Building Your Service Catalog
Last updated
Why the catalog comes first
You cannot price what you haven't defined, and you cannot sell what you can't state plainly. The service catalog – the written list of exactly what you deliver, what you don't, and what each piece costs you – precedes pricing and sales, because both collapse without it. Quote without a catalog and every proposal is bespoke; deliver without one and every "can you also just..." becomes free work. The classic new-MSP failure mode is a verbal deal with undefined scope, and the catalog is the first half of the fix (the contract is the second).
The catalog is an internal discipline document first and a sales document second. Write it before your first proposal, even if you have zero clients.
The core managed offering
Your base bundle is what every managed client gets, no exceptions. As of 2026 the standard core looks like:
- Monitoring and alerting – RMM agent on every endpoint, network monitoring, actionable alerting you actually respond to.
- Patch management – OS and third-party patching on a defined cadence, with reporting.
- Help desk – business-hours support through defined channels (email, portal, phone), every request ticketed, response times per your SLA.
- Security baseline – EDR on every endpoint, MFA enforcement, email security, DNS filtering, security awareness training. Make the baseline non-negotiable: a client who declines EDR is a breach you'll be blamed for.
- Backup oversight – managing and verifying backup/DR jobs, alert response, periodic restore tests. (Whether backup licensing itself is included or an add-on, the oversight is core.)
- vCIO touch and QBR – a strategic review cadence, technology roadmap, and budget forecast, even in lightweight form.
If an item is in the core, it's in every deal. Resist building a stripped tier that removes the security baseline to hit a price point – that's how you acquire clients whose incidents cost more than their contract.
The exclusions list
The exclusions section earns more money than the inclusions. Enumerate what is not covered and state that anything not listed defaults to a quote or time-and-materials at your current rates. Standard exclusions:
- Projects – migrations, office moves, server refreshes, new deployments: quoted separately, fixed-fee or T&M.
- After-hours work – outside business hours bills at the emergency rate unless the client buys a 24/7 tier.
- New-hire hardware – procurement, provisioning, and the hardware itself for headcount growth is a billable event (or a defined per-onboarding fee), not free labor.
- Third-party application development and deep LOB app support – you coordinate with the vendor; you don't write or debug their software.
- Anything not listed – the catch-all line that makes the list enforceable.
Add-on services
Add-ons attach to the core for clients who need them, at their own price:
- Compliance program management – HIPAA, CMMC, SOC 2 support priced as a program, not ad-hoc hours; see compliance as a service. Compliance-heavy verticals typically support 15–25% higher pricing overall.
- Co-managed IT – a defined subset of the catalog (tools, escalation, projects) delivered alongside internal IT. Kaseya's 2025 benchmark found 61% of MSPs saw co-managed revenue rise, so it's worth a defined offering rather than one-off deals.
- Advanced security – managed SOC/MDR, vulnerability management beyond the baseline; a serious add-on security stack typically retails at $25–$50/user/month on top of base.
- HaaS – hardware bundled into the monthly seat. Caution for new MSPs: you front the capital, carry asset-tracking overhead and default risk, and non-payment leaves you repossessing laptops. The common advice is to skip HaaS early or use third-party financing so the balance-sheet risk isn't yours.
Structuring tiers
Two to four tiers is the norm; three is the sweet spot. Every tier includes the full security baseline – tiers differ on coverage hours, strategy depth, and advanced services, not on whether the client is protected. A typical shape:
| Essential | Professional | Complete | |
|---|---|---|---|
| Monitoring, patching, help desk | Business hours | Business hours | Extended / 24×7 P1 |
| Security baseline (EDR, MFA, email security, SAT) | Included | Included | Included |
| Backup oversight | Included | Included | Included + DR testing |
| Managed SOC / MDR | – | Included | Included |
| vCIO / QBR cadence | Annual review | Quarterly | Quarterly + roadmap & budget |
| Compliance program support | – | – | Included |
Price the middle tier as your default recommendation and let the top tier anchor. Map tiers to per-user prices using your pricing model.
Map every line to a tool and a unit cost
For each catalog item, record two things: which tool or process delivers it and what it costs you per unit (per seat, per device, per client). "EDR" maps to your specific EDR product at its per-endpoint wholesale cost; "backup oversight" maps to your backup platform plus a labor estimate; "help desk" maps to PSA seat costs plus loaded tech time per ticket. This table – the catalog joined to your tool stack – is what makes your pricing floor computable instead of guessed, exposes which offerings are margin-negative, and tells you instantly what a vendor price hike does to each tier. One tool per function: stack sprawl multiplies training, documentation, and error surface, and margin leaks trace directly to it.
Scope-creep defense
The catalog's daily job is defending scope. The operating rule: everything not listed is a quote. When a client asks for something outside the catalog, answer, "That is outside the agreement, so I will send a quote," not with a favor. Undocumented favors compound: they train the client that scope is negotiable, they never make it into tickets or time entries, and they quietly destroy agreement margins – below roughly 45% gross margin on managed services, mispricing or scope creep is usually the culprit. A defined catalog turns every out-of-scope request from an awkward confrontation into a routine sales opportunity at your project rates (typically $125–$250/hr as of 2026).
The catalog and your MSA
The catalog is the source of truth for the service attachments in your MSA. The standard structure – an evergreen master agreement with services defined in attachments incorporated by reference – means the MSA body rarely changes while service attachments are generated from the current catalog. Scope, exclusions, and out-of-scope rates in the contract should be copied from the catalog, never improvised per deal. If the catalog and your contracts disagree, you have two sources of truth and, in a dispute, effectively none.
Review it annually
The catalog is a living document. Review it once a year (a fixed calendar quarter, before contract renewals): retire services nobody buys, promote add-ons that every client takes into the core, fold in new baseline expectations – the security baseline in particular has expanded every year – and refresh unit costs against current vendor pricing so your floor math stays honest. Feed the changes into renewals via the escalator and scope conversation, with evidence from your QBRs.
Where to start
Write version one this week, and keep it small: one core bundle with the six standard components, one explicit exclusions list ending in "anything not listed is quoted," and at most one add-on you can genuinely deliver. Map each line to its tool and unit cost, then use that to set prices and generate your first MSA service attachment. Add tiers when prospects force the conversation, not before. A one-page catalog you enforce beats a beautiful three-tier matrix you discount away – and it's the foundation everything else in starting your MSP builds on.