Skip to content

GuidesPublished Updated 11 min read

How to Evaluate IT Support Companies: A Buyer's Guide

Illustration: How to Evaluate IT Support Companies: A Buyer's Guide

TL;DR

Evaluate IT support companies by defining the service outcomes your business needs, comparing proposals with the same scope, verifying security evidence, testing operating fit, and protecting your ability to leave. Choose the provider with the most credible fit for your environment and contract terms, not simply the lowest per-user quote, largest team, or strongest sales presentation.

  • Normalize scope before comparing proposals.
  • Treat certifications as evidence to verify, not marketing shorthand.
  • Use scores, reviews, and weaknesses together.
  • Prefer shorter commitments and clear exit terms.
  • Assess support operations, not only response promises.

Overview

Choosing a Managed Service Provider (MSP) is a decision about operating model, risk allocation, and exit options as much as technical support. A useful evaluation starts with the work your organization expects a provider to own: user support, endpoint management, servers, cloud administration, cybersecurity controls, compliance assistance, strategic planning, or a defined supplement to an internal IT team. It ends with a contract that makes the promised scope testable and departure manageable.

IT Support Chicago research tracks 69 active Chicago MSPs. Our data is a starting point for a shortlist, not a substitute for confirming whether a provider can support your applications, locations, staff workflow, and industry obligations. Scores summarize our evaluation criteria, while client reviews can show buyer experience; neither removes the need for reference calls and a detailed scope review.

A disciplined buyer compares evidence in like-for-like categories. Ask each finalist to describe included services, exclusions, escalation ownership, security responsibilities, onboarding, reporting, and offboarding in writing. Then compare operational strengths against trade-offs. A provider can have meaningful review volume yet present a weakness relevant to your environment, such as reactive staffing, unverified security claims, or review concentration on one platform.

Our view is that right-sizing matters more than headcount. A smaller provider may be the better choice when it can demonstrate accountable coverage, relevant expertise, and a service design suited to your organization; a larger firm is not automatically more reliable.

Who This Guide Is For and Why It Matters

This guide is for Chicago-area organizations selecting their first outsourced provider, replacing an existing provider, or deciding whether outside support should complement internal IT. It also applies when a business is moving from hourly break-fix work toward an ongoing managed relationship, or considering co-managed IT, where a provider supplements an internal IT team.

IT Support Chicago research shows an average vendor score of 22.3% across the Chicago MSPs we track, with scores ranging from 4.8%-77.8%. That range is why buyers should use a repeatable process rather than assume that any provider with a strong local presence is interchangeable. The average client rating in our tracked set is 4.82 / 5.0 across 4,525 client reviews, which makes review context especially important: high ratings can coexist with limitations that matter to a particular buyer.

The decision matters because an MSP receives broad access to systems, users, vendors, and sensitive business processes. The provider will influence how incidents are triaged, how changes are made, how security controls are administered, and how knowledge is documented. A mismatch can create repeated friction even when individual technicians are capable.

Use this guide to build an evaluation record that leadership, finance, operations, and internal IT can review together. For organizations retaining internal technical staff, define shared responsibilities before comparing providers.

What is the step-by-step evaluation framework?

Start with a written requirements baseline, issue the same scope to each finalist, verify their evidence, test their operating model, and compare contract exit terms before selecting a provider. The purpose is to make every proposal answer the same business problem rather than letting each sales process define a different one.

IT Support Chicago research records vendor scores ranging from 4.8%-77.8%. Begin by documenting your users, devices, applications, cloud services, locations, existing IT staff, support coverage expectations, security obligations, and recurring pain points. Describe outcomes rather than assuming a particular tool or staffing pattern is the answer. Include who owns business decisions, who approves changes, and which work must remain with your team.

Next, provide finalists a common request for information. Require an included-services list, exclusions, assumptions, onboarding approach, escalation path, reporting sample, and a responsibility matrix. Ask each provider to identify dependencies on third parties and any tasks billed outside the recurring agreement. Compare answers line by line, not by the order or terminology of a sales deck.

Then test proof. Hold structured conversations with the people who would own service delivery, not only sales leadership. Ask for references resembling your environment, examples of recurring reporting, and an explanation of how unresolved issues are escalated. Evaluate whether answers are specific, consistent, and documented. Finally, have the finalist contract reviewed against the submitted scope, especially change control, access ownership, data return, and termination process.

How should buyers assess support, security, and operational fit?

Buyers should assess support, security, and fit by asking who performs the work, how issues move from intake to resolution, which controls are independently verified, and how the provider will adapt to the business environment. A promise of responsiveness is less useful than a clear explanation of ownership, escalation, documentation, and communication.

IT Support Chicago research identifies XL.net with a 77.8% score and verified SOC 2 Type II and ISO 27001 certifications. SOC 2 Type II is an independent auditor's attestation that a service firm's security controls operated effectively over a multi-month observation period. ISO 27001 is an international standard for information-security management systems, and certification requires an accredited external audit. These are meaningful forms of evidence, but buyers should still determine whether the controls and service scope apply to the engagement they are buying.

Treat claimed certifications differently from verified certifications. Framework IT lists PCI DSS as claimed. BetterWorld Technology lists SOC 2 Type II, ISO 27001, CMMC Level 1, and PCI DSS as claimed. CMMC is the US Department of Defense's cybersecurity maturity certification required of defense contractors and subcontractors. A claim scraped from a vendor website is not objectively verified in our data, so ask for current documentation and clarify what the certification or assessment covers. PCI DSS is the payment-card industry's data-security standard for firms that store, process, or transmit cardholder data.

Operational fit also includes proactive capacity. BetterWorld Technology has a heavily reactive support model with 86% reactive roles according to Apollo, while WEBIT Services has a heavily reactive support model with 75% reactive roles according to Apollo. Reactive support is not necessarily disqualifying, but organizations seeking regular planning, risk reduction, and change management should ask how proactive work is staffed, scheduled, measured, and protected from daily ticket demand. For deeper certification context, see our Chicago SMB IT Provider Certifications Report 2026.

Pricing and Contracts

Compare pricing only after scope is normalized, and prefer contract terms that preserve a practical option to leave when service is not working. A lower recurring charge can exclude services that another proposal includes, while a broader package can still shift important work into exclusions or project fees.

IT Support Chicago does not collect vendor pricing. Buyers can still compare quote structure intelligently. Per-user pricing is a flat monthly rate for each supported employee; per-device pricing applies a rate for each managed endpoint or server; tiered pricing bundles service levels at different rates; co-managed pricing supports an internal IT team; and break-fix billing is hourly per incident without an ongoing agreement. Service scope, user and device count, compliance requirements, coverage hours, and on-site versus remote support all affect cost.

Our position is that per-user price without scope context is misleading. Create a comparison sheet that lists what each tier includes for support, security, monitoring, administration, strategic planning, projects, after-hours work, onboarding, and hardware or software vendor coordination. Ask providers to mark every item as included, excluded, conditional, or separately billed. Resolve differences before asking which option represents better value.

A Service Level Agreement (SLA) is a contract clause defining measurable service commitments and remedies when a commitment is missed. Our view is that SLAs matter most in longer agreements, where they can share pain with the vendor. For agreements under a year, or those with termination-for-convenience clauses, termination is generally better recourse than attempting to recover a contractual remedy. We advise buyers to favor shorter agreements because long lock-ins primarily benefit the vendor. Review our contract length analysis and confirm notice, transition assistance, access return, documentation handoff, and termination rights before signing.

Red Flags to Watch For

Red flags are not automatic disqualifiers, but they should trigger targeted questions, documentary proof, or a narrower contract commitment. The strongest warning signs are gaps between what a provider markets and what it can verify, combined with terms that make it hard for a buyer to change course.

IT Support Chicago research flags client reviews on a single platform only for Network It Easy, LLC, LeadingIT, WEBIT Services, Aqueity, and Fulton May Solutions. Review concentration does not prove poor service. It does mean the buyer has less independent perspective across sources, so reference calls, role-specific conversations, and questions about negative feedback carry more weight. Network It Easy, LLC also has recent ratings trending down (-0.4 vs all-time) on Google, an item that warrants discussion about current service operations.

Other evidence should be read as a trade-off rather than a verdict. LeadingIT and Aqueity have below-average employee reviews of 3.1 on Indeed and Glassdoor. Employee feedback cannot establish client outcomes, but it can prompt questions about technician retention, workload, escalation capacity, and continuity. Fulton May Solutions has claimed SOC 2 Type I and PCI DSS credentials that are not objectively verified in our data; ask to see the relevant underlying evidence.

Watch for vague inclusions, undefined exclusions, resistance to written responsibility matrices, unverified security claims presented as completed certifications, and a contract that obscures exit duties. Also be cautious when a provider cannot identify who will own strategic planning or recurring operational review. The buyer needs a service model that can be inspected before the first invoice, not only reassurances that problems will be handled.

VendorScoreReviewsCertifications
XL.net77.8%228SOC 2 Type II ✓, ISO 27001 ✓
Framework IT62.3%157PCI DSS (claimed)
BetterWorld Technology44.1%109SOC 2 Type II (claimed), ISO 27001 (claimed), CMMC Level 1 (claimed), PCI DSS (claimed)
Network It Easy, LLC41.1%93PCI DSS (claimed)
LeadingIT40.0%181PCI DSS (claimed), CMMC Level 1 (claimed)
WEBIT Services39.7%90-
Aqueity37.0%65-
Fulton May Solutions33.6%84SOC 2 Type I (claimed), PCI DSS (claimed)

Common Pitfalls

The most common mistakes are comparing unlike proposals, treating marketing claims as verified evidence, overvaluing a single review metric, and accepting a long commitment before the operating model is clear. Each mistake can make a selection look straightforward while moving risk into unexamined assumptions.

IT Support Chicago research lists security certifications as not objectively verified for Framework IT, BetterWorld Technology, and Fulton May Solutions. Do not equate a claimed credential with verified certification. Ask what standard applies, what entity and service scope it covers, when evidence was issued, and whether the provider can share appropriate documentation. For regulated environments, determine whether the provider's controls match your specific obligations rather than presuming a familiar acronym resolves them.

Another pitfall is choosing by scale. Our position is that bigger is not inherently better; the right provider has sufficient capacity and the correct service design for the buyer's environment. Ask who handles your account, what happens during absences or escalations, how specialized issues are routed, and whether the provider can support your preferred communication and governance cadence.

Buyers also often confuse a fast initial acknowledgement with problem resolution. Request definitions for intake, triage, escalation, progress updates, and closure. Examine how recurring issues are analyzed and prevented, not merely how quickly a ticket receives a first response. Finally, do not defer offboarding questions until service has deteriorated. Use our onboarding and offboarding checklist to turn access, documentation, data, and transition responsibilities into pre-signature questions.

What should a buyer do before making the final choice?

Before selecting an IT support company, choose the finalist that has the clearest matched scope, strongest verifiable evidence, workable operating model, and least restrictive acceptable contract. Record why the provider won on those criteria so the decision remains understandable after implementation begins.

IT Support Chicago research identifies 228 client reviews for XL.net and 181 for LeadingIT. Review volume is useful context, but it should not override fit, weaknesses, security evidence, or contract terms. Use the final stage to reconcile every open item: included and excluded work, escalation contacts, access ownership, implementation plan, governance meetings, reporting, security responsibilities, and exit assistance.

Ask the preferred provider to convert proposal language into an operational agreement without ambiguity. If an item is important, identify the owner, deliverable, timing, condition, and remedy or termination option. If a provider cannot make a commitment clear before the relationship begins, assume the ambiguity will remain when a difficult issue appears.

We advise buyers to keep alternatives viable until the agreement is complete and exit terms are understood. A sound selection is not the provider that promises every outcome; it is the provider whose documented commitments, credible evidence, and contract structure make performance observable and replacement feasible.

Frequently asked questions

Should we choose the IT provider with the highest score?

Use score as a shortlist input, not a final decision. Confirm that the provider's scope, staffing model, security evidence, reviews, weaknesses, and contract terms fit your business.

Are claimed certifications enough to select an MSP?

No. Claimed credentials are not objectively verified in our data, so request documentation and determine whether the evidence applies to the services and environment you are evaluating.

What should be included when comparing IT support quotes?

Compare included services, exclusions, coverage, security responsibilities, onboarding, projects, reporting, and offboarding. A pricing model alone does not show what work is actually covered.

Do we need a strict SLA in every IT support contract?

Not necessarily. Our view is that SLAs are most useful in longer agreements; in shorter arrangements or contracts with termination-for-convenience rights, the ability to leave can be the stronger buyer protection.

Is a larger Chicago MSP automatically a safer choice?

No. Evaluate whether the provider has the capacity, expertise, escalation coverage, and operating model your organization needs. Right-sizing is more important than headcount alone.

All articles