Key Takeaway: The standard MSP evaluation selects for sales skill, not operational competence. The questions that reveal whether an MSP is genuinely competent are about operations: when did you last test a restore, how do you handle alerts, what happens in the first hour of a ransomware attack.
Most business owners evaluate MSPs the wrong way. They ask about certifications, vendor partnerships, and response time guarantees. Those questions are not wrong, but they are easy to answer well without meaning anything. The questions that reveal whether an MSP is genuinely competent are harder, and most MSPs are not prepared for them.
This guide is for business owners who are either selecting a new managed service provider or reassessing the one they have. It is also useful for MSP owners who want to understand what a rigorous evaluation looks like from the client’s side.
Why the Standard Evaluation Process Fails
The standard MSP evaluation goes like this: get three bids, compare pricing, check references, pick the one that felt most trustworthy in the sales meeting. That process selects for sales skill, not operational competence. The MSP that wins is the one with the best presentation, not necessarily the one that will protect your business most effectively.
The problem is that operational competence is invisible until something goes wrong. You cannot see whether an MSP is actively monitoring your environment or just running automated scripts. You cannot see whether their backup has ever been tested or just configured. You cannot see whether their technicians are following documented processes or improvising. By the time you find out, you have already signed a contract and experienced an incident.
The evaluation questions below are designed to make the invisible visible before you commit.
The Questions That Actually Reveal Competence
When did you last test a restore from a client’s backup, and can you show me the documentation?
Every MSP sells backup. Very few test restores systematically. An MSP that cannot show you a restore test log from the past 90 days either does not test restores or does not document them. Both are problems. The backup that has never been tested is not a backup. It is an assumption.
Walk me through what happens in the first hour of a ransomware attack on one of your clients.
This question has no good answer if the MSP does not have a documented incident response plan. A competent MSP should be able to describe the specific steps: who gets notified, what gets isolated, what gets preserved for forensics, how the client gets communicated with, and who makes decisions under pressure. Vague answers about “our team springs into action” are not answers.
How do you handle alerts from a client’s environment? Who reviews them, and how often?
Alert fatigue is one of the most common security failures in the MSP industry. MSPs that configure their monitoring tools to generate maximum alerts and then rely on automated responses are not actively monitoring your environment. Ask specifically: is there a human reviewing alerts daily? What is the process for escalating an alert that requires investigation? What happened with the last significant alert you received from a client?
What does your onboarding process look like, and how long does it take?
A documented onboarding process is a proxy for operational maturity. MSPs that onboard clients consistently have built the process. MSPs that wing it have not. Ask for the onboarding checklist. Ask how long the last three onboardings took. Ask what the client experience looks like in the first 90 days. If the answers are vague, the process does not exist.
Can I speak with a client who has been with you for more than three years?
References from recent clients tell you about the sales experience. References from long-term clients tell you about the service experience. An MSP that cannot produce a three-year client is either new or has a retention problem. Ask the reference specifically: what went wrong in the relationship, and how did the MSP handle it?
What happened with a client engagement that did not go well?
Every MSP has had a client relationship that did not work out. The ones that claim otherwise are not being honest. What you are evaluating is not whether problems occurred, but how the MSP handled them. An MSP that can describe a failure, explain what they learned, and show what changed is demonstrating the kind of operational maturity that protects you when things go wrong.
Who does the actual work after the sales call?
In many MSPs, the person you meet in the sales process is not the person who will manage your account. Ask to meet the technician or account manager who will be your primary contact. Ask about their tenure with the company. Ask what happens to your account if that person leaves.
The Questions About Security Specifically
What security controls do you require all clients to have in place?
A competent MSP has a security baseline that applies to every client. It should include MFA on all remote access and privileged accounts, endpoint detection and response, DNS filtering, verified backup with tested restore, and a documented incident response plan. If the MSP’s answer is “it depends on what the client wants,” that is not a security practice. That is a menu.
What would our cyber insurance carrier need to see to confirm our coverage?
Modern cyber insurance policies require documented security controls as a condition of coverage. An MSP that cannot answer this question is not helping you manage your insurance risk. An MSP that can walk you through the specific controls your carrier requires and confirm which ones they are delivering is doing the job.
Are you willing to sign an attestation letter for our cyber insurance renewal?
This question is increasingly standard. An MSP that is unwilling to attest to the security posture of your environment either cannot confirm what controls are in place or is not confident in the accuracy of what they would be signing. Both are worth understanding before you commit.
The Questions About the Relationship
How do you communicate with clients when something goes wrong?
The communication standard during incidents is one of the clearest indicators of client relationship quality. Ask for an example of how they communicated with a client during a significant incident. Ask whether they provide written post-mortems after major events. An MSP that goes silent during incidents and resurfaces with “it’s fixed” is not managing the relationship. They are managing the ticket.
What does a quarterly business review look like with your team?
If the MSP offers vCIO services or strategic advisory, the quarterly business review is where that value either shows up or does not. Ask what the agenda looks like. Ask whether they bring a technology roadmap. Ask whether the meeting starts with a question about your business or a slide deck about their services. The answer tells you whether you are getting advisory or account management.
Red Flags to Watch For
Vague answers to operational questions. If an MSP cannot describe their monitoring process, their onboarding checklist, or their incident response plan in specific terms, those processes do not exist in a meaningful way.
Reluctance to provide long-term client references. An MSP with strong retention is proud of it. An MSP that steers you toward recent clients is managing what you see.
Pricing that is significantly below market. Managed services has real costs: tooling, staffing, after-hours coverage, training. An MSP that is priced 40% below competitors is either cutting corners on those costs or planning to make it up in scope creep and add-on charges.
A vCIO or account manager who earns commissions on what you buy. This is a structural conflict of interest. The person providing strategic advice should not have a financial stake in what you purchase.
Frequently Asked Questions
How many MSPs should I evaluate?
Three is the standard recommendation, and it is reasonable. More than three creates comparison fatigue without meaningfully improving the decision. The quality of the evaluation matters more than the number of providers evaluated.
How long should the evaluation process take?
A thorough evaluation takes two to four weeks. Rushing it to meet an arbitrary deadline is how businesses end up with MSPs that looked good in the sales process and disappointed in the service delivery.
What should I do if my current MSP cannot answer these questions?
Ask them directly. Some MSPs have the operational maturity but have not been asked to demonstrate it. Others will reveal gaps that are worth addressing before you experience an incident. The conversation itself is useful regardless of the outcome.
About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He helps MSPs operate with greater maturity and helps business owners make IT choices that make them more secure and more efficient. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.
Related Reading
- What Is an MSP? The Definition, the Model, and What Good Looks Like
- MSP vs. In-House IT: An Honest Comparison
- What to Look for When Hiring an MSP: 11 Questions That Matter
- Is Your IT Provider Putting You at Risk? 11 Warning Signs
- MSP Cybersecurity: What Competent Security Actually Looks Like
- The Real Cost of Choosing the Cheapest IT Provider