Verified
Reviewed byOleh KemOleh Kem
Plans checked31 / 9 vendors
“Contact sales”14/31
Median entry$6.29/mo
Entry range$2.08-7.99
Publish a price4/9
Free tier0/9
Leader98 Huntress

Endpoint security compared: pricing, EDR, XDR and managed MDR

With no free tiers and most prices given only by quote, the figure on a pricing page rarely survives contact with a reseller. Here is what each of nine platforms publishes, per seat or per device, and where a managed hunting team is part of the price.

How much does endpoint security cost when most vendors price only by quote?

The per-seat plans that carry a public price sit between $2.08 and $7.99 a month, and just four of the nine print such a rate. The rest bill per device, per endpoint a year, or by quote. No platform runs a standing free tier, so the real entry is a paid plan, last checked July 29, 2026.

  • Of the 31 plans checked, Fourteen show no public price. They bunch at the enterprise end, where the deeper EDR and XDR suites sell through a sales engineer instead of a page.
  • Just four of the nine put a per-seat price where you can line it up against another. The rest meter per device, per hour of running compute, or per identity, and never land on the same scale.
  • The per-seat median of $6.29 fits almost no one. It sits between the two vendors that bill monthly per seat, a pair a real shortlist would rarely keep together.
  • Managed detection is the real fork. Some vendors run a hunting team against your alerts around the clock; others hand you the sensor and expect a security team on your side.
  • Per-device and per-user prices are not the same purchase. A device count and a headcount pull apart fast once every laptop and server carries its own agent.

Ranked by a transparency score: pricing transparency 60%, user satisfaction 40%. Capability is not scored. It is the condition grid below. Prices are read from vendor pricing pages and re-checked per product on the dates shown. ComparEdge sells no endpoint security software and takes no payment for placement. How the score is built.

01 / 07

Endpoint security ranked: EDR, XDR, managed MDR, DLP and identity

The table sorts on transparency, most open first. Price sits on one logarithmic axis covering all nine platforms, so a marker further right really does cost more. Every column marks its capability granted, conditional or absent across a free tier, tier-by-tier pricing, EDR, XDR, managed MDR, identity ITDR, DLP and network NDR.

Sorted by transparency scorePriced tiers 17 / 31Full disclosure 1 / 9
How to read this table
01HuntressNo free tierAll tiers pricedEDR listedXDR not on the recordManaged MDR listedIdentity ITDR listedDLP not on the recordNetwork NDR not on the record$2.08/learner98Alternatives to Huntress
02SentinelOneNo free tier1 of 5 tiers unpricedEDR listedXDR listedManaged MDR listedIdentity ITDR listedDLP not on the recordNetwork NDR not on the record$5.83/u85Alternatives to SentinelOne
03CrowdStrike FalconNo free tier1 of 5 tiers unpricedEDR listedXDR listedManaged MDR listedIdentity ITDR listedDLP listedNetwork NDR not on the record$7.99/device81Alternatives to CrowdStrike Falcon
04SophosNo published priceNo free tier1 of 3 tiers unpricedEDR listedXDR listedManaged MDR listedIdentity ITDR not on the recordDLP listedNetwork NDR not on the recordSales only72Alternatives to Sophos
05FortinetNo published priceNo free tier1 of 3 tiers unpricedEDR listedXDR listedManaged MDR not on the recordIdentity ITDR not on the recordDLP listedNetwork NDR listedSales only71Alternatives to Fortinet
06Cisco Secure EndpointNo free tier2 of 3 tiers unpricedEDR listedXDR listedManaged MDR listedIdentity ITDR listedDLP listedNetwork NDR listed$6.75/u47Alternatives to Cisco Secure Endpoint
07CynetNo published priceNo free tier0 of 3 tiers pricedEDR listedXDR listedManaged MDR listedIdentity ITDR listedDLP listedNetwork NDR listedSales only35Alternatives to Cynet
08ExtraHopNo published priceNo free tier0 of 2 tiers pricedEDR not on the recordXDR listedManaged MDR not on the recordIdentity ITDR not on the recordDLP not on the recordNetwork NDR listedSales only32Alternatives to ExtraHop
09TrellixNo published priceNo free tier0 of 3 tiers pricedEDR listedXDR listedManaged MDR listedIdentity ITDR not on the recordDLP listedNetwork NDR listedSales only24Alternatives to Trellix
GrantedSome tiers sealedNot on the recordCheapest paid seat* score is user satisfaction alone: the vendor publishes no pricesScore ranks pricing transparency and user ratings, not capability. Capability is the grid.
9 vendorsMedian entry $6.29Coverage span 62 of sixSealed tiers 14 / 31

Scroll the console sideways to reach the remaining conditions.

02 / 07

Shortlist endpoint security by device count and what it really costs

The shortlist ranks by what the plan actually costs your team, not by list price. Flat plans are folded into a per-team number so they compare like for like. Only vendors rated 85 and up are eligible.

Seats
6
Budget / seat

For 6 seats at $6 per seat, start with these

Ranked by monthly team cost, vendors rated 85 and up · Your ceiling for this team: $36 / mo

Best value

Huntress

CE 98

Client fleets spread across sites, watched by a hunting SOC you do not staff yourself.

Entry plan$2.08 / learner
× 6 learners$12.48
Against your $36 ceiling$23.52
Team cost$12.48 / mo
Best value

SentinelOne

CE 85

Teams that will not run detection by hand and want the agent to respond on its own.

Entry plan · billed yearly$5.83 / seat
× 6 seats$34.98
Against your $36 ceiling$1.02
Team cost$34.98 / mo
Not sure what to weigh? Five questions narrow it faster than the grid.Answer 5 questions
03 / 07

Every vendor's plans, verdicts and the date we checked each price

The order tracks each vendor's transparency score, so one that names its prices and pleases its users outranks one that keeps its enterprise tiers for a quote. That lifts a managed service built for small teams above several enterprise suites, which is the score doing its job, not a claim that one outguns the other. Weigh the condition columns and the managed-service line first, the rank second.

Transparency scorePricing transparency 60%User satisfaction 40%

01

Huntress, the managed EDR and threat-hunting service built for MSPs and small IT teams
Huntress

98Disclosure$2.08Learner / mo

Client fleets spread across sites, watched by a hunting SOC you do not staff yourself. Huntress sells that SOC inside the endpoint price and publishes four products in four units, endpoint, identity, log source and learner, with identity ITDR locked to a twelve-month term.

Critical gapThreat remediation depends on SOC detection, limiting manual intervention.

Plan table and expert take

Huntress: expert take

The $8.99 Managed EDR plan buys a per-endpoint sensor with a 24/7 hunting SOC already in the price. Huntress prices four products in four units and is the transparent end of the category, but identity ITDR sells only on a twelve-month term.

Where Huntress holds up

  • Highest G2/Capterra ratings in endpoint security (4.8/4.9)
  • Human-verified threats eliminate alert fatigue
  • Best value MDR for SMBs at $5/endpoint/mo
  • Built by hackers: deep adversary insight for SMB threat patterns

5.0CE scoreG2 4.9 · 883 reviewsCapterra 4.9Founded 2015Verified July 8, 2026

4 plans, as published
PlanMonthlyAnnual
Managed EDR$8.99Not published
Managed ITDR$4.80Not published
Managed SIEM$4Not published
Security Awareness Training$2.08Not published
02

SentinelOne, the autonomous AI endpoint platform with on-agent EDR and XDR
SentinelOne

85Disclosure$5.83Seat / mo, billed yearly

Teams that will not run detection by hand and want the agent to respond on its own. SentinelOne prices per seat but only on an annual contract, and every purchase closes through a reseller who sets the final number.

Critical gapComplex policy tuning requirements frequently demand specialized administrative staff for effective initial environment deployment.

Plan table and expert take

SentinelOne: expert take

The $15 Complete tier is SentinelOne's cheapest published seat, and only on an annual contract. There is no monthly option and no plan you buy directly; every deal closes through an authorized reseller who sets the final number.

Where SentinelOne holds up

  • Autonomous AI response without human intervention
  • Storyline attack correlation simplifies threat hunting
  • Consistently top-performing in MITRE ATT&CK evaluations
  • Unified Singularity XDR across endpoint, cloud, identity

5.0CE scoreG2 4.9 · 113 reviewsCapterra 4.8Founded 2013Verified July 8, 2026

5 plans, as published
PlanMonthlyAnnual
CoreNot published$5.83
ControlNot published$6.67
CompleteNot published$15
CommercialNot published$19.17
EnterpriseContact sales
03

CrowdStrike Falcon, the cloud-native EDR backed by the Falcon threat intelligence network
CrowdStrike Falcon

81Disclosure$7.99Device / mo

A card payment today and a path into managed hunting later, with no procurement cycle up front. CrowdStrike is the rare self-serve entry here, with Falcon Go capped at a hundred devices and core modules like device control and firewall billed as add-ons on top.

Critical gapThe platform currently lacks granular reporting for compliance audits.

Plan table and expert take

CrowdStrike Falcon: expert take

The $7.99 Falcon Go plan is the rare self-serve, per-device entry in this category, capped at a hundred endpoints. Device control, mobile and firewall are add-ons billed over that rate, and the fully managed Complete tier is quote-only.

Where CrowdStrike Falcon holds up

  • Best-in-class threat intelligence from 29k+ customer sensor network
  • Falcon OverWatch managed threat hunting is industry-leading
  • Threat Graph processes 1T+ events/week for AI detection
  • Comprehensive XDR platform covering endpoint to cloud

4.7CE scoreG2 4.6 · 408 reviewsCapterra 4.7Founded 2011Verified July 8, 2026

5 plans, as published
PlanMonthlyAnnual
Falcon Free Trial$0Not published
Falcon Pro$14.99$8.33
Falcon Enterprise$19.99$15.42
Falcon Go$7.99$5
Falcon CompleteContact sales
04

Sophos, endpoint, firewall and MDR managed from one cloud console
Sophos

72DisclosureSales onlyNo price

Shops that would rather not run endpoint and firewall from two consoles. Sophos manages both from one, with a managed tier above, and each server endpoint costs about twice its workstation endpoint at every tier.

Critical gapThe agent software creates significant resource latency on legacy VDI and virtualized infrastructure.

Plan table and expert take

Sophos: expert take

The $110 Endpoint Protection plan is Sophos's one public per-endpoint rate. A server endpoint runs about twice a workstation at each tier, and MDR is a premium managed layer on top, so the console-consolidation saving erodes as you climb.

Where Sophos holds up

  • Sophos Central provides a single pane of glass for endpoint, server, and firewall.
  • Synchronized Security links endpoints and firewalls for automated threat response.
  • Strong focus on MSPs with multi-tenant management and flexible billing.
  • Intercept X combines deep learning AI with anti-ransomware and exploit prevention.
  • Full-service MDR offering includes 24/7 threat hunting and complete remediation.

4.8CE scoreG2 4.7 · 826 reviewsCapterra 4.5Founded 1985Verified July 8, 2026

3 plans, as published
PlanMonthlyAnnual
Endpoint Protection$110 / endpoint/yrNot published
Cloud Firewall (PAYG)$0.42 / hr$2649.02 / yr
Sophos MDR (managed service)Contact sales
05

Fortinet, endpoint security folded into the FortiGate network platform
Fortinet

71DisclosureSales onlyNo price

Endpoint enforcement that lives inside a wider Fortinet network stack, not a standalone agent. Fortinet licenses the endpoint by quote or partner, and its public hourly cloud rate covers the software fee alone, with the AWS compute billed on top.

Plan table and expert take

Fortinet: expert take

The $0.54 FortiGate-VM hourly rate is a software fee only; AWS EC2 runs on top of it. Direct FortiClient endpoint licensing is quote or partner priced, so the public hourly figure covers the network VM, not the endpoint agent.

Where Fortinet holds up

  • 680k+ customers: the network security market leader
  • Single-vendor Security Fabric simplifies architecture
  • FortiGuard Labs provides best-in-class threat intelligence
  • OT/IoT security is industry-leading

4.7CE scoreG2 4.6 · 90 reviewsCapterra 4.5Founded 2000Verified July 8, 2026

3 plans, as published
PlanMonthlyAnnual
FortiGate-VM (PAYG)$0.54 / hrNot published
FortiWeb WAF (PAYG)$0.96 / hrNot published
FortiClient EMS / bundlesContact sales
A clear gap opens after the fifth vendor. Below the line the scores fall, as more of the pricing moves to a quote and user ratings soften.
06

Cisco Secure Endpoint, EDR wired into Talos intelligence and the wider Cisco stack
Cisco Secure Endpoint

47Disclosure$6.75Seat / mo

Enterprises that will not add another vendor to a stack already built on Cisco. Cisco Secure Endpoint prints its Essentials tier and quotes the two above it, and full XDR pulls in other Cisco products, so the product price is not the solution price.

Critical gapThe agent causes sustained 70 percent CPU utilization during routine background scanning.

Plan table and expert take

Cisco Secure Endpoint: expert take

The $6.75 Secure Endpoint Essentials tier is the only Cisco endpoint price you can read off a page. Advantage and Premier are quote-only, and a full XDR build pulls in other Cisco products, so the product price is not the deployment price.

Where Cisco Secure Endpoint holds up

  • Leverages Talos intelligence, one of the world's largest threat research teams.
  • Deep integration with Cisco network gear for unparalleled device context.
  • Unified XDR visibility via the included SecureX platform.
  • Orbital advanced search provides deep OS-level visibility using osquery.
  • Strong exploit prevention and behavioral protection against fileless malware.

4.6CE scoreG2 4.5 · 27 reviewsCapterra 4.2Founded 1984Verified July 8, 2026

3 plans, as published
PlanMonthlyAnnual
Secure Endpoint Essentials$6.75Not published
Secure Endpoint AdvantageContact sales
Secure Endpoint PremierContact sales
07

Cynet, the mid-market XDR bundling EDR and managed detection in one agent
Cynet

35DisclosureSales onlyNo price

EDR and managed detection consolidated into one agent instead of a rack of separate tools. Cynet quotes every tier, and its Elite plan folds in a 24/7 managed-detection team rather than charging for it as an add-on.

Critical gapThe platform maintains high licensing costs despite redundant feature overlaps with competitors.

Plan table and expert take

Cynet: expert take

One of the quote-only names here: Cynet prints no tier price, and the only public per-endpoint figures come from third-party review sites, not the vendor. Its Elite plan does bundle a 24/7 managed-detection team into the base rather than as an add-on.

Where Cynet holds up

  • 24/7 MDR (CyOps) included: rare value at this price
  • All-in-one: EDR + network + UEBA + deception in one agent
  • High G2 rating (4.7) for XDR category
  • AutoRemedy reduces response time without SOC headcount

4.8CE scoreG2 4.7 · 250 reviewsCapterra 4.8Founded 2016Verified July 8, 2026

3 plans, as published
PlanMonthlyAnnual
ProtectContact sales
EliteContact sales
All-in-OneContact sales
08

ExtraHop, the agentless network detection and response platform
ExtraHop

32DisclosureSales onlyNo price

SOC teams that cannot put an agent on every device and still need to catch lateral movement. ExtraHop watches network traffic instead of the endpoint, so it sits beside an EDR rather than replacing one, and it carries no public price at all.

Critical gapThe system generates false-positive alerts on legitimate traffic to common web services.

Plan table and expert take

ExtraHop: expert take

The outlier in the box: ExtraHop does network detection, not endpoint, and watches traffic agentlessly for lateral movement across unmanaged devices. It carries no public price at all, sold by annual subscription priced on traffic and asset count.

Where ExtraHop holds up

  • Best-in-class network detection and response (NDR)
  • Detects lateral movement that endpoint tools miss
  • Works on unmanaged devices (IoT, OT) without agents
  • CrowdStrike integration creates powerful XDR combination

4.7CE scoreG2 4.6 · 68 reviewsFounded 2007Verified July 8, 2026

2 plans, as published
PlanMonthlyAnnual
Reveal(x) 360Contact sales
Reveal(x) EnterpriseContact sales
09

Trellix, the XDR suite formed from the McAfee and FireEye merger
Trellix

24DisclosureSales onlyNo price

Enterprises carrying a McAfee or FireEye estate forward into one XDR stack with deep forensic collection. Trellix prices everything by private offer; the figures on its marketplace listing are placeholders, not rates.

Critical gapThe agent exhibits high resource consumption and frequent SIEM parsing errors in complex network environments.

Plan table and expert take

Trellix: expert take

A quote-only estate play: Trellix sells its EPP, EDR and XDR SKUs by private offer, with no public list price. The dimensions on its AWS Marketplace listing are placeholders labelled do-not-use, not real rates.

Where Trellix holds up

  • 40k+ enterprise customers provide strong market credibility
  • Broad XDR coverage across endpoint, email, network, cloud
  • Helix SIEM/SOAR integration
  • FireEye legacy threat intelligence

4.4CE scoreG2 4.3 · 327 reviewsCapterra 4.1Founded 2022Verified July 8, 2026

3 plans, as published
PlanMonthlyAnnual
Trellix Endpoint Security (EPP)Contact sales
Trellix Endpoint Detection and Response (EDR)Contact sales
Trellix XDRContact sales
04 / 07

Compare any two endpoint vendors: plans, device limits and score

vs

What the records say

For 6 seats, Huntress bills $12.48 / mo and SentinelOne bills $34.98 / mo, $22.50 / mo between them.

SentinelOne carries 4 of the 6 capability columns on the record; Huntress shows 3.

Users rate them level: 4.9 on G2 apiece.

Huntress prices everything it sells; SentinelOne leaves part of its lineup unpriced.

Pick Huntress for: Client fleets spread across sites, watched by a hunting SOC you do not staff yourself.

Pick SentinelOne for: Teams that will not run detection by hand and want the agent to respond on its own.

01

Huntress

CE 98 · G2 4.9
Published plans, US$/mo
Managed EDR$8.99
Managed ITDR$4.80
Security Awareness Training$2.08
Team of 6$12.48 / mo

Verified July 8, 2026

02

SentinelOne

CE 85 · G2 4.9
Published plans, US$/mo
CoreNot published
CompleteNot published
EnterpriseContact sales
Team of 6$34.98 / mo

Verified July 8, 2026

Both price lists on the category axis

Huntress
SentinelOne

Where they differ

Only Huntress has on the record

  • Every tier priced

Only SentinelOne has on the record

  • XDR
05 / 07

Endpoint questions: SentinelOne against CrowdStrike, per device or user

How much does SentinelOne cost compared with CrowdStrike?

SentinelOne prices per seat on an annual contract and does not sell a plan you buy directly, with tiers from the mid-single digits to the low twenties per seat a month and a quote-only Enterprise step. CrowdStrike sits at the other end: Falcon Go and Pro are self-serve per device, Complete is quote-only, and add-on modules raise the real total. Neither publishes the fully managed tier's price.

What is the difference between per-device and per-user endpoint pricing?

Per-device pricing counts each machine that runs an agent. Per-user pricing counts people, and one person often carries two or three devices. CrowdStrike Go and Pro bill per device; Cisco and SentinelOne bill per user, Sophos per endpoint. A device-heavy team is usually cheaper on per-user, a device-light team on per-device. Count both before you line up two rates.

How do I avoid the managed-detection surcharge?

Managed detection is a paid layer on most platforms here, sold as an upper tier or a separate hunting team. To skip it, buy the detection-only plan and run the alerts with your own security desk. That saves money only if you actually staff one around the clock. Cynet and Huntress fold a managed team into the base price instead, so with them there is no separate surcharge to dodge.

Can you try endpoint security without paying?

Only through trials, not a standing free tier. CrowdStrike offers a short self-serve trial with no card, and most others run a proof-of-value you arrange with their sales team. There is no permanently free plan you can run in production. Budget for a paid plan from the start, because the trial always ends and the meter starts the day it does.

Is SentinelOne better than CrowdStrike?

They solve the problem differently. SentinelOne leans on autonomous on-agent response and sells per seat through resellers on annual terms. CrowdStrike leans on a large intelligence network and managed hunting, and it lets small teams start self-serve before moving up to a quoted managed tier. The better fit tracks whether you want to buy direct or contract through a partner, and whether you staff incident response yourself.

What do the top EDR tools actually charge?

Published rates cluster low, then vanish. The self-serve tiers sit from the mid-single digits to about twenty per seat or per device a month, which covers the names chasing smaller teams like CrowdStrike, Cisco and Huntress. Above that, SentinelOne is annual-only through a reseller, and Cynet, Trellix, ExtraHop and Fortinet name no public price. The headline tiers are the cheap, comparable part; the enterprise suites are where the quotes live.

Why do most endpoint security vendors hide their price?

Enterprise EDR is priced against your fleet size and contract length and whichever modules you switch on, so the vendor holds the number until it knows those. Selling through partners adds a second reason: the reseller sets the final figure, not the pricing page. The vendors that do print a rate tend to be the ones after smaller teams who want to buy without a call.

What is the difference between EDR and XDR on this page?

EDR watches the endpoint itself: the laptop, server or VM running the agent. XDR widens that to network, identity and cloud signals correlated in one place. Almost every platform here now lists both, so the label rarely decides a shortlist. What differs is how deep each layer goes and whether a managed team reads the output, and neither of those shows up as a checkmark.

Which endpoint tool is best for an MSP or a small IT team?

Huntress is built around that buyer: a managed hunting SOC in the base price, per-endpoint billing, and partner rates for MSPs. Sophos and Cynet court smaller shops too, Sophos with one console for endpoint and firewall, Cynet with a managed team folded into the plan. If you have no security desk of your own, weight the managed service over the length of the feature list.
Field note 01

The managed service matters more than the detection engine

Every platform here raises alerts, and an alert is worth something only when someone acts on it. That is the real split in this market. Some vendors run a team that watches your alerts around the clock and hunts for what the automation missed. Others give you a strong sensor and assume you already staff a security desk of your own.

If you do not run that desk yourself, the managed service is the product, and its depth beats another row of feature checkmarks. The matrix marks who bundles managed detection. It cannot show how far that team goes before it hands the incident back. Ask what they contain on their own and what they only flag for you. Then ask how remediation works once a finding turns out to be real.

Field note 02

The agent runs on every machine you own, and that has a cost

This software installs on every laptop and server, and its weight lands on every user, not just the security team. Heavy scans and CPU load on older or virtualised hardware are a known tax across this category, and none of it shows up as a column. A platform that detects well and grinds a fleet to a crawl still costs you, in support tickets and in people quietly switching the agent off.

Operating-system coverage varies too. Windows support is even; macOS and Linux depth is not. Before a wide rollout, pilot the agent on the machines you actually run and measure what it does to a slow laptop. That result decides more day to day than the entry price does.

The verdict on endpoint security softwareSigned review · Updated
Oleh KemOleh KemFounder & Lead AnalystComparEdge Editorial

There is no free tier in endpoint security and, beyond a single self-serve entry bundle, no checkout either: this market sells through resellers, and the reseller sets your real number. Fix the unit first, device or user, then ask what the managed layer adds, because MDR is where quotes double.

Server endpoints price above workstations almost everywhere. The ranking follows published rates, and most of this market publishes nothing.

MethodEvery price on this page is read from the vendor's own pricing page: 31 plans across nine vendors, last verified .
DisclosureCollection is tool-assisted; every verdict is written and signed by a human analyst.
07 / 07

Read next: cost guides for endpoint security software, plus related categories

How this review is made. Prices are read from vendor pricing pages and re-checked on the dates shown against each product. Condition columns reflect the feature set recorded on the vendor’s own pages on that date. ComparEdge sells no endpoint security software and takes no vendor payment for placement. Where a vendor publishes nothing, this page says so rather than estimating. Ranking is by transparency score: pricing transparency 60%, user satisfaction 40%. What a product can do is shown in the condition columns and carries no weight in the number.