Skip to content
Revelion

Blog

The Margin Math on Managed Pentesting for MSPs

A practical margin model for MSPs turning pentesting into a managed service: package pricing, platform cost, delivery time, and the economics behind recurring security assurance.

7 min readMitch Spicer

Pentesting is one of the highest-trust services an MSP can offer. It proves risk, creates remediation work, supports insurance conversations, and gives clients evidence they can show to boards, auditors, and stakeholders. The problem is not demand. The problem is margin.

In the old model, a client asks for a penetration test and the MSP becomes a coordinator. You source a subcontractor, manage scope, wait for availability, chase the report, then add a markup on top. That can work for one-off projects, but it does not behave like a managed service. It is slow, difficult to standardise, and hard to repeat every month.

Managed pentesting only works if the economics work. This is the practical model we would use when building an MSP offer around Revelion.

The Old Model: Thin Margin, Slow Delivery

Traditional subcontracted pentesting usually starts with a cost base that is already too high for an MSP service line. If the subcontractor charges £2,000-£5,000 for a small assessment, the MSP has to choose between two weak options: pass the cost through with a small markup, or price high enough that many SMB clients say no.

The commercial problem is bigger than cost. You are also dealing with lead time, inconsistent reporting, limited control over quality, and a delivery experience that does not feel like your brand. The client sees a pentest as something separate from your managed service, not part of the security relationship you own.

Old model pressureWhy it hurts MSPs
High subcontractor costMargin is squeezed before the MSP adds delivery time.
Two to six week lead timeThe service feels like a project, not an always-on capability.
Third-party report formatThe MSP does not fully own the client-facing deliverable.
Hard to retest regularlyClients get a yearly snapshot instead of recurring assurance.

The Managed Model: Predictable Cost Basis

Autonomous AI pentesting changes the cost structure. The repeatable technical work can run through a platform. The MSP keeps the relationship, defines the package, reviews the output, adds remediation context, and delivers the report under its own brand.

For a typical Revelion mission, an MSP might consume around 30,000 credits. At roughly £30 platform cost before internal delivery time, QA, client support, tax, and sales cost, the service becomes much easier to package. The exact number varies by scope and usage, but the operating principle is what matters: predictable inputs make service-line pricing possible.

Illustrative unit economics

Client package price

£500

Platform cost

~£30

Before delivery time

~£470

This is gross profit before internal delivery time, QA, support, tax, and sales cost. It is a pricing model, not an accounting promise.

The Simple Margin Equation

A small managed pentesting package could be priced at £500 for a defined mission. If the platform cost is roughly £30, the gross profit before delivery time is around £470. That is an indicative gross margin of 94%.

That does not mean every £500 engagement drops £470 to the bottom line. The MSP still needs to review findings, add context, handle client communication, support remediation, and run retests. But it does mean the cost base is low enough to create a real managed service, not just a subcontracted project with a thin markup.

Line itemExampleComment
Package price£500A defined external or application assessment package.
Platform cost~£30Based on a typical mission around 30,000 credits.
Gross profit before delivery time~£470Room for review, support, remediation calls, and retesting.
Indicative gross margin94%Before people time and commercial costs.

Package the Outcome, Not the Scan

Clients do not buy a scan. They buy confidence. They want to know whether they are exposed, what needs fixing, whether fixes worked, and what evidence they can show to insurers, auditors, or internal stakeholders.

That is why the strongest MSP offer is packaged around assurance. The scan is the engine. The product is the client-ready evidence, the remediation path, and the recurring proof that security is improving.

  • Essentials: £300-£500 for external attack surface testing, exploit evidence, and a client-ready report.
  • Assurance: £750-£1,000 for deeper application or cloud-focused testing, prioritised remediation guidance, and retest proof.
  • Continuous: a monthly retainer for scheduled missions, recurring reporting, and ongoing compliance evidence.

Why This Works for MSPs

MSPs already own the client relationship. They understand the environment, handle remediation, and sit close to the commercial trust layer. Managed pentesting strengthens that position because it turns security validation into a regular conversation instead of a once-a-year procurement event.

The commercial benefit is obvious: new recurring revenue with a more predictable cost basis. The strategic benefit is stronger: clients stop seeing pentesting as something they need to buy elsewhere. They see it as part of your managed security offer.

That matters when a client asks, "are we exposed?" The MSP that can answer with fresh exploit-backed evidence is in a different category from the MSP that has to recommend a third-party project.

What to Include in the Service

A managed pentesting package should be tight enough to price clearly, but valuable enough that the client feels a proper service around the test.

  • Clear scope: agreed assets, mission type, frequency, and exclusions.
  • Exploit-backed findings: not just theoretical risk, but proof of what was validated.
  • Executive summary: plain-language risk context for non-technical stakeholders.
  • Technical remediation: practical fixes your team can own or support.
  • Retest evidence: proof that remediation worked.
  • White-label delivery: client-facing reports under your brand.

The Bottom Line

The opportunity is not "cheap pentesting." Cheap security rarely creates trust. The opportunity is productised assurance: real testing, real evidence, real reports, delivered through the MSP relationship the client already relies on.

If you can sell a £500 managed pentesting package with a roughly £30 platform cost basis, you have room to build a profitable service around review, reporting, remediation, retesting, and account growth. That is the difference between selling a one-off PDF and building a recurring security service line.

For a broader service-design playbook, read The MSP Pentesting Playbook. To model revenue and margin for your own client base, use the MSP ROI Calculator.

See how Revelion helps MSPs deliver AI pentesting under their own brand.

msppentestingpricingbusiness

Find out what an attacker would reach first.

Request access