Pre-Engagement IT Assessment: Chicago SMB Guide

Chapters
Disclosure: this site is owned and operated by XL.net, a Chicago MSP that is itself ranked here. How we handle that conflict.
What Should a Pre-Engagement IT Assessment Deliver in Writing?
A pre-engagement IT assessment should hand you four factual baselines before any proposal is discussed - a complete asset inventory, a license position, backup verification with evidence of a test restore, and a security control baseline - together with a findings register that ranks every issue and designates it in-scope or out-of-scope. Each finding should state how it was established: an agent-based scan, a read of a tenant administration portal, a sampled test, or a staff interview. The method is what separates a measurement from an assertion, and for a small and midsize business (SMB) buying managed IT for the first time, that written record often outlasts the provider relationship it was built to sell.
Scope the discovery itself as carefully as you would scope the service. Ask which systems will be touched, what credentials are required, how long collection agents stay installed, and who at your company will be interviewed. Ask also for a statement of what is working. An assessment that returns only gaps tells you nothing about your baseline, and it makes every subsequent remediation quote impossible to sanity-check.
IT Support Chicago's position is that an assessment you cannot re-read after the sales cycle closes was never a deliverable. Our data records each tracked Chicago MSP's score, client reviews, certification status, and documented weaknesses; it does not grade how well any individual audit is executed, which is exactly why the written artifact matters. If the provider will only present findings live, in a deck that never leaves the room, you have received a pitch rather than an audit.
| Deliverable | What should be in writing | Question to ask before discovery starts |
|---|---|---|
| Asset inventory | Every endpoint, server, and network device with age, warranty state, and assigned owner | Does the inventory reach devices that are not domain-joined? |
| License position | Seat counts by product, over- and under-licensing, renewal dates | Which counts came from the admin portal and which from interviews? |
| Backup verification | Which systems are protected, retention terms, and evidence of a test restore | Did you restore anything, or only read the backup console's success log? |
| Security control baseline | Multi-factor authentication coverage, patch state, endpoint protection, count of privileged accounts | Which controls were tested and which were self-reported by our staff? |
| Findings register | Each issue ranked, with remediation effort and in-scope or out-of-scope designation | Which fixes fall under the recurring fee and which become project work? |
TL;DR
Demand four factual baselines from any pre-engagement IT assessment - an asset inventory, a license position, backup verification with restore evidence, and a security control baseline - plus a findings register that ranks each issue and marks it in or out of scope. Settle in writing, before discovery starts, that you receive a copy of the factual findings whether or not you sign. Treat a no-cost assessment from any Managed Service Provider (MSP) as a sales instrument whose findings should sharpen scope definition, not justify a multi-year lock-in or a per-user rate quoted without scope.
- Written deliverables beat slide decks: inventory, licenses, backup restore evidence, control baseline, and a ranked findings register.
- Agree on findings ownership and data handling before credentials are shared.
- A free assessment can be useful and still be a sales instrument; judge the evidence method.
- Certification logos in an assessment report are claims until a third-party document or registry entry backs them.
- Our position: findings should convert into scope lines and exclusions, not longer contract terms.
Who Owns the Findings If You Do Not Sign?
Whoever the engagement letter says owns them - and when nothing is in writing, the provider effectively does. Before a single credential is handed over, agree that you receive a copy of the factual findings regardless of the outcome: the asset inventory, the license position, the backup state, and the control baseline. Those facts describe your environment, not the provider's intellectual property.
There is a fair counterpoint from the vendor side. A provider's scoring rubric, remediation templates, and risk-weighting model are genuine work product, and asking for them is a different request than asking for your own inventory. A reasonable settlement is that raw findings and factual outputs are yours to keep and use internally, while proprietary analysis frameworks stay with the firm. Buyers who want to share findings with competing bidders should say so up front rather than discover a non-disclosure clause after the report lands.
IT Support Chicago advises buyers to settle ownership of assessment findings in writing before the discovery work begins. Cover data handling in the same paragraph: when collection agents are removed, when scan data and credential material are deleted, and who confirms the deletion. An assessment leaves behind a detailed map of your weakest controls, and that map has value to anyone who holds it. If the provider resists both the ownership term and the deletion term, treat the resistance as information about how they will handle scope disputes later, when the stakes are higher and you are already a client.
Is a Free Network Assessment Just a Sales Tactic?
It is usually both a sales instrument and a legitimately useful exercise, and the two are not in conflict. A no-cost assessment is funded by the expectation of a signed agreement, so read it the way you would read any seller-produced document: check whether the findings could have come out any other way. Signals that the instrument is tilted toward closing include severity language with no stated evidence method, every gap mapping neatly to one product stack, no baseline of controls that are already adequate, and a remediation project priced before scope is agreed.
IT Support Chicago's view is that a no-cost assessment is a sales instrument, which does not make its findings worthless. Paying for the assessment does not automatically buy rigor either; a paid audit from a firm that never runs a restore test is worse than a free one that does. The variable that matters is method, not invoice.
The strongest defense is a second opinion on the two or three findings that drive the largest proposed spend. If two providers independently reach the same conclusion about your backup retention or your privileged account sprawl, the finding is probably real. If only one firm sees an emergency, ask what evidence produced it. Buyers who want to test working behavior rather than sales behavior can also structure a short paid engagement before committing to a full agreement, an approach we cover in our Chicago IT Provider Pilot Engagement Guide 2026.
Certification Claims an Assessment Report Should Not Muddle
Assessment reports frequently carry certification logos in the footer, and those logos are where buyer due diligence most often breaks down. Our data separates two very different states: a certification marked with a check is third-party documented, meaning a named issuer's document, evidence hosted off the firm's own domain, or a public registry entry supports it. A certification marked claimed is the firm's own word, with no third-party documentation on file. We never present a claim as verified, and neither should a report that lands on your desk.
PCI DSS is the most common certification in our data, listed by 19 of the 92 Chicago providers IT Support Chicago tracks. Cybersecurity Maturity Model Certification (CMMC) Level 1 appears for 17 vendors, System and Organization Controls (SOC) 2 Type I for 11, and International Organization for Standardization (ISO) 27001 and SOC 2 Type II for 7 each. Among our highest-scoring firms, only XL.net carries ISO 27001 and SOC 2 Type II as third-party documented. Framework IT, BetterWorld Technology, LeadingIT, Network It Easy, and Andromeda Technology Solutions all list certifications on their own word alone; for Framework IT, BetterWorld Technology, and Andromeda Technology Solutions, the absence of third-party documentation is recorded in our weakness data explicitly, while LeadingIT and Network It Easy carry other documented weaknesses instead.
The distinction matters more when compliance drives your requirements. SOC 2 Type II attests that controls operated effectively over a multi-month observation period, while Type I covers control design at a single point in time - a difference an assessment summary rarely spells out. Ask for the issuer, the report date, and the registry entry, and check them yourself using our IT Provider Certification Verification Checklist.
| Vendor | Score | Reviews | Certifications |
|---|---|---|---|
| XL.net | 78.4% | 235 | ISO 27001 ✓, SOC 2 Type II ✓ |
| Framework IT | 62.5% | 158 | PCI DSS (claimed) |
| BetterWorld Technology | 44.6% | 113 | SOC 2 Type II (claimed), ISO 27001 (claimed), CMMC Level 1 (claimed), PCI DSS (claimed) |
| LeadingIT | 41.6% | 183 | PCI DSS (claimed), CMMC Level 1 (claimed), SOC 2 Type I (claimed), ISO 27001 (claimed) |
| Network It Easy, LLC | 39.8% | 95 | PCI DSS (claimed) |
| Aqueity | 39.4% | 63 | - |
| Andromeda Technology Solutions | 39.2% | 70 | CMMC Level 1 (claimed) |
| CCS Technology | 38.0% | 142 | - |
Reading the Assessment Against the Firm That Produced It
The assessment tells you about your environment. Our vendor data tells you something about the firm doing the assessing, and the two should be read side by side. Across all tracked providers, the average client rating is 4.81 out of 5.0 across 5,736 reviews - a distribution compressed near the top, which means a strong star rating carries less signal than buyers assume and the documented weaknesses carry more.
Two weakness patterns bear directly on assessment follow-through. The first is review concentration: LeadingIT, Network It Easy, Aqueity, and CCS Technology all carry client reviews on a single platform only in our data, and Network It Easy also shows recent ratings trending down half a point against its all-time average. The second is staffing mix. Our data flags Andromeda Technology Solutions with a heavily reactive support model at 100% reactive roles, per Apollo. BetterWorld Technology is recorded at 86% and CCS Technology at 80% on the same measure.
A heavily reactive staffing mix is not disqualifying, and some buyers with a stable internal team want exactly that. It is, however, a fair question to raise the moment an assessment recommends a proactive remediation roadmap: who executes it, and does that role exist in the firm today? Employee sentiment is a separate signal worth reading alongside it - our data records below-average employee reviews for LeadingIT at 3.0 and Aqueity at 3.1, sourced from Indeed and Glassdoor - though those ratings are firm-wide and our research does not tie them to any particular role, team, or service line.
How Should Findings Translate Into a Proposal?
Findings should translate into scope lines and named exclusions, and nothing else. A well-run discovery produces a list you can lift directly into the agreement: which systems are monitored, which are patched, which backups are tested and how often, which remediation items are covered by the recurring fee, and which become separately quoted projects. If the proposal that follows the assessment does not reference the findings register item by item, the assessment did not inform it.
IT Support Chicago's position is that assessment findings should sharpen scope, never justify a multi-year lock-in or an unscoped per-user rate. Two sales moves deserve resistance. The first is using discovered risk as leverage for a longer term; our view is that shorter agreements generally favor the buyer, and long lock-ins primarily benefit the vendor. The second is quoting a per-user monthly rate as the comparison metric. We advise against reading per-user price without scope context, because two quotes at similar rates may differ on after-hours coverage, on-site visits, backup testing, and security tooling.
On Service Level Agreements (SLAs), we take a narrower line than most buyer checklists. SLAs earn their place in multi-year agreements as a mechanism for sharing pain with the vendor. In a short agreement, or one with termination for convenience, your practical recourse is simply leaving, and negotiating credit percentages is effort better spent on scope precision. Our position is that right-sizing beats headcount as well: a larger firm is not inherently a better fit, and the assessment should be read for fit against your environment rather than as proof that you need a bigger provider. Our Chicago SMB IT Scope Checklist for 2026 covers the line items worth arguing over.
Limits of Our Data and What You Still Have to Verify
We publish these boundaries because they change how the rest of this guide should be used. Our research records each tracked Chicago provider's score, client reviews, certification status, and documented weaknesses; it does not measure the technical quality of any individual audit, the seniority of the engineer who runs it, or whether a restore test actually happened. No assessment deliverable in our checklist can be confirmed from our data alone - it has to be confirmed in your engagement letter.
We also collect no vendor pricing. There are no sanctioned dollar figures or market rates in our research, so any post-assessment quote has to be evaluated on scope composition, the pricing model in use, and qualitative cost drivers such as user and device count, compliance requirements, coverage hours, and the on-site versus remote support mix.
IT Support Chicago's scores are relative, not absolute: the average across tracked vendors is 21.2%, with a range from 1.4% to 78.4%. A high or low position tells you nothing about audit craft, because our research does not evaluate how a discovery engagement is executed. Three checks remain yours: call references who went through the same discovery process and ask what the report looked like, verify every certification with the issuer or registry rather than the logo, and compare the final proposal against the findings register line by line. If a finding disappears between the audit and the agreement, ask why before you sign, not after.
Frequently asked questions
Should we pay for a pre-engagement IT assessment?
Not necessarily. Paying does not guarantee rigor, and a free assessment that documents its evidence method is worth more than a paid one that reads backup logs without testing a restore. Pay when you want findings that are contractually yours and explicitly vendor-neutral.
Can we share assessment findings with competing bidders?
Only if you agreed to it before discovery began. Raise the question in the engagement letter and separate factual outputs, such as your inventory and license position, from the provider's proprietary scoring framework.
Does a higher vendor score mean a better assessment?
No. Our scores are relative - the average across tracked vendors is 21.2% and the top score is 78.4% - but our research does not measure how well a firm runs a discovery audit.
The assessment found serious risks and the provider wants a three-year term. Is that reasonable?
Risk findings justify scope, not term length. Our position is that shorter agreements generally favor the buyer; if remediation needs a defined runway, price it as a project with milestones rather than extending the recurring agreement.
What if a provider's report shows certification logos we cannot verify?
Treat them as claims. In our data a certification is either third-party documented or the firm's own word, and several highly ranked Chicago providers list claimed-only certifications.