Every MSP selling security hits the same wall: clients expect 24/7 threat monitoring, and a security operations center is the machinery that delivers it. Building one in-house runs $1.2 million to $3 million a year before the first client pays a dime. Buying SOC as a service starts around $8 per endpoint per month. That gap looks like an easy call, but it hides trade-offs in margin, control, and what happens at 3 a.m. when an alert fires. Here's the 2026 math for both paths, and the endpoint count where the answer flips.
TL;DR
- Definition. SOC as a service is a subscription that delivers 24/7 threat monitoring, detection, and response from an external security operations center instead of an in-house team.
- Buy cost. Published 2026 rates run $8 to $25 per endpoint per month.
- Build cost. A minimum viable 24/7 SOC runs $1.2M to $3M a year, staffing 65-70% of it.
- The call. Under 1,000 endpoints buy, 1,000 to 3,000 co-manage, past 3,000 model the build.
What Is SOC as a Service
SOC as a service (SOCaaS) is a subscription model where an external provider runs your security operations center: the people, the detection stack, and the response process. The provider ingests telemetry from your endpoints, networks, identities, and cloud workloads, then triages alerts, hunts threats, and either responds directly or escalates to your team. You pay monthly, usually per device or per user, instead of hiring analysts and licensing a SIEM yourself.
For an MSP the model has a second layer. You're not protecting one company's environment, you're deciding how to deliver security operations across every client you manage. That multiplies both the cost of building and the margin impact of buying. A managed SOC that costs you $11 per endpoint and bills out at $25 changes your P&L very differently than a $2M internal build you have to amortize across your client base.
The stakes keep rising. IBM's 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million, up 12% year over year, and found that one in four malicious breaches is now AI-enabled, with those averaging $6 million. The number that should worry anyone selling monitoring: mean time to identify and contain a breach climbed to 247 days, reversing five straight years of improvement. Detection speed is a financial line item now, and a SOC, whoever runs it, is where detection speed lives.
The Real Cost of Building an In-House SOC
Start with people, because people are the budget. Round-the-clock coverage isn't three analysts working shifts. Once you account for nights, weekends, vacation, sick time, and training, each 24/7 seat needs five to six full-time analysts. A minimum viable SOC covering triage, investigation, and escalation across tiers needs 8 to 12 analysts. Glassdoor puts the average US SOC analyst near $100,000 a year as of mid-2026, with Tier 1 triage at $70,000 to $90,000 and Tier 2 investigators at $85,000 to $120,000. Salaries alone put you past $1 million before you've bought a single tool.
Then comes the stack: SIEM licensing, log storage that grows every time you onboard a client, EDR, SOAR tooling, threat intelligence feeds, and the engineering time to keep detections tuned. Published 2026 build-vs-buy models, including Cyflare's and Radicl's, converge on $1.2 million to $3 million per year for a functioning in-house SOC, with staffing at 65-70% of the total.
Hiring is the quieter problem. ISC2's last published workforce gap estimate, from its 2024 study, put it at 4.8 million unfilled roles. Its 2025 Cybersecurity Workforce Study stopped publishing a gap number and reported something more relevant to your P&L: 33% of organizations don't have the budget to staff their security teams adequately, and 29% can't afford people with the skills they need. Budget, not talent scarcity, is now the binding constraint. Attrition in Tier 1 roles compounds it, because alert triage burns people out and every departure restarts a 3-6 month hiring and training cycle.
The build path isn't irrational. It buys you full control of detection logic, data residency, and client experience, and it can become a product you sell at premium margin. But it's a seven-figure annual commitment with an 18-24 month road to maturity, and it only pencils out when enough endpoints are paying for it.
Talanos, an MSSP that sells the buy side, runs the same staffing arithmetic in two minutes. Worth watching for how quickly the headcount math stops being about salaries and starts being about coverage:
What Buying a SOC Looks Like in 2026
The buy side has matured fast, and the MSP channel is one of its main battlegrounds. Huntress built its business on a human-backed SOC sold through MSPs. Blackpoint Cyber sells MDR with active response aimed squarely at the channel. Arctic Wolf, eSentire, and a long tail of white-label providers round out the field. Published 2026 pricing research from NuHarbor and UnderDefense lands in the same band: $8 to $25 per endpoint per month for detection and response, with flat retainers running $1,000 to $10,000+ monthly depending on log volume, user count, and response depth. Bare alert forwarding sells for $3 to $9, and it's worth exactly that.
Pricing model matters more than sticker price. Per-device pricing scales cleanly with how MSPs bill, so you can bake SOC coverage into your per-seat price and protect margin as you grow. Log-volume pricing is harder to predict and spikes when a chatty client environment doubles its telemetry. Read the overage terms before you sign anything.
White-label deserves its own mention. A white-label SOC lets you sell 24/7 monitoring under your own brand while the provider's analysts do the work. Your clients see your name on the report, and you skip the seven-figure build. The trade-off is depth: you're reselling someone else's process, and when a real incident hits, your techs are coordinating with an external team they've never met. Ask any provider how escalation works at 3 a.m. on a Sunday, and ask for the SLA with the penalty clause attached, not the marketing version.
Build vs Buy: Side by Side
| Factor | Build In-House | Buy (SOCaaS) |
|---|---|---|
| Year-one cost | $1.2M-$3M | $12K-$120K+ per year, scales per device |
| Time to full coverage | 12-24 months | 2-8 weeks onboarding |
| Staffing burden | 8-12 analysts, 24/7 rotation | Zero analysts; vendor manages coverage |
| Control of detections | Full | Limited; tuning requests go through vendor |
| Data residency | Yours entirely | Logs live in vendor infrastructure |
| Margin model | High margin at scale, loss before it | Predictable spread on every endpoint |
| Exit cost | Sunk build cost | Contract term; telemetry re-pointing |
The table understates one thing: risk concentration. When you build, a bad quarter of attrition can gut your night shift. When you buy, a vendor acquisition or price hike hits every client at once. Neither path removes risk, they just move it.
The Build Path: Wazuh and Open Source
If you build, the open-source route cuts licensing out of the equation. Wazuh gives you SIEM and XDR capabilities with no per-endpoint license fee, which is why it keeps showing up in MSP build stories. The software is free; the work isn't. Sizing indexers, building decoders for client-specific log sources, tuning out false positives, and keeping clusters healthy is real engineering time. Our Wazuh deployment guide for MSPs covers the sizing, clustering, and cost math in detail, including where the hidden hours go.
Alert fatigue is the failure mode to plan for. An untuned SIEM will bury two analysts in thousands of daily alerts, and fatigue is what turns a detection miss into a breach headline. Budget the first 90 days of any build almost entirely for tuning, not monitoring. Detection you can't triage isn't detection, it's noise with a dashboard.
The realistic open-source build for a small MSP looks like this: Wazuh for SIEM and endpoint telemetry, an EDR you already resell, a documented escalation runbook, and two to four security-focused techs providing business-hours coverage with an on-call rotation for nights. That's not a 24/7 SOC, and it shouldn't pretend to be one. It's a credible detection capability for $150K-$300K a year in payroll, and for some client bases that's the right product at the right price.
The Buy Path: How to Pick a Provider
Sorting providers starts with sorting acronyms, because vendors blur them on purpose. A SOCaaS provider runs monitoring and detection across your telemetry. An MSSP manages security tooling more broadly. MDR focuses on detection and response, usually anchored to a specific agent. The lines matter for what's in scope when something goes wrong; our breakdown of what MDR covers and how it differs from MSSP untangles the categories before you sit through a single demo.
Evaluate every provider on the same five questions:
- Response authority. Will they isolate a host or kill a session themselves, or just email you an alert? Alert forwarding at 2 a.m. is not response.
- Telemetry scope. Endpoints only, or identity, cloud, network, and SaaS too? Identity attacks dominated 2025-2026 breach data.
- MSP economics. Per-device pricing, monthly terms, multi-tenant console, white-label reporting. If the provider leads with three-year contracts, keep walking.
- Escalation clarity. Named contacts, documented severity tiers, SLA with penalties. Ask to see a real, redacted incident report, not a sample.
- Exit terms. How do you get your logs and detections out? Lock-in doesn't stop being lock-in because it's wearing a security badge.
Run a 30-day pilot with one mid-sized client before rolling anything out fleet-wide. Every provider demos well; the pilot tells you how they handle your ticket volume, your naming conventions, and your 3 a.m.
Watch how they handle false positives during that pilot, because that's the daily texture of the relationship. A SOC that pages you for every PowerShell execution will train your techs to ignore it within a month, and an ignored SOC is an expensive way to feel secure. The pilot should end with a tuning conversation where the provider shows you what they suppressed, what they escalated, and why. If they can't walk you through that reasoning client by client, the monitoring is a black box, and black boxes are what you were trying to stop paying for.
MSPs run this exact argument in public. One operator's client SOC caught malicious code execution at 2 a.m., sent the report at 6 a.m., had not remediated anything, and asked the MSP to decide whether it counted as an issue:
The Margin Math Nobody Shows You
Work one concrete example before any contract lands on your desk. Say you manage 1,500 endpoints across 40 clients. A per-device SOCaaS plan at $11 per endpoint costs you $16,500 a month, or $198,000 a year. Bill SOC coverage into your security package at $25 per endpoint and you gross $450,000, clearing roughly $250,000 a year on the spread while a vendor staffs the night shift. The same 1,500 endpoints trying to carry a $1.5M internal build would need you to bill $83 per endpoint per month just to break even on the SOC alone, before RMM, backup, licensing, or your techs' time.
That break-even line moves with scale, which is the whole decision in one sentence. At 5,000 endpoints, the same internal build drops to $25 per endpoint per month of cost, and owning the detection stack, the client experience, and the premium pricing starts to beat reselling someone else's SOC. Below the line, buying prints margin. Above it, building compounds. The mistake is deciding by instinct instead of running your own endpoint count through the math.
Two cautions on the model. Price the build at what it costs when hiring goes sideways, not at what it costs on paper: the $1.5M figure assumes you fill every seat the first time, and the ISC2 budget numbers say that's the optimistic case. Price the buy the same way: vendor per-device rates climb at renewal, and a $3 bump across 5,000 endpoints is $180,000 a year straight out of your margin. Model both paths at year three, not year one.
Co-Managed SOC: The Middle Ground
Co-managed splits the work: the provider carries 24/7 monitoring and Tier 1 triage, your team keeps escalation, remediation, and the client relationship. For MSPs with a couple of security-minded techs but no appetite for a night shift, it's often the strongest position. Your techs keep their hands on the tooling and build skills against real incidents, while the provider absorbs the part of the job that burns people out.
Pricing for co-managed arrangements usually lands between pure SOCaaS and a full internal build: expect $2,000 to $8,000 a month depending on endpoint count and how much Tier 2 work stays on your side. The contract detail that matters is the division of responsibility during an active incident. Get it in writing: who isolates the host, who talks to the client, who owns forensics, and who signs the breach notification if it comes to that. Ambiguity there is cheap to fix in a contract and ruinously expensive to discover mid-incident.
It also derisks a future build. MSPs that eventually stand up their own SOC usually get there through co-management: they learn the workflows, inherit tuned detections, and hire analysts gradually instead of fielding a 10-person team on day one. If your five-year plan includes a security practice as a flagship product, co-managed is the on-ramp that doesn't gamble the P&L on year one.
The Call for Your MSP
The short answer by size. Under roughly 1,000 managed endpoints, buy white-label SOCaaS and bake it into your per-seat price. Between 1,000 and 3,000 endpoints, co-manage, keep two security techs in-house, and revisit yearly. Past 3,000 endpoints with security as a named product line, model the build, and start with the open-source stack so licensing doesn't eat the case before staffing does.
Whichever way you go, the SOC decision sits inside a bigger stack decision. Monitoring feeds tickets, tickets feed techs, and the platform holding it together determines whether SOC alerts become fast fixes or swivel-chair chaos. That's the gap OpenFrame is built for: an open, AI-native infrastructure layer for IT and security, with the agents built into the infrastructure rather than bolted on top, so an alert, the ticket it opens, and the endpoint it came from all live in one place. Open source takes the software bill down, the agents take the hours down, and your data stays yours if you change course. Our guide to the full MSP security stack shows where SOC coverage plugs into the rest of the picture.
One more number for the road: IBM found that organizations running AI and automation across prevention, detection, investigation, and response closed breaches about two months faster and paid $1.93 million less per breach. The MSPs winning security deals in 2026 aren't the ones with the biggest SOC. They're the ones who made a clear-eyed build-or-buy call, wrote it down, and put the savings into response speed.
Your clients don't care who staffs the SOC. They care who answers at 3 a.m. Decide who that is on purpose.
Content Marketing Lead
Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
