A managed security services business can look wonderfully predictable on a spreadsheet, right up until one noisy client consumes half the team before lunch. Owners, investors, and operators need more than a monthly recurring revenue number. They need to know what is actually recurring, what quietly expands delivery cost, and which contracts create durable value. In about 15 minutes, this guide will help you compare MSSP business models, price service tiers, test gross margin, spot churn risk, and choose a model that fits your team rather than merely flattering the forecast.
Who This Is For, and Who Should Pause
This article is for founders building an MSSP, MSP owners adding security services, private equity or search-fund buyers reviewing an acquisition, and security leaders deciding whether recurring services can support a larger business. It is also useful for finance teams that keep hearing “ARR” while invoices arrive in several different shapes.
Good fit
- You have a defined customer segment, such as 25 to 500 employee professional services firms.
- You can standardize most tools, onboarding steps, reporting, and escalation paths.
- You are willing to measure service cost by customer, not only by department.
- You can separate monitoring, response, compliance support, and project work in contracts.
Not a good fit yet
- Every customer receives a custom stack and a custom promise.
- Your team cannot tell which clients create the most alert volume or engineering time.
- You use “unlimited support” without a boundary, queue rule, or fair-use clause.
- Your security offering depends on one irreplaceable analyst who also handles sales demos, onboarding, and printer emergencies.
Consider a composite example: a six-person MSP adds endpoint detection and monthly reports for twenty clients. Revenue rises neatly. Then three clients ask for 24/7 response, cloud investigations, and audit evidence under the same fee. The offer is recurring, but the margin has quietly gone camping without leaving a note.
- Choose a narrow customer profile.
- Define what is included and excluded.
- Track labor and tool cost per account.
Apply in 60 seconds: Write one sentence describing the customer you serve best and the security outcome you deliver every month.
The MSSP Business Model in Plain English
An MSSP sells ongoing security outcomes through a mix of people, processes, software, and contractual response obligations. The customer usually pays a monthly or annual fee. The provider absorbs the work of monitoring, triage, reporting, maintenance, and sometimes response.
The important distinction is between recurring billing and recurring value. A contract may renew monthly, yet still depend on repeated manual work that scales almost one-for-one with client count. That is closer to a retainer-based consultancy wearing a software-shaped hat.
Four common MSSP models
| Model | Core Offer | Revenue Pattern | Main Margin Risk | Best Fit |
|---|---|---|---|---|
| Monitoring-led | SIEM, EDR, alert triage, reporting | Per user, device, log source, or site | Alert noise and data ingestion cost | Standardized SMB and mid-market fleets |
| MDR-led | Detection, investigation, guided or active response | Per endpoint, identity, cloud workload, or bundle | Response labor and liability expectations | Customers needing operational relief |
| Compliance-led | Controls, evidence, policy support, readiness reviews | Monthly platform fee plus periodic projects | Unpriced audit preparation and documentation | Regulated or contract-driven buyers |
| Platform-plus-service | Proprietary portal, automation, analytics, expert support | Subscription plus usage or premium services | Product development cost and weak adoption | Providers with repeatable workflows and capital |
NIST Cybersecurity Framework 2.0 organizes cyber-risk work around Govern, Identify, Protect, Detect, Respond, and Recover. That structure is useful for MSSP packaging because it exposes gaps between what the provider monitors and what the customer assumes is covered.
A useful internal companion is this guide to cybersecurity best practices, especially when translating broad security goals into repeatable monthly tasks.
How Recurring Revenue Really Behaves
MSSP recurring revenue is often described with SaaS language, but the economics are hybrid. Software cost may scale by endpoint or log volume. Labor cost may scale by incident frequency. Customer success cost may spike during audits, renewals, acquisitions, and executive turnover. A clean model separates each layer.
MRR, ARR, and contracted recurring revenue
- Monthly recurring revenue (MRR): normalized monthly subscription revenue from active customers.
- Annual recurring revenue (ARR): MRR multiplied by 12, adjusted for known contract changes.
- Contracted recurring revenue: the future recurring amount legally committed under signed agreements.
- Recognized revenue: the amount recorded under the applicable accounting rules, which may not match cash collected.
Do not mix onboarding fees, hardware resale, incident-response projects, or one-time assessments into ARR. They can be excellent revenue. They are simply different animals, and forcing them into the recurring pen makes forecasting smell strange.
Revenue quality scorecard
Score each item from 0 to 2
- Contract term: 0 for month-to-month, 1 for annual with easy exit, 2 for annual or multi-year with clear commitments.
- Gross margin visibility: 0 for unknown, 1 for estimated, 2 for measured by customer.
- Service standardization: 0 for mostly custom, 1 for mixed, 2 for standardized tiers.
- Concentration: 0 if one client exceeds 25% of MRR, 1 if the top five are heavy, 2 if diversified.
- Renewal friction: 0 if value is unclear, 1 if reporting is adequate, 2 if outcomes are documented and reviewed.
Interpretation: 0 to 3 is fragile, 4 to 7 is workable, and 8 to 10 is durable enough for closer analysis.
In another composite scenario, an MSSP reports $180,000 in MRR. One customer supplies $52,000, three contracts renew within sixty days, and the team has never allocated vendor licenses by account. The headline is strong. The supporting beams are chewing gum.
Visual Guide: From Contract to Durable Revenue
Define term, scope, response authority, exclusions, and renewal mechanics.
Standardize tools, onboarding, triage, reporting, and escalation.
Measure labor, licenses, cloud usage, and support by customer.
Prove outcomes, reduce surprises, and renew before the deadline panic.
- Separate recurring and project revenue.
- Measure gross margin by account.
- Flag renewal and concentration risk.
Apply in 60 seconds: Remove every one-time fee from last month’s revenue and recalculate true MRR.
Service Packages That Customers Can Understand
Customers rarely wake up wanting “more telemetry.” They want fewer business interruptions, faster containment, cleaner audits, and someone competent to call when the dashboard turns red at 2:13 a.m. Service packaging should translate technical activity into those outcomes without promising perfection.
A practical Good, Better, Best map
Good: Monitor
- Endpoint and identity monitoring
- Business-hours triage
- Monthly reporting
- Customer-led remediation
Best for: Smaller firms with capable IT staff.
Better: Detect and Respond
- 24/7 monitoring and investigation
- Pre-approved containment actions
- Quarterly security review
- Defined incident coordination
Best for: Firms that need operational coverage.
Best: Managed Risk Program
- Detection and response
- Vulnerability and exposure management
- Compliance evidence support
- Executive risk reporting
Best for: Regulated or rapidly growing organizations.
The trick is to make the boundaries visible. “Incident response included” can mean triage and phone coordination, or it can mean forensic imaging, malware analysis, legal support, and weeks of recovery work. Those are not the same sandwich.
Short Story: The Unlimited Plan That Ate Friday
A composite MSSP sold an “unlimited managed security” package to a regional accounting firm. The price covered endpoint monitoring, monthly reporting, and standard remediation guidance. Then tax season arrived. The client added temporary staff, new laptops, a cloud file-sharing tool, and several outside contractors. Alerts multiplied. The client also requested evidence for a cyber-insurance renewal and a customer security questionnaire, both due Friday. Because the contract used the word unlimited without defining users, projects, data volume, or response hours, the provider absorbed forty extra hours in one week. The customer was not unreasonable. The contract had simply invited two different interpretations to dinner. The practical lesson is plain: define the unit of service, include a change-control trigger, and price exceptional work separately. A clear boundary protects the relationship because neither side has to argue while the clock is ticking.
For providers selling visual risk reporting, this internal guide on cybersecurity risk heatmaps can help turn technical findings into a board-friendly service without pretending that red squares are a complete security program.
Pricing, Gross Margin, and Unit Economics
There is no universal MSSP price because scope varies wildly. A useful model begins with service units and cost drivers, then adds a margin appropriate to risk, customer support, selling expense, and reinvestment needs. Copying a competitor’s per-user price without copying its tooling, exclusions, automation, and staffing model is financial cosplay.
Common pricing units
- Per user: easy to explain, but may ignore servers, cloud workloads, and data volume.
- Per endpoint: aligns with endpoint tooling, but can underprice identity and cloud risk.
- Per log source or ingestion volume: closer to SIEM cost, but harder for buyers to forecast.
- Per site: simple for distributed businesses, but uneven when locations vary greatly.
- Flat platform fee plus usage: balances predictability and scale, though billing needs care.
- Risk-based bundle: aligns with outcomes, but requires strong scoping discipline.
Illustrative monthly cost table
The figures below are planning assumptions, not market quotes. Replace them with your vendor contracts and actual labor data.
| Cost Layer | Example Driver | Illustrative Range | Watch For |
|---|---|---|---|
| Security tools | Users, endpoints, workloads, or data | 20% to 40% of service revenue | Minimum commitments and overage fees |
| Analyst labor | Alerts, investigations, escalations | 15% to 35% | After-hours coverage and senior review |
| Customer success | Reviews, reporting, renewals | 5% to 12% | Audit-season spikes |
| Infrastructure | Cloud, storage, ticketing, integrations | 3% to 10% | Retention periods and data transfer |
| Delivery overhead | QA, management, training | 5% to 15% | Hidden nonbillable escalation time |
Mini calculator: monthly gross profit
Estimated MRR: $75,000
Estimated monthly gross profit: $41,250
Show me the nerdy details
Customer gross margin should allocate direct licenses, ingestion charges, cloud cost, analyst time, escalation time, customer-specific reporting, and delivery management. A useful contribution-margin view then subtracts customer success and support expenses that vary with the account. Company gross margin can still look healthy while a few large accounts destroy contribution margin, so calculate both.
A composite finance lead once found that the “largest and best” customer produced a 12% gross margin after data ingestion and senior analyst time. The smallest standardized clients averaged 63%. Revenue had been telling one story; cost allocation had been whispering another.
- Map each service to a measurable cost driver.
- Use change triggers for growth and unusual activity.
- Review customer margin at least quarterly.
Apply in 60 seconds: Pick one client and list every direct tool, cloud, and labor cost attached to that account.
Customer Acquisition and Retention Economics
MSSP sales cycles can be slow because the buyer is transferring access, trust, and operational responsibility. That means customer acquisition cost should include sales compensation, technical presales, security questionnaires, proof-of-concept support, legal review, and onboarding concessions.
Simple acquisition payback test
Divide total acquisition cost by expected monthly gross profit from the new customer. A $24,000 acquisition cost and $4,000 in monthly gross profit creates a six-month gross-margin payback. That is attractive only if churn, implementation burden, and collection risk remain controlled.
Retention is built before renewal
- Set baseline risk and asset coverage during onboarding.
- Report what changed, what was blocked, what remains open, and who owns the next action.
- Hold executive reviews before budget season, not two weeks before expiration.
- Record service exceptions and customer-caused delays.
- Connect recommendations to business impact, insurance requirements, contracts, or regulatory obligations.
One composite provider sent twenty-page monthly reports filled with alert counts. Renewal conversations stayed painful. After replacing most of the report with three pages on risk reduction, unresolved exposure, response performance, and next-quarter priorities, executives finally had something they could repeat in a meeting.
Churn signals worth tracking
- Low portal usage and repeated missed review meetings
- Unresolved onboarding gaps after sixty or ninety days
- Frequent disputes about what is included
- Executive sponsor departure
- Acquisition, private equity recapitalization, or major IT outsourcing change
- Persistent dissatisfaction with response time or reporting quality
Do not treat every churn event as a sales failure. Some customers were mispriced, poorly matched, or operationally hazardous from day one. Healthy retention includes the discipline to avoid renewing contracts that repeatedly generate negative margin or unacceptable risk.
Operations, Staffing, and SLA Design
The operating model decides whether recurring revenue compounds or merely repeats exhaustion. Standardized detection rules, ticket categories, escalation paths, and customer permissions reduce both cost and confusion. Automation helps, but it cannot rescue an offer whose boundaries are fog.
Capacity planning by work type
- Steady work: monitoring, health checks, reporting, patch verification, routine tuning.
- Variable work: investigations, false-positive review, customer questions, audit support.
- Shock work: active incidents, zero-day response, vendor outages, widespread misconfiguration.
A good staffing model reserves capacity for all three. If analysts are scheduled to 95% utilization on steady work, the first serious incident converts the queue into a traffic jam with a siren.
SLA design checklist
- Define severity levels using observable conditions.
- Separate acknowledgement, investigation, containment, and resolution targets.
- State business hours, time zone, and holiday coverage.
- Document customer dependencies and required contacts.
- Specify what actions the MSSP may take without approval.
- Explain exclusions for unsupported systems and missing telemetry.
- Describe service credits, caps, and claim procedures.
- Set change-control rules for users, endpoints, sites, and log volume.
CISA has warned that MSP and customer security depends on shared responsibility, baseline controls, and careful management of privileged access. For an MSSP, this is not merely a technical issue. It is part of product design, contract design, and customer education.
Providers expanding from general IT services may also find this internal guide on securing business data useful when defining the minimum controls customers must maintain before advanced monitoring can work.
- Define severity and timing precisely.
- State customer responsibilities.
- Reserve capacity for incident spikes.
Apply in 60 seconds: Circle every SLA phrase that depends on words such as fast, timely, reasonable, or immediate, then replace it with a measurable condition.
Cyber-Risk and Contract Disclaimer
This article provides general business analysis, not legal, accounting, investment, insurance, or incident-response advice. MSSP obligations can change based on contract language, customer industry, state privacy law, federal rules, cyber-insurance conditions, data location, subcontractors, and the facts of an incident.
No MSSP can promise that attacks will never succeed. The defensible promise is narrower: defined monitoring, documented response procedures, reasonable safeguards, transparent reporting, and clear escalation under agreed conditions.
Risk allocation questions
- Who owns security policy, asset inventory, backups, identity administration, and business continuity?
- Can the MSSP isolate endpoints, disable accounts, or block traffic without approval?
- Who pays for emergency forensic work, legal counsel, notification, and recovery?
- What happens when the customer declines a recommended control?
- Which subcontractors and technology vendors can access customer data?
- How are liability caps, indemnities, warranties, and exclusions structured?
The FTC advises businesses to establish and monitor cybersecurity risk-management strategy, document legal and contractual requirements, and evaluate vendor security practices. Those expectations matter to both MSSPs and their customers because outsourced security does not erase governance responsibility.
Common MSSP Business Model Mistakes
1. Selling “24/7” without pricing the night shift
Continuous coverage requires staffing, an outsourced SOC, an on-call rotation, or some combination. Put the real cost into the tier. Sleep is not a free infrastructure service.
2. Bundling incident response without a boundary
Include triage and coordination if that fits the offer. Price deep forensics, recovery, legal coordination, and extended surge work separately unless the premium truly covers it.
3. Ignoring data-volume economics
Customers with the same headcount can generate radically different log volume. Use included allowances, usage bands, or a documented repricing trigger.
4. Customizing the stack for every logo
Supporting many tools can win deals, but each exception adds training, integration, tuning, and troubleshooting cost. Maintain an approved stack and charge for exceptions.
5. Treating onboarding as free
Discovery, deployment, integrations, tuning, documentation, and training consume real labor. Charge an implementation fee or recover it through a minimum term and early-termination structure reviewed by counsel.
6. Reporting activity instead of outcomes
Alert counts are operational evidence, not the whole value story. Show coverage, response performance, closed exposure, open risk, and decisions required from the customer.
7. Letting one client dominate revenue
Concentration increases bargaining power, staffing dependence, and valuation risk. Track the largest customer and top-five share of MRR every month.
In a composite acquisition review, a buyer found attractive EBITDA but also discovered that the founder personally handled every severity-one incident for the largest customer. The business had recurring revenue and nonrecurring sleep. The purchase price changed quickly.
- Price after-hours and surge work.
- Limit unsupported tool variation.
- Protect against customer concentration.
Apply in 60 seconds: List the three promises sales makes most often and confirm that delivery cost is included in the price.
When to Seek Specialist Help
Bring in outside expertise before the contract, staffing, or incident becomes expensive. A small amount of specialist review can prevent a heroic amount of cleanup.
Seek legal counsel when
- You introduce active containment or remote administration.
- You serve regulated customers or process sensitive personal data.
- You revise liability caps, indemnities, warranties, or subcontractor terms.
- You plan multi-state or international delivery.
Seek accounting or transaction support when
- You are preparing for financing, acquisition, or sale.
- You cannot reconcile bookings, billings, cash, and recognized revenue.
- You capitalize software development or offer complex prepaid contracts.
- Customer-level gross margin is unavailable or disputed.
Seek incident-response support when
- There is evidence of active compromise, lateral movement, data theft, or ransomware.
- Your team lacks forensic preservation capability.
- Legal, insurance, regulatory, or notification duties may apply.
- The incident exceeds contracted tools, authority, or staffing.
For practical breach-response planning, see the internal guide on the first steps after a data breach. It can support customer education, but it should not replace incident-specific legal and forensic guidance.
Build a 15-Minute MSSP Revenue Model
You do not need a heroic spreadsheet to expose the first layer of truth. Open a blank sheet and create one row per customer. Then add the following columns.
Minimum model columns
- Customer name and segment
- Monthly recurring revenue
- Contract start, renewal, and notice dates
- Users, endpoints, sites, log volume, or other billing unit
- Direct license and cloud cost
- Monthly analyst and escalation hours
- Customer success and reporting hours
- Estimated gross profit and gross margin
- Open scope exceptions
- Churn risk and next action
Decision card
Choose your next operating priority
If margin is unknown: allocate tools and labor by customer before changing prices.
If margin is low: reduce tool variation, narrow scope, automate repeatable work, or reprice.
If churn is high: fix onboarding, expectation setting, reporting, and customer fit.
If growth is slow: tighten the ideal customer profile and package a specific business outcome.
If concentration is high: build pipeline before celebrating the next large renewal.
A composite founder completed this exercise and discovered five clients below 25% gross margin. Two needed repricing, one needed a tool migration, one required a project addendum, and one was better released. The model did not solve everything. It did stop the team from arguing with shadows.
- Use one row per customer.
- Include direct tools and labor.
- Assign one next action to every weak account.
Apply in 60 seconds: Create the first three columns now: customer, MRR, and renewal date.
FAQ
How do MSSPs make recurring revenue?
MSSPs charge monthly or annual fees for ongoing monitoring, detection, response, security administration, compliance support, or risk reporting. Pricing may be based on users, endpoints, sites, cloud workloads, data volume, or bundled service tiers.
What is a good gross margin for an MSSP?
There is no single correct target because delivery scope and accounting treatment vary. Compare customer-level margin over time, include direct labor and tools, and make sure the remaining margin can support sales, management, insurance, training, product development, and profit.
Is an MSSP business model the same as SaaS?
No. Both may produce subscription revenue, but MSSPs usually carry more labor, response, service-level, and liability exposure. An MSSP with strong automation may gain software-like efficiency, yet human judgment remains central in investigation and customer communication.
Should MSSPs charge per user or per endpoint?
Use the unit that most closely tracks service cost and is understandable to the buyer. Per-user pricing is simple, while per-endpoint pricing may align better with endpoint tooling. Many providers use a platform minimum plus usage bands.
What should an MSSP include in a monthly report?
Include coverage status, meaningful incidents, response performance, major exposure changes, unresolved risks, customer actions, and next-quarter priorities. Alert totals can support the report, but they should not be the entire value story.
How long should an MSSP contract be?
Annual terms are common because onboarding and tuning require upfront work, but the right term depends on sales motion, customer risk, implementation cost, and local law. Renewal, notice, repricing, termination assistance, and data-return terms matter as much as duration.
What is the biggest risk in an MSSP acquisition?
Common risks include customer concentration, hidden labor, vendor dependence, weak contracts, founder dependence, poor security controls, and revenue classified as recurring even when it is project-based. Customer-level margin and contract review are essential.
Can a small MSP successfully add managed security services?
Yes, but start with a narrow offer, a controlled tool stack, clear escalation, and a customer profile you already understand. Partnering for 24/7 monitoring may be sensible, provided responsibilities, access, data handling, and customer communication are explicit.
How can an MSSP reduce churn?
Improve customer fit, onboarding, coverage validation, executive reporting, service transparency, and renewal timing. Track sponsor changes, missed reviews, unresolved exceptions, and repeated scope disputes before they become cancellation notices.
Does an MSSP replace the customer’s security responsibility?
No. The provider can perform defined security functions, but the customer still owns governance decisions, business risk, internal policy, employee behavior, and many legal obligations. Contracts should clearly assign responsibilities and dependencies.
Conclusion: Sell Calm, Not Alert Volume
The curiosity at the start was not whether MSSPs can produce recurring revenue. They clearly can. The real question is whether that revenue stays valuable after tools, labor, incident spikes, contract risk, and customer concentration receive a seat at the table.
A durable MSSP model sells a defined outcome to a defined customer, using a repeatable stack and measurable operating boundaries. It does not rely on unlimited promises, invisible founder labor, or reports that count noise more carefully than risk.
Your next step takes less than 15 minutes: build one customer-level row with MRR, direct tool cost, monthly labor hours, gross margin, renewal date, and one open scope issue. Then repeat it for the five largest accounts. The result may not be elegant, but it will be honest, and honest models are easier to improve.
Last reviewed: 2026-08