Register of Vendor Pricing · Compiled by Digital Signet · Revised 20 June 2026
Annex X · Glossary

MDR procurement glossary.

Single source of truth for the acronyms that appear on MDR quotes. Definitions match the procurement vocabulary, not the marketing vocabulary.

Direct answer

MDR = outsourced 24x7 monitoring with validated alerts. MSSP = the legacy alert-forwarding category MDR replaced. SOCaaS = synonym for fully-outsourced MDR. XDR = the detection platform; not a service. SOAR = the automation layer. SIEM = the log platform. EDR = the endpoint agent.

MDR
Managed Detection and Response. Outsourced 24x7 security monitoring with analyst-validated alerts and (at higher tiers) active response on the customer's environment.
MSSP
Managed Security Service Provider. Legacy category that predates MDR; most MSSPs delivered alert forwarding rather than validated response. The MDR category emerged to mark the difference.
SOCaaS
SOC as a Service. Synonym for fully-outsourced MDR; emphasises the SOC-function-replacement framing over the detect-and-respond framing.
XDR
Extended Detection and Response. Platform category that bundles EDR with cloud, identity, network, and email signal sources into one detection layer.
SOAR
Security Orchestration, Automation and Response. The playbook-and-automation layer that converts an alert into a series of actions; sits between SIEM and the response tools.
TIP
Threat Intelligence Platform. Aggregates indicators of compromise and threat actor profiles; feeds detection content into SIEM and EDR.
SIEM
Security Information and Event Management. The log-collection and detection-rule platform that MDR vendors monitor on the customer's behalf; in BYO-SIEM the customer owns the licence.
EDR
Endpoint Detection and Response. The agent on the device that produces the telemetry MDR analysts triage.
CST
Concierge Security Team. Arctic Wolf's marketing term for the named-analyst delivery model. Other vendors use 'pod' or 'dedicated team' for similar constructs.
Pod
A named, persistent group of analysts assigned to a single customer or small set of customers. The opposite of the random-analyst MDR delivery shape.
Log source
A device, application, cloud account, or SaaS that produces logs the SOC monitors. Per-log-source pricing meters on this unit.
EPS
Events Per Second. The unit a SIEM (and some MDR contracts) uses to size ingest capacity; converts roughly to GB/day depending on event size.
MTTD
Mean Time To Detect. The SLA target for how quickly the SOC identifies a suspicious event after it occurs.
MTTA
Mean Time To Acknowledge. The SLA target for how quickly an analyst opens an alert after the SIEM creates it.
MTTR
Mean Time To Respond (or Resolve). The SLA target for how quickly the SOC contains or resolves a confirmed incident.
BYO-SIEM
Bring Your Own SIEM. MDR delivery where the vendor monitors the customer's existing SIEM rather than ingesting into the vendor's proprietary data lake.
Active response
Authority delegated to the vendor to take action on the customer's environment without per-incident approval (isolation, account disable, malicious process termination).
Breach warranty
A vendor commitment to pay out a capped sum if a breach occurs while the customer is fully covered by the vendor's product. Examples: Sophos ($1M), CrowdStrike Falcon Complete ($1M).
Definitions are aligned to NIST CSRC where applicable; vendor-specific terms (CST, pod) are sourced to the vendor's own pricing or product page.

Annex cross-references

AnnexPricing modelsGlossary terms applied to the metering question.AnnexBYO-SIEMGlossary terms applied to the SIEM question.AnnexSLA matrixMTTD / MTTA / MTTR commitments by vendor.