Six Questions to Ask Before You Sign a Managed IT Contract

Six Questions to Ask Before You Sign a Managed IT Contract

September 30, 2026 · Rodney HolumManaged IT
Share:

Six questions with the answers to listen for. Useful even if you end up signing with somebody else.

You are about to sign a contract that will give an outside company access to your network, your data, and your most critical systems. If that contract is vague or one-sided, you could end up locked in for years, hit with surprise bills, or unable to get your data back if things go wrong.

Most disputes between small businesses and managed IT providers come from things that were never written down. This checklist walks you through six questions to ask before you sign, the same questions that separate a fair deal from a trap.

Question 1: What is in scope, and what is not?

The single most important document in a managed IT contract is a written responsibilities matrix. It should list exactly which services the provider will deliver, which ones you are responsible for, and which ones nobody is responsible for.

A good answer sounds like this: "We will manage your servers, workstations, and network. We will patch all systems weekly. We will monitor your backup. We will not manage your phone system, your website, or your accounting software. You are responsible for enforcing password policy and approving new user accounts."

A bad answer sounds like this: "We provide unlimited support" or "We handle all your IT needs." Those phrases hide the real scope and set you up for disputes later.

The UK National Cyber Security Centre advises that the contract should clearly specify what is and what is not included, ideally with a matrix detailing what the MSP will do and what you are expected to do. CISA recommends that MSPs provide clear explanations of the services you are purchasing, the services you are not purchasing, and all contingencies for incident response and recovery.

Ask to see the responsibilities matrix before you sign. If it does not exist, ask them to build one. If they push back, that is a red flag.

Question 2: Who owns our data and admin credentials, and how do we get them back?

Offboarding, the process of moving your data and systems to a new provider or back in-house, should be spelled out in the contract before you sign, not negotiated when you are trying to leave.

Ask to see the data transition section of the contract. It should answer these questions in writing:

  • Who owns your data while the MSP is managing it?
  • What happens to your data if you cancel the contract?
  • Will the MSP export your data in a standard format, and at what cost?
  • Who has the admin passwords to your systems, and how do you get them?
  • How long does the offboarding process take?

If the contract does not have a data transition section, get it added before you sign. Do not agree to sign first and negotiate exit terms later. That is when you lose leverage.

Question 3: What are the contract terms, length, termination, and auto-renewal?

Read the termination clause carefully. Many managed IT contracts include auto-renewal: the contract automatically extends for another term (usually 12 months) unless you provide written cancellation notice within a narrow window. Miss that deadline by a week and you are committed for another year of payments.

Ask for the termination clause in plain English. Specifically ask:

  • How long is the initial contract term?
  • Does it auto-renew, and if so, for how long?
  • How much notice do you need to give to cancel, and by what date?
  • What happens if you miss the cancellation deadline?

The moment you sign, mark the cancellation deadline on your calendar. Set a reminder 60 days before it. Do not rely on the MSP to remind you.

Question 4: What security responsibilities does the MSP take on, and what stays with us?

Once you outsource IT to an MSP, the lines of responsibility for security can get blurry. CISA advises that you should ask who is responsible for security and operations once IT is outsourced, and what data the MSP will have access to.

Your contract should spell out who is responsible for each of these:

  • Endpoint protection (antivirus, malware detection)
  • Multi-factor authentication
  • Patching and updates
  • Backup and disaster recovery
  • Security awareness training
  • Incident response and breach notification

A good answer is specific: "We will deploy endpoint protection on all workstations and servers. You are responsible for enforcing MFA on all user accounts. We will patch all systems within 7 days of release."

A vague answer, "We take security seriously", tells you nothing about who does what.

Question 5: How is pricing structured, and how does it change over time?

Most managed IT providers charge per user per month. A typical fully managed IT service (helpdesk, monitoring, patching, backup, basic security) runs between $150 and $250 per user per month, depending on the region and the provider. Advanced add-ons like email security or 24/7 security monitoring cost extra.

Ask for the pricing breakdown in writing:

  • What is the per-user cost?
  • What is included in that cost?
  • What add-ons are available, and what do they cost?
  • How often does the price increase?
  • What was the average annual price increase for existing clients over the past three years?

A specific answer to that last question, "Our average increase is 3% per year", signals transparent pricing. A vague answer, "It depends" or "We will talk about that later", is a warning sign.

Question 6: How do we escalate problems, and what are the response commitments?

When your network goes down at 2 a.m., you need to know who answers the phone, how fast they respond, and what they will actually do.

Ask for the escalation path and the service-level agreements (SLAs) in writing. A good SLA is specific and measured: "Priority-one tickets (network outage, data loss, security incident) will receive a response within 1 hour, 24/7. We commit to resolving 95% of priority-one incidents within 4 hours."

A bad SLA is vague: "We will respond as quickly as possible" or "We will do our best."

Also ask: who is on call at night? Can they drive to your location if something is on fire, or are they remote-only? How many people are on the team? If your main contact leaves, who takes over your account?

What to do with the answers

Before you sign, you should have written answers to all six questions. If the provider will not put something in writing, do not assume it will happen. Assume it will not.

CISA publishes a free vendor risk questionnaire template that you can use to vet any MSP before you sign. It covers these questions and more.

If you are in western Wisconsin, the Chippewa Valley, or Southwest Florida, one advantage of working with a local provider is that you can walk into their office, meet the engineers who will be on your account, and ask these questions face to face. You can verify in person who answers the phone at 2 a.m., how fast someone can drive to your building, and whether the people in the proposal are the people who will show up. That is something a national provider cannot offer.

Bring your managed IT proposal to a 30-minute review. We will go through these six questions with you, point out anything missing, and tell you plainly whether the contract is fair, even if you end up signing with someone else.

managed IT services contracthow to choose an MSPmanaged IT services pricingswitching IT providersmanaged IT services La Crossemanaged IT services Eau Clairemanaged IT services Fort Myers

Ready to Strengthen Your IT?

Schedule a free discovery call to discuss your technology needs with our team.