Every SOC provider prices differently, which makes comparing them unusually hard. One quotes per endpoint. Another quotes per gigabyte of log data. A third quotes a flat monthly retainer and will not explain how it was calculated.
Underneath, they are all pricing the same two things: how much data they have to watch, and how many trained humans have to watch it. This guide explains the pricing models used in India in 2026, what the numbers typically look like, and which questions expose the difference between a real security operations centre and a dashboard with an alert feed.
What you are actually buying
A security operations centre is not software. The SIEM platform is the smallest part of the cost. What you are paying for is analyst coverage across three shifts, the tuning work that stops your team drowning in false positives, and a defined response when something real happens at two in the morning.
That distinction matters because the cheapest quotes are almost always selling tooling with an alert email attached. If nobody is contractually obliged to investigate an alert within a stated time, you have bought monitoring, not operations. Our explainer on what SOC support actually involves covers the difference in detail.
The four pricing models
Per endpoint or per device
The most common model in India, and the easiest to compare. Indicative monthly ranges:
- Workstations and endpoints: ₹300 – ₹800 per endpoint
- Servers: ₹1,500 – ₹4,000 per server
- Network devices: ₹800 – ₹2,500 per device
- Cloud workloads: ₹2,000 – ₹5,000 per workload
Straightforward to budget, but it can penalise you for having a large, low-risk estate of laptops while under-pricing the handful of servers that actually matter.
Per user
Roughly ₹200 – ₹800 per user per month for basic monitoring, and ₹800 – ₹2,000 per user per month where full managed detection and response with incident handling is included. This model suits organisations where headcount is a reasonable proxy for risk, and it scales predictably as you hire.
Per gigabyte of log data
Typically ₹150 – ₹500 per GB per day, covering ingestion, monitoring and first-line response. A mid-market business commonly generates five to fifty GB a day.
This model is honest about the real cost driver, but it creates a perverse incentive: you end up reluctant to send valuable log sources because each one raises the bill. If you go this route, agree in advance which sources are in scope and cap the overage rate.
Flat monthly tier
A bundled retainer against a stated estate size. Indicative Indian ranges in 2026:
| Estate size | Typical monthly retainer |
|---|---|
| Up to 100 endpoints | ₹1.0 – ₹2.0 lakh |
| 100 – 500 endpoints | ₹2.0 – ₹5.0 lakh |
| 500 – 2,000 endpoints | ₹5.0 – ₹12.0 lakh |
| 2,000+ endpoints | ₹12.0 lakh and above |
Easiest to budget and easiest to hide margin inside. Ask what happens when you exceed the tier.
In-house SOC versus managed SOC
Round-the-clock coverage needs a minimum of eight to ten analysts once you account for three shifts, leave and attrition. Add SIEM licensing, threat intelligence feeds, an EDR platform and the infrastructure underneath, and a genuine in-house SOC in India lands in the region of ₹2 crore a year before you have handled a single incident.
A managed SOC for a comparable mid-market estate typically runs ₹30 – ₹60 lakh a year. The gap is not because managed providers are more efficient at analysis; it is because they spread the same analyst bench across many clients.
The case for in-house is real in two situations: when regulation requires data and monitoring to stay inside your own boundary, and when your environment is unusual enough that generic detection rules will never fit. For most businesses under a few thousand endpoints, the maths favours managed.
The costs that do not appear in the quote
- Onboarding and integration. Connecting log sources, deploying agents and tuning out the first wave of false positives usually takes four to eight weeks. Ask whether it is included.
- Custom detection rules. Frequently billed separately, in the range of ₹10,000 – ₹50,000 per rule.
- Escalation to senior analysts. Some contracts bill L2 and L3 involvement hourly, around ₹3,000 – ₹8,000 per hour. That is exactly when you need them most.
- Alert volume overage. A noisy month can trigger surcharges under volume-based contracts.
- Incident response retainers. Detection and full forensic response are usually separate line items. Confirm which you are buying.
- Log retention. Compliance may require twelve months; the quote may assume three.
What separates a real SOC from a dashboard
- A written SLA for time-to-acknowledge and time-to-investigate, by severity — not just uptime
- Named escalation paths and a tested out-of-hours contact process
- Analysts who investigate and close alerts, rather than forwarding them to you
- Containment authority agreed in advance: can they isolate a host at 3am, or must they wait for you?
- Regular tuning reviews, with false-positive rates reported as a metric
- Threat hunting, not only rule-based alerting
- Monthly reporting a non-technical executive can read
How to compare SOC proposals
- Convert every quote to the same unit — cost per endpoint per month — before comparing.
- Ask for the SLA table, with severity definitions and response times in writing.
- Ask how many analysts are on shift at 3am on a Sunday, and where they sit.
- Ask what the provider is contractually permitted to do without your approval.
- Ask for the log source list they assume, and price the sources they left out.
- Ask for a sample monthly report and a sample incident report.
- Confirm the exit terms and who owns the historical log data if you leave.
Frequently asked questions
Is SOC as a Service the same as MDR?
They overlap heavily and vendors use the terms loosely. In practice, managed detection and response usually implies a stronger commitment to active containment, while SOC as a Service can stop at monitoring and escalation. Read the SLA rather than the label — our guide to managed detection and response unpacks the distinction.
Do we still need a SIEM if we buy a managed SOC?
You need the capability, but usually not your own licence. Most providers include their platform. If they use yours, licensing sits on your side of the budget — see our overview of how SIEM works.
How long does onboarding take?
Four to eight weeks is typical for a mid-sized estate: agent deployment, log source integration, baselining and tuning. Anyone promising meaningful coverage in a week is skipping the tuning, and you will feel it in the alert volume.
What size of business does this make sense for?
Below roughly fifty endpoints, well-configured endpoint protection plus a managed IT provider is often sufficient. Above that, or wherever regulated data is involved, the case for continuous monitoring strengthens quickly.
Can a managed SOC cover cloud as well as on-premise?
Yes, and it should. Cloud workloads are usually priced separately because the log volume and integration effort differ from a physical server.
Working out your own number
Start from your estate: endpoint count, server count, cloud workloads, and the log sources you are required to retain. That list, not a price list, determines what any provider will quote.
To scope 24/7 coverage for your environment, see our SOC support services or get in touch through our contact page.
All figures in this guide are indicative market ranges for India in 2026, compiled for budgeting purposes. They are not a quotation and will vary by provider and scope.