24/7 SOC monitoring costs a typical SMB $40–120 per user per month as a managed service, versus $1M+ per year to staff an in-house SOC. The managed price includes SIEM licensing, log ingestion, L1–L3 analysts, threat hunting and incident response coordination around the clock.
This is the pricing and scoping guide we wish buyers had before their first vendor call. For our own service specifics, see 24/7 SOC monitoring services.
What a 24/7 SOC actually does
| Tier | Role | Typical response |
|---|---|---|
| L1 — Triage | Watches alert queues 24/7, filters false positives, escalates real events with context. | Minutes, around the clock |
| L2 — Investigation | Correlates events across endpoints, identity and network; contains confirmed incidents (isolate host, disable account). | 15–60 minutes |
| L3 — Hunt & engineering | Proactive threat hunting, detection rule tuning, forensics on serious incidents. | Ongoing |
Managed SOC vs in-house: the real math
| Cost item | In-house 24/7 | Managed SOC |
|---|---|---|
| Analysts (minimum 8–10 for continuous coverage) | $700K–1.2M/yr | Included |
| SIEM/SOAR licensing & log storage | $50K–250K/yr | Included or passthrough |
| EDR/XDR tooling | $30–80/endpoint/yr | Often bundled |
| Hiring, training, attrition (30%+ turnover is normal) | Recurring pain | Provider problem |
| Total for a 100-user company | $900K–1.5M/yr | $48K–144K/yr |
What drives the price up or down
Four variables explain most quotes: log volume and retention (compliance-driven retention like NIS2 or CMMC raises storage cost), response scope (monitoring-only vs active containment vs full incident response), environment complexity (OT networks, multi-cloud, legacy servers), and compliance reporting (auditor-ready evidence for NIS2, ISO 27001, CMMC adds analyst documentation time). Beware of quotes that look cheap because they are alert-forwarding services — if the SLA does not include a human investigating within minutes at 3 AM, it is not a SOC.
Questions that expose a weak SOC vendor
Ask for the average time-to-acknowledge and time-to-contain over the last quarter (real SOCs publish these to clients), whether analysts can isolate an endpoint without waking you, what happens when your log source goes silent (silence should page someone — it usually means the attacker turned logging off), and who owns the SIEM data if you leave. Any hesitation on the last one is a lock-in flag.
Free SOC readiness call
30 minutes. We review your current monitoring coverage and show exactly what 24/7 would look like for your stack.
Fixed monthly quote
Per-user or per-asset pricing in 48 hours — typically 30–50% below US/EU MDR pricing.
FAQ
Is 24/7 monitoring overkill for a 20-person company?
Ransomware deployment overwhelmingly happens outside business hours. If downtime for a week would materially hurt the business, around-the-clock detection is justified — and at per-user pricing a 20-person company pays $800–2,400/month, less than one day of outage typically costs.
Does NIS2 require a SOC?
Not by name. NIS2 Article 21 requires incident handling, detection capability and 24-hour incident reporting — obligations that are hard to satisfy without continuous monitoring. Details in our NIS2 hub.
SOC vs MDR vs EDR — what is the difference?
EDR is the endpoint tool. MDR is a managed service around that tool. A SOC is the broader function: people, process and technology monitoring your whole environment — endpoints, identity, cloud, network — with defined escalation. Many vendors sell MDR labeled as a SOC; scope the log sources to know which you are buying.
Can an MSP resell your SOC?
Yes — that is our white-label model: your brand, our analysts, your client relationship stays untouched.
ITSECOPS runs a 24/7 SOC from India with a Norway entity for EU clients — fixed monthly pricing, no per-alert billing. General guidance, not a quote; environments differ.