← Back to Blog
HailBytes ASM

Reselling Continuous ASM as a Deliverable Between Pentests

April 16, 2026 • 10 min read

ASM · Pen-Test Recurring Revenue
How MSSPs Scale Recon: Multi-Tenant Attack Surface Management video thumbnail

Watch: how service providers run recon across a client portfolio.

Updated August 1, 2026. The pricing models and the sample P&L below have been recalculated against the current published ladder, which now starts at 8 vCPU, and the article has been reworked in a more important way than that. A previous revision built the whole margin case on one 8-vCPU instance shared across twenty monitored clients. That is not a configuration we can stand behind: running many monitored clients off a single shared ASM instance on recurring scheduled scans is not supported today, so the honest planning assumption is one instance per monitored client. That makes the platform line per client much larger, and it changes which of the pricing models below actually work. The lever that replaces consolidation is runtime — the meter bills only while the instance is running — and the arithmetic for that is shown in full.

Pen-test firms have a structural revenue problem. The work is project-based, the engagements are episodic, and the gap between a Q1 external assessment and the next one in Q3 is six months in which the client’s attack surface drifted, three new subdomains spun up in marketing’s account, an S3 bucket got reconfigured, and a TLS cert on a forgotten staging host expired into something exploitable. None of that shows up in the next report because none of it is being watched.

The firms that have figured out continuous ASM as a between-engagement deliverable are running it for two reasons. The honest one: they want recurring monthly revenue against the same client base they already have project relationships with. The defensible one: it makes their next pentest engagement materially better, because they walk in already knowing what changed.

This article covers how to package continuous ASM as a service line on top of HailBytes ASM. White-label scoping, three pricing models that work, the engagement mechanics that make it stick, and the operational mistakes that kill the margin.

Two ways to use HailBytes ASM in a pen-test firm

Before getting to pricing, get clear on which of these your firm is actually doing. The economics and the sales conversation are different.

Internal scoping accelerator (firm-only)

You run HailBytes ASM internally as a pre-engagement reconnaissance and scoping tool. The output never leaves your firm. Used to scope SOWs faster (an external assessment quote in 24 hours instead of a week), to prep your testers before kickoff, and to prevent the “we discovered three subdomains halfway through the engagement” problem that blows up your hour budget. This is a cost-side investment that pays back as faster sales cycles and tighter engagement margins.

Continuous monitoring deliverable (client-facing)

You run a HailBytes ASM instance per monitored client, white-labeled as part of your firm’s service offering, and bill the client monthly for ongoing external monitoring between point-in-time engagements. This is a recurring revenue line. Margin lives in the spread between the monthly fee and two costs: the platform, and the analyst time required to triage findings and produce a monthly written summary the client’s security team can act on.

Plan on one instance per monitored client. Running a book of monitored clients off one shared instance with recurring scheduled scans is not a supported configuration today, so do not build a price list on the assumption that the platform cost divides across your portfolio. It does not. At the 8-vCPU entry size the platform is $1,400/month of software plus roughly $280/month of cloud infrastructure — about $1,680/month all-in per monitored client at list if you leave it running 24/7, or about $1,260 on a one-year commitment paid upfront.

The lever that makes this work is runtime, not consolidation. The marketplace meter bills only while the instance is running, and continuous monitoring in practice means a scan on a schedule, not a scanner spinning all month. At roughly 100 running hours a month the software line is 100 h × 8 vCPU × $0.24 = $192. Two caveats, both of which cut against the optimistic reading: the infrastructure side does not fall away with the meter, because the managed database and storage persist between scans, so keep budgeting the full $280; and a term commitment is prepaid for the whole term regardless of runtime, so you take the commitment discount or the runtime saving, never both. On scheduled runtime at list, the all-in platform cost is therefore about $472/month per client, and that is the number the models below are built on.

Most firms doing this well end up running both motions: internal scoping for every prospect and active engagement, plus client-facing continuous monitoring for the subset of clients who want and can afford it. The rest of this article focuses on the second motion, where the revenue is.

Three pricing models that work

Model 1: Retainer add-on ($750–$1,500/month, and only on scheduled runtime)

Sold as an add-on to clients who already have an annual or semi-annual pentest engagement with you. Positioned as “continuous external monitoring between assessments, with monthly delta reports and immediate alerting on net-new high-severity exposures.” The recurring fee is small enough that the client’s security lead can approve it without budget cycles, and it turns a one-engagement-per-year client into a 12-month recurring relationship.

The band starts at $750 rather than the $500 an earlier version of this article used, because $500 does not cover the platform plus any meaningful consultant time on a per-client instance. If your firm wants a $500 price point, it has to be an alerting-only tier with no monthly written report, and you should price it knowing the consultant line is what you are removing.

This is the model that lands fastest in firms whose existing client base is mid-market companies with internal security teams of 1–3 people. They want the watching, they don’t want to staff for it, and they trust your firm because they already bought the pentest.

Model 2: Standalone monitoring service ($1,500–$5,000/month, per attack surface size)

Sold as its own service line, priced by the size of the client’s external attack surface (apex domains in scope, expected subdomain count, IP ranges). Includes the monitoring platform, a monthly written report from a senior consultant, and a quarterly deeper-dive readout call. Clients at this tier may or may not also do annual pentests with you; the monitoring stands on its own as a complete offering.

This works when the firm has the operational discipline to deliver a real monthly report rather than a CSV dump. Margin compression risk is real if the analyst time isn’t tightly bounded. On per-client instances the $1,500 low end clears comfortably on scheduled runtime (~$472/month of platform) but does not clear an instance left running 24/7 at list (~$1,680/month all-in) once you add consultant time. If a client’s contract requires genuinely continuous scanning rather than scheduled, price them at the top of this band or in Model 3.

Model 3: Compliance-driven monthly attestation ($2,000–$7,500/month)

Sold to clients in regulated industries (healthcare, financial services, defense supply chain) who need documented evidence of continuous external monitoring for SOC 2, ISO 27001, NIST CSF, PCI DSS, or HITRUST. The deliverable is a monthly attestation letter from your firm, signed by a named consultant, mapping the prior-month monitoring activity to specific control requirements. The client uses it as audit evidence; you charge a premium for the consulting overhead.

This is the most defensible pricing tier because the client cannot easily DIY it. They need an outside firm’s name on the attestation. It’s also the longest-tenure model: clients in this tier renew on multi-year cycles tied to their audit calendar, which pairs well with a term commitment on the meter. It is also the only model here that clears an instance left running 24/7, which matters because an attestation client is the one most likely to insist on genuinely continuous rather than scheduled scanning. On a three-year commitment: $2,000 revenue less ~$1,120/month of platform ($840 software + $280 infrastructure) less $400 of consultant time leaves about $480. At list rather than committed, the same client is roughly −$80/month, so write the term.

Sample P&L: Model 1 retainer add-on at $750/month

Mid-market client, 8 apex domains in scope, ~120 subdomains, on its own 8-vCPU HailBytes ASM instance. Two runtime shapes side by side, because that is the choice that now dominates the result: the instance scheduled at roughly 100 running hours a month, and the instance left running 24/7. List prices throughout; infrastructure at the whole-stack rate of ~$35/vCPU/month, held at the full $280 in both columns because the database and storage persist between scans.

Line ItemScheduled, ~100 h/mo ($/mo)Running 24/7 ($/mo)
Revenue: retainer add-on+750+750
HailBytes ASM marketplace meter at 8 vCPU (100 h × 8 × $0.24 / $1,400 at 730 h)−192−1,400
Cloud infrastructure (instance, database, storage, scan egress)−280−280
Senior consultant triage + monthly summary (~2 hr at $200/hr)−400−400
Monthly gross margin−122−1,330

The headline finding is uncomfortable and worth stating plainly: at $750/month, this client loses money in both columns. Left running 24/7 it loses $1,330/month, and no amount of analyst-time discipline fixes a $1,680/month platform line — a three-year commitment only brings it to about −$770/month. Even scheduled down to 100 running hours it is still −$122/month, because the consultant line is the bigger cost at that point. The previous version of this article showed +$266 here by dividing one instance across twenty clients. Remove that assumption and $750/month does not clear a full monthly report.

There are two honest ways to fix it, and they pull in opposite directions.

  1. Tighten the consultant line. If your monthly summary is templated, the platform handles delta detection automatically, and your consultant only spends real time on the months where ASM surfaces an actual high-severity finding (typically 1–2 months a quarter), the average drops to about 45 minutes/month, or $150. On scheduled runtime that turns the P&L positive: $750 − $192 − $280 − $150 = +$128/month, roughly $1,500/year per client. Real, but thin enough that one difficult client erases it. On the 24/7 shape the same discipline still leaves you at −$1,080/month.
  2. Charge more. The same scheduled instance and the same 2-hour report at $1,500/month yields $628/month, or about $7,500/year per client, which is a service line rather than a rounding error. Our read is that this is the right answer for most firms: the work genuinely costs what it costs, and pricing a monthly senior-consultant deliverable at $750 was under-charging even before the platform floor moved.

The reason firms still run the low tier anyway: the retainer doesn’t exist on its own. It rides alongside the annual pentest engagement at $20K–$60K, which the recurring monitoring relationship makes both more likely to renew and faster to scope. If you treat the retainer as customer-retention infrastructure rather than primary revenue, running it near breakeven is a defensible choice — just make it a deliberate one rather than a modelling error.

White-labeling: what to put your name on, what to leave alone

HailBytes ASM is built to be deployed inside your firm’s AWS or Azure account, which means you control the access surface entirely. The white-label question is what the client actually sees in your deliverables.

  • Monthly written report. Fully your firm’s document, branded, signed by a named consultant. Pull data from the ASM exports and assemble in your existing report template. This is the deliverable the client’s CISO forwards to their board.
  • Real-time dashboard access. If you give the client direct access to the ASM dashboard (most firms don’t for Model 1), put it behind your firm’s SSO and a custom subdomain. The platform is a tool; the relationship is yours.
  • High-severity alerting. Route critical-finding webhooks into your firm’s ticketing system, not the client’s. Your senior consultant validates and triages first, then escalates to the client with context. The client is paying for human judgment on top of automated detection.
  • Attestation letters (Model 3). On your firm’s letterhead, mapped to the client’s control framework, signed by a named partner or director. The client’s auditor recognizes your firm; that’s the asset they’re paying for.

How continuous ASM makes your pentests better

The hidden margin lever in this whole motion is what continuous monitoring does to your existing pentest engagements with the same clients. Three concrete operational improvements:

  1. Scoping happens in 30 minutes. When the client asks for an external pentest quote and you already have 9 months of attack-surface data on their environment, you know the asset count, the subdomain churn rate, the tech stack signals, and the obvious exposed services. Scoping calls that used to take a week become a same-day SOW.
  2. Pre-engagement recon is already done. Your testers walk into the engagement with a current asset inventory and a starting list of weak signals to chase down. Instead of burning the first 30% of the engagement on reconnaissance, they spend it on exploitation and impact analysis. Either you bill the client more efficiently, or you absorb the savings as engagement margin.
  3. Findings have context. “We found this exposed Jenkins instance” lands differently when the report can say “exposed since March 14, three weeks before this engagement, with no internal owner identified during ASM monitoring.” That context is the difference between a finding the client patches and a finding the client takes to their board.

Operational mistakes that kill the margin

  • Letting the monthly report bloat. Set a hard cap: 3–5 pages, executive summary on page one, no raw scan dumps. Every page beyond five is consultant time you’re not getting paid for.
  • Sending the client every alert. The platform will surface dozens of low-severity changes per month. The client doesn’t want them; they want the two or three that matter, with your consultant’s opinion on whether to act. Triage discipline is the product.
  • Mixing up the trial path. The AWS and Azure marketplace listings include a 30-day free trial. Use it to evaluate the platform on your firm’s own attack surface first, before you stand up your first client instance. The trial tends to make the internal scoping use case obvious before you ever commit to client-facing delivery.
  • Pricing per-asset instead of per-client. Asset counts drift; the client pushed three new subdomains live last week and you’re going to chase them for a contract amendment? Don’t. Price per client at a tier that accommodates reasonable growth.

The reNgine question

Pen-test firm CTOs evaluating HailBytes ASM almost always ask the same question: “What’s the difference between this and the open-source reNgine I could host myself?” The honest answer for the internal-scoping use case is “not much, if you have the engineering time to host it.” The honest answer for the client-facing recurring-revenue use case is different: when you bill a client $750–$5,000/month for continuous monitoring, the platform’s uptime, the audit logging, the marketplace billing path your client’s procurement will accept, and the ability to point at a vendor SLA become operational requirements. Self-hosting a free open-source tool against client SLAs is a worse business than running someone else’s managed deployment. Different math, different decision.

Scope Reseller Terms or Try It on Your Own Firm First

If you want to scope what continuous ASM as a client deliverable would look like for your firm (pricing tiers, white-label setup, expected margin against your existing client base), we’ll walk you through it. Or spin up a 30-day trial on the AWS or Azure marketplace and run it against your own attack surface first.