Search for MDR pricing and you will find the same figure everywhere: $10 to $30 per endpoint per month. It appears on vendor blogs, analyst summaries and comparison sites, almost always without a source and almost always without a date.
So we checked. On 12 August 2026 we opened the pricing page of every major MDR and EDR vendor and recorded what was actually published. The result is the point of this page:
Four vendors publish real prices. Eight publish nothing for MDR at all. Every MDR vendor we checked — CrowdStrike, Arctic Wolf, Expel, Rapid7, eSentire, Sophos, Red Canary and Blackpoint — routes managed-service buyers to a quote.
That is not a criticism of those vendors. There are sound reasons why MDR resists list pricing, and we explain them below. But it does mean the honest answer to "how much does MDR cost" is: nobody can tell you from a web page, and here is exactly what determines the number they will tell you on a call.
What Vendors Actually Publish (verified 12 August 2026)
Each figure below was read from the vendor's own site on the date shown. Where a cell says "not published", we looked and found no price.
| Vendor | Product | Published price | Billing unit | Verified from |
|---|---|---|---|---|
| CrowdStrike | Falcon Go | $7.99/device/mo or $59.99/device/yr (max 100 devices) | Per device | crowdstrike.com/en-us/pricing |
| CrowdStrike | Falcon Pro | $14.99/device/mo or $99.99/device/yr | Per device | crowdstrike.com/en-us/pricing |
| CrowdStrike | Falcon Enterprise | $19.99/device/mo or $184.99/device/yr | Per device | crowdstrike.com/en-us/pricing |
| CrowdStrike | Falcon Complete Next-Gen MDR | "Contact sales" | — | crowdstrike.com/en-us/pricing |
| Huntress | Managed EDR | $8.99/endpoint/mo (50-99 tier) | Per endpoint | huntress.com/pricing |
| Huntress | Managed SIEM | $4.00/source/mo | Per log source | huntress.com/pricing |
| Huntress | Managed ITDR | $4.80/identity/mo | Per licensed identity | huntress.com/pricing |
| SentinelOne | Singularity Complete | $179.99/endpoint/yr | Per endpoint (5-100 workstations) | sentinelone.com/platform-packages |
| SentinelOne | Singularity Commercial | $229.99/endpoint/yr | Per endpoint (5-100 workstations) | sentinelone.com/platform-packages |
| SentinelOne | Singularity MDR | Not published (add-on) | — | sentinelone.com/platform-packages |
| Microsoft | Defender for Business | $3.00/user/mo (annual) | Per user, 5 devices each, ≤300 users | microsoft.com |
| Microsoft | Defender Experts (MDR) | Not published | — | Same |
| Arctic Wolf | MDR | Not published — "Request a Demo" | — | arcticwolf.com |
| Expel | MDR | Not published | Integrations / data sources | expel.com |
| Rapid7 | Managed Threat Complete | Not published | Endpoints + servers + networks | rapid7.com |
| eSentire | Atlas Essentials / Advanced / Complete | Not published | Per endpoint | esentire.com |
| Sophos | MDR | Not published — "Get Pricing" | — | sophos.com |
| Red Canary | MDR | Not published | — | redcanary.com/pricing |
| Blackpoint Cyber | MDR | Not published | — | blackpointcyber.com/pricing |
Three things worth pulling out of that table:
Huntress is the only major MDR vendor publishing a real managed-service price. $8.99 per endpoint per month at the 50-99 tier, and its pricing page states there are "no separate setup or onboarding fees" and that the 24/7 SOC is included at no additional cost. Direct purchases carry a 50-seat minimum per product on a 12-month term. That transparency is genuinely unusual in this market and worth crediting.
SentinelOne's published prices come with a caveat you must read. Its pricing page states plainly that "all purchases will be made through an authorized third-party partner. As a result the prices contained here do not reflect final pricing which will be agreed to and purchased through an authorized partner." The list price is a reference point, not a checkout price.
The self-managed / managed line is where publishing stops. CrowdStrike publishes three EDR tiers to the cent and then says "Contact sales" the moment you cross into Falcon Complete MDR. That pattern repeats across the market and it tells you something real about the product: a licence can have a list price, a staffed service cannot.
Why MDR Genuinely Resists List Pricing
It is tempting to read quote-only pricing as a negotiating tactic. Some of it is. But most of it is structural, and understanding why makes you a better buyer.
The cost to serve is driven by incident volume, not seat count. A 500-seat manufacturer with a flat network and no cloud footprint and a 500-seat software company with 40 SaaS applications, three cloud accounts and a permissive identity posture generate wildly different analyst workloads. The vendor is pricing analyst hours. Endpoints are only a proxy.
Vendors do not even agree on the billing unit. Compare the units in the table above: Huntress prices per endpoint, per identity and per log source separately. Rapid7 states pricing is "based on the number of endpoints, servers, and networks we protect." Expel prices around integrations and data sources because it does not supply an agent at all. Microsoft prices per user with a five-device allowance. A single list price cannot span those models.
Telemetry volume is metered separately and is the usual budget surprise. Endpoint coverage is predictable. Log ingestion is not. If your quote includes a SIEM or log-analytics component, the per-GB ingestion rate and the retention period will move the total more than the endpoint count does, and they are the two variables most likely to grow after signature.
The Six Variables That Actually Set Your Quote
When you get on the call, these are the levers. Bring numbers for each one and you will get a comparable quote instead of a range.
-
Endpoint and server count. Servers frequently price higher than workstations. Ask for the split explicitly rather than accepting a blended per-seat figure. Rapid7 notes that its per-asset price decreases across asset-count tiers, which is typical of the market.
-
Log and telemetry volume, in GB per day. If you do not know this, that is your first homework item. Ask what is included in the base and what the overage rate is. This is where "cheap" MDR quotes stop being cheap in year two.
-
Retention. Ninety days of searchable telemetry and one year of searchable telemetry are different products at different prices. Compliance frameworks may set your floor here, so check before you negotiate it down.
-
Surfaces covered beyond the endpoint. Identity, cloud infrastructure, SaaS, email and network each add cost and each is where modern intrusions actually start. Expel makes a virtue of breadth here — its MDR page describes coverage across "endpoint, identity, cloud, network, SaaS, email" with 160+ technology integrations. Other providers quote endpoint-only by default and add surfaces as line items. Compare like for like.
-
Response SLA — and crucially, response authority. There is a large difference between a provider that notifies you and one that is contractually permitted to isolate a host at 3am without waking anyone. CrowdStrike states Falcon Complete spans "detection through resolution," including system isolation, persistence removal and restoration. Ask every vendor, in writing: what actions can you take without my approval, and at what hour?
-
Contract length. Two- and three-year terms carry the discount, and sometimes carry more than the discount. Arctic Wolf's Security Operations Warranty of "up to $3 million (USD) in financial assistance for cybersecurity incidents" is conditioned on purchasing its Total Security Operations Bundle and Aurora Managed Endpoint Defense on a three-year term. Warranty figures are frequently tied to bundle and term in this way — read the condition, not the headline.
Work through your own numbers with the cybersecurity budget calculator before you take the first call.
On Warranties and Guarantees
Two vendors publish a breach warranty figure, and both are worth understanding precisely rather than by headline:
- CrowdStrike: "Falcon Complete is backed by warranty coverage of up to $2 million." (Falcon Complete Next-Gen MDR, verified 12 August 2026)
- Arctic Wolf: "Up to $3 million (USD) in financial assistance for cybersecurity incidents," available with the Total Security Operations Bundle plus Aurora Managed Endpoint Defense on a three-year term. (Arctic Wolf MDR, verified 12 August 2026)
Both are "up to" figures with terms and conditions attached. Neither is cyber insurance, and neither should displace a policy. Treat them as a signal that the vendor is willing to put money behind its process, not as a coverage line.
What About the "$10-30 Per Endpoint" Figure?
It traces back mostly to vendor content marketing. UnderDefense — which ranks on page one for MDR pricing — states on its own pricing page that "the average monthly cost of a Managed Detection and Response (MDR) typically falls between $10 and $30 per asset," and prices its own Standard tier from $11 per device per month. No source or methodology is given for the range, and it lists no competitor pricing.
That does not make the range useless. It is a reasonable sanity check: a quote at $6 per endpoint probably excludes something material, and a quote at $45 probably includes surfaces or retention you may not need. But it is not a budget input, and it should not be cited as market data.
Where Self-Managed EDR Is Still the Right Answer
MDR is not automatically the upgrade. Published EDR pricing exists precisely because these are licences you operate:
- Microsoft Defender for Business at $3.00 per user per month covers up to 300 users with five devices each — the cheapest credible endpoint detection floor for a small business, provided someone actually watches it. Microsoft 365 Business Premium at $22.00 per user per month bundles it with the rest of the productivity and identity stack, which is often the real buying decision.
- CrowdStrike Falcon Go at $7.99 per device per month (capped at 100 devices) is a genuine self-serve on-ramp with a 15-day free trial and no credit card required.
- SentinelOne Singularity Complete at $179.99 per endpoint per year sits at the higher end and assumes you have someone to run it.
The honest test is not budget, it is rota. Detection technology only pays off if an alert at 2am on a Sunday reaches a human who can act. If you cannot staff that, you are buying a dashboard.
Use the EDR Needs Assessment to work out which side of that line you are on, or the MDR Vendor Selector to shortlist providers against your constraints.
Who Should Pick Which
Pick Huntress if you want managed detection with a price you can read before you talk to anyone, you are comfortable with the 50-seat minimum, and you value a low-friction commercial relationship. It is the transparency leader in this market and the easiest MDR to budget for.
Pick CrowdStrike Falcon Complete if you want one vendor owning agent, detection and remediation, and you need documented independent validation — CrowdStrike is among the eleven providers evaluated in the 2024 MITRE ATT&CK Evaluations for Managed Services. Expect a quote, not a price.
Pick Arctic Wolf if the thing you are buying is a relationship rather than a console — a named security team that learns your environment, plus reporting aimed at a board. Its Concierge model is the clearest expression of service-first MDR. Expect a quote and expect bundle-and-term conditions on the warranty.
Pick Expel if you already own an endpoint platform you are happy with and want a managed SOC layered on top without a rip-and-replace. Its breadth across identity, cloud and SaaS is a genuine differentiator, and it publishes response metrics most competitors will not.
Pick eSentire or Rapid7 if you need MDR that reaches well past the endpoint into network and vulnerability context, and you have the internal capacity to run a proper scoped evaluation. Both price per your environment and both will want to size it properly.
Pick Microsoft Defender for Business if you are under 300 users, already on Microsoft 365, and you have someone — internal or an MSP — who will actually look at it.
Related Comparisons
- CrowdStrike Falcon Complete MDR: what it includes and what it costs
- CrowdStrike vs Arctic Wolf: platform versus partnership
- CrowdStrike vs Expel: what the published response times actually mean
- EDR vs MDR for small business: which one you actually need
- MDR vendor performance benchmarks
Verification note. Every price, product name and quoted phrase on this page was read from the named vendor's own website on 12 August 2026. Where a vendor publishes no price we say so rather than estimating. Vendors change pricing without notice; confirm against the linked source before budgeting. We have no reseller relationship influencing the ordering of this page.