Questions to Ask Before Signing a Managed IT Contract
The sales conversation is where you learn whether you like a provider. The contract is where you learn what you actually bought.
Most managed IT agreements are reasonable documents written by reasonable people. But they are written by the provider, and every ambiguity in them will be resolved in the provider’s favor later, not because anyone is acting in bad faith but because that is how ambiguity works. The questions below are the ones worth asking before you sign rather than after something goes wrong.
Ask them in writing. A provider who answers cheerfully in a meeting and vaguely over email has told you something.
Term and exit
How long is the initial term, and what happens at the end of it? Multi-year agreements are normal and often carry better pricing. Automatic renewal is also normal. The combination of a long term and an auto-renewal with a short cancellation window is where people get stuck.
How much notice must we give to leave, and when can we give it? Watch for notice windows that only open briefly before renewal. A 90-day notice requirement on an agreement that auto-renews annually means missing one calendar reminder costs you another full year.
Can we exit for cause, and how is cause defined? If the agreement contains service commitments, ask what happens when they are missed repeatedly. An agreement with standards but no consequence for breaching them has standards in name only.
What does it cost to leave early? Get the actual number or formula, not a description.
Offboarding, which matters more than you think
This is the section most people skim and later wish they had not.
What happens to our documentation when we leave? Your provider will build a detailed map of your environment over the years: network layout, admin accounts, license keys, vendor details, and the reasoning behind configuration choices. If you change providers and that map does not come with you, your new provider rebuilds it from scratch, on your budget, while trying to keep things running.
Ask specifically whether you receive documentation on exit, in what format, and how quickly.
Who owns the licenses and accounts? If the provider purchased Microsoft 365, security tooling, or backup services on your behalf, find out whether those tenants and subscriptions are yours or theirs. Tenants registered to the provider are hard to move and occasionally impossible to move without disruption.
Will you cooperate with a successor provider, and is that obligation written down? Transition cooperation is standard among professional firms. It is still worth having on paper.
How long do you retain our backups after termination, and how do we get them?
Scope, and the boundary between support and project
Where exactly is the line between covered support and billable project work? This single boundary generates more disputes than everything else combined. A server migration is clearly a project. A password reset is clearly support. The disagreements happen in the middle, and the middle is where most of your requests will fall.
Ask for concrete examples on both sides of the line.
Are onboarding and offboarding of employees included? If you hire and lose people regularly, this is not a minor line item.
Is onsite support included, and how is it triggered? Included visits, billable visits, travel charges, and who decides when a problem warrants someone physically attending.
What are the after-hours rules? When do business hours end, what constitutes an emergency, and what is the after-hours rate?
Is there a cap on support requests? Uncommon, but it exists, and it is worth ruling out explicitly.
Security responsibilities
Which specific security tools are included versus add-on? Get the product names, not the categories. “Endpoint protection” describes both a free antivirus and a managed detection and response service with humans behind it.
Who is responsible if we are breached? Read this section carefully. Most agreements limit provider liability substantially, which is normal and often unavoidable. What matters is that you know where the line sits, so you can size your own cyber insurance accordingly rather than assuming coverage you do not have.
Do you carry cyber liability insurance, and will you show us the certificate? Reasonable to ask, easy to provide.
What are our obligations? Many agreements require you to maintain supported operating systems, apply recommendations within a timeframe, or enforce multi-factor authentication. Failing to meet your side can void the provider’s commitments. You should know what you are agreeing to do.
Who has administrative access to our environment, and how is that access controlled? Your provider will hold powerful credentials to your systems. Ask how those are protected, who internally can use them, and whether access is logged.
Response and escalation
Are response commitments in the contract or just on the website? Marketing claims are not contractual terms. If response times matter to you, they belong in the agreement.
How is priority determined, and who decides? If the provider classifies severity unilaterally, your urgent problem may be their routine ticket.
What is the escalation path when something is going badly? Get a name and a number, not a process diagram.
Is response time the same as resolution time? They are usually very different, and providers usually commit to the first. That is reasonable. Just know which one you were promised.
Money
How and when can pricing change? Annual increases are normal. Uncapped increases at the provider’s discretion are worth negotiating.
What happens when headcount changes? If you are billed per user, find out how and when the count is measured, whether it adjusts downward as readily as upward, and whether a minimum applies.
Is there a user minimum? Many providers enforce one. Better to know before budgeting.
What is the markup on hardware and software procurement? Providers reselling equipment usually mark it up, which is legitimate. It is reasonable to ask for the rate, and worth checking whether the agreement lets you buy elsewhere — some make support conditional on hardware procured through the provider.
Three things to check in the document itself
- Does the agreement reference other documents? Many contracts incorporate a separate service description or terms page by reference, including ones the provider can update unilaterally. Read those too, and ask whether changes require your consent.
- Do the written terms match what you were told verbally? Where they differ, the document wins. Get verbal assurances added or accept that they are not commitments.
- Is anything left blank or marked to-be-determined? Fill it in before signing. It will not become more favorable later.
A note on how providers respond to this list
Asking these questions is not adversarial, and a good provider will not treat it that way. Most of these have straightforward answers that a well-run firm gives without hesitation, and several are questions we wish more prospects asked, because the alternative is a client who discovers the boundary during a bad week.
What you are really testing is not the answers. It is whether the provider is comfortable being specific.
If you are reviewing a proposal from us or from anyone else and want a second read on it, send it over. If the other agreement is better for your situation, we will tell you that.
This describes general commercial practice and is not legal advice. An agreement of this size is worth an hour of your attorney’s time.
What Managed IT Services Cost in Central Ohio
Real 2026 market rates for managed IT, how per-user pricing works, what drives your number up or down, and how to compare…
How to Choose a Managed IT Provider in Columbus
Every MSP website says the same things. Here are the questions that actually separate one Columbus provider from another, including the ones…
How a Managed Service Provider Can Help Your Business
A managed service provider allows you to focus on your core competencies while leaving the management of your IT infrastructure to the…