Managed IT Services: 9 Critical Questions Before You Sign

Bar chart of the UK managed IT services market by provider size: 59% micro, 28% small, 9% medium, 4% large
Where size is known, roughly seven in eight UK providers are micro or small firms.

Almost everything published about managed IT services was written by someone who sells managed IT services. That is not a conspiracy — it is simply who has a commercial reason to publish. It does mean the definitions you find are shaped by whatever the author happens to offer, and that the buying advice tends to stop just short of the questions a provider would rather you did not ask.

We do not sell this model, and it is better to say so at the top than halfway down. There is no service desk here, no per-incident pricing and no first line — the same thing our co-managed IT support page has said in public since the day it went up. If a first-line desk is what you need, that is a completely legitimate thing to want and there are good providers who do it well. This piece exists to help you buy from one of them properly.

What managed IT services actually are

The model is simple to state: an external provider takes ongoing responsibility for an agreed part of your IT estate for a recurring fee, rather than being called in per incident and billed per incident.

Three words in that sentence carry the weight. Ongoing is what separates it from project work and from break-fix. Agreed is where most disappointment begins, because the scope tends to be described fully in the marketing and only partially in the contract. And responsibility is the word buyers skip: you are purchasing an outcome that somebody else owns, which means you are also purchasing a dependency on them.

In practice the contract usually bundles some combination of a service desk, endpoint management and patching, monitoring and alerting, backup administration, identity and licence administration, and vendor liaison. Security is sometimes inside that bundle and sometimes a separate line item with a separate provider behind it. The distinction between a managed service provider and a managed security service provider is real, and it is worth making somebody say out loud which one they are.

What the model is not is a strategy function. A provider paid to keep an estate running has no structural incentive to tell you the estate is the wrong shape. That is a different purchase with a different conflict of interest, set out in our piece on what a virtual CIO actually does.

The one definition nobody selling it wrote

Every vendor definition is really a description of that vendor. There is, however, one written by a party with nothing to sell: the UK government, which is in the middle of turning these providers into a regulated category and therefore had to define them precisely enough to enforce.

The Department for Science, Innovation and Technology’s Cyber Security and Resilience Bill policy statement, published on 1 April 2025, sets out a four-part test. A managed service is one that is provided to another organisation rather than in-house; that relies on network and information systems to deliver; that relates to ongoing management support, active administration or monitoring of IT systems, infrastructure, applications or networks; and that involves a network connection or access to the customer’s own systems. The statement is explicit that the exact wording remains subject to final drafting.

The fourth limb is the useful one, and it is the limb no marketing page leads with. What legally defines managed IT services is not the monthly fee, the ticket queue or the response-time table. It is that somebody outside your organisation holds standing access into it.

The four-part test for a managed service from the UK Cyber Security and Resilience Bill policy statement: provided to another organisation, relies on network and information systems, ongoing management or monitoring, and network access to the customer
All four limbs have to be true. The fourth is the one that changes your risk.

Who you are actually buying from

The word “provider” conjures something substantial. The only population-level count we could find says otherwise.

Research commissioned by the same department and published in February 2024 identified an estimated 11,492 active managed service providers in the UK, as at August 2023. Of those whose size was known, 59% were micro firms and another 28% were small. Large providers were 4% of the count and 74% of the revenue, and the ten biggest alone accounted for an estimated 27% of everything the sector earned.

Two things follow for a buyer. The first is that the typical provider is a small business carrying the same key-person risk, the same holiday-cover problem and the same concentration risk you have. Ask how many of their engineers actually know your estate; the honest answer is frequently one, and that person is why the relationship works.

The second is that no generic advice about managed IT services can be reliable across a market shaped like that, including this article’s. Treat everything below as questions to ask rather than answers to expect.

Nine questions to ask before you sign

Roughly in order of how much damage the wrong answer does. None of them are hostile; a good provider will have answered all nine before, and will say so. A managed IT services agreement is negotiated once and then lived with for years, so the hour spent here is the cheapest hour in the whole relationship.

  1. What is in scope — as a list, in the contract? Not in the proposal, not on the website. If a function is not named, assume it is not covered, and assume the argument about it happens on your worst day.
  2. Who is the tenancy and the licensing registered to? Yours, on your own billing relationship, is the only correct answer. Provider-held tenancy is the single most common form of lock-in in this industry and it is entirely avoidable at the start.
  3. Can we export the documentation, in a form we can use? If the only record of your environment lives in their tooling, leaving is expensive by design rather than by accident.
  4. How do your people authenticate into our environment? Named individual accounts rather than a shared provider login, multi-factor authentication with no exemptions, access scoped to the contract, and removal the day someone leaves their payroll — which requires them to tell you, which requires it to be written down.
  5. What happens when you are the one breached? Standing access into your estate means their compromise is your incident. Ask what they will tell you, how fast, and whether that is a contractual obligation or a promise.
  6. Who is allowed to declare an incident, and who talks to the business during one? Decide this while nothing is on fire.
  7. Where is the responsibility matrix? Every significant function with one named owner. Where a function looks genuinely shared, split it until it is not: “backup” is ambiguous, while “backup configuration” and “backup restore testing” can sit with different owners without confusion. Our note on what a restore drill exposes covers why that second one is not a formality.
  8. What does leaving look like? An exit clause with a handover obligation attached to it. Not because you expect to use it, but because an arrangement you can leave is one both sides keep earning.
  9. Which of these are you already legally obliged to do? A growing number of them, in more than one jurisdiction. That is the next section.

Where this model is genuinely the right answer

We are not damning it. There are situations where buying managed IT services is plainly the correct call, and pretending otherwise would be its own kind of marketing.

It is the right answer when the work is high in volume and low in variety — password resets, starters and leavers, device builds, the daily attrition of a user base. Providers are efficient at exactly that, and an internal hire doing it is expensive and will leave.

It is the right answer when you need cover rather than headcount. One internal person means illness, leave and resignation are all single points of failure, and a contracted provider who already knows the environment is continuity you can price.

And it is the right answer when the alternative is nobody. A business of forty people with no IT function at all is not choosing between a provider and an ideal; it is choosing between a provider and whoever is best at computers in the finance team.

When managed IT services are the wrong purchase

Four situations, all of which we have watched go wrong.

You already have a capable internal person. Buying a full contract over the head of someone competent does not add capacity, it adds a boundary dispute — and you will lose the person who knows why that odd exception exists in the finance system. What that situation actually calls for is described in our piece on the three co-managed IT models.

The gap is depth, not hours. A monthly contract priced per seat is a poor way to buy the four hours a year of genuinely specialist judgement you need. You will pay for volume you do not use to reach expertise you cannot schedule.

You need somebody to tell you the truth about a vendor. Independence is hard to buy from the party that implemented the thing and earns recurring revenue from it. That is the argument for keeping the advisory layer separate, which we set out in fractional CIO versus virtual CIO.

Your estate has no shape yet. Handing an undocumented, unowned, half-migrated environment to a provider on a fixed monthly fee produces a fixed monthly fee and an undocumented environment. Do the assessment first, even if somebody else does it.

The number we are not going to publish

Search for what managed IT services cost and you will find per-seat-per-month ranges everywhere, quoted with real confidence. We chased several of them and could not get any to a primary source. They cite each other, or they cite a provider’s own price list presented as a market rate.

So we are not publishing one. A number quoted without knowing the estate is marketing rather than information, and a number laundered through six blogs is worse than that.

What is worth understanding is the shape. Per-user or per-device monthly is the most common and the most predictable, and it is the model most likely to drift — once you are paying per seat, routing everything through the provider feels free. Blocked hours drawn down as needed suit an escalation relationship, and you should ask what happens to unused ones. Fixed-scope project pricing has edges, which makes it the easiest to verify afterwards. What moves any of them is users and sites, how much documentation already exists, out-of-hours expectations and regulatory exposure.

Where delivery capacity comes from another country, the same shapes apply and the obligations do not soften — the argument for and against that model is in IT outsourcing to South Africa.

Your provider is becoming a regulated entity

This is the part of the managed IT services conversation that has genuinely changed, and most buying guides have not caught up with it.

In the European Union, NIS2 already lists “ICT service management” — explicitly naming managed service providers and managed security service providers — among its sectors of high criticality, per the Commission’s own questions and answers on the directive. Member states were required to transpose it by 17 October 2024, and transposition is uneven: on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify their measures. So “we comply with NIS2” means different things in different member states, and is a fair question to ask.

In the United Kingdom the Cyber Security and Resilience (Network and Information Systems) Bill creates a new regulated category, the relevant managed service provider. The Information Commissioner’s Office, which would be the regulator, called that expansion “a natural progression” in its response of 23 December 2025. The policy statement proposes a two-stage clock: notify the regulator and the NCSC within 24 hours of becoming aware of a significant incident, with a fuller report inside 72 hours.

There is a large exemption, and it matters more than the headline. Small and micro businesses fall outside the proposed scope, which on the department’s own numbers leaves just over 9,800 of those 11,492 providers unregulated. So the probability that your provider becomes a regulated entity is not high — but the standards being written for the ones in scope are a perfectly good specification to hold a smaller supplier to voluntarily.

The Bill is not law yet. Parliament’s own record of its stages — which we read directly, because the human-readable pages block automated access — has it introduced on 12 November 2025, through Commons third reading on 16 June 2026, and sitting in Lords committee from 1 September 2026. Check that record rather than any article about it, including this one.

Timeline of the UK Cyber Security and Resilience Bill from first reading in November 2025 to Lords committee stage in September 2026
Stage dates read from Parliament’s Bills API on 31 August 2026. It will have moved.

One estimate discrepancy is worth flagging, because it is instructive. The policy statement says the measure would bring 900 to 1,100 providers into scope and cites the department’s own research as the source; that research puts the number of large and medium providers potentially in scope at 1,500 to 1,700. We have not found anything reconciling the two, so we are reporting both rather than picking the tidier one.

What we do instead, and why we are saying so

We are a consultancy, not a provider of this model. We do the layer above it: the architecture decisions that are expensive to reverse, the incident where the first hour of judgement matters, the migration with a vendor deadline attached, and the planning nobody internally has time for. Distance is not a constraint on that work — the disciplines it demands are in remote IT consulting across time zones, and the estates it applies to increasingly have no office at their centre at all, which we cover in distributed IT architecture.

Saying so costs us the enquiries from people who want a first line, and we would rather lose those at the top of a page than in a meeting. It also means we have no reason to flatter the model or to rubbish it. Buying managed IT services well is mostly a contract problem, not a technology one, and the nine questions above are worth more than any comparison table you will be sent.

If you already have someone good and out of hours, the arrangement you want is probably not this one — start with co-managed support instead.