Managed IT pricing models, and what each one hides
Six ways a managed IT bid can be constructed, and the variable each one puts out of sight.
A pricing model is not a discount scheme. It is a decision about who absorbs the cost when the environment turns out to differ from the description of it, and that decision gets made before either party knows what the difference will be. Federal contracting treats this as the whole game rather than a detail: negotiating the contract type and negotiating prices are closely related and should be considered together, with the aim of a structure that leaves reasonable risk on the contractor and rewards efficient performance. Commercial managed IT contracts are negotiated in exactly the opposite order. The buyer negotiates the number and inherits the structure.
What a pricing model allocates
Three variables move over the life of a managed IT contract, and every model is a bet on which of them will move most. Headcount moves with hiring, seasonal work and acquisitions. Device count moves with laptop refreshes, tablets in the field, and the servers a business swore it would retire two years ago. Labour hours move with incident volume, which correlates with neither of the first two nearly as tightly as proposals assume.
A model that prices in one of those units transfers the risk of the other two. That is legitimate. It stops being legitimate when the transfer is silent, and the transfer is nearly always silent, because the proposal names a unit without naming what happens when the other units change. The instructive extreme is the pure hourly contract, which the federal rules will not let a contracting officer sign casually: a time-and-materials contract provides no positive profit incentive to the contractor for cost control or labor efficiency, and so must carry a ceiling price the contractor exceeds at its own risk. Break-fix IT is that contract with no ceiling.
The six models
Per user
A monthly rate multiplied by headcount, usually counted as named accounts rather than people. Allocates device risk to the provider: the salesperson with a laptop, a tablet and a desk phone is one billable user and three things to patch. That is a real transfer and it is worth paying for if your device-to-user ratio is climbing.
What it hides is the definition of a user. Shared floor logins, service accounts, contractors, and the retired employee whose mailbox is still licensed all sit somewhere in that count, and the somewhere differs by provider. Ask for the count as a number, not a rate, and ask what triggers a recount.
Per device
A rate per managed endpoint, almost always with servers, hypervisor hosts and network appliances on separate lines at three to six times the workstation rate. Allocates headcount risk to the provider and device risk to you.
What it hides is the device inventory itself. The headline count in a proposal is whatever the discovery scan found on the day it ran, which misses everything that was powered off, everything on the guest network, and the two machines in the plant room nobody has logged into since 2019. It is the most legible model and the easiest to under-count.
Tiered
Bronze, silver, gold, or some house naming for the same three columns. A tier is a bundle of services at a per-user or per-device rate, and the bundling is where the comparison dies, because no two providers draw the tier boundaries in the same place.
What it hides is which services moved between tiers to hit a price point. Endpoint detection sits in the middle tier at one provider and the top tier at the next; backup verification is a gold feature here and a line item there. Price the tier you need against the tier you were quoted, which is frequently not the same tier.
Flat rate
One monthly number covering an agreed scope, typically inside a headcount band. Attractive because it budgets cleanly, and it does budget cleanly, right up to the band boundary.
What it hides is the band. Flat rate is per-user pricing with the arithmetic done once at signature, so a hiring run or a small acquisition re-tiers the invoice mid-term. Get the band written down in numbers, get the next band's price written down too, and find out whether crossing the boundary re-prices the whole contract or only the increment.
A la carte
Separate lines for helpdesk, patching, endpoint protection, backup, monitoring and projects. The most honest-looking model on the page and the one most likely to produce a lower headline than the scope justifies, because a line can simply be omitted.
What it hides is the integration. Six line items from one provider still need somebody accountable when the backup fails because the patch broke the agent, and that accountability is not a line item. Read this model looking for what is missing rather than what is priced.
Co-managed
A split with your internal staff, usually priced per device or per user at a discount to full service. The right answer for a lot of firms with one or two capable administrators, and the hardest to compare, because the discount is meaningless without the split.
What it hides is the duty roster. A co-managed proposal that does not name which ticket categories your admin still owns, who holds the on-call phone on a Saturday, and what happens when that admin resigns is not a price. It is an intention. The joint advisory reaches the same conclusion from the security side, recommending that a contract specifies whether the MSP or the customer owns specific responsibilities, such as hardening, detection, and incident response.
One office, six prices
A 62-person professional services firm on one floor and one small satellite: 82 workstations and laptops, six servers, 62 named accounts. Below is what that office was quoted under each structure, using rates that are unremarkable rather than extreme. The rates are illustrative; the arithmetic is not, and the spread it produces is the reason a headline number tells you almost nothing.
The co-managed figure is not a saving of $3,591 a month. It is a saving of $3,591 a month minus whatever the retained administrator costs, which is a bigger number, which is why co-managed bids belong in a separate comparison from full-service ones. Placing all six in one column is the commonest way a spreadsheet produces a confident wrong answer.
What included means in each
The word does the most work and carries the least meaning. In a per-user bid, included usually means anything reachable by a named account, which quietly excludes the shared devices nobody logs into. In a per-device bid it means the devices on the schedule and nothing arriving after it. In a tiered bid it means the contents of that tier on the day the proposal was generated, and tier contents are the vendor's to revise. In a flat-rate bid it means the scope as scanned. In an a la carte bid it means the four lines you bought and not the fifth you assumed. In a co-managed bid it means whatever your own administrator does not get to first.
Two exclusions recur across all six and are worth checking on every bid regardless of model. Project work — migrations, office moves, anything with a start and an end — is nearly always outside the recurring fee, priced hourly or as a fixed bid. And hardware, software licences and carrier circuits are usually passed through, sometimes at cost and sometimes at a margin the proposal does not break out. Neither exclusion is unreasonable. Both are large.
The labour floor under all six
Every one of these models resolves to people answering tickets, and people have a market price you can look up. The Bureau of Labor Statistics publishes wage data for network and computer systems administrators nationally and by metropolitan area. Take the median for your metro, add employer taxes, benefits, tooling and unbilled time, and you have a rough annual cost for one competent administrator.
The next step is the one we cannot do for you honestly. Converting that salary into a per-client cost requires knowing how many clients one engineer can carry, and we have no defensible source for that ratio. The figures that circulate in the channel come from vendor benchmark surveys with self-selected respondents and no published methodology, so we do not repeat them. What survives is a sanity check rather than a formula: if a bid implies dedicated senior attention for materially less than a fraction of one administrator's loaded cost, either the attention is not dedicated or it is not senior, and the proposal should say which.
Re-tier triggers and escalators
The clause that moves the most money over a three-year term is usually the one nobody reads, because it is in the commercial terms rather than the scope. Three specific things to find. First, the re-tier trigger: what headcount, device count or data volume causes a reprice, whether it is checked monthly or annually, and whether it can move downward as well as up. Second, the escalator: a fixed annual percentage, a CPI-linked adjustment, or nothing at all, and whether it is capped. Third, the true-up mechanism: whether the count is taken from your HR system, from the provider's monitoring agent, or from a licence report, because those three will not agree.
A four percent uncapped annual escalator on a 36-month term adds roughly eight percent to the aggregate contract value against a fixed rate. That is frequently larger than the gap between the bids being agonised over.
Which model to ask for
There is no best model, and any page telling you otherwise is describing the model its author sells. There is a best model for a given shape of business, and it follows from which of the three variables is most likely to move. Stable headcount with a rising device count favours per user. Stable device count with volatile headcount favours per device. Genuinely stable everything favours flat rate, provided the band is written in numbers. A capable internal administrator favours co-managed, provided the duty split is written as a roster rather than a paragraph.
For comparison purposes the model barely matters, because you are going to convert all of them into one unit anyway. What matters is that each bid discloses enough to be converted: the count it used, the rate it applied, the items it left on an optional schedule, and the trigger that changes any of them. A provider that supplies those four things has given you a comparable bid whatever shape it arrived in.
- FAR 16.103 — Negotiating contract type — U.S. General Services Administration, Acquisition.gov
- FAR 16.601 — Time-and-materials contracts — U.S. General Services Administration, Acquisition.gov
- Occupational Outlook Handbook: Network and Computer Systems Administrators — U.S. Bureau of Labor Statistics
- Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A) — Cybersecurity and Infrastructure Security Agency