Skip to content

535 040 361511 275 531

Book an IT review

How to choose an IT outsourcing company: a practical checklist

Offers from IT companies look similar because they describe the same thing in different words. The difference is only visible when you ask for proof instead of a declaration. Here's a sheet that makes it possible and you can use it to evaluate us too.

Jakub MazurekJuly 31, 202612 min read

Documents with data sheets, notebook and pen on wooden desk while comparing offers

The three offers on the desk look almost identical. Each promises comprehensive care, quick response, safety and individual approach. They differ in price and logo colour. On this basis, the management board is to make a decision that will determine who has access to all company data in the coming years.

The offers look similar because they describe the same thing in different words and because the declaration costs nothing. Question "do you have experience in our industry" will always get an affirmative answer. Question "please show the monthly report that a customer with a similar profile receives, with blurred data", not always.

This is the whole difference between comparing offers and evaluating them. Below you'll find a sheet built around the evidence: for each criterion there is a question, an artifact worth asking for, and an answer that should raise a red flag.

Fair Disclaimer: we write this as a company that provides IT outsourcing services itself. That's why the sheet is designed so that it can also be used to assess us, and so that we can perform average in several places. If a guide to choosing a supplier leads only to one right choice, it is not a guide, just an offer.

Define needs before requesting a quote

Request for quotation with content "we are asking for an offer for IT support for 30 people" guarantees three incomparable answers. Each supplier will fill the gap with their own assumptions, and you will end up with three different ranges at similar prices and never find out why.

Before you send an inquiry, establish four things.

What exactly is to be supported? Not "IT", just: so many workstations, physical and virtual servers, ERP system, e-mail on a specific platform, network in such and such location, specialized devices. Without this inventory, you're comparing prices for different things.

What is critical to the operation of the company. Which systems retain revenue, when they stop working, and after how long. This one piece of information influences a sensible offer more than the number of employees.

What do you expect beyond crash response. Infrastructure development, consulting, budget planning, documentation, reporting to the management board. If you expect growth and buy failure response, conflict is a matter of months.

What is your risk profile. An accounting office processing customer data, a production company with a production hall that stops due to a network failure, and a marketing agency have completely different weights for the same criteria. I'll come back to this with the sheet.

The result is to be a short inquiry with the same list of questions for all suppliers. Then the differences in responses are information, not noise.

10 comparison criteria

Each criterion has the same structure: what are you asking about, what evidence should appear, what should concern you.

1. Scope and limits of liability.

Question: what exactly is included in the subscription and what is billed separately? Evidence: A written, item-by-item responsibility matrix of who is responsible for what. Red Flag: "everything included" with no exclusions. Every service has limits; a supplier who does not name them will establish them unilaterally in the first dispute.

British NCSC guidelines for selecting a managed service provider (published 24/11/2025, reviewed 24/06/2026) put this point first among the elements of the contract: it should be clearly defined what the supplier is responsible for and what remains with the customer.

2. Work model and availability.

Question: what are the support hours, who answers the call outside of these hours and what is the commute like? Evidence: description of the process and hours in the contract, not on the website. Red Flag: "we are always available" without description of what it means in practice and how much it costs.

3. How tickets are received.

Question: through which channel do we report a problem and how do we check the status? Evidence: ticket system with history. Red Flag: reports to the private number of a specific technician. This is convenient for the first six months and disastrous when that technician changes jobs.

4. People and continuity of knowledge.

Question: How many people know our environment and what happens when the primary caregiver is unavailable? Evidence: description of the replacement and where the documentation is kept. Red Flag: one person has all the knowledge. This is exactly the problem you're running away from in your own business.

5. Documentation.

Question: what exactly are you documenting and will we get ownership of it? Evidence: Sample anonymized documentation from another client. Red Flag: documentation exists only in the vendor's tool and does not leave the vendor's tool in a readable form.

6. Access security. Separate section below.

7. Backup and business continuity.

Question: what is the backup, where is it located and when was the last time you tested the restore? Evidence: recovery test report. Red Flag: declaration "we have backup" without proof of recovery, or describing the file sync as a backup. These are two different things: sync also replicates file deletion and encryption to all copies, so it does not protect against the most common data loss scenario.

8. Reporting.

Question: what does management get and how often? Evidence: sample monthly report. Red Flag: report is a list of closed tickets. This tells the management board nothing about the risk status.

9. Development and consulting.

Question: who proposes changes and how do we plan the IT budget for the year? Evidence: description of the cyclical inspection. Red Flag: the supplier is waiting for your orders. If a company does not have its own IT department, there is no one to formulate these orders.

10. Termination of cooperation.

Question: what happens when we give up? Evidence: Handover process described in the contract. Red Flag: avoiding the topic. I come back to this below.

Provider access security

This criterion is sometimes overlooked, but it is the most serious one. Your IT provider has administrative rights to everything you have. His safety becomes your safety, and his incident can be your incident, even if nothing happened to you.

Questions to ask:

  • How do you protect your own administrative accounts in our environment? NCSC recommends that privileged accounts be protected by two-factor authentication and that only those who truly need them should have administrative access. Answer "we have strong passwords" is a negative response.
  • Do you apply the principle of minimum privileges? The same guideline explicitly states giving the supplier only those permissions that are needed to perform the task. Permanent global administrator account "just in case" is the reverse of this rule.
  • Who on your side will have access and how is it recorded? There should be a list, not a general one "our team".
  • What happens when your employee leaves the company? You are asking about the process of revoking access. The lack of a process means that after years of cooperation, there are accounts of people whose names you don't know in your environment.
  • What subcontractors do you use? The NCSC recommends assessing the supplier's supply chain risk and indicates that the contract should include liability for third parties used to provide the service. If someone else is doing some of the work, the same questions apply to them.
  • How will you notify us if an incident occurs at your place? The guidelines call for establishing a procedure for reporting incidents, including notifying the customer about an incident on the supplier's side. The notification time should correspond to the importance of the event and the specific nature of your company.
  • Do you have a tested incident response plan? Emphasis on "tested". A plan in a binder is not a plan.

It is also worth watching out for mental shortcuts in offers. "We keep you safe" may mean an installed antivirus program, it may mean an EDR-class system with active detection and response, or it may mean 24/7 monitoring by a team of analysts. These are three different services, three different costs and three different levels of protection. Ask them to name specific things.

No supplier will eliminate risk to zero, and such a declaration in itself is a red flag. The point is to know what exactly you are buying.

SLA and reporting method

When comparing offers, SLA numbers are the most misleading because they look objective.

Key Distinction: response time is not repair time. Response time tells you how long it takes for someone to deal with your report. Repair time when the problem disappears. The supplier can respond in 15 minutes and repair the fault in three days; formally, the SLA is met. An offer with a response time of "up to 4 hours" and a real process is sometimes better than "up to 15 minutes" without a description of what happens next.

To compare offers, you need answers to five questions:

  1. When does time run from, from the notification or from its acceptance?
  2. Who assigns priority and can you disagree with them?
  3. Does the meter work outside working hours, on weekends and holidays?
  4. What stops the counter, such as waiting for your decision or for parts to be delivered?
  5. What happens when SLA is not met?

The NCSC Guidelines provide indicative values: for urgent cases, a response below an hour, for a small one working day, and a solution for routine cases in two-three working days. These are guidelines developed for the UK market and should not be regarded as a standard in force in Poland or as a promise of any supplier. They will be useful as a reference point when the offer diverges radically from them in any direction. The same guidelines draw attention to the obvious, which is easy to forget: shorter response time increases the cost of the contract.

Evaluate reporting separately. Ask for a sample report and check if it answers the management's questions: what happened, what is the threat, what requires decisions and money. The closed ticket list does not do this.

Scope, exclusions and additional projects

The most disputes during cooperation do not concern quality, but whether a given work was included in the subscription.

Ask for a clear resolution of several common borderline situations: configuration of a new position for a new employee, email migration, implementation of a new system, purchase and configuration of equipment, team training, work outside hours in the event of a failure, on-site visit, minor change in the network. A good supplier will answer each of them with the word "included" or "separately" and provide the settlement method.

Note the two pricing mechanisms. The hourly model with a pool of hours rewards the supplier for the use of time, the unlimited subscription model rewards for a stable environment, but requires precise exclusions, otherwise the supplier must protect itself against unlimited liabilities. Neither is inherently better; it is important to understand what it encourages.

Also ask about changes. The company will have different needs in a year. The way the supplier describes the change in scope and price says more about future cooperation than the entire offer.

If you want to see what this scope separation looks like in practice, we have described it on the website IT outsourcing. We broke down the issue of the cost itself in the article about how much does IT outsourcing cost.

Evidence of experience

"We have many years of experience" is not information. Below are things that can be checked.

References from companies with a similar profile. NCSC recommends directly asking for references from other companies in the SME sector. It is important "similar profile": corporate experience does not translate into a 30-man manufacturing company.

Conversation with a current customer. The most valuable evidence and the least used. It is worth asking not about satisfaction, but about something specific: what the last serious failure was like and what happened then.

Team certifications and experience. Certificates can be helpful confirmation of knowledge of specific standards or technologies, but should not be the main criterion for choosing an IT company. ISO 27001 confirms the functioning of the information security management system within a specific scope, while the manufacturer's certificate may prove knowledge of a specific solution. However, none of them guarantees efficient service, quick response in the event of a failure or the ability to adapt the technology to the real needs of the company.

Equally important are the experience of people providing the service, the number of years of working with similar environments, the method of diagnosing problems and the procedures used. In the case of NexaIT, we base our competences primarily on over ten years of practical experience in the IT area, acquired while designing, implementing, securing and maintaining IT infrastructure. Therefore, when choosing a supplier, it is worth asking not only about their certificates, but also about specific implementations, documentation methods, security standards and the course of response to actual failures.

Producer partnerships. They are easily verified in public partner registers. This is worth doing because the word “partner” can be used loosely: sometimes it means formal status, and sometimes it's just that the company buys equipment from the distributor.

Company documents. Public records show how long a company has actually been in operation and who is behind it. Also ask about liability insurance and its scope, and ask for a document, not an assurance.

Agreement and exit plan

Exit conditions are checked before signing, because after that you no longer have any negotiating leverage.

NCSC recommends ensuring that the duration of the contract meets business objectives and provides flexibility when the business changes direction or when the quality of the service is no longer up to par. It also states that the contract should specify who is responsible for tracking the systems' end-of-support dates and acting before them.

Questions at the selection stage:

  • What is the notice period and does the contract extend automatically?
  • Does it include an obligation to cooperate in transferring the environment to a successor?
  • Who will own the documentation, accounts and configurations?
  • Will licences and subscriptions be purchased for your company or by the supplier?
  • Who is the domain registrant?

The last two points can be decisive. If the supplier buys everything on itself, when you part ways, you take over not only the new guardian, but also the project of recovering your own resources. We described what such a process looks like in the text about changing the IT company and taking over the administration.

The supplier's response to these questions is a test in itself. A factual response shows that the company has a process. Impatience or "why are you thinking about this, we're just getting started" proves the opposite.

The content of the agreement itself should be assessed by a legal adviser. This article is not legal advice and does not interpret contractual records. It only indicates what to ask.

Red flags

The following points describe behaviors, not companies. A single flag is a signal for inquiry, not a verdict. Several at a time is a pattern.

  • The answer to every question is "yes, of course." No company does everything right. A supplier who cannot name the limits of his competences either does not know them or hides them.
  • No exclusions in the offer. See above.
  • Full security declaration. Nobody eliminates risk completely.
  • Price clearly below the others. Someone's taken a different range. It is worth determining which element is the one before it is considered an opportunity.
  • Time pressure. "This price is valid until the end of the month" for a contract for several years.
  • Avoiding the topic of ending cooperation.
  • No reporting system.
  • Knowledge concentrated in one person.
  • Reluctance to show sample report or documentation. An anonymized artifact can be shown at any time. A refusal usually means that such a document does not exist.
  • Discrediting the previous supplier. A company that starts with a story about its predecessor's incompetence will one day tell a story about you.

Score Sheet

The spreadsheet below is our proposed methodology, not an industry standard. The weights depend on the company profile, so I am giving three variants instead of one.

You rate each criterion on a scale of 0-3:

  • 0: no response or evasive response;
  • 1: a declaration without proof;
  • 2: a declaration with partial proof;
  • 3: proof in document or artifact form.
Criterion Service/accounting office Production company Trading/service company
Scope and responsibility matrix 3 3 3
Provider access security 3 2 2
Backup with proof of recovery 3 3 3
SLA with clear counting rules 2 3 2
Knowledge continuity and substitution 2 3 2
Documentation provided to the client 2 2 2
Reporting to the management board 2 2 2
Consulting and budget planning 1 2 2
References from a similar profile 2 3 2
Terms of termination of cooperation 3 3 3

You calculate the result as the sum of the products of the rating and the weight. It's not about precision, it's about the differences between offers no longer being a matter of impression.

Two notes on interpretation. First things first, the offer with the highest score does not have to be the best choice if it falls poorly in the criterion of weight 3: no proof of backup reproduction does not compensate for great reporting. Secondly, price is deliberately not a criterion in the sheet. First, determine which offers actually meet your requirements; only compare the cost among them. The reverse order leads to choosing the cheapest coverage, not the cheapest service.

Choice based on evidence, not impression

It comes down to one habit change: instead of asking "are you doing X", ask to see X. The declaration is free, the artifact is not. A supplier who has a process will show it without resistance because showing it is cheaper than explaining why they can't.

If you want to apply this sheet to us, arrange a call and ask for the responsibility matrix and what we are willing to commit to. We'll answer the same questions you ask others, including the ones we're not very good at.


Disclaimer

The material is for informational purposes only. It does not constitute legal advice. Assessment of the content of the contract with an IT service provider, including the terms of liability and termination of cooperation, requires consultation with a legal advisor.

Sources

As of July 16, 2026

Read more in the same topic.

Free · 60 minutes online · no obligation

You want to check this out at home in your company?

  1. You talk to an engineerOnline, by video call. Not with a salesperson. We don't install or change anything.
  2. We check 8 areasBackups, access, network, email, server, licences, protection and KSeF readiness.
  3. You get a scorecardThree priorities on one page, emailed after the meeting. Yours to use however you like.

We don't use a contact form. We answer the phone and reply to emails.