Criteria catalog · Managed Detection and Response
MDR selection: the criteria that matter under NIS2 and DORA
Most MDR evaluations compare dashboards and a price per endpoint. What decides the choice is what the provider is contractually obliged to do in the first hour of an incident, who looks at your data while doing it, and whether the contract survives a DORA or NIS2 audit.
Independent criteria reference · 23 criteria · Last updated August 2026 · Not sponsored by any vendor
An MDR contract hands the most time-critical part of your security to a third party. Under NIS2 you remain responsible for the 24-hour early warning. Under DORA the provider is an ICT third party, often supporting a critical or important function, which pulls it into the contract minimums of Articles 28 to 30. The criteria below are the ones DecisionOS puts on the scoring sheet for a managed security case, in the same order and grouping, so that what you check here is what you score there.
Service Capabilities
Criterion 01
24/7 SOC Coverage & Analyst Depth (dedicated vs. shared, tier structure)
Why it matters
You buy MDR so that somebody competent watches at 3am on a Sunday. Whether that somebody is a dedicated analyst who knows your environment or a shared tier-one queue working from a runbook, and whether a tier-three engineer exists on the night shift at all, decides what happens in the first hour of a real incident. The SOC's staffing is the product.
What to ask
Ask for the number of analysts per shift and per tier, the analyst-to-customer ratio, whether your tenant has named analysts who know your environment, where the tier-three and incident response capability sits at night and on weekends, and for the shift roster of a typical week.
The trap
"24/7 SOC" often means a portal that accepts alerts around the clock and a tier-one team that escalates to an on-call engineer in the morning. Ask who exactly was working at 3am last Sunday and what they were authorised to do.
Criterion 02
MTTD / MTTR SLA Contractual Commitment & Historical Performance
Why it matters
MDR is sold on speed, but "minutes to respond" on a website is not a commitment. What matters is three separate clocks in the contract: time to detect, time until a human has triaged and classified the alert, and time until containment has started. Each of those clocks needs a number, a severity level it applies to, and a consequence if it is missed, and the provider's historical performance tells you whether the number is real.
What to ask
Ask for the contract clause that defines time to detect, time to triage and time to contain for a critical incident, with the measurement start point, the guaranteed value and the service credit or termination right if it is missed. Then ask for the last twelve months of actual measured values for existing customers.
The trap
"Mean time to respond under 15 minutes" is an average across all alerts, mostly low-severity ones that are closed automatically. The number you care about is the worst case for a critical alert at night, and a mean tells you nothing about it. If the contract only contains averages or targets, it contains nothing.
Criterion 03
Proactive Threat Hunting Frequency & Methodology
Why it matters
Real threat hunting is a human forming a hypothesis about your environment and searching for it in the data. Many services rebrand automated alert triage as hunting. The difference matters because the attacks that hurt are the ones the rules did not fire on, and only hunting finds those.
What to ask
Ask how many hunting hours per month are assigned to your tenant, who performs them, and for the last three written hunt reports delivered to a comparable customer, including the hypotheses tested and what was found.
The trap
"Continuous threat hunting powered by AI" is usually a detection engine with a new label. A provider who cannot show you a hunt report with a hypothesis, a query and an outcome does not hunt. They forward alerts, which is fine, as long as you are not paying hunting prices for it.
Criterion 04
Co-Managed Model Flexibility & Customer Visibility (portal transparency)
Why it matters
Your own team does not disappear when you buy MDR; it has to work with the provider's analysts, see what they see and take over parts of the work when it makes sense. A provider whose portal shows a list of closed tickets and nothing else turns your team into a recipient of conclusions, and under NIS2 the management body still has to oversee a measure it cannot look into.
What to ask
Ask whether your analysts can see the raw telemetry, the detection rules and the analyst's notes on every case in the same console the provider uses, whether you can run your own queries and hunts on your data, and how the split of responsibilities can be changed during the contract as your team grows.
The trap
"Full transparency portal" often means a dashboard of counts and a ticket list, while the actual data and the rules stay in the provider's internal tooling. Ask to log in to a real customer's portal, redacted, and try to reconstruct one incident from what you can see.
Criterion 05
Integrated IR Capability (retainer included vs. additional cost)
Why it matters
The R in MDR ranges from "we send you an alert with a recommendation" to "we isolate the host, disable the account and block the hash without waiting for you", and beyond containment lies incident response proper: forensics, eradication, recovery support and the written report your regulator wants. Whether that is included, in a retainer with pre-paid hours, or billed at emergency rates when you need it most, decides the real cost of your worst day.
What to ask
Ask for the list of containment actions the provider is authorised to execute on your systems without a prior call, the ones that need your approval, and how that approval is obtained at 3am. Then ask what incident response beyond containment is included, how many hours, at what rate beyond those, and how fast an IR engineer is on site or online.
The trap
"Guided response" and "response recommendations" mean the provider does not act. And "integrated IR" can mean an emergency hotline that connects you to a partner at a four-figure daily rate. Ask for the pre-authorisation matrix and the IR rate card from a live customer, not a template.
Technology Stack & Coverage
Criterion 06
Technology Agnosticism vs. Proprietary Stack Lock-in Risk
Why it matters
Some MDR providers monitor whatever EDR, SIEM and cloud you already run. Others only deliver their full service on their own stack and treat everything else as a log feed. The second model can mean replacing tools you bought two years ago, and it ties the exit from the service to the exit from the tooling, which doubles the switching cost DORA asks you to plan for.
What to ask
List your current EDR, SIEM, identity provider and cloud platforms and ask for each one whether the provider delivers detection, response actions and the full SLA on it, or whether the SLA applies only to the provider's own agent. Ask what happens to the service if you replace one of those tools during the contract.
The trap
"We support all leading EDR platforms" often means the alerts are forwarded, while hunting, containment and the response SLA exist only for the provider's own agent. Read the SLA scope clause, not the integration page.
Criterion 07
EDR / SIEM Coverage & Existing Tool Integration Quality
Why it matters
Most MDR services grew out of an EDR product and see the world through the endpoint agent. Modern intrusions start with a stolen identity, a misconfigured cloud role or a VPN appliance, none of which run an agent. Whether the provider ingests your existing EDR and SIEM at full depth, writes detections for those sources and has analysts who actually look at them decides whether the attack is seen early or after the attacker has what they came for.
What to ask
Ask which of your actual sources are ingested and monitored by analysts, not just collected: your EDR, your SIEM, identity provider logs, email, network and firewall, SaaS audit logs. For each one, ask whether detection rules exist, who maintains them, and how the integration was built and is kept working.
The trap
"Integrates with over 200 sources" means connectors exist. It does not mean anyone writes detections for them or that an analyst looks at them. Ask for the detection rule count per source on your tenant after onboarding, and compare it with the endpoint rule count.
Criterion 08
Cloud-Native & Multi-Cloud Coverage (AWS, Azure, GCP)
Why it matters
A growing share of what an attacker wants sits in the cloud control plane: identity roles, storage buckets, serverless functions and the audit trails that record who touched them. An MDR that watches endpoints and forwards cloud logs unread misses the misconfigured role that exposed a database, and it misses it across every cloud you run, not only the one the provider's own product supports.
What to ask
Ask which cloud platforms are monitored by analysts with cloud-specific detections, whether cloud control plane, identity and workload signals are correlated with endpoint activity in one incident, how a cloud incident is contained (role revocation, key rotation, instance isolation) and by whom, and what the coverage looks like for the second and third cloud you run.
The trap
"Multi-cloud coverage" frequently means the provider's cloud security product is available for one cloud and the others are log sources. Ask for the detection rule count and the containment actions per cloud, and for a cloud incident report from a live customer.
Criterion 09
OT / IoT Coverage Option (industrial environments)
Why it matters
If you run production plants, the attack that stops the business goes through the OT network, and an analyst trained on Windows process trees does not know what a suspicious Modbus write looks like. OT monitoring is passive, protocol-aware and cannot isolate a PLC the way it isolates a laptop, so the provider's OT option has to be a different service with different people, not the same SOC with another log source.
What to ask
Ask whether OT and IoT monitoring is a real service line with dedicated analysts who have industrial experience, which OT protocols and sensors are supported, how an OT incident is contained without stopping production, and for a reference customer with plants of your kind.
The trap
"OT visibility" often means the provider ingests alerts from an OT monitoring product you have to buy and operate yourself, and escalates them to you. If the night-shift analyst has never seen a plant, the OT option is a log forwarder with a premium price.
Criterion 10
Geographic SOC Location & Data Residency (EU-only SOC option)
Why it matters
An MDR analyst looks at process trees, usernames, file names and sometimes file contents from your systems. Where that analyst sits matters under GDPR and, for regulated workloads, under NIS2 and DORA. A follow-the-sun model means your night shift is handled from another continent, and that is access to personal data from outside the EU, regardless of where the data is stored.
What to ask
Ask where the analysts who will handle your alerts are physically located, per shift, and whether the contract guarantees EU-only analyst access. Ask what happens to that guarantee during an escalation or a major incident when extra staff is pulled in, and where the data lake and the backups sit.
The trap
"Data stored in the EU" is answered about the data lake, not about the people. Residency of storage is not residency of access. A SOC with an EU data centre and analysts logging in from three continents has solved the storage question and not the one you asked.
Operations & Governance
Criterion 11
SOC Maturity Level (SOC-CMM / CMMI certification or equivalent)
Why it matters
A SOC is a process organisation, and its maturity shows in whether procedures are documented, measured and improved or whether everything depends on the two senior analysts who might leave. SOC-CMM, a CMMI-style assessment or an equivalent independent review is the closest thing to evidence that the SOC will perform the same way in month eighteen as in the sales demo.
What to ask
Ask for the most recent independent maturity assessment of the SOC with its scope and findings, how detection engineering, incident handling and quality review are documented and measured, what the analyst turnover was in the last year, and how a new analyst is trained before they touch a customer tenant.
The trap
"Certified SOC" frequently refers to the ISO 27001 certificate of the company, which says nothing about how the SOC handles an incident. And a maturity assessment from three years ago describes a different team. Ask for the date, the scope and the improvement actions since.
Criterion 12
Escalation Process Quality & Communication SLA
Why it matters
In a real incident the question is not whether the provider detects, it is who calls whom, how fast, on which number, and what happens when the first contact does not answer. NIS2 gives you 24 hours from awareness for an early warning, and the provider is the one who becomes aware first. The escalation path and the communication SLA are where that clock is won or lost.
What to ask
Ask for the escalation matrix with names, roles, channels and time limits per severity, how the provider reaches you when your email and phone system are part of the incident, what the communication SLA guarantees (first contact, status updates, written summary) and for the record of the last major incident's communication timeline.
The trap
"Dedicated customer success manager" is a daytime role. Ask who calls you at 3am when the provider's tier-two decides the alert is critical, on which out-of-band channel, and what the contract says if that call is late.
Criterion 13
Threat Intelligence Sharing & Community Participation (ISACs)
Why it matters
A provider that shares indicators with its sector's ISAC, the national CERT and its peers sees campaigns against organisations like yours before they reach you, and it feeds what it learns from your incidents back into the community. A provider that only consumes commercial feeds knows what everyone knows, a day later.
What to ask
Ask which ISACs, CERTs and sharing communities the provider participates in actively, what it contributed in the last year, how fast an indicator from a peer incident becomes a detection on your tenant, and whether you can bring your own sector's feeds into the service.
The trap
"Global threat intelligence" describes the provider's own telemetry base, which is dominated by its largest markets. Membership logos on a slide say nothing about active participation. Ask for a recent example of a European campaign the provider detected through community sharing before public reporting.
Criterion 14
QBR Quality & Strategic Advisory Capability
Why it matters
Under NIS2 the management body is responsible for the cyber risk measures and must be able to oversee them; under DORA the management body is accountable for ICT third-party risk. Both need reporting they can read, and both benefit from a provider who tells them what to fix next. The quarterly review is where an MDR contract turns from a monitoring service into a security programme, or stays a page of alert counts.
What to ask
Ask for a real monthly report and a real quarterly management report from an existing customer, redacted. Check whether they show SLA attainment per severity, open findings, tuning changes, analyst coverage and a prioritised list of improvements, or whether they are alert counts and a threat landscape slide. Ask who presents the QBR and what their background is.
The trap
Pretty dashboards with large numbers of "threats blocked" satisfy nobody who has to sign something. A report that cannot show missed SLAs cannot show met ones either. If the provider's report never contains bad news or a recommendation that costs the provider revenue, it is a marketing document.
Criterion 15
Onboarding Duration & Integration Complexity
Why it matters
An MDR service is not live when the contract is signed. It is live when the agents are deployed, the log sources are connected, the asset inventory is known to the analysts and the false positives from your environment have been tuned out. That period is typically weeks to months, and during it the service is partly blind while you already pay.
What to ask
Ask for the onboarding plan with milestones, the effort expected from your side in person-days, the point at which the full response SLA becomes effective, and what the tuning period cost on the last three comparable onboardings.
The trap
"Up and running in days" refers to the agent rollout. Detection quality and response commitments come later, and some contracts quietly exclude the first ninety days from the SLA. Look for that exclusion and decide whether you want to pay full price for it.
Economics & Compliance
Criterion 16
Total Cost vs. In-House SOC Build (3-year like-for-like comparison)
Why it matters
The honest comparison is not MDR against nothing, it is MDR against the SOC you would otherwise have to build: analysts in shifts, tooling, training, turnover, and the management attention it takes. Both numbers have to be built on the same scope over the same three years, otherwise the cheaper option is simply the one that left more out.
What to ask
Build the three-year cost of an in-house SOC at the coverage the MDR promises (shift roster, salaries, tooling, training, recruiting) and ask the provider for the three-year total for the same coverage, including onboarding, IR hours, log volume growth and price adjustment at renewal. Compare the two numbers, not the per-endpoint price.
The trap
The MDR quote assumes today's endpoint count and the in-house estimate assumes no turnover. Neither is true. The like-for-like comparison is the one where both sides carry the same growth, the same coverage hours and the same incident load.
Criterion 17
GDPR / Data Residency & DPA for Managed Access to Security Telemetry
Why it matters
The provider's analysts access personal data in your telemetry every day, which makes the provider a processor under GDPR and the contract a data processing agreement with a list of sub-processors, locations and safeguards for any access from outside the EU. For a financial entity the same facts go into the DORA register of information. If the DPA is a generic annex, the residency you negotiated is not in it.
What to ask
Ask for the data processing agreement and the sub-processor list with locations, check whether it names EU-only analyst access and the transfer mechanism for any exception, ask what data the provider retains after contract end and for how long, and ask how a data subject request that touches your telemetry would be handled.
The trap
A DPA that says "data may be processed in countries with adequate protection" plus a sub-processor list that ends with "and affiliates" tells you nothing about who sees your data. Ask for the named entities, the named countries and the clause that makes the EU-only promise contractual.
Criterion 18
Vendor Lock-in & Exit Terms (runbook IP, data retrieval, transition support)
Why it matters
When the contract ends, you need your telemetry, your incident history, your detection rules and your tuning decisions, otherwise the next provider starts from zero and the audit trail of three years of incidents disappears. Under DORA an exit strategy for critical functions is mandatory; under NIS2 it is simply prudent.
What to ask
Ask which data is returned at exit, in what format, within what period and at what cost, whether the custom detection rules and runbooks written for you are your property, and for the transition assistance clause and how long the provider keeps operating during a handover.
The trap
"Full data export available" often means raw logs in a proprietary format, without the case notes, the analyst decisions or the rules. And the export itself can carry a fee that is invisible until you need it. Price the exit before you sign, when you still have leverage.
Criterion 19
Vendor Track Record & Reference Customers (relevant sector)
Why it matters
An MDR provider is judged by the incidents it has handled, and a provider that has never worked a ransomware case in a hospital, a bank or a plant of your kind will learn on yours. References from your sector, with incidents behind them, are the only evidence that the runbooks fit your reality and that the provider survives an audit by your supervisor.
What to ask
Ask for three reference customers in your sector and size, and ask them about the last real incident: how fast the provider detected, what it did, how the communication went and what the post-incident report looked like. Ask the provider how many customers left in the last two years and why.
The trap
Reference customers are chosen by the provider, and logos on a slide are not references. The useful question to a reference is not "are you satisfied" but "tell me about the last time it went wrong". A reference with no such story has not had an incident yet.
Criterion 20
Cyber Insurance Alignment & Compliance Certification (ISO 27001, SOC2)
Why it matters
Your cyber insurer increasingly asks which MDR you run and what it guarantees, and some policies discount or require specific capabilities such as 24/7 monitoring and contractual response times. The provider's own certifications (ISO 27001, SOC 2) are what your supplier file and your insurer's questionnaire ask for, and a gap in either costs money at renewal or, worse, at claim time.
What to ask
Ask which of your insurer's questionnaire items the provider can evidence in writing, whether the provider has worked with insurers' panel IR firms during a claim, and for the current ISO 27001 certificate and SOC 2 Type II report with scope covering the SOC service itself, not only the corporate IT.
The trap
"ISO 27001 certified" for the company, with a scope that excludes the SOC platform, and an insurance questionnaire answered with "yes" where the contract says "best effort". Match the provider's written commitments to the policy's warranties before the incident, not during the claim.
Pricing
Criterion 21
Pricing Model Alignment (per endpoint vs. per user vs. flat monthly)
Why it matters
Per-endpoint pricing is easy to compare and quietly excludes identity, cloud and network coverage, which are billed as add-ons or by ingested gigabyte. Per-user pricing looks fair until service accounts and contractors are counted. A flat monthly fee looks safe until you learn what scope the flat rate assumes. Each model rewards a different behaviour, and the wrong one turns every new log source into a budget negotiation.
What to ask
Ask for the three-year total for the coverage you actually need under each model the provider offers, including all log sources, retention, incident response hours beyond a cap, onboarding, and price adjustment at renewal. Ask what happens to the price if you double your cloud log volume or add a subsidiary.
The trap
The per-endpoint number wins the comparison sheet, and the gigabyte-based add-ons win the invoice. Ask the provider to sign the total, not the unit price. A provider who cannot state a total for a defined scope has told you the scope is not defined.
Criterion 22
Price Predictability & Alert Volume / IR Escalation Overage Terms
Why it matters
The quote assumes a normal month. The invoice that hurts comes after the abnormal one: an alert storm from a misconfigured source that counts against a volume cap, an incident that consumed forty IR hours beyond the included ten, an escalation to the provider's forensics team at emergency rates. Predictability is what the contract says about those months.
What to ask
Ask for the alert volume and log volume caps and the overage rates, the included incident response hours and the rate beyond them, whether emergency escalation to forensics is priced in advance, and for the largest single overage invoice a customer received in the last year and what caused it.
The trap
"Unlimited alerts" with a fair use clause the provider interprets, and "IR included" with ten hours that a real incident exhausts on day one. The predictable price is the one where the bad month has a number attached before it happens.
Criterion 23
Quoted Annual Service Price
Why it matters
At the end, the decision needs one number per provider that can be compared: the quoted annual service price for the coverage you will actually buy, over the term you will actually sign. Every other criterion in this catalog feeds into how much that number is worth; this one makes sure it exists and that it is comparable.
What to ask
Ask each provider for a binding written quote for the same scope: endpoint and user counts, the log sources and clouds identified in the criteria above, the response model and SLA tier, included IR hours, onboarding, and the contract term, with the annual price and the three-year total stated separately.
The trap
Quotes that differ in scope cannot be compared, and providers know it. One quote includes IR, the next excludes cloud sources, the third assumes half your endpoints. Normalise the scope before you compare the number, or the cheapest quote will be the one that left the most out.
Which obligation each criterion covers
The regulatory map of this catalog: the obligation, where it comes from, and the criteria that address it. Use it to show an auditor that the requirement list was built from the rules, not from a vendor deck.
| Obligation | Source | Covered by |
|---|---|---|
| Incident handling and early warning within 24 hours, notification within 72 hours, final report within one month | NIS2 Art. 23 | |
| Incident handling as a risk-management measure | NIS2 Art. 21(2)(b) |
|
| Supply chain security, including the security aspects of relationships with direct suppliers and service providers | NIS2 Art. 21(2)(d) | |
| Management body approves and oversees cybersecurity risk-management measures | NIS2 Art. 20 | |
| Contractual provisions with ICT third-party service providers, extended set for critical or important functions | DORA Art. 30 |
|
| ICT third-party risk: register of information, subcontracting chain, concentration risk, exit strategies | DORA Art. 28 | |
| Major ICT-related incident reporting | DORA Art. 19 | |
| Processor contract, security of processing and international transfers when analysts access personal data from outside the EU | GDPR Art. 28, Art. 32, Art. 44 ff. |
The question sheet
Every vendor question of this catalog in one list, in the order of the criteria. Put the same questions to every vendor in the same words and write the answers next to each other.
- 24/7 SOC Coverage & Analyst Depth (dedicated vs. shared, tier structure)
Ask for the number of analysts per shift and per tier, the analyst-to-customer ratio, whether your tenant has named analysts who know your environment, where the tier-three and incident response capability sits at night and on weekends, and for the shift roster of a typical week.
- MTTD / MTTR SLA Contractual Commitment & Historical Performance
Ask for the contract clause that defines time to detect, time to triage and time to contain for a critical incident, with the measurement start point, the guaranteed value and the service credit or termination right if it is missed. Then ask for the last twelve months of actual measured values for existing customers.
- Proactive Threat Hunting Frequency & Methodology
Ask how many hunting hours per month are assigned to your tenant, who performs them, and for the last three written hunt reports delivered to a comparable customer, including the hypotheses tested and what was found.
- Co-Managed Model Flexibility & Customer Visibility (portal transparency)
Ask whether your analysts can see the raw telemetry, the detection rules and the analyst's notes on every case in the same console the provider uses, whether you can run your own queries and hunts on your data, and how the split of responsibilities can be changed during the contract as your team grows.
- Integrated IR Capability (retainer included vs. additional cost)
Ask for the list of containment actions the provider is authorised to execute on your systems without a prior call, the ones that need your approval, and how that approval is obtained at 3am. Then ask what incident response beyond containment is included, how many hours, at what rate beyond those, and how fast an IR engineer is on site or online.
- Technology Agnosticism vs. Proprietary Stack Lock-in Risk
List your current EDR, SIEM, identity provider and cloud platforms and ask for each one whether the provider delivers detection, response actions and the full SLA on it, or whether the SLA applies only to the provider's own agent. Ask what happens to the service if you replace one of those tools during the contract.
- EDR / SIEM Coverage & Existing Tool Integration Quality
Ask which of your actual sources are ingested and monitored by analysts, not just collected: your EDR, your SIEM, identity provider logs, email, network and firewall, SaaS audit logs. For each one, ask whether detection rules exist, who maintains them, and how the integration was built and is kept working.
- Cloud-Native & Multi-Cloud Coverage (AWS, Azure, GCP)
Ask which cloud platforms are monitored by analysts with cloud-specific detections, whether cloud control plane, identity and workload signals are correlated with endpoint activity in one incident, how a cloud incident is contained (role revocation, key rotation, instance isolation) and by whom, and what the coverage looks like for the second and third cloud you run.
- OT / IoT Coverage Option (industrial environments)
Ask whether OT and IoT monitoring is a real service line with dedicated analysts who have industrial experience, which OT protocols and sensors are supported, how an OT incident is contained without stopping production, and for a reference customer with plants of your kind.
- Geographic SOC Location & Data Residency (EU-only SOC option)
Ask where the analysts who will handle your alerts are physically located, per shift, and whether the contract guarantees EU-only analyst access. Ask what happens to that guarantee during an escalation or a major incident when extra staff is pulled in, and where the data lake and the backups sit.
- SOC Maturity Level (SOC-CMM / CMMI certification or equivalent)
Ask for the most recent independent maturity assessment of the SOC with its scope and findings, how detection engineering, incident handling and quality review are documented and measured, what the analyst turnover was in the last year, and how a new analyst is trained before they touch a customer tenant.
- Escalation Process Quality & Communication SLA
Ask for the escalation matrix with names, roles, channels and time limits per severity, how the provider reaches you when your email and phone system are part of the incident, what the communication SLA guarantees (first contact, status updates, written summary) and for the record of the last major incident's communication timeline.
- Threat Intelligence Sharing & Community Participation (ISACs)
Ask which ISACs, CERTs and sharing communities the provider participates in actively, what it contributed in the last year, how fast an indicator from a peer incident becomes a detection on your tenant, and whether you can bring your own sector's feeds into the service.
- QBR Quality & Strategic Advisory Capability
Ask for a real monthly report and a real quarterly management report from an existing customer, redacted. Check whether they show SLA attainment per severity, open findings, tuning changes, analyst coverage and a prioritised list of improvements, or whether they are alert counts and a threat landscape slide. Ask who presents the QBR and what their background is.
- Onboarding Duration & Integration Complexity
Ask for the onboarding plan with milestones, the effort expected from your side in person-days, the point at which the full response SLA becomes effective, and what the tuning period cost on the last three comparable onboardings.
- Total Cost vs. In-House SOC Build (3-year like-for-like comparison)
Build the three-year cost of an in-house SOC at the coverage the MDR promises (shift roster, salaries, tooling, training, recruiting) and ask the provider for the three-year total for the same coverage, including onboarding, IR hours, log volume growth and price adjustment at renewal. Compare the two numbers, not the per-endpoint price.
- GDPR / Data Residency & DPA for Managed Access to Security Telemetry
Ask for the data processing agreement and the sub-processor list with locations, check whether it names EU-only analyst access and the transfer mechanism for any exception, ask what data the provider retains after contract end and for how long, and ask how a data subject request that touches your telemetry would be handled.
- Vendor Lock-in & Exit Terms (runbook IP, data retrieval, transition support)
Ask which data is returned at exit, in what format, within what period and at what cost, whether the custom detection rules and runbooks written for you are your property, and for the transition assistance clause and how long the provider keeps operating during a handover.
- Vendor Track Record & Reference Customers (relevant sector)
Ask for three reference customers in your sector and size, and ask them about the last real incident: how fast the provider detected, what it did, how the communication went and what the post-incident report looked like. Ask the provider how many customers left in the last two years and why.
- Cyber Insurance Alignment & Compliance Certification (ISO 27001, SOC2)
Ask which of your insurer's questionnaire items the provider can evidence in writing, whether the provider has worked with insurers' panel IR firms during a claim, and for the current ISO 27001 certificate and SOC 2 Type II report with scope covering the SOC service itself, not only the corporate IT.
- Pricing Model Alignment (per endpoint vs. per user vs. flat monthly)
Ask for the three-year total for the coverage you actually need under each model the provider offers, including all log sources, retention, incident response hours beyond a cap, onboarding, and price adjustment at renewal. Ask what happens to the price if you double your cloud log volume or add a subsidiary.
- Price Predictability & Alert Volume / IR Escalation Overage Terms
Ask for the alert volume and log volume caps and the overage rates, the included incident response hours and the rate beyond them, whether emergency escalation to forensics is priced in advance, and for the largest single overage invoice a customer received in the last year and what caused it.
- Quoted Annual Service Price
Ask each provider for a binding written quote for the same scope: endpoint and user counts, the log sources and clouds identified in the criteria above, the response model and SLA tier, included IR hours, onboarding, and the contract term, with the annual price and the three-year total stated separately.
These criteria are the starting point. Not the decision.
A criteria list tells you what to look at. It does not weigh them against your specific situation, check them against your hard constraints, or produce the memo your board and auditor need. DecisionOS takes these criteria, weights them for your decision, and builds a defensible record. In days, not months.
Continue with the decision guide
Related criteria catalogs
- Endpoint Detection and ResponseEDR selection: the criteria that matter under NIS2 and DORA23 criteria
- Security Information and Event ManagementSIEM selection: the criteria that matter under NIS2 and DORA23 criteria
- Backup and Disaster RecoveryBackup and DR selection: the criteria that matter under NIS2 and DORA23 criteria
Print this catalog or save it as PDF for the meeting
