How to Choose a Managed Service Provider: 12 Questions to Ask
When it comes to choosing a managed service provider, I have sat on both sides of the table. Early in my career I worked inside one, writing proposals and promising response times I privately hoped we could hit. Later I became the person reading those proposals as a CIO, and today I do the same thing as a virtual CIO for companies too small to hire one full time. That mix gives me an unfair advantage in one specific conversation: I know which answers are rehearsed and which ones come from people who actually run the service.
Here is the uncomfortable truth. Most companies pick a managed service provider the same way they pick a caterer. They collect three quotes, sit through three polished demos, and go with the one that felt friendliest and cost a little less. Then, eighteen months later, I get a call. The help desk is slow, nobody can find the backup reports, and the owner has just learned the provider has administrator access to every system the business owns with no real oversight.
What You Are Really Handing Over to a Managed Service Provider
That last point is the one I want you to sit with. When you hire a managed service provider, you are not buying a help desk. You are handing a third party the keys to your email, your finances, your customer data, and your ability to operate tomorrow morning. The stakes are not abstract. IBM’s 2026 Cost of a Data Breach Report put the global average breach at a record $4.99 million. It also found that supply chain compromise, where a business partner becomes the path in, adds more to the bill than any other single factor.
So this is not an IT purchase. It is a governance decision, and it deserves the same rigor you would give to choosing an auditor or a bank. Below are the twelve questions I personally ask on behalf of my clients, along with what a good answer sounds like and what should make you nervous.
Do Your Homework Before Calling a Managed Service Provider
The best question you can bring to a managed service provider is one you have already answered for yourself.
Write Down Four Things First
Before I let a client take a single meeting, we spend about two hours writing down four things.
- Our current inventory. A rough list of devices, cloud subscriptions, line of business applications, and who holds the admin passwords today. You would be amazed how often the answer to that last one is “the guy who left in 2023.” If any of those applications are custom built, note who maintains the code, since that work usually sits outside a support contract; our guide to custom software development cost explains why.
- What hurts. Not “IT is bad.” Specifics. Printers that fail every Monday, a salesperson who waited four days for a laptop, a cyber insurance renewal that asked questions nobody could answer.
- Compliance obligations. HIPAA, PCI DSS, CMMC, state privacy laws, or the security questionnaire your biggest customer sends every year.
- Budget and timeline. A budget range and a contract length you can live with. If you are still deciding whether to outsource at all, start with our managed IT services vs in-house cost comparison.
Send Every Managed Service Provider the Same Brief
This document becomes your requirements sheet. Send it to every shortlisted provider and ask them to answer in your format, line by line. One of the more useful buyer guides I have read, from Mind Core, makes the same point: a proposal written in the vendor’s own template cannot be compared with anything else. When everyone answers the same questions in the same order, the differences jump off the page.
It also changes the tone of the meeting. A provider who receives a clear brief knows they are dealing with an informed buyer, and the conversation shifts from a pitch to a working session. That is exactly where you want it.
The 12 Questions to Ask a Managed Service Provider
1. Who, by name, will work on our account, and where are they located?
Every provider has a great sales engineer. What you need to know is who answers the phone at 7:40 on a Tuesday morning when your accounting software will not open. Ask for the structure: help desk tier, escalation engineers, a named technical account manager, and the person responsible for strategy. Then ask whether any of that work is subcontracted or offshored. Neither is automatically bad, but you deserve to know before you sign, not after. A strong answer sounds like: “Your primary engineer is Dana, her backup is Luis, both are on our payroll, and you will meet them during onboarding.” A weak answer sounds like: “We have a deep bench.”
2. Exactly what access will you need, and how do you protect it?
This is the question I would keep if you made me throw out the other eleven. In 2021, attackers exploited Kaseya VSA, a remote management tool used by many providers. They pushed ransomware through roughly 50 to 60 managed service providers to as many as 1,500 of their customers, according to Huntress. One trusted tool became a highway into hundreds of businesses at once.
The joint advisory from CISA, NSA, FBI and allied agencies gives customers clear direction. Enforce multifactor authentication on provider accounts, apply least privilege, and restrict provider accounts to only the systems they manage. Ask the provider to describe how their technicians log in to your environment, whether every account is tied to a named person, and how quickly access is removed when one of their employees leaves. Then agree on those privilege levels before the contract is signed, not after.
3. Can you show us independent proof of your own security?
A provider that protects your environment should be able to evidence how it protects its own. Ask for a SOC 2 Type 2 report or an ISO 27001 certificate. The difference between SOC 2 report types matters. As Vanta explains, a Type 1 only describes the controls a company has in place at a single moment. A Type 2 tests whether those controls actually worked over a period of roughly three to twelve months. Smaller providers may not have either yet. In that case, ask for their cyber insurance certificate, their most recent penetration test summary, and a frank answer about whether they have ever had a breach and what they changed afterward. Our guide to penetration testing cost explains how to tell a real test from a scan with a cover page.
4. What happens in the first 90 days?
Onboarding is where good intentions go to die. A mature managed service provider will hand you a written plan: discovery and documentation in the first month, security baseline and quick fixes in the second, and a technology roadmap review by the end of the third. Ask what they will need from your team, how many hours of your staff’s time it will take, and what “done” looks like. If they cannot describe the first 90 days in detail, they will improvise them on your time. And if that roadmap includes moving servers to the cloud, ask them to walk you through their cloud migration strategy before you sign.
5. How are your SLAs written, and what happens when you miss them?
Read the service level agreement slowly, because the devil lives in the definitions. “One hour response” often means someone acknowledged the ticket, not that anyone fixed anything. Ask for separate targets for response and resolution, clear severity definitions (what counts as critical versus high), and the after hours escalation path. Then ask the most revealing question: “What was your actual SLA performance last quarter?” Providers who measure it will show you. Providers who do not will change the subject. Finally, ask what happens when they miss. Service credits are fine, but a pattern of misses should give you the right to exit.
6. What does “24/7” actually mean in your contract?
I have watched this phrase hide everything from a fully staffed security operations center to a single technician with a pager. Ask who is awake at 2:00 a.m. Find out whether that person can take action, such as isolating a laptop or disabling a compromised account, or can only send you an email. Also confirm whether after hours work costs extra. Acrisure Cyber Services frames this well: the question is not whether they will notify you, but who investigates and who contains the threat.
7. How do you back up our data, and when did you last test a restore?
Every provider says they back things up. Far fewer can tell you when they last restored a full server for a client and how long it took. Ask about two numbers: the recovery point objective (how much data you could lose) and the recovery time objective (how long you could be down). Ask whether backups are kept offsite and isolated from the main network, and how often restores are tested. CISA’s guidance specifically encourages secure offsite backups and regular recovery exercises. Request a sample restore test report. If none exists, that is your answer.
8. During a security incident, who does what?
Incidents are chaotic, and chaos exposes vague contracts. You want a written responsibility matrix that states who detects, who contains, who calls the insurer, who notifies customers or regulators, and who pays for forensic work. The same CISA advisory urges customers to make sure their contracts clearly assign ownership of security roles. Ask the provider to walk you through their last real incident, anonymized, from first alert to closure. The quality of the story tells you more than any brochure.
9. How will you report to us, and who joins our quarterly reviews?
Monthly ticket counts are not reporting. Good reporting tells you whether things are getting better: patch compliance, backup success rates, recurring issues, security findings, and the age of your hardware. Ask for a sample report from a current client with names removed. Then ask who attends the quarterly business review. If it is only an account manager trying to upsell, you are missing the strategic layer. The best providers include a vCIO or senior engineer who connects technology decisions to your business plan, budget, and risk.
10. How do you price, and what is not included?
Per user, per device, and tiered bundles can all be fair. What causes friction is the gap between what you assumed was covered and what the contract actually says. Ask for a plain list of exclusions: projects, new office moves, software licensing, after hours work, onsite visits, and incident response hours. Ask how adding or removing users affects the price mid contract. A provider who is confident in their value will show you the exclusions upfront rather than letting you discover them on an invoice. Development work is almost always excluded too; if you need it, our software development outsourcing cost guide shows what to budget.
11. Which subcontractors and software vendors sit behind your service?
Your managed service provider has its own supply chain: remote management platforms, security tools, cloud hosting, maybe an outsourced security operations center. Each one is a link in your chain too. The NIST Cybersecurity Framework 2.0 now places cybersecurity supply chain risk management under its Govern function, which is a polite way of saying leadership owns this risk. Ask for the list of critical vendors, how the provider vets them, and how they would notify you if one of them was compromised. Ask which cloud platforms they host on and support as well, since the AWS vs Azure decision shapes the skills you will need from them.
12. If we decide to leave, how do we get out cleanly?
Nobody likes discussing divorce on the first date, but this question separates confident providers from nervous ones. Ask what the termination terms are, what documentation you will receive, how admin credentials are handed over, and whether transition assistance is included. Clarify who owns the tools and licenses installed in your environment. A provider that answers calmly and in writing is one that expects to keep you by earning it, not by making exit painful.
How I Score Each Managed Service Provider’s Answers
After the interviews, I give each provider a score from 1 to 5 on every question, then weight them. Questions 2, 3, 7 and 8 (access, proof of security, backups, incident roles) count double. Those are the answers that decide whether a bad day becomes a catastrophe. Price gets weighed last, deliberately. When cost goes first, it quietly bends every other judgment.
Then I call references, and I ask for at least three clients of similar size and industry. I skip “Are you happy?” because everyone says yes. Instead I ask: “Tell me about the last time something went wrong and how they handled it.” And: “Has your main engineer changed in the past year?” High turnover on an account is one of the most reliable predictors of slipping service.
Managed Service Provider Red Flags I Never Ignore
Over the years, a handful of warning signs have earned automatic follow up from me:
- The provider cannot name the engineers who will support you.
- They want permanent domain administrator rights across everything “to be efficient.”
- There is no independent attestation, and they get defensive when asked about their own security.
- Their SLA measures acknowledgment only, with no resolution targets.
- They push a three year contract with automatic renewal and steep exit fees.
- Every recommendation they make happens to be a product they resell.
- Nobody can produce a single restore test report.
One red flag does not disqualify a managed service provider. Two or three together usually tell me everything I need to know, no matter how good the demo looked.
Final Thoughts on Choosing a Managed Service Provider
The right managed service provider will feel less like a vendor and more like a department you happen to rent. They will push back when you want to skip a security control. A good partner will also tell you when an expensive upgrade can wait another year. And at your quarterly review, they will bring a point of view about your business, not just a list of closed tickets.
You will not find that partner by comparing price sheets. You find them by asking hard questions, listening carefully to how they answer, and checking whether their clients tell the same story. Take these twelve questions, put them in your requirements document, and hold every provider to the same standard. If a provider welcomes the scrutiny, that is usually the best sign of all.
And if you are not sure how to judge the answers, bring in a vCIO or an independent advisor for the selection process. A few hours of experienced judgment up front costs far less than unwinding a bad three year contract later.
Frequently Asked Questions
What does a managed service provider actually do?
A managed service provider takes ongoing responsibility for some or all of your IT under a contract, usually for a predictable monthly fee. That typically covers help desk support, device and server monitoring, patching, backups, security tools, and vendor coordination. The CISA advisory defines MSPs as organizations that deliver, operate, or manage technology services for customers through a contractual arrangement such as a service level agreement.
What is the difference between an MSP and an MSSP?
An MSP manages your overall IT environment. A managed security service provider (MSSP) focuses specifically on security monitoring, threat detection, and response. Many MSPs now include security services or partner with an MSSP. As Dataprise notes, a dedicated MSSP is not always necessary, but you should know exactly who handles security in either model. Our guide to managed security services breaks down what that monthly fee covers.
How is managed IT usually priced?
Most providers charge per user, per device, or through tiered bundles that combine support and security. The fairest comparison is total cost over the full contract, including exclusions such as projects, onsite visits, licensing, and after hours work. Always ask for the exclusions list in writing before you compare quotes.
Do I need a vCIO if I already have a managed service provider?
Not always, but someone needs to own technology strategy. Day to day support keeps things running, while a vCIO connects IT spending to business goals, risk, and budget planning. As Meriplex points out, some providers include vCIO services in their offering. Other companies hire an independent vCIO to keep strategy separate from the provider being managed.
What certifications should a managed service provider have?
Look for a SOC 2 Type 2 report or ISO 27001 certification as independent evidence of security practices, plus vendor partner credentials for the platforms you rely on. As Sprinto explains, both SOC 2 report types require an examination by an independent CPA firm under AICPA standards. Read the report itself rather than trusting a logo on a website.
How long should a managed services contract be?
One to three years is common. Shorter terms give you flexibility, and longer terms may lower the monthly rate. Whatever the length, insist on clear performance based exit rights, defined transition assistance, and full handover of documentation and admin credentials if you leave.
References
- Help Net Security. “Data breach cost 2026 averaged $4.99 million, AI attacks ran higher.” helpnetsecurity.com
- CISA. “Protecting Against Cyber Threats to Managed Service Providers and their Customers.” cisa.gov
- NIST. “NIST Cybersecurity Framework 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management (C-SCRM).” csrc.nist.gov
- Huntress. “Lessons Learned During the Kaseya VSA Supply Chain Attack.” huntress.com
- Vanta. “SOC 2 Type 1 vs. Type 2: What’s the Difference?” vanta.com
- Sprinto. “SOC 2 Type 1 vs Type 2: Key Differences and Use Cases.” sprinto.com
- Mind Core. “How to Choose an IT Managed Service Provider: A 2026 Buyer’s Guide.” mind-core.com
- Acrisure Cyber Services. “Evaluating Managed Security Service Providers: What Should Small Businesses Look For?” acrisurecyber.com
- Dataprise. “12 Questions to Ask Managed Service Providers Before Hiring.” dataprise.com
- Meriplex. “Top Questions to Ask Before Hiring a Managed Services Provider.” meriplex.com
