Prancer Blog / MSP & MSSP
The MSP Margin Math: Why Subcontracted Pentesting Caps Your Security Revenue
Subcontracted penetration testing scales cost linearly with client count, which is why MSP security margins stay flat no matter how many clients are added. The unit economics of the subcontract model versus a multi-tenant platform, worked through.
Prancer Research · 2026-08-25 · 9 min
Most MSPs that sell penetration testing are running a brokerage, not a service. They source delivery from a consultancy, add a margin, and pass it through. The revenue line grows with the client count. So does the cost line, at almost exactly the same rate. The gross margin percentage does not move.
This is not a pricing failure. It is a structural property of the delivery model, and no amount of negotiating with the subcontractor fixes it.
The two cost curves
There are only two shapes a delivery cost can take as an MSP adds clients.
Linear cost. Every new client adds a proportional delivery cost. Subcontracted engagements, per-test licences, and anything billed per assessment sit here. Adding clients grows revenue and cost together; margin percentage is fixed at whatever your markup is, forever.
Fixed-plus-marginal cost. A platform subscription is largely fixed. Adding a client adds compute and a modest amount of analyst oversight. Margin percentage *improves* with every client added, because the fixed cost is amortised across a larger base.
The difference is not subtle at scale. Under the linear model, a 40% gross margin at 20 clients is still a 40% gross margin at 200 clients. Under the fixed-plus-marginal model, the same starting margin climbs steadily as the tenant base grows, because the denominator grew and the numerator barely moved.
Where the subcontract model actually leaks
Beyond the headline cost per engagement, the brokerage model carries costs that rarely make it onto the P&L line for the service.
Scheduling overhead. Coordinating a consultancy's calendar with a client's change freeze is real labour, performed by someone on your payroll, per engagement, per year.
Scope-change friction. The client acquires a subsidiary in month three. Under a per-engagement contract that is a re-scope, a re-quote and a new booking. The MSP absorbs the delay and often the awkward conversation.
Retest as a separate sale. The client fixes the findings and asks for confirmation. You either eat the cost of a retest or ask them to pay again to be told they did the thing you asked. Both outcomes damage the relationship.
No inter-engagement coverage. Eleven months of the year, the service produces nothing. Clients notice, and it makes the recurring fee hard to defend.
Zero control over quality. The report quality is the subcontractor's, but the client blames you. Variance between their senior and junior consultants becomes variance in your service.
Loss of the relationship. The subcontractor is in the room with your client, discussing their security posture. That is a strategically uncomfortable place to be.
The platform model, dimension by dimension
| Dimension | Subcontracted manual pentest | Multi-tenant autonomous platform |
| --- | --- | --- |
| Cost structure | Linear with client count | Fixed subscription + small marginal cost |
| Margin as you scale | Flat | Improves |
| Cadence delivered | Annual, sometimes semi-annual | Continuous |
| Turnaround | Gated by consultant availability | Findings as the run completes |
| Scope change | Re-scope, re-quote, re-book | Edit tenant scope, re-run |
| Retesting | Separate billable engagement | Automated, included |
| Deliverable | Third-party-branded static PDF | White-labelled OCSF, HTML graph, Markdown |
| Client relationship | Shared with subcontractor | Entirely the MSP's |
| Capacity ceiling | Consultant availability | Compute |
The row that changes strategy is the last one. Under the subcontract model, growth in the security line is rate-limited by a resource you do not own and cannot hire against. Under the platform model, it is rate-limited by sales.
What changes on the revenue side
Cost is only half of it. The platform model also changes what you are able to sell.
From project to subscription. An annual test is a project fee — lumpy, negotiated each year, easy for the client to defer in a bad quarter. Continuous validation is a monthly recurring line item on the same invoice as the rest of the managed service. That is a materially different revenue quality, and it is the one that shows up in an MSP's valuation multiple.
From one SKU to a ladder. Continuous external validation, internal and Active Directory validation, cloud posture validation, API and web application testing, compliance evidence packages — each is a separate tier, and none of them requires a new subcontract to deliver. Expansion revenue within an existing client stops depending on a supplier's capacity.
Into the SMB segment. A manual engagement has a price floor set by human time, which puts it out of reach for most of an MSP's smaller clients. Marginal-cost delivery removes that floor. The segment of the client base that was previously unservable for pentesting becomes addressable — and for many MSPs that is the majority of the book.
As a competitive wedge. "Continuous, evidence-backed validation with proof of remediation" versus "an annual test from a partner" is not a feature comparison. It is a different category of service, and it wins renewals and displacements against MSPs still brokering.
Model your own version of these numbers in the pricing calculator — client count, current subcontract cost per engagement, target price per tenant.
The costs that are real
An honest accounting includes what the platform model does add.
Analyst oversight. Autonomous does not mean unattended. Someone reviews graded findings, adds client context and handles escalations. This is far less labour than running engagements, but it is not zero — budget for it explicitly.
Onboarding per tenant. Scope definition, authorization, credentials and scheduling. A few hours per client, front-loaded, then largely static.
Business-logic testing. Automation is strong on infrastructure, identity, cloud and known application weakness classes. Genuine business-logic abuse — the multi-step workflow that lets a user approve their own refund — still benefits from a human. For most MSP clients this is an upsell, not a baseline requirement.
Change management. Your team has to learn to operate a platform rather than manage a supplier. That is a real transition, and it is usually the slowest part.
None of these change the shape of the cost curve. They shift the intercept, not the slope — which is precisely the point.
How to test the thesis on your own book
1. Take your current pentest revenue, subcontract cost, and the number of clients receiving any testing at all. 2. Compute gross margin percentage today, then compute it again assuming a fixed platform cost plus modest per-tenant oversight across the *whole* client base — not just the ones testing today. 3. Add the clients you currently cannot serve because the manual price floor is too high. That is usually where most of the upside is. 4. Run a one-quarter pilot on three representative tenants and replace your assumptions with measured delivery cost.
The MSPs that build durable security practices over the next few years will not be the ones with the best subcontract rate. They will be the ones whose cost of delivering the eightieth client is close to zero.
Related reading: the MSP and MSSP platform, continuous pentesting for MSPs, what to deliver to clients, and the partner program.