The IT Buyers Guide: How to Choose a Managed Service Provider

16 concepts · 1 comparisons · 16 updated this month

An IT buyers guide for choosing a managed service provider: what MSPs do, the alternatives, pricing models, questions to ask, red flags, and the contract.

5ways to get IT done, compared side by side
10questions to ask before you sign
7criteria on the proposal scorecard
90 daysto the first review of the service
In this guide

The IT buyers guide: how to choose a managed service provider and the tools behind it

This IT buyers guide is for the person who has to spend the money: an owner, an office manager or an IT lead deciding whether to outsource IT, which managed service provider to trust with it, and what the contract should say.

The technical pages elsewhere in this library explain how things work. This one explains how to buy them without being sold to.

It covers the decision in order: what a managed service provider is, the signs you need one, the alternatives, what MSP services include, how pricing works, what to look for, the questions to ask, the red flags, the contract and service level agreement, a scorecard for comparing proposals, and what onboarding should look like. Each section links to a full page in this library.

DefinitionWhat a managed service provider is

A managed service provider, or MSP, is an outside company that takes ongoing responsibility for some or all of an organization's IT, for a recurring fee. The word that matters is ongoing.

An MSP monitors, patches, backs up and supports your systems continuously and is paid to keep them working, which is the opposite of a repair shop that is paid when they break.

What an MSP is covers the model in depth, and IT outsourcing covers the wider decision of what to keep in house. A provider that specializes in security monitoring and response is a managed security service provider; what an MSSP is explains the difference, which matters because many MSPs sell security services they subcontract.

The caseWhy businesses use managed IT services

A business does not buy managed services because it enjoys technology. It buys them because IT has become infrastructure the business cannot run without, and because staffing it properly costs more than most small and midsize businesses can justify. The reasons owners give are consistent:

  • Predictable costs: a fixed monthly fee in place of surprise repair bills and emergency call-outs, which makes IT a line in the budget.
  • Access to a team: networking, cloud, cybersecurity and compliance skills that no single employee has, available without hiring for each.
  • Support when staff need it: a help desk that answers, including outside office hours.
  • Less downtime: problems found by monitoring and fixed before they stop work.
  • Strategic guidance: someone who plans technology around where the business is going, not only around what broke this week.
  • Room to focus: the people who were doing IT on the side go back to the jobs they were hired for.

The right managed service provider delivers those. The wrong one delivers an invoice, which is the reason for the rest of this guide.

TimingSigns your business needs an MSP

  • IT is somebody's second job, and it is taking over their first.
  • You find out about problems from users, not from monitoring.
  • Nobody has tested a restore, or knows for certain where the backups are.
  • Patching happens when someone remembers.
  • A customer, an insurer or a regulator has asked for security controls you cannot show.
  • Your one IT person cannot take a holiday without the business holding its breath.
  • You are growing, opening an office, or moving to the cloud, and need skills for a project and not for a career.

OptionsAn MSP vs the alternatives

An MSP is one of five ways to get IT done, and the right answer depends on size and on how much control you want to keep.

ModelHow it worksSuitsWeakness
In-house ITYour own employees run everythingOrganizations large enough to staff several rolesOne or two people cannot cover every skill, or every hour
Break-fixYou call a technician when something fails and pay by the hourVery small offices with simple needsNobody is preventing problems, and the provider earns more when you have them
Fully managed (MSP)The provider runs your IT for a recurring feeSmall and midsize organizations with no IT departmentYou depend on the provider's quality, so the choice matters
Co-managed ITThe MSP works alongside your internal IT team, taking the monitoring, tools or projects they lack time forOrganizations with an IT person or a small teamNeeds a clear line between who does what
MSSPA specialist handles security monitoring and response onlyAnyone whose IT is covered and whose security is notDoes not fix printers or onboard staff

The financial side of the choice, a salary and equipment you own against a monthly fee, is the subject of capex vs opex in IT.

ScopeWhat MSP services include

Managed IT services are sold as a bundle, and the bundles differ. These are the services to look for, and to check whether each is included or charged separately:

ServiceWhat you should getRead more
Help deskA number and a portal your staff can use, with stated hours and response times
Monitoring and patchingEvery device watched and updated through a remote management toolWhat RMM is
Backup and disaster recoveryBackups that are monitored, tested and kept off site, with stated recovery timesBackup and disaster recovery
CybersecurityEndpoint protection, MFA, email filtering, and someone watching the alertsThe security library
Network managementFirewall, switches, Wi-Fi and the internet connectionNetwork management software, managed ISP
Cloud and Microsoft 365 or Google WorkspaceLicensing, administration, security settings and backup of cloud dataGoogle Workspace vs Microsoft 365
StrategyA named person who plans budgets and replacements with youWhat a vCIO is
Vendor managementThe provider deals with your software, telecom and hardware suppliers for you

Two internal tools shape the service you receive, and a good provider will tell you which it uses: the RMM that manages your devices, and the PSA that runs its tickets and billing. The software rankings score the main products in both categories.

CostHow MSP pricing works

Providers price in a small number of ways, and a proposal is only comparable with another once you know which one it uses:

  • Per user: a monthly fee for each person supported, covering their devices. The most common model, and the easiest to budget because it follows headcount.
  • Per device: a monthly fee for each workstation, server and network device. It suits organizations with shared computers or many machines per person.
  • Tiered packages: bronze, silver and gold style bundles with more services at each level. Read what the lowest tier leaves out.
  • All-inclusive, flat fee: one price for everything in scope, which removes the provider's incentive to bill for incidents.
  • A la carte: individual services priced separately, useful in a co-managed arrangement.

What drives the number is the count of users and devices, the hours of cover, the security and compliance scope, and the state your environment is in when the provider inherits it.

Ask every bidder to price the same scope, and ask separately for onboarding fees, project rates, on-site visit charges and anything billed outside the agreement, because that is where proposals that look alike come apart.

RiskChoosing an MSP is a cybersecurity and compliance decision

Whoever manages your IT infrastructure holds administrator access to all of it, so the provider's security is your security. Attackers know this, and a compromised provider is a route into every business it serves. Treat the choice as a cybersecurity decision first and a support decision second.

  • Ask what is included in the base service: endpoint protection, MFA enforcement, email security, patching and monitored backups should not be optional extras.
  • Ask how the provider protects itself: MFA on its own tools, separate technician accounts, logging of technician access, and cyber liability insurance. An independent audit report, such as SOC 2, is evidence that its controls have been examined by a third party.
  • Match the provider to your industry. Compliance rules differ by industry: healthcare practices fall under HIPAA, anyone taking card payments under PCI DSS, defense contractors under CMMC, and financial firms under their own regulators. A provider with clients in your industry already knows what an auditor will ask for.
  • Ask who does the security work. If monitoring and response are resold from a third party, find out which one, and who calls you at three in the morning.
  • Expect help with cyber insurance. Insurers ask detailed questions about controls, and a capable provider can answer them and supply the evidence.

The cybersecurity services pages list providers that offer security as a service of its own.

CriteriaWhat to look for in a managed service provider

  1. A company that verifiably exists: a registered business, a real office and a phone that is answered. Our directory publishes those checks for every listing.
  2. Experience with businesses like yours: the same size, the same industry, the same line-of-business software and the same compliance rules.
  3. Its own security: an MSP holds the keys to every client, which makes it a target. Ask how it protects its own tools and staff accounts.
  4. A defined service: response times, hours and scope written down, not described in a meeting.
  5. Documentation you own: passwords, diagrams and configurations recorded, and handed over if you leave.
  6. Proactive support you can see: regular reports, patching and backup results, and strategic reviews of your technology, not silence between tickets.
  7. References you can call, of your size, who have been clients for more than a year.
  8. A local presence if you need on-site help. Browse managed IT services by city.

Due diligenceQuestions to ask an MSP before you sign

  1. What exactly is included in the monthly fee, and what is billed separately?
  2. What are your response and resolution times, by priority, and what happens when you miss them?
  3. Who answers the phone out of hours, and is that your staff or a subcontractor?
  4. How do you secure your own remote management tools and technician accounts?
  5. How often do you test our backups, and will you show us the result?
  6. Who owns the documentation, the admin accounts and the licenses if we part ways?
  7. What does onboarding involve, how long does it take, and what will you need from us?
  8. Who will be our named contact, and how often will we review the service together?
  9. Which security services do you deliver yourselves, and which do you resell?
  10. What are the contract length, the renewal terms and the notice period?

WarningsRed flags when choosing an MSP

  • A quote with no assessment: a price given before anyone has looked at your environment is a guess, or a template.
  • Vague scope: phrases such as "full support" with no list of what that means.
  • Long lock-in with no exit: multi-year terms, automatic renewal and no clause about handing over your data and passwords.
  • They keep the keys: reluctance to give you administrator credentials to your own systems.
  • No security answers: a provider that cannot describe its own controls will not manage yours.
  • Everything is reactive: no mention of monitoring, patching reports or reviews.
  • References that cannot be reached, or that are all very recent.

PaperworkThe MSP contract and service level agreement

The agreement is where the sales conversation becomes enforceable. It usually has two parts: a master services agreement with the legal terms, and a service level agreement, or SLA, with the measurable promises. Check that these are written down:

  • Scope: the users, devices, sites and services covered, and what is explicitly excluded.
  • Service levels: response and resolution targets by priority, hours of cover, and the remedy when they are missed.
  • Security and compliance responsibilities: who does what, including breach notification.
  • Data ownership and exit: your data, documentation and credentials returned within a stated time, and help with the transition.
  • Term, renewal and termination: the length, the notice period and the fees, if any, for leaving early.
  • Price changes: how and when the fee can rise, and how adding or removing users is handled.
  • Liability and insurance: the provider's cyber and professional liability cover.

ComparisonA simple scorecard for comparing proposals

Score each provider from 1 to 5 on the same criteria, and weight the ones that matter most to you. It turns three impressive presentations into a decision you can explain.

CriterionWhat a 5 looks like
Scope clarityA written list of inclusions and exclusions that matches what you asked for
Service levelsResponse and resolution times by priority, with a remedy
SecurityClear answers about its own controls and yours, with evidence
Relevant experienceClients of your size and sector, willing to talk to you
TransparencyYou hold admin access and documentation from day one
Exit termsReasonable notice, and a handover written into the contract
Total costMonthly fee plus onboarding, projects and out-of-scope rates, all stated

To collect proposals to score, request up to three quotes from listed providers that cover your city.

First 90 daysWhat MSP onboarding should look like

  1. Discovery: an inventory of every device, account, license and vendor, and a record of the passwords.
  2. Tool deployment: the monitoring agent, endpoint protection and backup installed everywhere. If you use Macs, ask about RMM for Mac.
  3. Stabilization: the urgent fixes, such as missing patches, failed backups and accounts of people who have left.
  4. Documentation and a plan: the environment written up, including any legacy systems that need replacing, with a roadmap and budget.
  5. Introduction to staff: how to ask for help, and what to expect.
  6. First review: a meeting at around 90 days to compare the service with what was promised.

That review closes the loop this IT buyers guide opened: you defined what you needed, compared providers on the same terms, put the promises in a contract, and now you check them against what was delivered.

How to read the it buyers guide silo

An IT buyers guide for choosing a managed service provider: what MSPs do, the alternatives, pricing models, questions to ask, red flags, and the contract.

  • Start with the concepts at the top, in order. They take about an hour together and everything else refers back to them.
  • Use the index by topic. Each group maps to a chapter of the common certification outlines.
  • Go straight to the troubleshooting group. Each page has a checklist at the top.
  • The comparison pages end with a decision chooser and link to the companies listed in the directory that deploy them.

IT Buyers Guide questions we get most

Short answers here, full pages one click away.

How do I choose a managed service provider?

Define the scope you need, ask several providers to price that same scope, check that each one verifiably exists and has clients like you, ask how it secures its own tools, read the contract for service levels and exit terms, and call the references. Score them on the same criteria so the decision can be explained.

What does a managed service provider do?

It takes ongoing responsibility for some or all of your IT for a recurring fee: help desk, monitoring and patching, backup, security, network and cloud administration, and planning. It is paid to keep systems working, not to repair them after they fail.

What is the difference between an MSP and an MSSP?

An MSP runs day-to-day IT. An MSSP specializes in security monitoring, detection and response. Many MSPs resell an MSSP service, so ask which security work the provider does itself.

What is co-managed IT?

An arrangement where an MSP works alongside your internal IT staff, taking the monitoring, tooling, out-of-hours cover or projects they do not have time for. It suits organizations that have an IT person but not a full department.

How do MSPs charge?

Most charge a monthly fee per user or per device. Others sell tiered packages or an all-inclusive flat fee. Onboarding, projects and on-site visits are often billed separately, so ask for them in every proposal.

What should an MSP contract include?

The scope of users, devices and services, response and resolution times with a remedy, security and breach notification responsibilities, ownership and return of your data and credentials, the term, renewal and notice period, how prices can change, and the provider liability insurance.

What are the red flags when choosing an MSP?

A price given without an assessment, a vague scope, long lock-in with no exit clause, reluctance to give you administrator access to your own systems, no clear answers about its own security, and references that cannot be reached.

When does a business need an MSP?

When IT has become someone second job, when problems are found by users instead of monitoring, when nobody has tested a restore, when patching is irregular, or when a customer, insurer or regulator asks for controls you cannot show.

Is an MSP cheaper than hiring IT staff?

For a small organization, usually, because one fee buys a team with several specialisms and out-of-hours cover that one employee cannot provide. For a larger one, an internal team supported by a co-managed agreement is often the better fit.

What is the difference between break-fix and managed services?

Break-fix is paid by the hour when something fails, so nobody is preventing problems. Managed services are a recurring fee for continuous monitoring, patching and support, which aligns the provider income with your systems staying up.

How long does it take to switch MSPs?

It depends on the size of the environment and on how well it was documented. Expect a discovery phase, tool deployment, then stabilization, with a first review at around 90 days. The exit terms in your current contract set the earliest start.

Do MSPs pay to be listed in your directory?

No. A listing is free and begins with one check, the company state registration. The other checks are published on each profile as they stand, and no provider can pay to rank higher.

Other silos

One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.