# EDR vs MDR vs XDR vs Antivirus: What's the Difference?

> Antivirus, EDR, MDR and XDR are layers of one stack, not rival products, and a small business should pick its layer by who will act on a detection. Antivirus blocks, EDR sees, MDR responds and XDR correlates. This reference defines each, prices each and says which layer fits which business.

Endpoint Index research (Reference). Published 2026-09-25, updated 2026-09-30, data as of 2026-10-02. Source: https://endpointindex.com/research/edr-vs-mdr-vs-xdr-vs-antivirus/

## Executive summary

**Most small businesses without security staff need antivirus that blocks on its own, or MDR that responds for them, and should skip both self-managed EDR and XDR.** The four terms name layers of one stack. Antivirus (EPP) blocks threats automatically. EDR records what happens on each device so a person can investigate. MDR is a service in which a provider's analysts watch that EDR data and respond around the clock. XDR stretches detection beyond the device to email, identity, network and cloud.

The layer you need follows from one fact: **who will act when something is detected.** EDR and XDR are only as good as the person reading them. Just 3 of the 17 products in our database, as priced on 2026-10-02, put that person in the base price.

| | Antivirus / EPP | EDR | MDR | XDR |
|---|---|---|---|---|
| **What it is** | Software | Software | Service (people plus software) | Software platform |
| **Main job** | Block malware before it runs | Record, detect, investigate and contain; some products also roll back | Detect, investigate and respond 24/7 on your behalf | Correlate signals across endpoint, email, identity, network and cloud |
| **Who acts on a threat** | The software, automatically | You or your IT provider | The provider's analysts | You, your IT provider, or an MDR service |
| **Needs staff to be useful** | No | Yes | No | Yes, unless managed |
| **Typical small-business fit** | 1 to 25 devices, low-risk data, no IT | Has an IT person or MSP | No security staff, sensitive data | Larger IT teams with several security tools |

## What does antivirus (EPP) do?

Endpoint protection platforms (EPP) are the business form of antivirus: they stop malicious code from running. Modern EPP goes well past matching known signatures. It uses behaviour analysis and machine-learning models to block suspicious files and scripts, and the business editions add a central console, policy control and remote management.

EPP's strength is that it acts alone. A blocked file needs no human decision. EPP's limit is visibility. When an attacker uses legitimate tools such as PowerShell, remote-desktop software or a stolen password, there may be no malicious file to block, and EPP will not show you what happened next.

EPP is the layer independent labs test most directly. AV-Test rates protection, performance and usability. AV-Comparatives publishes protection rates and false-alarm counts from its Business Security Test. Every product page here shows the latest result and its date.

## What does EDR add, and why doesn't it help without a responder?

Endpoint detection and response (EDR) keeps a running record of each device: processes started, network connections, file changes and logins. It flags sequences that look like an attack. An investigator can then see the whole chain of events and act: isolate the device, kill processes, or roll back changes, including ransomware encryption where the product supports rollback.

EDR comes with a condition. **Its alerts need a human decision.** Many are harmless activity that looks odd; a few are real intrusions that need action within minutes. If nobody reviews the console, EDR becomes an expensive record of what went wrong.

The mistake buyers make here is treating EDR as a stronger antivirus. EDR usually includes EPP-style blocking, so it is not worse, but the extra money buys visibility, and visibility nobody looks at is wasted.

MITRE ATT&CK Evaluations test EDR detection by emulating a real attacker step by step and publishing what each product saw. MITRE does not rank vendors, and its results show detection coverage, not how easy a product is for a small team to run.

## What is MDR, and how is it different from EDR?

Managed detection and response (MDR) is a **service**. Gartner describes it as remotely delivered security operations centre (SOC) functions in which the provider's staff detect, analyse, investigate and actively respond to threats, including containing them, instead of only sending notifications.

For a small business, MDR looks like this in practice:

- The provider's analysts watch your EDR data day and night.
- They decide which alerts are real.
- They contain the threat, for example by isolating a laptop, often before you know anything happened.
- They report what happened and what, if anything, you need to do.

**EDR is the tool; MDR is the team using it.** Some vendors sell managed response as an add-on to their EDR; others fold it into one per-seat price for small businesses. The [managed-response ranking](/best/endpoint-protection-with-managed-response/) lists the bundles, and the [managed EDR buyer's guide](/research/managed-edr-mdr-small-business-buyers-guide/) covers how to choose a provider.

The mistake buyers make with MDR is paying for "managed" monitoring that stops at an email. If the provider will not isolate a device without phoning you first, you have bought notification.

## What is XDR, and does a small business need it?

Extended detection and response (XDR) takes EDR's detect-and-investigate approach past the endpoint. Gartner defines XDR as a unified platform that automatically collects and correlates data from several security components. An XDR platform might tie a suspicious login, a phishing email and a process on a laptop into one incident, where separate tools would raise three unrelated alerts.

For most small businesses **XDR is the wrong question.** XDR pays off when you run several security tools and have people to investigate across them. A business without that capacity gets more from EDR plus managed response. If your MDR provider runs XDR behind the scenes, you benefit without having to operate it.

Watch the label, too. Vendors use "XDR" loosely, and a product sold under that name may be an EDR product with a few extra integrations.

## Is MDR the same as a managed SOC or SIEM?

MDR is a narrower thing than either. A **SIEM** (security information and event management) collects logs from across your environment for analysis and responds to nothing by itself. A **managed SOC** is a team that monitors your environment, often through a SIEM. **MDR** is a managed SOC focused on detection and active response, usually on the provider's own EDR or XDR technology. When the purchase is endpoint protection for a small firm, MDR is the form that matters. Ask whether the provider will *act* (isolate, contain, remediate) or only *notify*.

## How much do antivirus, EDR and MDR cost a small business?

Price rises with the work the product does for you. Published list prices at 10 seats run from $30.00 (<a href="/products/webroot-business-endpoint/">Webroot Business Endpoint Protection</a>) to $179.99 (<a href="/products/sentinelone-singularity-complete/">SentinelOne Singularity Complete</a>) per endpoint or user per year, and the median is $69.50. The entry price of each layer tells the story:

| Layer | Cheapest published price at 10 seats | Products tracked |
|---|---|---|
| Antivirus / EPP | $30.00 per unit per year | 9 |
| EDR (managed bundles included) | $36.00 per unit per year | 8 |
| EDR with 24/7 managed response included | $99.00 per unit per year | 3 |

The step from EPP to EDR is small at the entry level. The step to managed response is where the money goes, because it buys people. Prices at 10, 25 and 100 seats for every product are in the [2026 cost report](/research/small-business-endpoint-security-cost-2026/). The [SMB Endpoint Security Price Index](/research/smb-endpoint-security-price-index/) adds 5- and 50-seat prices and the products sold only by quote.

## Which one does my business need?

Answer three questions in order:

1. **Can anyone respond to a security alert within an hour, day or night?** If not, choose EPP (blocking only) or a product with managed response included. Do not buy self-managed EDR.
2. **Would stolen or encrypted data seriously hurt clients or the business?** Health records, payment data, legal files and client finances all count. If yes and nobody can respond, managed response is worth the price difference.
3. **Does an IT provider or MSP run your systems?** Ask whether they monitor EDR alerts and at what hours. If they cover nights and weekends, EDR they manage may be enough. If they work business hours, you still have a gap outside office hours.

Applied to common cases:

- **If you are a five-person office with no IT support and routine data,** buy a well-tested EPP product and switch on automatic updates.
- **If you are a small accountancy, clinic or law firm with no IT staff,** buy MDR or a managed EDR bundle; client data raises the stakes and nobody is there to respond.
- **If you have an MSP that monitors around the clock,** EDR managed by the MSP is the efficient choice. Confirm the hours in writing.
- **If you have an in-house IT team juggling email security, identity and endpoint tools,** that is the point at which XDR starts to earn its keep.

## Frequently asked questions

### Is EDR better than antivirus?

EDR is more capable than antivirus, but it is not automatically the right purchase for a small firm. EDR adds recording, investigation and response, and those help only if someone acts on the alerts. For a team with no IT staff, a well-tested EPP product that blocks automatically can be the better choice. Most EDR products include EPP-style blocking anyway. The [EDR comparison for small businesses](/research/edr-comparison-small-business-2026/) sets the EDR products side by side on price, test results and the work they leave to you.

### Do I need EDR if I have MDR?

MDR normally runs on EDR. The provider's analysts work from the EDR data on your devices, so buying MDR includes or requires an EDR agent. Ask whether the MDR price includes the EDR licence or bills it separately.

### What is the difference between MDR and XDR?

XDR is technology that correlates detection data across endpoints, email, identity, network and cloud. MDR is a service in which a provider's analysts detect and respond for you. The two combine, since some MDR providers run XDR platforms. A small business without security staff needs the service before the technology.

### Can Microsoft Defender replace EDR?

Microsoft Defender for Business is itself an EDR product with a management console, at $36.00 per user per year. The Defender Antivirus built into Windows is not EDR. Neither version includes 24/7 managed response, and Microsoft sells none for Defender for Business: its Defender Experts services are add-ons to enterprise suites such as Microsoft 365 E5. A small business that wants its Defender alerts watched pays an IT provider or MSP to do it, or picks a product with managed response included. Defender for Business also has no ransomware rollback.

### What should an MDR provider do when it finds a threat?

An MDR provider should contain the threat itself, by isolating the device or stopping malicious processes, and then report what happened. Alerting alone is monitoring, not response. Ask every provider for its response time and the list of actions it takes without permission.

## Methodology and caveats

The definitions here follow common industry usage and Gartner's published descriptions of MDR and XDR. Vendor marketing stretches all four terms, so check what a product does before trusting its label. Prices, counts and capabilities are inserted from Endpoint Index records during each build, which keeps this reference in step with the product pages; each value there shows its source and last check date.

Prices are US dollar list prices at 10 seats, before promotions and reseller discounts. Products without a published price are counted but not priced. This reference is information, not procurement advice.

## Sources

1. Gartner. [Managed Detection and Response market overview](https://www.gartner.com/en/insights/gartner-market-overviews/managed-detection-and-response). Definition of MDR services.
2. Gartner Peer Insights. [Extended Detection and Response market](https://www.gartner.com/reviews/market/extended-detection-and-response). XDR market definition.
3. MITRE. [ATT&CK Evaluations: Enterprise results](https://evals.mitre.org/results/enterprise).
4. AV-Test Institute. [Tests of business endpoint protection](https://www.av-test.org/en/antivirus/business-windows-client/).
5. AV-Comparatives. [Business Security Test 2026 (March to June)](https://av-comparatives.org/tests/business-security-test-2026-march-june/).
6. Endpoint Index. Product pages for each product named, with per-value sources and verification dates. Last price verification in this dataset: 2026-10-02.
