Teplov CPA Complimentary Review

Incident-Response Retainers, Deposits, and Revenue Recognition

A cybersecurity retainer or breach-response deposit is often a liability until work is delivered, not revenue the month cash arrives.

Read time
~ 4 min

Cybersecurity consultancies collect cash in ways that do not map cleanly onto ordinary project billing: an annual standby retainer paid to guarantee incident-response availability, a deposit collected before a breach engagement is confirmed, or a retainer that sits unused until an incident actually occurs. In each case, the cash lands before the work it is meant to cover, and the accounting treatment needs to reflect that gap rather than book everything as revenue the day it is received.

Standby Availability Is Not the Same as Delivered Work

An incident-response retainer is frequently paid for standby availability: guaranteed response time, a pre-negotiated rate, and a commitment of capacity, whether or not the client ever calls. That standby commitment is itself a service the firm is delivering continuously over the retainer period, distinct from the actual incident-response work performed if and when an incident happens.

This distinction matters for revenue recognition. The standby fee is earned gradually as the coverage period passes, the same way an insurance-style commitment is earned over its term, not all at once when the cheque clears. A twelve-month standby retainer paid in January should generally move into revenue in roughly equal monthly amounts across the year it covers, not as a single January revenue entry, even though the full amount was invoiced and collected up front.

Recording the full retainer as January revenue overstates that month’s results and understates the firm’s ongoing obligation to remain available to the client for the rest of the year. If the client cancels partway through the term, the unearned portion is what the firm may owe back, and the books should already reflect that as a liability rather than as spent profit.

Booking the Retainer as Deferred Revenue

The mechanics follow the general deposits-and-retainers structure covered in deposits, retainers, and deferred revenue for consulting firms, applied specifically to a standby security retainer:

  • The retainer is credited to a deferred revenue liability account when received, net of GST/HST.
  • A recurring journal entry, or a recurring invoice structure in QuickBooks Online, moves the earned monthly portion from the liability into revenue as the standby period passes.
  • If the engagement terms tie part of the retainer to specific deliverables, a quarterly tabletop exercise or an annual readiness assessment, that portion is recognized when the deliverable is completed rather than spread evenly with the rest.
  • The remaining deferred revenue balance is reviewed at each month-end close, so a mid-year cancellation or contract change is caught while the liability is still current.

A firm running multiple standby clients benefits from tracking each client’s deferred balance separately rather than pooling them, since the point of the tracking is knowing exactly how much standby obligation remains outstanding per client at any moment, not just an aggregate liability figure.

When an Incident Actually Occurs

Once an incident happens and the firm is engaged to respond, two revenue streams typically run in parallel. The standby fee keeps recognizing on its original schedule, since the client was already paying for guaranteed availability regardless of whether an incident occurred. The incident-response engagement itself, usually billed time and materials or against a separate incident-specific retainer, is new revenue recognized as that work is delivered.

Breach response moves quickly, often across a matter of days rather than the months a standard consulting engagement spans. That pace makes it easy to skip the deferred revenue step entirely and book an incident deposit straight to revenue because the engagement closes out so fast. The treatment is still the same in principle: a deposit collected before work starts is a liability until the work is delivered, even if the gap between the two is measured in days rather than months.

GST/HST Timing

The GST/HST question turns on what the payment actually is, the same distinction covered in GST/HST Memorandum 300-6-8, Deposits: a true refundable deposit against an engagement that might not proceed is not taxed until applied, while a nonrefundable prepayment or standby fee for a supply that is definitely proceeding, availability under a signed retainer agreement, is taxed at the earlier of when it becomes due or is received.

Most annual standby retainers are the latter. The client is paying, and the firm is providing, guaranteed availability starting the moment the agreement takes effect, not a contingent amount that might be refunded if nothing happens. GST/HST is generally due on the full retainer in the period it is invoiced or paid, even though the corresponding accounting revenue is recognized gradually over the coverage period as the deferred revenue balance is worked down. Confirming this against the specific retainer agreement, rather than assuming based on the word “deposit” or “retainer” on the invoice, avoids a mismatch between GST/HST collected and revenue reported when a return is prepared.

Scope of This Guide

This guide covers revenue recognition and GST/HST timing for standby incident-response retainers and breach-engagement deposits collected by Canadian cybersecurity consultancies. It does not cover:

  • Refund and cancellation terms, which are contract questions for a lawyer, not an accounting determination
  • Insurance-panel or cyber-insurer-directed engagements, where the insurer rather than the client is the paying party and separate billing arrangements often apply
  • QST timing for Quebec-based engagements, which generally follows the same advance-payment logic but should be confirmed separately

This is general information, not advice for a specific engagement. A CPA reviewing your firm’s actual retainer structure can confirm the correct booking and GST/HST timing for your specific agreements.

Alex Teplov, CPA · Last updated: August 2026

Alex Teplov is a CPA registered with CPA Ontario. This article is for general informational purposes only and does not constitute professional accounting, tax, or legal advice. It does not create an accountant-client relationship. A professional engagement with Teplov CPA is established only through a signed engagement letter. Tax law, CRA administrative positions, and provincial rules change frequently. Information in this article may not reflect the most recent developments. Do not make financial or tax decisions based solely on this content. Consult a qualified CPA for advice specific to your situation.

Alex Teplov, CPA
About the author
Alex Teplov, CPA

Teplov CPA helps Canadian IT professionals with tax, bookkeeping, and compliance. You’ll communicate directly with me. I remain your primary contact throughout the engagement, so you can bring questions, changes, and decisions to someone who understands your file.

About Alex
Browse the library

All Resources

Guides on tax, GST/HST, incorporation, and CRA compliance for Canadian IT contractors.

View all guides
Get professional advice

Work with Teplov CPA

Guides cover general rules. Your file involves details that general guidance cannot address.

Talk to a CPA

Want a second opinion?

Complimentary Tax and Compliance Review for Canadian IT Professionals

If you’re a Canadian IT professional, you can request a complimentary review of your most recent tax and compliance position.

Request a Complimentary Review
Get started

Questions about your tax position?

Teplov CPA works with Canadian IT contractors on tax planning, CRA compliance, and incorporation.

Book a 15-minute introduction