Towson

15 Questions to Ask an MSP Before You Sign: A Towson Business Checklist

Maryland MSP team · September 2026 · 9 min read

Every managed service provider sounds good in a sales meeting. They all promise fast response, proactive security, and a team that "acts like your own IT department." The differences that will actually shape your next two or three years live in the details the pitch skips: who answers the phone at 2 a.m., what the offboarding clause says, and whether "monitoring" means a human or a dashboard nobody checks.

This checklist is the set of questions we ask on behalf of clients when we run a search as an MSP broker. Bring it to every sales meeting, ask every question of every finalist, and write the answers down. Providers who deserve your business will respect the diligence. Providers who get evasive are telling you something useful too.

Service and response

1. What is your guaranteed response time, and what does "response" mean?

Some MSPs count an automated ticket acknowledgment as a response. You want to know when a qualified human starts working the problem. Ask for the guarantee in writing, broken out by severity: a down server should have a different clock than a printer question. Then ask what happens when they miss it. A service level agreement with no penalty is a marketing document.

2. Who actually answers when we call?

Is the helpdesk in-house or outsourced? During business hours only, or 24/7? Will your staff reach a technician who knows your environment, or a call center reading from a script? For medical and dental practices around Towson, where a down system can mean rescheduled patients, this question matters more than almost any other.

3. Can we talk to a current client our size, in our industry?

Not their biggest client. Not their oldest client. A client that looks like you. A 20-person practice near GBMC has different needs than a 200-person distributor, and a reference from the wrong tier tells you little. Ask the reference two things: what happens when something breaks, and what the provider is like when they make a mistake.

4. Do you have other clients in our area, and do you do on-site visits?

Remote support covers most issues, but hardware fails, networks need physical work, and some problems are faster to fix in person. If the provider's nearest technician is an hour away in traffic on the Beltway, ask how on-site response actually works: who comes, how fast, and whether visits are included in the monthly fee or billed separately.

Security and compliance

5. What security is included in the base price, and what costs extra?

Get the specific list: endpoint detection and response, multi-factor authentication enforcement, email filtering, security awareness training, patching cadence, backup testing. Many disputes with MSPs trace back to a client who assumed "we handle security" covered things it did not. Ask them to mark, line by line, what is in the quoted price.

6. How do you handle our compliance obligations?

Towson's business base leans heavily on healthcare: practices and specialists clustered around GBMC, St. Joseph, and the University of Maryland St. Joseph campus, plus the therapists, billing companies, and labs that serve them. If HIPAA applies to you, the provider must sign a business associate agreement and should be able to explain, without hand-waving, how they support a risk assessment. Law firms, CPAs, and financial advisors have their own obligations. If the salesperson cannot name the framework you just mentioned, keep looking.

7. Who is responsible when there is a breach?

Ask to see their cyber liability insurance certificate and their errors and omissions coverage. Ask what their own internal security looks like, since an MSP is a high-value target: a compromise of their tools can become a compromise of every client. A good provider answers this question comfortably because they have been asked before.

8. How are our backups tested, and what is the actual recovery time?

Everyone backs up. Far fewer providers regularly restore from those backups to prove they work. Ask when they last performed a test restore for a client your size, how long a full recovery would take, and where the backup copies live. "We could have you back up same day" should come with an explanation of how, not just a smile.

People and process

9. Who will we actually work with day to day?

Meet the account manager and, if possible, a technician before you sign, not just the sales team. Ask about technician turnover and how many clients each account manager carries. An MSP whose engineers stay for years will know your environment; one that churns staff will make you re-explain your setup every quarter.

10. What does onboarding look like, and how long until things are stable?

A serious provider has a written onboarding plan: documentation of your network, credential handover, agent deployment, a baseline security review, and a defined point where the previous arrangement ends. Ask how long it takes and what they need from you. Vague answers here predict a chaotic first ninety days.

11. How do you report on what you actually did?

Monthly or quarterly reporting should show tickets opened and closed, response times against the SLA, patch status, backup results, and security events. If the answer is "you can call us anytime," you will have no way to know whether you are getting what you pay for. This reporting is also what makes it possible to hold a provider accountable later.

Money and contract

12. What exactly does the per-user or per-device price include?

Pricing models vary: per user, per device, tiered, or a hybrid. None is inherently better, but every model has edges where surprise charges live. Projects, after-hours work, on-site visits, new-hire setups, hardware procurement, and "out of scope" tickets are the usual suspects. Ask for a sample invoice from a real month for a client your size.

13. What is the term, and how do we get out?

One-year terms are common; three-year terms deserve a discount and a performance escape clause. Read the termination-for-cause language: what counts as cause, how much notice, and what you owe if you leave early. If a provider will not negotiate any exit terms, that confidence is the wrong kind.

14. What happens to our data, documentation, and passwords when we leave?

This is the question almost nobody asks and everyone eventually wishes they had. Your network documentation, admin credentials, license keys, and configurations should be contractually yours, delivered in a defined format within a defined window, at no ransom fee. An MSP that resists this clause is planning to make leaving painful.

15. Why should we choose you over the other firms we are talking to?

Ask it directly. A strong provider will differentiate honestly and may even tell you when they are not the right fit, which is the most trustworthy sentence in any sales process. A weak one will trash competitors or retreat into generic promises you have already heard three times that week.

How to use this checklist

Ask all fifteen questions of at least two or three providers, and score the answers side by side rather than trusting your memory of whoever pitched last. If you want the comparison to be genuinely fair, put the questions in writing as a lightweight request for proposal so every provider answers the same thing in the same format. For a straight price comparison on a well-defined scope, an RFQ can do the job with less overhead; our guide to RFP versus RFQ for IT services explains which fits your situation.

And if you are asking these questions because your current provider is failing them, you may find our post on the signs it is time to switch your MSP a useful gut check before you start the search.

Want someone to ask these for you?

We put these questions to every provider we vet, compare the answers, and hand Towson businesses a shortlist, free.

Start Your Free Match