CrowdStrike publishes its EDR pricing to the cent and then stops. Falcon Go, Falcon Pro and Falcon Enterprise all carry public per-device prices. Falcon Complete Next-Gen MDR says "Contact sales."
That gap is the most useful fact about buying Falcon Complete, and most pages about it paper over the gap with invented numbers. This one does not. Below is what CrowdStrike actually publishes about Falcon Complete, verified against crowdstrike.com on 12 August 2026, plus what determines the quote you will be given.
What CrowdStrike Publishes: Verified Pricing
From crowdstrike.com/en-us/pricing, read 12 August 2026:
| Plan | Monthly | Annual | Notes |
|---|---|---|---|
| Falcon Go | $7.99 per device | $59.99 per device | Maximum 100 devices |
| Falcon Pro | $14.99 per device | $99.99 per device | — |
| Falcon Enterprise | $19.99 per device | $184.99 per device | — |
| Falcon Complete Next-Gen MDR | Contact sales | Contact sales | No published price |
| Falcon Free Trial | Free | — | 15 days, no credit card required |
Two implications worth stating plainly.
The published tiers are self-managed products. Falcon Go, Pro and Enterprise give you the technology. Someone on your side still has to receive the alert, judge it and act on it. If nobody does that at 3am, the difference between the tiers matters less than you think.
Falcon Complete is a different category of purchase, not a fourth tier. You are buying analyst hours and a response mandate. That is why it is quoted rather than listed — a point we cover across the whole market in our verified MDR pricing comparison, where 8 of 12 vendors publish no MDR price at all. CrowdStrike is not unusual here.
Beware any page — including vendor-adjacent blogs and reseller sites — that states a firm Falcon Complete per-endpoint price. None is published. Every such figure is either an estimate presented as fact or a specific customer's negotiated rate presented as a list price.
What CrowdStrike Claims for Falcon Complete
These are CrowdStrike's own published claims, taken verbatim from the Falcon Complete Next-Gen MDR page on 12 August 2026. We report them as vendor claims, because that is what they are.
| Claim | CrowdStrike's published figure |
|---|---|
| Median time to contain (MTTC) | "1 min" |
| Mean time to respond | "75% Reduction in mean-time-to-respond (MTTR)" |
| Warranty | "Falcon Complete is backed by warranty coverage of up to $2 million" |
| Oversight model | "Deterministic automation," "Adaptive AI agents," "Humans-in-the-loop" with "24/7 expert oversight" |
| Remediation scope | "detection through resolution" — including system isolation, persistence removal and restoration |
How to read the 1-minute figure. It is a median time to contain, which is a narrower and more favourable measure than an end-to-end mean time to respond across all incident types. A median discards the tail, and the tail is where hard incidents live. It is a real and impressive number for what it measures; it is not a promise that every incident is over in a minute.
How to read the 75% reduction. A relative improvement figure has no meaning without the baseline it improved on, and the baseline is not published. Ask CrowdStrike for the absolute MTTR for accounts of your size and shape, and ask what "respond" includes.
What has changed since the 1-10-60 era. Older comparisons of Falcon Complete — including previous versions of this page — cite CrowdStrike's "1-10-60 framework" (1 minute to detect, 10 to investigate, 60 to contain) and figures such as "~4 minute MTTD" and "~36 minute MTTR". Those numbers are not on CrowdStrike's current site. We removed them rather than carry them forward unsourced. If a comparison page still quotes them, it has not been checked recently.
The remediation scope is the genuinely differentiating claim. "Detection through resolution," with the same agent that saw the threat executing the isolation and the persistence removal, is not what every MDR provider sells. Many stop at notification. When comparing quotes, this is the clause that decides whether two quotes are for the same product.
What You Actually Get
Falcon Complete is Falcon plus a staffed operation, so the parts split cleanly:
Platform layer. All endpoints run Falcon Insight for telemetry, behavioural analysis and machine-learning detection, on a single lightweight cloud-native agent across Windows, macOS, Linux and cloud workloads. Falcon Complete customers also gain access to threat-hunting and IT-hygiene modules.
Service layer. CrowdStrike analysts monitor detections around the clock, investigate, determine severity and escalate. They can kill processes, quarantine hosts and remove persistence through the same agent — within guardrails you define. Every confirmed incident comes with root cause, timeline, containment actions and remediation guidance, which is the material your auditors and your board will ask for.
Integration layer. Ticketing and SIEM connectors (ServiceNow, Splunk, Microsoft Sentinel) matter more than they sound. If Falcon Complete's findings do not land in the system your team already lives in, the service degrades into an inbox nobody reads.
The Six Variables That Set Your Falcon Complete Quote
Bring numbers for each of these to the first call and you will get a comparable quote rather than a range:
- Endpoint and server count, split by type. Servers commonly price differently from workstations. Get the split, not a blended figure.
- Which modules are in scope. Identity protection, cloud workload protection and log management are separate lines. The modular model is flexible but it means two "Falcon Complete" quotes can describe quite different products.
- Log volume and retention if LogScale or any log-analytics component is included. This is the variable that grows quietly after signature.
- Response authority. Precisely which actions may CrowdStrike take without waking someone on your side, and at what hour? Get this in writing. It is the difference between a service and a notification feed.
- Contract length. Multi-year terms carry the discount. Check whether the warranty terms are conditioned on term length, as they are at some competitors.
- Onboarding state. If Falcon is not already deployed, budget real time for sensor rollout, policy tuning and network exclusions before the service produces value. MDR on a badly tuned estate mostly produces noise.
Model the total against the alternative with the cybersecurity budget calculator and the cybersecurity ROI calculator.
Independent Validation: What MITRE Actually Shows
CrowdStrike participates in the MITRE ATT&CK Evaluations for Managed Services, which tests the end-to-end managed service — analysts, workflows and response — rather than only the platform's detection coverage. That is meaningful, because strong platform detection does not guarantee effective managed response.
One correction worth making, because it is repeated widely and it is wrong. CrowdStrike is not the only MDR vendor to have done this. MITRE's second Managed Services round, published in June 2024 and emulating menuPass and ALPHV/BlackCat, included eleven participants: Bitdefender, BlackBerry, CrowdStrike, Field Effect, Microsoft, Palo Alto Networks, Secureworks, SecurityHQ, SentinelOne, Sophos and Trend Micro (MITRE news release). Earlier versions of this page carried the "only vendor" claim. It was inaccurate and we have removed it.
What remains true, and is the fair version of the point: CrowdStrike is in a minority of MDR providers that submit their managed service to independent evaluation at all. Arctic Wolf, Expel, Red Canary, eSentire and Huntress do not appear in that participant list. When you are comparing providers, ask whether the service — not just the product — has ever been externally tested, and by whom.
Explore the technique coverage yourself with our MITRE ATT&CK navigator.
Where Falcon Complete Fits — and Where It Does Not
It fits well when:
- You have a lean security team that needs 24/7 coverage without a four-to-five-person rota.
- You want single-vendor accountability: one agent, one console, one escalation path, no finger-pointing between platform and service at 3am.
- You operate across time zones and need consistent coverage rather than a follow-the-sun handoff between internal staff.
- You are in a regulated industry where documented, independently-tested response process is part of the audit story.
- You are rebuilding after an incident and need sustained expert monitoring while trust is restored.
It fits poorly when:
- You already have a mature 24/7 SOC. Threat hunting or log-analytics modules alone may serve you better than the full managed service.
- You are deliberately multi-vendor and want to keep endpoint platform and MDR provider separable. That is the Expel argument, and it is a legitimate one.
- Your budget genuinely tops out at the published EDR tiers. Falcon Pro at $14.99 per device per month with a competent MSP watching it beats an MDR contract you cancel in month eight.
- What you actually want is a named human who knows your business and briefs your board quarterly. That is closer to the Arctic Wolf Concierge model.
Questions to Ask Before You Sign
- What is the absolute MTTR for accounts my size, and what does "respond" include? The published 75% reduction has no stated baseline.
- Which containment actions can you take without my approval, at 3am? Get the list, not a philosophy.
- What exactly does the $2M warranty cover, and what voids it? It is an "up to" figure with conditions.
- What is included in the base, and what is a module? Identity, cloud and log management are the usual add-ons.
- What happens at renewal if my endpoint count grows 40%? Ask for the tier boundaries now.
- What does offboarding look like? Data export, retention and agent removal terms are easier to negotiate before signature than after.
Build your escalation expectations in advance with the incident response playbook generator.
Related Reading
- MDR pricing 2026: what 12 vendors actually publish
- CrowdStrike vs Expel: what the published response times actually mean
- CrowdStrike vs Arctic Wolf: platform versus partnership
- EDR vs MDR for small business
- MDR vendor performance benchmarks
Verification note. All CrowdStrike figures and quoted phrases on this page were read from crowdstrike.com on 12 August 2026 and are linked to source. Where CrowdStrike publishes no figure — notably Falcon Complete pricing — we say so rather than estimating. CrowdStrike changes pricing without notice; confirm against the source before budgeting.