Back to blog

How to Choose a Managed Service Provider: 12 Questions to Ask Before You Sign

May 28, 2026

Choosing a managed service provider is a high-stakes decision that most businesses make exactly once every five to seven years — which means most decision-makers have almost no practice at it. Meanwhile, every MSP website says the same things: proactive, 24/7, enterprise-grade, trusted partner. The marketing is indistinguishable. The service is not.

The gap between a great MSP and a mediocre one shows up in outage minutes, breach exposure, and the friction of every support ticket your team files for years. Here are the twelve questions that expose that gap before you sign — along with the answers you should expect to hear.

1. What are your guaranteed response and resolution times — in writing?

Ask for the actual service level agreement, not the sales summary. A real SLA specifies response times by severity (for example, 15 minutes for a business-down event, 4 hours for a single-user issue), defines what "response" means, and carries financial penalties when the provider misses. If the SLA lives only in a brochure, it isn't an SLA.

2. Who answers the phone at 2 a.m.?

"24/7 support" can mean an on-call engineer, an overseas answering service that opens a ticket for the morning shift, or nothing but voicemail. Ask specifically: if our server fails at 2 a.m. on a Sunday, who is working on it and when? The answer tells you whether after-hours coverage is an operation or a promise.

3. What does your security stack include — and what costs extra?

Managed detection and response, MFA enforcement, email filtering, security awareness training, and vulnerability scanning should be table stakes in 2026, not upsells. Get the security inclusions in writing and compare line by line across bidders. A cheap per-user price with security à la carte usually ends up more expensive than an inclusive one — and dangerously thin in the meantime. If you're subject to compliance frameworks, ask how they map their stack to your requirements; our compliance roadmap lists what auditors actually look for.

4. How do you test backups?

Everyone takes backups. Far fewer verify them. The answer you want: automated backup monitoring, regular test restores with documented results, and at least an annual full disaster recovery exercise. Ask when they last performed a test restore for a client and what they found. Hesitation is your answer. A provider that can't describe its restore testing in detail is describing its future apology. Our guide to ransomware-proof backups explains what a defensible backup architecture looks like.

5. Will we have a dedicated team, or a random queue?

Ticket roulette — a different technician every time, each re-learning your environment — is the single biggest driver of MSP dissatisfaction. Look for pod-based or dedicated-team models where a small group of engineers knows your business, plus a named account manager who owns your relationship.

6. How do you document our environment, and who owns that documentation?

The provider should maintain living documentation — network diagrams, credentials in a proper vault, asset inventories, configuration records — and your contract should state plainly that this documentation belongs to you and will be handed over on exit. This question doubles as an offboarding test: providers who resist it are telling you how departure will go.

7. What does offboarding look like contractually?

Read the exit clauses before you sign, not when you're leaving. Reasonable terms: 60 to 90 days' notice, full handover of documentation and credentials, cooperative transition support at their standard hourly rate. Red flags: perpetual auto-renewal with narrow cancellation windows, "our tooling, our data" positions on your own configuration records, or per-device ransom fees to release admin passwords.

8. Which vendors and platforms are you certified on?

You want evidenced depth in the platforms you actually run — Microsoft 365 or Google Workspace, your firewall vendor, your line-of-business applications — not a logo wall. Ask how many of their current clients look like you, in size and in industry. A provider whose median client is 10 seats will strain to serve 200, and vice versa.

9. What happens when you're breached?

Note the phrasing: not "if a client is breached" — when you, the MSP, are breached. MSPs are high-value targets precisely because they hold keys to many environments; supply-chain incidents like the 2021 Kaseya attack proved it. A mature provider will answer without flinching: separated administrative credentials per client, MFA on all remote access, their own SOC monitoring, cyber liability insurance, and a written incident response plan they'll share under NDA. A provider offended by the question has never rehearsed the scenario.

10. How do you report on what you actually did?

Monthly or quarterly reporting should show ticket volumes and resolution times against SLA, patch compliance rates, backup success rates, and security events. Ask to see a sanitized sample report from a real client. If reporting is vague, accountability will be too.

11. Do you provide strategic guidance, or just break-fix?

The difference between an MSP and an IT partner is the roadmap. Expect quarterly business reviews, a rolling 12-to-36-month technology plan, and budget forecasting — someone thinking about where your business is going, not just closing tickets. If your provider has never talked to you about where your infrastructure needs to be for AI workloads or your security posture's insurance implications, you have a vendor, not a partner.

12. Can we talk to three current clients — and one former client?

References from current clients are easy. The former-client reference is the revealing one: how did the relationship end, and how did the provider behave on the way out? A confident MSP will produce one. An evasive answer here outweighs every polished slide in the deck.

Scoring what you hear

A pattern to watch: strong providers answer these questions with specifics, documents, and examples. Weak providers answer with adjectives.

Weight the questions by your risk profile. If you're in a regulated industry, questions 3, 4, and 9 dominate. If IT downtime stops revenue — and for most businesses it does, expensively — weight 1, 2, and 4. If you've been burned by a previous provider, weight 6 and 7.

Finally, treat price as a tiebreaker, not a selection criterion. The spread between competing bids is usually 15 to 25 percent; the spread in outcomes between a strong and weak provider is far larger than that. You're choosing the team that will hold your keys, your data, and your uptime for the next five years. Choose on evidence.

Evaluating providers right now? YonderTech will happily answer all twelve of these questions in writing — and we encourage you to make our competitors do the same. Get in touch to start the conversation.