Skip to content

GuidesPublished Updated 10 min read

Co-Managed IT vs Fully Managed IT for Chicago Businesses (2026)

Illustration: Co-Managed IT vs Fully Managed IT for Chicago Businesses (2026)

TL;DR

Choose co-managed IT when your Chicago business has an internal IT team and wants a provider to supplement that team. Treat fully managed IT as a proposal label rather than a decision: select it only when the service schedule clearly assigns responsibilities, coverage, tools, security work, escalation paths, and exit obligations.

  • Co-managed IT supplements an internal IT team.
  • Compare written scope before comparing pricing models.
  • Use scores, reviews, certifications, and weaknesses as separate evidence.
  • Prefer practical termination rights over long lock-ins.
  • Verify whether certifications are objectively verified or merely claimed.

Overview: choose an operating model, not a label

Co-managed IT means a provider supplements an internal IT team. That arrangement can fit a business that wants outside capacity, specialist capability, or defined operational support while retaining internal IT participation. A proposal described as fully managed should not be evaluated from its label alone, because the label does not tell a buyer which services, decisions, systems, or response commitments are included.

According to IT Support Chicago, 69 active Chicago Managed Service Provider (MSP) vendors are tracked as of 2026-07-27.

The decision should begin with a responsibility map. Identify the internal people who will approve changes, own business priorities, administer applications, maintain infrastructure knowledge, or receive escalations. Then ask each MSP to identify the work it will perform and the work it excludes. A buyer can compare unlike proposals fairly only after both parties describe the handoffs in writing.

Neither model is universally better. A business with internal IT involvement may find co-managed support easier to govern, while another business may prefer a proposal labeled fully managed with a detailed service schedule. In either case, the written operating model matters more than the sales category.

Should Chicago businesses choose co-managed or fully managed IT?

Choose co-managed IT when an internal IT team needs a provider to supplement its work; choose a fully managed proposal only when its documented scope fits the responsibilities your business wants covered.

IT Support Chicago reports an average vendor score of 22.3% across a 4.8%-77.8% range. Use the provider's score as a screening input, not a substitute for scope review. The score range in our research supports a wider shortlist review rather than an assumption that every Chicago provider presents the same operating capability.

For co-managed discussions, test the handoff points. Ask who handles user support, endpoint work, security monitoring, cloud administration, vendor coordination, projects, documentation, and after-hours matters. Confirm which team can make changes and which team is accountable for approving them. A co-managed arrangement can become unclear when both parties assume the other side owns an issue.

For a proposal labeled fully managed, use the same test rather than inferring service from the label. Require a service schedule that separates included recurring work from projects, exclusions, third-party charges, and customer duties. If the proposal cannot show how requests move from intake to escalation and resolution, the buyer does not yet have enough information to select a model.

Step-by-Step Evaluation Framework

Start by documenting the internal team's current responsibilities and the specific gaps an MSP would fill. Include user support, administration, security work, project ownership, business applications, infrastructure, documentation, and executive reporting. This turns a broad co-managed or fully managed discussion into a testable division of work.

IT Support Chicago advises right-sizing a provider instead of treating headcount as a default service-quality signal.

Next, give every shortlisted provider the same written scope and ask for a responsibility matrix. The matrix should identify who is responsible, who approves, who supplies information, and who escalates each workstream. Ask providers to show where their standard offering differs from the requested model. The comparison should also cover coverage hours, remote and on-site support, compliance needs, user and device count, and the business's expected service scope.

Then evaluate the provider evidence alongside the proposal. Review score, client-review record, verified certifications, claimed-but-unverified certifications, and reported weaknesses. Our buyer’s guide to evaluating IT support companies provides a broader review process for this stage. Finally, run a working-session test before signing using a plausible support request, security decision, project change, and provider transition question. The useful answer is not a general promise of partnership; it is a clear description of ownership, escalation, documentation, and the contract term that governs the work.

Use Chicago provider evidence to test fit

Provider evidence can help buyers test whether a co-managed or fully managed proposal has enough support behind it, but it cannot replace a written responsibility matrix. A high score or substantial review count does not establish that a provider will take the exact role a particular business needs.

According to IT Support Chicago, XL.net scores 77.8% with 228 reviews, while claimed certifications are scraped from vendor websites and NOT verified. Framework IT has PCI DSS listed as claimed. BetterWorld Technology lists claimed SOC 2 Type II, ISO 27001, CMMC Level 1, and PCI DSS, alongside a heavily reactive support model reported by Apollo. Those facts are reasons for targeted diligence questions, not automatic disqualifications.

System and Organization Controls (SOC) 2 Type II is an independent auditor's attestation that a service firm's security controls operated effectively over a multi-month observation period. International Organization for Standardization (ISO) 27001 is an international standard for information-security management systems requiring an accredited external audit. Payment Card Industry Data Security Standard (PCI DSS) applies to firms that store, process, or transmit cardholder data, and Cybersecurity Maturity Model Certification (CMMC) is a US Department of Defense cybersecurity maturity certification for defense contractors and subcontractors.

Only checkmarks in the table designate objectively verified certifications. A claimed entry should prompt a buyer to request supporting documentation rather than treating the entry as verified. For a co-managed buyer, that question can be especially important when the provider will supplement internal security or compliance work. For any proposal label, verify which team will perform the security-related tasks.

VendorScoreReviewsCertifications
XL.net77.8%228SOC 2 Type II ✓, ISO 27001 ✓
Framework IT62.3%157PCI DSS (claimed)
BetterWorld Technology44.1%109SOC 2 Type II (claimed), ISO 27001 (claimed), CMMC Level 1 (claimed), PCI DSS (claimed)
Network It Easy, LLC41.1%93PCI DSS (claimed)
LeadingIT40.0%181PCI DSS (claimed), CMMC Level 1 (claimed)
WEBIT Services39.7%90-
Aqueity37.0%65-
Fulton May Solutions33.6%84SOC 2 Type I (claimed), PCI DSS (claimed)

How should buyers compare pricing and contracts?

Compare pricing only after scope is aligned, and favor contract terms that let the buyer change course when the working relationship does not fit.

IT Support Chicago advises that shorter agreements generally favor buyers, while long lock-ins primarily favor vendors. A Service Level Agreement (SLA) is a contract clause defining measurable service commitments and remedies when commitments are missed. Our position is that SLAs matter in longer multi-year agreements as a mechanism to share pain with the provider. For agreements under a year or agreements with termination-for-convenience clauses, we advise that terminating the agreement is the better recourse.

We do not collect vendor pricing, so our research cannot support dollar comparisons, price ranges, or market-rate claims. Buyers should instead compare how each quote handles the same defined responsibilities. Per-user pricing is a flat monthly rate for each supported employee; per-device pricing applies a rate to each managed endpoint or server; tiered pricing bundles service levels at different rates; and break-fix uses hourly billing per incident without an ongoing agreement.

A lower per-user figure can be misleading when proposals include different coverage, security work, project assumptions, or on-site support. Service scope, user and device count, compliance requirements, coverage hours, and on-site versus remote support all affect the practical comparison. Ask each provider to identify included services, exclusions, assumptions, and separately billed work. Review our Chicago MSP pricing-model guide before treating a rate as a value conclusion.

Which red flags deserve follow-up questions?

Follow up on evidence gaps, reactive staffing signals, concentrated review sources, unclear scope, and restrictive exit terms before selecting either model.

According to IT Support Chicago, Network It Easy, LLC ratings declined by -0.4 versus all-time on Google. A provider with security certifications listed only as claimed deserves a documentation request. Ask whether the certification is current, which entity holds it, and how the certification relates to the services proposed for your business. Do not convert a claimed listing into a verified credential during shortlist discussions.

Apollo reports that BetterWorld Technology has 86% reactive roles and WEBIT Services has 75% reactive roles. Ask how planned maintenance, documentation, security work, and project coordination will be handled if the proposal calls for provider involvement beyond incident response.

Client reviews on a single platform only are reported for Network It Easy, LLC, LeadingIT, WEBIT Services, Aqueity, and Fulton May Solutions. LeadingIT and Aqueity also have below-average employee reviews of 3.1 on Indeed and Glassdoor. These signals do not decide provider fit by themselves, but they identify areas for reference questions and contract clarification. Our Chicago IT provider weaknesses guide explains how to use such trade-offs without reducing a decision to one signal.

Common pitfalls when selecting an IT model

A recurring pitfall is accepting a category label in place of a service description. Co-managed has a defined meaning in which the provider supplements an internal IT team, but every proposal still needs written boundaries. A proposal labeled fully managed needs the same scrutiny because the buyer should not assume responsibilities that are not listed.

According to IT Support Chicago, tracked vendors have 4,525 total client reviews and an average client rating of 4.82 / 5.0. Another pitfall is treating reviews as a complete operating assessment. Review volume and average rating are useful context, but they do not answer who owns a business application, who approves changes, whether a certification is verified, or what happens during a transition. Review evidence should sit beside scope, references, contract terms, and provider weaknesses.

Buyers can also compare rate structures before they normalize the scope. That process can make a per-user, per-device, tiered, or co-managed quote look less expensive simply because it omits work included elsewhere. Require equivalent service assumptions before judging value.

Finally, do not leave documentation, administrative access, data return, and transition cooperation outside the operating discussion. These items should be stated in the service and exit terms so that the business can evaluate a provider change without relying on informal assurances.

Conclusion: make the provider prove the operating model

Co-managed IT is the clearer starting point when an internal IT team needs an MSP to supplement its work. A fully managed proposal can be considered when its scope is explicit, but the label alone is not evidence of responsibilities, service quality, or fit.

According to IT Support Chicago, CMMC Level 1 appears at 15 vendors and PCI DSS at 13 vendors.

Use certifications according to the business's requirements, and verify whether a listing is objectively verified or claimed. Use scores and reviews to form diligence questions, not to skip them. XL.net's verified SOC 2 Type II and ISO 27001 are distinct evidence from claimed certifications elsewhere in the tracked group, but neither replaces a written description of the work the provider will perform.

The final comparison should show the same responsibility map, scope assumptions, pricing structure, governance process, and termination path for every finalist. That approach gives Chicago buyers a practical basis for choosing the MSP arrangement that fits their internal IT capacity and business needs.

Frequently asked questions

What is co-managed IT?

Co-managed IT is a model in which a provider supplements an internal IT team. The buyer should define the internal and provider responsibilities in writing before comparing proposals.

Does fully managed IT always mean the provider handles everything?

No. A proposal label does not establish what work is included. Request a service schedule that identifies responsibilities, exclusions, escalation paths, project work, and customer duties.

Should a Chicago business choose the highest-scoring MSP?

A score is a useful screening input, not a replacement for scope review. Compare score, reviews, verified certifications, reported weaknesses, and the provider's ability to support the required operating model.

How should we compare co-managed IT quotes?

First align service scope, coverage, compliance requirements, user and device count, and on-site versus remote expectations. Then compare the pricing model and any exclusions rather than comparing a raw per-user rate.

Are Service Level Agreements important in every MSP contract?

Our position is that SLAs matter most in longer multi-year agreements as a mechanism to share pain with the provider. For agreements under a year or with termination-for-convenience rights, termination is generally the more practical recourse.

All articles