MSP Penetration Testing Services: The Real Economics

CT
CyberOrbit Team
28 min read
Share

A client forwards you an email at 4pm on a Thursday. It is a security questionnaire from their biggest customer, and question 14 reads: "Has a third-party penetration test been performed against your environment in the last twelve months?" The client has highlighted it in yellow and added one line: "Can you handle this?"

You probably said what most managed service providers say. Let me find someone.

That request now lands several times a year across a client base of any size, and it will land more often next year. Every time you answer it with "let me find someone," you introduce a security firm into an account you spent years earning, hand over the most credibility-rich conversation in the relationship, and give a competitor with a virtual CISO offering a warm introduction you paid for.

This post lays out the three ways an MSP can answer that question, with real numbers on each: the cost of building a practice in-house, the margin behaviour of subcontracting per deal, and the unit economics of white-label resale. Then the one question that decides whether any of it is sellable, which has nothing to do with margin.

Your Clients Are Buying Pentests. The Only Question Is Whether They Buy Them From You.

The demand is not speculative and it is not driven by fear. It is driven by paperwork.

SOC 2 Type II pushes an independent test onto SaaS companies that have never had a security function, not because the standard names one but because auditors and readiness checklists treat it as the evidence that control monitoring actually works. PCI DSS 11.4 is explicit where SOC 2 is not: internal and external testing at least every twelve months and after any significant change, performed by a qualified internal resource or a qualified third party with organisational independence from the environment being tested. The Essential Eight expects validation of control effectiveness. NIS2 has dragged thousands of mid-sized European suppliers into scope. And underneath all of it, the fastest-growing driver: enterprise procurement teams sending questionnaires down their supply chain to companies with forty staff and no CISO.

Those companies cannot answer for themselves. Roughly half of small businesses rely on untrained internal staff or the owner to manage cybersecurity entirely, according to Cyber Readiness Institute data compiled in 2026 small business security statistics. They have no security team to hand the questionnaire to. They have you.

Here is the strategic point, worth more than any margin table below. Referring a pentest out is not a neutral act. It teaches your client that security expertise lives somewhere other than your company. The firm you refer them to will deliver the report, walk them through the findings, and at the end of that walkthrough mention that they also offer virtual CISO services and compliance readiness work. That is how testing firms grow, and you made the introduction.

What Triggers the Request

The trigger is almost always one of four events, and all four are predictable a year in advance.

A client starts a SOC 2 Type II process, usually because a deal stalled, and finds the testing line on the readiness checklist six weeks before fieldwork. See SOC 2 penetration testing requirements for what auditors expect in the evidence package.

A client touches card data, even peripherally, and their acquirer or QSA raises PCI DSS 11.4. That one carries a hard annual clock and a retest obligation after remediation, covered in PCI DSS 4.0 pentest requirements.

A client's enterprise customer sends procurement diligence. No framework, no auditor, just a vendor risk team that will not sign until there is a report. Now the largest single category.

A client's cyber-insurance renewal asks whether testing is performed and how often. The answer moves the premium.

Name the clients who will hit one of these four next year and you have your first revenue forecast for this service line.

50%
of small businesses rely on untrained internal staff or the owner to manage cybersecurity
When roughly half the SME market has nobody internal who can answer a security questionnaire, the provider holding the relationship gets asked first, and the answer you give decides who owns security in that account from then on.

The Three Doors: Build, Subcontract, or White-Label

There are exactly three ways to put penetration testing on your price list, and they are not variations on a theme. Different cost structures, different risk profiles, different failure modes.

Build. You hire testers, buy tooling, maintain a methodology, carry the insurance for offensive work, and sign reports under your own name. You own the methodology and the relationship completely. You also own a fixed cost that does not care how many reports you sell.

Subcontract per deal. Each time a client needs a test, you find a firm, get a quote, mark up the invoice, and coordinate delivery. No fixed cost. The client usually knows who did the testing, because the tester is on the scoping call and the report carries their logo.

White-label resell. You sign one wholesale partner, agree pricing and turnaround up front, and resell under your own brand. The report carries your identity, the sign-off is handled by the partner's certified security professional, and you own the client conversation from scoping through remediation.

The thesis: for an MSP with fewer than about fifty clients, the arithmetic decides this before strategy gets a vote.

ℹ️How we built these numbers
Salary figures come from ZipRecruiter's US penetration tester data, taken as a base-salary band for a mid-level practitioner rather than a specific offer. Every figure below is in US dollars and modelled on US market data, so convert and re-anchor before applying any of it to another market. Employer on-costs are modelled at 22 percent of base, covering payroll tax, retirement, leave, and benefits. Billable utilisation is modelled at 60 to 65 percent, which is the realistic ceiling once scoping calls, report writing, quality review, tooling maintenance, training, and leave are deducted. Resale price is modelled at $10,000 against a market band of $9,000 to $12,000 for a scoped SME engagement. Wholesale cost is modelled as a share of that resale price rather than as any specific vendor's rate card, because partner pricing is volume-tiered and quoted per relationship. Nobody publishes it, ours included, so treat the share as a planning placeholder and replace it with a real quote. Every one of these is an assumption, not a law. Replace each with your own numbers before you make a hiring decision.

Door 1: What Building a Pentest Practice Actually Costs

Most MSPs who consider building do the salary calculation and stop there. Salary is roughly a third of the real number.

ZipRecruiter's penetration tester salary data puts the US national average in the low six figures, with mid-level practitioners commonly landing between $120,000 and $155,000 in base salary. That is the number in the job ad. Here is the number in the P&L.

$120,000–$155,000
typical US mid-level penetration tester base salary, before on-costs, tooling, and certification
Add employer on-costs, tooling, certification, liability cover, and non-billable ramp and the true year-one cost lands between roughly $189,000 and $276,000.
Line item Annual cost
Base salary, mid-level tester $120,000 to $155,000
Employer on-costs (payroll tax, retirement, leave, benefits) at around 22% $26,000 to $34,000
Commercial tooling, licences, cloud test infrastructure $12,000 to $25,000
Certification and training budget $6,000 to $12,000
Professional indemnity and cyber liability uplift for offensive work $5,000 to $15,000
Recruitment plus non-billable ramp (first 8 to 12 weeks) $20,000 to $35,000
Year one total $189,000 to $276,000

Call it $200,000 in year one at the sensible end, settling to $170,000 to $240,000 once recruitment and ramp fall away.

Then there is utilisation, where build economics usually break. A tester is not billable forty hours a week. Between scoping calls, report writing, quality review, tooling maintenance, training, leave, and the administrative gravity of working inside an MSP, realistic billable utilisation lands around 60 to 65 percent. That is roughly one fully scoped SME engagement per week including its report, or about forty reports a year at the ceiling. NetSPI reaches the same conclusion from the buyer's side in its comparison of in-house versus third-party testing: in-house capability buys control, at a cost that only makes sense at volume.

Set forty reports against a $200,000 fixed cost and a $10,000 resale price. Break-even is twenty reports a year. Not twenty at a good margin. Twenty to cover the tester and nothing else, before an hour of account management time.

Now count your clients. An MSP with twenty clients selling to every single one, at a 100 percent attach rate nobody achieves, produces exactly twenty reports and exactly zero gross profit. At a realistic 40 percent attach it sells eight, books $80,000 against a $200,000 cost, and has bought a $120,000 annual loss to avoid making a referral.

A healthy 50 percent margin needs forty reports, the tester's absolute ceiling with no slack for a sick week or a difficult engagement. That means eighty to a hundred clients, or selling testing capacity to other MSPs, which is a different business with a different sales motion. Building works above a client count most MSPs do not have, and it works best for firms that intend to become testing firms.

The Hidden Cost Nobody Budgets: When Your One Tester Resigns

A single in-house tester is a single point of failure wearing a person's face. Offensive security practitioners change jobs frequently because the market bids for them constantly. When yours resigns you lose the methodology that lived in their head, the tooling nobody else can operate, the relationships built during walkthroughs, and the ability to fulfil every engagement on your forward book. Replacement takes three to six months, plus ramp.

During that window you subcontract anyway, at retail prices, to cover commitments you sold at your own margin. Redundancy means a second tester, which doubles the fixed cost and pushes break-even to forty reports before you earn a dollar. Which raises the obvious question: why carry the fixed cost at all when you can buy delivery one engagement at a time?

See what your external surface exposes, mapped to the controls it touches.

Run a free External Security Check →

Door 2: Subcontracting Per Deal (and Why the Margin Erodes)

Subcontracting deserves an honest defence. If you sell two tests a year it is the right answer and everything below is academic: no fixed cost, no capacity risk, no insurance uplift. Do not overengineer a service line that generates $10,000 of annual gross profit.

Pros
  • No fixed cost and no headcount on your balance sheet
  • Full flexibility to pick a specialist firm per engagement
  • No hiring, no tooling budget, no offensive-work insurance uplift
Cons
  • Inconsistent margin, because every engagement is a fresh quote
  • Variable two to six week timelines set by the vendor's backlog, not your client's audit date
  • Client-leakage risk: the firm you introduce gets a direct line to your client's decision maker
  • Report format, severity scale, and evidence quality change with every vendor

The model degrades as volume grows, in four specific ways.

You renegotiate every time. No volume relationship means no volume price. Each engagement is a fresh quote priced against the vendor's queue rather than your relationship. Your cost per report is a variable you do not control, which makes your resale price a variable you cannot commit to.

You cannot promise a timeline. Traditional engagements run two to six weeks from signed scope to delivered report, and the variance tracks the vendor's backlog rather than your client's audit date. When your client asks whether the report lands before fieldwork, you are guessing. See the penetration testing cost guide for how scope and turnaround interact at retail.

Every report looks different. Three vendors produce three formats, three severity scales, three levels of evidence quality. You cannot build a repeatable delivery process on that, and your clients cannot compare this year's report to last year's.

The account leaks. This is the real cost. The firm you introduced now has a direct line to your client's decision maker, formed during the most trust-dense conversation in their calendar. Margin compresses each time the subcontractor learns your client's name, and it does not compress on the invoice. It compresses on everything you might have sold that client afterwards. Subcontracting is a way to fulfil the demand. It is not a way to own it.

Door 3: The White-Label Margin Math

White-label resale fits the shape of most MSP businesses for one structural reason: it converts a fixed cost into a variable one. You buy delivery capacity per report and sell it per report, so the service line cannot lose money at low volume.

55–70%
gross margin on security attach revenue, versus 52% blended MSP gross margin
Benchmarks from Medha Cloud and Pharallax 2026 data: the blended MSP average climbed from 48 percent in 2022 to 52 percent in 2025, and almost all of that improvement came from the shift toward security services.

Here is a representative per-report P&L using market-typical ranges rather than any specific vendor's rate card.

Per report Amount
Resale price to client $9,000 to $12,000 (model: $10,000)
Wholesale cost 40 to 50 percent of resale (model: 45 percent)
Gross profit $5,500
Gross margin 55%
Your delivery hours (scoping call, client comms, report walkthrough, remediation session) 3 to 5 hours
Gross profit per delivery hour About $1,200

That last row is the one to sit with. A typical MSP recovers $150 to $200 per billable labour hour on managed services. A white-labelled test at these ranges returns six to eight times that per hour of your team's involvement, because the delivery labour is not yours.

Now the portfolio view. Take a 25-client MSP. At a 40 percent attach rate, ten clients buy an annual test, which is $55,000 of annual gross profit for about 45 hours of your team's time across the whole year. One working week, spread thin. At a 70 percent attach rate, seventeen or eighteen clients buy, which is roughly $95,000 of annual gross profit for 75 to 85 hours. Under two working weeks, with no headcount attached and no capacity risk on your balance sheet.

Both numbers sit above the 52 percent blended MSP benchmark. A 55 percent line is not exotic on its own. A 55 percent line that consumes no headcount is, and 55 to 70 percent security attach is what security-forward providers already achieve. MSP revenue benchmarks for 2026 show providers who repriced around a security-first stack commanding roughly a 42 percent premium on per-user pricing. The willingness to pay is already there.

Project Revenue or Recurring Revenue

How you package this has a valuation consequence, and the same gross profit is worth materially different amounts depending on which framing you pick.

$10,000 invoiced once a year, per client. At a 70 percent attach rate across 25 clients that is roughly $95,000 of annual gross profit, booked as non-recurring revenue. It is lumpy, it is renegotiated every twelve months, and your account manager re-sells the scope from scratch each cycle. Acquirers routinely discount project revenue heavily, or exclude it from the multiple entirely.

Converting between the two is a packaging decision rather than an operational one, which is precisely why it is worth making before your first client buys. Repricing a service your clients have already learned to treat as an annual project means renegotiating with every one of them at once.

The Number That Decides It

All three doors side by side. Every input is an assumption you should replace with your own numbers.

Assumptions: resale price $10,000 per report; build cost $200,000 fixed per tester per year at 40-report capacity; subcontract cost 55 percent of resale with limited volume leverage; white-label cost 50 percent of resale at low volume, 45 percent at mid volume, and high-30s at volume-tier pricing. The build column is a fixed cost divided by volume, so it is shown in dollars. The other two are variable costs, so they are shown as a share of resale, which is how partner and subcontract quotes actually behave.

Metric Build Subcontract White-label
Fixed annual cost $200,000 $0 $0
Cost per report at 5/yr $40,000 55% of resale 50% of resale
Cost per report at 15/yr $13,300 55% of resale 45% of resale
Cost per report at 40/yr $5,000 55% of resale high 30s % of resale
Gross margin at 5/yr Loss of $150,000 45% 50%
Gross margin at 15/yr Loss of $50,000 45% 55%
Gross margin at 40/yr 50% 45% 62%
Your delivery hours per report Full practice overhead 8 to 10 3 to 5
Time to first revenue 4 to 7 months 3 to 6 weeks 2 to 6 weeks to onboard, then contracted per-report turnaround
Capacity ceiling About 40 per tester, hard Vendor queue, unpredictable Contracted with partner

Read the gross margin rows first. Build is loss-making until roughly twenty reports a year and only turns attractive at the top of one tester's capacity. Subcontract is flat and safe and never improves. White-label is the only column that gets better as you grow, because volume tiers cut your cost while your delivery burden stays at a handful of hours per report.

🎯Key Takeaway
Below roughly twenty reports a year, building an in-house practice is arithmetic you lose: the fixed cost of one loaded tester swallows the gross profit of every report you can realistically sell. Above twenty, the constraint stops being cost and becomes hiring capacity, because a single tester tops out near forty reports and redundancy doubles the fixed cost before it doubles the ceiling. Most MSPs never reach the crossover, which is why the decision is usually made by the spreadsheet rather than by strategy.

If your honest forecast is under twenty reports a year, the table has answered the question, and the further under you sit the less debatable it gets. But margin only matters if the report is sellable, and that depends on something the table cannot show you.

⚠️Margin is not the risk. Rejection is.
A 55 percent margin on a report an auditor refuses to accept is not a 55 percent margin. It is a refund, a remediation call you did not budget for, and a client explaining to their biggest customer why the evidence they submitted did not hold. Get the sign-off question right before you get the pricing question right.

The Question That Decides Whether You Can Sell It At All: Who Signs the Report?

Six months after you sign a partner and put your logo on a deliverable, your client's auditor will ask three questions in a single breath. Who performed this test. What are their credentials. Where is the sign-off.

If you cannot answer all three in thirty seconds with a name, a credential, and a signature page, you do not have a security service. You have a PDF, and your client is about to discover that in front of their auditor, using a report with your brand on the cover.

White-label cannot mean anonymous. This is the distinction that catches MSPs out, because the phrase suggests the tester disappears. It does not. White-label means the commercial relationship is yours: your brand, your pricing, your client conversation. It cannot mean the attestation is untraceable. Not every framework behind this demand names a penetration test at all: PCI DSS 11.4 and DORA are explicit, while SOC 2, ISO 27001, and the Essential Eight are not, and the testing gets bought because auditors, insurers, and enterprise customers treat it as the evidence those frameworks ask for. What all of them converge on, and it has not changed in twenty years, is the shape of the evidence: attestation by an identified party independent of the client, about a defined scope, at a defined time. An auditor is not grading the testing. They are checking whether an accountable third party who is not the client asserted something specific about a specific environment at a specific time. A report with no identifiable signer fails that check regardless of how good the findings are.

This is the live question in the industry right now. The share of security professionals willing to rely on fully autonomous AI penetration testing fell from 29 percent to 9 percent in a single year, on Cobalt survey data reported by DarkReading. The reasons the coverage gives are practical rather than philosophical: coverage blind spots, false positives, and AI spend that ran past its budget. Read it as a verdict on the current generation of walk-away tooling, not on automation itself, which does most of the systematic work in modern testing and does it well. Our own reading adds a second reason the survey does not test directly, and it is the one that matters for anything carrying your brand: a machine-generated finding list with no professional standing behind it is not the same artefact as an attestation, whatever its technical quality. What auditors look for is covered in AI pentest report trust.

The consequence for you is inherited rather than shared. Put your logo on a thin report and the auditor does not push back on your partner. They push back on your client, who pushes back on you. The credibility loss is yours, and if the client concludes your security offering was a reselling arrangement dressed up as expertise, so is the churn.

So run the diligence before you sign, and run it in writing. These are the nine questions that separate a partner you can put your brand on from a vendor who will hand you a PDF.

Who signs the report, and what is their professional credential?
Does the signer's name appear on the deliverable my client receives?
Is the tested scope and the testing date fixed in the report itself?
What evidence accompanies each finding: real request, real response, reproduction steps?
Is a retest after remediation included, or is it a change order at full price?
What turnaround time is contractually committed, not just quoted?
Can the report carry our brand without obscuring the independent signer?
What professional indemnity and cyber liability cover does the partner hold?
What happens if a client's auditor rejects the report?

A partner who answers all nine without hesitating is a partner you can put your brand on. If any answer arrives as "we can discuss that later," you have your result.

Does white-labelling mean the tester's name is hidden?
No, and a partner who treats it that way is the wrong partner. White-labelling governs the commercial wrapper: your brand, your pricing, your client conversation. The attestation underneath still has to name someone. Auditors check that a named professional independent of the client validated the findings and attested to them, that the scope is defined and stated, and that the testing date falls inside the required window with evidence supporting each finding. A white-labelled report can satisfy all three whenever the partner's sign-off is present in the document, because your brand governs the commercial relationship while the signer governs the attestation. A report that is unsigned, or that anonymises the tester in the name of white-labelling, fails on the first criterion before an auditor reads a single finding. That is a partner selection problem, not a flaw in the white-label model.
Send the list. We will answer all nine in writing, including the signer's credential and what happens if a client's auditor rejects a report, before any pricing conversation.
Put these nine questions to us

How to Add Pentesting to Next Year's Catalogue

Once the sign-off question is settled, the rest is operational sequencing. Seven steps, in this order.

1
Pick an attach-rate target. Forty percent in year one is realistic. Multiply by client count to get your report forecast, and use that number for every decision below.
2
Choose two segments to lead with. Compliance-driven clients first, meaning anyone with a SOC 2, PCI, or Essential Eight obligation already on the calendar, because the budget exists and the deadline sells for you. Enterprise-facing clients second, meaning anyone whose customers send questionnaires.
3
Price against the market band, not your cost. Retail for a scoped SME engagement sits between $9,000 and $12,000 in most markets, and the band moves with scope size rather than with your cost of delivery. Price inside it. Cost-plus-thirty tells your client what you paid, and it caps your margin at whatever your partner happens to charge.
4
Decide project or MRR before you sell one. Repackaging after clients have bought is painful. If you want the valuation benefit, build the security tier now and sell the test as an inclusion.
5
Write the scoping intake. Domains and IP ranges, application count, authentication requirements, testing window, out-of-scope systems, emergency contact. One page, completable on a call by someone without a security background. With the client's authorisation, run our free subdomain finder across their domain before the call: it surfaces hosts their own inventory forgot, which is where scope disputes come from. A quick pass with the security header checker gives you something concrete to open the conversation with.
6
Brief account managers on the three objections. "We already run a vulnerability scanner" (a scan is not an independent test, and the auditor knows the difference: see where automated testing is genuinely enough and where it is not). "This is expensive" (compare against the deal blocked by question 14, not your monthly fee). "Can we do it ourselves" (independence means independent of the people who built and run the system: PCI DSS does allow a qualified internal resource who meets that bar, but almost no SME has one, and an enterprise customer's questionnaire asking for a third-party test does not accept an internal one at all).
7
Run the first two engagements with your best clients. Not your biggest, your friendliest. You want forgiving walkthroughs while you learn how the process feels, and two references before you announce to the base.

Announce in month two, not month one. The service line is real once you have delivered it twice.

Frequently Asked Questions

Will an auditor accept a white-labelled penetration test report?
In practice yes, provided the report names the party that performed the testing, names and credentials the professional who validated and signed it, defines the scope, and carries a date. Acceptance is always the individual auditor's judgement, so treat this as the condition for a clean conversation rather than a guarantee. What auditors assess is independence and attestation, not whose logo is on the cover. A white-labelled report runs into trouble when the white-labelling extends to hiding the signer, which is a partner selection problem rather than a flaw in the model.
How many pentests per year does an MSP need to justify hiring in-house?
At a fully loaded cost of roughly $200,000 per tester and a $10,000 resale price, break-even is about twenty reports a year, and a healthy 50 percent margin requires close to forty, which is one tester's realistic ceiling. Most MSPs need well over eighty clients at a strong attach rate before the numbers work, and a second tester for redundancy doubles the threshold.
Who signs a white-label penetration test report?
A certified security professional engaged by the delivery partner validates the findings and signs the technical attestation, and their name and credentials appear in the report. Your brand carries the commercial relationship and the client-facing presentation. If a partner cannot tell you the signer's name and credential before you sign, treat it as disqualifying.
Should an MSP sell pentests as projects or as recurring revenue?
Amortise into a monthly security tier where you can. The same annual test at roughly $850 per month removes the annual buying decision, smooths revenue, and counts toward recurring revenue mix, which is what MSP valuations are built on. Project revenue is frequently discounted or excluded from acquisition multiples.
What should an MSP ask a white-label pentest partner before signing?
Who signs, by name and credential. Whether the signer's name appears on the client's deliverable. Whether scope and date are fixed in the report. What evidence accompanies each finding. Whether retesting after remediation is included. What turnaround is contractually committed. Whether your brand can appear without obscuring the signer. What professional indemnity and cyber liability cover the partner holds. And what happens if a client's auditor rejects the report.
What compliance frameworks make SME clients buy penetration tests?
PCI DSS 11.4 and DORA set out testing requirements in the text of the standard itself. SOC 2 Type II, ISO 27001, NIS2, and the Australian Essential Eight do not name a penetration test, but all four drive the same purchase, because an auditor assessing whether controls are effective wants independent testing as the evidence. In practice the largest single trigger is not a framework at all: it is an enterprise customer's procurement questionnaire asking whether a third-party test was performed in the last twelve months. Cyber-insurance renewals are a growing fourth driver.
How much does it cost to hire a penetration tester in 2026?
Base salary for a mid-level practitioner commonly runs $120,000 to $155,000. Loaded with employer on-costs, tooling, certification budget, liability insurance uplift, recruitment, and non-billable ramp, true year-one cost lands between roughly $189,000 and $276,000. Budget the loaded figure, and plan for the day that person resigns.

Own the Answer Instead of Making the Referral

The next time question 14 lands in a client's inbox, the arithmetic above tells you which door to walk through, and the sign-off question tells you whether the door leads anywhere. Under twenty reports a year, building loses to a spreadsheet. Above that, the constraint becomes hiring rather than cost. Either way, the report has to name an independent certified security professional, a defined scope, and a defined date, or the margin does not exist.

CyberOrbit is built to survive that list. The client sets the targets, our platform scopes and runs the assessment against them, and the completed report submitted for certification is independently reviewed and signed by a certified security professional whose identity, certification, signing date, and tamper-evident content hash are printed in the report itself. Every finding carries the real HTTP request and response behind it. When a report is resold through the partner programme it carries your brand on the cover and keeps that signed certification page intact underneath, which is the answer to question two on the list above. We handle the systematic testing across the attack surface; genuinely novel business logic still rewards a human specialist, and we would rather tell your client that than have their auditor tell them.

If you want to judge the evidence quality before you talk commercials, run the free External Security Check against a domain you control and read the output for yourself.

Tell us how many clients you hold and how many are compliance-driven, and we will come back with the volume tier that applies and the turnaround we will commit to contractually.
Get partner pricing for your client count

The security writing, weekly

New posts as they land: findings from real assessments, what the regulatory changes actually mean, and the occasional teardown.

Privacy