Buyer's Guide / MSP Selection
How to Choose a Managed IT Service Provider: 9 Questions Every SMB Owner Should Ask
Most MSP contracts look identical on paper — flat-rate pricing, "24/7 support," proactive monitoring — which is exactly why the wrong choice usually doesn't reveal itself until your server goes down on a Friday afternoon. This guide gives you nine pointed questions to ask on your next discovery call so you know how to choose a managed service provider before you sign, not after.
In This Article
Why the Standard MSP Checklist Fails SMBs
Most managed IT service provider evaluation guides tell SMBs to "assess technical expertise" and "check certifications." The problem: a 15-person dental practice in Tacoma has no way to audit whether an MSP's engineers are actually competent. The right strategy is to ask questions that force the provider to reveal the answer themselves.
Why Self-Disclosure Questions Work
A provider who can name their onboarding project manager, quote the SLA penalty clause from memory, and list the specific compliance frameworks they've implemented for HIPAA clients is demonstrating competence — not claiming it. When you ask how to choose an MSP and get vague assurances back, that vagueness is your answer.
The 9 Questions to Ask Every MSP Before You Sign
These nine questions are designed for a 30-minute discovery call. Each one has a clear tell: a weak answer signals a provider coasting on sales polish, while a strong answer surfaces the operational reality behind the proposal.
Q1: What Does Your Onboarding Process Look Like for the First 90 Days?
- Weak answer: "We'll get you set up and learn your environment as we go."
- Strong answer: "We run a structured onboarding over 30-60 days: network discovery in week one, security gap assessment in week two, documentation complete by day 30, and a named project lead assigned before your contract starts."
Providers who wing onboarding tend to "discover" your environment reactively — during an outage.
Q2: What Is Your Guaranteed Response Time, and What Happens If You Miss It?
- Weak answer: "We prioritize critical issues and respond as quickly as possible."
- Strong answer: "Critical issues get a 1-hour response. If we miss it, the SLA includes a service credit — here's the clause."
An SLA — a Service Level Agreement, the contract section defining response time commitments — means nothing without a financial penalty for breach. If the provider can't quote the penalty clause, it doesn't exist.
Q3: How Is Security Layered Across Our Environment?
- Weak answer: "We have an antivirus solution and monitor for threats."
- Strong answer: "We deploy EDR on every endpoint, enforce MFA on all cloud accounts, run quarterly phishing simulations, and monitor with a SIEM — here's how each layer works together."
EDR (Endpoint Detection and Response) is active threat hunting on individual devices — not the passive antivirus that ships with Windows. MFA (Multi-Factor Authentication) requires a second verification step beyond a password. Ask the provider to name all three layers: endpoint, identity, and human. A complete cybersecurity stack includes all of them — including employee phishing training, which is where most breaches actually start.
Q4: Do You Have Experience With Our Industry's Compliance Requirements?
- Weak answer: "We follow security best practices for all clients."
- Strong answer: "We've implemented HIPAA controls for dental and healthcare clients, SOC 2 frameworks for financial firms, and certificate-of-insurance requirements for construction companies — here are three references."
Washington-state SMBs in dentistry, finance, and construction face specific compliance requirements — HIPAA, SOC 2, and insurance carrier mandates respectively. "We follow best practices" without naming a framework means the provider hasn't done it.
Q5: Who Answers After-Hours Emergencies — Your Team or an Outsourced NOC?
- Weak answer: "We have 24/7 monitoring and support coverage."
- Strong answer: "After-hours calls go to our on-call engineer — same team, not a third-party NOC. Average callback is under 20 minutes."
A NOC (Network Operations Center) is a remote monitoring facility — often outsourced by smaller MSPs to a third party. The technician who answers at 2 a.m. may have never seen your environment. Ask explicitly: is it your team or a vendor?
Q6: What Does Your Offboarding Process Look Like If We Leave?
- Weak answer: "We'd work something out — we don't really lose clients."
- Strong answer: "We document everything in your name from day one. If you leave, you get full export of your documentation, credentials, and configurations within 30 days — no holdbacks."
A provider who owns your documentation, holds admin credentials, or adds friction to leaving has a structural incentive to keep you captive. This question is a direct trust test.
Q7: Do You Offer a vCIO or Strategic IT Roadmap?
- Weak answer: "We'll flag issues as they come up and make recommendations when needed."
- Strong answer: "You get a named vCIO who meets with you quarterly, builds a 12-month IT roadmap, and helps you budget for infrastructure before it becomes an emergency."
A vCIO or strategic IT roadmap — where vCIO stands for Virtual Chief Information Officer — turns your MSP from a break-fix vendor into a business advisor. Without it, you're paying for reactive support dressed up as a strategy.
Q8: How Is Pricing Structured, and What Is Not Included?
- Weak answer: "It's a flat monthly rate — everything's covered."
- Strong answer: "Per-user pricing covers X, Y, and Z. Project work, hardware procurement, and after-hours emergency calls beyond two per month are scoped separately — here's the full exclusion list."
Per-user pricing charges a fixed amount per employee. Per-device pricing charges per managed machine. Flat-rate covers all users and devices under one fee. The model matters less than knowing exactly what falls outside it.
Q9: Can You Provide Three Local Client References in a Similar Industry and Size?
- Weak answer: "We have many happy clients — I can send you some testimonials."
- Strong answer: "Here are three clients in Pierce County, similar size to yours — you can call them today."
National MSPs frequently can't produce local references in your industry and size range. A provider who can name three clients you could call tomorrow has nothing to hide.
Red Flags That Should End the Conversation
Four specific disqualifiers come up repeatedly in bad MSP engagements — and SMB buyers routinely miss them during the sales process because they sound reasonable in the moment.
- No written SLA or no financial penalty for breach: A verbal promise to respond "quickly" is unenforceable. If the SLA doesn't specify a credit or remedy for missed response times, assume it will be missed.
- The account manager and the technician are the same person: One overextended person cannot handle strategic account management and active support tickets simultaneously. This structure guarantees one of them gets dropped.
- Hardware pitch before business understanding: Any provider who leads with a server refresh or firewall upgrade before auditing your environment is selling inventory, not solving problems.
- Vague compliance answer: "We follow best practices" with no named framework — HIPAA, SOC 2, NIST — means the provider has no documented compliance process. For regulated industries, this is a direct liability.
How a Local Tacoma MSP Changes the Equation
For South Sound businesses, the practical gap between a local MSP and a national one becomes visible the moment question five above reveals an outsourced overnight NOC. On-site response time, Washington state data privacy familiarity, and a direct phone line to a named technician are not features national providers can match at scale.
The On-Site Response Gap
A national MSP's remote support model works fine for password resets. It fails when a server room floods in Puyallup at 11 p.m. and the "24/7 team" is a NOC in a different time zone with no dispatch authority. ArgoCTS serves businesses across Pierce County — including Federal Way and Olympia — with on-site capability that doesn't depend on a third-party escalation chain.
What ArgoCTS Does Differently
Unlike national MSPs that route you into a rotating helpdesk queue, ArgoCTS assigns a named vCIO for strategic planning and answers the phone directly. Every engagement starts with a free security assessment — before any contract is signed — so you have a concrete picture of your environment before committing to managed IT services.
Frequently Asked Questions
What questions should I ask a managed service provider before signing a contract?
Ask about the 90-day onboarding plan, SLA penalty clauses, security layering (EDR, MFA, phishing training), compliance framework experience, after-hours coverage model, offboarding process, vCIO availability, pricing exclusions, and local client references. Vague answers to any of these are disqualifiers, not just talking points.
How do I know if an MSP is right for my small business?
The right MSP can name a specific onboarding timeline, quote their SLA penalty clause, describe security layers beyond antivirus, and provide local client references in your industry. If a provider answers all nine evaluation questions with specifics rather than generalities, they've earned a deeper conversation.
What is a fair response time guarantee in an MSP SLA?
A fair SLA for critical issues — server down, full office outage — is a 1-hour response time with a defined service credit if missed. Non-critical issues commonly carry 4-8 hour response windows. Any SLA without a financial penalty for breach is a marketing document, not a commitment.
What compliance standards should my Tacoma business ask an MSP about?
Washington-state SMBs in dentistry and healthcare should ask about HIPAA. Financial firms should ask about SOC 2. Construction companies should confirm the MSP understands certificate-of-insurance and cyber liability requirements. Ask the provider to name specific controls they've implemented — not just frameworks they're familiar with.
Use These 9 Questions on Your Next MSP Call — Including Ours
Book a free security assessment with ArgoCTS and we'll walk through every one of these questions together — no jargon, no pressure, just a clear picture of where your IT stands and what it will take to protect it.
Book Your Free Security Assessment
