6 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)
SOC as a Service and MSSP Pricing: The Eight Things That Drive the Cost
Managed security quotes come in three pricing models and arrive with very different totals for what looks like the same service. This guide explains the models, the drivers behind the number, and the line items that only show up after you sign. No price list from us; every programme is scoped individually.
The three pricing models
Managed security is sold per asset, per data or per control. Per asset means a monthly fee per endpoint, server, user or identity, which is how most MDR services are priced. Per data means a fee based on log volume or events per second ingested into the SIEM, which is how most SOC as a service offerings are priced and where cost surprises usually come from. Per control means a fee per managed service: a firewall, an email security platform, a vulnerability management programme, each with its own line. Full MSSP contracts mix all three.
None of the models is better in the abstract. Per asset is predictable and scales with headcount. Per data is cheaper for small estates and expensive for chatty environments. Per control is transparent but adds up. The right model is the one whose growth variable you can forecast.
The eight cost drivers
Every quote is a function of these. Ask how each is counted before you compare totals.
1. Coverage hours and response commitment
Business hours monitoring with next-day response and true 24/7 monitoring with a committed containment time are different services at different prices. The response commitment is the single largest driver after scope.
2. Number of endpoints, identities and users
The base unit for MDR and most MSSP tiers. Clarify whether servers, workstations, mobile devices, service accounts and cloud identities count the same, and what happens when the count grows mid-contract.
3. Log volume and sources
For SIEM-based services, gigabytes per day or events per second ingested, and the number of distinct sources. Firewalls, cloud audit logs and identity providers are the heavy sources. Retention length multiplies the number.
4. Technology ownership
A provider that brings its own EDR, SIEM and SOAR bundles the licences into the fee. A provider that manages yours charges less but you pay the vendors. Ask for both versions of the quote.
5. Threat hunting and detection engineering
Proactive hunting, custom detection rules for your environment and purple-team validation are either included in a higher tier or sold as add-ons. They are also what separates a service that finds attackers from one that forwards alerts.
6. Response scope
Notification only, guided response, or hands-on containment by the provider. Each step up adds analyst time and liability, and each is priced accordingly.
7. Compliance reporting and evidence
Reports mapped to ISO 27001, SOC 2, NIS2 or DORA, audit support and attestation letters cost analyst and management time. Cheap tiers give you a dashboard; compliance tiers give you documents an auditor accepts.
8. Onboarding and integration
Agent deployment, log source integration, playbook design and tuning are usually a one-time fee. Underestimated onboarding is the most common reason the first invoice does not match the quote.
Where the hidden line items hide
Items that often appear after signature. Ask about each one up front.
| Line item | Typical trigger | How to contain it |
|---|---|---|
| Log overage | A new source or a verbose firewall pushes you past the ingestion tier | Cap and alert on volume; agree a per-GB overage rate in the contract |
| Incident response beyond containment | A real incident needs forensics, eradication and recovery | Agree an IR retainer or an hourly rate before you need it |
| Additional sources or integrations | New SaaS, new cloud account, new site | Price list for source types in the contract |
| Retention extension | Auditor asks for twelve months of logs, tier includes three | Match retention to your compliance need from day one |
| Custom detection rules | Your environment needs rules the provider's catalogue lacks | Include a quarterly tuning allowance |
| Reporting customisation | Board or regulator wants a format the platform does not produce | Agree report templates during onboarding |
| Exit and data export | You switch provider | Export format, period and cost stated in the contract |
How to compare two managed security quotes
Normalise both quotes on these before looking at the total.
- Same coverage hours and the same containment commitment, by severity
- Same count of endpoints, identities and users, with the same definition of each
- Same log sources and retention, with the overage rate stated
- Same response scope: notify, guide or contain
- Same reporting: which frameworks, which cadence, which deliverables
- Onboarding fee and timeline stated separately
- Licences included or excluded, listed per product
- Exit terms: notice, transition, data export
What moves the price down without weakening the service
Three levers work in most environments. Reduce log noise before onboarding, because you pay for every event whether it matters or not. Consolidate identity into one provider, because identity telemetry is both the most valuable and the cheapest source per detection. Start with MDR on endpoints and identities and add SIEM-based SOC coverage only for the sources that produce detections, instead of ingesting everything on day one. What does not work is buying notification-only monitoring to save money: the incident still happens, and now you own the response at the worst possible hour.
How HackersHub scopes managed security
We quote per programme, not per catalogue. A scoping session establishes your sources, your responders, your regulatory duties and your growth, and the written proposal states coverage hours, containment commitments by severity, counted units, log sources and retention, licence inclusions, onboarding, reporting and exit terms on one page. The number is built from the drivers above and you can see each of them. No published price list, because the drivers move the number more than any list could capture.
Frequently asked questions
Want a quote you can take apart line by line?
A scoping session gives you a one-page proposal with every cost driver visible. Talk to an expert.