Description
Sophos Next-Gen SIEM, 1000-1999 users and servers
Next-Gen SIEM adds long-term log retention and audit-ready compliance reporting to Sophos XDR and MDR. This listing covers the 1000-1999 band, counted across users and servers together.
The band counts users and servers combined. Forty staff plus twelve servers is fifty-two, which lands in the 50-99 band even though headcount alone says 25-49. Getting this wrong is the most common sizing error on this product.
What it adds to XDR and MDR
- Long-term log retention. Detection tooling keeps data for its working window. Auditors ask for considerably longer.
- Audit-ready compliance reporting. Reports aimed at ISO 27001, PCI DSS, HIPAA, GDPR and SOC 2 assessments, rather than raw log exports somebody has to interpret.
- One console. It sits inside the Sophos platform rather than beside it, so retention and detection are not two separate systems to reconcile.
What it is not
This is not a standalone SIEM. It extends Sophos XDR or MDR and assumes one of those is in place. If you are looking to replace a third-party SIEM outright and you do not run Sophos detection underneath, this is the wrong product and we will tell you so rather than sell it to you.
When it earns its place
Usually when an auditor, an insurer or a customer contract asks how long you keep security logs and whether you can produce a report on demand. If nobody is asking that question yet, XDR or MDR alone may be enough for now.
Frequently asked questions
How is Sophos Next-Gen SIEM licensed?
By the combined count of users and servers, not users alone. A 40 person office running 12 servers is 52, which puts it in the 50-99 band rather than 25-49. Count both before choosing a band.
Do I need Sophos XDR or MDR as well?
Yes. Next-Gen SIEM extends XDR and MDR with long-term retention and compliance reporting. It is not a standalone SIEM and does not replace the detection layer underneath it.
What does it add that XDR does not already do?
Retention and reporting. XDR keeps detection data for its own working window. Next-Gen SIEM holds logs long enough to satisfy an audit and produces the reports that ISO 27001, PCI DSS, HIPAA, GDPR and SOC 2 assessments ask for.
Was this previously called Agentic SIEM?
No. Agentic SIEM is TrendAI's product. The Sophos product has always been Next-Gen SIEM, sometimes shortened to NG-SIEM. If you have seen the two used interchangeably, they are different vendors.
What if my count sits on a band boundary?
Ask us before ordering. Rates change across bands, and a count of 99 against 100 can change the per-unit cost. It is also worth allowing for growth within the term rather than buying to today's exact number.
Get this quoted by Nuformat
Nuformat is a Sophos partner serving Canada and the United States. Send us your user and server count and which retention period your auditor expects, and we will confirm the band and quote it, usually in two to three business days.
Request a quoteCapabilities as published by Sophos. Pricing confirmed by Nuformat at the time of quotation.

