Security Operations Center: Build vs Buy
First developed as part of our SIEM capability whitepaper, May 2026. Expanded and updated for this site.
A mid-market defense contractor just won their first CUI contract — 200 employees, solid engineering talent, but no dedicated security operations team. Their newly hired CISO has 90 days to stand up 24/7 monitoring capabilities sufficient for CMMC Level 2 assessment, and an annual budget of $400K. Building an in-house SOC at that budget is mathematically impossible (you cannot hire six analysts in any US market for $400K). Buying managed services is achievable but introduces third-party risk into a CUI environment. The wrong decision here does not just waste money — it delays contract execution and potentially loses the revenue that justified the security investment in the first place.
Why Now: CMMC Phase 2 Forces the Question
CMMC Phase 2 enforcement begins November 2026, requiring thousands of Defense Industrial Base (DIB) organizations to demonstrate operational security monitoring capabilities for the first time. Many of these organizations have historically relied on compliance-checkbox approaches — annual penetration tests, periodic vulnerability scans, maybe a managed firewall. The CMMC Assessment Guide makes clear that this is insufficient: assessors will look for evidence of continuous monitoring, incident detection, and documented response processes.
The Change Healthcare breach in February 2024 — which ultimately cost UnitedHealth Group over $2.4 billion — demonstrated what happens when monitoring capabilities fail at scale. Their detection gap allowed attackers more than a week of undetected dwell time. For DIB organizations handling CUI, the stakes are different in kind (national security) but the operational lesson is identical: you need eyes on your environment 24/7/365, and those eyes need to be competent.
The Real Cost of Building In-House
The numbers that vendors quote for "building a SOC" consistently understate the true cost because they omit the long-tail expenses that compound over years.
Staffing (The Dominant Cost)
| Role | Headcount for 24/7 | Annual Cost Range |
|---|---|---|
| SOC Analysts (Tier 1/2) | 6-8 minimum | $600K-$1.2M |
| Senior Analyst / Hunt Lead | 1-2 | $140K-$220K |
| SOC Manager | 1 | $130K-$190K |
| Detection Engineer | 1 | $130K-$180K |
| Staffing subtotal | 9-12 | $1.0M-$1.8M |
The 6-analyst minimum assumes zero unplanned absences. In practice, covering vacation, sick time, training days, and the inevitable attrition (SOC analyst burnover averages 18-24 months) requires 8-10 analysts for sustainable operations. Every departure triggers a 3-6 month productivity gap: recruiting, onboarding, training to environmental proficiency.
Technology Stack
| Component | Annual Cost |
|---|---|
| SIEM platform | $100K-$500K (scales with log volume) |
| EDR platform | $50K-$200K (per-endpoint licensing) |
| SOAR / automation | $80K-$200K |
| Threat intelligence feeds | $30K-$100K |
| Vulnerability management | $40K-$120K |
| Network detection (NDR) | $60K-$150K |
| Technology subtotal | $360K-$1.3M |
Operational Overhead
| Category | Annual Cost |
|---|---|
| Training and certifications | $40K-$80K |
| Facility (if dedicated space) | $50K-$150K |
| Recruitment (ongoing, given turnover) | $30K-$60K |
| Process development and documentation | Staff time (buried in salary) |
| Overhead subtotal | $120K-$290K |
Total In-House Cost
Year 1: $1.8M-$3.5M (includes setup, hiring ramp, tool deployment) Steady-state annual: $1.5M-$3.4M 3-year TCO: $4.8M-$10.3M
The Real Cost of Buying
Managed security services come in several tiers, each representing a different tradeoff between cost, control, and capability.
| Service Model | Annual Cost | What You Get | What You Give Up |
|---|---|---|---|
| Managed SIEM only | $100K-$300K | Log collection, alerting, dashboards | Investigation, response, tuning |
| MDR (Managed Detection & Response) | $200K-$600K | Detection, investigation, guided response | Custom detection, deep environmental knowledge |
| Full MSSP | $300K-$800K | Comprehensive monitoring, response, reporting | Control, data sovereignty, customization |
| Co-managed / Hybrid | $400K-$1.2M | 24/7 base coverage + internal expertise | Simplicity (complex coordination required) |
Hidden Costs of Buying
- Integration fees — Connecting your specific log sources and tools often costs $20K-$50K upfront
- Overage charges — Most managed services price by log volume or endpoint count; growth means price increases
- Context ramp-up — A new MSSP takes 3-6 months to learn your environment's normal behavior
- Alert fatigue transfer — If the managed service sends you 50 "escalations" per day, you have not solved the problem — you have added a middleman
The Decision Framework
The build-vs-buy decision maps against four dimensions. Score each honestly:
1. Compliance Requirements
Some frameworks and contract vehicles have specific language about security operations:
- CMMC Level 2: Requires monitoring and incident response capabilities but does not mandate in-house. A managed service can satisfy the requirements IF the contract structure, data handling, and evidence trail meet assessor expectations.
- CMMC Level 3: Higher assurance requirements make managed services harder (not impossible) to justify. The DIB-SCC guidance suggests additional scrutiny for outsourced monitoring of CUI environments.
- FedRAMP High: Continuous monitoring requirements are stringent. FedRAMP-authorized MSSPs exist, but the compliance burden of verifying their authorization adds overhead.
- ITAR: Data sovereignty concerns often preclude sending security telemetry to a third-party managed service unless that service maintains ITAR-compliant infrastructure.
2. Threat Sophistication
If your adversary is a nation-state APT (defense, intelligence, critical infrastructure), generic MSSP rules optimized for commodity threats will miss the tradecraft. Advanced persistent threats require environmental context, custom detection logic, and threat hunting capabilities that most managed services do not provide at their base tier.
If your primary threats are ransomware, business email compromise, and opportunistic exploitation, managed services handle these effectively — these are exactly the scenarios their detection models are optimized for.
3. Budget Reality
Be honest about multi-year sustainability, not just Year 1:
- Under $400K/year: Build is not viable. Buy managed services. Supplement with 1-2 internal security staff for compliance coordination and escalation handling.
- $400K-$1M/year: Hybrid is possible. Buy 24/7 base monitoring; build 1-2 internal positions for escalation, hunting, and compliance.
- $1M-$2M/year: Both models are viable. Decision hinges on other factors.
- $2M+/year: Build becomes economically advantageous if you can hire and retain the talent (a significant if in the current market).
4. Organizational Maturity
Building a SOC requires existing competency in security operations. If your most senior security person is a compliance analyst who has never investigated a live incident, you cannot build a SOC from scratch — you need managed services to provide coverage while you develop internal capabilities over 2-3 years.
The Hybrid Model: Hardest to Execute
The hybrid SOC is not a middle ground — it is the hardest model to execute. You need clear handoff procedures, shared tooling access, mutual SLAs, and unambiguous ownership boundaries, or you end up with gaps where each side assumes the other is covering.
Where Hybrid Fails
The escalation gap: MSSP escalates an alert to your internal team at 2 AM. Your on-call person is a compliance analyst without investigation experience. The alert sits until 8 AM. Mean time to respond: 6 hours.
The context gap: Your MSSP sees a suspicious process and escalates. Your internal team sees the same process and knows it is your custom deployment tooling. Neither side updated the shared whitelist. Alert fatigue compounds.
The blame gap: An incident occurs in the boundary between managed and internal coverage. Each side documents their piece but neither owns the full timeline. The post-incident review devolves into finger-pointing.
Where Hybrid Succeeds
Hybrid works when the boundary is clean and the interfaces are defined:
- MSSP owns 24/7 monitoring and Tier 1 triage with a defined escalation criteria and SLA
- Internal team owns Tier 2+ investigation, threat hunting, detection engineering, and compliance with access to the same tooling the MSSP uses
- Shared SIEM with role-based access so both teams see the same data
- Weekly sync on detection tuning, false positives, and escalation quality
- Documented playbooks that explicitly define who does what at each stage
Staffing Models for In-House
If you choose to build, the staffing model determines sustainability:
Follow-the-Sun (Distributed)
Analysts in multiple time zones, each covering their local business hours. Avoids night shifts but requires geographic distribution, cross-timezone management, and consistent tooling across locations.
Split-Shift (Single Location)
Three 8-hour shifts at one location. The traditional model. Night shifts are hard to staff and suffer higher turnover. Expect 15-20% salary premium for overnight roles.
12-Hour Rotation
Two 12-hour shifts, typically 3-4 days on / 3-4 days off. Reduces handoff frequency but increases fatigue risk. Common in mature SOCs where alert volume is manageable per-analyst.
Measuring SOC Effectiveness (Either Model)
Regardless of build or buy, measure these:
| Metric | Target | Why It Matters |
|---|---|---|
| MTTD (Mean Time to Detect) | < 24 hours | Dwell time is the primary driver of breach severity |
| MTTR (Mean Time to Respond) | < 4 hours (critical) | Containment speed determines blast radius |
| False positive rate | < 30% of escalations | Higher means analyst burnout and missed real alerts |
| Detection coverage (ATT&CK) | > 60% of relevant techniques | Gaps are where breaches happen |
| Evidence completeness | 100% of incidents documented | Compliance frameworks require it |
| Analyst turnover | < 25% annually | Above this, you are constantly in training mode |
Key Takeaways
- Building an in-house SOC costs $1.5M-$3.4M annually at steady state — the math only works above $2M/year budget with proven ability to hire and retain talent
- Managed services provide 24/7 coverage at 60-70% lower cost but sacrifice customization, environmental context, and direct control over detection logic
- The hybrid model is the hardest to execute, not the easiest — it requires explicit handoff procedures, shared tooling, mutual SLAs, and weekly coordination
- CMMC Level 2 does not mandate in-house SOC capabilities, but the evidence trail and data handling requirements constrain which managed services qualify
- Budget below $400K/year makes building mathematically impossible in any US market; supplement managed services with 1-2 internal security staff for compliance coordination
- Measure effectiveness by MTTD, MTTR, false positive rate, and detection coverage regardless of model — these metrics are model-agnostic
Frequently Asked Questions
Can a managed service satisfy CMMC Level 2 monitoring requirements?
Yes, with caveats. The managed service must demonstrate appropriate handling of CUI-adjacent telemetry, their own security posture must be assessed, and your organization remains responsible for oversight. Assessors will verify that you understand what your MSSP does, that you review their reporting, and that escalation procedures are documented and tested. A contract with an MSSP does not transfer compliance responsibility — it transfers operational execution.
How long does it take to stand up an in-house SOC from scratch?
Minimum 9-12 months to initial operating capability. Months 1-3: hire SOC manager, select and procure tooling. Months 3-6: deploy SIEM, integrate log sources, hire initial analysts. Months 6-9: develop detection rules, build playbooks, establish processes. Months 9-12: achieve 24/7 coverage, tune detections, establish metrics baselines. Full operational maturity takes 18-24 months.
What is the minimum viable SOC for a 200-person defense contractor?
For a 200-person organization with CUI: 1 internal security lead (compliance + vendor management), MDR service for 24/7 detection and response ($250K-$400K/year), SIEM for log retention and compliance evidence ($80K-$150K/year), and documented incident response procedures. Total: $350K-$600K/year plus the internal position. This satisfies CMMC Level 2 monitoring requirements while remaining budget-realistic.
Should we build internal capability alongside managed services?
Yes — this is the rational long-term strategy for most organizations. Start with managed services for immediate coverage. Hire 1-2 internal security staff focused on detection engineering, compliance, and vendor oversight. Over 2-3 years, gradually shift more capability in-house as your team develops expertise. The managed service provides the safety net while you build. Cutting over completely requires reaching the staffing and budget thresholds for 24/7 internal coverage.
How do we evaluate an MSSP for defense industrial base work?
Key criteria: Do they handle CUI environments (not all do)? What is their FedRAMP or equivalent authorization status? Where is the SOC physically located (CONUS requirement for some contracts)? What detection content do they deploy (generic vs defense-sector-specific)? What is their analyst-to-customer ratio? Can you access the raw telemetry, or only their reports? Do they support your specific compliance evidence requirements? Request references from similarly-sized DIB organizations — generic commercial references do not transfer.
How Advisedly Helps
Advisedly provides the unified platform layer that supports all three SOC models — consolidating 80+ enterprise tools into a single environment where SIEM, detection engineering, compliance monitoring, and incident response share a common data layer, so whether your analysts are internal, managed, or hybrid, they operate from the same source of truth with the same audit trail. Contact begin@advisedly.ai
<!-- LI hook: A $400K SOC budget cannot hire six analysts. Know your real options. -->