Skip to main content
Has your work email already leaked?Run the 10-second check
MDR pricing

The number moves most on the thing nobody itemizes.

Two MDR quotes at the same endpoint count can differ enormously, and the reason is usually response mandate: whether the provider may act on your estate or only tell you about it. That almost never appears as a line item, and it should be the first question you ask.

The short version

MDR pricing is driven by six things: how many endpoints, users or assets are covered; how much response authority the provider has; coverage hours; whether the platform license is bundled or you bring your own; how far scope extends beyond the endpoint into identity, cloud and email; and whether retention and evidence are included.

Response mandate is the driver that moves the number most and is itemized least. A service permitted only to notify is cheaper to operate than one contractually able to isolate a host at 3am without waking anybody, because the second absorbs operational risk.

Vijilan does not publish rates; they are channel rates behind partner verification. ThreatRespond™ operates over the EDR you already own, so an existing license stays yours. ThreatDefend™ includes CrowdStrike Falcon® licensed and operated end to end. Comparing those two without normalizing is the most common error in this evaluation.

What moves the number

Six drivers, one of which is usually invisible.

Endpoints, users or assets

The headline meter, and the one every provider will quote against. Worth checking what counts: servers versus workstations, whether cloud workloads are included, and whether a user with four devices is one unit or four.

Response mandate

The driver that moves the number most and appears as a line item least. A service permitted to notify is cheaper to run than one permitted to isolate a host at 3am without waking anybody, because the second carries operational risk the provider absorbs. Ask which you are buying and get it in writing.

Coverage hours

Business hours, extended, or genuinely continuous with a staffed rotation. All three get described as 24/7 somewhere, and the difference is several salaries.

Whether the platform license is included

Some providers operate over the EDR you already own, some bundle their own. Those are very different quotes and comparing them without normalizing is the most common mistake in this evaluation.

Scope beyond the endpoint

Identity, cloud, email and network each add sources, detection content and investigation surface. An endpoint-only service and a cross-domain one are not the same product even where both are called MDR.

Retention and evidence

Whether a SIEM is included, and for how long data stays queryable. This is where an MDR quote and a compliance requirement collide, usually late.

Before you compare

Normalize the quotes, or the cheapest one wins for the wrong reason.

Ask every provider the same four questions and write the answers down. Which specific actions may you take without contacting us. What are the coverage hours, and is that a staffed rotation. Is the platform license included or do we bring our own. What is in scope beyond the endpoint.

A quote that is cheaper because it excludes response authority, runs business hours, or covers endpoints only is not a better price. It is a different product, and the difference surfaces on the night it matters rather than during procurement.

Questions

Including why we will not print a rate.

How much does MDR cost?

We do not publish rates, because they are channel rates behind partner verification. What is more useful before a quote is knowing the six things that move it, because MDR quotes that look wildly different are usually pricing different scopes rather than the same scope differently.

Why do MDR quotes vary so much?

Mostly response mandate and scope. A service that notifies you is a different operational commitment from one contractually able to isolate a host, disable an account and terminate a process without waking anybody, and the second carries risk the provider absorbs. Add whether the platform license is bundled and whether identity and cloud are in scope, and two honest quotes for "MDR" can be describing quite different products.

Is MDR priced per endpoint or per user?

Both models exist and the choice matters more than it looks. Per-user tends to favor organizations where people have several devices; per-endpoint tends to favor organizations with fewer, shared machines. Ask how servers, virtual desktops and cloud workloads count, because that is where two quotes on the same estate diverge.

Does the price include the EDR license?

Depends on the shape. ThreatRespond™ operates over the endpoint tooling you already own, so you keep an existing license and it is not in our number. ThreatDefend™ includes CrowdStrike Falcon® licensed, deployed and operated end to end. Comparing one against the other without normalizing is the most common error in this evaluation.

Is MDR cheaper than hiring analysts?

For almost every organization below enterprise scale, yes, and the comparison is not close. A genuinely staffed 24/7 rotation is several full-time salaries plus training to keep them current, and that is before tooling. The service is cheaper because the cost is shared across every organization the SOC covers.

What should we insist is in the contract?

The specific actions the provider may take without contacting you, the notification threshold, what happens to your data if you leave, and whether the evidence from an incident is yours. Those four are where a service that reads well diverges from one that works at 3am.

How do we get a real number?

The pricing wizard takes a verified work email and routes MSPs to the partner portal and enterprises to a scoped conversation. Bring your endpoint count, your coverage requirement and how much response authority you actually want to delegate.

We're online · book a SOC walkthrough today

Tell us how much authority
you actually want to delegate.

That answer changes the service more than the endpoint count does, and it is the part most quotes leave you to infer. We would rather establish it before quoting than after.