everything on day one. What does not work is buying notification-only monitoring to save money: the incident still happens, and now you own the response at the worst possible hour.

    How HackersHub scopes managed security

    We quote per programme, not per catalogue. A scoping session establishes your sources, your responders, your regulatory duties and your growth, and the written proposal states coverage hours, containment commitments by severity, counted units, log sources and retention, licence inclusions, onboarding, reporting and exit terms on one page. The number is built from the drivers above and you can see each of them. No published price list, because the drivers move the number more than any list could capture.

    Frequently asked questions

    Want a quote you can take apart line by line?

    A scoping session gives you a one-page proposal with every cost driver visible. Talk to an expert.