What Replaced the Gartner Magic Quadrant for MDR?
You know the routine. A new security service lands on your desk, and the first thing you do is go find the Magic Quadrant. Look at the upper right, note who is sitting there, and you have a shortlist before lunch.
Try that with managed detection and response and you hit a wall. You search, you get results that look promising, you click through, and none of them is an actual report. Most buyers assume they searched badly and try again.
They did not search badly. The report is not there. And for enterprise buyers, who tend to have the longest vendor lists and the most people asking how the shortlist was built, that absence creates real work.
The short answer
Gartner covers this market through the Market Guide for Managed Detection and Response Services, published once a year, alongside customer reviews collected in Gartner Peer Insights. There is no quadrant. There never has been one for this category, so nothing was withdrawn or replaced in the usual sense. The job a quadrant would have done for you is now spread across a few different sources.
This is not a trivia point. Vendor glossaries and comparison pages across the security industry talk about "the MDR Magic Quadrant" as though it were a live document you could download. Buyers pick that up and repeat it in RFPs. If your shortlist has to hold up in front of a board or an auditor, a citation to a report that does not exist is an awkward thing to discover late.
So a useful habit: if a provider tells you it is a Leader in an MDR Magic Quadrant, ask for the document title, the publication date and the ID. What comes back will either be a different market, usually endpoint protection, or nothing at all.
What each analyst publication actually does
Once you accept the quadrant is not coming, the question becomes which documents are worth your time. Four matter, and they do genuinely different jobs.
Publication | What it does | Ranks vendors? | Use it for |
Magic Quadrant | Plots selected vendors on vision and execution | Yes | Not available for this market |
Market Guide for MDR Services | Defines the category and sets expectations | No | Setting your qualification floor |
KuppingerCole Leadership Compass | Scores providers and issues leadership designations | Yes | Comparative positioning |
Gartner Peer Insights | Collects verified customer reviews | Aggregates ratings only | Deployment breadth and retention |
The useful way to read that table: the quadrant-shaped hole gets filled by two different things rather than one. You need a document that tells you what "qualified" means, and you need a ranked evaluation to see who is ahead. No single publication does both here, which is why so many buyers come away feeling like they are missing something.
What a quadrant would have given you
Briefly, since you probably want to know what you are missing.
It plots vendors on two axes, completeness of vision and ability to execute, then drops them into one of four boxes: Leaders, Challengers, Visionaries or Niche Players.
Two things about it that buyers routinely get wrong. It is not a census, because only a subset of vendors gets analysed and the selection criteria are not published, so absence tells you very little. And it rates the company, not the specific service in your RFP. A vendor can sit in the Leaders box on the strength of a product line that has nothing to do with what you are buying.
The floor the Market Guide sets
Here is the part most articles skip, and it is the most immediately useful thing available to you.
The Market Guide does not rank anyone, but it defines the category, identifies representative vendors, and establishes what security leaders should expect from a qualified provider. That gives you a filter you can apply on day one. The 2025 edition requires providers to deliver round-the-clock human-led staffing with threat monitoring and hunting expertise, immediate remote mitigation and containment that goes beyond alerting, daily engagement with individual customer data, and actionable findings aligned to business risk rather than technology output.
Read those four in order and most of the market thins out fast. A service that tells you what happened and leaves you to deal with it is not MDR, whatever the invoice says.
There is also a direction-of-travel point worth raising in any multi-year negotiation. Gartner expects that by 2028, half of the findings from MDR providers will focus on, or include detail on, threat exposures, up from 20% today. If you are signing for three years, ask how the provider plans to cover exposure alongside detection, because the definition of the service is moving underneath you.
Why enterprise needs differ from mid-market
This is where shortlists go wrong. Enterprise MDR and mid-market MDR get sold under the same two words and they are not the same purchase. The fundamentals do carry across, and everything from access controls to AI-assisted threat detection matters just as much at either end. What changes is the operational load, and that is where the two services stop resembling each other.
Start with the arithmetic behind round-the-clock coverage. Industry estimates put genuine 24/7 staffing at eight to twelve analysts, because a single always-on seat takes roughly five full-time people once holidays, sick leave and training are accounted for. Those figures mostly come from MDR providers, so treat them as directional, but the shift maths behind them is hard to argue with. And the staffing pressure has not really lifted: ISC2's 2025 workforce study found shortages easing only slightly, with 34% of organisations reporting they have the right level of security staffing, up four points. Slightly better is a long way from covering three shifts.
Here is how that plays out in practice. A manufacturer with plants in three time zones buys a service advertised as 24/7. On paper it is covered. In reality the overnight shift for two of those regions is a single analyst in a fourth country, working a queue for every customer on the books. When something moves laterally at 3am local time on the far side of the estate, the alert is seen. It just is not acted on for another six hours. Nobody lied in the sales cycle. The question was never asked precisely enough.
So the enterprise questions are different:
Does coverage match your geography? Analysts working local hours in each region you operate in, not one team plus a thin overnight rotation.
What do they produce for auditors? Enterprises have obligations that turn incident documentation into a deliverable other people read. Ask to see that output, not just the security team's dashboard.
How do they sit alongside your existing SOC? Most large organisations already have one. Who owns escalation, and where exactly is the handoff?
Can response authority be set per segment? Every large estate has systems where automatic containment would be worse than the incident.
Are you being quoted the right tier? Providers split their offering by organisation size, and the capabilities enterprises care about, retrospective hunting, forensics support, a named response lead, usually sit only in the upper tier. Comparing one vendor's entry-level service against another's enterprise service is the most common mistake in MDR shortlisting, and it produces a comparison that looks rigorous and means nothing.
So who ranks MDR providers?
Three sources carry the weight, and they are worth different amounts.
Ranked analyst evaluations
Gartner is not the only firm covering this space. The KuppingerCole Leadership Compass assesses MDR providers directly and issues leadership designations, which makes it the closest thing available to the report you went looking for.
One thing to understand before reading any of it. KuppingerCole scores product capability, innovation and market presence separately, and hands out a separate designation for each. A provider can lead one category and not appear in another, so the label on its own tells you less than it looks like it does. In the 2026 edition, ESET is named a Market Leader in MDR. Its enterprise tier, ESET MDR Ultimate, includes retrospective threat hunting, digital forensics and incident response support and a dedicated incident response lead.
That distinction matters more than most buyers realise. A vendor recognised for market presence is telling you it is widely deployed and well supported across regions, which is genuinely useful if you operate in a dozen countries. It is not telling you it has the strongest technical capability, and a vendor that leads on product may have nothing like the same footprint. Work out which of the two your situation actually needs before you read anyone's results.
Customer reviews
Gartner Peer Insights collects verified reviews in this category, and issues a Customers' Choice designation based on them. Be clear about what that is: customer sentiment, not analyst evaluation. What it does tell you reliably is whether a service is widely deployed and whether customers stay, which matters when you are picking someone you will depend on for years.
Published performance numbers
Where a provider publishes a performance figure, mean time to respond is the one to compare. It measures the average gap between an incident being detected and the first action taken to deal with it. Providers who publish a number and explain how they measured it are far easier to hold to account, and that willingness is itself a signal. Check which tier the number applies to, because it is often the entry-level service being benchmarked.
Building a shortlist without a quadrant
Start with delivery model, not vendor names. Do you need a SOC you do not have, or reinforcement for one you do? Answering honestly removes half the market before you open a brochure.
Compare like tiers. Enterprise offering against enterprise offering. Always.
Pin down containment authority in the contract. Which actions can they take without asking, and which systems are carved out entirely?
Use one definition of response time. Mean time to respond as defined above, and ask what it was measured against.
Check tooling alignment. Their stack means replacing yours. Your stack means inheriting its blind spots. Neither is wrong, but the costs land differently.
Ask for a redacted sample report. If it reads as a list of alerts rather than a story about business risk, it will not survive its first board meeting.
Frequently asked questions
Is there a Magic Quadrant for managed detection and response?
No. Gartner has never published one for this category. It covers the market through the annual Market Guide for Managed Detection and Response Services and collects customer reviews through Gartner Peer Insights.
Why do so many vendors mention one?
Usually because they hold a position in a neighbouring Gartner quadrant, often endpoint protection, or because the phrase gets searched often enough that repeating it has made it look legitimate. Ask for a document title, date and ID.
Is a Market Guide weaker than a quadrant?
It is scoped differently rather than less rigorously. A quadrant ranks vendors; a Market Guide defines what qualified means. At the start of a buying process, knowing the floor is more useful than knowing the order.
What should enterprises check that smaller buyers can skip?
Whether analyst coverage matches your operating regions in local hours, whether reporting is audit-grade, how the service interoperates with an existing SOC, whether response rules can be set per network segment, and whether the quote covers the enterprise tier rather than the entry-level one.
Where that leaves you
The missing quadrant tells you something about this market rather than about the research. MDR gets bought against your existing tooling, your team, your regulatory position and your appetite for someone else touching production systems. No two-axis chart resolves any of that.
Use the Market Guide to set your floor. Use ranked evaluations and customer reviews to build a shortlist, reading the criteria before the results. Then take the time you would have spent staring at a chart and put it into the questions that decide this: who can contain a threat without waiting for your approval, how fast they do it, and whether you are comparing services that were ever meant to be compared.