Cybersecurity consultancies collect cash in ways that do not map cleanly onto ordinary project billing: an annual standby retainer paid to guarantee incident-response availability, a deposit collected before a breach engagement is confirmed, or a retainer that sits unused until an incident actually occurs. In each case, the cash lands before the work it is meant to cover, and the accounting treatment needs to reflect that gap rather than book everything as revenue the day it is received.
Standby Availability Is Not the Same as Delivered Work
An incident-response retainer is frequently paid for standby availability: guaranteed response time, a pre-negotiated rate, and a commitment of capacity, whether or not the client ever calls. That standby commitment is itself a service the firm is delivering continuously over the retainer period, distinct from the actual incident-response work performed if and when an incident happens.
This distinction matters for revenue recognition. The standby fee is earned gradually as the coverage period passes, the same way an insurance-style commitment is earned over its term, not all at once when the cheque clears. A twelve-month standby retainer paid in January should generally move into revenue in roughly equal monthly amounts across the year it covers, not as a single January revenue entry, even though the full amount was invoiced and collected up front.
Recording the full retainer as January revenue overstates that month’s results and understates the firm’s ongoing obligation to remain available to the client for the rest of the year. If the client cancels partway through the term, the unearned portion is what the firm may owe back, and the books should already reflect that as a liability rather than as spent profit.
Booking the Retainer as Deferred Revenue
The mechanics follow the general deposits-and-retainers structure covered in deposits, retainers, and deferred revenue for consulting firms, applied specifically to a standby security retainer:
- The retainer is credited to a deferred revenue liability account when received, net of GST/HST.
- A recurring journal entry, or a recurring invoice structure in QuickBooks Online, moves the earned monthly portion from the liability into revenue as the standby period passes.
- If the engagement terms tie part of the retainer to specific deliverables, a quarterly tabletop exercise or an annual readiness assessment, that portion is recognized when the deliverable is completed rather than spread evenly with the rest.
- The remaining deferred revenue balance is reviewed at each month-end close, so a mid-year cancellation or contract change is caught while the liability is still current.
A firm running multiple standby clients benefits from tracking each client’s deferred balance separately rather than pooling them, since the point of the tracking is knowing exactly how much standby obligation remains outstanding per client at any moment, not just an aggregate liability figure.
When an Incident Actually Occurs
Once an incident happens and the firm is engaged to respond, two revenue streams typically run in parallel. The standby fee keeps recognizing on its original schedule, since the client was already paying for guaranteed availability regardless of whether an incident occurred. The incident-response engagement itself, usually billed time and materials or against a separate incident-specific retainer, is new revenue recognized as that work is delivered.
Breach response moves quickly, often across a matter of days rather than the months a standard consulting engagement spans. That pace makes it easy to skip the deferred revenue step entirely and book an incident deposit straight to revenue because the engagement closes out so fast. The treatment is still the same in principle: a deposit collected before work starts is a liability until the work is delivered, even if the gap between the two is measured in days rather than months.
GST/HST Timing
The GST/HST question turns on what the payment actually is, the same distinction covered in GST/HST Memorandum 300-6-8, Deposits: a true refundable deposit against an engagement that might not proceed is not taxed until applied, while a nonrefundable prepayment or standby fee for a supply that is definitely proceeding, availability under a signed retainer agreement, is taxed at the earlier of when it becomes due or is received.
Most annual standby retainers are the latter. The client is paying, and the firm is providing, guaranteed availability starting the moment the agreement takes effect, not a contingent amount that might be refunded if nothing happens. GST/HST is generally due on the full retainer in the period it is invoiced or paid, even though the corresponding accounting revenue is recognized gradually over the coverage period as the deferred revenue balance is worked down. Confirming this against the specific retainer agreement, rather than assuming based on the word “deposit” or “retainer” on the invoice, avoids a mismatch between GST/HST collected and revenue reported when a return is prepared.
Related Guides
- Deposits, retainers, and deferred revenue for consulting firms covers the general treatment this guide narrows to standby security retainers specifically.
- Insurance, E&O, cyber coverage, and deductibility covers the coverage side of incident response, separate from how retainer revenue is recognized.
- GST/HST and QST ITC/ITR documentation for IT contractors covers the broader documentation standard a retainer-related GST/HST filing should meet.
Scope of This Guide
This guide covers revenue recognition and GST/HST timing for standby incident-response retainers and breach-engagement deposits collected by Canadian cybersecurity consultancies. It does not cover:
- Refund and cancellation terms, which are contract questions for a lawyer, not an accounting determination
- Insurance-panel or cyber-insurer-directed engagements, where the insurer rather than the client is the paying party and separate billing arrangements often apply
- QST timing for Quebec-based engagements, which generally follows the same advance-payment logic but should be confirmed separately
This is general information, not advice for a specific engagement. A CPA reviewing your firm’s actual retainer structure can confirm the correct booking and GST/HST timing for your specific agreements.