MDR BUYER'S CHECKLIST
How to Evaluate an MDR Provider
A practical checklist for mid-market companies choosing a managed detection & response provider, including the NIS2 supply-chain questions a Greek buyer needs to ask that most generic vendor checklists skip.
How to Evaluate an MDR Provider
A practical checklist for mid-market companies choosing a managed detection & response provider, including the NIS2 supply-chain questions a Greek buyer needs to ask that most generic vendor checklists skip.
Every MDR vendor's homepage says "24/7 monitoring" and "15-minute response." The questions below are the ones that actually separate a real security operation from a marketing page.
1. Detection & response capability
- Is monitoring genuinely 24/7/365 with staffed analysts, or "business hours plus an on-call pager"?
- Ask for real MTTD/MTTR numbers from their last quarter, not a marketing range.
- Do they hunt for threats proactively, or only triage the alerts your existing tools already generate?
- Are they vendor-agnostic, working with the EDR/SIEM/cloud stack you already have, or do they require a rip-and-replace onto their own tooling?
2. Team & staffing transparency
- Who's actually on shift: dedicated analysts, or a shared queue spread across dozens of other clients?
- What's the analyst-to-client ratio? A vague answer here is itself an answer.
- During an active incident, is there a direct line to a senior analyst, or do you file a ticket and wait?
- Can they support you in your own language and time zone for incident calls, not just email in a support portal?
3. Contract terms & SLAs
- Are detection and response times written into the SLA with real penalties, or only stated as marketing targets?
- If you leave, do you keep your logs, detection rules, and incident history, or does the provider keep them?
- Which sub-processors (cloud infrastructure, SIEM vendor, ticketing system) touch your data, and are they disclosed?
4. Compliance & supply-chain fit
- If you're in scope for NIS2, Article 21 makes the security of your suppliers your obligation, not just theirs. Will the provider hand you documentation an auditor will actually accept?
- Will they help you hit the Article 23 reporting deadlines (24 hours / 72 hours / one month), or is that entirely on you?
- Is the provider itself ISO 27001 or SOC 2 certified, and will they show you the certificate, not just claim it?
5. Cost structure & scaling
- Is pricing per-endpoint, flat-fee, or tiered, and what happens to the bill when you add 50 endpoints mid-contract?
- Is incident response included, or billed separately as a retainer you only discover you need after something's already gone wrong?
6. References & proof
- Can they show you a real, redacted incident report, not a case-study slide?
- Will they give you a client reference you can actually call, ideally in your sector or region?
This checklist reflects criteria we'd want answered as a buyer, plus the NIS2 Article 21 and Article 23 supply-chain obligations that apply if you're an in-scope Greek entity. General guidance, not legal advice.
Comparing us against this checklist?
Ask us every question above. We'll answer directly, including the ones other vendors dodge.
