Strategy, Compliance & Planning
Updated
The first year with a managed service provider (MSP) is not the organization's general annual IT planning cycle. It is a time-bounded governance program for proving that the selected provider can assume agreed responsibilities, establish reliable evidence, stabilize service, operate an accountable review cadence, and prepare the organization to renew or transition without losing control.
This roadmap begins after provider selection. It does not replace the broader pre-budget technology roadmap, authorize uncontracted work, or guarantee that onboarding will finish on a fixed date. The board liaison keeps decisions, evidence, exceptions, and ownership visible while executives and service owners retain their delegated authority. NIST's CSF 2.0 Organizational Profiles guide uses current and target outcomes plus action plans; that evidence-based pattern can structure security improvements without turning the entire MSP relationship into a compliance score.
Define first-year governance before kickoff
Approve a relationship charter that names the executive sponsor, board liaison, internal service owners, finance contact, security and records owners, provider service lead, and escalation authority. Attach the signed scope, responsibility matrix, exclusions, assumptions, service targets, reporting commitments, project-authorization path, and renewal or termination dates. If a responsibility is described only in sales material, reconcile it with the executed agreement before treating it as an operating commitment.
Create a first-year evidence register covering administrative custody, inventory, support boundaries, current risks, backup and recovery evidence, lifecycle dates, licenses, open projects, third-party dependencies, and unresolved discovery items. Mark each item confirmed, partially confirmed, or unknown; record its source, owner, next action, and decision date. The new-provider onboarding guide provides the operational companion to this governance record.
Days 0-30: establish baseline evidence and control
The provider and internal owners should reconcile what was sold with what exists. Confirm authorized contacts, support intake, escalation, user and site counts, managed and excluded assets, privileged-access custody, domains, licensing, monitoring coverage, backup responsibilities, material vendors, current incidents, and change windows. Do not label an imported inventory "verified" until its source and material gaps are understood.
NIST's CSF 2.0 Quick Start Guides can help a small team organize security outcomes, but they do not establish the provider's contractual scope. Baseline findings should be classified as included remediation, proposed project, customer responsibility, third-party dependency, accepted risk, or unresolved contract question. Every classification needs an accountable internal owner, not only an MSP assignee.
Days 31-90: stabilize service and exit onboarding deliberately
Use early service data and controlled tests to resolve urgent gaps, tune support routing, remove duplicate or abandoned processes, and confirm reporting inputs. CISA's Cross-Sector Cybersecurity Performance Goals 2.0 can inform prioritization of material security outcomes, but local risk, dependencies, authority, and service impact determine sequence.
Onboarding is complete only when authorized owners approve its exit criteria. Completion does not mean every improvement is finished; it means the relationship can enter steady governance with open work accurately classified.
| Onboarding exit criterion | Required evidence | Acceptance owner and exception path |
|---|---|---|
| Scope and responsibility reconciled | Approved service matrix, exclusions, assumptions, sites, users, assets, and third-party duties | Executive sponsor records any commercial dispute |
| Administrative custody established | Authorized account, domain, license, portal, key, documentation, and recovery-method register | Security or system owner accepts custody exceptions |
| Service operations working | Support intake, escalation, monitoring, maintenance, change, and user communication paths exercised | Service owners approve or conditionally accept |
| Baseline evidence classified | Inventory, lifecycle, backup, recovery, risk, dependency, and project records with confidence status | Named owner and date for every unknown |
| Steady-state cadence scheduled | Monthly operating review, quarterly review, board reporting, project gate, and renewal calendar | Board liaison confirms governance dates |
Maintain one first-year MSP roadmap artifact
| Roadmap field | Required first-year content |
|---|---|
| Relationship period and gate | Onboarding, stabilization, operating cadence, improvement, renewal review, or transition-readiness checkpoint |
| Outcome and baseline evidence | Service result, current evidence, confidence level, and the gap this action addresses |
| Contract treatment | Included service, customer duty, third-party duty, authorized project, or unresolved scope decision |
| Owners | Accountable internal owner, MSP delivery owner, consulted roles, and acceptance authority |
| Dependencies and decision date | People, access, data, vendor, procurement, funding, outage window, and the date leadership must decide |
| Deliverable and acceptance | Provider output, business validation, required documentation, and exception treatment |
| Status and next governance forum | Proposed, approved, active, held, accepted, or carried forward; plus next monthly, QBR, or board decision |
Do not turn the artifact into a list of everything anyone wants from IT. Each row must connect relationship evidence to an owned decision or accepted result. Preserve prior-quarter status so deferrals, scope changes, and recurring exceptions remain visible.
Months 4-6: establish the operating and QBR cadence
Separate three forums. The monthly operating review handles service trends, recurring incidents, maintenance exceptions, open dependencies, and near-term actions. The quarterly business review (QBR) evaluates outcomes, material risks, lifecycle signals, contractual performance, project gates, and the next-quarter forecast. The board or governing packet contains only decisions, accepted risks, funding or policy gates, significant service changes, and renewal or transition matters within its authority.
A useful managed IT reporting and QBR structure supplies traceable evidence instead of dashboard decoration. Agree on data definitions, source systems, reporting periods, owner commentary, and corrective-action tracking. A provider-created score is context, not a substitute for source evidence or internal judgment.
Months 7-9: sequence improvement projects through governance gates
Discovery findings become projects only after scope, business outcome, contract treatment, dependencies, funding authority, change window, delivery owner, and acceptance test are clear. Keep routine contracted remediation separate from separately authorized project work. If evidence or assumptions are incomplete, schedule a discovery decision instead of presenting an artificial implementation date or unsupported cost.
GAO's IT Investment Management framework is a federal assessment framework rather than a private or local mandate, but its select-control-evaluate discipline is useful: choose work against documented criteria, govern it while underway, and evaluate the delivered result. Reforecast the first-year artifact when a project changes scope, timing, dependencies, or risk; do not overwrite the prior decision record.
Months 10-12: decide renewal and preserve transition readiness
Begin the checkpoint early enough to meet contractual notice and budget dates. Review service outcomes, unresolved scope disagreements, recurring escalation failures, accepted risks, project delivery, lifecycle forecast, reporting quality, administrative custody, documentation, pricing assumptions, and the next year's required decisions. The service escalation and support expectations guide helps distinguish an isolated miss from a governance pattern.
Renewal is not the only acceptable result. Leadership may renew as written, negotiate a documented change, extend for a defined transition need, or follow the contract's exit path. NIST's contingency planning guide and FEMA's non-federal continuity plan template highlight recovery dependencies and essential functions. Use those concepts to confirm that data, accounts, documentation, vendor relationships, and support knowledge remain usable if the provider changes; the cited publications do not impose universal transition requirements.
Quarterly board and QBR governance
At every relationship-quarter close, preserve the prior baseline and record evidence gained, exit criteria accepted, work added or removed, scope classifications changed, risks accepted, project outcomes validated, and decisions carried forward. Each change needs an owner, rationale, consequence, and next decision date.
- Quarter 1: approve onboarding exit or document the conditions preventing it.
- Quarter 2: confirm the operating cadence produces reliable evidence and owned corrective actions.
- Quarter 3: approve only sequenced projects with clear contract and acceptance treatment.
- Quarter 4: decide renewal posture and verify transition readiness before notice deadlines.
The board liaison should keep the packet concise: decisions requested, material exceptions, outcome evidence, current-quarter confidence, risks requiring authority, and upcoming contract gates. Ticket totals, tool activity, and technical detail belong in supporting material unless they change a governance decision.
Clarify ownership throughout the first year
- The board or governing body decides matters reserved to it; it does not manage tickets or direct provider staff.
- The executive sponsor owns relationship outcomes, cross-department decisions, and risk acceptance within delegated authority.
- The board liaison maintains the governance calendar, decision record, evidence trail, and board-ready exceptions.
- Finance confirms budget treatment, renewal dates, pricing assumptions, and approval timing.
- Service owners define operational outcomes, approve onboarding evidence, and accept delivered changes.
- The MSP owns its contracted assessments, services, delivery evidence, escalation, and reporting - not decisions reserved to the customer.
Sources and scope
- NIST SP 1301: Creating and Using Organizational Profiles
- NIST: CSF 2.0 Quick Start Guides
- CISA: Cross-Sector Cybersecurity Performance Goals 2.0
- U.S. GAO: Information Technology Investment Management Framework
- NIST SP 800-34 Rev. 1: Contingency Planning Guide
- FEMA: Continuity Plan Template for Non-Federal Entities
These sources offer adaptable evidence, investment, security, and continuity structures. They do not define a mandatory MSP onboarding period, QBR format, maturity rating, renewal decision, or guarantee of risk reduction. The executed agreement and the organization's delegated authorities control. Confirm legal, regulatory, insurer, grant, accounting, procurement, records, and governance requirements with the responsible officials.
Suggested next step
Book a discovery call if your leadership team needs a first-year MSP governance workshop that separates onboarding evidence, operating accountability, project gates, and renewal decisions.