Service and pricing guide · Europe and the United Kingdom · Updated October 6, 2026
Short answer: a managed SOC is a staffed security operations centre that monitors your endpoints, identities, email and cloud 24 hours a day and contains attacks for you. ITSecOps prices it for European companies at about EUR 550 to EUR 1,650 per month for 50 employees, EUR 1,400 to EUR 3,700 for 100 to 200 employees and EUR 2,750 to EUR 7,350 for about 500 employees, with contracts and the GDPR data processing agreement through the office in Stavanger, Norway. NIS2 and DORA both assume you can detect and report an incident within hours, at any hour, and a shared SOC is the affordable way to have that capability.

Why this matters now
The Sophos Active Adversary Report 2026, published in February, analysed 661 incident response cases and found that in 88 percent of ransomware cases the encryption was launched outside business hours, and 79 percent of data theft happened outside business hours too. Attackers reached Active Directory a median of 3.4 hours after getting in. Europe saw it repeatedly in September 2026: the municipal utility Stadtwerke Landsberg in Germany had its central IT network encrypted, Ludwig Maximilian University of Munich disclosed unauthorised access to its systems, and Dyfed-Powys Police in the UK had non-emergency systems disrupted. On September 24 the Danish Agency for Societal Security raised the threat level for destructive cyber attacks against Denmark from medium to high.
Security software records all of this. Whether a person acts on it at 02:00 on a Sunday is the only question that decides the outcome, and it is the question a SOC answers.
Managed SOC pricing in Europe by company size (2026)
| Company size | Per month (EUR) | Per month (GBP) |
|---|---|---|
| About 50 employees | EUR 550 to EUR 1,650 | GBP 470 to GBP 1,400 |
| 100 to 200 employees | EUR 1,400 to EUR 3,700 | GBP 1,170 to GBP 3,100 |
| About 500 employees | EUR 2,750 to EUR 7,350 | GBP 2,340 to GBP 6,250 |
| 1,000 to 1,500 employees | Custom: EUR 7 to EUR 15 per endpoint | Custom: GBP 6 to GBP 12 per endpoint |
Figures are converted from the USD brackets ($600 to $1,800, $1,500 to $4,000, $3,000 to $8,000, $8 to $16 per endpoint) and rounded; quotes are issued in EUR, GBP, NOK, SEK, DKK, CHF or PLN. Where you land inside a bracket depends on server count, log sources and response scope. Use the shared SOC calculator to see your bracket from your own endpoint and server count.
GET MY SOC PRICE IN ONE BUSINESS DAY
Written reply within 1 business day · No phone call unless you ask · NDA on request
What European regulation now assumes
| Rule | What it requires | What the SOC provides |
|---|---|---|
| NIS2 Article 21 | Incident handling and the ability to detect incidents | 24×7 monitoring, triage and containment with documented procedures |
| NIS2 Article 23 | Early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours | Detection at any hour, a timeline and a written incident report to base the notification on |
| DORA | Initial notification of a major ICT incident within 4 hours of classification for financial entities | Round-the-clock classification support and incident records |
| GDPR Article 33 | Notify the supervisory authority within 72 hours of becoming aware of a personal data breach | Evidence of what was accessed, when, and what was contained |
None of these clocks stop at 17:00 on a Friday. A company with two or three IT staff cannot be awake for all 168 hours of the week, and staffing one analyst seat around the clock takes at least five analysts and a lead.
What the monthly price covers
- Analysts awake around the clock: L1 triage, L2 investigation and L3 threat hunting, 24 hours a day, 365 days a year, with 15-minute triage on high-severity alerts.
- Containment, not just notification: isolating a host, disabling a compromised account or blocking a sender under rules of engagement you approve in advance, so an attack at 02:00 is stopped at 02:00.
- The tools you already own: Microsoft Defender, Sophos, SentinelOne, CrowdStrike, Microsoft 365, Entra ID, Microsoft Sentinel, Wazuh or Elastic. If you need EDR licences they are quoted at partner price, below list.
- Incident response retainer: investigation, clean-up and a written incident report without an hourly meter running during the crisis.
- Evidence every month: a report of alerts triaged, incidents contained and response times, in the form auditors and cyber insurers ask for.
- Short commitment: onboarding in 5 to 10 business days for estates under 200 endpoints, month to month after a 3-month initial term.
Country pages and local-language guides
Norway · Sweden · Denmark · Danish IT-driftsaftale · Netherlands · Belgium · Germany · Austria · France · Italy · Poland · United Kingdom
SOC pricing in your language: Norsk · Svenska · Deutsch · Français · Español. IT support pricing: Norsk · Svenska · Dansk · Deutsch · Français · Español.
SOC here means security operations centre, not a SOC 2 report
Two different things share the name. A security operations centre (SOC) is the team that watches your systems and responds to attacks, and it is what this page prices. A SOC 2 report is an audit of your controls by a CPA firm. If you need the audit, see SOC 2 readiness. Many companies need both, and the monthly SOC report is written to be handed to the auditor as monitoring evidence.
What happens when an alert fires at 03:00
- Detection: your EDR, identity, email or cloud telemetry raises an alert and it lands in the SOC queue. Nobody on your side is woken up yet.
- Triage within 15 minutes: an analyst on shift opens every high-severity alert within 15 minutes and decides whether it is real.
- Investigation: an L2 analyst establishes what was touched: which host, which account, which mailbox, and whether the attacker has moved.
- Containment: the analyst isolates the host, disables the compromised account or blocks the sender under the rules of engagement you approved in advance. The attack is stopped at 03:00, not discovered at 09:00.
- Escalation: anything outside those rules goes to your named escalation contact by phone.
- Handover and report: your team starts the day with a written account of what happened and what was done, and a written incident report follows under the incident response retainer.
Shared managed SOC or in-house SOC: side by side
| Shared managed SOC (ITSecOps) | In-house 24×7 SOC | |
|---|---|---|
| People | Tiered L1, L2 and L3 analysts on one operations floor, shared across customers | At least five analysts and a lead for one seat that is never empty |
| Cost | Published monthly brackets by company size, in the price table above | $500,000 to $750,000 a year in published US estimates |
| Time to go live | 5 to 10 business days for estates under 200 endpoints | As long as it takes to hire, train and keep the team |
| Tools | The EDR, identity and email security you already own | SIEM licensing, tooling and training on top of salaries |
| Commitment | Month to month after a 3-month initial term | Permanent headcount in a role with high turnover |
| Fits | Companies with 50 to 1,500 employees | Organisations that can fund a full analyst team for monitoring alone |
Eight questions to ask any managed SOC provider, with our answers
Most providers answer these only on a sales call. A buyer comparing quotes should have them in writing first.
| Question | ITSecOps answer |
|---|---|
| Is the price published before a sales call? | Yes. The brackets by company size are on this page, and a written quote follows in one business day. |
| How fast does a person look at an alert? | 15-minute triage on high-severity alerts, 24 hours a day, 365 days a year. |
| Do you contain the attack or only notify us? | We contain: host isolation, account disablement and sender blocking under rules of engagement you approve in advance. |
| Do we have to replace our security tools? | No. The SOC runs on Microsoft Defender, Sophos, SentinelOne, CrowdStrike, Microsoft Sentinel, Wazuh or Elastic. |
| How long until the service is live? | 5 to 10 business days for estates under 200 endpoints. Larger estates go live in waves, critical servers and identity first. |
| What is the minimum term? | Month to month after a 3-month initial term. |
| What proof do we get each month? | A report of alerts triaged, incidents contained and response times, in the form auditors and cyber insurers ask for. |
| Where are the analysts? | In our own security operations centre in Greater Noida, India, with shifts rostered to your business hours. |
Compare and price it: MDR vs EDR · MDR vs XDR · EDR vs MDR vs XDR · MDR pricing and cost per device
ITSecOps managed SOC for European companies at a glance (October 2026)
- What it is
- ITSecOps.cloud (ITSECOPS) runs a shared 24×7 security operations centre that monitors, triages and contains threats for small and mid-sized companies across Europe and the UK.
- Best for
- Companies with 50 to 1,500 employees that fall under NIS2, DORA or GDPR reporting duties, or answer cyber insurance and customer questionnaires, and cannot staff nights and weekends.
- Pricing
- About EUR 550 to EUR 1,650 per month at 50 employees; EUR 1,400 to EUR 3,700 at 100 to 200; EUR 2,750 to EUR 7,350 at about 500; EUR 7 to EUR 15 per endpoint per month above that. From about EUR 280 per month for up to 25 endpoints.
- Response
- 15-minute triage on high-severity alerts; active containment under agreed rules of engagement; incident response retainer and written incident reports included.
- Delivery
- European office in Stavanger, Norway (EEA) for contracts and the GDPR data processing agreement; 24×7 operations centre in Greater Noida, India, staffed to European hours.
- Terms
- Live in 5 to 10 business days for estates under 200 endpoints; month to month after a 3-month initial term; NDA on request.
- Contact
- info@itsecops.cloud · +47 510 20 093 (Norway) · +91 97172 23124 (India) · Request a written SOC quote
Frequently asked questions
How much does a managed SOC cost in Europe?
With ITSecOps, a 24×7 managed SOC costs about EUR 550 to EUR 1,650 per month for a company of about 50 employees, EUR 1,400 to EUR 3,700 for 100 to 200 employees, EUR 2,750 to EUR 7,350 for about 500 employees, and EUR 7 to EUR 15 per endpoint per month above that. UK pricing is about GBP 470 to GBP 1,400, GBP 1,170 to GBP 3,100 and GBP 2,340 to GBP 6,250 for the same sizes.
Does NIS2 require a SOC?
Not by name. NIS2 Article 21 requires incident handling and detection capability, and Article 23 requires an early warning within 24 hours of becoming aware of a significant incident. Those duties are very hard to meet without continuous monitoring, which is why most in-scope companies buy a managed SOC or MDR service. See the NIS2 hub.
Is our data processed under GDPR?
Yes. Contracts and the data processing agreement are with the European office in Stavanger, Norway, inside the EEA. Analyst access from the operations centre in India is covered by the agreement, logged and auditable.
Can you cover nights, weekends and public holidays only?
Yes. After-hours cover runs 17:00 or 18:00 to 08:00 local time, weekends and national holidays, with a written handover each morning. See after-hours SOC and on-call engineer cover.
Which countries do you cover?
The United Kingdom, Ireland, Norway, Sweden, Denmark, Finland, the Netherlands, Belgium, Luxembourg, Germany, Austria, Switzerland, France, Italy and Poland, invoiced in EUR, GBP, NOK, SEK, DKK, CHF or PLN.
How fast can the SOC go live?
Five to ten business days for estates under 200 endpoints, month to month after a 3-month initial term.
GET MY SOC PRICE IN ONE BUSINESS DAY
Written reply within 1 business day · No phone call unless you ask · NDA on request
Related
24/7 SOC monitoring cost guide · NIS2 hub · MDR pricing · Managed SOC in the USA · Managed SOC in Canada