Why the MSP versus in-house comparison starts with the wrong question
The typical IT sourcing conversation at a 100-person company goes something like this: "We're paying $X per month to our MSP. Could we hire a full-time IT person for that?" Or its inverse: "Our IT person costs $Y in salary. Could an MSP cover us for less?" Both versions share the same analytical flaw: they compare two numbers that don't represent the same thing.
The salary of one IT employee represents that employee's direct compensation. It does not represent the cost of the IT function. The monthly fee of an MSP represents the base contract. It does not represent the total cost of managed IT. To compare these as if they are equivalent is to compare one visible cost against another visible cost while leaving out most of the relevant numbers on both sides.
A complete comparison requires asking what IT capability the business actually needs, what it costs to deliver that capability through each model, and what risks and limitations each model creates. The TCO framework in this article builds that comparison. All numerical examples are illustrative models, not universal figures; actual costs depend on company size, location, infrastructure complexity, and vendor selection.
What an in-house IT team actually costs
The US Bureau of Labor Statistics reported a median annual wage of $99,130 for network and computer systems administrators in May 2025, with the lowest 10% earning under $62,640 and the highest 10% earning over $155,050. A comparable systems administrator at the median costs approximately $99,000 in base salary before any additional employment costs.
But base salary is only the starting point.
Direct employment costs beyond salary
Employer payroll taxes (Social Security, Medicare, FUTA/SUTA) add approximately 7.65% to base salary, and state unemployment insurance varies. Employer-sponsored health insurance for a single employee in 2025 cost employers a median of approximately $7,500-$8,500 annually; family coverage substantially more. Adding dental, vision, life insurance, disability, and 401(k) matching (commonly 3-5% of salary) adds further. In practice, total employer cost for benefits typically runs 20-30% above base salary for mid-market companies.
On a $99,000 base salary, a realistic total compensation cost including benefits and payroll taxes is approximately $115,000-$130,000 annually. This is the minimum starting point of the in-house labor cost, before any other components are added.
Recruiting and turnover costs
Recruiting an IT professional through a staffing agency typically costs 15-25% of first-year salary as a placement fee, or $15,000-$25,000 per hire at the median salary level. The Society for Human Resource Management estimates average cost-per-hire of approximately $4,700 for internal recruiting. Onboarding, during which a new hire is not yet fully productive, typically represents 2-4 months of reduced output.
IT staff turnover is real. The average IT professional tenure at a single employer was approximately 3.5-4 years according to multiple workforce analyses. At $15,000-$25,000 per replacement hire, turnover creates a significant recurring cost that never appears in a salary comparison. If a key IT employee leaves during a critical period, the recovery time, institutional knowledge loss, and gap coverage cost can be substantial.
A one-person or two-person team creates a single point of failure
When a company's entire IT function is one or two people, any absence creates a coverage gap: vacation, sick leave, personal leave, training, resignation, or termination. The BLS notes that most systems administrators work more than 40 hours per week and some require evenings, nights, or weekends for maintenance. If the company needs after-hours support and on-call coverage, one person cannot sustainably provide this indefinitely without burnout-driven attrition.
IT operating tools the internal team needs
An internal IT team needs the same tools an MSP uses to do its job. This is a cost that is almost always omitted in salary-versus-retainer comparisons. A realistic internal IT toolset for a 50-500 employee company includes: Remote Monitoring and Management (RMM) software; Professional Services Automation or ticketing system; Endpoint Detection and Response (EDR); email security and filtering; backup and disaster recovery software; network monitoring; patch management; password manager for the IT team; documentation platform; and remote support tooling. Depending on vendor selection, this toolset can run $15,000-$50,000 or more annually for a company of this size, in addition to the licenses it manages on behalf of end users.
Coverage and specialty gaps
A generalist systems administrator is competent across a range of tasks but is rarely a specialist in all of: network architecture, cybersecurity, cloud engineering, compliance, identity management, and help-desk operations simultaneously. When the company needs a cybersecurity audit, a cloud migration, a HIPAA security assessment, or a complex network redesign, it typically needs either specialized outside help or internal roles beyond one generalist. Each of those specializations represents either an additional hire (with its own salary and benefits) or a one-time consultant engagement billed at rates that can range from $150-$400+ per hour.
What an MSP actually costs in 2026
MSP pricing in 2026 is primarily structured around per-user or per-device models. Based on pricing data from multiple 2026 independent market sources, the US national range for managed IT services is approximately $100-$250 per user per month for standard managed services, with comprehensive security-forward packages running $200-$400 per user per month. The Petronella Technology / SerenIT pricing guide for small businesses specifically cites $100-$175 per user per month; for mid-market companies $125-$225 per user per month, covering help desk, monitoring, patching, EDR, and backup monitoring.
These ranges reflect significant variation by: service scope; cybersecurity tooling included; after-hours coverage terms; compliance requirements; cloud environment complexity; number of physical locations; on-site support requirements; and contract length. A quote at $100 per user and a quote at $250 per user are not automatically comparable. They may represent fundamentally different service scopes.
What the MSP fee typically does and does not include
A standard MSP managed-services agreement will typically include: help-desk support during agreed hours; remote monitoring and alerting; patch management; basic endpoint security (EDR or antivirus); network monitoring; and backup monitoring (note: backup monitoring is not the same as backup validation or disaster recovery testing). Most agreements will exclude some combination of: on-site visits (often billed separately per hour or per visit); project work (network upgrades, migrations, new system deployments); hardware procurement; software licensing costs; major cloud infrastructure costs; compliance consulting and auditing; security incident response; and after-hours emergency support (unless explicitly included).
Two proposals with the same per-user price can carry dramatically different scope. One MSP may include after-hours emergency coverage; another may bill it at $150-$200 per hour. One may include managed EDR as part of the package; another charges it as an add-on. One may include one on-site visit per quarter; another charges portal-to-portal travel for every site visit.
Additional MSP cost components buyers often overlook
Per-user or per-device MSP fees typically cover the service delivery cost but not all the technology costs. Microsoft 365 or Google Workspace licensing, cloud infrastructure (AWS, Azure, GCP), backup storage, and security tooling above the base tier are usually pass-through costs billed in addition to the base managed-services fee. Some MSPs include these in a bundled all-inclusive rate; many do not. Onboarding fees for new MSP relationships typically run $50-$250 per user one-time according to multiple 2026 published sources, and are often negotiable on longer contract terms. Compliance-specific work (HIPAA, PCI DSS, CMMC, SOC 2) typically adds $30-$90 per user per month above the base managed-services rate.
Full TCO comparison: MSP versus in-house IT
| Cost or capability factor | In-house IT team | Managed service provider |
|---|---|---|
| Base labor cost | $99,130 median salary (BLS, May 2025) plus 20-30% for benefits and payroll taxes = $115,000-$130,000+ per FTE annually | $100-$250/user/month base; $200-$400 security-forward. Annualized: $1,200-$3,000 per user for standard; $2,400-$4,800 for comprehensive |
| Recruiting and turnover | $15,000-$25,000 agency fee per hire; internal recruiting ~$4,700 per hire (SHRM estimate); plus onboarding time | Onboarding fee $50-$250/user one-time; no ongoing recruiting cost. Provider absorbs staffing risk. |
| Training and certifications | IT certifications (CompTIA, Microsoft, AWS, Cisco) cost $300-$1,500+ per exam; training time, courses, and conference attendance add cost. Typically $2,000-$8,000 per employee per year in established programs. | Provider absorbs training cost for its own staff. Buyer may fund specific cross-training sessions, but this is not a standard recurring cost. |
| IT management toolset | RMM, PSA/ticketing, EDR, backup, monitoring, documentation platform: typically $15,000-$50,000+ annually for a 50-500 employee company depending on toolset | Typically included in the base managed-services fee. Verify which tools are included and which are add-ons. |
| After-hours and on-call coverage | One sysadmin cannot sustainably provide 24/7 on-call. Additional staff or rotation required, adding significant cost and management complexity | Varies by contract: some MSPs include 24/7 NOC monitoring and after-hours emergency support; others bill outside business hours separately. Verify explicitly. |
| Cybersecurity expertise | A generalist sysadmin is not a cybersecurity specialist. Dedicated security roles command significantly higher salaries ($110,000-$180,000+ for security engineers/analysts). Specialty work requires either additional hires or external consultants. | Many MSPs include managed security services (EDR, email security, vulnerability management). Security-specific MSPs offer vCISO, penetration testing coordination, and incident response. Depth varies substantially by provider. |
| Cloud expertise | Cloud engineers command $120,000-$170,000+ median salaries. A generalist sysadmin with cloud skills is available but expensive. Deep multi-cloud architecture requires either a specialist or an outside consultant. | Most mid-market MSPs offer cloud management as a service. Depth of cloud expertise varies. Ask which platforms, whether they have Microsoft partner status, and how cloud management is priced. |
| Backup and disaster recovery | DR planning, backup software, testing, and recovery validation must be funded, staffed, and executed internally. Often neglected due to competing priorities. | Typically included in the base managed-services fee, but confirm the scope. Backup monitoring is not the same as tested DR. Ask for documentation of last recovery test. |
| Institutional knowledge and control | Advantage in-house. Internal teams accumulate deep organizational knowledge. Documentation follows internal standards. Full configuration control retained. | Risk: Documentation ownership and configuration knowledge can reside with the MSP. Contractually specify who owns documentation and how it is transferred if the relationship ends. |
| Scalability | Adding capacity requires additional headcount, with months of recruiting and onboarding time. | MSP capacity scales with user count. New employees are added to the managed-services agreement without additional recruiting. |
| Single point of failure risk | High risk in small teams. If the sole IT employee is unavailable, the company has no IT support. Mitigated only by adding headcount or a co-managed IT arrangement. | MSP maintains a team of technicians. Individual availability is managed by the provider. Verify staffing depth and escalation procedures for the account. |
| Strategic IT leadership | An experienced internal IT director or CIO provides institutional technology leadership, long-term planning, and business alignment that a service provider relationship may not replicate. | Many MSPs offer virtual CIO (vCIO) services, but the depth of strategic engagement varies. A vCIO at quarterly reviews is not equivalent to a full-time internal IT leader with organizational context. |
Neither column represents a clear winner across every row. The appropriate conclusion is that the advantage shifts by capability area. Cost efficiency in recruiting, training, coverage, and specialty expertise often favors the MSP model in smaller organizations. Institutional knowledge, strategic control, and deep organizational alignment often favor the internal model as the company scales and IT becomes more operationally central.
How the decision changes at 50, 100, 250, and 500 employees
Company size changes the economics on both sides. These are illustrative patterns, not universal rules; actual requirements depend on industry, technology complexity, compliance obligations, and business model.
Beyond cost: the non-financial factors that determine the better model
Cost analysis tells half the story. The operational and strategic factors below often determine whether the lower-cost option on paper is actually the better choice in practice.
Availability and response time. An MSP with a staffed help desk and a service-level agreement around response time provides formally committed availability. An internal IT employee provides no such commitment when they are sick, on vacation, or managing a concurrent issue. For companies where IT downtime carries direct revenue impact, an MSP's SLA can be more valuable than its cost-per-user number suggests.
Expertise breadth. A single IT generalist cannot match the combined expertise of an MSP team that includes network engineers, security analysts, cloud architects, and help-desk technicians. For companies whose technology complexity exceeds what one or two people can competently manage, the expertise gap represents real operational risk, not just a theoretical disadvantage.
Security capability. The cybersecurity threat landscape in 2026 requires capabilities that most generalist IT employees lack: endpoint detection and response, email security with advanced threat protection, vulnerability management, security monitoring, and incident response capability. Many MSPs now include security services as a standard component of managed-services agreements. For companies without a dedicated security staff member, an MSP with embedded security capability can provide substantially stronger protection than an in-house generalist.
Institutional knowledge and control. An internal IT team accumulates years of organizational context: why systems are configured the way they are, which departments have which requirements, the history of technical decisions, and the personalities involved in IT-adjacent work. This knowledge is genuinely valuable and is not easily transferred to an external provider. Companies that change MSPs discover this problem concretely: the new MSP needs months to develop the organizational understanding that the departing employee carried in their head. Internal teams are harder to replace on this dimension than cost comparisons suggest.
Strategic IT leadership. An experienced internal CIO or IT director shapes the technology strategy of the business: infrastructure investments, system selection, vendor management, digital transformation, and security posture. Most MSPs offer virtual CIO (vCIO) services, but a quarterly business review with a vCIO is substantively different from a full-time internal leader with board-level access and organizational authority. For companies where IT is a strategic competitive advantage, this distinction matters.
Decision framework: MSP, in-house, or hybrid?
| Situation | Recommended starting model | Key reasoning |
|---|---|---|
| Under 75 employees, cloud-first infrastructure, no on-site hardware requirements | Fully managed MSP | IT surface is manageable externally. Full MSP cost is typically lower than an equivalent in-house FTE when total employment costs are included. No coverage gap risk. |
| 50-100 employees with on-site infrastructure, physical locations, or specialized systems | MSP with defined on-site SLA, or early hybrid | On-site requirements may make a purely remote MSP inadequate. Verify on-site support terms explicitly. Consider one part-time or coordinator-level internal role alongside MSP. |
| 100-250 employees, IT complexity growing, compliance requirements emerging | Hybrid: 1-2 internal + co-managed MSP | Economics become competitive with in-house only at this size; hybrid often provides better coverage depth and security capability than either pure model. Internal lead provides institutional knowledge; MSP provides coverage and specialist depth. |
| 250-500 employees with significant infrastructure and strategic IT requirements | Internal IT team with co-managed MSP support | Internal team provides strategic direction and institutional knowledge. MSP supplements for after-hours, security, and specialist overflow. Full outsourcing becomes less common as complexity grows. |
| IT is a strategic competitive differentiator or core product | Internal team; MSP for discrete services | When technology is central to the business model, full outsourcing creates dependency and knowledge-transfer risk that internal ownership avoids. Use MSP for specific services (security monitoring, backup), not as the primary IT function. |
| Regulated industry (healthcare, financial services, government) with compliance requirements | MSP with verified compliance experience, or hybrid | Compliance frameworks like HIPAA, CMMC, or PCI DSS require specific security controls that many in-house generalist teams are not equipped to implement. An MSP with documented compliance experience can accelerate this without building internal expertise from scratch. See TechRadiant's guide to HIPAA vs HITRUST vs SOC 2. |
| Company is growing rapidly, headcount increasing significantly | MSP or co-managed MSP | MSP scales with user count without recruitment lag. Rapid headcount growth under a purely in-house model creates IT capacity constraints that are difficult to resolve quickly. |
How to evaluate an MSP before signing the contract
If the analysis above points toward an MSP or co-managed arrangement, the next question is how to evaluate providers. This is where most companies make their most avoidable mistakes: comparing proposals on monthly price rather than on scope, coverage, and capability.
Understand what is and is not in scope. Request a line-by-line breakdown of every service the proposal includes and explicitly confirm what is not included. After-hours emergency support, on-site visits, project work, hardware procurement, software licensing, security incident response, and compliance consulting are the most common exclusions that generate billing surprises after contract signing.
Evaluate the SLA in practical terms. Response time SLAs vary: 15 minutes for critical issues, 4 hours for high, 8 hours for medium is one common structure. Ask for historical SLA performance data. Also clarify how issues are categorized: an MSP that defines all issues as "medium" priority by default is effectively committing to an 8-hour response on everything. Understand the remediation commitment, not only the response commitment.
Verify cybersecurity depth specifically. Many mid-market MSPs have expanded into security services in response to the threat landscape. Verify whether the MSP's security capability is embedded in the managed-services agreement or is a separate add-on. Ask what endpoint security platform they use, how they monitor for threats, what their incident response process is, and whether they have ever managed a ransomware recovery. The answers distinguish security-capable MSPs from those with basic antivirus packaged as "managed security." For deeper guidance on security evaluation, see TechRadiant's guide to penetration testing and IT security assessments.
Ask who manages your account and who supports it. The sales conversation and the service delivery team may be entirely different people. Ask to meet the engineers who will actually support your account. Ask about technician turnover at the MSP, and what happens to account continuity when a technician changes roles. Verify the staffing depth on the support team that covers your account.
Clarify documentation and IP ownership before signing. Who owns the documentation of your network, configurations, passwords, and vendor relationships? If the MSP holds all documentation internally, transitioning to a new provider becomes difficult and expensive. Contractually specify that all documentation is the client's property and is delivered in accessible format on request at any time during the relationship and fully at termination.
Understand the exit terms. What is the minimum contract term, and what are the notice period and obligations for termination? What happens during transition? What is the MSP obligated to provide to ensure continuity? A good MSP will have clearly defined transition obligations; one that resists this question in the sales process is giving you information about how it handles difficult operational moments.
MSP buyer evaluation checklist
- What is explicitly included in the base managed-services fee? Request line-by-line scope documentation.
- What is explicitly excluded? After-hours, on-site, projects, hardware, licensing, security incidents?
- What are the SLA response and resolution time commitments, and how are priority categories defined?
- Can you provide SLA performance data from the past 12 months?
- Who specifically will be assigned to our account, and can we meet them before signing?
- What cybersecurity services are included and what are add-ons? Which EDR, email security, and monitoring platforms are used?
- Is backup and disaster recovery included, monitored only, or a separate add-on? When was the last tested recovery performed for a comparable client?
- What cloud platforms do you support and what is your Microsoft partner status?
- Who owns all network documentation, configurations, credentials, and vendor contact information?
- How is documentation delivered to us on request and at termination?
- What are the minimum contract term, notice period, and termination obligations?
- What transition obligations does the MSP accept at contract end?
- What is your process when an incident escalates beyond first-line support?
- What compliance frameworks have you supported (HIPAA, PCI DSS, CMMC, SOC 2)?
- What is your average technician tenure and what is the staff continuity commitment for our account?