SOC as a Service Pricing in India: What the Monthly Fee Buys

  • Home
  • SOC as a Service Pricing in India: What the Monthly Fee Buys
SOC as a Service Pricing in India: What the Monthly Fee Buys

Search for SOC as a service pricing in India and most of what comes back is American: per-endpoint dollars, per-user tiers, calculators built for a different market. The rupee numbers are scarce for a reason — the two figures that determine the price of a SOC (security operations centre) service are how much log data your estate produces and how many hours of analyst attention it genuinely needs, and neither is knowable before someone looks. What follows is what the monthly fee is actually made of, so you can read an Indian quote properly and tell a serious one from a guess.

Why nobody serious quotes a number up front

A SOC service is priced on your estate, not on a rate card. Fifty log sources producing a quiet trickle of events is a different service from fifteen sources producing a torrent, even if the second company is smaller. The provider who quotes you a fixed price before asking about log volume, source count and coverage hours has either padded the number heavily or plans to renegotiate it later — and both of those are your problem, not theirs.

The useful comparison is not between headline prices but between what each fee includes. That requires knowing what the fee is made of.

What the monthly fee is made of

The five components of SOC as a service pricing, largest firstHorizontal bar chart ranking the five cost components of a monthly SOC service fee by typical weight: analyst coverage largest, then SIEM licensing and log volume, detection tuning, incident response retainer, and compliance reporting smallest.What the monthly fee is made ofTypical weighting, largest first — shares vary by scope, the order rarely doesAnalyst shift coverageSIEM licence and log volumeDetection tuning and use-casesIncident response retainerCompliance reportingA quote that hides any of these is hiding the one it intends to charge you for later.

Analyst shift coverage. The largest component, always. Keeping one chair continuously staffed around the clock takes five to six analysts once shifts, leave and attrition are counted — arithmetic we work through in in-house versus outsourced SOC. A provider spreads those people across clients; that sharing is where the economics of the whole category come from, and it is also why coverage hours (24×7 against 8×5 with on-call) move the price more than any other single choice.

SIEM licence and log volume. Most SIEM platforms are licensed on ingest — gigabytes per day or events per second — so every log source you onboard has a metered cost behind it. This is also where CERT-In Direction 20(3)/2022 shows up in the bill: ICT logs retained for a rolling 180 days and maintained within India shape the storage design underneath the service. Our managed SIEM services page covers the levers that keep ingest under control; a quote that ignores your log volume has not priced this at all.

Detection tuning and use-cases. An untuned SOC forwards noise. The work of building correlation rules for your estate, suppressing the false positives your environment generates, and keeping detections current is real recurring engineering, and it is the component most often quietly excluded from cheap quotes — which is why cheap quotes escalate everything to you.

Incident response retainer. Monitoring tells you something is wrong; someone still has to act. Whether guaranteed response hours are inside the fee or bought separately as an incident response retainer is one of the biggest hidden differences between proposals that otherwise look alike.

Compliance reporting. Evidence packs for auditors, regulator-ready incident documentation, and the reporting cadence your framework expects. Small as a share of the fee, but if your organisation answers to the RBI, SEBI or CERT-In, its absence is expensive.

How the market quotes it — and where each metric misleads

Indian proposals arrive in four commercial shapes, and knowing which one you are reading matters more than the number on it. Per-device pricing is tidy until you notice it prices a domain controller and a receptionist’s laptop identically. Per-user pricing suits endpoint-centred services and quietly ignores the servers, network gear and cloud services that produce most of the interesting logs. Per-GB-ingested is the most honest about what a SIEM-backed service actually does, and the most punishing if nobody is managing what gets onboarded. Flat-scope pricing — one number for a written scope — is the most predictable, provided the scope schedule is specific enough to arbitrate against later. None of these is wrong; each is wrong for somebody. The test is whether the metric tracks the work your estate will actually generate.

Fully managed against co-managed

The second axis of every quote is who does what. Fully managed means the provider runs platform, detection and triage end to end — the price carries all five components above. Co-managed means your team keeps part of the work, commonly the daytime shift or the response half, and buys the provider’s night coverage, platform and escalation depth. Co-managed is cheaper per month and demands more of you per week; which one fits depends on the team you already have, and the honest version of that assessment is the one worth paying for. The delivery models are laid out on our SOC as a Service page, with the operating detail on managed SOC services.

What Indian market figures look like

With the components understood, the ranges publicly cited in the Indian market make sense. Entry-level managed monitoring for a small, log-light estate is advertised from around ₹50,000 a month. Mid-size enterprises buying genuine 24×7 fully managed coverage across a few hundred endpoints and a realistic log estate commonly see quotes in the low-to-mid lakhs per month. Treat both figures as orientation, not as prices — the spread between them is scope, and a number without a scope statement attached is not information.

The comparison that actually matters runs the other direction: an in-house SOC built to the same coverage standard runs to crores a year before it detects anything, which is why the build-versus-buy arithmetic deserves its own working — we have set it out in in-house SOC versus outsourced SOC.

Costs that surface in year two

Ingest creep. Log volume only grows: new applications, new cloud accounts, chattier sources. If the contract prices ingest without a growth allowance, year two arrives with an overage conversation. Ask how growth is handled before signing, in writing.

Scope creep by success. A SOC that works gets given more: OT networks, subsidiaries, the acquisition nobody mentioned. Each is legitimate new scope — the question is whether the commercial mechanism for adding it was agreed on day one or invented under pressure.

The renewal cliff. First-year pricing is sometimes a land-grab. Ask for year-two and year-three pricing in the original proposal, exactly as you would for a firewall subscription.

What a credible quote looks like

A log-volume and source-count basis, stated — measured if possible, estimated if not, but written down either way. Coverage hours in plain language, including who answers at 3 a.m. and how fast. The five components itemised, so you can see what is inside the fee and what is a change request. Response commitments with numbers on them. The compliance artefacts included, named. Growth and renewal pricing for the term. And the exit position: whose SIEM it is, who keeps the detection content, and what leaves with you if you go.

How we price it

We do not publish a rate card, for the reason this page has been explaining: a SOC price quoted before anyone has counted your log sources is a guess wearing a suit. What we do instead is measure — sources, volumes, coverage hours, the response commitment you actually need — then put a number against it that holds for the term, itemised the way this page is itemised. If the honest answer is that a co-managed arrangement or a smaller scope serves you better than the full service, we will say that; the long version of what the service contains is on the SOC as a Service page.

Leave a Reply

Your email address will not be published. Required fields are marked *