How to Choose an MDR Provider: A Buyer's Checklist
Most MDR buyers grade the wrong things. They compare dashboards and 24/7 badges, sign, then find out the provider can watch a ransomware attack unfold but can't stop it without paging your team first. This checklist ranks the eight criteria that decide whether MDR actually protects you, starting with the two nobody checks.
Table of Contents
To choose an MDR provider, verify response authority, a defined MTTR by severity with service credits, MITRE ATT&CK detection coverage, 24/7 human analysts, transparent per-unit pricing, and data you keep if you leave.
Detection was never the hard part. Stopping the attack is. Before you shop for managed cybersecurity, get clear on what you're actually buying. An MDR provider exists to catch a threat and shut it down before it becomes a breach, ideally in minutes. That's the whole promise. Yet according to Mandiant's M-Trends 2025, the global median dwell time, the window an attacker sits inside a network before anyone notices, is still 11 days. Eleven days is a long time to own your servers.
Here's the uncomfortable part. Two providers can quote the same monitoring, the same tools, the same "lightning-fast" response time, and deliver completely different outcomes when something actually catches fire. The gap doesn't show up in the sales deck. It shows up at 2 a.m. on a Saturday. This guide is built to surface that gap before you sign, not after.
What does an MDR provider actually do, and what doesn't it?
An MDR (managed detection and response) provider runs a 24/7 security team that watches your environment, investigates real threats, and takes or recommends containment. Monitoring plus response. That second word is where providers quietly differ.
Managed detection and response is a service, not a product category you bolt on. The provider ingests signals from your endpoints, Microsoft 365, identity systems, cloud, and network, correlates them, and separates the one alert that matters from the ten thousand that don't. When they find a live threat, a good MDR provider isolates the host, disables the account, or blocks the traffic. A weaker one sends you a ticket and wishes you luck. If you want the full breakdown, we wrote a longer piece on what MDR really means.
People mix up three terms constantly, and vendors are happy to let the confusion ride. MDR detects and responds. An MSSP manages security tools and usually just alerts you. A SIEM is the log platform underneath, not a service at all. The distinction sounds academic until you're paying MDR money for MSSP work. We break the categories down in MDR, MSSP, and SIEM, but here's the short version.
- MDR is a 24/7 service that detects and responds, and the provider contains the threat for you, often in minutes.
- An MSSP is a provider that manages your security tools, so your team does the containment after they alert you.
- A SIEM is a log and correlation platform, not a team. Nobody acts on it, because it's software.
Gartner's Market Guide for MDR is blunt about the baseline. Real MDR means 24/7 staffing, immediate remote containment, and a human-led service that engages with your data every day. If a provider can't check all three, it isn't MDR. It's monitoring with a nicer logo.
Answer three questions about your own environment first
You can't evaluate a provider until you know what you're asking it to protect. Skip this and every demo looks equally good. Three questions.
How many users and endpoints do you actually have, counting laptops, servers, cloud workloads, and the phones that touch company email? This number drives your price and your coverage. Undercount it and your quote is fiction.
What are you on the hook for, compliance-wise? A defense manufacturer chasing CMMC has different evidence needs than a real estate firm worried about wire fraud. If you carry SOC 2, CMMC, or PCI obligations, your MDR provider has to generate audit evidence, not just peace of mind. That's a hard requirement, and it's a separate discipline from the monitoring itself. Consilien treats compliance readiness as its own offering for exactly that reason.
And the honest one. What can your own team handle at 2 a.m. on a holiday weekend? For most companies with 20 to 500 users, the real answer is nothing, because the two people who know the environment are asleep. That gap is the whole reason MDR exists. Name it out loud before a salesperson names it for you.
The MDR buyer's checklist, 8 criteria that actually matter
Ranked by what breaks the deal, not by what's easiest to demo. The first two are the ones buyers skip and regret.

1. Response authority, can they contain or just call you?
Ask exactly this. What can your analysts do to my environment without calling me first? A strong answer names specifics. Isolate an endpoint, disable an account, block an IP, quarantine an email, all pre-authorized in the contract. A weak answer talks about notification and recommended actions. Response authority is the single most under-checked criterion in MDR selection, and it's the one that decides whether a fast-moving ransomware event gets stopped at one machine or spreads to forty while everyone waits for sign-off. The NIST incident handling framework puts containment right after detection for a reason. Detection without authority to act is just an expensive smoke alarm.
2. An MTTR that's defined, not marketed
Every provider brags about mean time to respond. Almost none define it the same way. A 15-minute response can mean an analyst glanced at the alert, or it can mean the threat was contained. Those aren't remotely the same thing. Pin the definition down in writing. You want MTTR by severity level, a separate clock for triage versus containment, and service credits when they miss. No credits means no real commitment. The SANS incident response data shows the top quarter of organizations detect inside 60 minutes. Ask where the provider's numbers actually land, and ask for audited proof, not a slide.
3. Detection coverage mapped to MITRE ATT&CK
A detection score you can't interrogate is worthless. Ask how their detection coverage maps to MITRE ATT&CK, the public catalog of real attacker techniques. Good providers can show you which behaviors they actively hunt and which still ride on automated rules. That transparency tells you where your blind spots are. If the answer is a proprietary number and a shrug, assume the gaps are wherever it's most convenient for them.
4. 24/7 human analysts, and named ones
Attackers prefer nights, weekends, and the Friday before a long holiday. So 24/7 can't mean a script that pages a human who logs on an hour later. It means people awake and watching. Then ask the follow-up most buyers forget. Will I work with the same analysts, or whoever's in the queue? Named analysts learn your environment. A rotating pool relearns it every incident, which is exactly when you can't afford the lag. Ask about analyst turnover too. High churn is a quiet quality problem.
5. Integration with the stack you already run
MDR only sees what it's plugged into. If a provider can't pull clean telemetry from Microsoft 365, your identity provider, your cloud, and your existing EDR, it has blind spots by design. Ask how many platforms they integrate with natively. Fewer than 20 to 30 is a warning sign. Ask specifically about your stack, by product name, not in the abstract. Saying they support most tools is not an answer. If you're weighing endpoint tooling alongside the service, our breakdown of EDR, MDR, and XDR untangles what sits where.
6. Compliance reporting that survives an audit
If you carry regulatory weight, monitoring isn't enough. The provider has to produce evidence. MDR maps cleanly to controls like Incident Response, Audit and Accountability, and System and Information Integrity, and the logs, investigations, and documented response actions become the paper trail an assessor wants. Ask to see a sample compliance report. If it's a generic PDF of green checkmarks, it won't hold up when a CMMC or SOC 2 auditor starts asking questions.
7. Transparent pricing with a monthly ceiling
Get the pricing model in plain terms. Per endpoint, per user, per gigabyte, or custom. Then ask the question that saves you later. What's the most I could pay in a single month? Incident response hours, data overages, and burst charges hide in the fine print, and a single bad month can blow a quarterly budget. A provider that won't quote a ceiling is telling you the meter runs faster than the brochure suggests.
8. Data and log ownership you keep when you leave
This is the criterion nobody asks about until they try to switch. Some providers own your normalized logs, your dashboards, and sometimes your tool licenses. Leave, and you lose your history. For a regulated company that's an audit risk, not just an inconvenience. As Expel notes on MDR contracts, lock-in through data ownership is a common trap. Demand a clean exit clause and data portability in writing. A provider confident in the work doesn't need to hold your data hostage to keep you.
Red flags that should end a sales conversation
Some answers aren't yellow flags to negotiate around. They're reasons to walk. Watch for these.
- They require you to rip out working tools and buy their proprietary stack. Forced purchases protect their margin, not your security.
- Anything below high severity gets logged but never investigated. That's where a patient attacker lives, in the alerts nobody reads.
- The MTTR is impressive and the methodology is a secret. A sub-one-minute number means nothing if the threshold definition is loose.
- Ask about a weakness and they get defensive. Every provider has gaps. The good ones tell you where.
- Vague pricing, punitive termination clauses, and a promise to figure out the details after you sign. You won't like the details.
One more, because it's expensive. Industry cost analysis puts real year-one spend around 37% above the headline per-endpoint price once onboarding, integration, and incident retainers land. If the quote looks clean and simple, ask what's not in it.
What MDR actually costs in 2026, and the fees nobody quotes
MDR runs roughly $5 to $25 per endpoint per month for monitoring and response, with full-response tiers reaching $25 to $50. Per-user pricing lands around $20 to $60. Those are the ranges. The real number depends on what you make it watch.
Coverage drives cost more than headcount does. Adding cloud workloads bumps the bill 20 to 40%. Identity monitoring adds 15 to 30%. Compliance reporting is its own line. A 100-endpoint shop might budget a few thousand a month for basic coverage or well into five figures for full response plus compliance evidence. Here's the shape of it.
- Per endpoint runs $5 to $25 a month, or $25 to $50 for full response, climbing with response depth, forensics, and retainer hours.
- Per user lands around $20 to $60 a month, driven by identity coverage and SaaS breadth.
- Add-on surfaces stack on top. Cloud adds 20 to 40%, identity adds 15 to 30%, one bump per telemetry source you connect.
- The fees nobody quotes. Onboarding at $5,000 to $25,000, IR retainers, and log overages push the year-one total around 37% over the headline.
The cheapest quote almost never wins the total-cost math. A provider that contains a breach in an hour instead of a week is doing something the discount vendor can't. IBM's 2025 Cost of a Data Breach report found the global average breach costs $4.44M, and organizations using AI and automation extensively cut their breach lifecycle by 80 days and saved $1.9M per incident. Speed isn't a luxury feature. It's the return on the whole investment.
Who should, and shouldn't, buy MDR right now
Bias disclosed. Consilien sells this. So here's the honest version, including when you don't need it.
You're a strong fit if you run 20 to 500 users, your IT team is small or stretched, and you can't realistically staff a security desk around the clock. You're an even stronger fit if you carry compliance weight. A defense contractor pursuing CMMC or a manufacturer whose customers demand a security attestation needs the evidence trail MDR produces, and building that internally costs far more than the service. Manufacturers get one extra thing to check. Ask whether the provider takes operational technology into account before it isolates something, because containment that shuts down a production line to stop malware can cost more than the malware would have.
Who shouldn't buy it yet? If you have a mature internal SOC already running 24/7, you may only need targeted support, not full MDR. And if you haven't covered the basics, MFA everywhere, endpoint protection, backups you've actually tested, spend there first. MDR watches a house. It doesn't lock the doors you left open. I'm not saying that because it costs me a sale. A provider that sells you response before you've done the fundamentals is selling you a false sense of safety.
How to run the evaluation, a 30-day plan
You don't need six months to pick a provider. You need a structured 30 days and the discipline to test claims instead of believing them.
Week one, write your requirements down and build a simple scorecard from the eight criteria above. Weight response authority and data ownership heavily. They're the ones you can't fix later. Week two, run two or three demos and score them against the same list, not against each other's marketing. Week three, run a proof of value on your top pick and actually test containment. Trigger a benign event and watch whether they contain it or ask permission. Not validating that during the trial is how buyers end up surprised at 3 a.m. Week four, make reference calls to customers in your industry, check the contract for the exit clause and the monthly ceiling, and sign.

If you want a head start on the shortlist, our roundup of top MDR providers for SMBs covers who fits which environment. Score them against your own list anyway. The best provider on paper isn't always the best one for your stack.
The bottom line
The provider that wins your business should be the one that scores highest on your criteria, not the one with the smoothest deck or the lowest quote. Three things carry the most weight. Response authority, because detection without the power to act is theater. A defined MTTR with service credits, because a promise with no penalty is just marketing. And data portability, because the day you want to leave is the day you find out who really owns your security history.
Run the checklist. Test the claims. Read the exit clause before you sign, not after.
If you're evaluating MDR for a 20 to 500-user company and want a second read on a provider's SLA and response authority before you commit, speak to a security operations expert who'll tell you what the contract actually guarantees.