In this guide
- What a managed service provider is
- Why businesses use managed IT services
- Signs your business needs an MSP
- An MSP vs the alternatives
- What MSP services include
- How MSP pricing works
- Choosing an MSP is a cybersecurity and compliance decision
- What to look for in a managed service provider
- Questions to ask an MSP before you sign
- Red flags when choosing an MSP
- The MSP contract and service level agreement
- A simple scorecard for comparing proposals
- What MSP onboarding should look like
- FAQ
The IT buyers guide: how to choose a managed service provider and the tools behind it
This IT buyers guide is for the person who has to spend the money: an owner, an office manager or an IT lead deciding whether to outsource IT, which managed service provider to trust with it, and what the contract should say.
The technical pages elsewhere in this library explain how things work. This one explains how to buy them without being sold to.
It covers the decision in order: what a managed service provider is, the signs you need one, the alternatives, what MSP services include, how pricing works, what to look for, the questions to ask, the red flags, the contract and service level agreement, a scorecard for comparing proposals, and what onboarding should look like. Each section links to a full page in this library.
DefinitionWhat a managed service provider is
A managed service provider, or MSP, is an outside company that takes ongoing responsibility for some or all of an organization's IT, for a recurring fee. The word that matters is ongoing.
An MSP monitors, patches, backs up and supports your systems continuously and is paid to keep them working, which is the opposite of a repair shop that is paid when they break.
What an MSP is covers the model in depth, and IT outsourcing covers the wider decision of what to keep in house. A provider that specializes in security monitoring and response is a managed security service provider; what an MSSP is explains the difference, which matters because many MSPs sell security services they subcontract.
The caseWhy businesses use managed IT services
A business does not buy managed services because it enjoys technology. It buys them because IT has become infrastructure the business cannot run without, and because staffing it properly costs more than most small and midsize businesses can justify. The reasons owners give are consistent:
- Predictable costs: a fixed monthly fee in place of surprise repair bills and emergency call-outs, which makes IT a line in the budget.
- Access to a team: networking, cloud, cybersecurity and compliance skills that no single employee has, available without hiring for each.
- Support when staff need it: a help desk that answers, including outside office hours.
- Less downtime: problems found by monitoring and fixed before they stop work.
- Strategic guidance: someone who plans technology around where the business is going, not only around what broke this week.
- Room to focus: the people who were doing IT on the side go back to the jobs they were hired for.
The right managed service provider delivers those. The wrong one delivers an invoice, which is the reason for the rest of this guide.
TimingSigns your business needs an MSP
- IT is somebody's second job, and it is taking over their first.
- You find out about problems from users, not from monitoring.
- Nobody has tested a restore, or knows for certain where the backups are.
- Patching happens when someone remembers.
- A customer, an insurer or a regulator has asked for security controls you cannot show.
- Your one IT person cannot take a holiday without the business holding its breath.
- You are growing, opening an office, or moving to the cloud, and need skills for a project and not for a career.
OptionsAn MSP vs the alternatives
An MSP is one of five ways to get IT done, and the right answer depends on size and on how much control you want to keep.
| Model | How it works | Suits | Weakness |
|---|---|---|---|
| In-house IT | Your own employees run everything | Organizations large enough to staff several roles | One or two people cannot cover every skill, or every hour |
| Break-fix | You call a technician when something fails and pay by the hour | Very small offices with simple needs | Nobody is preventing problems, and the provider earns more when you have them |
| Fully managed (MSP) | The provider runs your IT for a recurring fee | Small and midsize organizations with no IT department | You depend on the provider's quality, so the choice matters |
| Co-managed IT | The MSP works alongside your internal IT team, taking the monitoring, tools or projects they lack time for | Organizations with an IT person or a small team | Needs a clear line between who does what |
| MSSP | A specialist handles security monitoring and response only | Anyone whose IT is covered and whose security is not | Does not fix printers or onboard staff |
The financial side of the choice, a salary and equipment you own against a monthly fee, is the subject of capex vs opex in IT.
ScopeWhat MSP services include
Managed IT services are sold as a bundle, and the bundles differ. These are the services to look for, and to check whether each is included or charged separately:
| Service | What you should get | Read more |
|---|---|---|
| Help desk | A number and a portal your staff can use, with stated hours and response times | |
| Monitoring and patching | Every device watched and updated through a remote management tool | What RMM is |
| Backup and disaster recovery | Backups that are monitored, tested and kept off site, with stated recovery times | Backup and disaster recovery |
| Cybersecurity | Endpoint protection, MFA, email filtering, and someone watching the alerts | The security library |
| Network management | Firewall, switches, Wi-Fi and the internet connection | Network management software, managed ISP |
| Cloud and Microsoft 365 or Google Workspace | Licensing, administration, security settings and backup of cloud data | Google Workspace vs Microsoft 365 |
| Strategy | A named person who plans budgets and replacements with you | What a vCIO is |
| Vendor management | The provider deals with your software, telecom and hardware suppliers for you |
Two internal tools shape the service you receive, and a good provider will tell you which it uses: the RMM that manages your devices, and the PSA that runs its tickets and billing. The software rankings score the main products in both categories.
CostHow MSP pricing works
Providers price in a small number of ways, and a proposal is only comparable with another once you know which one it uses:
- Per user: a monthly fee for each person supported, covering their devices. The most common model, and the easiest to budget because it follows headcount.
- Per device: a monthly fee for each workstation, server and network device. It suits organizations with shared computers or many machines per person.
- Tiered packages: bronze, silver and gold style bundles with more services at each level. Read what the lowest tier leaves out.
- All-inclusive, flat fee: one price for everything in scope, which removes the provider's incentive to bill for incidents.
- A la carte: individual services priced separately, useful in a co-managed arrangement.
What drives the number is the count of users and devices, the hours of cover, the security and compliance scope, and the state your environment is in when the provider inherits it.
Ask every bidder to price the same scope, and ask separately for onboarding fees, project rates, on-site visit charges and anything billed outside the agreement, because that is where proposals that look alike come apart.
RiskChoosing an MSP is a cybersecurity and compliance decision
Whoever manages your IT infrastructure holds administrator access to all of it, so the provider's security is your security. Attackers know this, and a compromised provider is a route into every business it serves. Treat the choice as a cybersecurity decision first and a support decision second.
- Ask what is included in the base service: endpoint protection, MFA enforcement, email security, patching and monitored backups should not be optional extras.
- Ask how the provider protects itself: MFA on its own tools, separate technician accounts, logging of technician access, and cyber liability insurance. An independent audit report, such as SOC 2, is evidence that its controls have been examined by a third party.
- Match the provider to your industry. Compliance rules differ by industry: healthcare practices fall under HIPAA, anyone taking card payments under PCI DSS, defense contractors under CMMC, and financial firms under their own regulators. A provider with clients in your industry already knows what an auditor will ask for.
- Ask who does the security work. If monitoring and response are resold from a third party, find out which one, and who calls you at three in the morning.
- Expect help with cyber insurance. Insurers ask detailed questions about controls, and a capable provider can answer them and supply the evidence.
The cybersecurity services pages list providers that offer security as a service of its own.
CriteriaWhat to look for in a managed service provider
- A company that verifiably exists: a registered business, a real office and a phone that is answered. Our directory publishes those checks for every listing.
- Experience with businesses like yours: the same size, the same industry, the same line-of-business software and the same compliance rules.
- Its own security: an MSP holds the keys to every client, which makes it a target. Ask how it protects its own tools and staff accounts.
- A defined service: response times, hours and scope written down, not described in a meeting.
- Documentation you own: passwords, diagrams and configurations recorded, and handed over if you leave.
- Proactive support you can see: regular reports, patching and backup results, and strategic reviews of your technology, not silence between tickets.
- References you can call, of your size, who have been clients for more than a year.
- A local presence if you need on-site help. Browse managed IT services by city.
Due diligenceQuestions to ask an MSP before you sign
- What exactly is included in the monthly fee, and what is billed separately?
- What are your response and resolution times, by priority, and what happens when you miss them?
- Who answers the phone out of hours, and is that your staff or a subcontractor?
- How do you secure your own remote management tools and technician accounts?
- How often do you test our backups, and will you show us the result?
- Who owns the documentation, the admin accounts and the licenses if we part ways?
- What does onboarding involve, how long does it take, and what will you need from us?
- Who will be our named contact, and how often will we review the service together?
- Which security services do you deliver yourselves, and which do you resell?
- What are the contract length, the renewal terms and the notice period?
WarningsRed flags when choosing an MSP
- A quote with no assessment: a price given before anyone has looked at your environment is a guess, or a template.
- Vague scope: phrases such as "full support" with no list of what that means.
- Long lock-in with no exit: multi-year terms, automatic renewal and no clause about handing over your data and passwords.
- They keep the keys: reluctance to give you administrator credentials to your own systems.
- No security answers: a provider that cannot describe its own controls will not manage yours.
- Everything is reactive: no mention of monitoring, patching reports or reviews.
- References that cannot be reached, or that are all very recent.
PaperworkThe MSP contract and service level agreement
The agreement is where the sales conversation becomes enforceable. It usually has two parts: a master services agreement with the legal terms, and a service level agreement, or SLA, with the measurable promises. Check that these are written down:
- Scope: the users, devices, sites and services covered, and what is explicitly excluded.
- Service levels: response and resolution targets by priority, hours of cover, and the remedy when they are missed.
- Security and compliance responsibilities: who does what, including breach notification.
- Data ownership and exit: your data, documentation and credentials returned within a stated time, and help with the transition.
- Term, renewal and termination: the length, the notice period and the fees, if any, for leaving early.
- Price changes: how and when the fee can rise, and how adding or removing users is handled.
- Liability and insurance: the provider's cyber and professional liability cover.
ComparisonA simple scorecard for comparing proposals
Score each provider from 1 to 5 on the same criteria, and weight the ones that matter most to you. It turns three impressive presentations into a decision you can explain.
| Criterion | What a 5 looks like |
|---|---|
| Scope clarity | A written list of inclusions and exclusions that matches what you asked for |
| Service levels | Response and resolution times by priority, with a remedy |
| Security | Clear answers about its own controls and yours, with evidence |
| Relevant experience | Clients of your size and sector, willing to talk to you |
| Transparency | You hold admin access and documentation from day one |
| Exit terms | Reasonable notice, and a handover written into the contract |
| Total cost | Monthly fee plus onboarding, projects and out-of-scope rates, all stated |
To collect proposals to score, request up to three quotes from listed providers that cover your city.
First 90 daysWhat MSP onboarding should look like
- Discovery: an inventory of every device, account, license and vendor, and a record of the passwords.
- Tool deployment: the monitoring agent, endpoint protection and backup installed everywhere. If you use Macs, ask about RMM for Mac.
- Stabilization: the urgent fixes, such as missing patches, failed backups and accounts of people who have left.
- Documentation and a plan: the environment written up, including any legacy systems that need replacing, with a roadmap and budget.
- Introduction to staff: how to ask for help, and what to expect.
- First review: a meeting at around 90 days to compare the service with what was promised.
That review closes the loop this IT buyers guide opened: you defined what you needed, compared providers on the same terms, put the promises in a contract, and now you check them against what was delivered.
