The First Year With an IT Provider: What Good Actually Looks Like

Share this post on:

You signed the contract. The provider said they would reach out to get things started. Now you are waiting, wondering if anything is actually happening or if you made an expensive mistake. This is more common than it should be, and it points to a problem that most IT providers never talk about from the client side.

The first twelve months of a managed services relationship reveal everything about whether the partnership will work or slowly fall apart. Yet most business owners have no roadmap for what that year should look like. They are told to trust the process and hope for the best. That is not good enough when your operations depend on technology working.

This post describes what a competent provider delivers in the first year, what milestones you should expect, and what silence usually means.

Days 1 Through 30: Discovery and Stabilization

The first month is not about fixing things. It is about learning what exists, what is broken, and what is dangerous. A competent provider starts with a full network discovery and security assessment before touching a single setting. They inventory every device, every account, every piece of software, and every connection point. They identify what is exposed, what is out of date, and what the previous provider left undocumented.

This phase should produce a written baseline report. That report documents the current state of your environment: hardware age, software versions, open ports, user permissions, backup status, and known vulnerabilities. If your provider does not produce this document within the first thirty days, they are guessing about what they are protecting.

The provider should also conduct a security risk assessment during this window. Not a checkbox exercise. A real evaluation of your attack surface, your user access patterns, your patch status, and your exposure to common threats like phishing, ransomware, and credential theft. The results should be shared with you in plain language, not buried in a technical appendix that nobody reads.

What you should receive by day 30: a complete network inventory, a security risk assessment with prioritized findings, a list of immediate fixes already completed, and a written onboarding timeline for the next sixty days.

Days 31 Through 90: Implementation and Control

Once the baseline is established, the provider starts implementing their management layer. This includes deploying monitoring agents on every endpoint, configuring remote management tools, establishing backup verification procedures, setting up patch management, and standardizing security settings across the environment.

This is also when the provider should be addressing the critical findings from the initial assessment. Unpatched systems get patched. Default credentials get changed. Excessive user permissions get reduced. End-of-life hardware gets flagged for replacement. Backup jobs get tested, not just confirmed as “running.”

The ScalePad 2026 MSP Trends Report found that client onboarding is one of the two biggest inefficiency areas for MSPs, right alongside sales and marketing.1 That matters for you as a client because it means many providers treat onboarding as an afterthought. They deploy their tools, add your account to their dashboard, and move on to the next sale. The technical work gets done, but the deeper connection does not.

A strong provider uses this phase to establish communication rhythms. You should know who your primary point of contact is. You should know how escalations work. You should know what counts as an emergency and what counts as a standard request. These sound basic, but most clients cannot answer these questions six months into a relationship.

What you should receive by day 90: confirmation that all critical security findings have been addressed, a documented patch management process, verified backup and recovery testing results, and your first formal status report showing ticket volume, resolution times, and any open issues.

Days 91 Through 180: Optimization and Strategic Planning

This is where the relationship either deepens or stalls. The provider has stabilized your environment. The urgent fires are out. Now the question is whether they can move from reactive support to forward-looking guidance.

The first quarterly business review should happen around day 90 or 100. Not a sales call disguised as a review. A real conversation about what has been done, what is planned, what has changed in your business, and how technology should adapt to those changes. The provider should present data: ticket trends, response times, uptime metrics, security incidents caught and resolved, and progress against the initial risk assessment findings.

Axcient’s QBR handbook for MSPs describes the shift that needs to happen in this phase: moving from “here are your metrics” to “here is what these metrics mean for your business.”2 That reframing is the difference between a provider who delivers technical services and one who delivers business value.

This is also when the provider should start building your technology roadmap. Not a generic document pulled from a template. A plan that reflects your business goals, your compliance requirements, your growth plans, and your budget reality. The roadmap should cover the next twelve to twenty-four months and include projected costs, timelines, and dependencies.

Scopable’s guidance on annual technology planning emphasizes that this work should be separate from the QBR itself.3 The QBR reviews the past and near-term. The annual plan looks forward and makes deliberate choices about standards, lifecycle work, and budget allocation. Confusing the two means neither gets done well.

What you should receive by day 180: at least one formal QBR with data, a draft technology roadmap for the next twelve months, a review of your insurance and compliance posture, and a clear explanation of any recommended changes to your service agreement based on what they have learned about your environment.

Days 181 Through 365: Maturation and Accountability

The second half of the first year is about proving that the relationship works. The provider should be operating at full capability by now. Monitoring is established. Patching is routine. Security controls are in place and tested. Communication is consistent. Issues are getting caught before users notice them.

This is also when the provider should be delivering on the roadmap they built in the earlier phases. Hardware replacements that were identified in the discovery phase should be scheduled and executed. Software upgrades should be planned and tested. New security measures should be implemented based on threats that emerged during the year.

The second QBR should show measurable progress. Compare the current state to the baseline from day 30. How many vulnerabilities were resolved? What is the trend in ticket volume and severity? Are response times meeting the SLA? What incidents occurred and how were they handled? What is coming in the next quarter?

If the provider cannot show clear progress against the baseline, you need to ask why. Sometimes the answer is that your environment was in worse shape than anyone realized and the provider spent the entire year just getting to a stable point. That can be legitimate. But it should be documented and explained, not hidden behind vague language about “ongoing optimization.”

What you should receive by day 365: a year-end summary comparing your current state to the baseline, a full review of all security incidents and their resolution, an updated technology roadmap for the next twelve months, and a formal recommendation about whether your service agreement still matches your needs.

What Silence Sounds Like

The biggest risk in the first year is not a catastrophic failure. It is the slow accumulation of missed expectations that nobody talks about. The provider who never sends a report. The QBR that keeps getting postponed. The security finding that was identified in month two and still has not been addressed by month eight. The roadmap that was promised and never appeared.

Silence is data. If your provider goes quiet after the initial onboarding, they are telling you something about how they prioritize your account. If they cannot explain what they did last month and why it mattered to your business, they either do not know or do not think you are worth the explanation.

The IT Portal survey of over 2,000 MSP professionals found that 60 percent reported moderate to severe burnout among their staff.4 That burnout affects you directly. An overwhelmed technician does not monitor your environment unless something triggers an alert. An understaffed team does not have time to prepare a meaningful QBR. The provider’s internal problems become your service problems.

This is why the first year matters so much. It is not just about whether the provider can fix things when they break. It is about whether they can build the systems, habits, and communication patterns that prevent problems from reaching you in the first place.

What to Do If the First Year Is Not Working

If you are six months into a relationship and you have not received a baseline report, a security assessment, or a single QBR, you have a problem. The provider may be technically competent but operationally disorganized. Or they may be taking on more clients than they can serve properly.

Start by asking for the deliverables listed above. Put it in writing. Give them thirty days to produce the documentation and schedule the overdue reviews. A competent provider will acknowledge the gap and close it quickly. A struggling provider will make excuses. A neglectful provider will ignore the request entirely.

If you are past nine months and the provider has not delivered a technology roadmap or shown measurable progress against the initial assessment, you should begin evaluating your options. Not every relationship can be saved, and not every provider deserves another year of your patience.

The Datapath 30-60-90 day onboarding model makes a useful point that applies beyond just the first ninety days: the onboarding plan is one of the first real proofs of an MSP’s operating discipline.5 If the early milestones are missed, the pattern usually continues. What you see in the first ninety days is what you get for the next three years.

Where This Leaves You

The first year with a competent IT provider should feel like a steady progression from chaos to control. You should know more about your environment at month twelve than you did at month one. You should have documentation, metrics, a roadmap, and a relationship with a provider who understands your business well enough to give you honest guidance.

If none of that has happened, the problem is not your expectations. It is the provider’s execution. You deserve someone who treats your environment like it matters, not like it is just another dashboard tile they check between lunch and their next meeting.

Good providers exist. They do the work, they document it, and they show you the results. Find one and the rest of your technology decisions get a lot easier.

Sources

1 ScalePad, “2026 MSP Trends Report: Business Operations,” scalepad.com, 2026.

2 Axcient, “The Four Rs of MSP QBR Success: A Handbook,” axcient.com, 2025.

3 Scopable, “MSP Annual Technology Planning: Separate It From QBRs,” scopable.io, 2025.

4 IT Portal, “MSP Software and Operations Survey,” itportal.com, 2025.

5 Datapath, “How to Build a 30-60-90 Day MSP Onboarding Plan,” mydatapath.com, 2025.

Leave a Reply