MDR Pricing for Small Businesses: 9 Checks Before You Buy

MDR pricing for small businesses is easiest to compare when every quote covers the same assets, response duties, and contract period. A low per-device price can become expensive once you add required licenses, minimum commitments, identity monitoring, and the people who still have to act after an alert.

This guide helps an owner, IT manager, or MSP buyer turn three different quotes into one defensible budget. Start with the quick decision below, work through the nine checks, then copy the quote worksheet. You do not need to buy the largest package to close your most important coverage gap.

Research checked: October 10, 2026. Vendor examples come from official documentation, not hands-on product testing. Dollar amounts in the worked example are invented planning inputs, not vendor prices or market averages. Confirm current pricing and terms in a written quote.

Quick answer: what should a small business budget?

There is no useful universal MDR price without a defined scope. Ask for an annual total that separates the managed service, underlying security software, required integrations, onboarding, and optional response work. Compare that total with the work left for your team.

  • No one investigates security alerts overnight? Prioritize continuous investigation and a clear containment process.
  • Your existing EDR works, but nobody manages it? Ask about an MDR service that supports your current deployment before replacing licenses.
  • Account takeover is the main concern? Confirm identity and email telemetry explicitly; endpoint monitoring alone may leave that gap open.
  • You need breach forensics and business recovery? Check the response scope and a separate incident response arrangement. Do not infer those services from the word “response.”

Your first task is simple: list the devices, identities, cloud services, and critical systems you need monitored. Request the same scope from each provider. Only then does a price comparison mean anything.

EDR vs MDR vs an MSSP: what are you buying?

OptionMain roleBuyer question
EDR softwareCollects endpoint signals and supports investigation or response actions.Who operates it, investigates alerts, and acts after hours?
MDR serviceAdds managed threat investigation and defined response work to supported telemetry.Which signals and response actions are actually in scope?
MSSP offeringMay manage several security tools and operational services. Scope varies.Does this contract include active investigation and containment, or alert forwarding?

A security operations center (SOC) is the team and operating function behind monitoring. “24/7 SOC” is useful only when you know what it will do. An email sent overnight and a provider authorized to isolate a compromised laptop can carry similar marketing labels while leaving very different work for your business.

MDR pricing: 9 checks before you compare quotes

1. Count billable assets and minimum commitments

Count laptops, desktops, servers, virtual machines, and other supported workloads separately. Ask how shared devices, inactive agents, seasonal staff, and replacement machines are billed. A per-user quote and a per-endpoint quote can diverge when one employee uses several devices.

Minimums matter for very small teams. Huntress’s official Managed EDR pricing FAQ describes a standard 50-agent minimum and asks businesses below that size to confirm eligibility. That is a specific vendor example, not an industry rule. Check the Huntress pricing FAQ and ask a direct vendor or MSP for the applicable commitment.

2. Separate included software from prerequisite licenses

Ask whether the quoted fee includes the endpoint agent and protection license or manages software you buy separately. Record any required editions and supported operating systems. Also ask whether your existing subscription can remain in place and whether deployment or configuration work is included.

For example, Microsoft states that Defender Experts MDR is sold separately from other Defender products. Its Plan 2 requires Microsoft Sentinel. Treat the managed service and any necessary underlying products as separate budget lines until the seller confirms the complete package. Read Microsoft’s service overview.

3. Map endpoint, identity, email, and cloud coverage

Write a coverage row for each business-critical source. “Microsoft 365 integration” does not explain whether the service monitors sign-ins, mailbox activity, endpoint alerts, or all three. Ask which events are ingested, what detections use them, and what happens if a connector stops sending data.

Sophos’s current service-tier documentation describes user-priced packs for certain third-party integrations and an additional license for network detection and response. The practical lesson is to price your actual telemetry map instead of assuming every connector is bundled. Check Sophos’s tier documentation.

4. Define investigation and escalation after hours

Request the steps from detection to investigation, customer contact, and action. Distinguish an acknowledgement target from an investigation target and a containment target. Ask when each clock starts, whether severity changes the target, and which exclusions apply.

Run a simple scenario: a suspicious administrator sign-in appears at 2 a.m. on Sunday. Who reviews it? Who calls your backup contact? What happens if neither contact answers? A provider should explain the operating process in language your business owner can understand.

5. Put containment authority and recovery boundaries in writing

Identify who may isolate a laptop, disable an account, revoke sessions, or block malicious activity. Define pre-authorized actions and exceptions for systems where isolation could interrupt critical operations. Agree on an escalation path for exceptions rather than leaving them unresolved.

Containment interrupts an attack. Recovery restores trustworthy systems and business operations. Ask separately about forensic investigation, root-cause analysis, rebuilding devices, restoring backups, legal coordination, and on-site work. For emergency support outside the MDR scope, review the incident response retainer decision guide.

MDR response ownership diagram separating investigation, authorized containment, and business recovery.
Assign investigation, containment, and recovery owners before the first incident.

6. Budget onboarding and prove the service is operating

An installed agent is only one onboarding milestone. Ask who deploys it, removes incompatible tools, connects identity sources, checks healthy telemetry, and maintains the asset list. Confirm when billing starts and what evidence marks onboarding complete.

Use an agreed, harmless validation exercise to check the alert route and escalation contacts. Request a deployment report showing expected assets, monitored assets, exceptions, and owners. Do not run real malware or disruptive attack simulations in production to test a new service.

7. Price retention, exports, and reporting

Separate raw telemetry retention, searchable history, incident records, and archived reports. Ask which data you can export, in what format, at what cost, and within what time after cancellation. Longer retention is valuable when you need it, but an archive is not automatically available for live investigation.

Sophos’s cited tier page lists 90 days of standard device data storage and a paid one-year extension. Confirm the applicable data type and plan in your own quote. Request a sample report so you can judge whether it supports management decisions rather than merely counting alerts.

8. Compare contract length, growth, renewal, and exit

Record the committed quantity, billing frequency, term, renewal notice, and renewal-price mechanism. Ask whether quantities can decrease or only increase, how acquisitions or temporary workers affect billing, and what charges apply during a transition.

Compare year-one cost and the ongoing annual cost separately. Temporary overlap with your old license can make the first year more expensive without making the new service a worse long-term fit. Keep taxes, currency conversion, and any partner management fee visible instead of burying them in a headline rate.

9. Count internal work and incident exclusions

MDR does not remove the need for a business owner, an IT owner, or someone who can authorize exceptional actions. Estimate time for onboarding, monthly reviews, vulnerability remediation, access management, and following up on incidents. Ask who owns patching and backups; do not assume they are included.

If an insurance questionnaire asks about monitoring, preserve the service scope and coverage evidence. A subscription receipt alone cannot prove that every relevant system is monitored. Use the cyber insurance questionnaire checklist to organize factual answers, exceptions, and verification dates.

Three service models to compare on equal terms

These are purchasing models illustrated by current vendor documents, not a ranking or an endorsement. Match them to your environment and request the same asset list, response scope, and term from each shortlisted seller.

Model and exampleDocumented detailWhat to confirm
Bundled managed endpoint service — HuntressManaged EDR combines its agent with continuous SOC monitoring and response.Minimum commitment, supported assets, identity coverage, and your partner’s duties.
Tiered service with integrations — SophosMDR and MDR Plus have defined tiers; retention extensions and some integrations have licensing implications.Exact tier, included response work, required packs, and full annual cost.
Service over an existing ecosystem — MicrosoftPlan 1 covers Defender workloads; Plan 2 adds selected Sentinel telemetry and requires Sentinel.Underlying licenses, supported sources, eligibility, and remaining customer responsibilities.

If you already have a functioning security stack, include the cost of keeping it and adding managed investigation. If you need new endpoint technology, include both software and operations. Avoid declaring one model cheaper until the coverage and responsibilities match.

A worked MDR pricing example for 35 endpoints

Illustrative example only, in USD. Suppose a company has 35 endpoints. Offer A bills a minimum of 50 at an invented $12 per endpoint per month and charges $500 for onboarding. Its annual cash cost is 50 × $12 × 12 + $500 = $7,700.

Offer B bills the actual 35 endpoints at an invented $18 per month, plus a hypothetical $100 monthly integration charge and $800 onboarding. Its annual cash cost is (35 × $18 + $100) × 12 + $800 = $9,560.

Budget lineOffer AOffer B
Billable endpoints50 minimum35 actual
Monthly endpoint service$600$630
Monthly integration charge$0 assumed$100
One-time onboarding$500$800
Year-one cash cost$7,700$9,560
Ongoing annual cash cost$7,200$8,760

Offer A is $1,860 lower in year one under these assumptions. That is an arithmetic result, not a recommendation. If B monitors a critical identity source that A excludes, the offers are not equivalent. Ask A to quote the missing coverage, or document why your business accepts the gap. Repeat the comparison at your expected endpoint count next year.

Budget formula: year-one cash cost = 12 × (managed service + required licenses + recurring integrations + retention + partner fees) + onboarding + transition costs. Adjust for shorter terms, billing changes, and tax treatment. Track internal staff hours separately; monetizing those hours helps compare operational effort without confusing it with the invoice.

For the broader security budget, use the security tool stack cost calculator guide to identify overlapping subscriptions and costs outside MDR.

MDR pricing cost worksheet showing recurring subscriptions, one-time setup, transition costs, and internal staff work.
Separate recurring fees, setup costs, and internal effort when comparing quotes.

Copy this MDR quote comparison worksheet

Use one copy per vendor. Ask the seller to fill in missing items in writing. An unanswered field is a follow-up question, not a zero-dollar cost or an included feature.

  • Scope: endpoints ___; servers ___; identities ___; cloud and email sources ___; unsupported assets ___.
  • Commercial terms: billable unit ___; minimum ___; term ___; quantity adjustment rules ___; renewal notice ___.
  • Year-one charges: service ___; required software ___; integrations ___; retention ___; setup ___; overlap ___; taxes ___.
  • Overnight process: investigation owner ___; primary and backup contacts ___; action if unreachable ___.
  • Response authority: pre-authorized containment ___; exceptions ___; approval owner ___.
  • Incident boundaries: included work ___; excluded work ___; extra fees ___; recovery owner ___.
  • Evidence: monitored-asset report ___; last coverage check ___; sample incident report ___; export and exit process ___.
  • Internal effort: onboarding hours ___; monthly hours ___; patching owner ___; backup and restore owner ___.

A practical selection rule: first reject a quote that cannot cover a critical source or define who acts after hours. Then compare full cost among the remaining options. A low price cannot compensate for an unresolved response owner.

MDR pricing FAQ

Is MDR worth it for a small business?

It can be useful when your business has meaningful security exposure and lacks the people to investigate and respond consistently. Start with the specific gap: overnight endpoint alerts, identity threats, or investigation capacity. A defined gap makes a buying decision clearer than a generic desire for “more security.”

Does MDR replace antivirus or EDR?

Some services bundle endpoint technology; others operate over an existing product. Confirm whether your quote replaces a license or adds managed work. Do not remove existing protection until the supported migration and coverage checks are complete.

Is MDR the same as cyber insurance?

No. MDR provides defined security operations; insurance is a policy with its own terms. A monitoring service does not guarantee policy eligibility or claim payment. Your broker can clarify the policy’s requirements, while your IT owner verifies actual technical coverage.

Can a business with fewer than 50 devices buy MDR?

Ask each vendor or MSP. Minimum commitments and partner offers vary. Price the billable minimum rather than multiplying a rate by your actual devices. Also check whether a partner’s package includes deployment, escalation support, and other work you need.

Why does the cheapest MDR quote sometimes cost more?

It may exclude underlying licenses, integrations, retention, onboarding, or response tasks your team must buy separately. Put those costs into the same worksheet, then compare the ongoing year and the first year separately.

Your next step and official sources

Spend 20 minutes making the asset list and identifying the person who can authorize response after hours. Send the same worksheet to your shortlisted providers. Ask them to walk through one endpoint incident and one account-takeover scenario. The strongest quote will make both the invoice and the operating responsibilities understandable.

Sources checked October 10, 2026. This article evaluates documented purchasing criteria; it does not claim independent product performance tests. Service names, licensing, and commitments can change. The signed order and service terms determine your purchased scope.

Stay Updated with Kioptrix

Get practical guides, useful resources, and new articles delivered to your inbox.

No spam. Unsubscribe anytime. Read our Privacy Policy.