# MSP Revenue Model

The MSP revenue model is the commercial framework through which a Managed Service Provider generates income by delivering IT services, cybersecurity, and consulting to business clients. Unlike traditional 'break-fix' models that rely on hourly billing for reactive repairs, the modern MSP model prioritises proactive, recurring revenue (MRR) by charging a predictable monthly fee for ongoing management, monitoring, and security.

The **MSP revenue model** is the commercial framework through which a Managed Service Provider generates income by delivering IT services, cybersecurity, and consulting to business clients. Unlike traditional "break-fix" models that rely on hourly billing for reactive repairs, the modern MSP model prioritises **proactive, recurring revenue (MRR)** by charging a predictable monthly fee for ongoing management, monitoring, and security.

- **Recurring Revenue:** The foundation of the model, typically delivered through per-user or per-device pricing.
- **Project Revenue:** One-time professional services such as cloud migrations or hardware refreshes.
- **Transactional Revenue:** The resale of hardware, software licenses, and cloud subscriptions.
- **Security-as-a-Service:** Specialised high-margin layers that address modern compliance and risk management.

Building a successful MSP isn't just about being good at technology. It’s about building a predictable, scalable commercial engine. **Luis Navarro**, the founder of MSP Agenda, learned this over 15 years growing Totality Services from a small startup into a highly profitable MSP with an eight-figure exit. 
 
 Luis wasn't the technical lead; his focus was on the commercial reality of the business—sales, marketing, and the **MSP revenue model**. He learned that clients don't buy "managed services"; they buy uptime, security, and peace of mind. To deliver that while remaining profitable, an MSP must master its pricing and service delivery structure.

## The Evolution of Managed Services Pricing
In the early days of IT support, the "break-fix" model was king. If something broke, you fixed it and sent a bill. While simple, it was a terrible business model for both parties. The client suffered downtime, and the MSP only made money when the client was in pain. It created a conflict of interest that hindered growth.

The modern **MSP revenue model** flips this dynamic. By charging a fixed monthly fee to keep things running, the MSP’s goals align with the client’s. If everything works perfectly, the MSP is more profitable because labour costs are low, and the client is happy because they have no downtime.

### Common Revenue Streams for MSPs
| Revenue Type | Description | Typical Margin |
| --- | --- | --- |
| Managed Services (MRR) | Ongoing support, monitoring, and maintenance. | 50% – 70% |
| Security Services | SOC, MDR, EDR, and compliance management. | 40% – 60% |
| Professional Services | One-off projects like server migrations or office moves. | 30% – 50% |
| Product Resale | Selling hardware (laptops, firewalls) and software. | 10% – 20% |
| Cloud Subscriptions | Microsoft 365, Google Workspace, AWS/Azure. | 5% – 15% |

## Core Models: Per-User vs. Per-Device
One of the most frequent debates in the industry is whether to price based on the number of users or the number of devices. While both have their place, the trend in the United States and global markets has shifted significantly toward the **per-user** model.

### The Per-User Pricing Model
This is generally considered the most "modern" approach. You charge a flat fee for every employee the client has. This user typically gets support for their laptop, their mobile device, their cloud identity (M365/Google), and their home office setup.

**Pros:**

 Easy for the client to understand and forecast.
 Covers the modern "work from anywhere" reality.
 Simplifies billing as the client’s HR headcount changes.

**Cons:**

 Can be risky if a user has an unusually high number of devices.
 Requires clear "fair use" policies in the contract.

### The Per-Device Pricing Model
This model charges for every endpoint managed—servers, workstations, and mobile devices. It was the standard when everyone worked in a physical office with a single desktop computer.

**Pros:**

 Very precise; you know exactly what you are managing.
 Good for environments with shared workstations (like manufacturing or retail).

**Cons:**

 Becomes complex as users add tablets, smartphones, and home PCs.
 Billing can become a mess of small additions and subtractions every month.

## The "All-In Seat Price" (AISP)
The most successful MSPs, including those Luis Navarro scaled to eight-figure valuations, often utilise the **All-In Seat Price**. Instead of line-iteming every single service (antivirus, backup, helpdesk, patching), you bundle everything into a single, high-value price point.

For example, instead of charging $100 for support and $50 for various tools, you charge $175 per user for a "Total Care" package. This creates a "black box" for your margins. As you find more efficient tools or automate your service delivery, your margins increase without the client asking for a discount on a specific line item.

Crucially, this model should include a regular rhythm of **Security Reviews**. When you bake these into your service, you aren't just a "tech guy"—you are a commercial advisor. This helps you maintain high retention and naturally leads to project revenue when the review identifies a need for new infrastructure or advanced security layers.

## Tiered Pricing Structures
Even with an all-in model, many MSPs offer tiers to give clients a choice. This is often described as the "Good, Better, Best" approach. However, in today’s threat environment, we recommend a "Secure, More Secure, Compliant" approach.

### 1. The Foundation Tier
Includes basic helpdesk support, patch management, and standard antivirus. This is often a "legacy" tier that experienced MSPs are moving away from because it doesn't provide enough protection for the client or enough margin for the MSP.

#### 2. The Professional/Growth Tier
The sweet spot for most SMBs. Includes everything in the foundation plus **Advanced Security** (MDR/EDR), email security, and multi-factor authentication (MFA) management. This tier is where the **MSP revenue model** starts to become truly profitable.

#### 3. The Compliance/Enterprise Tier
Designed for clients in regulated industries (Finance, Healthcare, Defence). It includes everything in the lower tiers plus 24/7 SOC monitoring, advanced encryption, and regular **Security Reviews** tailored to specific regulatory frameworks like HIPAA or CMMC.

## Driving Profitability Through Project Revenue
While MRR is the lifeblood of an MSP, **Project Revenue** is the turbocharger for profitability. However, many MSPs struggle to generate consistent project work, leading to "lumpy" cash flow. The secret to fixing this lies in how you handle recommendations.

When Luis Navarro co-founded Totality Services, he realised that technical teams are often great at identifying problems but struggle to explain **why a client should care**. A recommendation for a new firewall isn't about "packet inspection"—it's about "preventing a total business shutdown that costs $10,000 per hour."

By standardising these recommendations through a clear, commercial lens, you turn the **MSP revenue model** into a proactive engine. Instead of waiting for things to break, you are constantly reviewing the client's risk profile and proposing projects that lower that risk. This not only increases your revenue but also makes the client safer and more reliant on your expertise.

## Key Metrics to Track
To know if your revenue model is working, you need to look beyond your bank balance. You need to understand your **commercial benchmarks**.

- **Contribution Margin:** The revenue from a client minus the direct costs (licenses and engineer labour). Aim for 60%+.
- **Average Revenue Per User (ARPU):** The total monthly fee divided by the number of users. In the US, high-performing MSPs often see $150–$250+ per user.
- **Client Lifetime Value (LTV):** How much a client is worth over the average 3-to-5-year contract life.
- **Cost of Goods Sold (COGS):** The direct costs associated with delivering your service. Monitoring this prevents "margin creep."

### Example Profitability Comparison
| Metric | Standard MSP | High-Growth MSP |
| --- | --- | --- |
| Pricing Model | A La Carte / Per Device | All-In Per User |
| ARPU | $75 - $100 | $175 - $250 |
| Focus | Technical Support | Security & Business Risk |
| Quarterly Reviews | Reactive / Informal | Standardised / Commercial |
| Gross Margin | 35% - 45% | 55% - 70% |

## The Role of Security in the Revenue Model
Security is no longer an "add-on." It is the core of the **MSP revenue model**. Ten years ago, security was a firewall and a piece of antivirus software. Today, it involves identity management, dark web monitoring, security awareness training, and incident response.

The mistake many MSPs make is absorbing these new costs into their existing price points. This is a recipe for bankruptcy. Instead, security should be the primary driver for price increases. When you explain to a client that the threat landscape has changed—and you show them the specific gaps in their current defence—they are usually willing to pay more for the protection.

This is why **Security Reviews** are so critical. They provide the evidence needed to justify a higher seat price or a significant security project. Without a structured way to communicate this risk, you are just another vendor asking for more money.

## Scaling the Model: The Totality Services Journey
Luis Navarro’s journey with Totality Services is a masterclass in refining the **MSP revenue model**. Starting as a small team, the business eventually served over 150 clients across London and Johannesburg. The growth wasn't just about hiring more technicians; it was about standardising the sales and relationship side of the business.

Luis spent years sitting between technical teams and business leaders. He saw firsthand that technical jargon kills deals. By translating complex cybersecurity issues into simple, commercially meaningful choices, he was able to drive higher recurring revenue and more frequent project wins. This commercial clarity is what made the business attractive for an eight-figure acquisition.

After exiting, Luis realised that most MSPs still struggle with this transition. They have the technical talent, but their **Security Reviews** are inconsistent or too technical for the client to understand. That’s why he founded MSP Agenda—to help MSPs run consistent reviews, communicate risk clearly, and turn recommendations into profitable action.

## Common Challenges in the Revenue Model
Even with a great plan, the **MSP revenue model** faces several common hurdles:

### 1. Service Creep (Scope Creep)
This happens when you agree to a fixed fee, but the client starts asking for things outside the contract—like helping an executive’s kid with their home gaming PC or managing a complicated custom software integration. If you don't bill for these, your effective hourly rate plummets.

#### 2. The "Commodity Trap"
If you sell "IT support," you are a commodity. There will always be someone cheaper. To escape this, you must sell **business outcomes**. You aren't fixing computers; you are ensuring the accounting firm can bill their hours during tax season without a ransomware interruption.

#### 3. Underpricing Projects
Many MSPs use their helpdesk staff for projects, leading to delays and poor service on both fronts. Project work should be priced at a premium and, ideally, handled by a dedicated team or scheduled during quiet periods to protect the margin of your recurring service.

## Best Practices for a Profitable MSP Revenue Model
1. **Review your pricing annually:** Inflation and the cost of security tools are always rising. Your contracts should have a built-in annual increase (usually 3-5% or CPI-linked).
2. **Automate everything:** Every minute an engineer spends on a manual task is a minute of lost profit. Invest in RMM (Remote Monitoring and Management) and PSA (Professional Services Automation) tools that actually work.
3. **Standardise your stack:** If you manage five different types of firewalls, your team will never be experts at any of them. Pick one and tell your clients that's what you support.
4. **Don't hide your value:** Send a monthly "Executive Summary" that shows how many threats you blocked and how many patches you applied. If the client doesn't see what you're doing, they'll eventually wonder why they're paying you.
5. **Focus on high-value clients:** Not all revenue is good revenue. A "D-list" client who calls every five minutes and complains about every bill is actually costing you money. Fire them and make room for "A-list" clients who value your partnership.

---

Source: https://mspagenda.com/blog/msp-revenue-model
Last updated: 2026-04-03
