Insights › Managed IT

How to choose a managed IT provider: 12 questions to ask before you sign

Questions? Call (714) 441-2900

Choosing a managed IT provider is choosing who holds the keys to every system your business runs on. Proposals look alike on paper, so the differences show up in the questions below. We wrote this as a checklist you can use with any provider, including us.

The short answer

Pick the provider that can show you, not tell you, four things: who answers when something breaks (and how fast), what security is included by default, how you leave if it does not work out, and proof they have done this for companies like yours. Price matters, but only after those four.

12 questions to ask before you sign

Support and response

  1. Who answers the phone, and when? Is it a live engineer 24/7, or a voicemail and a ticket outside business hours? Ask them to call their own support line in front of you.
  2. What are your response and resolution targets, in writing? Look for defined priorities (for example, a whole office down versus one user’s printer) with a response time for each.
  3. When do you come onsite, and is it included? Ask where engineers are based and whether onsite visits cost extra.

Security

  1. What security is included by default? At a minimum in 2026: multi-factor authentication everywhere, endpoint detection and response (EDR) watched by people 24/7, email filtering, patching, and backups that cannot be altered or deleted (immutable backups).
  2. When did you last test a restore? A backup nobody has restored is a hope, not a plan. Ask how often they test, and for a sample report.
  3. How do you protect your own access to our systems? Attackers target IT providers to reach all their clients at once. Ask how their staff sign in, how admin access is limited and logged, and whether they have had an independent security review.

Compliance

  1. Have you taken companies through our framework? If you face CMMC, SOC 2, HIPAA or PCI DSS, ask for specifics. For CMMC, ask whether they are a Cyber AB Registered Provider Organization (RPO).
  2. Who writes the policies and collects the evidence? Many providers configure tools but leave the paperwork to you. Find out before the auditor asks.

Contract and price

  1. What exactly is in the monthly fee, and what is billed extra? Projects, after-hours work, onsite visits, new-hire setup and security tools are the usual extras.
  2. How do we leave? The contract should require them to hand over documentation, passwords, admin accounts and licenses, without a fee to release your own data.
  3. Who owns the licenses and the equipment? Microsoft 365 tenants, domains and firewalls should be in your company’s name, not the provider’s.

Fit

  1. Can we talk to two clients like us? Same size, same industry, ideally ones who have been with the provider for several years. Ask them what happens when something goes wrong.

Red flags

  • They cannot tell you who will be your main engineer or account manager.
  • Security tools are an optional add-on rather than part of the base agreement.
  • Your Microsoft 365 tenant, domain or firewall would be registered to them.
  • Long auto-renewing terms with no exit for poor performance.
  • Vague answers about backups: “it’s in the cloud” is not a recovery plan.
  • They promise to make you “compliant” or “certified”; only an independent assessor or auditor can certify you.

Pricing models at a glance

ModelHow it worksBest forWatch out for
Per user, all-inclusiveOne price per employee covers their devices, support and securityMost small and mid-sized businessesWhat counts as “included” versus a project
Per devicePrice per computer, server and network deviceShared workstations, production floorsCosts climb as devices multiply
Tiered packagesBronze, silver, gold bundlesSimple environmentsEssential security only in the top tier
Co-managedProvider supports your internal IT teamCompanies with IT staff who need depth or coverageUnclear split of responsibilities
Hourly / break-fixPay when something breaksVery small officesNo monitoring, no prevention, unpredictable bills

Frequently asked questions

How much should managed IT services cost?

Most providers charge a fixed monthly fee per user or per device, with the price driven by what is included: help desk hours, security tools, backup, compliance work and onsite visits. Compare proposals line by line, because a low price often means security tools, after-hours support or projects are billed extra.

Should I choose a local IT company or a national one?

Most support is delivered remotely, so location matters less than it used to. It still matters for onsite work, office moves and hardware problems. A regional provider with nationwide remote coverage gives you both.

How long should a managed IT contract be?

One to three years is common. Whatever the term, make sure you can terminate for poor performance, and that the contract requires the provider to hand over documentation, passwords and admin access when you leave.

What is the difference between managed IT and co-managed IT?

With managed IT the provider is your whole IT department. With co-managed IT you keep internal IT staff and the provider fills gaps: help desk overflow, after-hours coverage, security operations or compliance.

How long does it take to switch IT providers?

Typically two to four weeks: collecting documentation and access, deploying the new provider’s monitoring and security tools, and an agreed cutover date. A good provider coordinates directly with the outgoing one.

How CorporateTech answers these questions

CorporateTech has been an outsourced IT and security department for businesses in Orange County, Los Angeles, San Diego and nationwide since 1999. We run a 24/7 live help desk and monitoring, include security in every IT Management agreement, and run CMMC, SOC 2, HIPAA and PCI DSS programs as a Cyber AB Registered Provider Organization. Ask us any of the twelve questions above on a first call; we would rather you compare us carefully. See our local pages for Orange County, Irvine, Los Angeles and San Diego.

Compare us against your checklist

A 30-minute call is usually enough to tell you where you stand and what to do first. No obligation.

(714) 441-2900

Sales line: Monday to Friday, 8 AM to 6 PM Pacific. Existing clients: support is available 24x7.

  • Managed IT
  • Cybersecurity
  • Buying guide

‹ All insights