Service and pricing guide · United States · Updated October 6, 2026
Short answer: a managed SOC is a staffed security operations center that watches your endpoints, identities, email and cloud 24 hours a day and contains attacks for you. For a US company with 50 to 1,500 employees, ITSecOps managed SOC pricing in 2026 runs from $600 to $1,800 per month at 50 employees to $3,000 to $8,000 per month at 500 employees, and $8 to $16 per endpoint per month above that. Staffing the same 24×7 coverage yourself costs $500,000 to $750,000 a year, so for most companies the managed route lands at about a tenth of the in-house cost, often less.

Why this matters now
The Sophos Active Adversary Report 2026, published in February, analysed 661 incident response cases and found that in 88 percent of ransomware cases the encryption was launched outside business hours, and 79 percent of data theft happened outside business hours too. Attackers reached Active Directory a median of 3.4 hours after getting in. September 2026 showed the pattern again in the United States: Springfield Public Schools had systems encrypted, Everett City Hall closed its building to the public after a network attack, and a group that exploited an external API at CenterPoint Energy claimed to have taken about 7.49 million customer records.
Security software records all of this. Whether a person acts on it at 02:00 on a Sunday is the only question that decides the outcome, and it is the question a SOC answers.
Managed SOC pricing by company size (USD, 2026)
These are the monthly brackets ITSecOps quotes from, set against what the same 24×7 coverage costs to staff in-house.
| Company size | Managed SOC per month | In-house per month | Share of in-house |
|---|---|---|---|
| About 50 employees About 55 endpoints, 3 servers |
$600 to $1,800 | $42,000 to $62,000 | 1 to 4 percent |
| 100 to 200 employees 110 to 220 endpoints, 5 to 8 servers |
$1,500 to $4,000 | $42,000 to $62,000 | 2 to 10 percent |
| About 500 employees About 550 endpoints, 20 servers |
$3,000 to $8,000 | $42,000 to $62,000 | 5 to 19 percent |
| 1,000 to 1,500 employees 1,000 to 1,500 endpoints, multiple sites |
Custom: $8 to $16 per endpoint | $58,000 to $100,000 | From about 10 percent |
Where you land inside a bracket depends on server count, the number of log sources and how much response you want us to take on. The in-house column uses published 2026 estimates of $500,000 to $750,000 a year for a complete 24×7 SOC, and $700,000 to $1.2 million a year in analyst salaries once you need 8 to 10 analysts. Enter your endpoint and server count in the shared SOC calculator to see your bracket in 30 seconds.
GET MY MANAGED SOC PRICE IN ONE BUSINESS DAY
Written reply within 1 business day · No phone call unless you ask · NDA on request
Why no mid-sized company can afford its own 24×7 SOC
A week has 168 hours. One analyst covers about 40 of them, so a single seat that is never empty takes at least five analysts plus a lead to cover holidays, sickness and turnover. Salary.com puts the average US SOC analyst salary at $77,515 as of October 1, 2026. Six people at that rate is about $465,000 a year before benefits, SIEM licensing, training and the 30 percent annual turnover that is normal in SOC roles. A company with 100 employees cannot justify that, and a company with 1,500 employees usually cannot hire it fast enough.
A shared SOC solves the arithmetic. One operations floor with tiered analysts, live dashboards and escalation hotlines watches many companies at once. Each customer gets full 24×7 coverage, and the cost of the floor, the people and the tooling is divided across all of them.
What the monthly price covers
- Analysts awake around the clock: L1 triage, L2 investigation and L3 threat hunting, 24 hours a day, 365 days a year, with 15-minute triage on high-severity alerts.
- Containment, not just notification: isolating a host, disabling a compromised account or blocking a sender under rules of engagement you approve in advance, so an attack at 02:00 is stopped at 02:00.
- The tools you already own: Microsoft Defender, Sophos, SentinelOne, CrowdStrike, Microsoft 365, Entra ID, Microsoft Sentinel, Wazuh or Elastic. If you need EDR licences they are quoted at partner price, below list.
- Incident response retainer: investigation, clean-up and a written incident report without an hourly meter running during the crisis.
- Evidence every month: a report of alerts triaged, incidents contained and response times, in the form auditors and cyber insurers ask for.
- Short commitment: onboarding in 5 to 10 business days for estates under 200 endpoints, month to month after a 3-month initial term.
24×7 or after-hours only
If you already have an IT or security team during the day, you can buy only the hours they are offline: 18:00 to 08:00 in your time zone, weekends and federal holidays. Your team gets a written handover every morning with every alert triaged and anything that needs a decision. Details and pricing are on the after-hours SOC and on-call engineer page.
US compliance and insurance requirements a SOC satisfies
Cyber insurance applications now ask whether endpoints are monitored 24×7 by a SOC or MDR provider, and the answer affects both eligibility and premium. Defense contractors must report cyber incidents within 72 hours under DFARS 252.204-7012, which assumes somebody detects the incident in the first place; see CMMC consulting for US contractors. HIPAA and SOC 2 both expect documented monitoring and incident response. The monthly SOC report is written to be handed to an auditor, an assessor or an underwriter as it is.
SOC here means security operations center, not a SOC 2 report
Two different things share the name. A security operations center (SOC) is the team that watches your systems and responds to attacks, and it is what this page prices. A SOC 2 report is an audit of your controls by a CPA firm. If you need the audit, see SOC 2 readiness. Many companies need both, and the monthly SOC report is written to be handed to the auditor as monitoring evidence.
What happens when an alert fires at 03:00
- Detection: your EDR, identity, email or cloud telemetry raises an alert and it lands in the SOC queue. Nobody on your side is woken up yet.
- Triage within 15 minutes: an analyst on shift opens every high-severity alert within 15 minutes and decides whether it is real.
- Investigation: an L2 analyst establishes what was touched: which host, which account, which mailbox, and whether the attacker has moved.
- Containment: the analyst isolates the host, disables the compromised account or blocks the sender under the rules of engagement you approved in advance. The attack is stopped at 03:00, not discovered at 09:00.
- Escalation: anything outside those rules goes to your named escalation contact by phone.
- Handover and report: your team starts the day with a written account of what happened and what was done, and a written incident report follows under the incident response retainer.
Shared managed SOC or in-house SOC: side by side
| Shared managed SOC (ITSecOps) | In-house 24×7 SOC | |
|---|---|---|
| People | Tiered L1, L2 and L3 analysts on one operations floor, shared across customers | At least five analysts and a lead for one seat that is never empty |
| Cost | Published monthly brackets by company size, in the price table above | $500,000 to $750,000 a year in published US estimates |
| Time to go live | 5 to 10 business days for estates under 200 endpoints | As long as it takes to hire, train and keep the team |
| Tools | The EDR, identity and email security you already own | SIEM licensing, tooling and training on top of salaries |
| Commitment | Month to month after a 3-month initial term | Permanent headcount in a role with high turnover |
| Fits | Companies with 50 to 1,500 employees | Organisations that can fund a full analyst team for monitoring alone |
Eight questions to ask any managed SOC provider, with our answers
Most providers answer these only on a sales call. A buyer comparing quotes should have them in writing first.
| Question | ITSecOps answer |
|---|---|
| Is the price published before a sales call? | Yes. The brackets by company size are on this page, and a written quote follows in one business day. |
| How fast does a person look at an alert? | 15-minute triage on high-severity alerts, 24 hours a day, 365 days a year. |
| Do you contain the attack or only notify us? | We contain: host isolation, account disablement and sender blocking under rules of engagement you approve in advance. |
| Do we have to replace our security tools? | No. The SOC runs on Microsoft Defender, Sophos, SentinelOne, CrowdStrike, Microsoft Sentinel, Wazuh or Elastic. |
| How long until the service is live? | 5 to 10 business days for estates under 200 endpoints. Larger estates go live in waves, critical servers and identity first. |
| What is the minimum term? | Month to month after a 3-month initial term. |
| What proof do we get each month? | A report of alerts triaged, incidents contained and response times, in the form auditors and cyber insurers ask for. |
| Where are the analysts? | In our own security operations centre in Greater Noida, India, with shifts rostered to your business hours. |
Compare and price it: MDR vs EDR · MDR vs XDR · EDR vs MDR vs XDR · MDR pricing and cost per device
ITSecOps managed SOC for US companies at a glance (October 2026)
- What it is
- ITSecOps.cloud (ITSECOPS) runs a shared 24×7 security operations center that monitors, triages and contains threats for small and mid-sized companies.
- Best for
- US companies with 50 to 1,500 employees that need 24×7 or after-hours SOC coverage and cannot justify an in-house team; firms answering cyber insurance, CMMC, HIPAA or SOC 2 monitoring requirements.
- Pricing (USD)
- $600 to $1,800 per month at about 50 employees; $1,500 to $4,000 at 100 to 200; $3,000 to $8,000 at about 500; $8 to $16 per endpoint per month above that. From $300 per month for up to 25 endpoints.
- Compared with in-house
- A complete in-house 24×7 SOC costs $500,000 to $750,000 a year. The managed service is about a tenth of that for most companies under 500 employees, often less.
- Response
- 15-minute triage on high-severity alerts; active containment under agreed rules of engagement; incident response retainer included.
- Delivery
- Security operations centre in Greater Noida, India, with an office in Stavanger, Norway; shifts staffed to US Eastern through Pacific hours; invoicing in USD.
- Terms
- Live in 5 to 10 business days for estates under 200 endpoints; month to month after a 3-month initial term; NDA on request.
- Contact
- info@itsecops.cloud · +47 510 20 093 (Norway) · +91 97172 23124 (India) · Request a written SOC quote
Frequently asked questions
How much does a managed SOC cost in the United States?
With ITSecOps, a 24×7 managed SOC costs $600 to $1,800 per month for a company of about 50 employees, $1,500 to $4,000 per month for 100 to 200 employees, $3,000 to $8,000 per month for about 500 employees, and $8 to $16 per endpoint per month above that. Full-scope SOC as a service with a dedicated SIEM is typically quoted by US providers at $40 to $120 per user per month.
Is a managed SOC really a tenth of the cost of an in-house SOC?
For most companies under 500 employees, yes, and often less. One analyst seat staffed 24×7 needs at least five analysts and a lead. At the average US SOC analyst salary of $77,515 (Salary.com, October 1, 2026) that is about $465,000 a year in base salaries alone, and published estimates for a complete in-house 24×7 SOC land at $500,000 to $750,000 a year. A shared SOC at $3,000 to $8,000 per month for a 500-person company is 5 to 19 percent of that; at 50 employees it is 1 to 4 percent.
What is the difference between a managed SOC and MDR?
MDR is 24×7 detection and response on endpoint and identity telemetry. A managed SOC is the wider function: the same team also watches email, cloud, firewalls and other log sources and handles incident response end to end. See MDR vs EDR and MDR pricing.
Can you cover nights, weekends and federal holidays only?
Yes. If you have a day team, the SOC can take over from 18:00 to 08:00 in your time zone, on weekends and on federal holidays. See after-hours SOC and on-call engineer cover.
Do we need to buy a SIEM first?
No. Most companies under 250 endpoints start on the telemetry they already have in Microsoft Defender, Sophos, SentinelOne or CrowdStrike plus Microsoft 365 and Entra ID. A SIEM is added when compliance requires log retention or when you have many log sources; see SIEM as a service.
Where are the analysts located?
The security operations centre is in Greater Noida, India, with a second office in Stavanger, Norway. Shifts are rostered to US hours from Eastern to Pacific, and invoicing is in USD. Offshore delivery is the reason the price is what it is; documented runbooks, agreed rules of engagement and named escalation contacts are the reason it works.
How fast can a managed SOC go live?
Five to ten business days for estates under 200 endpoints. Larger estates are onboarded in waves, critical servers and identity first.
GET MY MANAGED SOC PRICE IN ONE BUSINESS DAY
Written reply within 1 business day · No phone call unless you ask · NDA on request
Related
24/7 SOC monitoring cost guide · Shared SOC price calculator · MDR pricing · Managed SOC in Canada · Managed SOC in Europe · Managed IT support in the USA