Having run both in production, let me save you some time. "Feature parity" is a marketing fantasy. They're solving different problems.
Intercept X is a solid, traditional AV with decent EDR bolted on. You're paying for the Sophos ecosystem. Cortex is a true XDR platform built for SOC analysts. The cost per endpoint reflects this. Last I checked, Intercept X was around $45-$55 per endpoint for the full suite. Cortex will run you $60-$80, easy. You're not comparing apples to apples; you're comparing a Swiss Army knife to a scalpel.
If you just need to stop ransomware on your endpoints and have a managed service provider, Sophos is fine. If you have a security team that actually uses the telemetry for threat hunting, Cortex is the only real choice. The price gap is the feature gap. Don't let a sales rep tell you otherwise.
CRM is a necessary evil
I'm a security product manager at a 2000-person fintech, and we actually ran both in parallel for six months during a bake-off before standardizing.
**Real price per endpoint:** OP's numbers are directionally right but oversimplify the tiers. Sophos Intercept X Complete hit us at $38/endpoint for a three-year commitment, but that required bundling their firewall SKU. Palo Alto's Cortex XDR Pro, sold standalone, started at $67. The hidden adder is that Cortex's worthwhile features, like the third-party data ingestion, often push you into the $80+ "Premier" tier.
**Deployment and integration tax:** Deploying Cortex's agent is trivial, but the value is zero until you integrate your identity provider, firewall logs, and cloud telemetry. That's a 40-60 hour project for an engineer. Intercept X gives you a usable console after the agent installs; it's just less data.
**Where Intercept X breaks:** Its cloud management console, Central, is painfully slow for any real hunting. We clocked a 9-12 second load time when pivoting between endpoint details and the investigation timeline. For a SOC analyst clicking through dozens of alerts a day, that's a productivity killer.
**Where Cortex clearly wins:** The correlation engine that builds "incidents" out of disparate alerts actually works. In our test, it condensed 72 individual malware alerts from our email gateway and endpoints into 3 incidents tied to the same campaign. Intercept X left us with the 72 alerts, and an analyst had to manually connect them.
We went with Cortex, but only because we have a 5-person SOC team that lives in the tool. If you're a sub-500 person company without dedicated threat hunters, I'd recommend Sophos and use the cost difference to fund a managed detection and response service. Tell us your team size and whether you already have a SIEM.
But what about the edge case?