Vendor pricing

Cortex XDR pricing: endpoint EDR with a data-ingestion meter attached.

Cortex XDR is Palo Alto's endpoint and extended-detection platform. It sits at the premium end of the market, and the catch most buyers miss is the data-ingestion charge: the per-endpoint licence is only half the bill once log volume is metered. Figures here are aggregated; Palo Alto quotes the Prevent tier custom.

Pricing verified June 2026
The short answer

Palo Alto Cortex XDR is priced per endpoint per year, with the entry Cortex XDR Pro tier starting around $81/endpoint/year and the overall range running roughly $9 to $36/endpoint/month (about $108 to $432/endpoint/year) across tiers. The Prevent tier is custom-quoted. The figure that surprises buyers is data ingestion: Cortex meters log volume separately (per-TB), so the effective cost can land well above the per-endpoint headline. These are aggregated buyer-reported figures; Palo Alto does not publish a standard list.

Aggregated buyer data, not a vendor list price. Palo Alto Cortex XDR does not publish standard per-endpoint pricing. The figures below are aggregated from public reseller catalogues, marketplace listings, and buyer-reported quotes (see aggregated reseller and buyer-reported pricing and our sources page), cross-checked June 2026. They are estimates, not quotes. Always get the number in writing.

Palo Alto Cortex XDR pricing tiers

TierPriceReal EDR?Notes
Cortex XDR PreventCustom quoteNoNGAV + exploit/behaviour prevention. Endpoint-only, no full EDR data.
Cortex XDR Pro (per endpoint)from ~$81/endpoint/yr~$6.75/mo+YesThe EDR tier: telemetry, analytics, investigation, response.
Cortex XDR Pro (higher tiers)up to ~$432/endpoint/yrup to ~$36/moYesBroader correlation, identity analytics, longer retention.
Cortex XDR Pro per TBCustom (per-TB data)YesData-ingestion model. Log volume is metered separately.

The entry tier that delivers genuine EDR (continuous telemetry, behavioural detection, threat hunting, and response actions) is Cortex XDR Pro (from ~$81/endpoint/year). Cheaper tiers in the table are NGAV or prevention-only and do not give you the post-incident investigation trail that defines EDR.

What it costs at your size

Worked annual figures at the entry EDR tier, before negotiation. Use these to size the budget line, then run your own numbers in the budget calculator, which layers deployment, tuning, and internal operating cost on top of the licence.

OrganisationEndpointsTierAnnual licencePer endpoint / mo
Small business200Cortex XDR Pro~$16,000+~$6.75+
Mid-market1,000Cortex XDR Pro~$81,000+~$6.75+
Upper mid-market5,000Cortex XDR Pro~$405,000+~$6.75+
Enterprise25,000Cortex XDR Pro~$2.0M+~$6.75+
Plus data ingestionanyper-TB add-onmetered on topvaries

Licence only. Deployment, tuning, IR retainer, and internal operating cost sit on top: see the five TCO categories. At SMB scale the licence is roughly half of true all-in cost.

Four ways to bring the Palo Alto Cortex XDR number down

Model the data charge before you sign

Cortex meters log ingestion per TB on top of the per-endpoint licence. For chatty environments this can match or exceed the endpoint cost. Get a quote that includes a realistic data-volume estimate, not just the per-seat number.

Right-size the tier

The range spans $9 to $36 per endpoint per month. Most endpoint buyers need Pro, not the highest correlation tiers. Do not pay for identity analytics and extended retention you will not operationalise.

Lean on a Palo Alto platform consolidation deal

If you already run Palo Alto firewalls or Prisma, Palo Alto offers platform-consolidation pricing. A combined renewal is your strongest discount lever on Cortex.

Negotiate retention down

Longer telemetry retention drives both tier and data cost. Match retention to your actual compliance requirement (often 90 to 180 days) rather than buying a year by default.

When Palo Alto Cortex XDR is the right pick, and when it is not

Right pick if
  • + You already run Palo Alto firewalls or Prisma and want a consolidated Palo Alto security platform.
  • + You need deep cross-layer correlation (endpoint, network, cloud, identity) in one analytics engine.
  • + You have the SOC maturity to operationalise a heavy, data-rich XDR platform.
  • + You can model and absorb the per-TB data-ingestion cost.
Wrong pick if
  • You are a budget-sensitive SMB: Cortex sits at the premium end and the data charge compounds it.
  • You only need endpoint EDR: a per-device EDR like Falcon Pro or Defender P2 is simpler and cheaper.
  • You cannot predict your log volume: the per-TB meter makes the bill hard to forecast.
  • You are on Microsoft 365 E5: Defender for Endpoint P2 is already paid for and far cheaper.

Palo Alto Cortex XDR pricing questions

How much does Cortex XDR cost per endpoint?
Palo Alto Cortex XDR is priced per endpoint per year, with the entry Cortex XDR Pro tier starting around $81 per endpoint per year and the overall range running roughly $9 to $36 per endpoint per month (about $108 to $432 per endpoint per year) across tiers. The Prevent tier is custom-quoted. These are aggregated buyer-reported figures verified June 2026; Palo Alto does not publish a standard price list.
Why is Cortex XDR more expensive than it looks?
Cortex XDR meters data ingestion separately, charging per TB of log volume on top of the per-endpoint licence. For environments with high telemetry volume, the data charge can match or exceed the endpoint licence, so the effective cost lands well above the per-endpoint headline. Always get a quote that models your realistic log volume, not just the per-seat number, before comparing Cortex to per-device EDR competitors.
Which Cortex XDR tier includes EDR?
Cortex XDR Pro is the tier with full EDR: continuous telemetry, behavioural analytics, investigation, and response. The Prevent tier is NGAV and exploit/behaviour prevention without the full detection-and-response data layer. If you need EDR for compliance or cyber insurance, Cortex XDR Pro (from roughly $81 per endpoint per year) is the minimum tier, not Prevent.
Is Cortex XDR worth it versus CrowdStrike or Defender?
Cortex XDR makes sense when you already run Palo Alto firewalls or Prisma and want a consolidated platform with deep cross-layer correlation, and you have the SOC maturity and budget to absorb the per-TB data cost. For straightforward endpoint EDR, a per-device platform like CrowdStrike Falcon Pro or Microsoft Defender for Endpoint P2 is simpler and usually cheaper, particularly for E5 customers who already own Defender.

Updated 2 May 2026