Managed IT

25 Questions to Ask a Managed IT Provider

25 Questions to Ask a Managed IT Provider

Why These Questions Work

The fastest way to evaluate a managed IT provider is to ask questions with verifiable answers, then watch whether you get numbers and documents or adjectives and reassurance. A good MSP answers with specifics: a written SLA, a measured response time, a named exclusions list, a sample report, a reference you can call. A weak one answers with “we’re very responsive” and “security is baked into everything we do.”

That is the whole method. The 25 questions below are grouped into six areas, with what good and bad answers sound like for the ones that matter most. They work just as well on a provider you already use as on one you are about to hire.

Still deciding whether managed IT fits your business at all? Start with our complete managed IT services guide and come back when you have a shortlist.

Question areaGood answers sound likeBad answers sound like
Support and responseNumbers in a contract, plus measured actuals“We pride ourselves on responsiveness”
SecurityNamed tools and named inclusions“Security is included”
Contract and pricingA written exclusions list“We cover everything”
Onboarding and offboardingA documented process with dates and deliverables“It’s usually pretty quick”
Proof and referencesClient references, sample reports, audit evidenceLogos on a website
StrategyA named person and a meeting cadence“You can always reach out”

Support and Response Questions

1. “What are your guaranteed response times by ticket severity, and are they in the contract?”

Why it matters: response time is the single most common complaint that drives businesses to switch providers, and an SLA that lives in a sales deck instead of a contract is not an SLA. A good service contract should include an SLA that requires the MSP to meet specific standards, such as responding to any critical ticket within 30 minutes.

A good answer: “Critical tickets get a response in 30 minutes or less, high priority in 2 hours, normal in 8 business hours. It’s section 4 of the agreement, and there are remedies if we miss.”

A bad answer: “We respond really fast, usually same day.” Same day is not a commitment. It is a hope.

2. “What is your actual measured response time, not the contractual ceiling?”

Why it matters: the SLA is the worst you should ever experience; the median is what daily life will feel like. Any provider running a real ticketing system knows this number cold. For reference, Prevvi’s median response time is 15 minutes.

A good answer: a specific number, plus how it is measured and over what period.

A bad answer: “We don’t really track that, but clients are happy.”

3. “Who answers when we call: a live technician or a ticket queue?”

Why it matters: the difference between a 5-minute fix and a 2-day fix is often whether the first person who touches the issue can actually resolve it. Ask what percentage of tickets are resolved at first contact and whether after-hours calls reach a human.

4. “What happens after hours, on weekends, and on holidays?”

Why it matters: for a 20-person business doing $5 million in revenue, downtime can cost about $3,362 per hour, and outages do not schedule themselves inside business hours. A good answer names the after-hours route, who staffs it, and what qualifies as an emergency. A bad answer is “leave a voicemail and we’ll get to it first thing.”

5. “Will we work with a consistent team, or whoever picks up the ticket?”

Why it matters: institutional knowledge of your environment is most of what you are paying for by month six. Look for a named pod or primary engineers with documented handoffs, not a fully anonymous queue.

Security Questions

6. “Exactly which security services are included in the base fee, and which cost extra?”

Why it matters: “security included” is the most abused phrase in MSP sales. Verizon’s 2025 Data Breach Investigations Report found ransomware involved in 88% of breaches at small and midsize businesses, compared to 39% at large organizations, so the depth of the included security layer is not a detail. We break down what is typically included versus an add-on in what managed IT services actually cover.

A good answer: a named list. “Base fee includes EDR on every endpoint, MFA enforcement, email security, security awareness training, and Microsoft 365 backup. Managed detection and response and compliance work are priced separately, here’s the sheet.”

A bad answer: “Don’t worry, security is baked into everything we do.” Unnamed security is unverifiable security.

7. “Is endpoint detection and response deployed on every device, and who watches the alerts?”

Why it matters: an EDR tool with nobody watching it is a smoke detector with no battery. A good answer names the tool, confirms coverage on every endpoint including remote laptops, and explains who triages alerts at 2 AM. A bad answer confuses EDR with antivirus or admits alerts are reviewed “as we get to them.”

8. “What happens, step by step, if we are breached on a Saturday night?”

Why it matters: IBM’s 2025 Cost of a Data Breach report put the mean time to identify and contain a breach at 241 days, the lowest in nine years. Response speed drives final cost. A good answer walks you through a documented incident response process: who is paged, how isolation happens, when you get told, who talks to your insurer. A bad answer starts with “that’s never happened to us.”

9. “When did you last test a restore from backup for a client, and did it work?”

Why it matters: backups that have never been restored are a theory. A good answer includes a recent, specific test and the measured recovery time. A bad answer treats the existence of backup software as the finish line.

10. “How do you secure your own company?”

Why it matters: your MSP holds administrative credentials to your entire environment, which makes the MSP itself a target. A good answer covers their own MFA, access controls, vendor audits, and cyber insurance without getting defensive.

Contract and Pricing Questions

11. “What exactly is excluded from this agreement?”

Why it matters: surprise invoices come from unread exclusions, not from the included services. Projects, hardware, line-of-business application support, and compliance certification work are commonly out of scope. A good answer is a written exclusions list the provider volunteers proudly. A bad answer is “we cover everything,” which no MSP does.

12. “How is pricing structured, and what triggers a price change?”

Why it matters: flat-rate managed IT typically runs $100 to $200 per user per month, but the structure (per user, per device, tiered) determines how your bill behaves as you grow. A good answer explains the model, the true-up process when headcount changes, and how much notice you get before any increase. We break the full math down in how much managed IT services cost.

13. “What does it cost to leave early, and what is the renewal term?”

Why it matters: auto-renewing multi-year terms with steep exit penalties are how mediocre providers keep clients. A good answer states the term, the notice window, and the early exit cost plainly. A bad answer is vague about renewals.

14. “Are projects billed separately, and at what rates?”

Why it matters: office moves, server migrations, and new deployments are almost always separate project work. Ask for the project rate card now, not when the project arrives.

15. “How are you incentivized: do you profit when we have more problems or fewer?”

Why it matters: flat-fee providers profit when your environment is stable; hourly providers profit when it is not. A good answer explains the model honestly.

Want to see what transparent answers look like in practice? Prevvi’s managed IT services page publishes its scope, SLA approach, and security baseline openly, and we will answer all 25 questions in a free assessment whether or not you hire us.

Onboarding and Offboarding Questions

16. “What does onboarding look like, week by week?”

Why it matters: for most small and midsize businesses, onboarding a new MSP takes around 30 to 90 days, covering discovery, tool deployment, remediation, and stabilization. A good answer is a phased plan with milestones and named owners. A bad answer promises to be “fully up and running in a couple of days,” which usually means no real assessment happened.

17. “How will you document our environment, and who owns that documentation?”

Why it matters: undocumented environments are hostage environments. A good answer: the provider documents everything (network maps, credentials, configurations, licenses) and the documentation is contractually yours. A bad answer treats documentation as proprietary provider property.

18. “If we leave, exactly how do we get our credentials, configurations, and data back?”

Why it matters: this is the question weak providers hate most, which is precisely why you ask it before signing. A good answer describes a defined offboarding process with a handover window and any fees stated up front. A bad answer is a joke (“you won’t want to leave!”) or visible irritation. How a provider talks about your exit is how they will behave during it.

19. “Are our software licenses and cloud tenants registered to us or to you?”

Why it matters: if your Microsoft 365 tenant or security licenses live under the MSP’s account, switching providers can mean rebuying and rebuilding. Everything should be registered to your organization, with the MSP holding delegated access.

Proof, References, and Strategy Questions

20. “Can we speak with two current clients about our size, in a similar industry?”

Why it matters: references filter marketing from reality. A good answer produces names within a day or two. When you call, ask the reference one question above all: “What happens when something goes wrong?” In one survey, 52% of organizations reported challenges with their MSP being reactive instead of proactive, and references will tell you which side of that line a provider actually lives on.

21. “What third-party evidence can you show: audits, certifications, insurance?”

Why it matters: claims are free; evidence costs effort. A good answer offers something verifiable, such as a SOC 2 report, security certifications, or proof of cyber liability insurance. A bad answer is a wall of vendor partner logos and nothing independently checked.

22. “Can we see the actual monthly or quarterly report we would receive?”

Why it matters: the sample report shows you what the provider actually measures. A good report covers ticket volumes, response times against SLA, patch status, backup results, and security events in plain English. If they cannot produce one, reporting is an afterthought.

23. “Who is our strategic contact, and how often do we meet?”

Why it matters: without a scheduled strategy cadence (usually a quarterly business review with a vCIO or account manager), the relationship decays into pure break-fix. A good answer names the role and the calendar. A bad answer is “reach out anytime,” which means never.

24. “How do you use automation and AI in your own service delivery?”

Why it matters: providers that automate triage, patching, and monitoring resolve issues faster and make fewer manual errors than providers doing everything by hand, and the honest ones can explain exactly where automation ends and human judgment begins. (Ask us too: Prevvi runs internally on multi-agent AI automation and is Claude Certified by Anthropic, and we expect prospects to make us explain what that means in practice.)

25. “Based on what you have seen of our environment, what would you fix first, and why?”

Why it matters: this is the closest thing to a free consulting session and the best single test of competence. A good answer is specific to you, prioritized by risk, and includes at least one thing that does not make the provider money. A bad answer is a generic pitch that could have been delivered to any company.

The Full Question Checklist

Print this section and bring it to every evaluation call.

Support and response

  1. What are your guaranteed response times by ticket severity, and are they in the contract?
  2. What is your actual measured response time?
  3. Who answers when we call: a live technician or a ticket queue?
  4. What happens after hours, on weekends, and on holidays?
  5. Will we work with a consistent team or whoever picks up the ticket?

Security

  1. Exactly which security services are included in the base fee, and which cost extra?
  2. Is EDR deployed on every device, and who watches the alerts?
  3. What happens, step by step, if we are breached on a Saturday night?
  4. When did you last test a restore from backup, and did it work?
  5. How do you secure your own company?

Contract and pricing

  1. What exactly is excluded from this agreement?
  2. How is pricing structured, and what triggers a price change?
  3. What does it cost to leave early, and what is the renewal term?
  4. Are projects billed separately, and at what rates?
  5. How are you incentivized: more problems or fewer?

Onboarding and offboarding

  1. What does onboarding look like, week by week?
  2. How will you document our environment, and who owns the documentation?
  3. If we leave, exactly how do we get our credentials, configurations, and data back?
  4. Are our licenses and cloud tenants registered to us or to you?

Proof, references, and strategy

  1. Can we speak with two current clients our size, in a similar industry?
  2. What third-party evidence can you show: audits, certifications, insurance?
  3. Can we see the actual monthly or quarterly report we would receive?
  4. Who is our strategic contact, and how often do we meet?
  5. How do you use automation and AI in your own service delivery?
  6. What would you fix first in our environment, and why?

If you are running this checklist against a provider you already pay, and the answers are coming back thin, read the signs your MSP is underperforming before you decide whether to renegotiate or replace.

The Next Step

No provider will ace all 25 questions, and that is fine. What you are looking for is a pattern: specifics over adjectives, documents over promises, and comfort rather than defensiveness when you ask about measurement and exit terms. A provider that welcomes this list is a provider that expects to be held to it.

If you want to see how Prevvi answers, book a free assessment. We are headquartered in Cambridge, MA, we will walk through every question on this list, and you will leave with a documented picture of your environment either way.

Sources

Frequently asked questions

Focus on questions with verifiable answers: response time SLAs by ticket severity (in writing), exactly which security services are included in the base fee, a written list of contract exclusions, the offboarding process for getting your passwords and documentation back, and references from clients your size. Providers who answer with documents and numbers are safer bets than providers who answer with adjectives.

A strong SLA defines response times by ticket severity, in the contract, with critical issues answered in 30 minutes or less. The provider should also be able to tell you their actual measured response time, not just the contractual ceiling. If the SLA has no severity tiers or no time commitments, treat that as a red flag.

Ask which security services are included in the base fee by name (EDR, MFA enforcement, email security, backup testing), who monitors alerts after hours, and how the MSP secures its own company. A provider that cannot describe its own internal security posture, or that treats endpoint detection as an upsell, is a weak security partner.

The contract should state that your documentation, admin credentials, license ownership, and data are yours and will be handed over within a defined window if you leave, along with any offboarding fees. Ask the question before signing; a provider that gets defensive about exit terms is telling you something.

For most small and midsize businesses, onboarding a new managed IT provider takes roughly 30 to 90 days: discovery and tool deployment first, then remediation and migrations, then stabilization and a first strategic review. A provider that promises full onboarding in a few days probably is not doing a real assessment.

Written by

Andrew Wienen Founder & CEO, Prevvi

Andrew is the founder and CEO of Prevvi, a Cambridge, Massachusetts managed IT and AI solutions provider. He is Claude Certified by Anthropic and built the multi-agent AI operation Prevvi runs on, after leading enterprise AI, automation, and Workday Financials programs.

Want this handled for you?

Talk to a real engineer about your environment: no sales script, just straight answers.