Mdr Security

MDR Pricing 2026: What 12 Vendors Actually Publish

We checked all 12 major MDR and EDR vendor pricing pages on 12 August 2026. Four publish real per-endpoint prices. Eight do not publish MDR pricing at all. Here are the verified numbers and what actually drives the quote.

By InventiveHQ Team

Search for MDR pricing and you will find the same figure everywhere: $10 to $30 per endpoint per month. It appears on vendor blogs, analyst summaries and comparison sites, almost always without a source and almost always without a date.

So we checked. On 12 August 2026 we opened the pricing page of every major MDR and EDR vendor and recorded what was actually published. The result is the point of this page:

Four vendors publish real prices. Eight publish nothing for MDR at all. Every MDR vendor we checked — CrowdStrike, Arctic Wolf, Expel, Rapid7, eSentire, Sophos, Red Canary and Blackpoint — routes managed-service buyers to a quote.

That is not a criticism of those vendors. There are sound reasons why MDR resists list pricing, and we explain them below. But it does mean the honest answer to "how much does MDR cost" is: nobody can tell you from a web page, and here is exactly what determines the number they will tell you on a call.

What Vendors Actually Publish (verified 12 August 2026)

Each figure below was read from the vendor's own site on the date shown. Where a cell says "not published", we looked and found no price.

VendorProductPublished priceBilling unitVerified from
CrowdStrikeFalcon Go$7.99/device/mo or $59.99/device/yr (max 100 devices)Per devicecrowdstrike.com/en-us/pricing
CrowdStrikeFalcon Pro$14.99/device/mo or $99.99/device/yrPer devicecrowdstrike.com/en-us/pricing
CrowdStrikeFalcon Enterprise$19.99/device/mo or $184.99/device/yrPer devicecrowdstrike.com/en-us/pricing
CrowdStrikeFalcon Complete Next-Gen MDR"Contact sales"crowdstrike.com/en-us/pricing
HuntressManaged EDR$8.99/endpoint/mo (50-99 tier)Per endpointhuntress.com/pricing
HuntressManaged SIEM$4.00/source/moPer log sourcehuntress.com/pricing
HuntressManaged ITDR$4.80/identity/moPer licensed identityhuntress.com/pricing
SentinelOneSingularity Complete$179.99/endpoint/yrPer endpoint (5-100 workstations)sentinelone.com/platform-packages
SentinelOneSingularity Commercial$229.99/endpoint/yrPer endpoint (5-100 workstations)sentinelone.com/platform-packages
SentinelOneSingularity MDRNot published (add-on)sentinelone.com/platform-packages
MicrosoftDefender for Business$3.00/user/mo (annual)Per user, 5 devices each, ≤300 usersmicrosoft.com
MicrosoftDefender Experts (MDR)Not publishedSame
Arctic WolfMDRNot published — "Request a Demo"arcticwolf.com
ExpelMDRNot publishedIntegrations / data sourcesexpel.com
Rapid7Managed Threat CompleteNot publishedEndpoints + servers + networksrapid7.com
eSentireAtlas Essentials / Advanced / CompleteNot publishedPer endpointesentire.com
SophosMDRNot published — "Get Pricing"sophos.com
Red CanaryMDRNot publishedredcanary.com/pricing
Blackpoint CyberMDRNot publishedblackpointcyber.com/pricing

Three things worth pulling out of that table:

Huntress is the only major MDR vendor publishing a real managed-service price. $8.99 per endpoint per month at the 50-99 tier, and its pricing page states there are "no separate setup or onboarding fees" and that the 24/7 SOC is included at no additional cost. Direct purchases carry a 50-seat minimum per product on a 12-month term. That transparency is genuinely unusual in this market and worth crediting.

SentinelOne's published prices come with a caveat you must read. Its pricing page states plainly that "all purchases will be made through an authorized third-party partner. As a result the prices contained here do not reflect final pricing which will be agreed to and purchased through an authorized partner." The list price is a reference point, not a checkout price.

The self-managed / managed line is where publishing stops. CrowdStrike publishes three EDR tiers to the cent and then says "Contact sales" the moment you cross into Falcon Complete MDR. That pattern repeats across the market and it tells you something real about the product: a licence can have a list price, a staffed service cannot.

Why MDR Genuinely Resists List Pricing

It is tempting to read quote-only pricing as a negotiating tactic. Some of it is. But most of it is structural, and understanding why makes you a better buyer.

The cost to serve is driven by incident volume, not seat count. A 500-seat manufacturer with a flat network and no cloud footprint and a 500-seat software company with 40 SaaS applications, three cloud accounts and a permissive identity posture generate wildly different analyst workloads. The vendor is pricing analyst hours. Endpoints are only a proxy.

Vendors do not even agree on the billing unit. Compare the units in the table above: Huntress prices per endpoint, per identity and per log source separately. Rapid7 states pricing is "based on the number of endpoints, servers, and networks we protect." Expel prices around integrations and data sources because it does not supply an agent at all. Microsoft prices per user with a five-device allowance. A single list price cannot span those models.

Telemetry volume is metered separately and is the usual budget surprise. Endpoint coverage is predictable. Log ingestion is not. If your quote includes a SIEM or log-analytics component, the per-GB ingestion rate and the retention period will move the total more than the endpoint count does, and they are the two variables most likely to grow after signature.

The Six Variables That Actually Set Your Quote

When you get on the call, these are the levers. Bring numbers for each one and you will get a comparable quote instead of a range.

  1. Endpoint and server count. Servers frequently price higher than workstations. Ask for the split explicitly rather than accepting a blended per-seat figure. Rapid7 notes that its per-asset price decreases across asset-count tiers, which is typical of the market.

  2. Log and telemetry volume, in GB per day. If you do not know this, that is your first homework item. Ask what is included in the base and what the overage rate is. This is where "cheap" MDR quotes stop being cheap in year two.

  3. Retention. Ninety days of searchable telemetry and one year of searchable telemetry are different products at different prices. Compliance frameworks may set your floor here, so check before you negotiate it down.

  4. Surfaces covered beyond the endpoint. Identity, cloud infrastructure, SaaS, email and network each add cost and each is where modern intrusions actually start. Expel makes a virtue of breadth here — its MDR page describes coverage across "endpoint, identity, cloud, network, SaaS, email" with 160+ technology integrations. Other providers quote endpoint-only by default and add surfaces as line items. Compare like for like.

  5. Response SLA — and crucially, response authority. There is a large difference between a provider that notifies you and one that is contractually permitted to isolate a host at 3am without waking anyone. CrowdStrike states Falcon Complete spans "detection through resolution," including system isolation, persistence removal and restoration. Ask every vendor, in writing: what actions can you take without my approval, and at what hour?

  6. Contract length. Two- and three-year terms carry the discount, and sometimes carry more than the discount. Arctic Wolf's Security Operations Warranty of "up to $3 million (USD) in financial assistance for cybersecurity incidents" is conditioned on purchasing its Total Security Operations Bundle and Aurora Managed Endpoint Defense on a three-year term. Warranty figures are frequently tied to bundle and term in this way — read the condition, not the headline.

Work through your own numbers with the cybersecurity budget calculator before you take the first call.

On Warranties and Guarantees

Two vendors publish a breach warranty figure, and both are worth understanding precisely rather than by headline:

  • CrowdStrike: "Falcon Complete is backed by warranty coverage of up to $2 million." (Falcon Complete Next-Gen MDR, verified 12 August 2026)
  • Arctic Wolf: "Up to $3 million (USD) in financial assistance for cybersecurity incidents," available with the Total Security Operations Bundle plus Aurora Managed Endpoint Defense on a three-year term. (Arctic Wolf MDR, verified 12 August 2026)

Both are "up to" figures with terms and conditions attached. Neither is cyber insurance, and neither should displace a policy. Treat them as a signal that the vendor is willing to put money behind its process, not as a coverage line.

What About the "$10-30 Per Endpoint" Figure?

It traces back mostly to vendor content marketing. UnderDefense — which ranks on page one for MDR pricing — states on its own pricing page that "the average monthly cost of a Managed Detection and Response (MDR) typically falls between $10 and $30 per asset," and prices its own Standard tier from $11 per device per month. No source or methodology is given for the range, and it lists no competitor pricing.

That does not make the range useless. It is a reasonable sanity check: a quote at $6 per endpoint probably excludes something material, and a quote at $45 probably includes surfaces or retention you may not need. But it is not a budget input, and it should not be cited as market data.

Where Self-Managed EDR Is Still the Right Answer

MDR is not automatically the upgrade. Published EDR pricing exists precisely because these are licences you operate:

  • Microsoft Defender for Business at $3.00 per user per month covers up to 300 users with five devices each — the cheapest credible endpoint detection floor for a small business, provided someone actually watches it. Microsoft 365 Business Premium at $22.00 per user per month bundles it with the rest of the productivity and identity stack, which is often the real buying decision.
  • CrowdStrike Falcon Go at $7.99 per device per month (capped at 100 devices) is a genuine self-serve on-ramp with a 15-day free trial and no credit card required.
  • SentinelOne Singularity Complete at $179.99 per endpoint per year sits at the higher end and assumes you have someone to run it.

The honest test is not budget, it is rota. Detection technology only pays off if an alert at 2am on a Sunday reaches a human who can act. If you cannot staff that, you are buying a dashboard.

Use the EDR Needs Assessment to work out which side of that line you are on, or the MDR Vendor Selector to shortlist providers against your constraints.

Who Should Pick Which

Pick Huntress if you want managed detection with a price you can read before you talk to anyone, you are comfortable with the 50-seat minimum, and you value a low-friction commercial relationship. It is the transparency leader in this market and the easiest MDR to budget for.

Pick CrowdStrike Falcon Complete if you want one vendor owning agent, detection and remediation, and you need documented independent validation — CrowdStrike is among the eleven providers evaluated in the 2024 MITRE ATT&CK Evaluations for Managed Services. Expect a quote, not a price.

Pick Arctic Wolf if the thing you are buying is a relationship rather than a console — a named security team that learns your environment, plus reporting aimed at a board. Its Concierge model is the clearest expression of service-first MDR. Expect a quote and expect bundle-and-term conditions on the warranty.

Pick Expel if you already own an endpoint platform you are happy with and want a managed SOC layered on top without a rip-and-replace. Its breadth across identity, cloud and SaaS is a genuine differentiator, and it publishes response metrics most competitors will not.

Pick eSentire or Rapid7 if you need MDR that reaches well past the endpoint into network and vulnerability context, and you have the internal capacity to run a proper scoped evaluation. Both price per your environment and both will want to size it properly.

Pick Microsoft Defender for Business if you are under 300 users, already on Microsoft 365, and you have someone — internal or an MSP — who will actually look at it.


Verification note. Every price, product name and quoted phrase on this page was read from the named vendor's own website on 12 August 2026. Where a vendor publishes no price we say so rather than estimating. Vendors change pricing without notice; confirm against the linked source before budgeting. We have no reseller relationship influencing the ordering of this page.

Frequently Asked Questions

How much does MDR cost per endpoint?

There is no single answer because most MDR vendors do not publish prices. Of the 12 vendors we checked on 12 August 2026, only Huntress publishes a true managed-service price: $8.99 per endpoint per month for Managed EDR at the 50-99 endpoint tier, 24/7 SOC included. CrowdStrike, Arctic Wolf, Expel, Rapid7, eSentire, Sophos, Red Canary, Blackpoint and SentinelOne all route MDR buyers to a sales quote. Self-managed EDR is where published prices exist: CrowdStrike Falcon Go is $7.99 per device per month, Falcon Pro $14.99, Falcon Enterprise $19.99.

Why won't MDR vendors publish pricing?

MDR is a labour-loaded service, not a licence. The cost to serve depends on how much telemetry your environment generates and how many incidents your analysts have to work, and neither is knowable from an endpoint count alone. Vendors also price differently by unit: Huntress and eSentire price per endpoint, Rapid7 prices per endpoint plus servers plus networks, and Expel prices around integrations and data sources rather than agents. A published list price would be wrong for most buyers, so vendors quote instead.

What actually drives an MDR quote?

Six things, in roughly this order of impact: endpoint and server count; log and telemetry volume, because SIEM-style ingestion is usually metered separately; retention period for that telemetry; how many non-endpoint surfaces you want covered (identity, cloud, SaaS, email, network); the response SLA and whether the provider is contractually allowed to take containment actions without asking; and contract length, since two- and three-year terms typically carry the discount.

Is remediation included in MDR pricing, or extra?

Ask explicitly, because it varies and it is the single biggest source of quote-to-quote incomparability. CrowdStrike states Falcon Complete covers detection through resolution including system isolation, persistence removal and restoration. Other providers stop at notification and hand the containment action back to you. A cheaper quote that stops at 'we will call you' is not the same product as one that ends with the host isolated.

Does MDR pricing include the endpoint licence?

Not always. Vendor-agnostic providers such as Expel deliberately do not supply the agent, so your total is your existing endpoint platform cost plus their MDR fee. eSentire supports bring-your-own-licence scenarios for the same reason. Bundled providers such as CrowdStrike Falcon Complete include the agent in one line item. When comparing quotes, normalise this first or the bundled vendor will look artificially expensive.

Is the '$10-30 per endpoint per month' figure everyone quotes accurate?

It is a vendor blog estimate, not a measured market rate, and it is repeated across dozens of pages without a primary source. UnderDefense publishes a range of $10 to $30 per asset per month on its own MDR pricing page, and its own Standard tier starts at $11 per device per month. Treat it as a sanity check on a quote you have already received, not as a budget input.

What is the cheapest legitimate MDR for a small business?

Among vendors with published pricing on 12 August 2026, Huntress Managed EDR at $8.99 per endpoint per month is the lowest published price that includes a 24/7 SOC, though direct purchase carries a 50-seat minimum per product. Below that price point you are generally buying self-managed EDR, not MDR: Microsoft Defender for Business is $3.00 per user per month for up to 300 users and five devices per user, but you or a partner operate it.

How many endpoints do I need before MDR makes sense?

The threshold is about staffing, not seat count. Genuine 24/7 in-house coverage needs four to five analysts to cover the rota, which is a payroll line most organisations under a few thousand seats cannot justify. If you have no security staff at all, MDR makes sense at almost any size. If you have a two-person security team working business hours, MDR is usually cheaper than the third and fourth hires needed to cover nights and weekends.

Need licensing?

Get CrowdStrike Falcon pricing

We resell CrowdStrike Falcon through distribution, so we can quote licensing, renewals and seat changes directly. Tell us your seat count and we will come back with real numbers rather than a "contact sales" form.

Request a quote
mdr pricingmdr costedrmdrendpoint securitycrowdstrikehuntressmdr comparison