Operating picture · measured 2026-09-09

374 US IT providers name security-operations work — 0.95% of the market.

SOC as a service is sold as a category. In the US directory it is named by 374 firms, and another 49 use "SOC" to mean an audit report instead.

0.95%

of 39,235 US providers name a SOC or security-operations service

n = 39,235 published US providers, of which 374 name security-operations work — a SOC, a security operations center, managed SOC, SOC monitoring or SOC as a service — with SOC 1 and SOC 2 audit references excluded. 49 firms name a SOC audit or attestation, of which 11 also name operations work, so 38 use the three letters in the audit sense alone. Services are on file for 35,344 of the 39,235, so 0.95% is a floor. Measured 2026-09-09 in one repeatable-read snapshot.

Providers naming security-operations workbase 39,235
1% Name a SOC or security operations (374)Do not (38,861)
The detection stack, by firms naming each component
SOC / security operations374
Threat hunting or detection342
MDR / managed detection309
EDR / endpoint detection247
SIEM188
XDR67
SOAR24
Two meanings of the same three letters
SOC as an operation
374 firms — a place where alerts are watched
Share of directory
0.95%
Also name SIEM
188 firms
Also name SOAR
24 firms
SOC as an audit
49 firms — a SOC 1 or SOC 2 attestation report
Share of directory
0.12%
Name both senses
11 firms
What it proves
Controls, not detection

The published statistic behind this

23.8% of the providers we have checked claim 24/7 support on their own website, 5,871 firms of 24,675 checked.

n = 24,675 providers checked · measured 2026-09-17. The figures on this page are frozen at their own measurement date and are not recomputed from that table.

Share claiming 24/7 support

The narrowest capability claim we can measure

374 of 39,235 published US providers name security-operations work among their services — 0.95%. That is narrower than any vertical claim on this site and narrower than every other security service we count.

For scale: 19,959 providers in this directory name some security service and 16,794 name cybersecurity specifically. The number that names the thing a SOC actually is — a staffed place where alerts are watched — is 374.

The rest of the detection stack is the same order of magnitude. Threat hunting or threat detection 342 firms, MDR 309, EDR 247, SIEM 188, XDR 67, SOAR 24. Each of the seven is under 1% of the directory.

SOAR at 24 firms is the real end of the chain

The seven components form a rough sequence. A SIEM collects the logs, detection tooling raises the alert, a SOC staffs the watch, and SOAR automates the response. 188 firms name the collection layer and 24 name the automation layer.

Twenty-four firms out of 39,235 is 0.06%. Whatever automated security response is in this market, it is not a thing US IT providers advertise, and a buyer who wants it should assume they are commissioning it rather than buying it off a list.

188 firms naming SIEM against 374 naming a SOC is the more surprising pair. More providers claim to staff a watch than claim to run the log platform the watch would look at, which is consistent with most SOC claims being a resold service rather than an in-house build.

Three letters, two completely different products

49 providers in this directory use "SOC" to mean a SOC 1 or SOC 2 audit — an attestation report about a company's internal controls, produced by an accountant. It is a compliance document. It watches nothing.

11 firms name both senses, which is legitimate: a provider can hold a SOC 2 report and also run a security operations center. But a buyer reading "SOC" on a proposal has no way to know which one is meant, and the two answer entirely different questions.

This distinction is not pedantry — it was a measurement error before it was a finding. An earlier pass in this session matched "soc" as a substring, counted soc_1_audits and soc2_compliance as detection capability, and would have published an inflated number. Excluding the audit sense is what produced 374.

What this number can't tell you

  • ·374 firms is a small base against 39,235. Each firm moves the directory share by 0.003 points, so the share is quoted to two decimals and no further.
  • ·This measures what providers publish, not what they operate. A provider running a genuine staffed operation that never names it is not counted, and naming a SOC is not evidence of running one.
  • ·Services are on file for 35,344 of the 39,235 published firms, so 0.95% is a floor and an unknown counts against it.
  • ·Nothing here distinguishes an in-house SOC from a resold one. The SIEM-against-SOC comparison suggests reselling is common, but that is an inference from two counts, not a measurement of who builds and who resells.
  • ·SOC 1 and SOC 2 audit references are excluded from the 374. An earlier substring match in this same session counted them as detection and produced an inflated figure; the exclusion is the correction.
  • ·Short acronyms are matched on token boundaries rather than as substrings, because a substring match on "edr" also matches fedramp_compliance.
  • ·The seven stack components overlap heavily — most firms naming SOAR also name SIEM — so the bars are not additive and do not describe seven distinct groups.
  • ·We hold no measurement of staffed hours, response times or whether any of these operations run overnight, which is the question a buyer most needs answered.

What to do about it

  • Buying: "SOC as a service" needs three questions — is it yours or resold, what are the staffed hours, and what is the SIEM underneath. 374 providers name the service; 188 name a SIEM, so a fair number cannot answer the third question about their own stack.
  • Selling: at 0.95% this is the least contested capability claim in the directory. If you run or resell one, naming the SIEM and the staffed hours alongside it distinguishes you from most of the 374, let alone the 16,794 firms whose security offer is the word cybersecurity.

Questions this finding answers

How many US providers offer SOC as a service?
SOC as a service is sold as a category. In the US directory it is named by 374 firms, and another 49 use "SOC" to mean an audit report instead.
How was this measured?
n = 39,235 published US providers, of which 374 name security-operations work — a SOC, a security operations center, managed SOC, SOC monitoring or SOC as a service — with SOC 1 and SOC 2 audit references excluded. 49 firms name a SOC audit or attestation, of which 11 also name operations work, so 38 use the three letters in the audit sense alone. Services are on file for 35,344 of the 39,235, so 0.95% is a floor. Measured 2026-09-09 in one repeatable-read snapshot.
What can't this number tell you?
374 firms is a small base against 39,235. Each firm moves the directory share by 0.003 points, so the share is quoted to two decimals and no further.

Where does your firm sit on this?

Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.

Claim your MSP ▸

Related markets

More findings

◂ All 39 findings