Ask five New York MSPs what managed IT costs and you will get five versions of “it depends,” usually followed by a discovery call. It does depend — but the ranges are documented, and there is no good reason to hide them. This guide lays out the published benchmark figures with their sources, the variables that move a quote up or down, and the place most budgets actually get hurt: the out-of-scope column. It pairs with our managed IT services page, which describes what a complete scope looks like.
The short answer, with sources
Stedholm is a new firm with no pricing history to average, so we will not invent one. What exists in public are 2026 benchmark guides — from Datapath, Corsica Technologies, ITBudgetCalculator, and several MSP directories — whose published figures converge on a consistent band. Treat the numbers below as those guides’ claims, which is what they are.
| Scenario | Published 2026 benchmark band | Notes |
|---|---|---|
| Small business, 10-50 users | $100-$175 per user / month | Standard stack, limited compliance overhead |
| Mid-market, 50-250 users | $150-$250 per user / month | More infrastructure; co-managed arrangements common |
| Security- and compliance-heavy scopes | $300-$400 per user / month | Regulated firms where monitoring and evidence are in scope |
Two further findings from the same guides are worth knowing before you compare quotes: more than 80 percent of benchmarked MSPs price per user per month, and hidden out-of-scope charges commonly add 30 to 50 percent over the headline rate. That second number is the one this article exists to help you avoid.
What moves the per-user number
- Compliance obligations. If you certify under NYDFS Part 500, operate under HIPAA, or fall under the FTC Safeguards Rule’s nine required elements, your provider is producing evidence — risk assessments, MFA enforcement records, monitoring reports, incident documentation — not just closing tickets. That labor is real and it is priced in.
- Security depth. Antivirus and patching sit at the bottom of every band. Managed detection and response, vulnerability management, and identity monitoring move a quote toward the upper bands — and increasingly, your cyber-insurance carrier decides this variable for you.
- Fully managed versus co-managed. If you have internal IT and buy escalation depth, projects, and security operations around them, the per-user rate is usually lower than a full-service scope — but the split of duties must be written down.
- Servers and infrastructure. On-premises servers, virtualization hosts, and complex networks add device-based line items that user counts alone do not capture.
- Onsite expectations. In New York City specifically, guaranteed onsite response means travel time in a vertical city. Remote-first support with scheduled onsite work prices differently from a standing onsite commitment.
The out-of-scope column is where budgets go wrong
The headline per-user rate is the most comparable and least informative number in a quote. What separates one $150 provider from another $150 provider is what happens when work falls outside the base agreement. Common examples worth pricing before you sign:
- Projects — migrations, office moves, server replacements — billed hourly on top of the retainer
- After-hours or weekend work at multiplied rates
- New-hire setup and departure processing as per-event fees
- Security incidents handled as billable emergencies rather than covered response
- Hardware and license procurement with undisclosed markup
- Coordinating with your other vendors — phones, ISP, line-of-business software — billed as consulting
- Offboarding: documentation and credential handover charged at exit, when your leverage is lowest
None of these items is illegitimate on its face — projects genuinely are separate work. The defect is discovering them after signature. Ask for the out-of-scope schedule in writing and attach it to the agreement.
The four pricing models you will meet
- Per user per month. The dominant model, per the benchmark guides. Predictable, scales with headcount, and easy to compare — provided the scopes behind the rates match, which they rarely do without work on your part.
- Per device. Common where servers and infrastructure outweigh headcount, or layered on top of per-user pricing for data-center equipment. Watch for double-billing when a user’s laptop, phone, and desktop each count separately.
- Tiered — bronze, silver, gold. The tier names are marketing; the delta between tiers is usually security and reporting depth. Ask for the tier-by-tier inclusion matrix rather than the tier names, and check which tier the quoted price refers to.
- All-in fixed fee. One monthly number covering support, security, and a defined project allowance. Rare in the New York market but growing in regulated verticals, and the easiest model to budget — if the definition of “all” is written down.
No model is inherently more honest than another. The honest version of each is the one where the inclusion list, the out-of-scope schedule, and the incident terms are in the agreement rather than in the sales deck.
How to compare quotes on equal terms
- Normalize scope before comparing rates: two quotes are comparable only after you list what each includes for security monitoring, backup verification, and compliance reporting.
- Ask what a security incident costs under each agreement. The answer is often the largest hidden variable in the whole comparison.
- Ask what leaving costs. Documentation, credentials, and configurations should be yours; an exit-fee schedule tells you how a provider expects the relationship to end.
- Work through our twelve questions to ask any NYC MSP — several of them exist specifically to surface pricing behavior before it surfaces itself on an invoice.
Where Stedholm sits
We publish behavior rather than a rate card: scope, inclusions, and the out-of-scope schedule go into the agreement before you sign, and compliance-grade reporting is in scope where your regime requires it. In the Tri-State market, managed IT with genuine security generally lands in the low-to-mid hundreds per user per month depending on scope and compliance requirements — consistent with the published bands above. The precise number is a function of your environment, which is why the honest first step is a scoped IT and security assessment: you receive the findings and a priced plan in writing, and both are yours to keep whatever you decide.