One of the most common questions in the industry is, "What should I charge?" In the US market, MSP per user pricing typically ranges from $100 to $250 per user, per month. Where you fall on that spectrum depends on your geographic location, the complexity of the client's requirements, and the depth of your security stack.
To calculate your rate, you must first understand your Cost of Goods Sold (COGS). This includes:
-
The cost of your toolset (RMM, EDR, Backup licenses).
-
The cost of labour (the hourly rate of your engineers multiplied by the average time spent per user).
-
Overheads (office space, insurance, sales).
-
Desired profit margin (aim for 50-70% gross margin on managed services).
Low pricing is a trap. If you charge $75 per user but your tool stack costs $40 and your labour costs $30, you are left with $5 per user. One difficult support ticket or a minor security incident will wipe out your profit for the entire year. High-growth MSPs focus on value, not price. They explain that the fee isn't just for "fixing things," but for protecting the business from downtime and cyber threats.
When Luis grew Totality Services to over 150 clients, he realised that the most profitable clients weren't the ones with the lowest support needs, but the ones who were fully standardised on the MSP’s recommended stack. A higher per user price allows you to include better tools, which in turn reduces the number of support tickets, increasing your net profitability.
Clear boundaries are essential. If you don't define what is not included, you will suffer from "scope creep," where your team performs project work under the guise of daily support. This kills margins and burns out staff.
- Hardware Purchases: Laptops, servers, and networking gear should always be billed separately.
- Project Work: Moving an office, migrating to a new cloud platform, or major infrastructure overhauls.
- After-Hours Support: Unless specifically included in a "premium" tier, support outside of 9-to-5 should carry an additional cost.
- On-site Visits: Many MSPs bill for travel or on-site time if the issue could have been resolved remotely.
By keeping these items separate, you ensure that your recurring revenue remains stable while your project revenue provides the "bonus" profit that helps you scale. It also makes your Security Reviews more effective, as you can clearly present projects as necessary upgrades rather than things the client "thought were already covered."
In the current threat environment, you cannot separate "IT Support" from "Cybersecurity." However, many MSPs struggle with how to price security. Should it be an add-on, or should it be baked into the per user fee? Our experience suggests that baking a "Base Security Standard" into every seat is the only way to operate safely.
If you make security optional, some clients will decline it to save money. When they eventually get breached, they will still blame you. By including core security—like EDR, MFA management, and email filtering—in your standard MSP per user pricing, you protect the client and your own reputation. You are essentially saying, "This is the minimum requirement to be a client of our firm."
Once the base seat price is established, you can use regular audits to identify gaps. This is where a structured approach to reviews becomes vital. We founded MSP Agenda because we saw too many MSPs failing to communicate the value of these security additions. A recommendation that a client doesn't understand is unlikely to become a project. Using a clear framework helps you translate technical risks into business outcomes, naturally leading to increased revenue per user over time.
While we advocate for the per user model, it helps to understand how it stacks up against the alternative. In the early 2000s, per device was the industry standard. Today, it is largely relegated to specialised environments (like manufacturing plants with many shared kiosks) or lower-maturity MSPs.
| Feature | Per User Pricing | Per Device Pricing |
|---|
| Billing Simplicity | High (matches HR headcount) | Low (requires constant auditing) |
| Profitability | Higher (captures multi-device users) | Lower (often misses mobile/home tech) |
| Client Perception | Fair (supports the person) | Frustrating (fees for every gadget) |
| Scalability | Easy (scales with client growth) | Manual (requires inventory tracking) |
Scroll the table horizontally to see all columns →
The per user model is inherently more commercially minded. It treats the client relationship as a partnership in supporting their workforce, rather than a tally of their hardware assets. For an MSP looking to scale toward a high-value exit, the clean, predictable nature of per user MRR is much more attractive to potential acquirers.
No model is perfect. The most frequent challenge with MSP per user pricing is defining what constitutes a "user." Does a part-time receptionist count the same as a full-time software engineer? What about a generic "info@" email address or a shared warehouse terminal?
The "Light User" Dilemma: Some clients will argue they shouldn't pay full price for a staff member who only checks email once a week. You must be firm here. That light user still needs an M365 license, still needs EDR, still needs their password reset, and still represents a security hole if not managed. Most successful MSPs have a "minimum seat count" (e.g., 10 users) to ensure the account is profitable regardless of individual user activity.
Shared Workstations: In industries like retail or healthcare, you might have 50 employees sharing 10 computers. In these specific cases, a hybrid model or a "per device" exception might be necessary. However, keep these exceptions rare to maintain the simplicity of your billing engine.
If you are currently billing per device or hourly, moving to a per user model can feel daunting. You might worry about price hikes causing client churn. The key is to frame the transition not as a price increase, but as a "Service Evolution."
- Audit Your Current Costs: Before talking to clients, calculate exactly what each client costs you today under your old model.
- Standardise the Stack: Ensure every user will receive the same high level of security and support tools.
- The "Co-Term" Strategy: Don't change everyone at once. Transition clients as their contracts come up for renewal or during their next major Security Review.
- Communicate the Value: Explain that the new model covers them wherever they work, on whatever device they use, providing them with total cost certainty.
During his time at Totality Services, Luis found that clients actually appreciated the shift once they understood it. It made their internal budgeting easier. They no longer had to ask, "Will it cost more if I buy my team tablets?" They knew the answer was "No," provided their headcount stayed the same.
The per user model only works if you are disciplined about standardisation. If you support five different antivirus products and three different backup solutions across your client base, your labour costs will skyrocket. Your engineers will spend too much time switching contexts and learning different interfaces.
To maximise your margins, you must mandate your "Standard Stack." Every user you bill for should be protected by the same EDR, the same backup agent, and the same MFA protocol. This allows your team to become experts in those specific tools, significantly reducing the time it takes to resolve issues. Efficiency is the bridge between revenue and profit.
Standardisation also makes your account management much simpler. When you sit down for a QBR or a security briefing, you aren't talking about a random collection of tools. You are talking about your "Secure User Standard." It’s much easier to explain why a client needs to upgrade when you can point to a clear standard that all your successful clients follow.
While a single flat fee is simple, many growing MSPs find success with a tiered "Good-Better-Best" approach. This allows you to cater to different budget levels while still maintaining the per user structure.
- Tier 1: Foundation. Essential support + basic security. Target for budget-conscious clients in low-risk industries.
- Tier 2: Professional. The "Standard." Includes advanced EDR, security awareness training, and vCIO services. This should be your primary offering.
- Tier 3: Compliance/Enterprise. For clients in regulated industries (HIPAA, CMMC). Includes SIEM/SOC, advanced encryption, and frequent auditing.
This structure gives the client a sense of choice while ensuring that even your "lowest" tier is still profitable and secure. It also provides a natural path for "upselling" as the client’s business grows and their risk profile changes.
At the end of the day, your pricing model is a reflection of your business strategy. If you want to be a low-cost provider, you will always be fighting for pennies. If you want to build a high-value, highly profitable MSP that is attractive to buyers, you need a model that scales cleanly and demonstrates clear value.
MSP Agenda was born from the experience of actually building one, growing one, and successfully exiting one. We know that the goal isn't just to "close the deal," but to close the right deal at the right price. MSP per user pricing provides the framework for those right deals. It allows you to move away from being a "fix-it" shop and toward being a strategic partner.
When you align your pricing with the way your clients work, and back it up with standardised tools and clear communication, you create a resilient business. You stop worrying about how many hours your technicians logged and start focusing on how many users you are protecting. That is the shift that takes an MSP from a lifestyle business to an enterprise-grade asset.