MSP Evaluation Worksheet Score any IT provider.

Six categories, 24 questions. Score your current IT provider β€” or any provider you're considering. Takes about 10 minutes. Bring the results to any vendor meeting, including ours.

πŸ“‹ 24 Questions 6 Categories Free Β· No Signup Print / Export Ready
0 of 24 questions answered 0%
⏱️ Response Time & SLA 20 pts β€”
Does your IT provider have a written, signed SLA with specific response time commitments?
Verbal promises don't count. A real SLA names the issue type, response time target, and what happens if they miss it.
What is the guaranteed response time for a production-down emergency?
1 hour or less is the standard for managed IT. Anything beyond 4 hours for a full outage is a red flag.
Is after-hours emergency support available for critical issues?
Ransomware doesn't wait until Monday morning. Confirm whether after-hours response is included or costs extra.
Does your provider track and report on SLA performance (tickets closed, response times, etc.)?
An SLA without reporting is unenforceable. Ask for last month's performance summary.
πŸ’Ύ Backup & Recovery 20 pts β€”
Does your IT provider perform and document test restores β€” not just confirm backup jobs ran?
A backup job showing green does not mean your data is recoverable. Ask for the last restore test report. If they don't have one, that's your answer.
Are backups stored off-site or in a separate cloud location from the primary data?
Ransomware that encrypts the primary server often targets local backups too. Off-site or immutable cloud storage is required for real protection.
Can your IT provider state your current RTO and RPO β€” and are these documented?
RTO = how long to restore. RPO = how much data you'd lose. If your IT provider can't answer both without pausing, they haven't actually planned your recovery.
Are backup files encrypted at rest and in transit?
Unencrypted backups expose the same data a breach would. Confirm encryption is enabled, not just assumed.
πŸ“„ Documentation & Transparency 16 pts β€”
Do you have a current network diagram and asset inventory you can access at any time?
If your IT provider left tomorrow, could you hand a new provider a complete picture of your environment? If the answer is no, you're dependent on one person's tribal knowledge.
Are all passwords, licenses, and vendor credentials stored somewhere you can access β€” not just in the provider's systems?
This is a common pain point when switching providers. Make sure your Microsoft 365 admin credentials, domain registrar access, and key vendor logins are in your control.
Does your provider give you a written summary after completing a project or major change?
Change documentation protects you if something breaks later, and ensures the next person can understand what was done.
If your primary IT contact left their company tomorrow, would their replacement be able to support your environment from day one?
Key-person risk is one of the most common hidden vulnerabilities in small business IT. Documented environments eliminate it.
πŸ’° Pricing & Contract Terms 16 pts β€”
Is pricing flat-rate and predictable, or do bills vary month to month based on hours used?
Hourly billing creates an incentive for more tickets, not fewer. Flat-rate MSPs benefit when your environment runs cleanly.
Is the contract month-to-month, or are you locked into a multi-year term?
Long-term contracts aren't always bad, but a provider that requires a 3-year commitment upfront before proving value is worth questioning.
Are all included services clearly listed in writing β€” or is scope left vague?
Vague scope leads to surprise "out of scope" charges. A good contract lists exactly what's included and what costs extra.
Can you exit the contract without penalty if the provider isn't meeting their commitments?
Look for a performance-based exit clause. If the provider misses SLA targets consistently, you should be able to leave without a cancellation fee.
πŸ”’ Security Posture 16 pts β€”
Does your IT provider actively manage endpoint protection (EDR) across all your devices β€” not just install antivirus and move on?
Managed EDR means someone is reviewing alerts and responding to threats. Installed-and-forgotten antivirus is not the same thing.
Is MFA enforced for Microsoft 365, email, and remote access β€” not just recommended?
Recommended is not enforced. If staff can still log in without MFA, the policy isn't protecting you.
Does your provider include patching management β€” ensuring OS and software updates are applied on a defined schedule?
Unpatched systems are the single most common ransomware entry point. Ask for proof of patch compliance rates.
Has your IT provider ever performed or commissioned a security risk assessment for your environment?
Not a sales pitch β€” an actual written assessment of your current exposure. Required for HIPAA, strongly recommended for anyone.
πŸ“ž Communication & Reporting 12 pts β€”
Do you receive a regular (monthly or quarterly) report on your IT environment's health?
Covers patch status, backup health, open tickets, security alerts. If you're only hearing from your IT provider when something breaks, that's reactive β€” not managed.
Is there a clear single point of contact who knows your environment and business?
Calling a generic helpdesk queue and explaining your setup from scratch every time is a time tax on your staff. A dedicated contact who knows your environment eliminates that.
When something breaks, does your provider communicate proactively β€” or do you have to chase them for updates?
Radio silence during an outage is a red flag. Good providers send status updates at defined intervals even when there's nothing new to report.

Your MSP Evaluation Results

Provider evaluated β€”
Questions answered 0 of 24
Total score 0 / 48
Score percentage β€”
Verdict Complete the worksheet above

See how LineSight Digital scores.

We're happy to walk through this worksheet with you β€” about us, or about your current provider. Free IT assessment, no obligation.

  • Written SLA β€” 4hr standard, 1hr emergency
  • Verified backups with restore test reports
  • Full environment documentation, yours to keep
  • Month-to-month contracts
  • BAA available for HIPAA clients
Get Free IT Assessment See our pricing β†’
Common Questions

What to Ask Any IT Provider

What should I look for when evaluating an MSP? +

The six areas that matter most: response time and SLA guarantees, backup verification (do they test restores?), documentation of your environment, pricing transparency and contract terms, security posture and tooling, and communication quality. An MSP that can't answer clearly in all six is a risk.

What's a reasonable SLA for an IT provider? +

For small businesses, a reasonable SLA is 4 business hours for standard issues and 1 hour for production-down emergencies. Any provider that won't commit to a written SLA is relying on goodwill rather than accountability.

How do I know if my IT provider actually tests our backups? +

Ask for a restore test report. A legitimate MSP performs periodic test restores and documents the results. If your provider only shows you that the backup job ran without a corresponding restore test, you don't actually know if your data is recoverable.

Should I be worried if my IT provider holds all our passwords and credentials? +

Yes. You should always have direct access to your Microsoft 365 admin account, domain registrar, and key vendor logins. A provider that holds these exclusively creates a painful transition if you ever need to switch β€” and in some cases it's used as leverage to keep clients from leaving.

Want to See How We Score?

Score us on this same worksheet. We'll walk through every question with you during a free IT assessment β€” no sales pressure, just straight answers.

Get Free IT Assessment See Our Pricing