Guide to Onboarding New IT Provider First 90 Days

What a disciplined first 90 days should look like.

Updated

The first 90 days are a planning frame, not a universal completion guarantee. A ten-person office and a multi-site healthcare operator do not transfer at the same speed. The useful question is whether the transition has gates, owners, evidence, and an explicit decision about what is safe to move into steady-state support.

Define the handoff before day one

Onboarding starts before tools are deployed. NIST's supplier due-diligence guidance treats research into a technology supplier as part of making an informed acquisition decision. CISA likewise advises MSP customers to define shared responsibilities in the agreement. For a transition, document what the outgoing provider, incoming provider, client, and critical vendors must each deliver.

Minimum transition packet before access changes begin
AreaEvidence to collectClient decision
AuthorityExecutive sponsor, technical contact, emergency contacts, and authorized approvers.Who may approve access, containment, purchases, and service-impacting changes?
Identity and accessTenant ownership, domains, administrative roles, MFA methods, emergency access, and vendor portals.Which accounts must be transferred, replaced, retained, or disabled?
Critical operationsBusiness applications, locations, internet circuits, network diagrams, support contacts, and blackout windows.What cannot tolerate an unplanned change?
RecoveryCovered systems, backup platforms, job history, retention, encryption, and available restore evidence.Which recovery claims require validation before reliance?
Commercial scopeOrder Form, selected services, quantities, licenses, project statements, and known exclusions.What is recurring support, onboarding work, a project, or a pass-through cost?

Days 0-30: establish control and a trustworthy baseline

The first phase should confirm coverage, gain approved access, inventory the environment, establish support intake, and identify immediate continuity or security concerns. Tool deployment is not the same as understanding the environment. Reconcile tool data against contracts, invoices, diagrams, physical locations, cloud tenants, and what employees actually use.

The exit gate is not "all agents installed." It is a reviewed baseline: covered users and systems are known, critical unknowns have owners, support can be reached, emergency contacts work, and high-impact inherited risks are visible. Use the MSP selection guide to confirm that the transition matches what was sold.

Days 31-60: stabilize without hiding inherited risk

After access and inventory are credible, the provider can standardize selected tools, repair support routing, validate documentation, and begin approved remediation. Backup status deserves particular care: a successful job record is not the same as demonstrated recoverability. CISA recommends regularly testing backup availability and integrity in a disaster-recovery scenario. The backup versus disaster recovery guide explains why those are separate decisions.

Inherited issues should become a register with impact, evidence, disposition, owner, and target decision date. Some items are routine remediation. Others require a separately approved project, vendor engagement, hardware purchase, migration, or risk acceptance. A credible MSP makes that boundary visible instead of forcing every pre-existing problem into the recurring fee.

Days 61-90: prove the operating cadence

The final phase should demonstrate that normal support, escalation, documentation, reporting, and roadmap ownership work without the onboarding team improvising every step. Remaining risk does not have to be eliminated, but it should be assigned and governed.

A gated 90-day transition plan
PhaseRequired outputExit signal
0-30: ControlCoverage baseline, access register, critical-system map, support path, and inherited-risk log.Known systems can be supported; material unknowns have owners.
31-60: StabilizeApproved tooling, usable documentation, remediation queue, vendor map, and recovery-evidence plan.Urgent gaps are addressed or accepted; larger work is scoped.
61-90: OperateService review, escalation test, roadmap, lifecycle list, and recurring reporting cadence.Both parties agree what is steady state, open risk, and planned work.

Keep onboarding and project work separate

Cloud Core MSP's Service Guide describes onboarding as access coordination, inventory validation, approved tool deployment, documentation, baseline review, and stabilization. It separately identifies large migrations, tenant cleanup, server rebuilds, network redesign, cabling, office moves, emergency remediation of major pre-existing failures, security incident response, and large-scale deployments as billable unless included in writing. Review the current Onboarding and Stabilization scope with the Quote, Order Form, or SOW.

This separation exposes the real transition cost and avoids assuming every inherited deficiency belongs in recurring service. The technology refresh guide can move aging assets into a planned lifecycle rather than an emergency list.

Acceptance checklist before steady state

  • Covered users, systems, sites, tenants, and vendors match the signed scope.
  • Administrative access is attributable, MFA-protected as appropriate, and documented.
  • Emergency contacts and the critical escalation channel have been exercised.
  • Monitoring gaps, unsupported systems, stale accounts, and missing credentials are recorded.
  • Backup scope and restore evidence are stated without overclaiming confidence.
  • Critical vendor ownership, renewal dates, and support paths are known.
  • Routine remediation, client decisions, projects, and accepted risks are separated.
  • A first service review has owners, due dates, and decisions rather than only activity totals.

Use the guide to managed IT reporting and quarterly reviews as the next acceptance test.

Sources and further reading

Want help applying this to your environment?

Start with a short discovery call and we will help you sort the practical next step without overcomplicating it.