03333 44 6500 Mon–Fri 8am–6pm
Client Portal
IT Support

How to Choose a Managed IT Provider: The Checklist UK SMEs Actually Need

There are hundreds of managed IT providers in the UK, and most of them will tell you more or less the same things on a sales call. Here's how to tell the good from the average — and what questions actually reveal the difference.

AS
Adam Smith
10 Jun 2026 · 8 min read

I've been in managed IT long enough to know exactly what the standard sales pitch sounds like. "We're proactive, not reactive." "You'll have a dedicated account manager." "Our response times are industry-leading." Every provider says some version of these things, because they're what businesses want to hear.

What distinguishes a genuinely good managed IT provider from an average one isn't the pitch. It's the specifics behind the pitch — the actual numbers, the actual processes, the actual contracts. And most businesses don't know which specifics to ask for.

This checklist is designed to help. Use it on your next provider conversation. A good provider will have clear, confident answers. A mediocre one will get vague.

1. What Are Your Actual Response Time Guarantees?

"Fast response times" is meaningless without a number. Ask for the specific SLA — the guaranteed response time for priority 1, 2 and 3 issues, what happens if those SLAs are missed, and how they're measured and reported.

A good answer: "For Priority 1 issues — full outage or critical system failure — we guarantee a 15-minute response time. That's first contact with a qualified engineer, not an acknowledgement email. We measure this through our ticket system and include it in your monthly report. If we miss an SLA, we flag it proactively."

A concerning answer: "We aim to respond as quickly as possible. Most issues are resolved within the hour." That's not a guarantee, and the absence of a number tells you something.

2. What Does Your Onboarding Process Look Like?

The onboarding process reveals a great deal about how a provider operates. A properly run onboarding should include a full documentation exercise — hardware, software, licensing, network configuration, backup configuration — before any transition happens. If a provider is vague about this, documentation is probably not a strength, which means you'll have a support relationship built on incomplete knowledge of your environment.

Ask specifically: "Who will document our environment, how long will it take, and what do we receive as an output?" You should receive a comprehensive IT asset and configuration register that belongs to you, not the provider.

Why this matters: One of the most common problems we see when businesses switch to us from another provider is inadequate documentation. The previous provider knew the environment — sort of, in the heads of the engineers who worked on it — but nothing was formally recorded. When key engineers left the provider, so did the institutional knowledge. Proper documentation protects you regardless of what happens on the provider's side.

3. What Security Is Included as Standard?

This question separates providers who treat security as an add-on from those who treat it as a fundamental. The baseline security that should be included in any managed IT service in 2026:

  • Endpoint detection and response (EDR) on all managed devices — not just basic antivirus
  • Patch management — automated and managed, with reporting on patch compliance
  • Microsoft 365 security configuration — Conditional Access, Safe Links, Safe Attachments
  • Backup monitoring — verification that backups are completing and recoverable
  • Security awareness support — at minimum, guidance and resources for staff training

If a provider's standard package includes only "antivirus and basic monitoring", that's a 2015 security posture. Press on what's specifically included and what costs extra. If email security, EDR and MFA enforcement are all add-ons, the headline price is misleading.

4. Can You Show Me Your Cyber Essentials Certificate?

A managed IT provider that doesn't hold Cyber Essentials certification for their own business is a significant red flag. How seriously should you take their security advice when they haven't met the baseline standard themselves?

A good provider will have Cyber Essentials — ideally Cyber Essentials Plus — and be able to produce it without hesitation. At CloudHost, we're Cyber Essentials certified as a business and we're also an accredited Cyber Essentials certification body, able to guide and process client certifications directly.

5. Who Will I Actually Deal With Day-to-Day?

Many providers sell on the promise of a dedicated account manager but deliver a rotating cast of helpdesk engineers who don't know your business. Ask specifically: who will be your named account manager, what does that relationship look like in practice, how often will you review your IT together, and what happens when that person leaves?

A good provider will have a clear answer about continuity. Account managers move on — the question is whether the relationship and the knowledge of your business is held in the organisation or in one person's head.

6. What Does Your Contract Say About Leaving?

This is the question many businesses forget to ask until they want to leave. Check:

  • The notice period — 30 days is reasonable, 90+ days should prompt negotiation
  • What happens to your documentation, passwords and admin access when you leave — you should have full access to all of these from day one
  • Whether there are exit fees or penalties for early termination
  • What the transition support looks like — a good provider will commit to a structured handover

A provider that makes it difficult to leave is betting on your inertia, not your satisfaction. At CloudHost we operate on rolling monthly agreements. If we're not delivering, you can leave. That's the only model that creates the right incentives.

7. What Is and Isn't Included in the Monthly Fee?

Get this in writing, in detail. Common things to clarify:

  • Are onsite visits included, or charged separately? (If separate, what's the rate?)
  • Is new hardware setup included, or is there a per-device fee?
  • Are Microsoft 365 licences included or charged as a passthrough?
  • What constitutes a "project" that falls outside the monthly fee?
  • Are security incidents covered under the contract or treated as separate engagements?

There's no universally right answer to these questions — some models include more, some less, and pricing reflects that. What matters is clarity. You should know exactly what you're getting for your money before you sign anything.

8. Can You Give Me a Reference From a Business Like Mine?

References are table stakes. Any provider worth working with should be able to provide two or three references from businesses of a similar size and sector. Not testimonials on a website — actual contacts you can call and ask questions of.

When you call the references, the most useful questions are: "What do they do badly?" and "What would you change?" A provider whose references can only say positive things is either unusually good or has carefully curated who they put forward. A reference who says "they're excellent, except response times on Friday afternoons can be slower" is telling you something real and useful.

A note on size: Be cautious about providers who are significantly larger or smaller than your business needs. A five-person provider may not have the resource to support a 40-person client reliably. A 500-person managed service provider may not give a 20-person client the attention they need. The right fit — in terms of size, sector experience and cultural match — matters as much as the technical capability.

What Good Actually Looks Like

Based on working with businesses of all sizes across Derby, Nottingham, Leicester and beyond, a managed IT relationship that's working well has a few consistent characteristics:

Your team rarely notices IT problems, because most are resolved proactively before they surface. When something does go wrong, it's fixed fast and you're kept informed throughout. Your account manager raises things you hadn't thought to ask about. Your monthly report shows you what's been done and what's being monitored. Security is a standing item in your reviews, not something that only comes up after an incident.

If any of those things sound like a distant aspiration rather than your current experience, the provider you're with now probably isn't the right one. The good news is that switching is easier than you think — and the difference in day-to-day experience, once you're with a provider who's doing it properly, is immediate and tangible.

Next Step

See How CloudHost Answers These Questions

We're happy to be held to every point in this checklist. Book a free consultation and ask us anything — response times, security posture, onboarding process, contract terms. We'll give you straight answers.

Or call: 03333 44 6500 · Mon–Fri 8am–6pm