The Real Question
Every team evaluating cyber ranges eventually faces the same fork: pay a vendor to manage everything (CRaaS) or build and maintain your own lab (DIY). The wrong choice costs months of wasted effort or tens of thousands in unnecessary spending.
I have advised teams who chose DIY because "we have an engineer" and then watched that engineer spend six months patching the lab instead of training analysts. I have also seen teams burn $40K on CRaaS when a $3K open-source stack would have met their needs. The right answer depends on five factors — not one.
The 12-Month Cost Reality
Here is the honest first-year math for a 10-person SOC team running quarterly exercises:
| Cost Factor |
CRaaS (RangeForce) |
DIY (Security Onion + AWS) |
| Platform / hosting |
$12,000–25,000/yr |
$3,000–6,000/yr (AWS EC2) |
| Staff time (setup + maintenance) |
$0 (included) |
200–400 hrs @ $75/hr = $15,000–30,000 |
| Scenario library |
Included (50–500+ scenarios) |
Build yourself or use Atomic Red Team ($0–$500) |
| Scoring / reporting |
Built-in dashboards |
Custom scripts or manual ($1,000–5,000) |
| Total first-year cost |
$12,000–25,000 |
$19,000–41,000 |
The hidden cost of DIY is always labor. If your analyst earning $85K/year spends 20% of their time maintaining the lab, that is $17,000 you did not budget. CRaaS makes that cost zero and predictable.
5-Factor Decision Framework
1. Team Size
- 1–5 people: DIY is often overkill. TryHackMe, LetsDefend, or Splunk Attack Range are faster and cheaper.
- 6–15 people: The CRaaS sweet spot. You need team management and scenario libraries, but lack a full-time infrastructure person.
- 16+ people: CRaaS or enterprise platform (SimSpace, Cyberbit) depending on exercise complexity and compliance needs.
2. Infrastructure Skill
- No Linux engineer: CRaaS only. Security Onion or Caldera will stall without someone who can troubleshoot kernel panics and network configs.
- 1 part-time engineer: Hybrid — CRaaS for core training, DIY micro-labs for specific detection engineering work.
- Full-time DevOps/Linux staff: DIY becomes viable. Factor their loaded cost into the comparison — $90K–120K/year is not "free."
3. Timeline Pressure
- Need training in <1 week: CRaaS only. DIY stacks take 2–4 weeks minimum for a functional lab.
- 1–3 month horizon: Either works. DIY gives you more control; CRaaS gives you faster ROI.
- No deadline: DIY is the better learning investment. Building the lab teaches you more than using someone else's.
4. Compliance Requirements
- NIST, CMMC, SOC 2: CRaaS (Cyberbit, Cloud Range) with built-in control mapping saves audit preparation time.
- Air-gapped or classified: DIY or on-prem enterprise only. Most CRaaS is cloud-hosted and cannot meet classification requirements.
- No compliance driver: DIY is more attractive — you are not paying for compliance features you do not need.
5. Customization Depth
- Standard MITRE ATT&CK coverage: CRaaS libraries cover this out of the box.
- Custom network topology: DIY wins. Replicate your exact production subnetting, VLANs, and firewall rules.
- Proprietary application testing: DIY wins. You cannot upload your internal app to a vendor's cloud range.
The hybrid middle ground: Many teams I advise use CRaaS for quarterly team exercises (vendor-managed, no setup) and a small DIY stack (Splunk Attack Range or Atomic Red Team) for weekly detection engineering practice. This gives you the best of both worlds without either cost dominating.
When CRaaS Is the Clear Winner
- You have 0–2 infrastructure staff and no plans to hire any
- Leadership wants training metrics in 30 days for budget justification
- Your threat model is standard enterprise — no exotic OT/ICS or classified systems
- Budget is $10K–30K/year and you need predictable spend
- You want quarterly scenario updates without manual curation
When DIY Is the Clear Winner
- You have a spare engineer who wants the project and whose time is already budgeted
- Your environment has unique requirements no commercial platform matches
- Budget is <$5,000/year — CRaaS at this price point is either limited or nonexistent
- You need air-gapped deployment for classified or regulated data
- Your goal is engineering skill building as much as analyst training — building the stack is the lesson
Still Unsure Which Path Fits Your Team?
I help teams map their staff, budget, timeline, and threat model to the right approach — CRaaS, DIY, or a hybrid of both.
Work With Todd →