How to Choose a Managed Services Provider: The Criteria That Actually Matter
Choosing a managed services provider is one of the highest-stakes IT decisions a business can make. You're not buying a product — you're handing over operational responsibility for the technology your business runs on. A bad MSP doesn't just cost money. It costs uptime, security posture, employee productivity, and in some cases, customer relationships.
Yet most MSP evaluations are shockingly shallow. Businesses compare pricing tiers, skim a feature checklist, and make a decision based on who had the best sales presentation. Then they spend the next 18 months dealing with slow response times, finger-pointing during outages, and a contract that makes it painful to leave.
This guide is for businesses that want to do it right. We'll cover the criteria that actually predict MSP performance, the questions most evaluations skip, the red flags that should end a conversation, and how to structure a selection process that gives you real signal instead of polished demos.
What a Managed Services Provider Actually Does
Before evaluating MSPs, it's worth being precise about what you're buying. "Managed services" is a broad term that can mean anything from basic remote monitoring to full IT outsourcing. The scope varies enormously across providers.
A full-service MSP typically covers:
Not every MSP does all of this. Some specialize in specific verticals or technology stacks. Some are strong on infrastructure but weak on security. Understanding exactly what you need before you start evaluating is the prerequisite to everything else.
---
The Eight Criteria That Actually Predict MSP Performance
1. Response Time SLAs — and How They're Measured
Every MSP will quote you a response time SLA. The number is almost meaningless without understanding exactly what it measures.
Response time is how long it takes for a human to acknowledge your ticket. Resolution time is how long it takes to fix the problem. These are very different things, and most SLAs only commit to the former.
Ask for the provider's actual SLA structure in writing, including:
A provider that can't answer these questions precisely, or whose SLA document is vague, is telling you something important about how they operate.
2. NOC and Help Desk Staffing — the Real Numbers
The quality of your MSP experience is almost entirely determined by the people who answer your tickets. Ask direct questions about staffing:
The outsourced NOC question is particularly important. Many MSPs white-label a third-party NOC for after-hours coverage. This isn't inherently bad, but it means the people handling your 2 AM outage have never seen your environment before. Ask whether the NOC has access to your documentation, runbooks, and escalation contacts — or whether they're working blind.
3. Onboarding Process and Documentation Standards
How an MSP onboards you tells you everything about how they operate. A rigorous onboarding process — network discovery, asset inventory, documentation of your environment, runbook creation, escalation path definition — is a sign of operational maturity. A loose, informal onboarding is a sign of what's coming.
Ask for a sample onboarding checklist or project plan. Ask how long onboarding typically takes and what deliverables you'll receive at the end. Ask where your documentation is stored and whether you own it if you leave.
That last question matters more than most businesses realize. Some MSPs store all documentation in their own systems and provide no export. If you leave, you leave with nothing. A good MSP documents your environment in a format you own and can take with you.
4. Security Capabilities — Depth, Not Checkbox
Security is the area where MSP capability gaps are most dangerous and most commonly obscured by marketing language. "We include endpoint protection" and "we run a mature security operations practice" are not the same thing.
Evaluate security depth across several dimensions:
Endpoint detection and response (EDR): Are they deploying a true EDR platform (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint) or a legacy antivirus product? EDR vs. AV is not a minor distinction — it's the difference between behavioral threat detection and signature-based scanning.
SIEM and log management: Do they aggregate and analyze logs from your environment? Can they detect lateral movement, privilege escalation, and other attack patterns that don't trigger endpoint alerts?
Vulnerability management: How frequently do they scan your environment for vulnerabilities? What is the remediation SLA for critical findings?
Incident response: If you have a breach, what happens? Do they have a documented IR process? Do they have cyber insurance that covers their clients? Do they have relationships with forensics firms?
Compliance support: If you operate in a regulated industry (healthcare, financial services, government contracting), does the MSP have experience with your compliance framework (HIPAA, PCI-DSS, CMMC, SOC 2)? Can they provide evidence for audits?
Ask for their security stack in writing. Ask whether security is included in the base contract or sold as an add-on. Ask when they last had a security assessment of their own operations.
5. Proactive vs. Reactive Operating Model
The fundamental value proposition of managed services is proactive management — catching problems before they affect your business. In practice, many MSPs operate reactively: they respond to tickets, but they don't proactively identify and address issues before users notice them.
The difference shows up in metrics. Ask for:
A mature MSP will have clear answers and data to back them up. A reactive MSP will give you vague answers about "monitoring everything" without being able to quantify what that means.
6. Vertical Experience and Compliance Familiarity
A generalist MSP that serves everyone from dental offices to law firms to manufacturers may have broad experience but shallow depth in any specific area. For businesses in regulated industries or with specialized technology environments, vertical expertise matters.
Ask specifically:
For healthcare organizations, a HIPAA Business Associate Agreement (BAA) is non-negotiable. For government contractors pursuing CMMC certification, the MSP needs to understand the CMMC framework and ideally be a Registered Practitioner Organization (RPO). For financial services firms, PCI-DSS and SOC 2 familiarity is essential.
7. Contract Terms — Flexibility, Ownership, and Exit
MSP contracts are where the relationship gets real. Read them carefully, and pay particular attention to:
Contract length: Most MSPs require 1–3 year commitments. Longer terms often come with better pricing, but they also reduce your leverage if service quality degrades. A 3-year contract with no performance-based exit clause is a significant risk.
Termination for cause: What constitutes a material breach that allows you to exit without penalty? Is repeated SLA failure a termination trigger? Get this in writing.
Data and documentation ownership: As noted above, ensure you own your documentation, configurations, and data. Specify in the contract that all documentation must be provided to you in a portable format upon termination.
Price escalation: Does the contract allow for annual price increases? If so, is there a cap? Uncapped escalation clauses can significantly change your TCO over a multi-year term.
Scope creep: How are out-of-scope requests handled? Is there a clear process for quoting and approving work that falls outside the managed services agreement? Ambiguous scope definitions lead to disputes.
Transition assistance: What does the MSP commit to providing during an offboarding transition? A good provider will commit to a defined transition period and deliverables. A provider that makes offboarding difficult is telling you something about how they view the relationship.
8. Financial Stability and Business Continuity
Your MSP is a critical operational dependency. If they go out of business, get acquired, or lose key staff, your operations are at risk. Evaluate their stability:
The MSP industry has significant consolidation happening — private equity firms are rolling up smaller providers at a rapid pace. An acquisition isn't automatically bad, but it often means changes to staffing, pricing, and service quality. Ask directly whether the company is for sale or has received acquisition interest.
---
The Questions Most Evaluations Skip
Beyond the eight criteria above, there are questions that rarely appear in RFPs but consistently reveal the most about an MSP's operational reality:
"Walk me through your last major outage — what happened, how you detected it, and how you resolved it." A mature MSP will have a clear post-incident review process and will be able to describe a real event with specifics. Vague or defensive answers are a red flag.
"What happens to my environment if you go out of business tomorrow?" This question reveals how seriously they've thought about business continuity — for you, not just for themselves.
"Can I speak with a client who left you, and why did they leave?" No MSP will volunteer this, but asking it signals that you're a serious evaluator. Their response to the question is itself informative.
"What do you not do well?" Every MSP has gaps. A provider that claims to be excellent at everything is either lying or lacks self-awareness. A provider that honestly identifies their limitations and explains how they address them is demonstrating the kind of transparency you want in a long-term partner.
"How do you handle a situation where a client's request is outside your area of expertise?" Do they have a referral network? Do they bring in specialists? Do they pretend to know things they don't?
---
Red Flags That Should End the Conversation
Some signals in an MSP evaluation are disqualifying. Walk away if you encounter:
No documented SLAs or vague SLA language. "We respond quickly" is not an SLA. If they won't commit to specific numbers in writing, they won't perform to specific numbers in practice.
Technician-to-client ratios above 1:100. At this ratio, your environment is not getting proactive attention. You're getting reactive break-fix with a managed services label.
No ownership of your documentation. If your configurations, runbooks, and asset inventory live only in their systems, you're being held hostage.
Resistance to reference calls. A confident MSP will connect you with multiple clients without hesitation. Resistance or delay is a signal.
Pricing that seems too good. Managed services is a labor-intensive business. An MSP pricing significantly below market is either cutting corners on staffing, security tools, or both. Understand exactly what's included before comparing prices.
No cyber liability insurance or inadequate coverage. If they have a breach that affects your environment, you want them to be able to cover the costs. Ask for a certificate of insurance.
Pressure to sign quickly. A legitimate MSP will give you the time you need to evaluate properly. High-pressure sales tactics are a preview of the relationship dynamic.
---
How to Structure the Evaluation Process
A rigorous MSP evaluation typically takes 4–6 weeks and follows a structured process:
Week 1–2: Requirements definition. Document your environment (endpoints, servers, applications, locations), your compliance requirements, your current pain points, and your budget range. Define what success looks like in year one.
Week 2–3: Vendor identification and RFP. Identify 4–6 MSPs that serve your geography and vertical. Issue a structured RFP that covers all eight criteria above. Require written responses, not just a sales call.
Week 3–4: Proposal review and shortlist. Evaluate written proposals against your requirements. Shortlist 2–3 providers for deeper evaluation.
Week 4–5: Reference calls and site visits. Conduct reference calls with at least three clients per shortlisted provider. Ask the hard questions. If possible, visit the MSP's NOC or operations center.
Week 5–6: Contract negotiation. Don't accept the standard contract. Negotiate SLA commitments, documentation ownership, termination for cause, and transition assistance before signing.
---
The Case for Vendor-Neutral MSP Advisory
The MSP market has over 40,000 providers in the US. The quality range is enormous — from sophisticated, well-staffed operations with mature security practices to one-person shops with a monitoring tool and a white-labeled help desk.
Navigating this market without guidance is difficult. MSP sales processes are designed to obscure the differences between providers, not illuminate them. Reference calls are curated. Demos are polished. Contracts are written to favor the provider.
BTSI helps businesses across the country evaluate and select managed services providers without a vendor agenda. We've worked with dozens of MSPs across our 220+ provider network, and we know which ones perform and which ones don't — by vertical, by geography, and by company size. Our advisory process runs the evaluation, negotiates the contract, and stays engaged through the transition.
Schedule a free managed services consultation with BTSI — we'll assess your current IT environment and help you identify whether managed services is the right model, and if so, which provider is the right fit.
Ready to see what vendor-neutral IT advice can do for your business?
Book a free consultation with BTSI — no cost, no obligation.
Book My Free Consultation