Skip to content

Methodology

Ownership and material connection

IT Support Chicago is owned and operated by XL.net, a Chicago-area managed IT services provider. XL.net is itself one of the firms evaluated and ranked on this site.

We think you should know that before you read a single score. It is a real conflict of interest, and no amount of methodology removes it. What we can tell you is how we constrain it: XL.net is scored by the same published criteria as every other firm, from the same public sources (client and employee reviews, verified certifications), with no manual adjustment and no paid placement available to anyone — including XL.net.

Our scoring is public and reproducible: read the methodology and check our numbers against the sources yourself. If you would rather take a ranking from someone with no stake in the outcome, that is a reasonable thing to want, and we would rather you knew.

Our public ranking uses 4 criteria scored from public data. Nothing a vendor tells us privately affects the public score. One thing a vendor publishes about itself can, on the security criterion: certifications it lists count as claims, capped at 25/100, unless a certification is third-party documented — a named third-party issuer’s document behind an evidence link, evidence published on a third-party website, or a public registry entry. That test is applied automatically, per certification; no editorial step is part of the definition. Every formula is documented here, and each certification on a provider page is labelled with what stands behind it.

Which Firms Are Included

This list includes all IT managed service providers with offices within 100 miles of downtown Chicago that have at least 25 aggregate reviews across our tracked platforms (Google Business, Clutch, Cloudtango, The Manifest, Glassdoor, Indeed, and others). Geographic proximity is an inclusion filter, not a scored criterion — every firm on the list already serves the Chicago area. Firms are discovered automatically from public directory listings and verified for geographic eligibility. If your firm meets these criteria and is not listed, you can submit your data to be included.

The 4 Public Criteria

The public ranking scores every firm on 4 objectively verifiable criteria. Weights sum to 100 and reflect the relative importance of each factor for a typical Chicago SMB.

Client Reputation

reputation_client

29

Employee Reputation

employer

20

Proactive Issue Reduction

issue_reduction

27

Security Certification

security

24

Reputation Formula

Each vendor is scored objectively across client reviews and employer reviews using a Bayesian model. The two pools use tuned parameters so that employer reviews (which cluster lower industry-wide) are scored on a fair scale.

effective_reviews = Σ(count × credibility_weight)
  credibility_weight is per source; Clutch is auto-set to 1.25 × the
  vendor's best other source weight (1.0 if Clutch is the only source).
  group_mean_effective and the group mean rating are computed with the
  same per-vendor weights; recent-12mo counts are unweighted.
weighted_rating   = Σ(rating × count × weight) / effective_reviews
bayes_rating      = (effective × weighted_rating + C × m) / (effective + C)
  C = prior strength (per pool)
  m = group mean rating − skeptic margin (per pool)
floor             = group_mean_rating − 1.0 (dynamic, per pool)

If bayes_rating < floor (below-floor age decay):
  age_ratio       = recent_12mo_count / total_review_count
  gap             = floor − bayes_rating
  effective_gap   = gap × (0.5 + 0.5 × age_ratio)
  effective_bayes = floor − effective_gap
Else:
  effective_bayes = bayes_rating

rating_quality    = clamp((effective_bayes − floor) / (5.0 − floor), 0, 1)
rating_factor     = rating_quality ^ exponent

Client pool:
  volume_factor   = effective_reviews / group_mean_effective
  recency_factor  = max(0.5, recent_12mo / group_mean_recent_12mo)

Employer pool (threshold-based, saturates at full credit):
  volume_factor   = min(1, effective_reviews / volume_threshold)
  recency_factor  = max(0.5, min(1, recent_12mo / recency_threshold))

attainment        = rating_factor × min(cap, volume × recency) × 100

Pool-specific parameters:

ParameterClientEmployer
Prior strength (C)103
Skeptic margin0.250.15
Exponent1.51.0
Volume modelratio to meanthreshold (10)
Recency modelratio to meanthreshold (2)
Volume × recency cap1.01.0
Recency floor0.50.5

The floor is computed dynamically from each pool's group mean rating, not hardcoded. Employer reviews on Glassdoor/Indeed typically average lower than client reviews on Clutch/Google, so each pool gets a floor calibrated to its own data. When a vendor's Bayesian rating falls below the floor, old reviews carry less negative weight than recent ones — a firm that improved recently is not punished as heavily for historical scores.

A recency floor of 0.5 ensures that vendors are never fully penalized when per-review date breakdowns are unavailable. Not all review platforms expose individual timestamps — for example, the Google Places API returns only a small sample of reviews with dates. We estimate Google review recency by sampling up to five reviews per location and extrapolating the recent proportion to the full review count. Vendors with no recency data at all still receive at least half credit for the recency factor rather than being zeroed out.

Security Scoring

Security is scored per certification. A certification earns its tier value when it is third-party documented; everything else the firm says about itself scores as a claim, capped at 25/100. The same per-certification test decides the score, the badge and the tooltip, so they cannot disagree.

A certification is VERIFIED when any of these holds:
  (a) it names a third-party issuer and carries an evidence link
      (the document may sit on the firm's own domain — an auditor's
      report excerpt hosted by the firm is still the auditor's), or
  (b) its evidence link is hosted on a third-party website — the
      link's registrable domain differs from the firm's own, or
  (c) it comes from a public certification registry.
An operator ruling recorded for a firm overrides the test in
either direction.

Certifications passing the test score by tier:
  Top-tier (50 pts each):
    CMMC L3, ISO 27001, HITRUST, SOC 2 Type II, FedRAMP, CMMC L2+
  Lower-tier (25 pts each):
    CMMC L1, SOC 2 Type I, PCI-DSS
Everything else — certifications failing the test, plus loose
marketing claims — adds 5 pts, capped at 25 total:
  score = min(100, tier_sum + min(25, 5 × claim_count))

A firm listing “SOC 2” on a marketing page does not qualify — a scraped name carries no document. A feed entry with an evidence link on the firm’s own domain and no third-party issuer named does not qualify either: we show it as vendor-claimed with evidence so you can read the link yourself, and it scores as a claim.

Two honest caveats, stated because this page is the one that claims to publish every formula. First, the test checks that documentation is third-party in form— it does not authenticate the third party. A firm could name a fabricated issuer in its own feed, or host a document on any third-party site, and pass; publishing false data is grounds for removal from the rankings, and an operator ruling can strip a firm’s verification either way. Second, “registrable domain” is computed from a common-suffix approximation rather than the full Public Suffix List; the rare miss treats two hosts as distinct, which errs toward qualifying.

Proactive Scoring

We analyze each vendor’s workforce composition to measure how proactively they invest in preventing IT issues vs. reacting to them. Employee job titles are fetched from Apollo.io and classified by a keyword classifier — published in full below — into three buckets:

  • Proactive — architects, security engineers, vCIOs, compliance specialists, penetration testers, automation engineers, etc.
  • Reactive — help desk, service desk, NOC analysts, desktop support, field technicians, support engineers, etc.
  • Neutral (excluded) — leadership, sales, HR, accounting, software development, and other non-IT-operations roles.
reactive_share = reactive / (reactive + proactive)
attainment     = (1 − reactive_share) × 100

The floor is 3 distinct reactive job titles— not 3 reactive employees. The classifier runs over the de-duplicated set of title strings a firm’s staff hold, so twenty people who all report as “Help Desk Technician” count once. That distinction cuts both ways: a 32-person firm whose support bench reports two title strings falls below the floor, while a 6-person firm with three distinct ones clears it. Below the floor the ratio is noise — one misfiled title would move it by a third — so the firm is treated as unmeasured and takes the pessimistic floor described under Missing Data Policy below. It is a floor on what we are willing to score, not a judgement about the firm.

View the full title classifier — all six lists, in the order they are applied

These six lists are the entire classifier — there is no seventh list, and no editorial step. They are applied in the order printed here and the first match wins: a title is tested against list 1, then list 2, and so on, and the first list that matches decides the verdict outright — nothing below it is consulted. Matching is case-insensitive substring containment (“Chief Technology Officer” contains “chief ”), except for list 5, which is compared against the whole title. A title that matches nothing in any of the six is left unclassified, which for scoring is the same as neutral: it counts toward neither side of the ratio above. Entries are printed separated by · rather than by commas, because two entries contain a comma of their own; a space or a comma at the end of an entry is part of the rule, and every entry that carries one is called out below.

1. Always proactive — checked first (6)

Genuinely proactive titles that happen to contain a leadership word and would otherwise be caught by list 2. A vCIO contains “cio”; “Manager, Project Engineering” contains “manager”. Being checked first is the whole purpose of this list — every entry also appears in list 3, so it changes no verdict except by outranking list 2.

vcio · virtual cio · virtual chief information · manager, project engineering · digital transformation executive · fractional cio

2. Leadership — counted as neutral (22)

Seniority is not evidence of a proactive service model, so directors, VPs, the C-suite, owners, partners, managers and supervisors are set aside and counted neither for nor against a firm. This is the rule that makes “Chief Technology Officer” neutral even though “technology officer” sits in list 3 below — list 2 is reached first. It applies to every firm on this site equally, including the one that operates it. Three entries here carry punctuation that is easy to lose in print but is part of the rule: “vp ” and “chief ” each end in a space and “vp,” ends in a comma, so they catch “VP of Technology” and “VP, Information Security” without also catching “VPN Engineer”.

director · vice president · vp · vp, · evp · manager · president · founder · co-founder · owner · chief · ceo · coo · cfo · cto · ciso · cio · partner · principal · team lead · engineering lead · supervisor

3. Proactive (53)

Non-leadership roles that exist to stop tickets being filed: architects, security engineers, vCIOs, compliance and audit specialists, penetration testers, automation engineers.

vcio · virtual cio · virtual chief information · security engineer · security architect · cybersecurity · information security · cloud architect · cloud security engineer · solution architect · solutions architect · site reliability · sre · automation engineer · automation specialist · disaster recovery · enterprise architect · technical architect · it consultant · technical alignment engineer · engineer resident · business system architect · compliance auditor · compliance specialist · exploitation analyst · penetration test · patch management · security and grc · system analyst · systems analyst · senior systems analyst · tier 3 network architect · project engineer · project lead · project specialist · project administrator · project lead engineer · ai and cloud solution · technical project resource · technology officer · information assurance · it auditor · senior it auditor · staff it auditor · information technology auditor · technology and risk assess · internal audit consultant · cloud architecture · splunk cloud engineer · test automation engineer · manager, project engineering · digital transformation executive · fractional cio

4. Reactive (113)

Non-leadership roles that exist to close tickets that were filed: help desk, service desk, NOC and SOC analysts, desktop support, field technicians.

help desk · helpdesk · service desk · desktop support · desktop technician · support technician · it support specialist · it support analyst · field technician · field service · onsite technician · dispatch · dispatcher · tier 1 · tier i · level 1 · level i · tier 2 · tier ii · level 2 · level ii · break-fix · break fix · support specialist · support analyst · support representative · technical support · client support · support coordinator · noc engineer · noc analyst · noc technician · noc lead · noc level · network operations center · network operations analyst · monitoring · managed security analyst · system engineer · systems engineer · computer technician · head of customer support · support services technician · sr. technician · sr technician · senior technician · l2 it technician · l1 it technician · associate engineer · support lead · data center support · soc analyst · soc specialist · security operations center · it technician · it support · onsite support · support engineer · network specialist · security specialist · application analyst · collaboration engineer · computer engineer · computer technical · customer engineer · data center engineer · escalation engineer · field engineer · information technology specialist · it service delivery · network analyst · wireless network analyst · noc associate · noc l3 · onsite it service delivery · onsite team lead · systems support administrator · technical delivery associate · threat hunting · threat investigation · usg analyst · voice and data technician · vulnerability remediation · cloud operations · oc analyst · customer service agent · customer service representative · customer operations · client success engineer · client service representative · network admin ii · information technology engineering specialist · technical specialist · customer service specialist · client services specialist · client service specialist · client services representative · technical lead support services · threat analyst · cyber security threat · cyber investigation · service tech · senior tech · technician · repair technician · mechanical technician · tech support · senior field support · customer service rep · customer service · técnico de asistencia · customer leader · systems support network

5. Reactive, exact whole-title match (1)

The one list compared against the complete title rather than searched for inside it. Someone whose entire title is “Tech” is doing support work — but as a substring those four letters also sit inside technology, technical and technician, so this list only ever fires when it equals the whole title.

tech

6. Neutral / excluded (253)

Real jobs that say nothing about this particular question — sales, HR, finance, software development — plus a long tail of specific titles we have actually observed and ruled on. Consulted last, so anything above it wins first.

account executive · sales · business development · bdr · sdr · marketing · content · copywriter · graphic design · human resources · hr · recruiter · recruiting · talent · finance · accounting · controller · bookkeeper · office manager · admin assistant · administrative · ceo · coo · cfo · chief executive · chief operating · chief financial · president · founder · co-founder · owner · receptionist · office coordinator · intern · software engineer · software developer · full stack · full-stack · frontend · front-end · backend · back-end · web developer · mobile developer · data scientist · machine learning · ai engineer · product manager · product owner · ux · ui · designer · qa · quality assurance · test engineer · payroll · benefits specialist · accountant · senior accountant · general counsel · legal · operations coordinator · consultant · partner · principal · chief architect · chief information officer · team lead · engineering lead · senior engineer · data engineer · senior data engineer · data analyst · database analyst · data scientist · deployment engineer · deployments specialist · infrastructure specialist · onboarding · scrum master · programmer · application packager · procurement · purchaser · renewal · business communications analyst · incident response supervisor · security analyst · solution analyst · solutions analyst · national solutions analyst · national solution analyst · advanced solutions analyst · business analyst · senior business analyst · business communications analyst · staff assistant · office administrator · office generalist · office service · admin officer · office mgr · executive assistant · secretary · front office · auditor · audit · tax · cpa · financial · investment · wealth · transaction advisory · advisor · developer · netsuite · erp · compliance assistant · contract · litigation · risk associate · proposal · public relations · social media · lead generation · market research · training & consulting · regulatory · efficiency specialist · operations specialist · educational technology · technical education · billing · collections · credit analyst · rebate · vendor lia · inventory · parts administrator · buyer · material and manufacturing · resource/parts · driver · electrical · mechanical · security guard · security professional · wireless installer · wireless site survey · home care · broker · student · self employed · operations strategist · telecom analyst · software analyst · business applications expert · administrator · senior genius · first impressions · problem solver · visionary · board member · head of strategic · industry growth · regulated industries · technology practice · global communications · member in charge · practice development · practice lead · managed services leader · cause-driven · computer software professional · masters of professional · dynamics demo · compensation specialist · total rewards · licensing operations · learning and development · senior resource specialist · senior retirement plan · senior cgxp · senior data architect · senior workday · validation analyst · platform specialist · data center advisor · delivery lead · facility security officer · ai / analytics · sikich data · trackwise · supervising senior · senior eating · distinguished transformational · senior digital marketer · administration & facilities · employee at it · ison technologies · business service ambassador · business operations administrator · regional delivery leader · it leader who · assurance · senior associate · senior analyst · corporate and individual · part-time · project management administrator · purchasing admin · technical lead threat · technical lead | national · technology · leader · engineer · senior · associate · agent · comunications analyst · comminucations analyst · sikici · sjij · tas senior · ***** · network engineer · wireless engineer · infrastructure engineer · devops · devops engineer · enterprise platform · platform engineer · solutions engineer · solutions consultant · m365 engineer · microsoft engineer · network administrator · system administrator · systems administrator · sysadmin · isg engineer · isg networking · isg - engineer automation · strategic advisor · strategic business advisor · business it consultant · digital marketing project · it solutions architect · it solutions & cybersecurity account · infrastructure administrator · for-profit auditor · technical lead network security · it engineer

Contract Terms

Contract duration, performance-based termination rights, auto-renewal terms, and price lock guarantees are evaluated directly within the Price & Contract criterion. Vendors answer structured questions about their standard contract terms, and responses are scored using the same tiered rubric system as all other inquiry-based criteria. Shorter agreements, performance exit clauses, and buyer-friendly renewal terms score higher.

Data Sources

  • Client Reviews: Google Business Profiles, Clutch.co, Cloudtango, The Manifest, MSP Companies
  • Industry Rankings: CRN MSP 500 (list presence, not review scores)
  • Employer Reviews: Glassdoor, Indeed
  • Directory & Strengths: Expertise.com, MSP Directory, MSP Database (vendor discovery and capability data, not reviews)
  • Security: Third-party certification databases, vendor feed submissions with evidence
  • Apollo.io: Employee role analysis (proactive vs reactive title share)
  • Vendor Feed: Voluntary structured data from vendors (spec)

Data is refreshed periodically. See individual vendor pages for “last updated” timestamps.

Corrections

We publish corrections here, dated, with the old and new wording. When an article’s substance changes, its “Updated” date moves too.

2026-08-31 — how our certification marks are described

Articles on this site have described a check mark as a certification that was “objectively verified in our research”, and a “claimed” mark as one “scraped from the vendor’s website”. Neither describes how the mark is actually decided, and the first asserts a piece of research we did not do.

What the marks mean is set out under Security Scoring above: a check mark records that we hold third-party documentation for that entry; “claimed” records that we do not.

The part a reader should weigh most. A firm can only reach the check mark through documentation we hold, and today exactly one firm — XL.net, which owns this publication — submits a certification feed to us. Every other firm’s certification data is read from its own website, which our rule does not accept as third-party documentation. No firm has ever been invited to submit a feed.So a “claimed” mark on another firm says what we hold about it — not what that firm can prove, and not that we asked. XL.net’s own two certifications are documented by named third parties (IS Partners, LLC for SOC 2 Type II; DNV Business Assurance for ISO 27001).

What is not yet corrected.The phrase “objectively verified” still appears in article text across most of the archive, and some articles still describe named competitors in those terms. Correcting that wording across the archive is under review and is not finished. No score, rank or mark changed as part of this correction.

Missing Data Policy

When we cannot verify a criterion from public sources, that cell shows “—” on the rankings table. For scoring purposes, unmeasured criteria receive the lowest score observed among vendors where we could measure that criterion. This pessimistic approach ensures vendors are not rewarded for opacity.

Vendors can move their own security score by submitting certification evidence through our vendor feed — it is checked automatically, per certification, against the test above.

Editorial Beliefs

We hold a set of editorial positions that all content on this site — whether written by a human or generated by AI — is checked against. These beliefs reflect our experience advising IT buyers and are published here for full transparency.

SLA-001: SLAs & Contract Terms
SLAs only matter in longer agreements (multi-year) as a mechanism to share pain with the vendor. For agreements under a year, or agreements with termination-for-convenience clauses, the better recourse is simply terminating the agreement. Content should not present SLAs as universally critical or essential.
SIZE-001: MSP Size
Bigger is not inherently better. Right-sizing matters more than headcount. Content should not imply that larger MSPs deliver superior service by default.
PRICE-001: Price Comparison
Per-user price without scope context is misleading. Content should never compare raw per-user prices without discussing what is included in each tier.
CONTRACT-001: Contract Length
Shorter agreements are generally better for the buyer. Long lock-ins primarily benefit the vendor. Content should not present multi-year contracts as a neutral or positive default.

Interactive Preview

Drag the sliders to see how changing weights affects the ranking. This uses real vendor scores — no account required.

Client Reviews29
Employer Reputation20
Issue Reduction23
Security28
Total: 100/100
1XL.net
79.4%
2Framework IT
61.3%
3Network It Easy, LLC
45.3%
4BetterWorld Technology
43.2%
5LeadingIT
42.3%

Like what you see? Sign in to save a custom evaluation with all 10 criteria weighted for your business.

Are you an IT firm in the Chicago area?

Submit a data feed from your domain to improve listing accuracy. Your file provides pointers to help us verify your information.

Submit your data

Custom Evaluations: 6 Additional Criteria

The public ranking intentionally excludes criteria that depend on your specific business requirements. When you sign in with your work email, you unlock 6 additional criteria:

  • Support Coverage and Responsiveness — scored from IT firm responses to contextual inquiry questions tailored to your support needs
  • Compliance and Regulatory Fit — scored from IT firm responses to questions specific to your compliance requirements (HIPAA, PCI, SOX, etc.)
  • Geographic / Onsite Fit — proximity and on-site capability (auto-scored from Google Places data)
  • Price & Contract — scored from IT firm responses to pricing, contract duration, exit flexibility, and auto-renewal questions adapted to your IT model and company size
  • Service-Scope Match — scored from IT firm responses to questions about service breadth matched to your needs
  • Similar Size Fit — MSP size vs. your company size (auto-scored from Apollo workforce data)

Geographic and Similar Size Fit are auto-scored from third-party data.Support Coverage and Price & Contract are included in every evaluation and use a contextual question enginethat generates questions tailored to your company profile. Two additional criteria — Compliance and Service-Scope — can be added optionally. All inquiry-based criteria are scored from a firm’s own answers to those questions — an answer we record, not a capability we verified — and only where a firm has answered.

Inquiry-Based Criteria

Several criteria are scored from direct IT firm responsesto structured questions. This includes the four contextual criteria above (Support, Compliance, Price & Contract, Service-Scope) plus additional specialized criteria you can add to your evaluation.

When your evaluation includes inquiry-based criteria, the platform sends a unified outreach email to top-ranked vendors on your behalf. The email reveals only your industry, company size, and city — never your identity. IT firms click a magic link to authenticate and submit structured answers through a vendor response portal. Answers are scored against the published rubric for that criterion and appear in your evaluation for you to read.

For the four contextual criteria, the questions are dynamically tailored to your company profile. For example, if you selected HIPAA compliance, the Compliance criterion will include specific HIPAA questions (BAA signing, risk assessments, PHI handling). If you use a co-managed IT model, pricing and scope questions adapt to ask about co-managed rates and shared responsibilities.

What we hold today. These questions belong to the signed-in evaluation tool, not to the public ranking. No answer a firm has given us has ever changed a published score, and no score published on this site is derived from one. Firms answer rarely: most inquiry criteria have never been answered by anyone.

You can also add custom criteria with your own questions using a multi-question builder. Define answer types (free text, numbers, yes/no, select, multi-select) and optionally set conditions based on your company profile.

All inquiry-based criteria are visually distinguished with a blue “Inquiry-based” label. IT firms' answers are persisted and pre-filled on subsequent evaluations, reducing response burden.

Hard Requirements

Beyond weighting criteria, you can set hard requirementsthat act as non-negotiable filters. Any IT firm that fails a requirement is disqualified from your shortlist entirely — the requirement is not factored into scoring, it is a binary pass/fail gate.

Available requirement types vary by criterion. For data-backed criteria like Client Reputation, you can set minimum attainment scores, minimum average ratings, or minimum review counts. For Security, you can require specific certifications (ISO 27001, SOC 2, etc.). For Similar Size Fit, you can set minimum and maximum employee counts. For inquiry-based criteria, you can set structured requirements derived from the criterion's answer fields (e.g. “Must offer 24/7 support”) or free-text requirements evaluated by AI.

When hard requirements reduce the qualified pool below 5 IT firms, the system presents relaxation suggestionsranked by impact — showing which single requirement removal would add the most vendors. You can relax requirements inline without restarting your evaluation.

For inquiry-based requirements, enforcement is retroactive. Vendors appear as “pending” until they respond. Once a response arrives, the system checks it against your requirements and disqualifies vendors that fail. You can always view disqualified vendors and their failure reasons in the results section.