Skip to main content
← Back to all posts
edr··7 min read·By Quantm Security Team

Managed EDR SLA Checklist: What the Contract Should Define

A managed EDR SLA should define the event, clock, target, responsible party, exclusions, evidence, and remedy for each service commitment.

A useful managed EDR SLA defines what event starts a clock, what action must occur, who is responsible, which conditions pause or exclude the target, how performance is proven, and what happens after a miss. A promise of “fast response” does not settle those points.

Learn the service components first in what to expect from managed EDR and the main EDR guide.

Separate the response stages

Acknowledgement, triage, investigation, containment, and recovery are different activities. A provider might acknowledge an alert without determining whether it is malicious. A containment recommendation is also different from completed isolation.

Contract field What it should answer
Covered event Which alert, severity, or customer request qualifies?
Clock start Detection time, provider receipt, ticket creation, or customer report?
Required action Acknowledge, investigate, notify, recommend, or contain?
Target What time commitment applies to that action?
Service window Which hours, days, holidays, and time zone apply?
Responsibility Provider, customer, or a named shared step?
Pause and exclusions Does missing access, approval, or contact pause the clock?
Evidence Which timestamps, tickets, and reports prove performance?
Remedy and review What follows a miss or repeated pattern?

Do not assume one response-time statement covers every severity or response stage.

Use a severity and action matrix

The exact targets belong in the negotiated agreement. A structure like this makes them testable:

Severity Example condition Provider stage Customer duty Evidence
Critical Confirmed active harmful behaviour with material business exposure Immediate human validation, urgent notification, and authorized containment or recommendation Maintain reachable decision-maker and start the incident process Source alert, analyst note, contact log, action audit, and timestamps
High Credible suspicious activity requiring prompt investigation Investigate within the stated target and escalate with evidence Supply business context and approve restricted actions within the stated window Case record, evidence summary, questions, approvals, and decision
Medium Suspicious or policy-relevant activity without confirmed active harm Review within the applicable service window Respond to context requests and remediate accepted findings Queue, disposition, linked remediation, and closure basis
Low Informational or low-risk activity useful for trend or tuning Review, group, or report under the stated cadence Review trends and approve tuning where needed Report, tuning log, and retained source record

The contract should define the actual severity conditions and allow reclassification with an audit trail. A vendor severity label should not silently determine customer business impact.

Turn promises into clause fields

For each target, write a complete sentence with variables filled in: “For a covered critical endpoint detection received during the all-hours service window, the provider will begin human investigation within X minutes of provider receipt, notify the customer's designated channel within Y minutes after validation, and perform only the response actions authorized in Schedule Z.”

Then define provider receipt, human investigation, validation, successful notification, authorized action, unavailable customer, unsupported device, and evidence. Legal counsel should adapt wording to the final agreement; this example shows the missing fields, not contract language to copy unchanged.

Define scope and coverage

List the endpoint products, device types, operating systems, business units, and service locations in scope. State whether monitoring includes servers, mobile devices, cloud workloads, and endpoints that have stopped reporting.

Clarify data retention, investigation limits, threat hunting, tuning, reporting, and incident support. Record separately billed work and any case limits. The managed versus in-house EDR comparison helps expose work that may remain with the customer.

List every incorporated document and resolve conflicts among the order form, service description, SLA, data-processing terms, support policy, acceptable-use terms, and proposal. A sales presentation should not be the only place where a required duty appears.

Make response authority executable

The agreement should say whether the provider may isolate a device, terminate a process, quarantine a file, or recommend action only. Define which conditions permit immediate action and how the provider proceeds when an approver cannot be reached.

Include rollback and business continuity. A technically correct containment action can still interrupt a critical process.

Record response authority by action and device class. Include isolation, release, process termination, file quarantine, indicator blocking, evidence collection, and account-related requests. State whether the provider acts, recommends, or waits for approval. Define the fallback when the primary and secondary contacts do not answer.

Check customer dependencies

Service commitments commonly depend on current contacts, valid access, functioning agents, supported systems, and timely customer approval. Those dependencies should be visible, reasonable, and measurable.

Avoid a clause that lets the provider pause every clock for any customer dependency. Tie each pause to a specific requested input or approval, require the provider to record when the request was made, continue work that is not blocked, and resume the clock when the dependency is satisfied. Reporting should separate provider and customer delay.

Examine remedies and chronic failure

Service credits may be limited, require a claim, and be the exclusive financial remedy. Record the calculation, cap, evidence, claim window, and whether a repeated pattern triggers a corrective plan, management escalation, termination right, or transition support. A small credit does not restore lost response time.

The operational review matters even when no credit applies. Require root-cause review for material or repeated misses, an owner, corrective action, target date, and follow-up evidence.

Cover security, privacy, and resilience

Review provider access controls, MFA, privileged administration, personnel access, audit logs, vulnerability management, incident notification, business continuity, disaster recovery, subcontractors, insurance, and customer audit information. Confirm how the provider maintains service during its own outage or security incident.

Document where endpoint telemetry and cases are stored and processed, which subprocessors receive them, permitted uses, retention, legal requests, return, deletion, and verification. Canadian organizations should assess applicable privacy and contractual duties with qualified advisers.

Make exit workable

The agreement should cover notice, transition period, open-case handoff, case and policy export, telemetry access, agent removal or transfer, integration shutdown, credential revocation, customer-data return and deletion, and reasonable transition assistance. State formats, timing, rates, and what happens if a security incident is active at termination.

Test export before the end of the term. Data that is technically exportable but unusable without undocumented fields or a proprietary viewer may not meet the business need.

The managed EDR onboarding process should test them before the service enters steady operation.

Require useful reporting

Ask for a report that distinguishes:

  • total in-scope devices from enrolled and actively reporting devices;
  • alerts from confirmed incidents;
  • acknowledgement from investigation and containment times;
  • provider-controlled delays from customer-controlled delays;
  • missed targets, causes, corrections, and recurring issues; and
  • material configuration or coverage changes.

Require enough raw timestamps or case access to reproduce material results. A monthly percentage without the qualifying incidents, exclusions, clock pauses, or severity changes cannot be audited.

The UK's National Cyber Security Centre includes incident management, resilience, audit, data, and exit considerations in its guidance for choosing a managed service provider. Use those themes when reviewing the wider agreement, not only the SLA table.

Final buyer checklist

  • Are all terms defined in the agreement?
  • Do the SLA and service description describe the same scope?
  • Are severity rules and response stages unambiguous?
  • Can the provider act with the authority the service assumes?
  • Are customer dependencies and pauses visible?
  • Is performance evidence available for review?
  • Are subcontractors, data location, security, and exit addressed?
  • Is there a scheduled process to review misses and changing requirements?

Have qualified legal and security advisers review the final agreement for your organization. This checklist supports due diligence but is not legal advice.

Need help turning endpoint requirements into provider questions? Talk to Quantm.