How to Vet an MSP: What to Actually Ask Before You Sign | LDD Consulting

Choosing the Right IT Partner

A Vetting Checklist for Small Business

By David Luft | CEO, LDD Consulting | MCSE, MCT, MBA | Published August 27, 2026 | 6 min read

Choosing the Right IT Partner

THE SHORT ANSWER

Every managed service provider claims fast response times, strong security, and great communication — the real differences only show up once you ask specific, pointed questions. Vetting an MSP well means checking their certifications independently, requesting real client references in your industry, understanding exactly what’s included versus billed separately, and confirming their security and compliance depth actually matches your business’s risk profile. A little diligence upfront saves months of frustration and re-onboarding down the line.

Why Vetting Matters More Than Picking Based on Price

It’s tempting to compare MSPs the same way you’d compare any vendor — get three quotes, pick the middle one, move on. But an MSP isn’t a one-time purchase. They’re the team responsible for your uptime, your data security, and often your compliance standing, every single day for years.

Choosing the wrong provider rarely shows up as an obvious, immediate problem. It shows up slowly — tickets that take longer to close, vague answers when you ask what’s actually being monitored, a security posture that looked fine on paper but was never really tested. By the time it’s obvious something’s wrong, you’re often looking at months of re-onboarding with a new provider to fix it.

Pro tip: Price differences between MSPs are usually explained by what’s included, not just markup. A cheaper quote that excludes security monitoring or after-hours support isn’t actually cheaper once you need those things.

What to Actually Check Before You Sign

Certifications — Verified, Not Just Claimed

Anyone can put a certification badge on a website. Ask which certifications the individual technicians hold, not just the company, and verify them independently rather than taking a sales rep’s word for it.

Client References in Your Industry and Size Range

A glowing reference from a 200-person manufacturing company doesn’t tell you much if you’re a 15-person professional services firm. Ask for references specifically from businesses your size, in your industry, and speak with them directly — not over email.

What’s Actually Included vs. Billed Separately

Get a clear, itemized breakdown of what’s covered under the monthly fee versus what triggers an additional charge. “All-inclusive” claims fall apart fast once you see the fine print on things like after-hours support or new device setup.

Security Depth, Not Just a Checkbox

Basic antivirus isn’t a cybersecurity program in 2026. Ask specifically what layers of protection are included — endpoint detection and response, email security, multi-factor authentication enforcement, and how incidents are actually handled when something gets flagged.

Questions That Separate Real Answers from Sales Talk

For each of these, a specific, confident answer is a good sign. A strong provider can explain the factors that influence the answer. Be cautious of vague responses that lack specifics, examples, or a documented process.

“What’s your average response time, and how is it measured?”

Good answer: a specific number, backed by a documented SLA — not just “we’re usually pretty fast.”

“Can you walk me through what happens during a major incident?”

Good answer: A clear, step-by-step process they can describe without hesitation, including how they coordinate with the client’s incident response plan, communicate during an event, and assist with containment, recovery, and post-incident review.

“How do you handle compliance requirements specific to our industry?”

Good answer: specific familiarity with your regulatory framework (HIPAA, PCI-DSS, CMMC, etc.), not a generic reassurance that they “handle compliance.” This matters even more if your business has compliance obligations tied to client contracts or industry regulation.

“What does onboarding actually look like, and how long does it take?”

Good answer: a documented process with a realistic timeline — most transitions take 30 to 90 days depending on complexity. Vague timelines usually mean an undocumented process.

“What happens if we want to leave?”

Good answer: clear exit terms, data portability, and a transition plan explained upfront — before you’ve signed anything, not after.

Red Flags That Mean Walk Away

  • Vague answers to specific questions, especially around security and incident response
  • Reluctance to provide references, or only offering references outside your industry or size
  • No documented SLA — response time promises that exist only in conversation, not in writing
  • One-size-fits-all proposals that don’t reflect anything specific about your business, industry, or current environment
  • Pressure to sign quickly without time to check references or review the contract closely

Common Mistakes Businesses Make When Choosing an MSP

Mistake 1 — Choosing Based on Price Alone

The cheapest quote often excludes services you’ll need later, turning into a much higher real cost once those gaps surface.

Mistake 2 — Skipping Reference Calls

Reading testimonials on a website isn’t the same as talking to a real client. A five-minute call can reveal things a curated testimonial never will.

Mistake 3 — Not Asking About Their Own Security

The MSP itself needs strong security practices — password management, access controls, and internal safeguards — since a breach at your provider can expose your data too.

Mistake 4 — Assuming All MSPs Offer the Same Services

Some providers focus mainly on helpdesk tickets. Others include proactive monitoring, managed IT services, and strategic planning as standard. Compare what’s actually included, not just the price on the page.

Frequently Asked Questions

How long should the vetting process take?

Plan for several weeks if you’re doing it right — enough time to review proposals, check references, and ask follow-up questions rather than deciding after a single sales call.

Is it worth switching MSPs if we're only somewhat unhappy with our current provider?

It depends on what “somewhat unhappy” means. Recurring unresolved issues, unclear reporting, or an untested backup and recovery process are worth addressing directly — sometimes through a frank conversation with your current provider, sometimes through a switch. If you’re not sure which situation you’re in, contact us and we can help you evaluate it.

What's a reasonable client-to-technician ratio to ask about?

There’s no single right number, but it’s a fair question to ask directly — an MSP stretched too thin across too many clients tends to show it in response times.

Should local or national MSPs be prioritized?

It depends on your needs. Local providers tend to offer stronger on-site support and a more personal relationship; national providers may offer broader 24/7 coverage. Many Albuquerque businesses value having a local IT support partner who understands the regional business landscape directly.

What's the biggest indicator that an MSP will actually deliver what they promise?

Specificity. Providers who give exact, confident answers — response time numbers, named security tools, a documented onboarding timeline — are far more likely to deliver than ones who lean on reassuring but vague language.

David Luft

CEO, LDD Consulting

David founded LDD Consulting in 2003 with a straightforward mission: help small and mid-sized businesses in Albuquerque and across New Mexico get reliable, enterprise-quality IT support without the enterprise price tag. He holds an MBA with a concentration in Information Systems from the University of New Mexico, along with Microsoft Certified Systems Engineer (MCSE) and Microsoft Certified Trainer (MCT) credentials. He’s been solving business technology problems for more than 25 years. 

Linkedin |  Learn More About David