MSP Pricing Models

Last updated

Why pricing is the decision you can't easily undo

Most technical founders agonize over their tool stack and wing their pricing. That's backwards. Analyses of small MSPs consistently estimate the average shop is roughly 30% underpriced, and the mechanism is brutal: your first price becomes a permanent anchor. Clients internalize a below-market rate as "fair," so every later correction reads as gouging. Worse, cheap pricing wins you clients you can't afford to serve properly, which means you can't fund the tooling and staff to serve them – a downward spiral that starts with one nervous quote.

Before you can price anything, you need to know exactly what you're selling – build your service catalog first. Then pick a model.

Per-device pricing

You charge a flat monthly rate per managed asset. Typical US ranges as of 2026: $25–$60 per workstation (some 2026 guides cite higher as tooling costs rose), $200–$500 per production server, and roughly $25–$75 per network device or firewall. The bundle usually covers monitoring, patching, AV/EDR, and basic remediation.

Pros: Dead simple to quote – count the assets, multiply. Fits shared-device environments (clinics, manufacturing floors, retail) where headcount and device count diverge.

Cons: Penalizes you as clients multiply devices per person, and invoices get haggled line-by-line ("do we really need the lab PC covered?"). See per-device pricing for the short version.

Best fit: Environments where devices are shared, headcount fluctuates, or devices-per-user is unpredictable.

Per-user pricing

You charge per human, covering all of that person's devices. This model won the remote-work era: with roughly half of remote-capable employees hybrid and each carrying two to three devices, one clean per-user line item is easier to explain, scales with headcount, and stops the device-counting arguments.

Typical US range as of 2026: $100–$250 per user per month all-in, with the fat middle at $125–$200. Entry-level bundles (monitoring, patching, help desk, AV, backup) run lower; fully managed with EDR and vendor management sits in the middle; premium tiers with 24/7 coverage, advanced security, and compliance reach $250–$300+. Major coastal metros price at the top of the range; secondary markets commonly land at $100–$150 for the same scope. Compliance-heavy verticals typically add 15–25%.

One trap: define "user" contractually. Is it a named person with a mailbox? Does a part-timer count? A shared warehouse login? A contractor with email but no device? If the contract doesn't say, the client will define it in their favor and your seat count will mysteriously shrink. See per-seat pricing and lock the definition into your MSA.

Many MSPs quietly run a hybrid – per-user plus per-server and per-network-device. That's fine if it's intentional and documented.

Tiered good-better-best

Package two to four bundles (e.g., Essential / Professional / Complete) at ascending per-user prices. Tiers give price-sensitive prospects a door in, give you a structured upsell path, and let you anchor the conversation on the middle tier. The common failure is building a cheap tier so thin (no EDR, no backup oversight) that it produces unprofitable, breach-prone clients – every tier should include your non-negotiable security baseline, with tiers differing on coverage hours, strategy depth, and advanced services.

Value-based pricing

Value-based pricing anchors the price to what the client avoids – downtime cost, breach cost, compliance exposure, the salary of the IT hire they don't make – rather than your cost to deliver. Pure cost-plus systematically underprices because it ignores risk transfer; pure value-based is hard to quote repeatably. The practical synthesis used by mature shops: cost-plus sets your minimum, value-based sets your ask.

A la carte vs. all-in

The a-la-carte path prices every component separately: base support, plus EDR, plus backup, plus security awareness training, each its own line. It feels transparent but invites procurement to shop each line item, makes every renewal a negotiation, and lets clients decline exactly the security items you'll be blamed for when things go wrong.

Mature MSPs converge on the opposite: one all-in seat price that includes everything recurring – licenses, security, backup, support. TruMethods (Gary Pica) tracks this as the "all-in seat price" (AISP): total monthly revenue from a client divided by seats. Their data shows the average MSP's AISP is under $100/seat, while Pica argues the modern benchmark should move toward $300/seat at a 70% gross margin as security scope expands. Whatever number you land on, the all-in structure simplifies buying, hides individual tool margins from scrutiny, and gives you a single metric to manage upward. (For the unlimited-support variant, see all-you-can-eat pricing.)

The numbers around the model

Whichever model you pick, the deal has more moving parts than the seat price:

  • Onboarding fee: charging roughly 1x your monthly recurring fee – "the 13th month" – is the standard rule of thumb (observed range: one to two months of MRR). Onboarding is genuinely expensive (agent deployment, documentation, cleanup, credential capture), and a fee filters out non-serious buyers. Some MSPs waive it as a closing concession on three-year terms.
  • Out-of-scope and project rates: typical 2026 benchmarks are $125–$250/hr (most SMB MSPs at $150–$200), more in high-cost metros or for senior specialists, and $250–$500/hr for after-hours emergencies. State in the contract that anything not listed in the catalog bills at these rates.
  • Minimum engagement: most established MSPs won't take clients below roughly $500–$1,000/month, often expressed as a 5- or 10-seat minimum. Fixed per-client overhead – onboarding, documentation, tooling minimums, QBRs – makes tiny clients structurally unprofitable, and a floor filters for clients who value IT.

Pricing your floor from cost basis

Don't guess your minimum – compute it. The TruMethods-style discipline: tie every recurring cost to a per-seat unit cost. Sum your tool stack per seat (RMM, EDR, backup, email security, licenses – see your tool stack), allocate labor by realistic tickets-per-seat and loaded tech cost, add a share of overhead, then apply your gross margin target – 70% GM is the best-in-class benchmark. If your delivery cost is $60/seat, a 70% margin puts your floor at $200/seat. Quote below your computed floor and you're paying to work. Track the result in your KPIs.

Increases and indexing

Vendors raised EDR, M365, and backup prices sharply through 2024–2025, and MSPs without escalator clauses ate every hike. Standard contract terms run 12–36 months, and contracts increasingly include an annual CPI-plus-tool-cost escalator so increases happen automatically instead of requiring an awkward conversation. If you must reprice legacy clients, the pattern that works: lead with a service review of what's changed over 12–24 months, give 60–90 days notice, and tie the increase to scope. Experience reports say roughly 5–10% push back, most accept, and the rare departures were unprofitable anyway. Put the escalator in the contract from day one and you mostly avoid the conversation.

Bottom line

Price at market from client number one – typically $125–$200+ per user all-in as of 2026 – because repricing later is far harder than pricing right now. Use per-user unless the environment is genuinely device-centric, bundle security into one all-in seat price, compute your floor from per-seat cost at a 70% gross margin target, charge ~1x MRR for onboarding, hold a $500–$1,000 monthly minimum, and put a CPI-plus-tool-cost escalator in the contract. Then go win deals on value, not discounts – that's a sales problem, not a pricing one.