ARPU varies significantly based on geography, industry vertical, and service level. However, we can categorize MSPs into three general tiers based on their commercial maturity and service offerings.
| Tier | Monthly ARPU Range | Typical Service Inclusion |
|---|
| Basic / Reactive | $50 – $100 | RMM, basic antivirus, reactive helpdesk, and email hosting. |
| Standard Managed Services | $100 – $175 | Comprehensive support, cloud backups, MFA, and basic firewall management. |
| Advanced / Security-First | $175 – $300+ | EDR/MDR, vCISO services, compliance management, and strategic roadmap consulting. |
Scroll the table horizontally to see all columns →
If your MSP average revenue per user is consistently below $100, you are likely stuck in a reactive cycle. You are likely competing on price, which is a race to the bottom. At this level, it is difficult to invest in the talent or tools needed to provide proactive security, leading to higher client churn and lower employee satisfaction.
For most successful US-based MSPs, the goal is to move into the $150–$225 range. This level allows for a healthy margin, covers the cost of a modern security stack, and provides the budget for professional account managers who can drive further project revenue. This is the range where Totality Services operated effectively to reach that eight-figure exit.
Increasing your MSP average revenue per user isn't about just raising your prices by 10% and hoping no one notices. It requires a fundamental shift in what you deliver and how you communicate that value to the client. You have to move away from "fixing things" toward "managing risk."
One of the biggest drags on ARPU—and profitability—is supporting a "snowflake" environment where every client has different tools. By standardising your stack, you can bundle high-value services into your base seat price. If every user gets EDR, advanced email filtering, and identity management by default, your baseline ARPU naturally rises.
Instead of pricing based on your costs plus a markup, price based on the value of the outcome. If a law firm loses access to their data for a day, it costs them tens of thousands of dollars. Your service prevents that. When you frame the conversation around business continuity and risk mitigation, a $200 per user fee becomes a logical investment rather than a line-item expense to be negotiated down.
You cannot increase ARPU if you only talk to your clients when something is broken. Regular Security Reviews and QBRs are the commercial engine of an MSP. These meetings should be used to demonstrate the work you’ve done, show the threats you’ve neutralized, and point out the gaps that still exist. A recommendation that a client doesn't understand is unlikely to become a project, so clarity is essential here.
Cybersecurity is currently the single greatest driver of MSP average revenue per user. The threat landscape has changed so drastically that the "basic" security of five years ago is now considered negligence. This shift provides a massive opportunity for MSPs to add value and increase their recurring revenue.
Replacing traditional antivirus with Managed Detection and Response (MDR) or a 24/7 Security Operations Centre (SOC) can add $30 to $60 per user to your MRR. While these services have a higher cost to you, the perceived value to the client—knowing someone is watching their network 24/7—is immense. This is a primary example of how technical sophistication translates into commercial growth.
For clients in healthcare (HIPAA), finance (FINRA), or defence (CMMC), compliance is not optional. Providing compliance tracking, documentation, and reporting is a high-margin service that significantly boosts ARPU. It also makes your service "stickier," as the cost of switching to a non-compliant provider is too high for the client to risk.
Cyber insurance providers are now demanding specific controls be in place before they will even issue a policy. By aligning your service tiers with insurance requirements, you aren't just selling "tech"; you are helping the client maintain their insurability. This makes the discussion about MSP average revenue per user much easier because the alternative—no insurance coverage—is a non-starter for most business owners.
Even with a clear strategy, many MSP owners struggle to actually raise their ARPU. Usually, the resistance isn't coming from the market; it's coming from within the MSP itself. Internal hurdles, legacy mindsets, and fear of client pushback often stall progress.
The biggest hurdle to increasing ARPU is the fear that clients will leave if you raise prices or insist on a new security standard. In reality, the clients who leave because you are trying to make them more secure are often the clients you shouldn't have anyway. High-value clients understand that quality costs money. Low-value, price-sensitive clients are often the ones who take up 80% of your helpdesk time while providing only 20% of your profit.
Most MSPs have a few "charity cases"—clients who have been with them since the beginning and are still paying 2015 prices. These accounts pull your MSP average revenue per user down and consume resources that could be spent on more profitable clients. You must have the courage to either bring these clients up to your current standards or help them find a provider more suited to their budget.
Often, the technical team knows what the client needs, but the sales or account management team doesn't know how to sell it. Or, the sales team sells a "custom" solution that the technical team can't support efficiently. As Luis Navarro experienced while building his MSP, the magic happens when the commercial side of the business and the technical side are in total alignment. This is why MSP Agenda focuses on making complex security issues easy for non-technical stakeholders to understand.
Raising the MSP average revenue per user across your existing base is a delicate but necessary process. You can't just send an email announcing a price hike. You have to demonstrate that the increased cost is tied to increased protection and service quality.
- The "Security Upgrade" Approach: Instead of a price increase, announce a new "Mandatory Security Standard." Explain that the threat environment has changed and, to protect the client (and your own liability), you are upgrading all clients to a new baseline that includes X, Y, and Z.
- The Annual Review: Use the QBR to show the client their current risk profile. Compare it to the "Standard" profile you now offer. Show the gap. Most clients, when faced with a clear risk, will opt for the solution rather than the risk.
- Phased Rollouts: If you have a large client base, you don't have to re-price everyone on January 1st. Roll it out as contracts come up for renewal. This allows you to manage the workload and refine your messaging based on client feedback.
Don't guess what your clients need. Use data. If you can show a client that their employees are clicking on phishing links or that their hardware is three years out of warranty, the conversation about increasing their spend becomes grounded in reality rather than sales fluff. This is where a structured approach to Security Reviews becomes your most powerful sales tool.
When you successfully increase your MSP average revenue per user, the impact is felt across the entire organisation. It isn't just about the bank balance; it’s about the quality of the work environment and the level of service you can provide.
Higher ARPU allows you to:
- Hire Better Talent: You can afford to pay for senior engineers who can solve problems faster and more permanently.
- Reduce Noise: Standardised, higher-paying clients usually have better equipment and fewer "emergency" tickets, leading to a calmer service desk.
- Invest in Tools: You can afford the best-in-class security and automation tools that keep your margins high.
- Focus on Strategy: Instead of firefighting, you can spend time on vCISO services and long-term planning, which adds even more value to the client.
To improve your MSP average revenue per user, you need to track it accurately. This requires clean data in your PSA (Professional Services Automation) tool. You should be able to look at ARPU not just as a global average, but broken down by various segments.
Looking at a single average for the whole company can hide problems. You should analyse ARPU by:
- Client Size: Do 10-user firms have a higher ARPU than 50-user firms? (Usually, yes, because of minimum management fees).
- Industry Vertical: Are your medical clients paying more for compliance than your retail clients?
- Acquisition Date: Are your newer clients paying significantly more than your legacy clients? This shows how much "catch-up" work you have to do.
- Service Tier: What is the average ARPU for clients on your "Gold" plan versus your "Silver" plan?
ARPU is only half the story. You must also track the "Cost to Serve" (CTS) per user. If your ARPU is $200 but your CTS is $150, you are in a worse position than an MSP with an ARPU of $150 and a CTS of $70. The goal is to widen the gap between revenue per user and the cost of delivering that service through automation and standardisation.
Once you have mastered the basics of bundling and security, you can look at more advanced ways to push your MSP average revenue per user even higher. These tactics often involve specialised services that move beyond the desktop and server.
As the perimeter disappears, identity is the new firewall. Charging a premium for managing complex identity environments—Single Sign-On (SSO), Multi-Factor Authentication (MFA), and lifecycle management (onboarding/offboarding)—is a major ARPU booster. It is a high-value, high-visibility service that clients interact with every day.
Many clients are overspending on their cloud environments (Azure/AWS). By offering "Cloud Governance" as a recurring service, you can take a percentage of the savings you generate or charge a flat fee for continuous optimisation. This adds revenue without significantly increasing your support ticket volume.
With regulations like CCPA and GDPR, clients are increasingly worried about where their data lives and who has access to it. Providing data discovery and governance services allows you to move into the "data layer" of the business, which commands a much higher price point than the "infrastructure layer."
At the heart of the MSP average revenue per user discussion is a commercial reality that Luis Navarro understood well at Totality Services: you are running a business, not a charity. Your expertise has value, and your ability to protect a client’s livelihood is worth a premium.
When you stop seeing yourself as a "tech guy" and start seeing yourself as a "business protector," your confidence in your pricing increases. You stop apologizing for your rates and start explaining why those rates are necessary to provide the level of security the client requires. This shift in mindset is what separates the struggling small shops from the highly profitable, acquisition-ready MSPs.
The journey from a low-ARPU reactive model to a high-ARPU proactive model requires the right tools. We built MSP Agenda because we saw a gap in how MSPs handle the most critical part of the sales process: the Security Review. We knew that for an MSP to be successful, they needed a way to bridge the gap between technical teams and business owners.
MSP Agenda helps you increase your MSP average revenue per user by:
- Standardising Reviews: Ensure every client gets the same high-quality assessment, making it easier to identify upsell opportunities across your entire base.
- Clarifying Recommendations: We help you translate "technical debt" into "business risk," making it easier for clients to say "yes" to your recommendations.
- Creating Accountability: By tracking decisions and recommendations, you create a trail of value that justifies your monthly fees and project costs.
- Demonstrating Value: Our reports are designed to be read by MDs and FDs, not just IT managers. When they see the value, they are less likely to push back on price.
As Luis often says, "A recommendation that a client doesn't understand is unlikely to become a project." MSP Agenda ensures they understand, they value the work, and they are willing to pay for the expertise required to keep them safe.