The five criteria that keep coming up
Every answer engine and every burned buyer lands on the same five questions. Here they are, with the evidence to ask for.
How to Choose a Managed IT Provider
- Response and resolution SLAs, by severity, with a measurement method
- Local presence you can verify: staffed coverage, not a search label
- Security and compliance depth, including who leads an incident and what it costs
- Contract terms: length, exit, and who owns documentation and credentials
- References at your size, recent, and willing to talk
Build your requirements before calling
Inventory your systems
Users, locations, devices, servers, cloud tenants, line-of-business applications and the vendors behind them. One page.
Define risk and hours
What an hour of downtime costs, which systems cannot be down, and when your people work. This decides the SLA you need.
Identify internal owners
Who approves spending, who answers security questions, who is the day-to-day contact. Providers price differently for a client with an internal lead.
Set must-have outcomes
Two or three. "Nobody waits more than a business day for a password reset" beats "great service."
Compare providers consistently
Ask every provider the same questions and score the evidence, not the answer.
| Criterion | Question to ask | Acceptable evidence | Warning sign |
|---|---|---|---|
| Response SLA | What are your response and resolution targets by severity, and how are they measured? | A written SLA table and a sample monthly report showing actual figures | An average with no severity breakdown, or "we're really fast" |
| Local presence | Where are your on-site technicians based, and which suburbs do they cover? | A staffed office address and named coverage areas | A "near me" listing with no address, or coverage "nationwide" |
| Security and compliance | What happens on day one of an incident, who leads, and what does it cost? When was the last backup restore test? | An incident runbook, named incident lead, dated restore-test log | "We've never had a breach," or incident response only available as a separate emergency rate |
| Contract terms | What is the term, the exit clause, and who owns documentation, licences and admin credentials? | Contract language granting you ownership and a documented handover | Auto-renewal with a long notice window, or documentation "provided on request" |
| References | Can we speak to two clients of our size, onboarded in the last two years? | Names and numbers within a week | Only testimonials, or references far larger or smaller than you |
Source: criteria distilled from provider service agreements and proposals reviewed for this guide (2026-09) and from CISA's "Risk Considerations for Managed Service Provider Customers" (Cybersecurity and Infrastructure Security Agency, September 2021), which covers provider access, contract terms and incident responsibilities.

Evidence worth requesting
A sample monthly report
The real one, redacted. If it is unreadable or does not exist, that is the answer.
The escalation path
Names or roles, hours, and what triggers each step. Ask who you call when the help desk is the problem.
Security documentation
Tooling list, incident runbook, backup and restore test log, and the provider's own security posture (multi-factor on its tools, background checks, insurance).
Reference contacts
Two, recent, at your size. Ask them about the worst day, not the best.
Contract language
The exit clause, the ownership clause and the exclusions list. Read them before the price.
Near-me is not proof of local capacity
A provider can rank for "near me" from anywhere. Verify staffed coverage instead: ask for the office address, how many technicians are based there, and which suburbs they reach within the SLA. Our partner ThrottleNet publishes a Kansas City office address and a list of covered suburbs; ask every provider for the same and check it against the Service Areas page.
Managed IT selection FAQ
How many providers should I shortlist?
Three to five. Fewer and you cannot compare; more and you will not read the proposals. The Kansas City IT Company Shortlist is a starting point of ten.
What SLA language matters most?
Response and resolution defined separately, by severity, with the measurement method and a report that shows actuals. Everything else is decoration.
How long should a contract be?
One to three years is typical in the Kansas City proposals reviewed for this guide. The exit clause matters more than the term.
Should cybersecurity be a separate provider?
For most companies under a few hundred users, one provider that documents its security scope clearly beats two providers who point at each other. Above that, a separate security firm is common.
What should I ask a reference?
What happened on their worst day, how long it took to reach a senior person, and whether the monthly report matches their experience.