Headline finding · measured 2026-09-09
19,959 US providers sell security. 1,071 name a capability that detects an attack.
Half the directory sells security. One in nineteen of those names a SOC, SIEM, MDR, EDR, XDR or threat-hunting service — the tools that notice an intrusion rather than prevent one.
of the 19,959 security-selling providers name no detection capability at all
n = 39,235 published US providers. 19,959 name at least one security service; 1,071 name a detection capability (SOC, SIEM, MDR, EDR, XDR, SOAR, managed or endpoint detection, threat hunting), of which 1,059 also carry a broader security tag. Services are on file for 35,344 of the 39,235, so both shares are floors. SOC 1 and SOC 2 audit references are excluded from detection — an attestation report is not a detection capability. Measured 2026-09-09 in one repeatable-read snapshot.
- Share of directory
- 50.9%
- Shows a certification
- 23.4%
- Shows a Google rating
- 51.0%
- Median headcount
- 9
- Share of directory
- 2.7%
- Shows a certification
- 23.1%
- Shows a Google rating
- 31.8%
- Median headcount
- 11
The published statistic behind this
MSP Signal tracks 40,647 active IT service providers, classified into 13 categories.
n = 40,647 active providers · measured 2026-09-17. The figures on this page are frozen at their own measurement date and are not recomputed from that table.
Providers tracked by category ▸The term covers two different businesses
"Managed security service provider" is used two ways in this market. One means a provider that sells security services alongside IT: 19,959 of 39,235 published US providers, or 50.9%, name at least one. The other means a provider that operates a detection capability — something that watches for an intrusion and responds. That is 1,071 firms, or 2.7% of the directory.
18,900 of the 19,959 security-selling providers name no detection capability of any kind. That is 94.7% of the firms selling security in this market.
This is a different finding from the certification gap. Our security-washing card measures whether security sellers publish third-party proof, and 76% do not. This measures whether they name the machinery at all. A provider can be fully certified and still sell only prevention; a provider can run a genuine SOC and publish no certificate.
What the 1,071 look like
They are slightly larger than the market — a median headcount of 11 against the directory's 9 — and no better credentialed. 247 of the 1,071 show a certification, 23.1%, statistically level with the 23.4% across all security sellers.
They are markedly less visible to consumers. 341 show a Google rating, or 31.8%, against 51.0% of security sellers and 44.3% of the whole directory, at a median of 5 reviews among those rated against 9. Detection is sold to businesses through procurement, not found through local search, and the review data shows it.
By headquarters: California 106, Florida 85, Texas 79, Virginia 72, New York 68 and Maryland 42. Virginia and Maryland placing fourth and sixth on a base of a thousand firms is the federal-contracting corridor showing up in the data — neither state is close to that rank in the directory overall.
Why the gap is this wide
Detection is expensive to operate. It needs staffed hours, tooling with a per-endpoint cost, and someone to answer at two in the morning. Prevention — a firewall, a patching policy, an email filter — can be delivered by the same engineers who run the help desk.
So the honest reading of 94.7% is not that those providers are lying about security. It is that most of them sell the preventive half, and the market's language does not distinguish the two halves. A buyer asking for "managed security" will be answered by 19,959 firms and served detection by roughly a thousand.
The 12 firms that name a detection service and carry no other security tag are worth noting for the arithmetic: detection is not a strict subset of the security-selling group, which is why 19,959 minus 1,071 does not equal 18,900.
What this number can't tell you
- ·This measures the words providers publish about their services, not audited capability. A provider running a genuine 24-hour operation that never names it is counted in the 94.7%, and naming a service is not evidence of running one well.
- ·Services are on file for 35,344 of the 39,235 published firms, so 50.9% and 2.7% are both floors and an unknown counts against them.
- ·SOC 1 and SOC 2 references are excluded from the detection count. 49 firms name a SOC audit or attestation, which is a compliance report, not a security operations center; an earlier pass that matched "soc" as a substring counted those as detection and was wrong.
- ·Short acronyms are matched on token boundaries, not as substrings. Matching "edr" as a substring pulled in fedramp_compliance — "f-EDR-amp" — and inflated an earlier count.
- ·Detection is not a strict subset of the security-selling group: 12 firms name managed or endpoint detection with no broader security tag, so the two counts do not subtract cleanly.
- ·Certification shares are what providers publish, not what they hold, and the difference between 23.1% and 23.4% is well inside what this method can resolve. It should be read as "no difference", not as a small one.
- ·Rating values are not plotted, only rating presence and review count, because google_rating bunches at the top of its range.
- ·The explanation offered for the size of the gap — that detection costs staffed hours while prevention does not — is an interpretation. We measured the gap, not its cause.
- ·This card overlaps two others by design and does not restate them: security-washing measures published proof among security sellers, and the MSSP definition card measures the 1,897 firms classified as MSSPs. Neither is rebased here.
What to do about it
- ▸Buying: ask one question — who watches the alerts, and when. "Managed security" is claimed by half the directory; a staffed detection capability is named by 2.7%. If a provider cannot say what tool generates the alert and who answers it overnight, you are buying prevention.
- ▸Selling: naming the detection stack is unusual enough to be a position by itself, because 94.7% of your security-selling competitors do not. If you resell someone else's detection, say whose — the directory cannot tell a buyer that and neither can your competitors' websites.
Questions this finding answers
- How many US providers operate as a managed security service provider?
- Half the directory sells security. One in nineteen of those names a SOC, SIEM, MDR, EDR, XDR or threat-hunting service — the tools that notice an intrusion rather than prevent one.
- How was this measured?
- n = 39,235 published US providers. 19,959 name at least one security service; 1,071 name a detection capability (SOC, SIEM, MDR, EDR, XDR, SOAR, managed or endpoint detection, threat hunting), of which 1,059 also carry a broader security tag. Services are on file for 35,344 of the 39,235, so both shares are floors. SOC 1 and SOC 2 audit references are excluded from detection — an attestation report is not a detection capability. Measured 2026-09-09 in one repeatable-read snapshot.
- What can't this number tell you?
- This measures the words providers publish about their services, not audited capability. A provider running a genuine 24-hour operation that never names it is counted in the 94.7%, and naming a service is not evidence of running one well.
Where does your firm sit on this?
Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.
Claim your MSP ▸Related markets
More findings
- 42.8%16,794 US providers name cybersecurity. Every specific security service is named by under 3.1% of the market.
- 0.95%374 US IT providers name security-operations work — 0.95% of the market.
- 32.5%12,907 US IT providers name healthcare — 32.5% of the market.
- 5.0%Only 5.0% of US IT providers name Microsoft 365 as a service.