Sophos MDR and security services licensing covers the managed and professional services Sophos sells on top of its products. These are Sophos Managed Detection and Response (MDR) in two tiers, Managed Risk, and a range of advisory, incident response and testing services. The End User Terms of Use define a Security Service as a managed or associated service described in a published Service Description or in a Statement of Work.[4] The MDR Service Description is part of the customer’s agreement, and where they conflict, the Service Description prevails.[1] The Licensing Guidelines set the unit. MDR and MDR Plus are subscriptions per User and per Server, and each subscription includes one licence to Sophos XDR.[3]
Editions
The MDR Service Description offers two tiers.[1]
| Tier | Scope (Service Description) | SLA and warranty |
|---|---|---|
| Sophos MDR | Onboarding, health checks, triage, investigation, threat response in the chosen Threat Response Mode, and 24/7/365 monitoring and threat hunting[1] | Service level targets only, not an SLA[1] |
| Sophos MDR Plus | Everything in MDR, plus remote Incident Response on Monitored Endpoints running Sophos XDR, with an Incident Response Advisor[1] | Time to Respond SLA with service credits; Breach Protection Warranty[1] |
Other managed and advisory services in the Licensing Guidelines include Managed Risk (for MDR customers), Digital Forensics and Incident Response (one-time, per hour), several retainers (per tier), penetration testing and red team exercises (one-time, per tier), and Taegis MDR tiers (per User).[3] Sophos ITDR is an add-on for Sophos MDR and Sophos XDR.[5] Sophos does not publish MDR prices.
Metrics
MDR uses the same User and Server units as the product licences. One MDR subscription includes one Sophos XDR licence, so a customer does not buy XDR separately for the same User or Server.[3] Catalog: Each MDR subscription includes one Sophos XDR licence.
Inside the service, the Service Description counts Covered Endpoints. These are Monitored Endpoints running Sophos XDR or the XDR Sensor, plus Agentless Third-Party Endpoints that send telemetry to Sophos Fusion. The customer designates them, and they must stay properly configured and visible.[1] For Agentless Third-Party Endpoints, Response Actions are limited to host isolation and un-isolation.[1]
Advisory services use other units, recorded as Hour (Digital Forensics and Incident Response) and Tier (for example Security Services Retainer tiers 1 to 4, or Small, Medium and Large penetration tests).[3] The Sophos Incident Response Retainer includes a maximum device count that depends on the purchase.[3]
Counting / floors
Minimum deployment. Service Software must be deployed on at least 80% of licensed volume, so that Sophos has enough visibility to deliver the service.[1] The customer must also keep a valid Sophos Fusion account, configure integrations and run only supported versions. If the customer does not take required actions after written notice, that is a material breach of the Agreement, and Sophos may suspend delivery until they are done.[1] This is the reverse of the usual compliance question: an MDR customer that deploys too little is in breach, just as one that deploys too much is. Catalog: MDR requires Service Software on at least 80% of licensed volume.
Managed Risk limits. Managed Risk is licensed per User and per Server and is available only to MDR customers. Per customer it covers asset monitoring of 25 root domains and external vulnerability scanning of 1,000 IP addresses. Internal vulnerability scanning is capped at 120% of the customer’s Managed Risk entitlement.[3]
Next-Gen SIEM with MDR. Next-Gen SIEM is available to XDR or MDR customers, and its subscription count must equal the total number of XDR and MDR subscriptions.[3] Catalog: Next-Gen SIEM requires XDR or MDR and has a 1GB daily ingestion limit.
Service hours. Pre-purchased Security Service hours that are not used expire twelve months after purchase. Hours in a time-and-material SOW are estimates, and Sophos must get approval before exceeding them.[4] Catalog: Unused pre-purchased Security Service hours expire after 12 months.
Service levels
Targets (both tiers). Sophos targets 2 minutes from Detection ingestion to Case creation, and 30 minutes from Case creation to initial action. These are targets, not a service level agreement.[1]
MDR Plus SLA. Time to Respond must be within 60 minutes for 90% of Priority Investigations, measured monthly. Measurement starts 60 days after purchase for new customers, or at renewal for existing ones. Sophos misses the SLA if it fails the monthly commitment in more than three months of any rolling twelve-month period. The credit is the lesser of 5% of the fees paid for the previous billing cycle or USD 5,000. It is applied to the next subscription term and forfeited if the subscription lapses. Credits must be claimed within 30 days, no more than three times a calendar year.[1] For MSPs the SLA applies per Beneficiary, not to the MSP account as a whole.[1] Catalog: MDR Plus SLA credit capped at 5% of fees or USD 5,000.
Programs
MDR Plus Breach Protection Warranty. The warranty applies to customers with a current, fully paid-up MDR Plus subscription. If a ransomware Breach Incident on a Healthy Environment causes irretrievable data loss, Sophos pays up to the limits set in the warranty.[2] The terms are closely tied to licensing:
- Per-licence cap. Sophos pays no more than USD 1,000 for the lesser of each fully paid licence or each breached Managed Endpoint. The total is capped at USD 1,000,000 per Year, and ransom payments at USD 100,000 per claim. A claim needs at least USD 5,000 of demonstrable out-of-pocket expenses.[2]
- Over-deployment. If the customer deploys more endpoints than its licence entitlement, Sophos reserves the right to deny the claim.[2] Under-licensing therefore puts the warranty at risk, as well as creating an invoice under the End User Terms of Use.
- Coverage conditions. MDR Plus agents must be on all endpoints and servers. The Threat Response Mode must be Authorize or Collaborate with authorize. The subscription must be continuous and fully paid for at least 12 months, and incidents in the first 60 days are excluded.[2]
- Eligibility. The warranty does not apply to MSPs or their customers and cannot be transferred.[2]
Catalog: Breach Protection Warranty paid per licence, capped per year; Breach Protection Warranty excludes MSPs and the first 60 days.
Integrations. Sophos included all integrations with new and existing Sophos MDR and Sophos XDR subscriptions from 2025-11-01 for term licences and from late January 2026 for MSP Flex. At those dates it retired integration pack licences.[5] Catalog: Integration packs included with MDR and XDR; pack licences retired.
Contract terms
Threat Response Modes. The customer picks Authorize, Collaborate, Collaborate then Authorize, or Notify Only. The choice controls whether Sophos acts without asking first. Sophos warns that Notify Only can materially delay containment.[1] The mode chosen also affects warranty eligibility.[2]
Incident Response scope (MDR Plus). Incident Response is performed remotely and only for Incidents on Monitored Endpoints running Sophos XDR. Excluded items include court-admissible evidence, system restoration, disk forensics, ransomware negotiation and on-site services.[1]
Service changes. Sophos may modify the Service and the Service Description, provided the overall scope, and its own obligations, are not materially reduced. Updates take effect when posted.[1]
MSP delivery. An MSP must act as the contact for its Beneficiaries, obtain their consents and indemnify Sophos for claims caused by its own failures.[1] See Sophos MSP Flex and partner licensing.
Out of scope
- MDR and advisory service prices, which Sophos does not publish.
- The MDR Plus MSP Breach Protection Warranty, a separate document for MSPs.
- The Taegis MDR, VMS Platinum and advisory service descriptions, apart from their units in the Licensing Guidelines.
- Cyber insurance arrangements that reference Sophos services.