MDR Renewal: Make Your Provider Prove the Service
An MDR renewal should not be approved because the dashboard is green and the monthly report has a lot of charts.
You bought managed detection and response to add detection, investigation, and response capacity your internal team did not have. At renewal, the provider should be able to show what it covered, what it found, what it did, where the service struggled, and what improved because of the work.
If the evidence is limited to alert counts and generic threat news, you do not have a renewal case. You have activity.
The decision is whether the service reduced a real operating gap at a fair cost, whether the gap can be fixed, or whether the company should compare other options.
Start with the service you thought you bought
Your renewal review needs to start with the signed scope, not the current sales deck.
Pull the order form, statement of work, service description, response playbooks, support terms, data retention terms, and any amendments. Write down:
- Which assets and data sources are covered
- Which assets and sources are excluded
- Which hours and regions the provider monitors
- Which events the provider investigates
- Which response actions it may take
- Which actions require your approval
- Which incident tasks stay with your team
- Which reports, reviews, and service levels were promised
This division of labor is not paperwork for paperwork’s sake. NIST Special Publication 800-61 Revision 3 says incident response responsibilities transferred to a service provider should be clearly defined in the contract. NIST also calls out information flows, coordination, authority to act, and restrictions on what the provider can do.
That is the baseline. Renewal is where you compare the written promise with the service that showed up.
Ask for a twelve-month evidence packet
Ask for a clean evidence packet covering the current term.
It should include:
- Coverage: Assets, users, identities, cloud workloads, and other agreed data sources under monitoring, plus gaps and collection failures.
- Detections: Investigated events by severity and source, with enough context to distinguish useful detection from automated noise.
- Escalations: Cases sent to your team, the reason for escalation, elapsed times, and the final disposition.
- Response actions: Endpoints isolated, accounts disabled, sessions revoked, malicious processes stopped, or other actions taken under the agreed authority.
- Tuning: Detection rules, exclusions, allowlists, integrations, and playbooks changed during the term.
- Service failures: Missed service levels, delayed notifications, failed agents, unavailable integrations, or incidents where the handoff broke.
- Improvement work: Recommendations issued, owners assigned, items completed, and material risks still open.
A zero in one category is not automatically bad. Maybe there were no confirmed incidents. The provider should still show coverage health, investigation work, tuning, exercises, and open gaps. Bigger alert counts are not the goal. Evidence that the service operated as promised is.
Test coverage before you discuss renewal pricing
A provider cannot detect what it cannot see.
Compare the contracted scope with your current environment. Cloud workloads, applications, users, identities, and endpoint types change during a contract term. The MDR deployment may not have followed.
Build a coverage table:
| Coverage question | Evidence to review |
|---|---|
| Are all in-scope endpoints reporting? | Current asset inventory and agent-health export |
| Are identity events included? | Connected tenants, event types, and ingestion status |
| Are cloud workloads covered? | Account inventory, workload list, connector health, and exclusions |
| Are critical systems sending useful telemetry? | Data-source map, last-seen records, and parsing errors |
| Did coverage change during the term? | Onboarding, offboarding, acquisition, and project records |
| Who owns broken coverage? | Ticket history, escalation path, and named owner |
If the provider says coverage is 100 percent, ask what the denominator is. The assets in its console may not include every asset the company needs protected.
Our MDR fit guide explains the broader category. Renewal requires a narrower test: did this service cover your actual risk surface during this term?
Separate notification from response
Many renewal reviews get fuzzy right here.
A provider can investigate an event, open a ticket, call an administrator, recommend isolation, perform isolation, or coordinate a larger incident. Those are different levels of service.
Take several meaningful cases and reconstruct the timeline:
- When did the provider receive the relevant signal?
- When did an analyst investigate it?
- When did the provider decide it required action?
- When did your team receive the escalation?
- What action did the provider take?
- What action remained with your team?
- When was the event contained or closed?
- What changed afterward?
Do not reduce the exercise to one average response number. Averages can hide the cases that mattered and mix low-risk alerts with serious incidents.
Then compare the behavior with the contract and playbooks. If the provider had authority to isolate a compromised device but waited for approval, find out why. If the provider was never authorized to act, decide whether that operating model still fits the business.
Price the work your internal team still owns
MDR is often justified by the security capacity it adds. That value gets weaker when the internal team spends too much time checking, translating, and correcting the service.
Ask the people who operate it:
- How much time goes into chasing provider updates?
- Does the team re-investigate alerts because the escalation lacks context?
- Who fixes broken agents and connectors?
- Who writes or tunes the detections the company cares about?
- Who handles containment after hours?
- Which promised tasks quietly became internal work?
The provider will not own everything. The retained work still needs to be visible.
A service can be technically competent and still be the wrong operating fit. If your team has to reconstruct every escalation and manage every handoff, the renewal price is only part of the cost.
Look for improvement, not just operation
Review what changed during the term. Did recurring false positives get tuned? Did the provider find persistent visibility gaps? Were response playbooks updated after exercises or incidents? Did executive reporting become more useful? Did the provider flag a risky pattern your internal team could fix?
NIST’s current incident response guidance places preparation, detection, response, recovery, and lessons learned inside the broader Cybersecurity Framework 2.0. It also recommends performance measures and periodically testing procedures.
That gives you a useful renewal question: what did this relationship teach the company, and where is that learning recorded?
If the same blind spots, handoff issues, and noisy detections appear quarter after quarter, the service is operating without improving.
Score the renewal across six areas
Use a simple zero-to-two score. Zero means missing or unsupported. One means partial or inconsistent. Two means clear and evidenced.
| Renewal area | Buyer test | Score |
|---|---|---|
| Contract fit | Scope, responsibilities, authority, and exclusions are clear | 0-2 |
| Coverage | In-scope assets and data sources are healthy and reconciled | 0-2 |
| Detection quality | Investigations show useful context and reasonable tuning | 0-2 |
| Response execution | Escalations and actions match the agreed playbooks | 0-2 |
| Operating value | The service adds capacity without pushing hidden work back to IT | 0-2 |
| Improvement | Gaps, lessons, and recommendations turn into tracked changes | 0-2 |
Do not let the total decide by itself. A failure in response authority or critical-system coverage can matter more than several strong reporting scores.
Set the decision states before the renewal deadline:
- Renew: The service fits, the evidence is strong, and the commercial terms remain reasonable.
- Renew with remediation: The model fits, but specific coverage, playbook, reporting, or service issues need written owners and deadlines.
- Run a competitive review: The provider may be replaceable, or the company needs a different operating model.
- Redesign the scope: The tool set, data sources, internal security maturity, or response needs have changed enough that a like-for-like renewal makes no sense.
- Do not renew yet: Material evidence or terms are still missing.
Put remediation into the renewal record
A provider may agree to fix every concern in the meeting. Put the important ones in writing.
For each gap, record the deliverable, owner, due date, acceptance evidence, escalation path, and commercial consequence if applicable. Route contract and legal questions through the right reviewers. Do not rely on a slide that disappears after signature.
Also confirm what happens on exit. Ask about data export, incident records, playbook portability, agent removal, retained logs, transition support, deletion, and access revocation. A clean exit plan gives the buyer leverage even when the right decision is to stay.
Your incident response plan should reflect the final division of responsibility. The provider’s name in a contact list is not enough. Your team should know who decides, who acts, how the parties communicate, and what happens when the provider cannot reach the primary contact.
Make the provider earn the renewal
MDR can be a smart way to add security coverage and response capacity without building every function internally. But the value is in the service delivered, not the category name.
Before you renew, ask for twelve months of evidence. Reconcile coverage. Reconstruct meaningful incidents. Price the work your team still owns. Put remediation and exit terms in the written record.
If the provider can prove the service, the renewal conversation gets easier. If it cannot, you found the issue before another contract term made it more expensive.
Catch Advisors helps IT leaders review security providers, compare operating models, and pressure-test contract value without steering the decision toward one vendor. If your MDR agreement is approaching renewal, request a vendor-neutral Contract and Spend Risk Review before the deadline takes over the decision.