# Managed EDR and MDR for Small Business: 2026 Buyer's Guide

> A small business with nobody to watch security alerts should buy managed EDR rather than a bare EDR console. The choice between providers turns on three facts: whether their analysts act or only notify, what independent evidence backs the detection underneath, and whether the contract fits how your IT is run.

Endpoint Index research (Buyer's guide). Published 2026-09-25, updated 2026-09-30, data as of 2026-10-02. Source: https://endpointindex.com/research/managed-edr-mdr-small-business-buyers-guide/

## Executive summary

**A small business that cannot answer a security alert at night should buy managed EDR, and should judge providers on what their analysts are contractually allowed to do, not on the software.** Managed EDR puts a vendor's security team behind the EDR agent on your devices: they sort real alerts from noise and contain threats, often before you hear about it. Across the 17 products in the database (last price check 2026-10-02), 3 include that 24/7 service in the base price and 2 sell it as an add-on.

The price gap is the cost of people. The cheapest published bundle with analysts included is $99.00 per seat per year (<a href="/products/threatdown-elite/">ThreatDown Elite</a>). The cheapest self-managed antivirus is $30.00.

The buyer mistake this guide exists to prevent: paying for EDR, leaving it unwatched, and discovering after an incident that the alerts were there all along. The other expensive mistake is a "managed" service that only emails you.

Three questions decide between providers:

1. **Will the provider act, or only notify?** Isolation and containment should be done by their analysts, in writing.
2. **What independent evidence backs the detection engine?** Some bundles have no public lab result at all.
3. **Does it fit how your IT is run?** An MSP-run business needs multi-tenant support and RMM integration; a regulated one needs a signed BAA.

## What is managed EDR, and how is it different from MDR?

**Managed EDR** is endpoint detection and response software watched by the vendor's own security operations centre (SOC). **MDR** (managed detection and response) is the wider service category; Gartner defines it as remotely delivered SOC functions that detect, investigate and actively respond to threats. For a small firm shopping for device protection, the two labels usually mean the same purchase: an EDR agent on every device plus analysts who respond for you.

The difference is scope. Managed EDR watches laptops, desktops and servers. A broader MDR service may also watch email, Microsoft 365 sign-ins, firewalls and cloud workloads. Most small businesses start with endpoints because ransomware runs there.

[EDR vs MDR vs XDR vs antivirus](/research/edr-vs-mdr-vs-xdr-vs-antivirus/) covers the wider set of acronyms.

## Which managed EDR and MDR products are available to small businesses?

Three routes exist, and they suit different buyers.

**Bundles with analysts in the base price.** These are the simplest purchase for a business with no security staff:



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">#</th><th scope="col">Product</th><th scope="col">Price at 10 seats</th><th scope="col">24/7 managed response</th><th scope="col">Min seats</th><th scope="col">SMB Fit Score</th></tr></thead><tbody><tr><td data-label="#"><span class="cell"><span class="mono">01</span></span></td><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/threatdown.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/threatdown-elite/">ThreatDown Elite</a></span></span></td><td data-label="Price at 10 seats"><span class="cell"><span class="num">$99.00</span> <span class="unit">/endpoint/yr</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Min seats"><span class="cell"><span class="num">5</span></span></td><td data-label="SMB Fit Score"><span class="cell"><span class="num strong">52</span></span></td></tr><tr><td data-label="#"><span class="cell"><span class="mono">02</span></span></td><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="Price at 10 seats"><span class="cell"><span class="muted">Min 50 seats</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Min seats"><span class="cell"><span class="num">50</span></span></td><td data-label="SMB Fit Score"><span class="cell"><span class="num strong">35</span></span></td></tr><tr><td data-label="#"><span class="cell"><span class="mono">03</span></span></td><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/cynet.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/cynet/">Cynet</a></span></span></td><td data-label="Price at 10 seats"><span class="cell"><span class="muted">Quote only</span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Min seats"><span class="cell"><span class="num">1</span></span></td><td data-label="SMB Fit Score"><span class="cell"><span class="num strong">34</span></span></td></tr></tbody></table></div><figcaption>Ranked by <a href="/methodology/">SMB Fit Score</a> (fit-v1), then price. Prices are annual list prices per unit at 10 seats, from each vendor's own pricing page; "Min N seats" means the vendor's smallest purchase is larger. Follow a product link for the source and verification date.</figcaption></figure>



**EDR with managed response sold on top.** You buy the EDR licence, then add the vendor's managed service at extra cost: <a href="/products/watchguard-endpoint-security-360/">WatchGuard Endpoint Security 360</a>, <a href="/products/webroot-business-endpoint/">Webroot Business Endpoint Protection</a>. Budget for both lines; the add-on price is usually quoted, not published.

**Your MSP's own SOC.** Some MSPs run round-the-clock monitoring on a third-party EDR. Get the hours and response actions into your contract with them.

Five capabilities separate these products for a managed purchase:



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">24/7 managed response</th><th scope="col">Ransomware rollback</th><th scope="col">macOS</th><th scope="col">MSP multi-tenant</th><th scope="col">RMM/PSA integration</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/webroot.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/webroot-business-endpoint/">Webroot Business Endpoint Protection</a></span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-add_on">Add-on</span></span></td><td data-label="Ransomware rollback"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="macOS"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="MSP multi-tenant"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="RMM/PSA integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/threatdown.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/threatdown-elite/">ThreatDown Elite</a></span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Ransomware rollback"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="macOS"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="MSP multi-tenant"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="RMM/PSA integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Ransomware rollback"><span class="cell"><span class="state state-not_offered">Not offered</span></span></td><td data-label="macOS"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="MSP multi-tenant"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="RMM/PSA integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/cynet.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/cynet/">Cynet</a></span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="Ransomware rollback"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="macOS"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="MSP multi-tenant"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="RMM/PSA integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/watchguard.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/watchguard-endpoint-security-360/">WatchGuard Endpoint Security 360</a></span></span></td><td data-label="24/7 managed response"><span class="cell"><span class="state state-add_on">Add-on</span></span></td><td data-label="Ransomware rollback"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="macOS"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="MSP multi-tenant"><span class="cell"><span class="state state-included">Included</span></span></td><td data-label="RMM/PSA integration"><span class="cell"><span class="state state-included">Included</span></span></td></tr></tbody></table></div><figcaption>From each vendor's product and pricing pages. "Add-on" means available at extra cost. Follow a product link for sources and verification dates.</figcaption></figure>



## How should a small business evaluate a managed EDR provider?

### Does the provider respond, or only alert?

This question outweighs every other. A managed response service **takes action**: it isolates an infected device, kills malicious processes, removes persistence, then tells you what it did. A service that only emails you an alert has handed the hard part back to you. Put three questions to every provider:

- Which actions will your analysts take without asking me first?
- What is your response time for a critical alert, and is it in the contract?
- Who do I speak to during an incident, and at what hours?

Published speed figures are not the same as a contractual commitment. Huntress advertises an 8-minute mean time to respond (MTTR) for Managed EDR, a marketing figure rather than an SLA. ThreatDown reports a median 5 minutes to detect and 19 minutes to contain for its MDR, from its own incident data, and offers contractual SLAs only with MDR Plus, not with Elite.

### What independent evidence backs the detection?

Labs test software, not analysts, so only the EDR engine underneath has a public score. The bundles differ sharply:



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">AV-Test protection</th><th scope="col">AV-Comparatives protection</th><th scope="col">MITRE ATT&CK Evaluation</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/threatdown.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/threatdown-elite/">ThreatDown Elite</a></span></span></td><td data-label="AV-Test protection"><span class="cell"><span class="muted">No public result</span></span></td><td data-label="AV-Comparatives protection"><span class="cell"><span class="muted">No public result</span></span></td><td data-label="MITRE ATT&amp;CK Evaluation"><span class="cell"><span class="num">Participated</span> <span class="unit">2024</span> <span class="state state-not_offered">Dated</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="AV-Test protection"><span class="cell"><span class="muted">No public result</span></span></td><td data-label="AV-Comparatives protection"><span class="cell"><span class="muted">No public result</span></span></td><td data-label="MITRE ATT&amp;CK Evaluation"><span class="cell"><span class="muted">No public result</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/cynet.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/cynet/">Cynet</a></span></span></td><td data-label="AV-Test protection"><span class="cell"><span class="muted">No public result</span></span></td><td data-label="AV-Comparatives protection"><span class="cell"><span class="muted">No public result</span></span></td><td data-label="MITRE ATT&amp;CK Evaluation"><span class="cell"><span class="num">100% coverage</span> <span class="unit">2025</span></span></td></tr></tbody></table></div><figcaption>Latest published round per lab, as recorded on each product page. Results marked "Dated" are past the freshness window and score zero in the SMB Fit Score. MITRE does not rank or score vendors.</figcaption></figure>



Huntress Managed EDR has no public AV-Test, AV-Comparatives or MITRE ATT&CK result. ThreatDown Elite's last MITRE round was 2024 (ER6), and it has no AV-Test business result since October 2023 or AV-Comparatives business result since 2022. Cynet took part in MITRE's 2025 round (ER7). None of this proves weakness. Where results are missing you are relying on the vendor's claims, so ask for references from businesses your size.

### What does it cost at your seat count?

Managed bundles cost more per seat because the price includes people. Compare the all-in price at your real seat count: separate EDR licences, onboarding fees and seat minimums all count. Huntress Managed EDR bought direct or from a reseller has a 50-endpoint minimum (Huntress sets none through an MSP), which changes the sum completely for a ten-person firm. The [cost report](/research/small-business-endpoint-security-cost-2026/) lists published prices at 10, 25 and 100 seats, and the [price index](/research/smb-endpoint-security-price-index/) shows which managed products publish a price at all.

### Does it work with your MSP?

If an MSP runs your IT, check three things:

- **Multi-tenant management**, so the MSP can run your account alongside its other clients.
- **Integration with the MSP's RMM and PSA tools.** Each product page names the integrations.
- **Who the SOC calls during an incident:** you, or the MSP. Agree this before signing.

### What happens after the provider contains a threat?

Containment stops the spread; recovery is a separate job. Ask whether the product can roll back ransomware changes, whether the provider helps restore systems, and what incident response beyond containment costs. Huntress Managed EDR does not offer automated ransomware rollback. ThreatDown Elite does, on Windows only.

### What does the contract lock you into?

Terms vary more than prices. ThreatDown Elite's licence agreement renews the subscription automatically; opting out takes 30 days' written notice before the renewal date. Cynet's terms say a signed sales order cannot be cancelled or refunded. Read the term and notice clauses on each product page before you sign a multi-year order.

## Which managed EDR fits which business?

- **If you have 5 to 20 devices, no IT provider and want to buy online,** ThreatDown Elite is the only managed bundle here sold self-serve, at $99.00 per endpoint per year. Its online store takes 5 to 20 devices; larger orders go through ThreatDown sales or a partner, by quote.
- **If your IT is outsourced to an MSP,** find out whether it resells Huntress Managed EDR; bought through an MSP it carries no seat minimum. The [Huntress vs ThreatDown Elite comparison](/compare/huntress-managed-edr-vs-threatdown-elite/) sets the two side by side.
- **If you handle patient data,** confirm the BAA first. Huntress states it does not provide one, and ThreatDown's HIPAA notice says its services are not designed to receive health data. Cynet maps its reporting to HIPAA but does not say publicly that it signs a BAA, so get the signed agreement before deployment.
- **If you already run Microsoft Defender for Business,** nobody watches it for you: Microsoft offers no managed response for this product, and its Defender Experts services attach to enterprise suites such as Microsoft 365 E5. Either pay an IT provider or MSP to monitor it, or switch to a bundle with analysts included. Compare the two routes in the [Huntress vs Microsoft Defender for Business comparison](/compare/huntress-managed-edr-vs-microsoft-defender-for-business/).
- **If you want independent lab evidence above all,** <a href="/products/cynet/">Cynet</a> is the only bundle here with a lab result from the last 18 months: MITRE's 2025 evaluation (ER7), where it detected all 90 substeps. The EDR product with the broadest recent results, <a href="/products/microsoft-defender-for-business/">Microsoft Defender for Business</a> (AV-Test August 2026, AV-Comparatives first half of 2026), includes no managed response and Microsoft sells none for it, so choosing it means pairing it with an MSP or third-party SOC.

The regulatory position of the products with managed response, included or as an add-on:



<figure class="data-figure"><div class="table-wrap"><table class="data-table"><thead><tr><th scope="col">Product</th><th scope="col">HIPAA BAA</th><th scope="col">Supports PCI DSS</th><th scope="col">CMMC-relevant</th><th scope="col">FedRAMP</th></tr></thead><tbody><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/webroot.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/webroot-business-endpoint/">Webroot Business Endpoint Protection</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/threatdown.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/threatdown-elite/">ThreatDown Elite</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-not_offered">No</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/huntress.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/huntress-managed-edr/">Huntress Managed EDR</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-not_offered">No</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/cynet.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/cynet/">Cynet</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr><tr><td data-label="Product"><span class="cell"><span class="prod-cell"><img class="logo logo-24" src="/logos/watchguard.png" alt="" width="24" height="24" loading="lazy" /><a href="/products/watchguard-endpoint-security-360/">WatchGuard Endpoint Security 360</a></span></span></td><td data-label="HIPAA BAA"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="Supports PCI DSS"><span class="cell"><span class="state state-included">Yes</span></span></td><td data-label="CMMC-relevant"><span class="cell"><span class="state state-unknown">Unknown</span></span></td><td data-label="FedRAMP"><span class="cell"><span class="mono">none</span></span></td></tr></tbody></table></div><figcaption>From each vendor's trust or compliance pages. "Unknown" means the vendor does not publish the fact; follow a product link for sources.</figcaption></figure>



## Is Huntress worth it for a small business?

Huntress Managed EDR folds its 24/7 SOC into the per-seat price, $107.88 per endpoint per year, and sells mostly through MSPs. Its SMB Fit Score is 35. Three facts decide whether it is worth it:

- **Managed response is included.** That is the point for a firm without security staff: the analysts do the work.
- **No public lab results.** Huntress appears in none of the AV-Test, AV-Comparatives or MITRE ATT&CK results recorded here, so it scores zero on efficacy under the published formula. That explains much of its rank.
- **No automated ransomware rollback.** Huntress relies on its SOC's response instead, as its product page records.

**Our read:** Huntress suits MSP-served businesses that value a human-led response over lab scores. A buyer who wants independent test evidence should compare it with products that have it. The [Huntress vs SentinelOne comparison](/compare/huntress-managed-edr-vs-sentinelone-singularity-complete/) lays out the trade-offs field by field.

## Huntress or SentinelOne for an MSP?

Huntress and SentinelOne sell into the same MSP market from opposite ends:

| | Huntress Managed EDR | SentinelOne Singularity Complete |
|---|---|---|
| **24/7 managed response** | Included in the price | Not offered in Complete |
| **List price** | $107.88 per endpoint per year | $179.99 per endpoint per year |
| **Independent test evidence** | No public results | MITRE ATT&CK 2024 (ER6); skipped the 2025 round |
| **Renewal clause** | Not stated in the public pricing FAQ | Renews at 120% without 30 days' notice (MSA 11.1) |
| **SMB Fit Score** | 35 | 33 |

An MSP that wants the vendor's SOC to carry response gets that built into Huntress. An MSP with its own SOC, or one that wants a MITRE evaluation history and can staff response itself, has the stronger case for SentinelOne, since Complete comes with no managed service.

## How do you roll out managed EDR in a small business?

1. **Onboarding call.** Agree contacts, escalation rules and the actions analysts may take without asking.
2. **Agent deployment.** Install the agent everywhere, remove the old antivirus if the new product replaces it, and reconcile the device count against your asset list.
3. **Tuning period.** Expect an initial period in which the SOC learns what normal looks like and you approve exclusions for legitimate business software.
4. **Steady state.** Read the monthly report. Re-confirm emergency contacts each quarter, because a stale phone number turns a contained incident into an uncontained one.

## Frequently asked questions

### What is the best MDR for a small business?

The best MDR is the one whose analysts will act on your behalf within a contracted response time. Among bundles, the right pick depends on whether you buy online or through an MSP, whether you need a HIPAA BAA, and how much weight you give independent lab results. The ranked table above orders the bundles by SMB Fit Score.

### How much does MDR cost for a small business?

Among bundles that include 24/7 managed response and publish a price, the lowest is $99.00 per seat per year (<a href="/products/threatdown-elite/">ThreatDown Elite</a>). Cynet and most add-on services are quote-only, so real prices spread wider than the published figures.

### Do I need MDR if I have an IT provider?

You need MDR if your IT provider does not monitor and respond to security alerts around the clock. Many providers work business hours only. Ask yours who handles a critical EDR alert at 2am on a Sunday, and get the answer in writing.

### Is managed EDR the same as MDR?

Managed EDR is MDR limited to devices. Both put a vendor team behind an EDR agent; MDR can extend to email, identity, network and cloud.

### What should an MDR contract include?

An MDR contract should list the response actions taken without asking, a response time for critical alerts, named escalation contacts and the price of incident response beyond containment. Check the term, auto-renewal and notice period too; each product page records them.

## Recommendations

1. **Buy managed response if nobody can answer alerts around the clock.** An unwatched EDR console is spending on alarms nobody hears.
2. **Get response actions and response times written into the contract.**
3. **Weigh lab evidence, and ask for references where there is none.**
4. **Compare all-in cost at your seat count,** separate EDR licences and minimums included.
5. **Confirm the BAA before deployment** if you handle health data.
6. **If an MSP runs your IT, agree who the SOC calls first** and write it down before an incident.

## Methodology and caveats

Managed-response status, prices, scores and lab results in this guide come from the Endpoint Index database at build time, the same records behind every product page. Those pages show a source link and a verification date beside each value.

- **"Included" means in the base price** the vendor publishes. "Add-on" means sold at extra cost.
- **Prices** are US dollar list prices per seat per year, without promotions, reseller margins or onboarding fees. Quote-only bundles are ranked but not priced.
- **The SMB Fit Score** judges how well a product suits a small buyer. It cannot judge a provider's analysts, because no public test does. The [formula is published](/methodology/).
- **Coverage.** 17 products from 14 vendors are tracked. Providers missing from the list can [apply for a free listing](/for-vendors/list/?plan=free).

Treat this as information rather than procurement or legal advice, and confirm response commitments with the provider before signing.

## Sources

1. Gartner. [Managed Detection and Response market overview](https://www.gartner.com/en/insights/gartner-market-overviews/managed-detection-and-response). Definition of MDR services.
2. Huntress. [Huntress and HIPAA compliance](https://support.huntress.io/hc/en-us/articles/4404004949523-Huntress-and-HIPAA-Compliance). Statement that Huntress does not provide BAAs.
3. ThreatDown. [ThreatDown and HIPAA](https://support.threatdown.com/hc/en-us/articles/40223444237843-ThreatDown-and-Health-Insurance-Portability-and-Accountability-Act-HIPAA) and [software licence agreement](https://www.threatdown.com/legal/eula/), section 5(a).
4. Cynet. [Terms and conditions](https://www.cynet.com/eula/), section 6.4.
5. SentinelOne. [Master Subscription Agreement](https://www.sentinelone.com/legal/master-subscription-agreement/), section 11.1.
6. MITRE. [ATT&CK Evaluations: Enterprise results](https://evals.mitre.org/results/enterprise).
7. AV-Comparatives. [Business Security Test 2026 (March to June)](https://av-comparatives.org/tests/business-security-test-2026-march-june/).
8. Endpoint Index. Product pages and comparisons for each product named, with per-value sources and verification dates. Last price verification in this dataset: 2026-10-02.
