---
title: "Your Pen-Test Bench Sells Out Every October. Demand Models Now Price the Q4 SOC 2 Crush Before You Quote It."
description: "Security firms sell out every October. How 2026 demand forecasting and pricing models set the Q4 rate card and book tester capacity back in July, with numbers."
canonical: https://callsphere.ai/blog/your-pen-test-bench-sells-out-every-october-demand-models-now-price-th
category: "IT & SaaS Support"
tags: ["penetration testing", "mssp pricing", "demand forecasting", "soc 2", "capacity planning", "managed security"]
author: "CallSphere Team"
published: 2026-06-22T11:16:04.000Z
updated: 2026-07-25T23:18:52.173Z
---

# Your Pen-Test Bench Sells Out Every October. Demand Models Now Price the Q4 SOC 2 Crush Before You Quote It.

> Security firms sell out every October. How 2026 demand forecasting and pricing models set the Q4 rate card and book tester capacity back in July, with numbers.

It is the second Monday in October, and the whiteboard in the small conference room has twelve columns on it — one per week until the holidays — and six rows, one per tester. Every square is filled except four in Thanksgiving week. The sales engineer is in the doorway because there is a scoping call at eleven: a payments company wanting an external test, an internal test, two web application tests and a segmentation check, all before their SOC 2 observation window closes on 31 December.

You know how this goes. You will quote it. You will win it. And in November you will pay a subcontractor $12,500 for a tester-week you could have booked in July for $8,500 — on an engagement priced at last year's rate.

## The pile-up is not random, and everybody in this trade pretends it is

Security services demand looks lumpy inside one quarter and looks like clockwork from three years up. SOC 2 Type II observation windows overwhelmingly end on 31 December, pushing the required penetration test and the remediation retest into October and November. PCI DSS testing clusters around each merchant's assessment anniversary, often in Q1. Federal fiscal year end on 30 September pulls DoD subcontractors' CMMC readiness work into August; municipal clients spend before 30 June. Cyber insurance renewals cluster in January, and every renewal application asks whether an independent test was performed in the last twelve months.

None of that is a mystery. It is sitting in your PSA right now. But the way most firms of nine to forty people actually forecast is: the owner scrolls the open opportunities in ConnectWise Manage or Autotask, adds a gut number for "the stuff that always comes in late", and sets the tester calendar six weeks out. Pricing works the same way — a rate card built two Januarys ago and a discount the account manager invents on the call to keep the logo.

**Demand forecasting in a security services firm means predicting how many tester-weeks, analyst-hours and assessment days your clients will actually buy in a given month, early enough to price and staff for it rather than subcontract your way out of it.**

## What the fixed-fee quote actually gets wrong

Two errors cost you money, and they compound in the same eleven weeks.

The first is capacity. Your constraint is not sales, it is the small number of people with OSCP or GPEN behind their name who can run an internal test unsupervised and write a report a client's auditor accepts without a second call. When October arrives short you have three bad options: subcontract at spot rates, push the client into January and watch them phone a competitor, or let one senior tester carry six engagements and hand PlexTrac reports to the delivery manager three days late.

The second is price. Fixed-fee quotes come off a scoping questionnaire — live host count, applications, authenticated or not, segmentation in scope or not — then a flat fee. What that questionnaire never captures is the two days of scope creep from a client whose asset inventory was wrong, the retest your statement of work said was included, and the four hours the delivery manager spends on a findings call with the client's insurance broker. Blend those in and Q4 work runs at half the margin of the identical engagement sold in May.

## What actually changed in 2026

Demand forecasting and price optimisation quietly became two of the highest-adoption uses of AI anywhere in the economy — forecasting sits near 48% adoption in manufacturing, pricing near 72% in retail and e-commerce. That did not happen because owners took an interest in statistics. It happened because the 2026 generation of models copes with the kind of history a services firm actually has: three or four years of it, full of gaps, with churned clients, a rate card that changed twice, and service names that mean different things depending on who typed them. The older forecasting tools wanted tidy monthly numbers going back a decade. These do not.

So you can hand over the messy record — closed-won opportunities with close dates, service type, hours delivered against hours quoted, each client's audit anniversary and headcount at signing — and get back a month-by-month view of tester-weeks required, with the confident parts and the shaky parts marked separately. Then ask what happens if you raise the Q4 internal-test rate 8% and offer 10% off for January delivery.

```mermaid
flowchart TD
  A["Closed-won history in ConnectWise / Autotask"] --> B["Add each client's audit window end and renewal month"]
  B --> C["Forecast tester-weeks needed, month by month"]
  C --> D{"Forecast weeks > bench weeks?"}
  D -->|"Yes"| E["Raise Q4 rate and pre-book subcontractors in July"]
  D -->|"No"| F["Hold the rate card, sell the open weeks"]
  E --> G["Delivery manager locks the October calendar"]
  F --> G
  G --> H["Compare quoted hours to delivered hours every month"]
```

## A Tuesday in July, running next October's book

The delivery manager exports three years of closed engagements from the PSA — service type, client, quoted fee, hours delivered, tester assigned, close date, delivery month. She adds two columns nobody normally tracks: the client's audit window end date, which sits in Vanta or Drata or the auditor's engagement letter, and their cyber insurance renewal month, which is in the MSA folder. Then she hands the whole thing to Claude Cowork with a plain instruction: build the month-by-month tester-week demand for the next four quarters, flag the months that exceed six testers, and show me which clients drive each spike.

What comes back is not a pretty dashboard. It is a table saying weeks 41 through 50 need roughly 82 tester-weeks against a bench of 66, that eleven of the sixteen missing weeks trace to nine clients whose observation windows all close 31 December, and that the April dip repeats every year. That is enough to do three things in July: raise the Q4 internal-test rate before the rate card goes out, pre-book subcontract capacity at July prices, and have the account managers offer those nine clients a September slot at the old rate.

## The arithmetic on one mis-priced October

Assumptions, all illustrative: six billable testers and eleven sellable weeks before the holiday shutdown, so 66 tester-weeks in-house against forecast demand of 82. An internal-test week bills at $14,000. Subcontract cost is $8,500 booked in July, $12,500 booked in panic.

| Item | You find out in July | You find out on 3 October |
| --- | --- | --- |
| Subcontract weeks booked | 10 at $8,500 = $85,000 | 7 at $12,500 = $87,500 |
| Q4 rate move on 66 in-house weeks | +8% = +$73,920 | $0 — quotes already signed |
| Weeks moved to January at 5% off | 6 weeks, $4,200 given away | 0 |
| Weeks turned away | 0 | 9 at $14,000 = $126,000 unbilled |
| Net position against plan | **+$69,720** | **&minus;$213,500** |

The swing is not the model being clever. It is the difference between deciding in July and reacting in October — and roughly two thirds of the money comes from the price move, not the staffing move. That is the part firms in this trade leave on the table every year, because nobody knew in July that October was 24% oversold.

## Where the forecast is blind — and the one thing to do Monday

A model built on your own history cannot see a client getting acquired, and acquisition is the biggest source of both windfall assessment work and sudden churn in this sector — the acquirer's security team either doubles your scope or replaces you within a quarter. It cannot see a new requirement landing, and when a prime contractor or a state regulator changes what it demands of subcontractors, demand moves in a direction no prior year contains. It cannot see a breach at one of your clients, which turns a planned $40,000 quarter into $200,000 of incident response followed by a canceled renewal.

It is also worthless for the deal in front of you. Whether to hold price on the manufacturer of six years, or discount to win the hospital group that will drag your team through eleven months of evidence requests, is a judgment about the relationship. Use the forecast to decide what the rate card says in September; use your own head to decide what this one client pays.

And do not let it set the tester calendar directly. Which tester runs the retail client's internal test in November depends on who owns the relationship, who is close to burning out, and who needs a supervised web application engagement to grow into. No forecast knows any of that.

Monday's version is small: pull 24 to 36 months of closed opportunities into one spreadsheet and add two columns by hand — audit window end date and insurance renewal month. That afternoon of typing is the whole project. Then do one thing with the answer: move one number on the rate card for one quarter, and pre-book subcontract capacity for the two worst weeks.

## Frequently asked questions

### We only have three years of history and we changed our rate card twice. Is that enough?

Yes, and that is precisely what changed. Three messy years with rate changes, churned clients and inconsistent service naming is exactly the input that used to make forecasting tools useless. Tell it about the rate changes rather than hiding them.

### Won't raising Q4 rates cost us clients?

Some, at the margin. The point of forecasting first is to know which weeks you were going to subcontract or turn away anyway, and to price only those. If October is 24% oversold, the client who walks over an 8% Q4 increase was going to be delivered by a subcontractor at thin margin regardless. Hold your rate flat in the months the forecast shows open bench.

### Does this work for the SOC retainer, or only for project work?

Better on retainers, because the monthly per-seat fee is where firms in this trade quietly lose money — you priced a client at 400 managed devices and they generate three times the alert volume of the similar-sized client next door. Feed it seat counts, ticket volume and hours delivered per client per month, and ask which retainers are underpriced against the work they pull. Expect two or three names you already suspected.

## A note from CallSphere

The forecast also tells you which weeks your phone gets busiest — October scoping calls, January insurance-renewal questions, the "we need a test before month end" calls that land while every senior person is on an engagement. [CallSphere](https://callsphere.ai) builds AI voice and chat agents that answer the business line and website chat around the clock, qualify the caller, book the scoping call and capture the lead into your systems — so a Q4 spike you predicted in July does not become voicemails nobody returns until Thursday.

---

Source: https://callsphere.ai/blog/your-pen-test-bench-sells-out-every-october-demand-models-now-price-th
