Operating picture · measured 2026-09-08
1,897 US firms present as MSSPs — and only 7.4% of them name managed security services as a service.
A managed security service provider runs your security the way an MSP runs your IT. Here is what the ones in this market actually publish.
US firms classified as MSSPs, out of 39,188
n = 39,188 published US firms in the IT services market; 1,897 are classified as MSSPs. Shares labeled "of MSSPs" are against those 1,897 and are floors, since services are on file for 1,780 of them and certifications for 634. Market-wide shares are against the whole 39,188. Measured 2026-09-08 in one snapshot.
The published statistic behind this
MSP Signal tracks 40,647 active IT service providers, classified into 13 categories.
n = 40,647 active providers · measured 2026-09-17. The figures on this page are frozen at their own measurement date and are not recomputed from that table.
Providers tracked by category ▸The short answer
An MSSP — managed security service provider — is a firm you pay a recurring fee to run your security: monitoring your systems for attacks, investigating what the monitoring finds, and responding when something is real. The managed part means it is ongoing and contracted, not a one-off project.
It is the security-specialist version of an MSP. Where an MSP takes responsibility for whether your IT works, an MSSP takes responsibility for whether it is being attacked.
1,897 of the 39,188 firms in this market are classified that way — 4.8%. It is the smallest of the four categories we track, behind IT consulting at 18,779, MSPs at 16,455 and VAR and telecom resellers at 2,057.
What they actually publish
Cybersecurity is named by 1,206 of the 1,897, or 63.6%, and compliance by 887, or 46.8%. Those two are the business.
Then the security-operations work a buyer is usually shopping for: penetration testing at 15.2%, incident response at 14.1%, vulnerability management at 6.3% and cloud security at 5.9%.
The odd result is the label itself. Only 140 of the 1,897 — 7.4% — name "managed security services" as one of their services. Firms in this category describe the work they do rather than the category they are in, so searching for the phrase is a poor way to find them.
And they are not purely security shops. 449 name cloud migration, 444 name backup and disaster recovery, 192 name managed IT and 165 name IT consulting. Most MSSPs sell general IT work alongside the security practice.
Proof is the category's real differentiator
634 of the 1,897 MSSPs, 33.4%, show at least one certification. That is the highest rate of any category in this market — MSPs are at 20.9%, IT consultancies 10.4%, VAR and telecom 6.4% — and it is still only a third.
The mix leans toward regulatory frameworks rather than security audits: HIPAA at 16.8% and CMMC at 13.2% come ahead of SOC 2 at 11.8%, NIST at 10.5%, PCI DSS at 9.6% and ISO 27001 at 7.9%. FedRAMP, the federal cloud authorization, appears for 44 firms, or 2.3%.
Every one of those is a floor. 1,263 of the 1,897 MSSPs show us no certification at all, and that is a statement about what is published, not about what is held.
Where they are
MSSPs cluster where the rest of the market clusters: California 204, Texas 187, Florida 165, New York 120 and Virginia 98.
As a share of each state's own directory the ordering changes. Florida is the most security-dense at 6.4% of its 2,565 firms, then New York at 6.1%, Georgia at 5.5%, Texas at 5.4% and California at 5.4%. New Jersey is the thinnest of the top ten at 3.8%.
Virginia is worth naming separately: 98 MSSPs, but only 4.9% of its 2,010 firms, which is below the national density despite the federal market on its doorstep.
What to ask one
Ask what "managed" covers overnight. The category name promises continuous coverage; 14.1% of these firms name incident response, so ask specifically who acts at 3am and under what commitment.
Ask for the report, not the framework. HIPAA and CMMC lead the certification mix, and those are compliance regimes rather than audits of the provider itself. A SOC 2 report says something about how the provider runs; 11.8% of MSSPs have one to show.
Ask what you are buying besides security. Most MSSPs here also sell cloud, backup and general managed IT, which can be an advantage or a distraction depending on whether you already have an MSP.
Ask the price in writing. Only 18 of the 1,897 publish a per-user, per-month rate anywhere we can find it.
What this number can't tell you
- ·The MSSP category is MSP Signal's own classification from what each firm publishes. There is no MSSP registry and no self-identification step, so the boundary with a security-led MSP is genuinely blurry.
- ·Services are on file for 1,780 of the 1,897 MSSPs and certifications for 634, so every share here is a floor — "shows us", not "holds".
- ·Service labels come from a controlled vocabulary matched against provider sites. The 7.4% for "managed security services" is a tag frequency, not a measure of how many of these firms sell managed security; the category count answers that.
- ·Certification tokens are unioned across spellings where a credential is recorded two ways (`soc2` with `soc_2`, `cmmc` with `cmmc_l2`, `iso_27001` with `iso27001`). Counting a single spelling would understate each.
- ·State counts are by headquarters state, so a firm serving a region is counted once, where its head office is.
- ·The 18 MSSPs publishing a seat rate is a count, not a sample — no price median is quoted from it anywhere on this page.
What to do about it
- ▸Buying: shortlist on published proof and stated response commitment. A third of this category shows any certification and 11.8% show a SOC 2, so asking for one immediately narrows the field to the firms that can answer.
- ▸Buying: do not search for the phrase. Only 7.4% of MSSPs use "managed security services" as a service label, so browsing by what firms do — monitoring, incident response, penetration testing — finds more of them than the category name does.
- ▸Selling: 66.6% of your own category shows no certification and 99% publish no seat rate. Publishing either one makes you the comparable option in a category buyers currently cannot compare.
Questions this finding answers
- What is an MSSP?
- A managed security service provider runs your security the way an MSP runs your IT. Here is what the ones in this market actually publish.
- How was this measured?
- n = 39,188 published US firms in the IT services market; 1,897 are classified as MSSPs. Shares labeled "of MSSPs" are against those 1,897 and are floors, since services are on file for 1,780 of them and certifications for 634. Market-wide shares are against the whole 39,188. Measured 2026-09-08 in one snapshot.
- What can't this number tell you?
- The MSSP category is MSP Signal's own classification from what each firm publishes. There is no MSSP registry and no self-identification step, so the boundary with a security-led MSP is genuinely blurry.
Where does your firm sit on this?
Claim your MSP with a magic link from your company email to see your own certifications, reviews, web footprint and local rank measured against every provider we track.
Claim your MSP ▸Related markets
More findings
- 9.1%Project work is listed almost twice as often as managed work: 53.0% of US IT firms name a project service, 28.6% name a managed one.
- 15.5%6,083 US IT providers name education — 15.5% of the market.
- 32.1%4,027 US IT providers name construction — and they are the best-credentialed vertical group we measure.
- 17.6%6,897 US IT providers name manufacturing — 17.6% of the market, and the largest firms of any vertical we measure.