← All articles
Managed IT

What to Expect From a Managed IT Provider: A Buyer's Checklist

Not all managed IT agreements cover the same things. Use this checklist to compare MSPs on support, security, response times and contract terms before you sign.

Hiring a managed service provider (MSP) means handing over the systems your business runs on. Two proposals can look similar on price and be very different in what they actually cover. This checklist is what we would want answered if we were on your side of the table.

Support and response

  • What are the guaranteed response times? Ask for them in writing, by priority level. "Fast" isn't a service level.
  • How do users get help? Phone, email, a portal, chat? Can staff reach a real person during business hours?
  • Is after-hours support included, or billed separately? What counts as an emergency?
  • Is onsite support included if a problem can't be fixed remotely?

What's covered, and what's extra

The most common source of friction with an MSP is a surprise invoice. Get clear answers on:

  • Whether helpdesk support is unlimited or capped by hours
  • How new-employee setup, offboarding and moves are billed
  • Whether projects like server migrations or office moves are separate
  • Which third-party software licenses are bundled and which you pay for directly

Security should be built in, not bolted on

A modern managed IT agreement should include security as standard. Look for:

  • Endpoint detection and response (EDR) with 24/7 monitoring, not just antivirus
  • Automated patch management with reporting
  • Email security and phishing protection
  • Backup for servers, workstations and cloud apps like Microsoft 365, with regular restore testing
  • Multi-factor authentication rollout and enforcement
  • Security awareness training for staff

If a provider treats security as an optional add-on, ask how they'd handle a ransomware incident on a device they don't protect.

Visibility and reporting

  • Will you get regular reports on tickets, patching, backups and security alerts?
  • Is there a periodic business review where they recommend improvements and flag aging hardware?
  • Will they document your network, accounts and vendors, and will you own that documentation?

Compliance and industry fit

If you handle health information, government contracts, student data or payment cards, ask what experience the provider has with the requirements that apply to you, and how their tools and processes support audits. An MSP doesn't make you compliant by itself, but the right one makes it much easier.

Contract terms

  • How long is the initial term, and what does it cost to leave?
  • How is pricing calculated: per user, per device or flat rate? How does it change as you grow?
  • If you leave, will they hand over admin credentials, documentation and data in an orderly way?

Red flags

  • No written service levels
  • Admin passwords held only by the provider, with no access for you
  • No backup restore testing
  • Pressure to sign a long contract before an assessment of your environment

The bottom line

The right MSP should reduce your risk and your surprises, not just answer tickets. Ask for specifics, get the answers in writing, and pick the partner who explains things clearly.

CIRRUS provides managed IT services across Maryland, DC and Virginia, with security built into every plan. We're happy to answer every question on this list. Request a quote and we'll start with an assessment of your current setup.

Need a hand?

Want this handled for you?

CIRRUS runs IT, security and websites for organizations across Maryland, DC and Virginia. Tell us what you are working on and we will point you in the right direction.