On this page
Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
If your managed services business is growing but your margin keeps slipping, you’re not alone. The uncomfortable truth is that many MSPs do not have a sales problem; they have a profitability problem.
In this post, you’ll learn why top-line growth can hide deeper financial issues, how changing client expectations are quietly increasing delivery costs, and why risk-based pricing is the best way to rebuild healthy margins. If you run an MSP, this is about more than pricing; it’s about making sure the work you do is worth what you charge for it.
Growth Can Hide the Real Problem
Many MSPs measure success the way the market tells them to: more customers, more MRR, more ARR, and more services sold. Those measures matter, but they can be misleading if you do not also look closely at gross profit and bottom-line margin.
The problem is simple: revenue can rise while profitability falls. You can add clients, expand contracts, and still end up with less money left over because delivery costs have grown faster than the prices you charge. That is why growth alone is not proof that the business is healthy.
This is where many MSPs get trapped. They see competitors growing quickly and assume those companies are doing something right. But fast growth does not always mean profitable growth. It may simply mean someone is scaling inefficiency.
That distinction matters because inefficient growth eventually hits a wall. At first, it looks impressive: more deals, more recurring revenue, and more activity. But if every new engagement adds more obligation without enough margin, the business eventually plateaus. After that, it can decline quickly.
The deeper issue is that MSPs often accept more responsibility without charging for it. They promise more, customers ask for more, and the price stays the same. That is not a growth strategy; it is a margin leak.
Client Expectations Have Changed, and So Has the Cost of Delivery
Client expectations have changed dramatically, creating another source of margin pressure for MSPs. A managed services relationship used to be more technical and clearly bounded. Today, clients expect security guidance, compliance support, reporting, faster response times, and even strategic advice.
That is a significant shift.
Customers no longer want someone only to keep the lights on. They want help with cyber risk, insurance questionnaires, audit readiness, policy decisions, board reporting, and executive-level conversations. Those are valuable services, but they require time, expertise, and accountability.
That is where the pricing problem begins.
Many MSPs quietly absorb this extra work. A client asks for help with a cyber insurance form, and the MSP provides it. The same request returns the following year, but now it involves a SOC 2 package, CMMC requirements, or a compliance checklist that takes days instead of hours. The work keeps growing, but the contract does not.
The point is important: when expectations change, the agreement must change, too. If the customer expects more security, compliance, or advisory work, the service catalog needs to reflect it. Otherwise, you are effectively donating labor.
That is especially true in cybersecurity and compliance. Too many MSPs still treat security pricing as a markup on a tool license. But the license is not the service. The service includes configuration, monitoring, escalation, investigation, client communication, vendor coordination, and ongoing accountability.
The same is true for compliance. Evidence collection, documentation preparation, control validation, policy work, and advisory support are all real services. They may not be tools, but they have genuine costs.
One of the biggest mistakes MSPs make is treating these expanding responsibilities as though they are simply part of the old contract. They are not. If the scope changes, the price should change, too.
Why AI Makes the Pricing Problem Even More Urgent
AI is adding a new layer to an already stretched service model. Clients are now asking MSPs questions such as:
- Can you help us define an AI policy?
- How should we use AI in our business?
- Can this tool actually save us money?
- What are the risks of using AI in our workflow?
Those are not simple licensing questions. They involve governance, training, integration, monitoring, and business processes. In other words, they create more responsibility for the MSP.
That is exactly why AI is also an opportunity.
Instead of treating AI as just another tool to resell, MSPs can use it as an opportunity to reset the relationship. If you have underpriced advisory work for years, AI provides a legitimate reason to revisit the model and say, “Here is what you are asking for now, and here is what it costs to deliver it responsibly.”
That conversation may feel overdue because it is.
Clients often assume AI should reduce costs, while MSPs are expected to take on new governance and support obligations. That mismatch squeezes margins. The customer sees more value, but the MSP sees more labor, risk, and pressure.
[INTERNAL LINK: Related post on MSP AI advisory services]
This is also where MSPs can move up the value chain. These conversations are no longer purely technical; they are taking place at the board, executive, and business levels. Your role is expanding, and so is your right to charge for that expanded role.
The important thing is not to hide this work behind vague marketing language. Make the service visible. Whether you call it a professional service, managed service, compliance package, or vCISO offering, it needs to be defined, priced, and deliverable.
If you do not name it, scope it, and charge for it, it becomes invisible labor.
Why Risk-Based Pricing Beats Per-Seat Pricing
If you want to address margin pressure, per-user or per-device pricing is not enough on its own.
It is useful as a starting point because it measures volume. It helps you estimate how many users, devices, and licenses you need to support. But it does not tell you how much responsibility you are taking on.
That is the problem.
Two companies can have the same number of users and devices but very different risk profiles. One may have strict regulatory obligations, sensitive data, extensive compliance requirements, and high service intensity. The other may be far simpler. If you price them the same way, you are almost certainly undercharging one of them.
Risk-based pricing is the better model because it accounts for what the MSP is actually doing. You are not just supporting seats; you are managing exposure.
What should go into the pricing model? Start with the baseline:
- Number of users
- Number of devices
- Core tool stack required
Then go beyond volume and look at the real cost drivers:
- Security exposure
- Compliance obligations
- Technical complexity
- Business complexity
- Service intensity
- Reporting burden
- Customer expectations
- Liability and shared accountability
This is where many MSPs leave money on the table. If a client wants more reporting, meetings, guidance, escalation support, or advisory work, that should influence the price. Those are not abstract extras; they are genuine operational costs.
Per-seat pricing may represent only 10% of the overall pricing calculation. The other 90% reflects risk, complexity, and responsibility.
That does not mean you need a large, complicated proposal. In many cases, a clear service line item with a short description of what it includes is enough. The key is for both you and the customer to understand what is being delivered and what it costs.
How to Reassess and Protect Profit Over Time
Pricing is not a one-time decision. It must be reviewed regularly because client risk changes.
At a minimum, MSPs should reassess pricing annually. If the customer’s environment becomes more complex, compliance obligations increase, or the relationship becomes more service-intensive, the price should reflect those changes.
You also need to document when a customer declines a recommended service.
That matters more than many MSPs realize. If a client refuses a security control, rejects a compliance recommendation, or declines a necessary service, document it clearly. This helps protect you in the event of an audit, cyber insurance claim, or legal dispute. If the customer later fails an assessment, you want a record showing what was recommended and what was rejected.
This is not just about liability; it is also about leadership.
When you document risk and speak clearly about what is required, you raise the customer’s awareness of what it takes to work with you. That helps reset expectations and reduces the chance that your work will be taken for granted.
MSPs that do this well tend to appear more professional, confident, and valuable. More importantly, they are paid more fairly for the work they already perform.
Here is the practical takeaway: if the relationship changes, the pricing should change, too. Do not wait until margin erosion becomes a crisis. Review the scope, revisit the risk, and adjust before the business absorbs too much cost.