Criteria catalog · Endpoint Detection and Response
EDR selection: the criteria that matter under NIS2 and DORA
Most EDR evaluations check detection rate and price. Under NIS2 and DORA, that is not enough. These are the criteria that decide whether your choice holds up in an audit, not just in a demo.
Independent criteria reference · 23 criteria · Last updated August 2026 · Not sponsored by any vendor
An EDR decision looks like a security decision. Under NIS2 and DORA it is also a documentation and jurisdiction decision. The tool with the best detection score can still be the wrong choice if it cannot export a forensic report in time, if its data leaves the EU, or if the vendor cannot produce the attestations your auditor asks for. The criteria below are the ones DecisionOS puts on the scoring sheet for an EDR case, in the same order and grouping, so that what you check here is what you score there.
Detection & Response
Criterion 01
Detection Accuracy (MITRE ATT&CK Coverage)
Why it matters
Vendor-reported detection rates are marketing. What counts is performance in independent evaluations like MITRE ATT&CK, where every vendor is tested against the same adversary techniques under the same conditions.
What to ask
Ask for the vendor's results in the most recent MITRE ATT&CK Enterprise evaluation, specifically the detection coverage and the number of missed detections. Not the press release, the actual results.
The trap
Vendors cite the evaluation round where they performed best, which may be years old. Always ask for the latest round, and check whether they participated at all in the most recent one.
Criterion 02
Mean Time to Detect (MTTD)
Why it matters
The time between an attacker's first action on an endpoint and the first alert decides how much of the network they reach. A tool that detects a ransomware chain at the encryption stage has technically detected it and practically lost. Under NIS2 Article 23 your own 24-hour clock starts at awareness, and awareness starts with this alert.
What to ask
Ask for the measured median and worst-case time from initial execution to alert for the techniques in the latest MITRE evaluation, and whether the alert fires at initial access, at privilege escalation or only at impact. Ask a reference customer for the same number from a real incident.
The trap
"Real-time detection" describes the telemetry pipeline, not the detection logic. A tool can stream events in milliseconds and still raise the alert an hour later once a cloud analysis job runs. Ask where the delay sits, and whether it grows when the vendor's cloud is under load.
Criterion 03
Mean Time to Respond (MTTR)
Why it matters
Detection buys you a window; response is what you do with it. Time to respond is the time until a host is isolated, a process killed or an account disabled, and it is limited by whether the tool can act, who is allowed to trigger it and how fast the console reacts during an incident. It is the number your incident timeline will be judged on.
What to ask
Ask for the time from alert to executed containment in the vendor's own measurements and in a reference customer's incident, and ask to isolate a host in the demo while the clock runs. Ask whether response actions work when the endpoint is off the corporate network.
The trap
"Response in seconds" refers to the API call, not to the workflow around it. If containment needs an analyst, an approval and a VPN, the real number is hours. Measure the path you will actually use at night, not the button in the demo.
Criterion 04
Automated Response / Remediation
Why it matters
Detection without action is a notification. When an attacker moves laterally at 2am, what limits the damage is whether the tool can isolate the host from the network, kill the process, quarantine the file and roll back the changes on its own, under rules you set in advance. Under NIS2 the incident handling measure is judged by what happened, not by what was seen.
What to ask
Ask which containment actions the product can execute automatically, per platform, on which conditions, and how a wrong automatic isolation of a production server is reversed. Ask to trigger an isolation in the demo and to see the endpoint reconnect afterwards.
The trap
"Automated response" frequently means an alert is created automatically and a human still clicks isolate. Ask for the list of actions that run without a click, and check that list against your servers, where automatic isolation is exactly what you do not want unless the rule is precise.
Criterion 05
False Positive Rate
Why it matters
A tool that flags everything is as useless as one that flags nothing. High false positive rates burn out your SOC team and lead to real alerts being ignored. This is an operational cost that never shows up in the sales deck.
What to ask
Ask for a reference customer of similar size and industry, and ask that customer directly how many false positives they handle per week and how tuning worked in the first three months.
The trap
Demo environments are tuned to look clean. The false positive problem only appears once the tool meets your real, messy environment. A reference call reveals what a demo hides.
Coverage & Deployment
Criterion 06
OS & Platform Coverage (Windows, Linux, macOS)
Why it matters
An EDR only protects the endpoints it runs on. Server estates are mostly Linux, developers and executives often use macOS, and the odd end-of-life Windows server or embedded system still carries production. A vendor that treats one of those as a second-class platform leaves exactly the systems an attacker looks for outside your detection, and the audit will count them as unprotected assets.
What to ask
Hand the vendor your real OS inventory, including versions and end-of-life systems, and ask for each line whether the agent is supported with the same detection and response features as on current Windows, with reduced features, or not at all.
The trap
"Supported" on the platform matrix often means the agent installs. Behavioural detection, isolation and rollback may exist only on Windows, and the Linux agent may be a file scanner. Ask for feature parity per platform, not for the checkmark.
Criterion 07
Deployment Complexity & Rollout Effort
Why it matters
An EDR that takes nine months to reach every endpoint protects nothing for nine months, and the endpoints that are hard to reach, such as unmanaged laptops, factory PCs and servers with change freezes, are the ones that stay unprotected longest. Rollout effort is a security number as much as a project number.
What to ask
Ask for the deployment plan for your real estate: agent packaging for your management tools, behaviour on machines without permanent connectivity, coexistence with the antivirus you remove, and the number of person-days a comparable customer needed to reach 95 percent coverage.
The trap
"Deploys in minutes" refers to one agent on one machine. The months go into the exceptions: legacy systems that crash with the kernel driver, the reboot nobody may schedule, the ten percent of devices the management tool has never seen. Ask for the coverage curve of the last three rollouts.
Criterion 08
Agent Performance Impact (CPU/RAM)
Why it matters
The EDR agent runs on every endpoint. If it slows machines down, users notice, complain, and in the worst case try to disable it. A heavy agent is a security risk because it creates pressure to remove it.
What to ask
Ask for measured CPU and memory footprint under normal load, and run a pilot on real machines used by real people before you commit. Not on clean test machines.
The trap
Performance benchmarks are run on idle machines. The impact you care about is on a developer's laptop running a build, or a finance machine running heavy spreadsheets. Test where the pain would actually show.
Criterion 09
MDR / Managed Detection & Response Option
Why it matters
If your team cannot staff a 24/7 SOC, the tool alone is not enough. A mature MDR offering means the vendor watches your environment when your team sleeps. Under NIS2, response time is not optional.
What to ask
Ask what the guaranteed response time is for a critical alert at 3am on a Sunday, and whether that is contractually binding or a best-effort target.
The trap
"We offer MDR" can mean a mature 24/7 team or a thin service that emails you and waits. The gap between those two is enormous. The contract language tells you which one it is.
Criterion 10
XDR / Extended Detection Capability
Why it matters
Attacks rarely stay on one endpoint. XDR is the promise that the tool correlates endpoint telemetry with identity, email, network and cloud signals into one incident instead of four alerts in four consoles. Whether that correlation exists for your sources decides whether the analyst sees an attack or a list.
What to ask
Ask which of your non-endpoint sources the platform ingests natively and correlates into a single incident, whether that correlation is vendor-maintained logic or a search you write, and to see one cross-domain incident from a live tenant, not a demo dataset.
The trap
"XDR" on the datasheet is frequently the EDR with a data lake attached. Ingesting a log is not correlating it. If the vendor's XDR only correlates its own products, the X covers the vendor's portfolio, not your estate.
Integration & Intelligence
Criterion 11
SIEM Integration & Log Forwarding
Why it matters
An EDR tool that does not integrate cleanly with your SIEM, your ticketing, and your identity provider becomes an island. Isolated security tools create blind spots exactly where attackers operate, in the gaps between systems. And under NIS2 and DORA the SIEM is where the evidence for the incident timeline is expected to be.
What to ask
Ask for a list of native integrations with your specific stack, whether the full telemetry or only alerts can be forwarded, in what schema and at what cost, and whether they are maintained by the vendor or by you. Ask to see the integration working in the demo, not just listed on a slide.
The trap
"Integrates with everything via API" means you build and maintain the integration yourself. And "SIEM integration" often forwards alerts only, while the raw telemetry stays in the vendor's cloud and costs extra to export. Native, vendor-maintained integrations with full event forwarding are worth far more than a generic API.
Criterion 12
Threat Intelligence Feed Quality
Why it matters
Threat intelligence is what lets the tool recognise a known campaign in the first minute instead of after the analysis. Its value depends on freshness, on relevance to your region and sector, and on whether indicators are enriched with context the analyst can act on. Stale or generic feeds produce alerts nobody can prioritise.
What to ask
Ask where the intelligence comes from, how fast a new campaign's indicators reach your tenant, whether sector- and region-specific intelligence (for example on groups targeting European critical infrastructure) is included, and whether you can add your own feeds and those of your CERT.
The trap
"Powered by global threat intelligence" describes the vendor's telemetry base, which is dominated by whichever markets the vendor sells in most. Ask for the share of indicators that are less than a week old and for a recent example of a European campaign the feed caught before public reporting.
Criterion 13
Forensics & Investigation Capability
Why it matters
NIS2 Article 23 requires an early warning within 24 hours of becoming aware of a significant incident, and a full notification within 72 hours. If your EDR tool cannot reconstruct what happened on the endpoint and export the forensic data fast enough and in a usable format, you cannot meet that deadline, no matter how good the detection is.
What to ask
Do not ask "are you NIS2 compliant." Everyone says yes. Ask: how far back does the endpoint telemetry reach, how fast can I export a full forensic report of an incident with process tree, file and network activity, and in what format? Can I do it myself or do I depend on your support team?
The trap
Many vendors advertise "NIS2-ready" without the reporting actually supporting the 24-hour deadline in practice, and the telemetry retention in the base tier is often shorter than the time an attacker sits in the network. You find out in the middle of your first real incident, the worst possible moment.
Criterion 14
API & Automation Support (SOAR Integration)
Why it matters
Everything you want to automate around the EDR, from ticket creation to enrichment to a SOAR playbook that isolates a host and disables the account, runs through its API. An API that is rate-limited, incomplete or undocumented turns each automation into a support ticket, and the response you planned to automate stays manual.
What to ask
Ask for the API documentation and check whether every action available in the console is also available through the API, what the rate limits are, whether there are vendor-maintained integrations for your SOAR or ticketing platform, and how API changes are announced and versioned.
The trap
"Full REST API" often covers reading alerts and little else; the containment actions you care about may be console-only or in a higher tier. Test the two automations you actually plan to build during the pilot, not the API reference.
Criterion 15
Cloud Workload & Container Coverage
Why it matters
A growing share of your workloads runs as cloud instances, containers and serverless functions that a classic endpoint agent never sees. If the EDR stops at the virtual machine, the systems that hold your data in the cloud are outside detection, and the same is true of the Kubernetes cluster your developers stood up last year.
What to ask
Ask which cloud platforms, container runtimes and Kubernetes distributions are covered, how (agent, sidecar, agentless), whether container images and running containers are both in scope, and what a detection on a short-lived container looks like once the container is gone.
The trap
"Cloud workload protection" is frequently a separate product with a separate licence and a separate console, bundled on the price list and not in the platform. Ask whether cloud and endpoint alerts land in the same incident, and price both if they do not.
Economics & Compliance
Criterion 16
Per-Endpoint Licensing (3-year TCO)
Why it matters
The per-endpoint price is only part of the cost. Full platform value often requires higher tiers, add-on modules, and the MDR service. The number in the first quote and the number you pay in year two are frequently very different.
What to ask
Ask for the full three-year cost including all modules you actually need, price increase caps at renewal, and what specifically is not included in the base price.
The trap
The attractive entry price often excludes the features that made you interested in the first place. Price the configuration you will actually run, not the base tier that looks good in the comparison.
Criterion 17
SOC 2 / ISO 27001 / GDPR Compliance
Why it matters
EDR tools collect enormous amounts of telemetry from your endpoints, including usernames, file names and command lines. Where that data is processed and stored has direct GDPR implications, and for a regulated organisation the vendor's own attestations (SOC 2, ISO 27001) are what goes into the supplier file. A US-headquartered vendor may route telemetry through US infrastructure, which creates Schrems II exposure.
What to ask
Ask for the current SOC 2 Type II report and ISO 27001 certificate with scope, and then ask specifically: is there an EU-only processing region, is it the default or an upgrade, and can the vendor contractually guarantee that no telemetry leaves the EU, including for support and analysis?
The trap
"EU region available" often means available at a higher tier, or available for storage but not for the support team who can still access your data from anywhere. Residency of storage is not residency of access. And a certificate covers the services and locations in its scope statement, which may not include the region you buy.
Criterion 18
Vendor Support SLA & Incident Response
Why it matters
When the agent breaks a production system or the console is down during an incident, the vendor's support is part of your incident response. The support SLA decides whether you get an engineer within the hour or a ticket number within the day, and whether the vendor's own incident response team can be pulled in when your investigation exceeds your capacity.
What to ask
Ask for the contractual response and resolution times per severity in the tier you will buy, whether 24/7 support with a named escalation path is included, and what incident response services (retainer, hourly, included hours) the vendor offers and at what price.
The trap
"24/7 support" often means a portal that accepts tickets around the clock, with engineers in one time zone. Ask a reference customer how long their last critical ticket took to reach a person, and whether the incident response retainer had to be bought separately after the fact.
Criterion 19
Vendor Lock-in & Data Portability
Why it matters
Switching EDR means re-deploying an agent to every endpoint and losing the telemetry history, the tuned exclusions and the detection customisations you built. That switching cost is what lets a vendor raise prices at renewal. Under DORA an exit strategy for critical ICT services is expected; under NIS2 it is simply what keeps you negotiating from strength.
What to ask
Ask how telemetry, incidents, exclusions and custom rules can be exported in an open format, whether historical data remains accessible after the contract ends, what the vendor offers to assist a migration out, and what the agent removal looks like at scale.
The trap
"Open platform" for data ingestion, proprietary for everything you built on it. And the telemetry that you paid to collect for three years is deleted with the tenant. Price the exit before you sign, and keep a copy of what you would need to prove an old incident.
Criterion 20
Roadmap & Threat Landscape Alignment
Why it matters
You buy an EDR for three years, and the threat landscape changes every quarter. Whether the vendor invests in the techniques that matter to you, from identity-based intrusions to living-off-the-land and cloud pivots, decides whether the tool still detects the attacks of year three. A roadmap is also a signal of whether the vendor will still exist independently by then.
What to ask
Ask for the twelve-month roadmap under NDA and check it against the attack techniques in your own threat model, ask which of last year's roadmap items actually shipped, and ask how the vendor's research team publishes and how quickly new techniques turn into detections.
The trap
Roadmap slides are aspirations with dates. The useful evidence is the delivery record: what was promised eighteen months ago and what is in the product today. And a roadmap full of AI features says little about whether the Linux agent will ever get behavioural detection.
Pricing
Criterion 21
Pricing Model Alignment
Why it matters
EDR is licensed per endpoint, per user, per server, or in bundles that mix all three, and the same estate costs very different amounts under each model. Virtual desktops, shared shop-floor machines, servers that scale up and down and contractors with two devices each break the assumptions behind a per-endpoint or per-user price.
What to ask
Describe your estate honestly (endpoints, servers, virtual desktops, cloud instances, users with multiple devices) and ask the vendor to price it under each model they offer, then ask what counts as an endpoint when a virtual machine exists for an hour.
The trap
The model that wins the comparison sheet is the one whose counting unit is smallest in your estate today. Ask how the count is measured, how often it is trued up and what happens when your server fleet doubles for a migration weekend.
Criterion 23
Quoted License Price
Why it matters
At the end, the decision needs one number per vendor that can be compared: the quoted licence price for the configuration you will actually run, over the term you will actually sign. Every other criterion in this catalog feeds into how much that number is worth; this one makes sure it exists and that it is comparable.
What to ask
Ask each vendor for a binding written quote for the same scope: endpoint and server count, the modules and tiers identified in the criteria above, retention, support tier, onboarding, and the contract term, with the annual price and the three-year total stated separately.
The trap
Quotes that differ in scope cannot be compared, and vendors know it. One quote includes MDR, the next excludes retention, the third is per user. Normalise the scope before you compare the number, or the cheapest quote will be the one that left the most out.
Which obligation each criterion covers
The regulatory map of this catalog: the obligation, where it comes from, and the criteria that address it. Use it to show an auditor that the requirement list was built from the rules, not from a vendor deck.
| Obligation | Source | Covered by |
|---|---|---|
| Early warning within 24 hours, notification within 72 hours, final report within one month of a significant incident | NIS2 Art. 23 | |
| Incident handling as a risk-management measure, including detection and response capability | NIS2 Art. 21(2)(b) | |
| Supply chain security, including the security-related aspects of relationships with suppliers and service providers | NIS2 Art. 21(2)(d) | |
| Management bodies approve and oversee the risk-management measures and can be held liable | NIS2 Art. 20 | |
| Contractual provisions with ICT third-party providers, including service descriptions, data locations and access rights | DORA Art. 30 | |
| Management of ICT third-party risk, register of information and exit strategies | DORA Art. 28 | |
| Reporting of major ICT-related incidents to the competent authority | DORA Art. 19 | |
| Processor contract and lawful international transfers of personal data in endpoint telemetry | GDPR Art. 28 and Art. 44 ff. |
The question sheet
Every vendor question of this catalog in one list, in the order of the criteria. Put the same questions to every vendor in the same words and write the answers next to each other.
- Detection Accuracy (MITRE ATT&CK Coverage)
Ask for the vendor's results in the most recent MITRE ATT&CK Enterprise evaluation, specifically the detection coverage and the number of missed detections. Not the press release, the actual results.
- Mean Time to Detect (MTTD)
Ask for the measured median and worst-case time from initial execution to alert for the techniques in the latest MITRE evaluation, and whether the alert fires at initial access, at privilege escalation or only at impact. Ask a reference customer for the same number from a real incident.
- Mean Time to Respond (MTTR)
Ask for the time from alert to executed containment in the vendor's own measurements and in a reference customer's incident, and ask to isolate a host in the demo while the clock runs. Ask whether response actions work when the endpoint is off the corporate network.
- Automated Response / Remediation
Ask which containment actions the product can execute automatically, per platform, on which conditions, and how a wrong automatic isolation of a production server is reversed. Ask to trigger an isolation in the demo and to see the endpoint reconnect afterwards.
- False Positive Rate
Ask for a reference customer of similar size and industry, and ask that customer directly how many false positives they handle per week and how tuning worked in the first three months.
- OS & Platform Coverage (Windows, Linux, macOS)
Hand the vendor your real OS inventory, including versions and end-of-life systems, and ask for each line whether the agent is supported with the same detection and response features as on current Windows, with reduced features, or not at all.
- Deployment Complexity & Rollout Effort
Ask for the deployment plan for your real estate: agent packaging for your management tools, behaviour on machines without permanent connectivity, coexistence with the antivirus you remove, and the number of person-days a comparable customer needed to reach 95 percent coverage.
- Agent Performance Impact (CPU/RAM)
Ask for measured CPU and memory footprint under normal load, and run a pilot on real machines used by real people before you commit. Not on clean test machines.
- MDR / Managed Detection & Response Option
Ask what the guaranteed response time is for a critical alert at 3am on a Sunday, and whether that is contractually binding or a best-effort target.
- XDR / Extended Detection Capability
Ask which of your non-endpoint sources the platform ingests natively and correlates into a single incident, whether that correlation is vendor-maintained logic or a search you write, and to see one cross-domain incident from a live tenant, not a demo dataset.
- SIEM Integration & Log Forwarding
Ask for a list of native integrations with your specific stack, whether the full telemetry or only alerts can be forwarded, in what schema and at what cost, and whether they are maintained by the vendor or by you. Ask to see the integration working in the demo, not just listed on a slide.
- Threat Intelligence Feed Quality
Ask where the intelligence comes from, how fast a new campaign's indicators reach your tenant, whether sector- and region-specific intelligence (for example on groups targeting European critical infrastructure) is included, and whether you can add your own feeds and those of your CERT.
- Forensics & Investigation Capability
Do not ask "are you NIS2 compliant." Everyone says yes. Ask: how far back does the endpoint telemetry reach, how fast can I export a full forensic report of an incident with process tree, file and network activity, and in what format? Can I do it myself or do I depend on your support team?
- API & Automation Support (SOAR Integration)
Ask for the API documentation and check whether every action available in the console is also available through the API, what the rate limits are, whether there are vendor-maintained integrations for your SOAR or ticketing platform, and how API changes are announced and versioned.
- Cloud Workload & Container Coverage
Ask which cloud platforms, container runtimes and Kubernetes distributions are covered, how (agent, sidecar, agentless), whether container images and running containers are both in scope, and what a detection on a short-lived container looks like once the container is gone.
- Per-Endpoint Licensing (3-year TCO)
Ask for the full three-year cost including all modules you actually need, price increase caps at renewal, and what specifically is not included in the base price.
- SOC 2 / ISO 27001 / GDPR Compliance
Ask for the current SOC 2 Type II report and ISO 27001 certificate with scope, and then ask specifically: is there an EU-only processing region, is it the default or an upgrade, and can the vendor contractually guarantee that no telemetry leaves the EU, including for support and analysis?
- Vendor Support SLA & Incident Response
Ask for the contractual response and resolution times per severity in the tier you will buy, whether 24/7 support with a named escalation path is included, and what incident response services (retainer, hourly, included hours) the vendor offers and at what price.
- Vendor Lock-in & Data Portability
Ask how telemetry, incidents, exclusions and custom rules can be exported in an open format, whether historical data remains accessible after the contract ends, what the vendor offers to assist a migration out, and what the agent removal looks like at scale.
- Roadmap & Threat Landscape Alignment
Ask for the twelve-month roadmap under NDA and check it against the attack techniques in your own threat model, ask which of last year's roadmap items actually shipped, and ask how the vendor's research team publishes and how quickly new techniques turn into detections.
- Pricing Model Alignment
Describe your estate honestly (endpoints, servers, virtual desktops, cloud instances, users with multiple devices) and ask the vendor to price it under each model they offer, then ask what counts as an endpoint when a virtual machine exists for an hour.
- Price Predictability & Hidden Costs
Ask for a written list of everything that can generate a charge beyond the licence: retention tiers, export and API usage, additional modules, support tiers, onboarding services, and the maximum price increase at renewal. Ask a reference customer what their second-year invoice looked like against the first quote.
- Quoted License Price
Ask each vendor for a binding written quote for the same scope: endpoint and server count, the modules and tiers identified in the criteria above, retention, support tier, onboarding, and the contract term, with the annual price and the three-year total stated separately.
These criteria are the starting point. Not the decision.
A criteria list tells you what to look at. It does not weigh them against your specific situation, check them against your hard constraints, or produce the memo your board and auditor need. DecisionOS takes these criteria, weights them for your decision, and builds a defensible record. In days, not months.
Continue with the decision guide
Related criteria catalogs
- Security Information and Event ManagementSIEM selection: the criteria that matter under NIS2 and DORA23 criteria
- Managed Detection and ResponseMDR selection: the criteria that matter under NIS2 and DORA23 criteria
- Identity and Access ManagementIAM selection: the criteria that matter under NIS2 and DORA23 criteria
Print this catalog or save it as PDF for the meeting
