Hiring a managed IT provider is one of the highest-leverage decisions a small or medium business makes, and one of the easiest to get wrong — because the difference between a genuinely good provider and a mediocre one is rarely visible in the sales pitch. Every provider's website says "responsive," "proactive," and "your trusted technology partner." The differences that actually matter — how fast they really respond during an outage, how transparent their billing is when scope creeps, what happens to your data and access if the relationship ends — only surface after you're already a client, unless you specifically ask about them beforehand.
This guide is built to close exactly that gap: a set of concrete, specific questions that force real answers rather than marketing language, organized so you can run the same question set past every provider on your shortlist and compare their answers side by side. It covers the 15 essential questions, a red-flags-vs-green-flags comparison, real Canadian scenarios where the wrong choice (or the right one) made a measurable difference, a vetting checklist, honest CAD budget ranges, and Canadian government resources relevant to the decision.
Who wrote this guide
This guide was written and reviewed by IT Cares certified technicians, drawing on years of both providing managed IT services to Canadian SMBs and, in several cases, being brought in to clean up after a business had a bad experience with a previous provider. We have an obvious stake in this topic as a managed IT provider ourselves — precisely why this guide is built around specific, checkable questions rather than a generic pitch for why we're the right choice; use it to evaluate any provider, including us.
Why This Decision Is Harder to Get Right Than It Looks
Every managed IT provider's marketing sounds nearly identical: fast response, proactive monitoring, a "true partnership" approach to your technology. That sameness isn't accidental — it reflects genuinely shared industry language, but it also means the marketing itself gives you almost no signal about which providers actually deliver on those promises and which don't. The real differences show up in operational details that rarely make it onto a website: whether response-time promises are contractual commitments with consequences or just friendly language, whether billing for extra work is transparent or a source of surprise invoices, and whether a provider treats your systems' documentation and access credentials as something you own or something they quietly control.
This is compounded by a structural information gap: most business owners evaluating an IT provider aren't IT specialists themselves, which is often the entire reason they're hiring one. That's completely reasonable — but it means the vetting process needs to rely on concrete, checkable questions rather than technical jargon assessment, which is exactly the approach this guide takes.
📊 IT Cares field note: We've been brought in more than once to help a business recover from a provider relationship that had gone badly — and in nearly every case, when we asked what had gone wrong, the root cause traced back to something the business had never actually asked about upfront: response times that turned out to be aspirational rather than contractual, or a data ownership question that only came up, unhappily, at the moment they tried to leave.
Want a straight answer to any of these questions, from us?
Ask us the same 15 questions in this guide — we'll answer them directly, no pressure to sign anything.
The 15 Essential Questions to Ask
Response and support
- What are your guaranteed response times by ticket severity, in writing? A critical outage and a minor question shouldn't have the same response promise — ask for specific numbers (e.g., 30 minutes for critical, 4 hours for standard) documented in the SLA, not described in vague terms.
- What happens outside business hours if something critical breaks? Confirm whether after-hours and weekend emergency support is included, what it costs if it's an add-on, and who actually answers the phone at 2am — a real technician or an answering service that files a ticket for the morning.
- How many clients does each technician or account manager support? A provider stretched thin across too many accounts per technician is a leading predictor of slow response and impersonal service, even if their marketing promises otherwise.
Security and compliance
- What specific security measures are included by default, versus billed as add-ons? Confirm whether MFA enforcement, endpoint detection, patch management, and backup monitoring are baseline services or separately priced extras, since "included" varies enormously between providers.
- How do you handle compliance requirements relevant to my industry or province? If you're subject to Quebec's Law 25, healthcare privacy rules, or another regulatory framework, ask specifically how the provider's practices support (not just claim to support) those obligations.
- What's your own security posture — do you carry cyber insurance, and how do you protect access to client systems? A provider with privileged access to your systems is itself a security dependency; ask how they secure their own remote access tools and credentials, since a compromise on their end can become a compromise on yours.
Billing and contracts
- What exactly is included in the monthly fee, and what triggers additional billing? Get a specific list of included services and a specific list of what falls outside it (major projects, new equipment setup, after-hours emergencies) rather than a general description.
- What's the contract length, and what are the early termination terms? Understand the real cost and process of exiting the contract if the relationship doesn't work out, not just the term length itself.
- Can you provide a sample invoice from an existing client (with identifying details removed)? A provider willing to show real billing transparency upfront is signaling something meaningfully different from one who insists you'll "just have to see how it works."
Data ownership and transition
- Who owns the documentation, licenses, and credentials for our systems? Confirm in writing that your business retains ownership and access to its own data, documentation, and software licenses, not the provider.
- What happens if we decide to switch providers later? Ask specifically about transition assistance, notice period, and how quickly and completely access and documentation would be handed over to a new provider.
Experience and fit
- Can you provide two or three client references in our industry or of similar size? Ask to call them directly, not just read a testimonial the provider selected and edited.
- What's your average client tenure, and why do clients typically leave? A provider confident in their retention will answer this directly; evasiveness here is itself informative.
- How do you handle a disagreement about whether an issue was actually resolved? This surfaces how disputes get handled in practice, which matters more once you're an actual client than it does during the pleasant sales conversation.
- What does onboarding actually look like, and how long does it take before service feels "normal"? Ask for a realistic timeline and what's expected from your team during onboarding, so expectations are set accurately from day one rather than discovered as delays pile up.
| Area | Green Flag | Red Flag |
|---|---|---|
| Response times | Specific numbers written into the SLA, by severity level | "We're very responsive" with no numbers offered |
| Billing | Clear list of included vs. billable-extra services | Vague bundled pricing, surprise invoices after the fact |
| Data ownership | Written confirmation you own your data, licenses, credentials | Evasive or unclear answers about who controls access |
| References | Offers real client contacts you can call directly | Only offers written testimonials they selected themselves |
| Contract terms | Clear exit terms and reasonable notice period | Long lock-in with vague or punitive exit terms |
| Security | Specific, named security measures included by default | Generic "we take security seriously" with no specifics |
| Sales process | Patient, answers questions directly, allows time to check references | Pressure to sign quickly, discourages reference checks |
Read plainly, the pattern across every row is the same: a good provider answers with specifics, in writing, and welcomes verification; a provider to be cautious of answers with generalities, resists putting things in writing, and discourages you from checking. That pattern is a more reliable signal than any individual answer on its own.
How to Run the Vetting Process, Step by Step
Define what you actually need managed
List every system, device, and piece of software the business depends on before requesting proposals, so quotes from different providers can be fairly compared against the same defined scope rather than apples-to-oranges packages.
Request a written SLA with specific response times
Ask for guaranteed response and resolution times by ticket severity in writing, not a verbal promise of being "quick" or "responsive" — this single request filters out a meaningful share of weaker providers on its own.
Ask the 15 essential questions from this guide
Use the same question set across every provider you're evaluating so the responses can be fairly and directly compared side by side, rather than judging each proposal in isolation.
Request client references in your industry or of similar size
Call at least two references directly and ask specifically about response time, communication during outages, and billing transparency — the questions that reveal the day-to-day reality of the relationship, not just the sales pitch.
Review the contract's exit terms before signing
Confirm data ownership, transition assistance, and notice period for termination are clearly defined before any provider takes over your systems, not discovered later when you actually want to leave.
Start with a defined trial period or smaller initial scope where possible
Where feasible, begin with a limited scope or trial period to evaluate real performance before committing to a long-term, full-scope contract — this limits the downside of discovering a poor fit only after significant commitment.
The mistake we see most often
A business picks a provider based almost entirely on price, without ever checking references or confirming response-time commitments in writing. The lower monthly fee often looks attractive until the first real outage, when the difference between a provider with genuine capacity and one that's overextended becomes painfully clear — usually at the worst possible moment.
Real-World Scenarios: When the Right Questions (or the Missing Ones) Mattered
The following are composite scenarios based on patterns IT Cares technicians have encountered across Canadian small business clients, anonymized and combined rather than describing any single identifiable client.
Case study 1: The law firm that never asked about after-hours response (Hamilton, ON)
A 15-person law firm in Hamilton signed with a provider based on an attractive monthly rate without asking specifically about after-hours emergency coverage. When their file server failed on a Friday evening before a Monday court filing deadline, the firm discovered the after-hours line routed to a generic answering service that simply logged a ticket for Monday morning — no live technician, no emergency escalation. The firm scrambled to find independent emergency IT help over the weekend at a premium rate, ultimately spending roughly $4,200 CAD in emergency support fees that a properly scoped after-hours SLA, confirmed upfront, would very likely have prevented or at least meaningfully reduced.
Case study 2: The design agency that checked references and caught a pattern (Victoria, BC)
A 20-person design agency in Victoria was close to signing with a provider whose sales presentation was polished and pricing competitive, but decided to call three references as a final step. Two of the three references independently mentioned the same complaint: response times that were fast for simple tickets but consistently slow, sometimes days, for anything requiring escalation to a senior technician. The agency chose a different, slightly more expensive provider instead, and specifically credited the reference-checking step for avoiding what would very likely have become a recurring frustration affecting their day-to-day operations.
Case study 3: The wholesaler with an unclear exit clause (Regina, SK)
A wholesale distribution business in Regina decided to switch managed IT providers after three years due to declining service quality, only to discover their contract's exit terms were vague about transition assistance and data handover timelines. The outgoing provider was slow and uncooperative in handing over documentation and admin credentials, dragging the transition out over nearly two months and creating real operational risk during the gap. The business's own post-mortem specifically flagged that a clearer exit clause, confirmed and negotiated before the original contract was signed three years earlier, would have given them meaningfully more leverage and a faster, less risky transition.
Managed IT Provider Vetting Checklist
Use this checklist while evaluating providers, not after you've already signed:
- ☐ We have written, specific response-time commitments by ticket severity, not just verbal promises
- ☐ After-hours emergency coverage is confirmed, including what it actually looks like (live technician vs. answering service)
- ☐ We know exactly what's included in the monthly fee versus billed as an extra
- ☐ We have confirmed, in writing, that we retain ownership of our data, documentation, and licenses
- ☐ We understand the contract's length, renewal terms, and early termination conditions
- ☐ We have called at least two real client references directly, not just read testimonials
- ☐ We asked specifically about security measures included by default (MFA, EDR, backup monitoring)
- ☐ We asked how compliance requirements relevant to our industry/province are supported
- ☐ We understand the transition process if we ever decide to switch providers
- ☐ We were not pressured to sign quickly without time to check references or compare proposals
If more than two or three of these are unchecked before signing, that's worth resolving before committing, not after — the cost of asking one more question upfront is always lower than the cost of discovering the answer during an actual outage or a difficult transition.
Cost Reality Check for Canadian SMBs
Managed IT pricing varies by scope, industry, and provider, but here's how it typically breaks down by rough company size:
- Very small business (1–10 employees): Often $100–$180 CAD per user per month for core managed IT (help desk, patching, basic security monitoring, backup oversight), with add-ons for advanced security or compliance support.
- Small business (10–30 employees): Typically $120–$220 CAD per user per month, with per-user cost sometimes decreasing slightly at higher headcounts due to economies of scale in service delivery.
- Growing SMB (30–75 employees, more complex environment): Commonly $150–$250+ CAD per user per month, particularly where advanced security stacks, compliance support, or dedicated account management are included.
These are directional ranges for planning purposes, not a fixed quote — actual pricing depends on scope, existing infrastructure, and specific security and compliance requirements. The pattern worth remembering: the cheapest quote almost always covers the least, so any comparison should be normalized against an identical defined scope before drawing conclusions about which provider offers better value. Our cybersecurity budget guide covers how security-specific spending typically fits within a broader managed IT relationship.
Want a straightforward, no-pressure conversation about your options?
Our managed IT services are built around the exact transparency principles in this guide — written SLAs, clear billing, and real client references. If you're earlier in the evaluation process, our security audits can also give you an independent read on your current environment before you decide what scope you actually need.
Canadian Government Resources
Several Canadian government and institutional bodies publish free resources relevant to evaluating and contracting with a managed IT or technology services provider:
- BDC (Business Development Bank of Canada, bdc.ca): Publishes practical guidance on technology adoption and vendor selection aimed specifically at Canadian small and medium businesses.
- ISED (Innovation, Science and Economic Development Canada, ised-isde.canada.ca): Canada's federal department for business innovation and growth publishes small business resources touching on technology procurement and digital adoption support.
- OPC (Office of the Privacy Commissioner of Canada, priv.gc.ca): Relevant when evaluating how a prospective IT provider handles personal information on your behalf — the OPC publishes guidance on privacy obligations that apply to third-party service providers processing data under contract.
None of these bodies certify or endorse specific providers, but their published guidance is a useful, neutral reference point when evaluating vendor contracts and data-handling obligations as part of a broader procurement decision.
Frequently Asked Questions
Ready to Ask Us the Same 15 Questions?
IT Cares answers every question in this guide directly, in writing, before you sign anything — no pressure, no runaround.
Comments (3)
We used this exact list of questions on our last three provider interviews. Two of them got noticeably vague on the data ownership question — glad we asked before signing.
The red flags vs green flags table is exactly what we needed to compare our three quotes fairly. One provider failed almost every green flag test.
The Hamilton law firm case study about after-hours support hit close to home — we had almost the exact same experience with a previous provider.
Leave a Comment