SmartSoft Authorised Partner Sophos
Q2 2026 promotional pricing ends IN --d --h --m --s
Sophos XDR - Q2 2026 Offer

One attack story across
every layer of your security.

Sophos XDR pulls signals from your endpoints, servers, firewall, email gateway, identity and cloud - and stitches them into a single attack timeline. So instead of three teams chasing three half-stories, you see one chain of events from initial click to data-staging server.

Endpoint + server + firewall + email + cloud Cross-domain correlation 30-day data lake retention

Cross-domain XDR - custom quote

Server & endpoint licences combine into one XDR coverage. Pricing on request.

Server licencePer server, 1-year or 3-year locked
On request
Endpoint licencePer laptop / PC, 1-year or 3-year locked
On request
3-year lock-in availableFreeze your security budget until 2029
Best value

All licences in INR, GST extra. Server + endpoint quoted as one solution.

Why XDR, why now

Your firewall, EDR & email gateway each see one piece of the attack.

Modern attacks touch four to seven different systems. Without correlation, your team is reading three different log files trying to guess what just happened.

Three tools, three half-stories

Email gateway saw a phishing link. EDR saw a process spawn. Firewall saw outbound C2. Nobody connected the dots until the breach was complete.

Alert overload

Each tool fires its own alerts. Your team triages 200/day in isolation - and the one cross-tool pattern that mattered gets buried.

No long-term hunting data

Most tools keep 7-14 days of logs. Attackers dwell for months. XDR's 30-day data lake lets you hunt across the full window.

7 tools

Average number of security tools a modern attack chain touches before damage is done - endpoint, email, identity, firewall, DNS, server, cloud. XDR is the only way to see them as one chain.

What you actually get

Six XDR capabilities - on day one.

Cross-domain telemetry

Endpoints, servers, Sophos Firewall, Sophos Email, Microsoft 365, Google Workspace, AWS, Azure - all into one data lake.

One-click attack chain

Sophos auto-correlates events across tools - so a phishing email + endpoint compromise + firewall C2 appears as a single incident, not three.

30-day cloud data lake

Live Discover SQL queries across 30 days of cross-domain telemetry - hunt for IoCs, patterns and dormant compromises.

3rd-party integrations

Native connectors for Microsoft 365, Google Workspace, Okta, AWS, Azure, plus syslog/REST for any other tool you run.

Cross-domain response

Isolate an endpoint AND block the attacker IP at the firewall AND revoke their M365 session - in one action, from one console.

Single agent, single console

Same Sophos agent as EDR - just unlocks the cross-domain data feeds. No new infrastructure to deploy.

EDR vs XDR vs MDR

EDR sees one laptop. XDR sees the whole organisation. MDR adds a 24x7 SOC.

Pick EDR if your IT team will operate one console for endpoints/servers. Pick XDR if you also run Sophos Firewall, Sophos Email or M365 and want one correlated view. Pick MDR if you want Sophos analysts to do all of it for you, 24x7.

EDR

Endpoint & server only

XDR

+ firewall, email, cloud

MDR

+ 24x7 Sophos SOC

Q2 2026 Promotion

One XDR solution. One PO. Two licence components.

Sophos XDR is licensed per server and per endpoint - quoted together as your complete coverage. Cross-domain integrations (Sophos Firewall, M365, AWS, etc.) are included at no extra licence cost. All prices per licence, GST extra.

Component 1 - Servers

XDR Server licence

Per physical or virtual server. File servers, AD, ERP, app servers, hypervisors.

1-Year
On requestper server / yr
3-Year
On requestper server / 3 yrs, locked rate
  • Cross-domain telemetry from every server in scope
  • Linux + Windows + virtualised workloads
  • Server-grade lateral-movement detection
  • 30-day cloud data lake retention
  • Live Discover queries across all data sources
  • Bundled Intercept X for Server licence
Component 2 - Endpoints

XDR Endpoint licence

Per laptop, desktop or workstation. Windows + macOS supported.

1-Year
On requestper endpoint / yr
3-Year
On requestper endpoint / 3 yrs, locked rate
  • Endpoint telemetry into the XDR data lake
  • Cross-domain attack-chain visualisation
  • Bundled Intercept X Advanced licence
  • 3rd-party integrations (M365, Google, AWS, Azure)
  • Live Discover threat hunting (30-day window)
  • Co-terminus billing with existing Sophos
Request a quote

Indicative endpoint pricing

Per-laptop / PC pricing (Windows + macOS). Server pricing & cross-domain integration setup confirmed on quote.

1 Year
₹ 1,430 +GST
per endpoint / yr
3 Years · Best value
₹ 2,730 +GST
per endpoint / 3 yrs, locked rate

Indicative SmartSoft pricing. Server licences & large-volume discounts on request — final quote within 1 business day. GST extra. Cross-domain integrations (M365, AWS, Sophos Firewall etc.) included at no extra licence cost.

Request quote

One PO. One renewal date. One invoice. Server & endpoint licences are quoted, billed and renewed together as your single XDR solution.

From PO to protected

Live in 7 working days.

Our standard XDR onboarding playbook - including cross-domain integrations.

1

Discovery & integration map

30-min call. We map your endpoints, servers, firewall, email, M365/Google, cloud accounts.

2

Quote & PO

Custom quote on your exact licence count - 1-yr or 3-yr term, with finance options.

3

Deploy & integrate

Agent push, plus M365/Google/AWS/Sophos Firewall connectors - remote & onsite.

4

Train & tune

4-hour XDR workshop on cross-domain hunting, attack-chain analysis, response actions.

Bundled with this offer

Four things SmartSoft throws in - no extra charge.

Free Security Posture Audit

30-minute audit with a written top-5 risks report. Worth Rs.25,000.

Free 3rd-party Integration Setup

SmartSoft configures M365, Google Workspace, AWS, Azure & Sophos Firewall connectors.

4-hour XDR Workshop

Hands-on training on cross-domain hunting, Live Discover queries & attack-chain analysis.

0% EMI for 24 months

Spread the 3-yr cost across 24 EMIs on orders above Rs.3 lakh. HDFC / ICICI partner.

Get your custom Sophos XDR quote

Tell us your environment - we'll come back within one working day with a tailored quote, the integrations we'll set up, and a free baseline audit.

By submitting, you agree to be contacted by SmartSoft. We never share your details. GST extra on all quotes.

Got it - we'll be in touch within one working day.

Meanwhile, our security team is preparing your custom quote and audit slot.

Quick answers

Common questions before you sign.

Do I need Sophos Firewall to use Sophos XDR?
No. XDR's biggest gains come from Sophos Firewall + Sophos Email integration (deepest correlation), but it also pulls signals from Microsoft 365, Google Workspace, Okta, AWS, Azure, and any tool that can syslog. Even endpoint-only XDR gives you a 30-day data lake and Live Discover queries that EDR doesn't.
What's the difference between EDR and XDR?
EDR sees only your endpoints & servers. XDR adds firewall, email, identity, cloud and SaaS into one correlated view. If you only have endpoints/servers and a small Sophos Central tenant, EDR is enough. If you run multiple security tools and want one attack story across them, you need XDR.
Will XDR slow down our laptops?
No. The agent is the same Sophos Central agent used for EDR (~80 MB, <2% CPU at idle). XDR is mostly a cloud-side feature: extra telemetry collection, a bigger data lake, more correlation rules. Endpoint impact is identical to EDR.
Does XDR replace my SIEM?
For most Indian SMBs, yes - it eliminates the need for a separate SIEM tool (Splunk, QRadar etc.) that typically costs Rs.50L+ to deploy. For larger enterprises with compliance log-retention requirements, XDR complements your SIEM by sending pre-correlated incidents instead of raw logs.
Can I upgrade from EDR to XDR mid-term?
Yes - the agent is the same, only the licence SKU and back-end features change. We prorate your existing EDR term against the XDR upgrade and align everything on a single co-terminus renewal date.
What about MDR - do I get a 24x7 SOC with XDR?
No. XDR is a tool - your IT team operates it. If you want a 24x7 Sophos SOC to monitor and respond on the same XDR data, that's Sophos MDR. Same agent, same console, same data lake - we just add the analysts.