automated EPP + EDR that stops breaches and ransomware in real time — even on an already-compromised device
FortiEDR delivers proactive attack-surface reduction, kernel-level machine-learning NGAV prevention, and real-time post-infection detection, defusing and automated response across Windows, macOS, Linux, mobile and legacy/OT systems — from one lightweight agent. Deploy in the cloud, on-premises, hybrid or air-gapped, add XDR and managed (MDR) services, and buy with live subscription pricing from a Canadian Fortinet specialist.

FortiEDR is Fortinet's endpoint detection and response platform — built from the ground up to detect advanced threats and stop breaches and ransomware in real time, even on an already-compromised device. A single lightweight agent combines proactive attack-surface reduction, kernel-level machine-learning NGAV prevention, and post-infection detection, defusing and automated response, all managed from a unified cloud (or on-premises) console. It protects workstations, servers, cloud workloads, mobile, and legacy/OT systems with a flat per-device cost, and is the base for FortiXDR. Proven in MITRE ATT&CK and SE Labs testing, and certified to ISO 27001/27017/27018, SOC 2 Type II, PCI DSS and HIPAA.
Vulnerability assessment, device/IoT discovery, virtual patching and application control shrink the attack surface before anything runs.
A kernel-level, machine-learning anti-malware engine stops ransomware and advanced attacks before execution, online or offline.
Real-time detection defuses file-less and living-off-the-land attacks by blocking exfiltration and C2 the instant behaviour turns malicious.
Automated playbooks roll back malicious changes, terminate processes and isolate devices — preserving uptime, no VSS reliance.
Patented code-tracing gives full attack-chain visibility mapped to MITRE ATT&CK, with threat hunting via TAXII/IoC import.
Out-of-the-box detect-and-defuse plus playbook automation cut mean-time-to-respond and eliminate alert fatigue.
One agent under 1-2% CPU covers Windows (back to XP), macOS, Linux, VDI, mobile, POS and OT with full feature parity.
Native cloud multi-tenant management, or deploy on-premises, hybrid or fully air-gapped for sensitive networks.
FortiEDR is licensed per endpoint on a flat, predictable cost. Pick a tier by how much of the prevent-detect-respond lifecycle you want, then layer on XDR or a managed (MDR) service. Start here, then jump to live pricing.
XDR extends detection and correlation across your Fortinet fabric and third-party tools. MDR (FortiGuard Managed Detection & Response) adds 24x7 monitoring, alert triage and incident handling by Fortinet analysts — available as Basic, Standard or fully Managed XDR on the tiers below.
All tiers use the same single lightweight agent and cloud management with FortiCare Premium 24x7. The difference is how much of the discover-prevent-detect-respond lifecycle is included.
| Capability | Discover & Protect | Protect & Respond | Discover, Protect & Respond |
|---|---|---|---|
| Attack-surface reduction & risk mitigation (Discover) | ✓ | — | ✓ |
| Vulnerability assessment, virtual patching, app control | ✓ | — | ✓ |
| Device / IoT / rogue-asset discovery | ✓ | — | ✓ |
| Kernel-level ML NGAV, pre-infection prevention (Protect) | ✓ | ✓ | ✓ |
| Real-time detect, defuse & respond (EDR / Respond) | — | ✓ | ✓ |
| Automated response, remediation & rollback | — | ✓ | ✓ |
| Threat hunting & forensic investigation | — | ✓ | ✓ |
| XDR add-on available | — | ✓ | ✓ |
| Managed Detection & Response (MDR) available | Basic | ✓ | ✓ |
| On-premises & air-gapped deployment | — | — | ✓ |
| Cloud management + FortiCare Premium 24x7 | ✓ | ✓ | ✓ |
Prices are live in your selected currency. FortiEDR licenses are delivered electronically worldwide, usually within hours. Choose a tier, then the endpoint pack and term; XDR and MDR variants are shown inside each tier. Minimum seat quantities apply and a Best Practice Service is required on new orders (both below). Need a size between the packs? Request a quote.
Expand a tier to buy by endpoint pack (25 / 500 / 2,000 / 10,000) with live 1, 3 and 5-year pricing. XDR and MDR variants are inside each tier.

The endpoint-protection (EPP) tier. Proactively shrinks the attack surface with vulnerability assessment, device/IoT discovery, virtual patching and application control, then blocks attacks before execution with a kernel-level, machine-learning NGAV engine. The right starting point for prevention-first endpoint security.
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-350-01-12 | View productFC1-10-FEDR1-350-01-36 | View productFC1-10-FEDR1-350-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-350-01-12 | View productFC2-10-FEDR1-350-01-36 | View productFC2-10-FEDR1-350-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-350-01-12 | View productFC3-10-FEDR1-350-01-36 | View productFC3-10-FEDR1-350-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-350-01-12 | View productFC4-10-FEDR1-350-01-36 | View productFC4-10-FEDR1-350-01-60 |
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-391-01-12 | View productFC1-10-FEDR1-391-01-36 | View productFC1-10-FEDR1-391-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-391-01-12 | View productFC2-10-FEDR1-391-01-36 | View productFC2-10-FEDR1-391-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-391-01-12 | View productFC3-10-FEDR1-391-01-36 | View productFC3-10-FEDR1-391-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-391-01-12 | View productFC4-10-FEDR1-391-01-36 | View productFC4-10-FEDR1-391-01-60 |
Cloud subscription incl. FortiCare Premium 24x7 · 100-seat minimum · 2 & 4-year terms on request — ask for a quote.

The detection-and-response (EDR) tier. Combines the NGAV prevention layer with real-time, post-infection detection that defuses file-less and living-off-the-land attacks even on an already compromised device — then orchestrates automated response and remediation with playbooks, rollback and threat hunting. Add XDR or a managed (MDR) service.
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-351-01-12 | View productFC1-10-FEDR1-351-01-36 | View productFC1-10-FEDR1-351-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-351-01-12 | View productFC2-10-FEDR1-351-01-36 | View productFC2-10-FEDR1-351-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-351-01-12 | View productFC3-10-FEDR1-351-01-36 | View productFC3-10-FEDR1-351-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-351-01-12 | View productFC4-10-FEDR1-351-01-36 | View productFC4-10-FEDR1-351-01-60 |
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-393-01-12 | View productFC1-10-FEDR1-393-01-36 | View productFC1-10-FEDR1-393-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-393-01-12 | View productFC2-10-FEDR1-393-01-36 | View productFC2-10-FEDR1-393-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-393-01-12 | View productFC3-10-FEDR1-393-01-36 | View productFC3-10-FEDR1-393-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-393-01-12 | View productFC4-10-FEDR1-393-01-36 | View productFC4-10-FEDR1-393-01-60 |
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-392-01-12 | View productFC1-10-FEDR1-392-01-36 | View productFC1-10-FEDR1-392-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-392-01-12 | View productFC2-10-FEDR1-392-01-36 | View productFC2-10-FEDR1-392-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-392-01-12 | View productFC3-10-FEDR1-392-01-36 | View productFC3-10-FEDR1-392-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-392-01-12 | View productFC4-10-FEDR1-392-01-36 | View productFC4-10-FEDR1-392-01-60 |
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-596-01-12 | View productFC1-10-FEDR1-596-01-36 | View productFC1-10-FEDR1-596-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-596-01-12 | View productFC2-10-FEDR1-596-01-36 | View productFC2-10-FEDR1-596-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-596-01-12 | View productFC3-10-FEDR1-596-01-36 | View productFC3-10-FEDR1-596-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-596-01-12 | View productFC4-10-FEDR1-596-01-36 | View productFC4-10-FEDR1-596-01-60 |
Cloud subscription incl. FortiCare Premium 24x7 · 500-seat minimum · 2 & 4-year terms on request — ask for a quote.

The complete FortiEDR platform — every capability in one lightweight agent: attack-surface discovery and risk mitigation, kernel-level NGAV prevention, and real-time EDR detection, defusing, automated response and remediation. Deploy in the cloud, on-premises, hybrid or fully air-gapped, with optional XDR and managed services.
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-348-01-12 | View productFC1-10-FEDR1-348-01-36 | View productFC1-10-FEDR1-348-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-348-01-12 | View productFC2-10-FEDR1-348-01-36 | View productFC2-10-FEDR1-348-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-348-01-12 | View productFC3-10-FEDR1-348-01-36 | View productFC3-10-FEDR1-348-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-348-01-12 | View productFC4-10-FEDR1-348-01-36 | View productFC4-10-FEDR1-348-01-60 |
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-394-01-12 | View productFC1-10-FEDR1-394-01-36 | View productFC1-10-FEDR1-394-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-394-01-12 | View productFC2-10-FEDR1-394-01-36 | View productFC2-10-FEDR1-394-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-394-01-12 | View productFC3-10-FEDR1-394-01-36 | View productFC3-10-FEDR1-394-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-394-01-12 | View productFC4-10-FEDR1-394-01-36 | View productFC4-10-FEDR1-394-01-60 |
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-349-01-12 | View productFC1-10-FEDR1-349-01-36 | View productFC1-10-FEDR1-349-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-349-01-12 | View productFC2-10-FEDR1-349-01-36 | View productFC2-10-FEDR1-349-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-349-01-12 | View productFC3-10-FEDR1-349-01-36 | View productFC3-10-FEDR1-349-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-349-01-12 | View productFC4-10-FEDR1-349-01-36 | View productFC4-10-FEDR1-349-01-60 |
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-597-01-12 | View productFC1-10-FEDR1-597-01-36 | View productFC1-10-FEDR1-597-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-597-01-12 | View productFC2-10-FEDR1-597-01-36 | View productFC2-10-FEDR1-597-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-597-01-12 | View productFC3-10-FEDR1-597-01-36 | View productFC3-10-FEDR1-597-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-597-01-12 | View productFC4-10-FEDR1-597-01-36 | View productFC4-10-FEDR1-597-01-60 |
Cloud subscription incl. FortiCare Premium 24x7 · 500-seat minimum · 2 & 4-year terms on request — ask for a quote.
The full Discover, Protect & Respond platform, self-hosted for teams that cannot use the public cloud.
Prefer to keep the FortiEDR management console on your own infrastructure? The full Discover, Protect & Respond platform is available as an on-premises (internet-connected) or fully air-gapped deployment for the most sensitive and regulated environments.
Run the FortiEDR management console on-premises while still using Fortinet Cloud Services for classification.
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-352-01-12 | View productFC1-10-FEDR1-352-01-36 | View productFC1-10-FEDR1-352-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-352-01-12 | View productFC2-10-FEDR1-352-01-36 | View productFC2-10-FEDR1-352-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-352-01-12 | View productFC3-10-FEDR1-352-01-36 | View productFC3-10-FEDR1-352-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-352-01-12 | View productFC4-10-FEDR1-352-01-36 | View productFC4-10-FEDR1-352-01-60 |
Fully isolated deployment for networks with no internet access, for the most sensitive environments.
| Endpoints | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| 25 endpoints | View productFC1-10-FEDR1-1362-01-12 | View productFC1-10-FEDR1-1362-01-36 | View productFC1-10-FEDR1-1362-01-60 |
| 500 endpoints | View productFC2-10-FEDR1-1362-01-12 | View productFC2-10-FEDR1-1362-01-36 | View productFC2-10-FEDR1-1362-01-60 |
| 2,000 endpoints | View productFC3-10-FEDR1-1362-01-12 | View productFC3-10-FEDR1-1362-01-36 | View productFC3-10-FEDR1-1362-01-60 |
| 10,000 endpoints | View productFC4-10-FEDR1-1362-01-12 | View productFC4-10-FEDR1-1362-01-36 | View productFC4-10-FEDR1-1362-01-60 |
Extend data retention for longer threat-hunting history, and add the required guided-deployment service.
| Repository add-on | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| Additional 512 GB data retention Extends EDR data-retention storage for longer threat-hunting history. | View productFC1-10-FEDR1-1112-01-12 | View productFC1-10-FEDR1-1112-01-36 | View productFC1-10-FEDR1-1112-01-60 |
| Coverage tier | 1 Yr | 3 Yr | 5 Yr |
|---|---|---|---|
| Up to 500 endpoints/users | View productFC0-10-EDBPS-310-02-12 | View productFC0-10-EDBPS-310-02-36 | View productFC0-10-EDBPS-310-02-60 |
| 501 - 1,000 endpoints/users | View productFC1-10-EDBPS-310-02-12 | View productFC1-10-EDBPS-310-02-36 | View productFC1-10-EDBPS-310-02-60 |
| 1,001 - 3,000 endpoints/users | View productFC2-10-EDBPS-310-02-12 | View productFC2-10-EDBPS-310-02-36 | View productFC2-10-EDBPS-310-02-60 |
| 3,001 - 10,000 endpoints/users | View productFC3-10-EDBPS-310-02-12 | View productFC3-10-EDBPS-310-02-36 | View productFC3-10-EDBPS-310-02-60 |
| 10,001 - 30,000 endpoints/users | View productFC5-10-EDBPS-310-02-12 | View productFC5-10-EDBPS-310-02-36 | View productFC5-10-EDBPS-310-02-60 |

Every Fortinet purchase from DataCenter360.ca is backed by hands-on services across the full lifecycle — from rollout to round-the-clock protection.
FortiEDR protects nearly everything and shares its endpoint intelligence across the Fortinet Security Fabric and third-party tools for coordinated, automated response.
Shares endpoint threat intelligence with the firewall and can instruct response actions such as blocking or suspending an IP after an attack.
Shares discovered assets and threat intel; can isolate a compromised device to a remediation VLAN via Syslog actions.
Auto-submits suspicious files for detonation and streams events/alerts to FortiSIEM with an out-of-the-box parser and REST APIs.
Feeds endpoint status into ZTNA posture checks and device tagging, tightening zero-trust access decisions.
Fortinet Select Partner and MSSP, FCP-certified. Genuine subscriptions registered correctly the first time.
FortiEDR subscriptions are electronic and delivered worldwide, usually within hours of purchase.
Add FortiGuard MDR, or have our own team help deploy, tune and run FortiEDR for you.
Talk to an FCP-certified engineer who will size the right tier, seat count and services for your environment.
Tell us your endpoint count, the OS mix (including any legacy/OT) and whether you want a managed service. We will size the licensing and quote it, usually same day.
FortiEDR is Fortinet's endpoint detection and response platform. A single lightweight agent combines proactive attack-surface reduction, kernel-level machine-learning NGAV prevention, and real-time post-infection detection, defusing, automated response and remediation — stopping breaches and ransomware in real time even on an already-compromised device, and forming the base for FortiXDR.
Discover & Protect is the EPP tier: attack-surface reduction plus ML NGAV prevention. Protect & Respond is the EDR tier: NGAV prevention plus real-time detection, defusing, automated response and threat hunting. Discover, Protect & Respond is the complete platform with all three, and is the only tier available on-premises or air-gapped. XDR and MDR can be added to the response tiers.
XDR extends detection and correlation across your Fortinet Security Fabric and third-party tools for a broader picture than endpoint alone. MDR (FortiGuard Managed Detection & Response) is a managed service where Fortinet analysts provide 24x7 monitoring, alert triage and incident handling. FortiEDR offers Basic MDR, Standard MDR and fully Managed XDR variants depending on tier.
Yes. FortiEDR is cloud-native but the Discover, Protect & Respond platform can also run on-premises (internet-connected, using Fortinet Cloud Services for classification) or in a fully air-gapped deployment for isolated, highly sensitive networks. Endpoints stay protected on- and off-line through onboard AI.
Yes. FortiEDR includes a kernel-level machine-learning NGAV engine that replaces traditional antivirus, plus EDR detection and response on top. One lightweight agent (under 1-2% CPU) covers current and legacy operating systems — back to Windows XP and Server 2003 — as well as POS, manufacturing controllers and OT systems with full feature parity.
FortiEDR has minimum seat quantities — typically 100 seats for Discover & Protect and 500 seats for the response tiers. Fortinet also requires a Best Practice Service (BPS) on every new order: a guided-deployment service covering architecture, configuration, playbook set-up, tuning and training so your rollout succeeds. We include the correct BPS tier when we quote.
FortiEDR is software, so there is nothing to ship. Licenses are delivered electronically worldwide as an Authorized Fortinet Select Partner, usually within hours of purchase. We can also help register the entitlement, stand up your console and tune your first policies.
DataCenter360.ca is an Authorized Fortinet Select Partner. Capabilities shown are from the FortiEDR datasheet (April 2025) and the FortiEDR ordering guide (2026). Pricing is live from our catalogue and may vary with currency and promotions. FortiEDR, FortiXDR, FortiGate, FortiGuard, FortiCare and FortiClient are trademarks of Fortinet, Inc.