In this article:

SOC as a Service Pricing: What Drives the Number

Cybersecurity
/
July 18, 2026
SOC as a Service Pricing: What Drives the Number

SOC as a service typically costs $8 to $25 per endpoint per month in 2026 for a service that detects and responds, with platform-tied enterprise offerings running $25 to $45 and bare alert forwarding available for $3 to $9. Buyers who want one number instead of a meter see flat co-managed retainers, commonly $5,000 to $25,000 per month in the mid-market. Four pricing models dominate: per endpoint, per user, per GB ingested, and flat retainers. Five drivers move the number inside every model: how much log data you generate, the hours a human is watching, how many attack surfaces the detections cover, how deep response goes, and the compliance reporting attached to it. The models, the current ranges, and what the cheap tiers cut follow.

The four pricing models

Per endpoint is the most common meter. You pay for each monitored device per month, which maps cleanly onto services built around an EDR agent because the count is easy to audit. Mainstream detection and response runs $8 to $25 per endpoint per month, and volume moves the rate: buyers with 100 endpoints commonly pay $15 to $25, while a 1,000-endpoint estate can negotiate toward $8 to $12. Read the definition of an endpoint before comparing quotes, because servers, virtual machines, and containers are often counted differently or priced at a multiple.

Per user prices identity instead of hardware. Published per-user rates for SOC and MDR services cluster around $8 to $15 per user per month at organizations of 200 to 1,000 users, and the model favors companies where one person carries a laptop, a phone, and a tablet. Ask how service accounts, shared mailboxes, and contractors count, since those definitions move the invoice more than the headline rate does.

Per GB ingested passes the SIEM's economics through to you. The provider's operating fee rides on top of ingestion pricing that runs roughly $2 to $5 per GB for a cloud SIEM's analytics tier as of mid-2026: Microsoft Sentinel lists $4.30 per GB pay as you go in its cheapest US region, falling to an effective $2.30 to $3.00 at commitment tiers of 100 GB per day and above. The model is predictable for a stable estate and punishing when a new log source triples your volume overnight.

Flat co-managed retainers price the work instead of the asset count: detection engineering, alert triage, tuning, and reporting on an agreed coverage window, delivered on a stack you own. Mid-market retainers commonly land between $5,000 and $25,000 per month. The meter here is scope, so the number moves when you onboard new log sources or extend coverage hours, and it holds steady when you hire another 40 people.

What actually drives the number

Log volume is the strongest single predictor. Every source you onboard adds ingestion cost, retention cost, parsing work, and detection rules someone has to maintain, so a quote is only as good as the GB-per-day assumption underneath it. Get that assumption in writing.

Coverage hours are the biggest step change. Keeping one analyst seat staffed around the clock takes roughly five people once shifts, weekends, and leave are counted, which is why continuous human coverage prices at a large multiple of business hours plus on-call. Some coverage decisions cost less than buyers expect: automated containment overnight with human triage at 7 a.m. covers many mid-market threat models at a fraction of a fully staffed night shift.

Detection scope determines how much engineering you are buying. Endpoint-only coverage is the entry point. Adding identity, cloud control planes, and SaaS audit logs multiplies the detection content to build and the analyst skill needed to read it, and each addition shows up in the price.

Response depth separates a monitoring product from a security operation. Notification is cheapest. First-pass triage that validates and enriches alerts costs more. Containment authority, where the provider can isolate a host or disable an account, costs more again, and full incident response is usually a separate engagement or an incident response retainer with its own terms.

Compliance reporting is the quiet fifth driver. SOC 2, ISO 27001, and HIPAA all expect monitoring controls with evidence behind them, and a provider that produces disposition records, tuning logs, and monthly reviews in audit-ready form charges for that discipline. It usually costs less than assembling the same evidence yourself every audit cycle.

Managed SOC pricing as of mid-2026

Published rates move, so treat these as a mid-2026 snapshot rather than a quote. Entry-level offerings that forward alerts with limited response run $3 to $9 per endpoint per month. Mainstream managed detection and response, the scope most buyers mean when they say SOC as a service, runs $8 to $25. Platform-tied enterprise services, where the vendor's own agent, analysts, and response come bundled, run $25 to $45, and three-year contracts for a 500-endpoint estate at that tier price out between roughly $330,000 and $830,000 across the major vendors. Organizations of 100 to 1,000 employees buying a managed SOC as a monthly retainer mostly land between $5,000 and $25,000 per month.

The in-house comparison frames all of it. A minimal internal SOC with around-the-clock staffing clears $1 million a year in salaries alone before any tooling, which is the arithmetic that keeps this market growing and the reason a $120,000-per-year managed service can be the conservative option.

What the cheap tiers cut

A $3-per-endpoint service and a $25-per-endpoint service carry the same label and sell different work. The low tier holds its price by cutting the same five things: triage becomes alert forwarding with a severity stamp, detection content stays at vendor defaults never tuned to your environment, noisy rules never get retired, response stops at an email, and analyst attention spreads across enough clients that your alerts wait in a long queue. None of that is visible in a demo.

The result lands on your team. A service that forwards 200 unvalidated alerts a week has moved the SOC's hardest job, deciding what matters, back inside your company while the invoice says you outsourced it. If nobody on staff has time to work that queue, the cheap tier costs more than the price difference.

The hidden costs

Pricing guides consistently find final invoices landing 20 to 40 percent above the quoted rate. The gap comes from a short list of predictable lines:

  • SIEM licensing and ingestion. If the service runs on your SIEM, you carry the $2 to $5 per GB directly. If it comes bundled in the provider's platform, you are still paying it inside the margin, and leaving the provider later means rebuilding the data layer.
  • Ingestion overage. Quotes anchor to today's volume, and a new SaaS audit log or a verbose firewall can double GB per day. Get the overage rate and the re-tiering process in writing before signature.
  • Onboarding. Setup commonly runs $5,000 to $25,000 or a first-month equivalent, covering log source onboarding, parsing, and runbook build. Cheap onboarding usually means default rules.
  • Out-of-scope response. Incident hours beyond the contracted boundary bill hourly, typically $250 to $500. The time to find that boundary is before an incident, in the contract.
  • Escalators and add-ons. Annual uplifts of 3 to 8 percent compound quietly, and capabilities that sounded included, such as threat hunting, vulnerability management, and compliance reporting, are often separately priced modules.

How co-managed pricing differs from full outsourcing

Full outsourcing bundles the platform, the data, and the people into one per-endpoint or per-user number. It is the simplest model to buy and the hardest to leave, because the telemetry history, the detection content, and the tuning live in the provider's tenant and stay there when you go.

A co-managed SOC prices differently because the property lines sit differently. The SIEM and EDR run in your tenant under your contracts, so tooling cost is visible and stays yours, and the provider charges a flat retainer for the operating work: designing the stack, writing and tuning detections, triaging the queue on the agreed window, and escalating confirmed incidents into your response process. The retainer moves with the drivers above, mainly sources onboarded, GB per day, coverage hours, and how much of the queue your own team keeps.

Our SOC as a service engagements are built this way: co-managed on your stack, with coverage windows, escalation authority, and division of labor set in a responsibility matrix during onboarding, and with triage records that double as monitoring evidence for SOC 2 and ISO 27001. Full outsourcing wins when you have no stack, no team, and a deadline measured in weeks. Co-management wins when the licenses already exist, when auditors will ask for evidence in your environment, and when you want an exit that does not mean starting over.

Pricing it for your environment

Quotes only compare when scope does, so fix the variables first: your GB per day, the coverage window you need, the response depth you expect, and the compliance reporting your auditors will ask for. If continuous visibility is the immediate gap, real-time security monitoring is where that starts, and our comparison of MDR, SOC as a service, and MSSP models covers which delivery model fits before you price one. Speak with BD Emerson about what a co-managed SOC costs for your environment. The useful answer starts with your log volume rather than a rate card.

About the author

Leslie Sakal is a Managing Director at BD Emerson focused on cybersecurity, enterprise risk management, and regulatory compliance. She brings over a decade of experience advising organizations across technology, financial services, education, and other regulated industries on implementing organization-wide goals and programs that align with their broader business objectives.
Leslie Sakal
Leslie Sakal
Managing Director