Questions to Ask Before Signing a Managed IT Contract
The sales conversation is where you learn whether you like a provider. The contract is where you learn what you actually bought.
Most managed IT agreements are reasonable documents written by reasonable people. They are also written by the provider, and ambiguity in them tends to get resolved in the provider’s favor later. That happens without anyone acting in bad faith. It is how ambiguity works. The questions below are the ones worth asking before you sign, rather than after something goes wrong.
Ask them in writing. A provider who answers cheerfully in a meeting and vaguely over email has told you something.
Term and exit
How long is the initial term, and what happens at the end of it? Multi-year agreements are normal and often carry better pricing. Automatic renewal is also normal. People get stuck when a long term, an auto-renewal, and a short cancellation window all land in the same agreement.
How much notice must we give to leave, and when can we give it? Watch for notice windows that only open briefly before renewal. A 90-day notice requirement on an agreement that auto-renews annually means one missed calendar reminder costs you another full year.
Can we exit for cause, and how is cause defined? If the agreement contains service commitments, ask what happens when they are missed repeatedly. Standards with no consequence attached are standards in name only.
What does it cost to leave early? Ask for the actual number, or the formula that produces it.
Offboarding, which matters more than you think
This is the section most people skim and later wish they had not.
What happens to our documentation when we leave? Your provider will build a detailed map of your environment over the years: network layout, admin accounts, license keys, vendor details, and the reasoning behind configuration choices. If you change providers and that map does not come with you, your new provider rebuilds it from scratch, on your budget, while trying to keep things running.
Ask whether you get that documentation on exit, in what format, and how quickly.
Who owns the licenses and accounts? If the provider purchased Microsoft 365, security tooling, or backup services on your behalf, find out whether those tenants and subscriptions are yours or theirs. Tenants registered to the provider are hard to move, and occasionally impossible to move without disruption.
Will you cooperate with a successor provider, and is that obligation written down? Transition cooperation is standard among professional firms. It is still worth having on paper.
How long do you retain our backups after termination, and how do we get them?
Scope, and the boundary between support and project
Where exactly is the line between covered support and billable project work? This single boundary generates more disputes than everything else combined. A server migration is clearly a project. A password reset is clearly support. The disagreements happen in the middle, and the middle is where most of your requests will fall.
Ask for concrete examples on both sides of the line.
Are onboarding and offboarding of employees included? If you hire and lose people regularly, this is not a small line item.
Is onsite support included, and how is it triggered? Find out how many visits are included, what gets billed, whether travel is charged, and who decides that a problem needs someone there in person.
What are the after-hours rules? When do business hours end, what counts as an emergency, and what is the after-hours rate?
Is there a cap on support requests? Uncommon, but it exists. Worth ruling out explicitly.
Security responsibilities
Which specific security tools are included versus add-on? Get the product names, not the categories. “Endpoint protection” describes both a free antivirus and a managed detection and response service with humans behind it.
Who is responsible if we are breached? Read this section carefully. Most agreements limit provider liability substantially, which is normal and often unavoidable. What matters is knowing where the line sits, so you can size your own cyber insurance around it instead of assuming coverage you do not have.
Do you carry cyber liability insurance, and will you show us the certificate? Reasonable to ask, easy to provide.
What are our obligations? Many agreements require you to maintain supported operating systems, apply recommendations within a timeframe, or enforce multi-factor authentication. Falling short on your side can void the provider’s commitments, so read that part closely.
Who has administrative access to our environment, and how is that access controlled? Your provider will hold powerful credentials to your systems. Ask how those are protected, who internally can use them, and whether access is logged.
Response and escalation
Are response commitments in the contract or just on the website? Marketing claims are not contractual terms. If response times matter to you, they belong in the agreement.
How is priority determined, and who decides? If the provider sets severity on its own, your urgent problem may be their routine ticket.
What is the escalation path when something is going badly? Get a name and a number, not a process diagram.
Is response time the same as resolution time? They are usually very different, and providers usually commit to the first. That is reasonable. Just know which one you were promised.
Money
How and when can pricing change? Annual increases are normal. Uncapped increases at the provider’s discretion are worth negotiating.
What happens when headcount changes? If you are billed per user, find out how and when the count is measured, whether it comes down as readily as it goes up, and whether a minimum applies.
Is there a user minimum? Many providers enforce one. Better to know before budgeting.
What is the markup on hardware and software procurement? Providers reselling equipment usually mark it up, which is legitimate. It is reasonable to ask for the rate. Check the agreement for whether you can buy elsewhere, because some providers make support conditional on hardware bought through them.
Three things to check in the document itself
- Does the agreement reference other documents? Many contracts incorporate a separate service description or terms page by reference, including ones the provider can update on its own. Read those too, and ask whether changes require your consent.
- Do the written terms match what you were told verbally? Where they differ, the document wins. Get verbal assurances added or accept that they are not commitments.
- Is anything left blank or marked to-be-determined? Fill it in before signing. It will not become more favorable later.
A note on how providers respond to this list
Asking these questions is not adversarial, and a good provider will not treat it that way. Most of them have straightforward answers that a well-run firm gives without hesitation. Several are questions we wish more prospects asked, because the alternative is a client who finds the boundary during a bad week.
The real thing you are testing is whether the provider is comfortable being specific.
If you are reviewing a proposal from us or from anyone else in Columbus or Central Ohio and want a second read on it, send it over. If the other agreement is better for your situation, we will tell you that.
This describes general commercial practice and is not legal advice. An agreement of this size is worth an hour of your attorney’s time.
Onsite vs. Remote IT Support: What Columbus Businesses Should Expect
Most IT problems are solved faster remotely. Some genuinely need someone in the building. Here is where the line sits, and what…
What Managed IT Services Cost in Central Ohio
Real 2026 market rates for managed IT, how per-user pricing works, what drives your number up or down, and how to compare…
How to Choose a Managed IT Provider in Columbus
Every MSP website says the same things. Here are the questions that actually separate one Columbus provider from another, including the ones…