Editorially independent. Sponsors are disclosed and never influence our analysis.
Independent research, supported bycriblSponsor
Vendor / Rapid7

Rapid7 InsightIDR pricing in 2026: per-asset, bundles, real cost

The independent Rapid7 InsightIDR pricing reference. The SIEM packages now sell as Incident Command, priced per asset per year on the AWS Marketplace. List rates, Insight Platform bundle economics, the MDR upsell path, real cost scenarios from the 251-asset minimum to 30,000-plus assets, and where Rapid7 wins on cloud-native simplicity. Updated August 2026.

Pricing model
Per asset / yr
12-month contract, 251-asset minimum
List rate
From $70.40
Essentials, per asset / yr
MDR
Quote-only
Managed Threat Complete, 24/7
Contract floor
$17.7K/yr
Essentials at the 251-asset minimum

List rates from the Rapid7 Incident Command AWS Marketplace listing and rapid7.com/products/siem/packages, retrieved 4 August 2026. Retention as stated on the packages page (90-day logs on Essentials, 180-day on Advanced and Ultimate, 13-month alert and audit retention).

How Rapid7 InsightIDR pricing actually works

Rapid7 InsightIDR prices on a per-asset-per-month meter, with log ingestion, EDR (Insight Agent), UEBA, deception, and basic correlation bundled in. The asset definition is broad: physical servers, virtual machines, cloud workloads, network devices, and user endpoints all count. The meter simplicity is the largest structural difference from per-GB SIEMs and the largest reason mid-market SOCs choose Rapid7: budget forecasting becomes a function of headcount and IT estate growth rather than log volume volatility.

The packages now sell under the Incident Command name. The AWS Marketplace list (retrieved 4 August 2026) runs $70.40 per asset per year for Essentials, $96.80 for Advanced, and $123.20 for Ultimate, on a 12-month contract with a 251-asset minimum, so the smallest marketplace contract is $17,670 to $30,923 per year. Essentials is the real floor; Advanced is the mid tier. Rapid7 states that the price per asset decreases across asset-count tiers, but publishes no rates for those higher tiers, so anything beyond the list anchor is a quote. Quarter-end pressure produces real discount outcomes; transactional list-rate purchases leave value on the table.

The asset count is the cost-discipline lever that matters most. Ephemeral cloud workloads count when the Insight Agent is installed; decommissioned-but-not-cleaned-up assets in CMDB count if Rapid7 last scanned them within retention window; shadow-IT cloud accounts count if discovered. Quarterly asset audits routinely remove 20-30 percent of the meter without losing real coverage. The cleanup discipline is the single highest-leverage Rapid7 optimisation and the one most customers do not invest in.

The Insight Platform bundle combines InsightIDR (SIEM/EDR), InsightVM (vulnerability management), and InsightConnect (SOAR/automation) at a negotiated combined discount versus standalone licensing; Rapid7 publishes no bundle rate. For organisations that genuinely run vulnerability management as an active discipline, the bundle math is decisive. For SIEM-only buyers, standalone InsightIDR is the right purchase; the bundle becomes economical only when InsightVM is genuinely used.

Rapid7 MDR is the co-managed upsell path. MDR pricing is quote-only (Rapid7 publishes no MDR list price); the quote typically includes the underlying InsightIDR licence and adds 24/7 SOC coverage with triage, investigation, and response. For organisations without internal SOC capacity or with limited 24/7 coverage, MDR is the genuine path. For organisations with internal SOC capability, MDR scoped to crown-jewel assets (production, payment processing, regulated data) while running self-service InsightIDR on the rest typically delivers better unit economics than full-estate MDR coverage.

The 2026 competitive environment for Rapid7 is unusually favourable. The vendor's historical positioning as a vulnerability management leader has expanded into a credible SIEM/XDR/MDR consolidator, and pricing aggression against Sentinel, Sumo Logic, and CrowdStrike Falcon for SMB and mid-market buyers is producing 20-25 percent discount outcomes on multi-year commits. The Insight Platform bundle pricing is genuinely competitive against Sentinel-plus-Defender and Sumo-plus-Wiz consolidation pitches.

InsightIDR pricing by asset band

Asset bandProfileAnnual licence
251 assets (minimum)Small business / single-site SMB$17.7K-$30.9K/yr (the AWS Marketplace contract floor)
500 assetsGrowing mid-market$35K-$62K/yr list
2,500 assetsMid-market, multi-site$176K-$308K/yr list, before volume-tier discount
10,000 assetsLower enterprise$704K-$1.23M/yr list, before volume-tier discount
30,000+ assetsEnterprise / regulated$2.1M-$3.7M/yr list, before volume-tier discount

Incident Command standalone, before Insight Platform bundle discount or MDR upsell. Bands are Essentials-to-Ultimate list math at the published per-asset rates; Rapid7 applies volume-tier discounts above the list anchor but does not publish them, so treat larger bands as before-discount ceilings.

Rapid7 SKU reference

SKUPricingNotes
Incident Command Essentials$70.40/asset/yearAWS Marketplace list (retrieved 4 Aug 2026): $17,670.40/yr at the 251-asset minimum, 12-month contract. 90-day log retention, 13-month alert and audit retention. Core SIEM, log management, UEBA, detection library
Incident Command Advanced$96.80/asset/yearAWS Marketplace list (retrieved 4 Aug 2026): $24,296.80/yr at the 251-asset minimum. 180-day log retention. Adds extended retention and ransomware prevention
Incident Command Ultimate$123.20/asset/yearAWS Marketplace list (retrieved 4 Aug 2026): $30,923.20/yr at the 251-asset minimum. 180-day log retention. Adds EDR/NDR/IDS, deception, AI-SOC triage, unlimited automation
Insight Platform BundleInsightVM + InsightIDR + InsightConnectBundle pricing is quote-only; Rapid7 publishes no bundle rate
Managed Threat Complete (MDR)Quote-onlyRapid7's MDR product/bundle name, priced separately from standalone InsightIDR; 24/7 SOC. Rapid7 publishes no MDR list price

Five Rapid7 cost optimisations that genuinely work

Audit asset count rigorously

20-30% on per-asset

Rapid7's per-asset meter counts everything visible: ephemeral cloud workloads, decommissioned servers still in CMDB, dormant accounts. Quarterly asset audits routinely remove 20-30 percent of the count without losing real coverage. The cleanup is the single highest-leverage Rapid7 cost lever.

Bundle Insight Platform for VM + IDR

Negotiated, quote-only

Customers running InsightVM (vulnerability management) and InsightIDR separately leave bundle savings on the table. Insight Platform combined contracts price below standalone purchasing, plus operational simplification from a single console; Rapid7 publishes no bundle rate, so size the saving in the quote.

Right-size MDR coverage scope

30-50% on managed service

MDR pricing scales with asset count, but most customers do not need full 24/7 coverage on every asset. Limiting MDR scope to crown-jewel assets (production, payment, regulated) while running InsightIDR self-service on the rest typically halves the MDR bill without operational compromise.

Negotiate at multi-year renewal

15-20% list

Rapid7's renewal cycle is the credible negotiation pressure point. Multi-year commits at term renewal produce 15-20 percent off list. Quarter-end carries deeper discount potential, particularly Q4.

Drop low-value log sources

Operational, indirect

Unlike per-GB SIEMs, Rapid7's per-asset pricing does not directly reward log filtering. Indirectly, fewer log sources means simpler tuning and lower analyst hours per signal. Aggressive source prioritisation is operational discipline that compounds across multi-year contracts.

When Rapid7 InsightIDR is the right SIEM

InsightIDR wins decisively for mid-market organisations between 500 and 5,000 assets that want a bundled SIEM-EDR-UEBA stack with predictable per-asset pricing and a credible MDR upsell path. Cloud-native engineering teams, fast-growing technology companies, regional financial services firms, and mid-market healthcare networks all fit the profile cleanly. The Insight Platform bundle (InsightIDR + InsightVM + InsightConnect) is genuinely competitive against Sentinel-plus-Defender or Sumo-plus-Wiz consolidation pitches, particularly when vulnerability management is an active discipline.

InsightIDR loses where the asset-to-log-volume ratio is unfavourable (low asset count with very high log volume from cloud APIs and SaaS audit logs), where deep UEBA is the binding constraint (Exabeam or Securonix maintain depth advantages), or where the customer wants a single per-GB or data-cap meter rather than per-asset (Chronicle wins simplicity). The per-asset meter also rewards organisations with disciplined asset management and punishes those with sprawling, undocumented IT estates.

The 2026 competitive trajectory is favourable. Rapid7's MDR business has matured into a credible alternative to Arctic Wolf, eSentire, and CrowdStrike Falcon Complete for mid-market organisations that want managed augmentation without the full MSSP commitment. For mid-market buyers in 2026 weighing managed security service options, InsightIDR plus Rapid7 MDR is genuinely worth the competitive evaluation against the established MDR vendors.

FAQ

Common questions

How is Rapid7 InsightIDR priced in 2026?

Rapid7 now sells the InsightIDR-based SIEM packages under the Incident Command name, priced per asset per year. AWS Marketplace list rates (retrieved 4 August 2026) are $70.40 per asset per year for Essentials, $96.80 for Advanced, and $123.20 for Ultimate, on a 12-month contract with a 251-asset minimum, so the contract floor is $17,670 to $30,923 per year. A 500-asset mid-market deployment lands at roughly $35K on Essentials to $62K on Ultimate per year list, before bundle discount or multi-year commit. The per-asset model is structurally simpler than per-GB SIEM pricing and produces predictable budget outcomes for organisations whose asset count is stable and well-understood. The downside is that ephemeral cloud workloads, decommissioned-but-not-removed assets, and shadow-IT additions can quietly drive the count and the bill upward.

What is included in InsightIDR versus separate products?

InsightIDR includes SIEM (log collection, correlation, detection), endpoint detection (the Insight Agent), UEBA, deception technology, and basic SOAR via InsightConnect integration. Vulnerability management is sold separately as InsightVM; full SOAR workflows are InsightConnect. The Insight Platform bundle combines all three at a negotiated discount versus standalone purchasing; Rapid7 publishes no bundle rate, so the combined price is quote-only. For organisations buying SIEM-only, InsightIDR is the right SKU; for organisations also doing vulnerability management, the bundle math typically wins decisively.

How does Rapid7 MDR pricing work?

Rapid7's MDR offering is sold under the product name Managed Threat Complete, a co-managed security service that bundles InsightIDR with 24/7 SOC coverage; it is Rapid7's MDR offering itself, not an InsightIDR tier. Pricing is quoted separately from the standalone SIEM packages and Rapid7 publishes no MDR list price, so treat MDR as strictly quote-only. For organisations without internal SOC capacity, Managed Threat Complete is the path; for organisations with internal SOC, MDR scoped to crown-jewel assets while running self-service InsightIDR on the rest typically delivers better unit economics.

Is Rapid7 InsightIDR cheaper than Splunk?

On per-asset versus per-GB economics, the comparison depends on the asset-to-log-volume ratio. A 500-asset environment ingesting 50 GB per day pays roughly $48K on Advanced list (500 x $96.80/asset/yr) versus Splunk Cloud ES at roughly $50K base to $100K all-in. The same environment scaled to 5,000 assets at the same 50 GB per day pays roughly $352K on Essentials list (before the volume-tier discounts Rapid7 applies but does not publish) versus Splunk unchanged at roughly $100K, because Splunk meters log volume rather than assets. Rapid7 wins decisively in low-asset / high-log-volume environments and loses in high-asset / low-log-volume environments. Sampling actual asset count is the discipline that matters; assumed counts routinely produce wrong vendor comparisons.

Does InsightIDR include UEBA?

Yes. UEBA (user and entity behaviour analytics) is included in InsightIDR base licence, not sold as a separate add-on. The depth is moderate: comparable to Splunk Enterprise Security with the basic UEBA app or to Sentinel's built-in UEBA, but not matching Exabeam or Securonix specialist depth. For mid-market SOCs whose UEBA needs are basic-to-moderate, InsightIDR's bundled UEBA is genuinely sufficient. For deep insider-threat or privileged-access-monitoring use cases, Exabeam or Securonix maintain a content depth advantage that InsightIDR does not match.

Didn't find your answer?

Ask us. A real person reads every question and we answer the ones we can, with sources. If your question would help other readers, we may publish an anonymised version, with your permission. General reference only.

Ask a question

questions@siemcostcalculator.com

Updated 13 July 2026