White-Label SOC for MSPs: Add 24/7 Security Without the Overhead

Launch enterprise-grade security services in 72 hours, not months. CyberQuell runs the monitoring and response under your brand, while you own the client relationship and keep the recurring margin.

Free first step: we estimate the SOC revenue your client base can add
72-hr

Go-live time

15-min

Response time

99.9%

Uptime SLA

Want a detailed quote?
Fill out the form and our partner team will reach out the same business day with a detailed quote and onboarding plan.
No obligation. We reply the same business day.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Your clients get enterprise-grade, certified security expertise, across Microsoft, Google Cloud, Palo Alto and more, delivered entirely under your brand.

Microsoft Certified: Cybersecurity Architect Expert badge

Microsoft Cybersecurity Architect (Expert)

Microsoft Certified: Security Operations Analyst Associate badge

Microsoft Security Operations Analyst

Palo Alto Networks PSE Foundation badge

Palo Alto PSE Foundation

Google Cloud Certified badge

Google Cloud Certified

Oracle Cloud Infrastructure Architect Professional badge

Oracle Cloud Infrastructure Architect

Built on Microsoft Sentinel & Defender · Connected via Azure Lighthouse

Why most MSPs struggle to offer SOC services

You know security drives margins. But building a SOC from scratch means expensive tooling, scarce talent, and months of setup before you can bill a single client.

Hiring and keeping SOC analysts

Enterprise SOC analysts are expensive and scarce. Building a 24/7 team adds heavy salary, training and turnover costs that quietly break your margins.

Expensive SIEM, SOAR and threat-intel tooling

Enterprise platforms carry large upfront and ongoing costs. Licensing, storage and tuning add up fast, long before you see any return on the investment.

Compliance reporting eats time

Auditable, client-ready reports for SOC 2, HIPAA, PCI-DSS or GDPR need process, tooling and skilled staff. That is operational overhead many MSPs can't absorb.

24/7 coverage stretches your team

Round-the-clock monitoring means night shifts, rotations and extra headcount. Small teams can't cover every hour and stay responsive during the day.

Long setup delays revenue

Onboarding tenants, tuning detections and validating playbooks can take weeks to months. Slow time-to-value stalls your sales and delays recurring revenue.

Tool sprawl and alert overload

Juggling point tools, each with its own console, creates alert noise and manual correlation work. A managed SOC consolidates it and cuts analyst burnout.

The MSP question we always get

"How much can I actually make?"

White-label SOC is one of the highest-margin recurring services an MSP can add. You pay our published partner rates, resell security at your own price, and keep the difference every month, for every client.

  • Published rate card below. The same rates for everyone, no haggling.
  • Upsell 24/7 security to clients you already manage, with no new headcount.
  • Rates step down as your device count grows. No setup fees, no hidden costs.
  • At typical market prices, partners keep a 35–50% margin on every seat.
Published partner rates

Your cost vs. your revenue

200 minimum6,000
none1,000+
$/ endpoint$/ server

MSPs typically resell managed detection at $7–15 per endpoint. We default to $10, the middle of that range. Set yours.

Your partner cost / mo
$3,840
You bill clients / mo
$6,500
Your monthly margin
$2,660 · 41%
See the cost breakdown
Lock in this quote

Partner cost uses the published CyberQuell rate card, including volume bands and base-fee waivers. Client prices are examples, you set your own. Minimum billing 200 endpoints or 50 servers. Microsoft licences and tax not included.

Two service tiers you can resell. One dedicated option.

Pick the level of SOC you want behind your brand. Start clients on Watch, upsell Defend as the value lands, and you can change tiers at any time.

WATCH

Managed monitoring

We watch alerts 24/7, investigate, and tell your team when action is needed.

from $1,488/mo

Minimum billing: 200 ep or 50 servers

  • 24/7 L1 + L2 analyst monitoring
  • Alert triage & escalation
  • Priority IR SLA, isolation & containment
  • White-labeled monthly report
  • Monthly review call
Get my Watch quote
MXDR

Dedicated SOC team

Analysts who work only on your clients. For large or regulated books of business.

Custom

Scoped per engagement

  • Analysts exclusive to your environment
  • Bespoke threat intel & detection engineering
  • Embedded, continuous tuning
  • Custom integrations & API support
Discuss MXDR

Watch vs. Defend vs. MXDR

What each tier includes, so you know exactly what you're reselling.

Swipe sideways to compare each tier →
Service level Watch Defend MXDR
24/7 L1 triage + L2 investigationDedicated
Incident commander on call
Proactive threat hunting
Detection & alert tuningStandardContinuous, tailoredEmbedded
Full IR (forensics, root cause, report)Add-on (time & materials)
Isolated malware sandboxing
White-labeled reportsMonthlyWeekly + monthlyWeekly + monthly
Quarterly business review
Dedicated success manager
Analysts exclusive to your clients
Minimum billable size200 ep / 50 sv200 ep / 50 svScoped
Best for reselling asEntry security monitoring planYour flagship managed security offerEnterprise / regulated clients

The published partner rate card

Same rates for everyone, no haggling. The highlighted maths in the calculator above comes straight from these tables.

Endpoint band Watch Defend
Monthly, per endpoint. Volume bands apply to your whole count across all clients.
Base fees are charged on top of the per-device rates. Endpoint base fee: $864 Watch / $1,440 Defend per month, waived when servers are added. Server base fee: $504 / $840 when endpoints are also billed, or $1,008 / $1,680 for servers on their own.
Volume bands apply to your whole count. Cross into a lower band and the cheaper rate applies to every device, across all your clients combined.
Billing: monthly, or save 10% by paying the year upfront. 1-year service term. Minimum billing: 200 endpoints or 50 servers.
Not included: Microsoft licences, which your clients keep buying directly because we never resell licences, and tax.

The gap between our rate and retail is your margin

Same footprint, 500 endpoints and 50 servers, monthly. What that costs you on Defend, next to what clients pay for comparable services at retail.

Your margin at retail
up to $16,285/mo

You pay $3,840. Clients pay $5,169–$20,125 for comparable managed security. The difference is yours, every month.

$3,840
Your cost / mo
1.3–5.2×
Retail markup
Huntress
published retail
$5,169
1.3×
Sophos MDR Complete
published retail
$7,763
2.0×
Arctic Wolf MDR
published retail
$9,200
2.4×
CrowdStrike Complete
published retail
$20,125
5.2×
In-house 24/7 SOC
build it yourself
~$145,833
38×
Competitor figures are published list pricing and public benchmarks; actual quotes vary. In-house figure is a typical fully-loaded annual SOC cost divided by 12, and extends far beyond this scale.

Building a SOC in-house vs. partnering with CyberQuell

The same 24/7 outcome, without the year-one cost, the hiring, or the wait. Here is the honest comparison.

Swipe sideways to compare →
What it takes Build your own SOC White-label with CyberQuell
Time to first client liveWeeks to months of setup and tuning72 hours
Upfront costSIEM, SOAR and threat-intel licensing, storage, tuningNo setup fees, published monthly rate card
Analysts to hireA full 24/7 rota: salaries, training, turnoverNone, our certified analysts cover 24/7
Tooling to maintainYour team owns updates, detections, playbooksFully managed on Microsoft Sentinel & Defender
Compliance reportingBuilt and staffed by youCo-branded, audit-ready reports included
Your brandYours, but months from revenueYours from day one, we stay invisible

What's included in your white-label SOC

Not a vague promise. Here is the concrete service scope every partner gets from day one.

Coverage

24/7 analyst monitoring

Certified SOC analysts and threat hunters watching your client tenants around the clock, every day of the year.

Tooling

SIEM, SOAR & threat intel

We operate Microsoft Sentinel and Defender end to end — tuning, detections, playbooks. Your clients keep their own Microsoft licences; we never resell.

Response

Triage & escalation flow

Automated triage with playbook-backed escalation. Confirmed incidents come to you with context and remediation guidance.

Reporting

White-labeled reports

Monthly executive reports on Watch; weekly threat summaries plus quarterly business reviews on Defend. All under your logo, ready to hand to each client.

SLA

15-minute response, 99.9% uptime

SLA-backed response times so you can make firm commitments to your clients with confidence.

Compliance

SOC 2, HIPAA, PCI, ISO support

Audit-friendly evidence and reporting that support your clients' compliance obligations across major frameworks.

The technology behind your SOC

Microsoft-native at the core — your clients licence it, we run it. We also operate Google Cloud, Palo Alto and other stacks where your clients need them.

Endpoint

Microsoft Defender for Endpoint

Detect threats, investigate alerts, and isolate infected devices across your client fleet.

SIEM & SOAR

Microsoft Sentinel

Alerts from every client tenant correlated in one place, with automated playbook response.

Access

Azure Lighthouse delegation

Scoped, time-bound, fully audited access to client tenants. You or your client can revoke it at any time.

Email

Defender for Office 365

Email threat protection with Safe Links and Safe Attachments, monitored alongside endpoints.

Sandbox

Isolated sandbox analysis (Any.Run)

Suspicious files detonated in an isolated sandbox. Your clients' data never touches public scanners.

Frameworks

MITRE ATT&CK mapping

Detections mapped to ATT&CK techniques, with evidence that supports SOC 2, HIPAA, PCI and ISO obligations.

From first call to live monitoring

No mystery process. A clear path from enquiry to your first protected client, live within three days of connection.

Step 1

Discovery call

We confirm your endpoint and server counts across clients, and pick the right tier together. Watch, Defend, or MXDR.

Step 2

Final scoped quote

Your exact price from the published rate card, plus your billing choice: monthly, or 10% off annual upfront.

Step 3

Onboarding & secure connection

Partner account, NDA, and connection to your first client environment via Microsoft Azure Lighthouse, with zero disruption.

Step 4

Baseline & tuning

Our analysts review the current Sentinel and Defender configuration, close gaps, and tune alerts so your team only sees threats that matter.

Step 5

Go live in 72 hours

Continuous monitoring and incident response activate within three days of connection. Triaging alerts, correlating events, escalating confirmed incidents.

Step 6

Ongoing reporting & reviews

White-labeled reports on your tier's cadence, review calls, and continuous detection tuning as threats evolve.

Partner Kickstart Programme

See your SOC revenue opportunity before you commit

A complimentary partner readiness and revenue assessment. When you're ready, start with a paid 30-day pilot on a single client tenant before rolling out across your book.

We review requests the same business day. No obligation, fully confidential.
  • 30–45 minute assessment call

    A focused review with a partner specialist to map your stack, telemetry and client needs.

  • Revenue opportunity estimate

    A calculation of the recurring revenue you can add by selling white-label SOC to your book.

  • One-page launch roadmap

    Practical next steps, a recommended pricing approach, and a go-live timeline to share with leadership.

  • 30-day pilot - your next step

    When you're ready, validate detections, reports and workflows on one client tenant before full production. Low commitment, real results.

What stands behind the service

Every commitment on this page is contractual, not marketing. Here is what backs it.

Microsoft-native, certified

Built and run on Microsoft Sentinel and Defender by Microsoft-certified security operations analysts. Founded 2024.

SLA-backed operations

15-minute response and 99.9% uptime commitments, so you can make firm promises to your own clients.

Partner-first, no lock-in

Knowledge transfer, training and clean handovers so you always stay in control of the client relationship.

Ready to add SOC to your stack?

Let’s talk about how CyberQuell can power your 24/7 security operations while you stay focused on your clients.

Book a Call with
CyberQuell Founders
Book a Call

FAQs

Straight answers to what MSPs ask before starting a white-label SOC partnership, from pricing and margins to onboarding and minimum commitment.

What is a white-label SOC?

A white-label SOC is a Security Operations Center that one company operates for another under that company's brand. For an MSP, it means CyberQuell's analysts run 24/7 monitoring, threat detection and incident response for your clients, while the service, dashboards and reports all carry your logo. Your clients see you as the security provider; we stay invisible in the background.

How does the white-label SOC partnership work?

You keep the client relationship and your brand. We connect to your client tenants through Microsoft Azure Lighthouse, run 24/7 monitoring, triage and response on Microsoft Sentinel and Defender, and deliver co-branded reports you share with clients. You resell the service at your own price and keep the recurring margin.

How quickly can we go live after signing up?

72 hours. After partner onboarding and NDA, we connect to your client environments via Azure Lighthouse, run a baseline assessment of the existing Sentinel and Defender setup, and activate continuous monitoring and incident response within three days. No long setup cycles and no tooling to buy.

Do you charge any setup or onboarding fees?

No. Partner onboarding and Azure Lighthouse configuration are included at no additional cost. You only pay for active monitored endpoints once your SOC service goes live, so there is no upfront risk.

How does white-label SOC pricing work for MSPs?

Pricing follows our published partner rate card: a monthly base fee plus a banded per-device rate that gets cheaper as your device count grows. Defend starts at $4.80 per endpoint per month, Watch at $3.12. Adding servers waives the endpoint base fee. You set your own client-facing price on top, which is where your recurring margin comes from. Billing is monthly, or 10% off when you pay a year upfront. No setup fees, no hidden costs.

How exactly is my partner price calculated?

Your monthly price is the base fee plus a per-device rate for each endpoint and server. Example on Defend: 500 endpoints and 50 servers is 500 × $4.80, plus an $840 server base fee, plus 50 × $12 — $3,840 per month. The endpoint base fee is waived because servers are included. Microsoft licences and tax are not included. The calculator above runs this exact maths.

Does CyberQuell provide or resell Microsoft licences?

No. Your clients keep buying Microsoft licences directly from Microsoft or their reseller, and we operate the security tools on top. No licence reselling means no markup hidden in your rate and no lock-in to a licensing bundle.

Which tools and integrations do you support?

Our SOC is built on Microsoft-native technologies: Sentinel, Defender for Endpoint, Defender for Office 365, Intune and Entra ID. We also integrate with common PSA and ITSM tools so tickets and reporting flow into the systems your team already uses.

Is there a minimum commitment?

Minimum billing is 200 endpoints or 50 servers, with a 1-year service term. Per-device rates step down automatically as your monitored device count grows, so the service gets cheaper per seat as you onboard more clients. Many partners begin with a single client during the pilot.

Can we start on Watch and upgrade to Defend later?

Yes. Partners can move between Watch, Defend and MXDR as their client base and service commitments grow. Many start clients on Watch monitoring and upsell Defend once the value is proven.

How do the paid pilot and the 1-year term fit together?

The 30-day pilot is a standalone paid engagement on one client tenant, with no long-term commitment. You use it to validate detections, reports and workflows under your brand. The 1-year service term only begins when you move to full production after the pilot

What happens if our device count changes mid-term?

Billing follows your active device count each month, with the 200-endpoint / 50-server minimum as the floor. Onboard more clients and your per-device rate steps down automatically as you cross volume bands. If a client churns, your bill adjusts down to the active count, never below the minimum.

Do you offer pilots or trials?

The partner readiness and revenue assessment beforehand is free. Most partners then begin with a paid 30-day pilot on one client tenant to validate detections, reports and workflows before rolling out to their full book. After the pilot you transition to full production with no disruption.

How do billing and invoicing work?

We can invoice you directly so you manage client billing, or bill your clients under your brand. Billing is monthly or annual and includes full endpoint-level reporting for transparency.