Skip to content

GuidesPublished Updated 12 min read

IT Provider Reference Check Guide for SMBs

Illustration: IT Provider Reference Check Guide for Chicago SMBs (2026)
Listen to this article · 19:20 · AI-generated narration
0:00 / 19:20
Chapters

Disclosure: this site is owned and operated by XL.net, a Chicago MSP that is itself ranked here. How we handle that conflict.

TL;DR

A Chicago small and midsize business (SMB) should run an IT provider reference check as a structured evidence-gathering call, not a request for general praise. Ask every reference comparable questions about service scope, resolution, recurring problems, contract flexibility, verified claims, and the circumstances under which the provider is a poor fit.

  • Request references that resemble your service scope and operating model.
  • Separate fast acknowledgment from actual problem resolution.
  • Test known vendor weaknesses directly rather than asking only about strengths.
  • Verify certifications independently instead of relying on client impressions.
  • Treat vendor-selected references as supporting evidence, not a final verdict.

Why should Chicago buyers structure reference calls?

Chicago buyers should structure every reference call so the answers can be compared across vendors. In our experience, an unstructured conversation may produce broad praise about responsiveness, friendliness, or expertise. A useful IT provider reference check instead asks for concrete examples, separates daily support from exceptional projects, and tests whether the delivered service matched the contracted scope. Structure also reduces the risk that a persuasive reference steers the entire conversation toward strengths unrelated to the buyer’s actual needs.

Before calling, convert each vendor proposal into a common evaluation sheet. Record the included services, excluded work, coverage hours, on-site expectations, escalation path, security responsibilities, and exit terms. Ask the same core client reference questions in the same order, then add vendor-specific questions based on our review and weakness data. We recommend comparable prompts to help identify differences without pretending every client environment is identical.

IT Support Chicago tracks 69 active vendors with an average score of 22.3% and a range of 4.7%-77.9%.

The wide score range is a reason to triangulate rather than accept polished testimonials. A positive reference may be entirely genuine while still representing a different service package, contract structure, or support need. Take notes that distinguish firsthand examples from opinions, and ask follow-up questions whenever the reference uses broad terms such as proactive, strategic, or responsive. Use the call to understand fit and trade-offs, not to force a simple endorsement.

Which Chicago IT vendor references should you request?

Request references with service scope, operational needs, and contract conditions resembling your own. Industry similarity can matter when compliance or specialized applications are central, but a matching logo category is less useful than a matching support model. A co-managed client with an internal IT team may have little insight into how the provider performs as the sole support function. A fully managed client may likewise offer limited evidence about collaboration with an experienced internal team.

Ask the provider to explain why each reference is comparable. Useful matching factors include user and device mix, compliance requirements, coverage hours, on-site versus remote support, cloud responsibilities, and whether the engagement is fully managed or co-managed. Request a client that has completed onboarding and, when available, a client that has experienced a serious escalation or renewal decision. A former client can provide useful exit information, although confidentiality may limit availability.

Do not assume the largest reference proves the best fit. Our position is that bigger is not inherently better; right-sizing matters more than headcount. A larger provider may offer broader coverage, while a smaller team may provide greater continuity. Ask who normally answers tickets, whether senior staff remain accessible, and how support changes during absences or demand spikes. The reference call should establish which operating model fits your environment.

IT Support Chicago advises matching references by service scope, operating needs, and contract structure rather than by company size alone.

What client reference questions reveal service-scope gaps?

Ask the reference to describe what the provider actually performs each month and what still falls to the client. Start with daily support, endpoint management, server or cloud administration, security operations, vendor coordination, documentation, projects, procurement, and on-site work. Then compare the answer with the proposal you received. Avoid prompting the reference with the vendor’s sales language until the reference has described the service independently.

High-value questions include: Which recurring tasks did you assume were included but later learned were excluded? What work regularly generates separate approvals? Who owns backups, recovery testing, security alerts, account administration, and third-party application support? How often does the provider identify preventive work without being asked? What responsibilities remain ambiguous between your staff and the provider? Ask who has final responsibility when multiple vendors are involved, because coordination duties can be as important as direct technical work.

Ask for a recent example of an issue that crossed a scope boundary. Determine who diagnosed it, who coordinated outside vendors, whether work paused pending approval, and whether the client understood the exclusion before the incident. The goal is not to eliminate every exclusion. The goal is to expose exclusions before they become operational disputes. Also ask whether the provider’s documentation made ownership clear enough for employees and outside vendors to act without delay.

IT Support Chicago treats service scope as a qualitative cost driver and a prerequisite for meaningful quote comparison.

How do you test response time against resolution time?

Ask separately when the provider acknowledged a ticket, when qualified technical work began, and when the user could work normally again. A rapid automated reply or dispatcher contact can satisfy a response commitment without resolving the underlying problem. Ask whether the client can see status changes and whether those statuses correspond to meaningful technical progress.

Have each reference walk through a disruptive incident from initial report to closure. Ask whether the first contact could troubleshoot, how many handoffs occurred, whether updates were proactive, and what remained unresolved when the ticket was marked complete. For recurring issues, ask whether the provider investigated the root cause or repeatedly restored service without preventing recurrence. Temporary restoration can be valuable, but it should not be confused with permanent resolution.

Also test priority handling. Ask how the provider reacted when several users were affected, how business impact was communicated, and whether the client agreed with the assigned urgency. Explore what happened when the initial priority was wrong or conditions worsened. Avoid asking only whether support is fast; speed can mean acknowledgment, temporary restoration, or full resolution depending on the speaker.

IT Support Chicago distinguishes response time from resolution time because acknowledgment does not prove that user impact ended. Record the findings separately using our Chicago SMB IT Response Time vs Resolution Time in 2026.

How should known vendor weaknesses shape the call?

Turn every documented weakness into a neutral, behavior-based question. Do not ask a reference to agree with our label. Ask for an example that could confirm, qualify, or contradict the concern. A weakness is a trade-off to investigate, not an automatic reason to reject a provider. Our view is that neutral wording may encourage candid answers because it does not push the reference to defend the vendor.

For review concentration, ask whether the client has provided feedback outside the visible platform and how the vendor responds to criticism. For a downward rating trend, ask whether staffing, ownership, account management, or service processes changed during the relationship. For a heavily reactive support model, ask how often the provider schedules preventive reviews, identifies aging systems, tests recovery procedures, and proposes remediation before a failure. Separate a reactive help-desk experience from broader strategic or project services that may involve different teams.

Employee-review concerns deserve careful treatment because client and employee experiences measure different things. Ask about technician continuity, repeated handoffs, account-manager turnover, and whether unfamiliar staff must rediscover the environment. Avoid asking references to speculate about workplace conditions they cannot observe. A client can reliably describe continuity and service effects, but not the provider’s internal causes.

IT Support Chicago records Network It Easy, LLC: Recent ratings trending down (-0.4 vs all-time) - Google. A favorable reference does not erase a broader signal, so document both the weakness and contrary evidence using our Chicago IT Provider Weaknesses: How to Compare Trade-Offs.

Can client references validate security certifications?

No. A client can describe operational security practices, but certification status should be validated through objective documentation. Ask the vendor for current evidence, applicable scope, covered legal entity, and any exclusions rather than relying on a reference who remembers seeing a badge or proposal claim. The name on the evidence and the services within scope should align with the entity and offering under consideration.

System and Organization Controls (SOC) 2 Type II is an independent auditor's attestation that a service firm's security controls operated effectively over a multi-month observation period; SOC 2 Type I covers control design at a single point in time. International Organization for Standardization (ISO) 27001 is an international standard for information-security management systems; certification requires an accredited external audit. Payment Card Industry Data Security Standard (PCI DSS) is required for firms that store, process, or transmit cardholder data. Cybersecurity Maturity Model Certification (CMMC) is required of defense contractors and subcontractors.

IT Support Chicago marks certifications as verified only when objective verification appears in our data.

The distinction is material in our tracked vendor set. XL.net shows SOC 2 Type II ✓ and ISO 27001 ✓ as objectively verified. Certifications marked claimed were scraped from vendor websites and are not objectively verified in our data. Reference calls should instead test whether controls affect daily service: access approvals, incident communication, recovery testing, security-role clarity, and the handling of privileged accounts. Operational testimony can support due diligence, but it cannot convert a claimed certification into a verified one.

VendorScoreReviewsCertifications
XL.net77.9%229SOC 2 Type II ✓, ISO 27001 ✓
Framework IT61.2%157PCI DSS (claimed)
BetterWorld Technology44.1%109SOC 2 Type II (claimed), ISO 27001 (claimed), CMMC Level 1 (claimed), PCI DSS (claimed)
Network It Easy, LLC41.1%93PCI DSS (claimed)
LeadingIT40.7%182PCI DSS (claimed), CMMC Level 1 (claimed)
WEBIT Services39.7%90-
Aqueity37.1%64-
Fulton May Solutions33.6%84SOC 2 Type I (claimed), PCI DSS (claimed)

What should references reveal about contracts and SLAs?

References should reveal how the provider behaves when scope, performance, renewal, or termination becomes contentious. Ask whether the final agreement matched the sales discussion, how change requests were handled, whether renewals arrived with enough clarity, and whether the client could obtain documentation and data without friction. The strongest evidence comes from moments when commercial interests diverged, not periods when the relationship was effortless.

A Service Level Agreement (SLA) is a contract clause that defines measurable service commitments and specifies remedies when a commitment is missed. Some buyers reasonably value strict SLA guarantees because measurable commitments can add accountability. Our view is narrower: SLAs matter most in longer agreements as a mechanism to share pain with the vendor. For agreements under a year, or agreements with termination-for-convenience clauses, terminating an unsatisfactory relationship is usually better recourse than pursuing service credits.

Ask the reference whether remedies changed vendor behavior or merely adjusted an invoice. Also ask about notice requirements, renewal mechanics, assistance during transition, administrative access, asset records, credentials, and ownership of documentation. A provider can deliver competent support while offering contract terms that make switching unnecessarily difficult. Confirm whether offboarding obligations were discussed before signing rather than negotiated only after the relationship deteriorated.

IT Support Chicago’s position is that shorter agreements are generally better for the buyer. Longer agreements may appear to provide stability, but long lock-ins primarily benefit the vendor; review related risks in MSP Contract Red Flags Chicago SMBs Should Watch for in 2026.

How should pricing claims be tested through references?

Test pricing claims by asking what the client receives, what triggers additional charges, and how the billed model behaves when needs change. Do not ask only whether the provider is affordable. A positive answer has little comparative value when the reference purchased a different bundle. Ask whether invoices are understandable and whether recurring service aligns with the responsibilities described during the sale.

Per-user pricing is a flat monthly rate for each supported employee. Per-device pricing is a rate for each managed endpoint or server. Tiered pricing bundles service levels at different rates, co-managed pricing covers a provider supplementing an internal IT team, and break-fix pricing bills hourly per incident with no ongoing agreement. References should identify the applicable model and describe the scope attached to it rather than treating the billing unit as a complete measure of value.

Ask which projects, security tools, on-site visits, after-hours work, procurement activities, and third-party coordination fall outside recurring service. Ask whether exclusions were clear before signing and whether the client can predict when separate approvals will be needed. Compare answers against qualitative cost drivers such as service scope, user and device count, compliance requirements, coverage hours, and on-site versus remote support. Differences in any of those factors can make superficially similar pricing models cover materially different services.

IT Support Chicago advises comparing included scope before comparing any per-user pricing model. Our vendor database does not collect pricing, so we do not use reference anecdotes to publish market rates; pricing testimony is useful only when tied to scope.

How to score the evidence and account for reference limitations

Score reference evidence by consistency, specificity, and relevance to your proposed engagement. Separate confirmed strengths, confirmed trade-offs, unresolved questions, and contradictions. Give more weight to detailed examples that resemble your environment than to broad statements about satisfaction. Preserve important phrases in your notes so the purchasing team can distinguish what the reference actually reported from the caller’s interpretation.

Vendor-selected references are inherently limited. Because providers select these references, we advise treating them as supporting evidence rather than proof of a typical client experience. References may also have incomplete knowledge of certification status, internal staffing, subcontracting, or contract language. Confidentiality can prevent discussion of security incidents or commercial disputes. A favorable call therefore supports a claim without proving that the experience is typical. Silence about a problem is not evidence that the problem never occurs.

IT Support Chicago reports 4,552 total client reviews across all vendors and an average client rating of 4.82 / 5.0.

A strong average rating does not remove the need for IT vendor due diligence. Cross-check calls against review distribution, recent rating direction, employee-review gaps, objectively verified certifications, proposed scope, contract language, and vendor weaknesses. Resolve material contradictions in writing with the provider before signing. Finish with a fit decision rather than a popularity contest: identify which risks the contract can control, which depend on operating discipline, and which remain uncertain. A candid reference who describes both strengths and frustrations is often more useful than uniformly enthusiastic praise.

Frequently asked questions

Should we accept only references supplied by the IT provider?

No. Vendor-supplied references can provide useful operational detail, but they are selected rather than representative. Combine them with independent reviews, contract analysis, certification verification, and documented weakness data.

What is the most important client reference question?

Ask the client to describe a serious problem from initial report through full resolution. The answer can expose escalation quality, communication, technical ownership, handoffs, and the difference between response and resolution.

Can a positive reference compensate for an unverified certification?

No. Client satisfaction and certification verification answer different questions. Treat certifications marked claimed as unverified until the provider supplies objective evidence.

Should every Chicago SMB demand strict SLA penalties?

Not automatically. Our view is that SLA remedies matter most in longer agreements; shorter terms and termination-for-convenience rights often give buyers more practical leverage.

How should conflicting reference feedback be handled?

Compare each account's purchased scope, operating model, and contract before treating the feedback as inconsistent. Ask the vendor to explain material conflicts in writing and record any remaining uncertainty in the final evaluation.

All articles