Pricing
EDR vs MDR vs XDR: what you're actually paying for
Three acronyms, three very different cost structures — here is what separates the tool, the service, and the platform.
EDR, MDR, and XDR get used almost interchangeably in vendor pitches, but they describe fundamentally different things — a tool you operate, a service you buy, and a platform tier you upgrade to. Knowing which is which is the difference between a budget line that makes sense and one that double-counts.
The one distinction that matters: who does the work
Strip away the marketing and the categories sort cleanly by who runs it:
- EDR (Endpoint Detection and Response) is a tool you run. It puts an agent on each endpoint, collects telemetry, and alerts. Your team triages and responds.
- MDR (Managed Detection and Response) is a service. It bundles detection telemetry (often EDR) with a 24/7 human team that triages, investigates, and responds on your behalf.
- XDR (Extended Detection and Response) is a platform tier that correlates signals across endpoint, cloud, identity, and email rather than endpoint alone. It is usually a premium upgrade of an endpoint or platform suite.
The most common budgeting mistake is treating these as a price ladder for the same thing. They are not. EDR is a license; MDR is licenses plus labor; XDR is broader coverage.
What each one costs
List prices give you a planning range before quotes arrive. Expect negotiated rates to land below these at scale:
| Category | Typical range | Planning midpoint | What you get |
|---|---|---|---|
| EDR | $3–$20 / user / mo | ~$8 | Endpoint agent + alerts you triage |
| MDR | $3–$45 / endpoint / mo | ~$6 | Telemetry + a 24/7 team that responds |
| XDR | $5–$25 / user / mo | premium tier | Correlation across endpoint, cloud, identity, email |
MDR’s range is wide because pricing varies with scope — some offers are detection-only, others include active response and even limited remediation. Always confirm what “response” actually includes before comparing two MDR quotes.
The hidden line item: your own labor
The EDR-versus-MDR decision is really a build-versus-buy decision, and the comparison only works if you price your own people. Running EDR well requires analysts on the queue around the clock. At a loaded cost of roughly $162K per FTE, even a minimal 24/7 rotation is several full-time staff before you have detected a single threat.
A $6/endpoint MDR service can be cheaper than the in-house alternative once you count the staff EDR alone would require — particularly below the scale where a full SOC is justified.
For many small and mid-sized teams, MDR is not a premium add-on to EDR; it is what makes EDR usable without standing up a 24/7 team you cannot otherwise afford.
Where XDR fits — and where it does not
XDR is the category most likely to be oversold, because “extended” can mean almost anything. The useful version of XDR correlates signals that would otherwise sit in separate consoles: an endpoint alert, a suspicious cloud API call, and an anomalous sign-in stitched into one timeline. That correlation is genuinely valuable when your risk spans those domains.
It is less valuable when:
- Your environment is endpoint-heavy and you have little cloud or identity surface to correlate against.
- The “XDR” on offer only ingests data from one vendor’s own products, so coverage is narrower than the name implies.
- You would be paying the premium tier mainly for a dashboard, while the underlying response work still falls to a team you do not have.
Ask vendors exactly which domains their XDR correlates and whether it ingests third-party telemetry. The answer separates a real cross-domain platform from a rebranded endpoint suite.
How to decide
A short decision path:
- Do you have 24/7 analyst coverage today? If no, MDR is likely cheaper than building it — compare the MDR quote against the loaded cost of the staff you would hire.
- Is your risk concentrated on endpoints, or spread across cloud and identity? If it is spread, an XDR tier or cross-domain correlation matters more than a richer endpoint tool.
- Are you double-paying? If you already buy MDR, you are paying for endpoint telemetry inside that service — adding a separate premium EDR license may be redundant.
None of these tiers makes you “secure” on its own; each buys you a specific capability — faster detection, outsourced response, or broader visibility. Match the spend to the gap you actually have, not the acronym with the most coverage in the diagram.
To model EDR, MDR, and XDR against your headcount and endpoint counts, use the cybersecurity budget calculator.
References
- Endpoint pricing — CrowdStrike, SentinelOne, Microsoft Defender (list) (opens in a new tab) · verified Jun 2026
- MDR pricing — Huntress, Arctic Wolf, CrowdStrike, SentinelOne (opens in a new tab) · verified Jun 2026
- BLS — Information Security Analysts (OES wage data) (opens in a new tab) · verified May 2024
Put this into a number
Build a sourced, defensible budget from your own risk profile — free and ungated.