MSP stands for managed service provider: a company that runs some or all of your IT for a fixed monthly fee rather than charging each time something breaks.
The fee usually covers a help desk, monitoring and patching, a security baseline, backups and planning. The pricing model is the defining part, because a flat fee makes an outage cost the provider money instead of earning it.
- Managed service provider, and the M is the part that matters
- Usually per user per month, with the services named in the contract
- Break-fix bills hourly, so it is paid more when more goes wrong
- An MSSP is the same arrangement narrowed to security
- Co-managed works alongside your IT staff instead of replacing them
On this page
The workWhat managed services actually cover
The service list is long enough that it hides the shape, so it is worth naming the four services almost every MSP offers, and then the ones only some MSPs provide.
Help desk support. Somebody your staff can call for help when a laptop will not print or a mailbox stops syncing. This is the part employees experience and the part that decides whether the arrangement feels like value.
The number that matters is the response time in the service level agreement, not the marketing: an SLA promising fifteen minutes and one promising four business hours are different products at a similar price.
Monitoring and patch management. An agent on every endpoint, server and network device, reporting failures, and a patching schedule that runs whether or not anybody remembers. This is where IT infrastructure earns the phrase: MSPs watch systems most of your staff never see.
The tooling behind it is an RMM platform, and the software an MSP runs is worth knowing about, because a provider is only as good at this as the platform it standardized on.
A security baseline. This is the part that protects your data, and in practice it means multi factor authentication on the accounts that matter, endpoint protection, backups that follow a rule rather than a habit, and the reports an auditor asks for. Larger providers offer cybersecurity services such as detection and response on top of that baseline.
Vendor and lifecycle management. Licenses, renewals, hardware refresh, and the quarterly conversation that decides what gets replaced next year. This is the least visible of the services and often the one that saves the most money.
Beyond those four what MSPs offer varies a great deal. Some managed service providers sell mobile device management, a virtual CIO, compliance programs, cloud migration or voice. Others deliberately do not, and a service provider that says no to something is usually easier to work with than one that says yes to everything.
The modelThe question behind what is an MSP is really about the pricing model
Ask what is an MSP and most answers describe the services. The services are not the distinguishing part: an hourly IT consultant will also fix your laptop, patch your servers, configure your network and set up your backups. The distinguishing part is how the money moves, and it changes what the business on the other side of the contract wants.
Under break-fix, you call when something is wrong and pay for the time. Revenue rises with the number of failures. Nobody is being dishonest and the incentive still points the wrong way: preventing an outage is unpaid, and cleaning one up is billable.
Under a managed services agreement, the fee is the same in a quiet month and a terrible one. Every hour spent on your emergency is an hour the MSP does not spend on anything else, so preventing the emergency is now in their interest.
That is the whole argument for managed services, and it is a real one. The benefits a business is actually buying follow from it: a predictable bill, support cover outside one person's working hours, and somebody whose own margin depends on your systems staying up.
It also explains the two failure modes. An MSP that has priced too low starts avoiding your support tickets, because each one costs money.
A business that treats a flat fee as unlimited access starts using it as free labor for projects that were never in scope. Both are the same misunderstanding from opposite ends, and a contract that names which services are included is what prevents them.
PricingHow MSPs charge, and what each model rewards
Four pricing models cover almost every quote you will see.
Per user, per month. The most common arrangement under a couple of hundred people and usually the fairest, because it follows headcount, which is what drives support volume, and covers whatever systems that person uses.
Provider guides published in 2026 put it at roughly $100 to $400 per user per month, most often $150 to $200 once a security baseline is included. The guides are named on that page, with the date each was read.
Per device, per month. Older, still common with providers serving manufacturing or retail, where machines outnumber people or a shop floor terminal is shared. Watch what counts as a device: the infrastructure in the rack, a server, a firewall and a network switch, is often priced differently from a laptop.
Tiered bundles. Essentials, standard and something with security in the name. Easy to compare on paper and easy to misread, because the tier boundaries are where the margin lives and the one capability your business needs has a way of sitting in the next bracket up.
Co-managed. A lower fee for tools, escalation and out of hours support alongside your own IT staff. Two published guides, from SkyNet MTS and Meriplex, put it at $60 to $125 and at $45 to $175 per user per month, depending on how much the provider takes on.
Most MSPs now offer it, and it is the arrangement most often overlooked by businesses that assume the choice is all or nothing.
What none of them should be is a number with no scope attached. A price per user means nothing until the service agreement says what that user is entitled to, what happens when a project falls outside it, and what the rate is when it does.
The acronymsMSP, MSSP, VAR and the other acronyms
The terms overlap in marketing and mean different things in a contract.
MSP. A managed service provider runs technology broadly: help desk, systems, network infrastructure, a security baseline and planning.
MSSP. A managed security service provider. The same recurring model narrowed to security services, usually built around a cybersecurity operations center, detection and response, and compliance work. Many businesses keep a managed service provider for technology in general and an MSSP for cybersecurity, and many providers now offer both, which is why the labels blur.
Co-managed IT. Not a different kind of company, a different division of labor. Your IT staff keep ownership and the MSP provides scale, tooling and support cover. Most MSPs offer it as a lower tier of the same managed service.
VAR. Value added resellers provide hardware and software with services attached to the sale. The revenue comes from the product, not from a recurring fee, and that is the difference worth knowing.
IT staffing or staff augmentation. Providers place people with you, billed by the hour or the day, managed by you. No service commitment, no response time, no monitoring.
vCIO and vCISO. Advisory time rather than a company type: somebody senior, part time, who owns strategy or security governance. Often bundled into a higher tier of managed services, sometimes sold separately, and the bundling is where the conflict of interest lives.
The limitsWhat an MSP will not do
MSPs are bought on an assumption and delivered against a contract, and the gap between the two causes most of the friction in the first year.
Line of business applications. Providers keep the systems, the network and the accounts working. The industry specific software that runs your practice, your firm or your workshop usually has its own vendor, and the MSP's job is vendor management rather than fixing it.
Anything that was never scoped. An office move, a cloud migration, a data center exit and a new site build are infrastructure projects. They are quoted separately in almost every managed services agreement, and a provider that folds them into the monthly fee has priced for that somewhere else.
Owning the decision. Good MSPs will tell you what they recommend and why. Signing off the spend and accepting the residual risk stay yours, and MSPs that make those choices silently are a worse problem than the ones that ask.
Being your entire IT department at scale. Past roughly two hundred people most businesses want one internal person who holds context, and the arrangement shifts to co-managed. Managed services do not stop working, they stop being the whole answer.
EvidenceHow to tell a good MSP from a confident one
Everything in this section is a document, not an impression, because every MSP will tell you it is responsive.
A support response time in the contract, with a credit attached. Response is not resolution, and knowing which one the number refers to is the first question. A commitment with no remedy behind it is a sentence.
A written onboarding plan. Discovery, documentation, agent deployment, and a date when the MSP takes responsibility. A provider that cannot describe the first thirty days in writing has not done many of them.
Monitoring you can see. Ask for the report MSPs send their clients, not the sales dashboard. If the only view of your own infrastructure is a monthly PDF, you have bought services you cannot audit.
Named escalation. Who is called at two in the morning during a security incident, in what order, and what they are authorized to do. Ask them to write it down.
An exit clause you have read. Notice period, what offboarding costs, who owns the documentation and the tooling, and how your data comes out of their systems. The time to establish this is while they want your signature.
References you chose. Any provider can produce three happy clients. Ask for one business in your industry and one of similar size, and ask those clients what went wrong and how it was handled, because something always did.
PitfallsWhere businesses go wrong
Comparing the monthly figure. Two MSPs quoting the same price per user routinely include different services, and the cheaper one is frequently the one with the project rate hidden in an appendix.
Assuming security is included. The baseline usually is. Detection and response, a security operations center, awareness training and compliance evidence usually are not, whatever else MSPs offer, and the gap between those two lists is where most of the disappointment sits.
Ignoring who owns the tooling. If the RMM, the documentation and the password vault belong to the service provider, leaving means rebuilding all three. This is the single most expensive thing to discover late, and it is a question you can ask in the first meeting.
Signing a three year term for a first engagement. Longer terms buy a lower rate, which is not worth much if the relationship is wrong. A twelve month term with a clean exit costs slightly more and is worth it the first time.
Treating the flat fee as unlimited. Every hour is somebody's hour, so businesses that use a managed service agreement as free project labor get slower support, and the MSP is not being petty when that happens.
ComparisonFour ways to run IT for a company under 200 people
| Criterion | Managed IT | Co-managed | Break-fix | In-house hire |
|---|---|---|---|---|
| Cost model | $100 to $400 / user / mo | $45 to $175 / user / mo | $100 to $400 / hour | $99k median wage, plus benefits |
| Best at | 10 to 200 users, no IT staff | 1 to 3 internal IT staff | Under 10 users | 200+ users, custom systems |
| Support response | In the contract, by priority | In the contract | Next available | Immediate, one person |
| Cover outside hours | Included | Included | No | One person cannot |
| Budget predictability | Flat monthly | Flat monthly | Varies with failures | Salary plus tools |
| Who holds the context | The MSP | Shared | Nobody | Your employee |
| Exit | Notice period in the contract | Notice period in the contract | Immediate | Notice period, knowledge loss |
The benefits are concentrated in two rows. The one that decides it for most businesses is the second, and the answer moves with headcount rather than with the sales pitch. Under ten people, break-fix is often genuinely correct. Between ten and two hundred, managed services usually win on support cover alone. Above that, the question becomes which parts stay inside.
FAQFrequently asked questions
What does MSP stand for?
Managed service provider. In technology it means a service provider that runs your systems and network for a recurring fee, with the service and the response times written into a service level agreement.
What is an MSP in simple terms?
An outsourced IT department you pay monthly. It offers help desk support, keeps systems and network devices patched and monitored, maintains a security baseline and backups, and handles hardware and licensing management with you.
What is the difference between an MSP and an IT company?
IT company is the general term for anyone who provides technology help. MSP is the specific arrangement where the service is delivered under a recurring fee with a defined service level, rather than billed by the hour when something breaks.
What does MSP mean in business outside IT?
The acronym is reused elsewhere, most often for managed service provider in staffing and for manufacturer's suggested price in retail. In a technology context it means managed service provider.
How much do managed services cost?
Provider guides published in 2026 put full management at roughly $100 to $400 per user per month, most often $150 to $200 with a security baseline, and co-managed support at $45 to $175. The range depends mostly on how much security is bundled in. The sources are named on the managed IT services page.
Is an MSP cheaper than hiring someone?
Usually for businesses below roughly two hundred users, because one salary buys an organization one person with no support cover outside their hours. Above that, an internal hire supported by co-managed services tends to win.
What is the difference between an MSP and an MSSP?
Scope. MSPs run IT broadly. An MSSP offers security services only, built around monitoring, detection and response and compliance. Some organizations buy both, and many providers now offer both.
What is co-managed IT?
An arrangement where the MSP works with your internal IT staff instead of replacing them, providing tooling, escalation and support outside working hours at a lower fee per user.
Do MSPs provide cybersecurity services?
A cybersecurity baseline, yes: multi factor authentication, endpoint protection, network filtering, patch management and backups. Detection and response, a security operations center and compliance evidence are usually a higher tier or a separate contract, so read which one you are being quoted.
How long are MSP contracts?
Commonly twelve to thirty six months with automatic renewal. Longer terms buy a lower rate, and a first engagement is usually better at twelve months with a clean exit.
What should be in a managed services contract?
A named service list, a service level agreement with a credit when the response time is missed, what counts as a project and at what rate, who owns the tooling and documentation, how security incidents are escalated, and the exit terms.
How do I switch MSPs?
Serve notice in the window, get the documentation, credentials and license ownership transferred before the last day, and overlap the two MSPs if the contract allows. The offboarding cost and the data handover are the parts to settle in the first service agreement, not the last one.
Can an MSP work with our existing IT staff?
That is exactly what co-managed services are for. It is the most common arrangement for businesses with one to three internal people who need support cover and tooling rather than replacement.
How do I find a good MSP near me?
Check the business exists as a registered entity, that the phone reaches somebody who knows it, and that any certification claimed is confirmed by its issuer. Our directory of MSPs by city publishes the record of those checks on every listing.
Keep readingRelated concepts
Read next · Identity and access What Is MFA? The first control in any provider security baseline, and the one whose absence tells you most. Open this next16 min- Backup · 13 min The 3-2-1 Backup Rule, and What Ransomware Did to It The backup standard a provider should already be following, and a fair question to ask on the first call.
- Operations · 13 min Patch Management, and Why the Hard Part Is Not the Patching One of the four things a managed agreement almost always covers, and the one whose quality is easiest to check.
- Managed IT · 10 min CapEx and OpEx in IT, and Why the Budget Line Shapes the Build The opex form of the IT team itself.
- Operations · 10 min What a CMDB Is, and the Question That Justifies One Why an RMM inventory does not answer this.
- Managed IT · 9 min What RMM Is, and What the Agent Can Actually Do Who is holding the credential set.
- Managed IT · 11 min What an MSSP Sells, and What Round the Clock Really Costs The broader arrangement an MSSP is a specialization of.
- Managed IT · 11 min IT Outsourcing, and the Decision Behind It What a managed service provider is, and what the flat fee changes.
- Managed IT · 9 min What an MSP PSA Actually Is, and Why Replacing One Is Harder The software that business is actually run on.
- Managed IT · 9 min What a vCIO Is, and the Question to Ask Before Buying One The strategic role most of them also sell.
- Managed IT · 9 min What a Managed ISP Sells, and How to Tell If It Is Worth It The provider that manages the connectivity instead.