Managed IT & Buying Guidance
Updated
The first 90 days are a planning frame, not a universal completion guarantee. A ten-person office and a multi-site healthcare operator do not transfer at the same speed. The useful question is whether the transition has gates, owners, evidence, and an explicit decision about what is safe to move into steady-state support.
Define the handoff before day one
Onboarding starts before tools are deployed. NIST's supplier due-diligence guidance treats research into a technology supplier as part of making an informed acquisition decision. CISA likewise advises MSP customers to define shared responsibilities in the agreement. For a transition, document what the outgoing provider, incoming provider, client, and critical vendors must each deliver.
| Area | Evidence to collect | Client decision |
|---|---|---|
| Authority | Executive sponsor, technical contact, emergency contacts, and authorized approvers. | Who may approve access, containment, purchases, and service-impacting changes? |
| Identity and access | Tenant ownership, domains, administrative roles, MFA methods, emergency access, and vendor portals. | Which accounts must be transferred, replaced, retained, or disabled? |
| Critical operations | Business applications, locations, internet circuits, network diagrams, support contacts, and blackout windows. | What cannot tolerate an unplanned change? |
| Recovery | Covered systems, backup platforms, job history, retention, encryption, and available restore evidence. | Which recovery claims require validation before reliance? |
| Commercial scope | Order Form, selected services, quantities, licenses, project statements, and known exclusions. | What is recurring support, onboarding work, a project, or a pass-through cost? |
Days 0-30: establish control and a trustworthy baseline
The first phase should confirm coverage, gain approved access, inventory the environment, establish support intake, and identify immediate continuity or security concerns. Tool deployment is not the same as understanding the environment. Reconcile tool data against contracts, invoices, diagrams, physical locations, cloud tenants, and what employees actually use.
The exit gate is not "all agents installed." It is a reviewed baseline: covered users and systems are known, critical unknowns have owners, support can be reached, emergency contacts work, and high-impact inherited risks are visible. Use the MSP selection guide to confirm that the transition matches what was sold.
Days 31-60: stabilize without hiding inherited risk
After access and inventory are credible, the provider can standardize selected tools, repair support routing, validate documentation, and begin approved remediation. Backup status deserves particular care: a successful job record is not the same as demonstrated recoverability. CISA recommends regularly testing backup availability and integrity in a disaster-recovery scenario. The backup versus disaster recovery guide explains why those are separate decisions.
Inherited issues should become a register with impact, evidence, disposition, owner, and target decision date. Some items are routine remediation. Others require a separately approved project, vendor engagement, hardware purchase, migration, or risk acceptance. A credible MSP makes that boundary visible instead of forcing every pre-existing problem into the recurring fee.
Days 61-90: prove the operating cadence
The final phase should demonstrate that normal support, escalation, documentation, reporting, and roadmap ownership work without the onboarding team improvising every step. Remaining risk does not have to be eliminated, but it should be assigned and governed.
| Phase | Required output | Exit signal |
|---|---|---|
| 0-30: Control | Coverage baseline, access register, critical-system map, support path, and inherited-risk log. | Known systems can be supported; material unknowns have owners. |
| 31-60: Stabilize | Approved tooling, usable documentation, remediation queue, vendor map, and recovery-evidence plan. | Urgent gaps are addressed or accepted; larger work is scoped. |
| 61-90: Operate | Service review, escalation test, roadmap, lifecycle list, and recurring reporting cadence. | Both parties agree what is steady state, open risk, and planned work. |
Keep onboarding and project work separate
Cloud Core MSP's Service Guide describes onboarding as access coordination, inventory validation, approved tool deployment, documentation, baseline review, and stabilization. It separately identifies large migrations, tenant cleanup, server rebuilds, network redesign, cabling, office moves, emergency remediation of major pre-existing failures, security incident response, and large-scale deployments as billable unless included in writing. Review the current Onboarding and Stabilization scope with the Quote, Order Form, or SOW.
This separation exposes the real transition cost and avoids assuming every inherited deficiency belongs in recurring service. The technology refresh guide can move aging assets into a planned lifecycle rather than an emergency list.
Acceptance checklist before steady state
- Covered users, systems, sites, tenants, and vendors match the signed scope.
- Administrative access is attributable, MFA-protected as appropriate, and documented.
- Emergency contacts and the critical escalation channel have been exercised.
- Monitoring gaps, unsupported systems, stale accounts, and missing credentials are recorded.
- Backup scope and restore evidence are stated without overclaiming confidence.
- Critical vendor ownership, renewal dates, and support paths are known.
- Routine remediation, client decisions, projects, and accepted risks are separated.
- A first service review has owners, due dates, and decisions rather than only activity totals.
Use the guide to managed IT reporting and quarterly reviews as the next acceptance test.
Sources and further reading
- NIST SP 1326: C-SCRM Due Diligence Assessment Quick-Start Guide - current supplier due-diligence guidance.
- CISA: Risk Considerations for Managed Service Provider Customers - customer responsibilities and contract considerations.
- NIST SP 800-161 Revision 1, Update 1 - supply-chain risk management across the supplier lifecycle.
- CISA #StopRansomware Guide - backup testing and recovery preparation.