There are two ways to buy IT support and they are priced on opposite principles. Break-fix bills by the hour, roughly $100 to $350, and the provider earns money when something is broken. A managed contract bills per user per month, roughly $102 to $400, and the provider earns the same whether anything breaks or not. Comparing the two on price alone compares the wrong thing entirely.
| Service | Typical |
|---|---|
| Managed IT supportNational range | $102 to $400 per user, per month |
| Break-fix IT support, hourlyNational range | $100 to $350 per hour |
| Custom software developmentNational range, boutique and small US agency | $75 to $250 per hour |
Ranges last checked September 2026. They come down automatically when they are due to be rechecked.
Every figure above comes from a named source we can link to, with the date we last checked it. We publish ranges rather than single prices because a range is what a provider will actually give you: the same job moves with what is being worked on, the materials, how hard it is to get at and how busy the trade is locally. Treat these as the order of magnitude to expect before you call, not as a quote.
The figures here are national. Where a source publishes figures state by state, the state pages carry that local figure instead of this one. We do not scale a national number by a multiplier of our own invention.
Every range carries a review date. When that date passes the number comes down until it is rechecked, rather than sitting here undated.
Break-fix is where most small businesses start. You call when something stops working, a technician bills their time, and nothing at all happens between calls. There is no monitoring, no patching and no backup verification in the gaps. Response is whatever the provider can fit in, on whatever schedule they have room for.
A managed contract inverts the arrangement. A flat monthly fee per user buys steady-state operation, and a contractual response time comes with it. The provider absorbs the cost of things going wrong. Synoptek, which sells managed services and is therefore not a neutral party, puts the incentive plainly: a break-fix provider only makes money when the business suffers a disruption.
That is the real difference, and it is invisible in an hourly rate set against a monthly rate. The question is not which is cheaper per unit. It is which one is being paid to prevent the problem.
Projects. On a full managed agreement the monthly seat fee covers running the environment as it stands; changing it is scoped and billed on top. Equipment installation, server migrations, software upgrades and after-hours emergency work all sit outside. Third-party licensing is usually passed through at cost, and some providers charge an onboarding fee of roughly one month of support.
So ask for the project rate card at the same time as the monthly quote. A low seat price with an unseen project rate behind it is not the cheaper contract, and you will not find that out until the first migration.
Cyber insurance underwriting has tightened to the point where it reads like a specification. Multi-factor authentication enforced across all accounts, with particular scrutiny on VPN, remote desktop and administrator access. Managed detection and response with human monitoring, because endpoint tools without oversight no longer satisfy underwriters. Tested, isolated backups. A documented incident response plan. Centralized logging with defined retention.
One study across more than ten thousand policies found the backups question on applications was answered incorrectly or incompletely ninety percent of the time. Those answers are representations on an insurance application. The practical consequence is that the security tier of an IT contract is often decided by an underwriter rather than by the buyer.
No federal or state credential is required to provide IT services or write software. What exists instead are vendor certifications and voluntary frameworks, which are worth something but are not licensure and should not be read as it.
One federal rule does reach further into ordinary small business than most buyers expect. The FTC Safeguards Rule, 16 CFR Part 314, applies to non-bank financial institutions under FTC jurisdiction, and that list includes tax preparation firms, mortgage brokers and lenders, collection agencies, credit counselors, investment advisers not registered with the SEC, payday lenders and check cashers. It requires a named Qualified Individual, a written risk assessment, encryption of customer information at rest and in transit, multi-factor authentication for anyone accessing customer information, annual penetration testing, vulnerability scans every six months, a written incident response plan, and oversight of service providers, which means oversight of the IT provider itself. Businesses holding information on fewer than five thousand consumers are exempt from certain provisions.
If a business falls inside that rule, the contract is not only a purchase. It is part of the compliance record.
Decide which model you are buying before you compare any numbers. If the answer is that you want someone to call when things break, you are buying break-fix and the hourly rate is the number that matters. If the answer is that you want fewer things to break, you are buying a managed contract and the seat price is the number that matters. Quotes for the two are not comparable and should not be laid side by side.
Ask what happens between calls. On a managed agreement, monitoring, patching and backup verification are the product. A provider who cannot describe what they do on a quiet week is selling break-fix with a monthly invoice attached.
Get the project rate card up front, and ask specifically what counts as a project. That boundary is where the monthly fee stops, and every provider draws it in a slightly different place.
Ask who is on the other end at two in the morning, and whether that is inside the contract. After-hours is the most common carve-out and the most expensive one to discover during an outage.
On a software build, ask for the maintenance figure before you sign the build. Ten to twenty percent of the original cost, every year, is the industry pattern, and a build quoted without it is quoted incompletely.
Published 2026 guides put it between $102 and $400 per user per month. VC3 gives $150 to $400 and Dataprise gives $102 to $210, so the honest answer is a wide band that depends on which tier of security and compliance you are buying.
Between about $100 and $350 an hour, depending on the guide and the seniority of the technician. Emergency and after-hours call-outs can double or triple the base rate.
That is the wrong comparison. Break-fix pays a provider when something breaks; a managed contract pays the same whether or not it does. The cheaper one on paper is often the more expensive one over a year.
No. Project work sits outside almost every managed agreement, and so does after-hours emergency support on many of them. Ask for the project rate card alongside the monthly quote.
No. There is no federal or state license to provide IT services or write software. What you will see instead are vendor certifications, which are real but are not licensure.
A boutique or small US agency runs about $75 to $250 an hour, and around two thirds of projects land between $30,000 and $100,000 in total. Budget another 10 to 20 percent of the build cost every year for maintenance.