MDR Providers UK: The 2026 Market Compared Honestly
Who actually provides managed detection and response in the UK, what their NCSC and CREST standing really is, the only public price points that exist, and an honest answer on when a mid-sized business needs an MSSP rather than an enterprise MDR contract.
UK MDR market reality
Quick answer
There is no single best UK MDR provider - the market splits by who you are. Bridewell and NCC Group serve large regulated and enterprise estates (NCC holds NCSC Cyber Incident Response assurance at both Standard and Enhanced levels), Sophos MDR runs at global midmarket scale, Quorum Cyber and Six Degrees sit Microsoft-centric across public and private sector, and Socura runs Wales's national CymruSOC. Almost none publish pricing. For a 10-500-person business, a fixed-price MSSP with a 24/7 SOC - AMVIA's Enterprise plan is £60/user/month, published - is often the better-shaped contract than enterprise MDR.
Written by Nathan Hill-Haimes, Co-Founder, AMVIA
Bridewell vs NCC Group vs Sophos MDR: At a Glance
| Feature | BridewellUK regulated sectors | NCC GroupGlobal enterprise, LSE-listed | Sophos MDRMidmarket scale |
|---|---|---|---|
| SOC model | Own UK SOC (Reading HQ); CREST-accredited incl. SOC | Global SOC network; European MDR via Fox-IT (Delft); CREST SOC accredited | Six global SOCs; UK SOC location not published |
| NCSC standing | Listed for five NCSC schemes incl. Cyber Incident Response | CIR assured at BOTH Standard and Enhanced levels | CIR certified |
| Typical customer | Aviation, energy, finance, government - large regulated estates | Global enterprise; 1,800+ staff; FTSE 250 | 39,000+ organisations (vendor figure); IDC midmarket MDR Leader 2026 |
| Technology stance | Microsoft Defender XDR + Sentinel | Managed XDR for Microsoft and Splunk | Own stack or third-party tooling |
| Published pricing | None | None (agreed per client) | None (channel-sold) |
Who each provider actually fits
Bridewell
Large UK organisations in regulated sectors (CNI, aviation, finance, government) wanting a UK SOC with broad NCSC scheme coverage.
NCC Group
Global enterprises wanting a listed company with dual-level NCSC CIR assurance and CREST SOC accreditation; European delivery runs through Fox-IT in the Netherlands.
Sophos MDR
Midmarket organisations already on (or open to) the Sophos stack, buying through the channel at global scale.
Quorum Cyber
Microsoft-estate organisations across finance, education, housing and the public sector; NCSC CIR Standard assured; Microsoft Security MSSP of the Year 2025.
Six Degrees
Public-sector and mid-to-large organisations buying through G-Cloud with SC-cleared UK staff; its G-Cloud MXDR rate card is one of the few public price points in the market.
Socura
Public services and critical-service providers; runs the Welsh Government's national CymruSOC from a CREST-accredited UK SOC.
A 10-500-person business
Honestly: most SMEs do not need an enterprise MDR contract. A managed cybersecurity service with a 24/7 SOC, fixed per-user pricing and one SLA - AMVIA's Enterprise plan is £60/user/month, published - covers detection and response without enterprise procurement.
What UK MDR actually costs
<p>Almost no UK MDR provider publishes standard pricing - of the seven active providers reviewed here, none shows a price on its own website. The only public price points are procurement-framework rates: Six Degrees lists its MXDR SOC service on G-Cloud at £3.50 to £55.00 per device per month, and Socura's G-Cloud MDR listing shows £80 per unit per month. Everything else is quoted per engagement.</p><p>By contrast, AMVIA publishes its ladder: managed cybersecurity within the Enterprise managed-IT plan at £60/user/month including a 24/7 SOC, with Essentials at £25 and Advanced at £40. For a 50-person business that is £3,000/month, known before you talk to anyone - the pricing transparency the MDR market conspicuously lacks.</p>
The AMVIA Recommendation
The AMVIA recommendation
<p>Buy the shape of service your organisation can actually operate. If you run a large security function that will consume analyst-grade telemetry, an enterprise MDR from the providers above is the right category - shortlist on NCSC CIR status, CREST SOC accreditation and sector references, and check financial stability (the Adarma administration in July 2025 caught customers of one of the UK's largest independents). If you are a 10-500-person business without a security team, an MSSP that owns the whole stack - detection, response, patching, user support - under one SLA is usually the better contract. That is the service AMVIA runs, with published pricing.</p>
How the UK MDR market is actually structured
Managed detection and response in the UK is not one market. At the top sit enterprise providers - Bridewell (listed by the NCSC for five assured schemes) and NCC Group (NCSC Cyber Incident Response assured at both Standard and Enhanced levels) - serving regulated estates and global enterprise. A Microsoft-centric middle tier includes Quorum Cyber (NCSC CIR Standard, Microsoft Security MSSP of the Year 2025) and Six Degrees (NCSC CHECK-listed, SC-cleared staff, G-Cloud). Sophos MDR operates at a different scale entirely - a vendor-run service its own pages say protects 39,000+ organisations globally. And Socura runs the Welsh Government's national CymruSOC, the first scheme of its kind in the UK. One thing unites them: pricing is almost never published.
What the NCSC does and does not assure
A common buying mistake is looking for an NCSC-certified MDR. The NCSC does not assure ongoing monitoring; its Cyber Incident Response scheme assures the response service that takes over when detection escalates - Standard level for most organisations, Enhanced level (13 competency areas, including nation-state experience) for critical national infrastructure and government. The SOC function itself is independently accredited by CREST. So the due-diligence pattern is: CIR status for response, CREST SOC accreditation for the operations centre, ISO 27001 for the provider's own management - and the NCSC's supplier-verification pages to check any claim.
The providers, one by one
Bridewell (Reading, UK-wide offices): own UK SOC, CREST-accredited including the SOC discipline; Microsoft Defender XDR and Sentinel stack; named clients include Northern Gas Networks and Manchester Airport Group; strongest fit is large regulated organisations. NCC Group (Manchester HQ, LSE-listed): managed XDR for Microsoft and Splunk; European MDR delivered through its Dutch subsidiary Fox-IT in Delft; ten CREST disciplines including SOC; the only provider here with NCSC CIR at both levels. Sophos MDR (Abingdon-headquartered vendor): six global SOCs, NCSC CIR certified, Gartner Peer Insights Customers' Choice for MDR (March 2026), completed its $859m Secureworks acquisition in February 2025; sold through the channel. Quorum Cyber (Edinburgh): Microsoft-centric Clarity Extend MDR, SOCs in Edinburgh and North America, NCSC CIR Standard assured, Microsoft-verified MXDR. Six Degrees (London): Sentinel/Defender MDR from a UK-only CSOC with SC-cleared staff; NCSC CHECK-listed for penetration testing; its G-Cloud MXDR listing (£3.50-£55.00 per device/month) is one of the market's only public rate cards. Socura (Cardiff): CREST-accredited UK SOC, vendor-agnostic MDR, and operator of CymruSOC for Welsh local authorities and fire services.
The Adarma lesson: stability is a selection criterion
In July 2025, Adarma - an Edinburgh MDR and managed-SOC provider widely described as one of the UK's largest independents - entered administration and ceased trading immediately, with 173 staff made redundant. Administrators cited the loss of a major customer and sustained margin pressure. Customers had to re-procure detection and response mid-contract. The takeaway is not that independents are unsafe; it is that provider financials, customer concentration and exit terms belong on the same checklist as accreditations.
When a mid-sized business should buy an MSSP instead
Enterprise MDR assumes you keep the rest: firewalls, endpoint estate, patching, identity, user support. A 10-500-person business without a security team usually needs those owned too - which is the MSSP model: one provider, one SLA, monitoring plus the stack underneath it. That is the service AMVIA runs from its Sheffield operations centre, with published pricing (Enterprise, including the 24/7 SOC, at £60 per user per month) - the transparency this comparison shows the MDR market lacks. The honest boundary: if you have an in-house security function consuming raw telemetry, buy MDR from the providers above, not an MSSP.
Frequently Asked Questions
It depends who you are. For large regulated estates: Bridewell and NCC Group (NCC holds NCSC Cyber Incident Response assurance at both levels). For Microsoft-centric organisations: Quorum Cyber and Six Degrees. For midmarket at global scale: Sophos MDR. For public services: Socura, which runs Wales's national CymruSOC. For a 10-500-person business, a fixed-price MSSP with a 24/7 SOC is usually the better-shaped contract than enterprise MDR.
Not for the monitoring itself. The NCSC's relevant scheme is Cyber Incident Response (CIR), which assures the response service a provider deploys when detection escalates - at Standard level for most organisations and Enhanced level for CNI, government and heavily targeted estates. For the SOC function itself, the main independent accreditation is CREST's Security Operations Centre accreditation. Any provider's claimed NCSC status can be checked on the NCSC website's supplier-verification pages.
Almost nobody publishes it. None of the seven active providers reviewed here shows standard pricing on its own website; the only public figures are G-Cloud framework rates - Six Degrees at £3.50-£55.00 per device per month and Socura at £80 per unit per month (both as listed Sept 2026). Everything else is quoted per engagement, which makes budgeting hard before procurement starts.
Adarma, an Edinburgh-headquartered MDR and managed-SOC provider described as one of the UK's largest independent cyber security businesses, entered administration on 14 July 2025 and immediately ceased trading, with 173 staff made redundant. Administrators cited the loss of a major customer and sustained margin pressure. The practical lesson for buyers: financial stability belongs on the MDR selection checklist alongside accreditations.
MDR is a focused service: detection, investigation and response on top of your security telemetry, usually assuming you retain wider IT and security operations. An MSSP owns more of the stack - monitoring plus the firewalls, endpoint security, patching and user support underneath it - under one SLA. Enterprises with security teams tend to buy MDR; businesses of 10-500 staff without one usually get more from an MSSP.
Three things cover most of the assurance ground: NCSC Cyber Incident Response (Standard or Enhanced) for the response arm; CREST Security Operations Centre accreditation for the SOC function itself (held by, among others, Bridewell, NCC Group and Socura); and ISO 27001 for the provider's own security management. Treat vendor superlatives as marketing unless they trace to a listing you can check.
Security operations sized for a 10-500-person business
24/7 monitoring, detection and response under one SLA with published pricing - Enterprise at £60/user/month, no enterprise procurement cycle.
Related Resources
Managed Cybersecurity Services
What AMVIA's 24/7 monitoring, detection and response covers.
MSP vs In-House IT
The build-vs-buy decision for mid-sized UK businesses.
How Much Does Managed Cybersecurity Cost?
UK price ranges and what moves them.
Best MSSP for Small Business UK
The SME security market compared honestly: who serves your size, verified.
Protect your business → Get Cybersecurity Assessment