Skip to content

GuidesPublished Updated 14 min read

IT Provider RFP for Chicago SMBs, 2026

two doorways, one dim and one bright, joined by a bridge
Listen to this article · 20:58 · AI-generated narration
0:00 / 20:58
Chapters

Disclosure: this site is owned and operated by XL.net, a Chicago MSP that is itself ranked here. How we handle that conflict.

What should an IT provider RFP for Chicago SMBs request?

An IT provider Request for Proposal (RFP) for Chicago small and midsize businesses (SMBs) should force every Managed Service Provider (MSP) to bid the same work: a shared scope, a stated contract term, and an inclusions list that names what sits inside the recurring fee. The packet should also request verified versus claimed certifications, local office presence, service exclusions, and termination terms. It should not treat headcount or Service Level Agreement (SLA) penalties as default filters.

We write the packet that way because the Chicago MSPs we track do not present comparable offers on their own. IT Support Chicago's own research (as of 2026-08-23) tracks 85 active vendors with an average score of 21.4%. The published range is 1.4%-78.3%, which is why a buyer who asks only for a per-user rate receives answers that cannot be lined up. Our analysis treats scope, term, and inclusions as the minimum shared frame; certifications as a dimension we already score, and local presence, exclusions, and exit language as terms the packet itself has to collect from bidders; and size plus SLA credits as optional questions, not gates. Average client rating across the set is 4.81 / 5.0, drawn from 5,299 client reviews, so star averages alone will not separate bids either.

A formal RFP is a structured packet, not a ritual. Smaller organizations can send a scoped requirements note that still names those same dimensions. Neither format replaces a reference check or a line-by-line reading of lock-in clauses, auto-renewal, and termination-for-convenience language. We advise buyers to ask each vendor to map every scope line to an include, an exclude, or an extra, and to mark every certification as verified by an auditor or merely claimed on a website, because that mapping is what makes later bid comparison honest. Limitation: our vendor database does not include pricing, so the RFP still has to collect commercial terms from bidders, and we can only help you judge those terms against score, review, and certification evidence.

TL;DR

Request a shared scope, contract term, and inclusions list so every Managed Service Provider (MSP) bid describes the same work, then require verified versus claimed certifications, local office presence, service exclusions, and termination terms. Do not treat headcount or Service Level Agreement (SLA) penalties as default filters. A formal Request for Proposal (RFP) is not required for every search-smaller organizations can send a scoped requirements note-and neither format replaces reference checks or a line-by-line reading of lock-in clauses.

  • Freeze scope, term, and inclusions before comparing any per-user bid.
  • Request verified-versus-claimed certifications, Chicago office evidence, exclusions, and exit terms.
  • Do not use headcount or SLA penalties as default knockout filters.
  • Prefer shorter agreements; treat multi-year lock-ins as a vendor-favoring concession.
  • A scoped note can replace a formal RFP; neither replaces reference checks.

Why is per-user price without shared scope misleading?

Because a per-user monthly rate without a shared inclusions list describes different products, not different prices. Our position is that per-user price without scope context is misleading. Buyers who still compare Managed Service Provider (MSP) quotes by the cheapest per-user figure, or who treat per-user cost as the most important pricing metric, are ranking unlike scopes. The opposing view-compare providers by their per-user monthly rate; the cheapest per-user price is the best value-is easy to understand and easy to test: freeze the work first, then look at the rate.

We do not collect vendor pricing, so we never publish dollar figures, ranges, or market rates. What we can describe is how pricing models work and what drives cost qualitatively. Per-user is a flat monthly rate for each supported employee. Per-device is a rate for each managed endpoint or server. Tiered bundles service levels at different rates. Co-managed means the provider supplements an internal IT team. Break-fix is hourly billing per incident with no ongoing agreement. Qualitative cost drivers include service scope, user and device count, compliance requirements, coverage hours, and on-site versus remote support. A Request for Proposal (RFP) that does not freeze those drivers will produce bids that look cheaper because they omit after-hours coverage, on-site visits, or security tooling.

Once every bidder prices the same user count, device count, coverage hours, and include/exclude list, a lower per-user figure can be discussed as a commercial difference rather than as a missing stack. Until that happens, the lower number is an incomplete description of work. Use our Chicago SMB IT scope checklist to keep those lines identical across packets. Chicago small and midsize businesses (SMBs) that skip the checklist often discover after signature that monitoring, backup testing, or on-site dispatch sat outside the quoted tier. That is a scope failure, not a bargain.

Which certifications and local-office facts belong in the packet?

Each Managed Service Provider (MSP) should list certifications as objectively verified or claimed-but-unverified, and should document a Chicago-area office, because certifications are a dimension we already track, and local presence is a term the packet itself has to collect from bidders. Do not accept a homepage logo as proof. Spell out what you need: Payment Card Industry Data Security Standard (PCI DSS) if you handle cardholder data (see our comparison of Chicago finance IT support providers); Cybersecurity Maturity Model Certification (CMMC) if you sit in a defense chain; System and Organization Controls (SOC) 2 Type II if you need a multi-month operating attestation rather than SOC 2 Type I design-only; International Organization for Standardization (ISO) 27001 if you need an accredited information-security management audit.

IT Support Chicago's own research (as of 2026-08-23) finds PCI DSS on 17 vendors and CMMC Level 1 on 16 vendors. SOC 2 Type I appears on 10 vendors, SOC 2 Type II on 6 vendors, and ISO 27001 on 6 vendors. Only objectively verified marks should be treated as held. XL.net is the verified example in our set: SOC 2 Type II ✓ and ISO 27001 ✓. Framework IT, BetterWorld Technology, LeadingIT, Network It Easy, LLC, and Andromeda Technology Solutions carry claimed marks, and we record security certifications not objectively verified where that weakness applies. Aqueity and RWK IT Services show no certifications in our data.

The Request for Proposal (RFP) should ask for the auditor letter or report date on any verified mark, and should require website-only marks to be labeled claimed. Our IT provider certification verification checklist is the companion worksheet. For local presence, ask for a street address in the Chicago metro, the functions housed there, and whether on-site work is staffed from that office or dispatched from elsewhere. A claimed Chicago listing is not the same as a service office.

Should headcount or SLA penalties be default filters?

No. Do not use staff headcount or Service Level Agreement (SLA) penalty schedules as default gates in an IT provider Request for Proposal (RFP) for Chicago small and midsize businesses (SMBs). Our position is that bigger is not inherently better and right-sizing matters more than headcount. Larger Managed Service Providers (MSPs) can look safer on paper. The argument that larger MSPs deliver superior service, that bigger firms provide better support, that buyers should choose the largest provider they can afford, or that enterprise-scale MSPs are inherently more reliable, deserves a fair hearing: scale can mean deeper benches and redundant shifts. Scale can also mean a Chicago SMB is a small account in a wide queue. Right-sizing-matching delivery model to the buyer's complexity-matters more than counting engineers.

The same caution applies to SLAs. An SLA is a contract clause that defines measurable service commitments and specifies remedies when a commitment is missed. Many advisors will say SLAs are essential for every MSP engagement, that buyers should always demand strict SLA guarantees before signing, that SLA penalties are the primary way to hold vendors accountable, and that SLA commitments are contractually enforceable in a way that adds real accountability. In our view, Service Level Agreements only matter in longer multi-year agreements as a mechanism to share pain with the vendor, and for agreements under a year or with termination-for-convenience clauses the better recourse is simply terminating the agreement. Ask for response-time and resolution-time definitions if you want operational clarity. Ask for termination-for-convenience if you want leverage. Credits inside a multi-year lock-in are a pain-sharing tool; credits inside a short agreement that you can leave are usually theater.

Weakness data in our set is a better filter than headcount. BetterWorld Technology shows a heavily reactive support model (86% reactive roles) per Apollo, and Andromeda Technology Solutions shows a heavily reactive support model (100% reactive roles) per Apollo, which is a delivery-mix fact rather than a headcount fact. If you need proactive work, ask the RFP to break out proactive versus reactive roles. If you need a large bench, ask how the account will be staffed, not how many people the company employs worldwide.

Term, termination, and lock-in language to request

Ask every bidder to put term length, auto-renewal mechanics, termination-for-convenience, offboarding assistance, and data-return duties in one table, because those clauses decide whether a bad fit is reversible. Our view is that shorter agreements are generally better for the buyer. Multi-year contracts are often sold as stability, as better for both parties, as a way to lock in a rate, and as a path to consistent service. We take that case seriously: a longer term can reduce re-procurement work and may come with a lower unit rate, yet it also concentrates risk on the buyer, and long lock-ins primarily benefit the vendor, so we advise Chicago small and midsize businesses (SMBs) to prefer shorter terms and to treat multi-year paper as a concession granted only after scope, exclusions, and exit terms are acceptable rather than as a neutral default.

The Request for Proposal (RFP) should require a yes or no on termination-for-convenience, the notice period, any early-termination fee as a formula rather than a surprise invoice, whether unused prepaid months are refundable, and whether the Managed Service Provider (MSP) will export documentation, passwords, and diagrams in a usable form. Auto-renewal should be described as opt-in or opt-out, with the notice window stated. Buyers who skip this page discover the lock-in only when they try to leave. For agreements under a year, or agreements that already allow termination-for-convenience, spending the packet on elaborate Service Level Agreement (SLA) credit math is usually the wrong emphasis; the recourse is to leave.

Honest limitation: we do not collect vendor pricing, so we cannot tell you whether a longer term actually lowers the rate you will be quoted. Evaluate the commercial trade-off against our score, review, and certification data, not against a promised discount you cannot benchmark. Read every lock-in clause line by line even after a clean RFP response; proposal language is not the signed contract. Switching costs live in the exit terms, not in the sales deck.

When a formal RFP is optional for Chicago SMBs

A formal Request for Proposal (RFP) is not required for every search. Smaller Chicago small and midsize businesses (SMBs) can send a scoped requirements note, provided it still freezes scope, term, inclusions, verified versus claimed certifications, local office presence, service exclusions, and termination terms. The format is less important than whether every Managed Service Provider (MSP) answers the same questions. A long RFP that leaves exclusions blank is weaker than a short note that maps include, exclude, and extra on every line.

IT Support Chicago's own research (as of 2026-08-23) counts 5,299 client reviews across all vendors. That volume is useful and still incomplete. Network It Easy, LLC, LeadingIT, Aqueity, and RWK IT Services show client reviews on a single platform only - Google, with Network It Easy, LLC also showing recent ratings trending down (-0.5 vs all-time) - Google, LeadingIT below-average employee reviews (3.1) - Indeed, Glassdoor, Aqueity below-average employee reviews (3.3) - Indeed, Glassdoor, and RWK IT Services below-average employee reviews (3.1) - Glassdoor. A short requirements note that never asks for multi-platform reviews and employee-review context will miss those gaps. Average client rating across vendors is 4.81 / 5.0, a compressed scale that can look uniformly strong until you split sources.

Neither a formal RFP nor a short note replaces reference checks. Ask for Chicago-metro clients of similar size and call them. The packet gets you comparable bids. The calls tell you how the account actually feels. Limitation: our data does not cover every private reference a bidder will name, and a polished written response can still hide a reactive delivery model until you ask about staffing mix.

Using our Chicago MSP scores when bids arrive

Use our scores as a pre-read on the firms that responded, not as a substitute for the scoped comparison the Request for Proposal (RFP) was built to create. IT Support Chicago's own research (as of 2026-08-23) shows an average vendor score of 21.4%. The range is 1.4%-78.3% across 85 active vendors, so a locally high score is still a relative mark inside a set whose average is low. A bigger score is not a reason to ignore scope, and a bigger headcount is not a reason to ignore score. Right-sizing and inclusions still decide fit.

XL.net leads the table we publish at 78.3% with 235 reviews and verified SOC 2 Type II and ISO 27001, a combination that is rare in our set and still not an automatic award if the bid excludes on-site coverage the buyer needs. Framework IT at 62.5% and BetterWorld Technology at 44.5% show how claimed certifications can sit on otherwise substantial review counts (158 and 113). Andromeda Technology Solutions at 39.2% with 70 reviews carries CMMC Level 1 (claimed) plus a heavily reactive support model (100% reactive roles) - Apollo, which is a delivery-model trade-off a bid cover letter will not volunteer. Read weaknesses alongside the RFP matrix rather than treating the ranking as a shortlist you cannot leave.

Limitation: we do not collect vendor pricing, so a high score cannot tell you whether a quote is expensive or thin. Compare the commercial page against the shared scope, then use score, reviews, and verified certifications as quality context. Claimed marks stay claimed until an auditor packet arrives. Single-platform Google review sets stay single-platform until another source appears.

VendorScoreReviewsCertifications
XL.net78.3%235SOC 2 Type II ✓, ISO 27001 ✓
Framework IT62.5%158PCI DSS (claimed)
BetterWorld Technology44.5%113SOC 2 Type II (claimed), ISO 27001 (claimed), CMMC Level 1 (claimed), PCI DSS (claimed)
Network It Easy, LLC42.4%94PCI DSS (claimed)
LeadingIT41.5%183PCI DSS (claimed), CMMC Level 1 (claimed), SOC 2 Type I (claimed), ISO 27001 (claimed)
Aqueity40.2%63-
Andromeda Technology Solutions39.2%70CMMC Level 1 (claimed)
RWK IT Services37.5%103-

Caveats: what the packet does not replace

A clean Request for Proposal (RFP) still does not replace a line-by-line reading of the contract, a reference check, or an exclusions review. Our analysis treats service exclusions as a first-class bid field rather than a footnote. Managed Service Providers (MSPs) often win on a tidy per-user page and then carve out backup testing, after-hours dispatch, project work, or on-site response in a schedule the buyer skims. Use our Chicago IT service exclusions guide when you mark each scope line include, exclude, or extra. If the exclusions page is blank, the bid is not complete.

We also cannot see inside every delivery model from public data alone. Heavily reactive support, single-platform reviews, and claimed-but-unverified certifications are the weakness patterns that show up often enough in our set to earn their own RFP questions. They are not automatic disqualifiers. A reactive mix may fit a break-fix-leaning shop; it is a poor fit for a buyer who asked for proactive maintenance. A claimed Payment Card Industry Data Security Standard (PCI DSS) mark may be in process; it is not the same as a held mark. State the difference in the scoring sheet you will use when bids are compared.

Finally, the 2026-08-23 snapshot of 85 active vendors we track is not a warranty that a specific bid team will perform for a given Chicago small and midsize business (SMB), and scores plus reviews will age after the packet goes out. The RFP's job is to make the offers comparable on scope, term, and inclusions so that per-user prices are never compared without that context. After that, the buyer still has to read, call, and walk the office. We would rather under-claim what a packet can do than imply that paperwork selects the provider.

Frequently asked questions

Do we need a formal IT provider RFP for a Chicago SMB search?

No. A formal Request for Proposal (RFP) is not required for every search; smaller organizations can send a scoped requirements note that still freezes scope, term, and inclusions. Neither format replaces reference checks or a line-by-line reading of lock-in clauses.

Can we rank MSP bids by per-user monthly price?

Not until every bidder prices the same scope, term, and inclusions. We advise against comparing raw per-user figures when tiers omit coverage hours, on-site work, or security tooling, and we do not collect vendor pricing to benchmark rates.

Should we disqualify vendors that refuse strict SLA penalties?

Not by default. In our view, Service Level Agreements (SLAs) only matter in longer multi-year agreements as a mechanism to share pain with the vendor, and for agreements under a year or with termination-for-convenience the better recourse is simply terminating the agreement.

How should claimed certifications be treated against verified ones?

Treat objectively verified marks as held and website-only marks as claimed-but-unverified. Among the Chicago Managed Service Providers (MSPs) we track as of 2026-08-23, PCI DSS appears on 17 vendors and SOC 2 Type II on 6 vendors, and several of the higher-review firms in our table carry claimed rather than verified marks.

Is the highest-scoring MSP automatically the right fit?

No. Right-sizing matters more than headcount, and a high score does not fill a scope gap. Use scores and reviews as context after bids share the same inclusions list.

All articles