Choosing an IT support provider should be an evidence decision, not a comparison of plan names. Ten gates can reveal whether the proposed service fits the business, protects privileged paths, produces useful evidence, remains supportable, and can be exited cleanly.
Publication boundary: This article provides general educational and operational guidance. Publishing it does not mean ITECS or any specialist approved a reader’s organization-specific implementation, measured its results, made a legal or compliance determination, or verified a vendor’s configured capability.
Current as of 2026-08-15
NIST SP 1305 helps organizations define supplier requirements according to criticality. NIST Cybersecurity Framework 2.0 supplies risk outcomes that can be allocated between customer and provider without transferring accountability.
Decision summary
- Gates one through three: business fit, scope, and responsibility.
- Gates four through six: people, support behavior, and security.
- Gates seven and eight: suppliers, continuity, and measurement.
- Gates nine and ten: lifecycle economics and exit.
Gates one through three: fit and ownership
- Map critical business services, users, locations, information, applications, dependencies, and recovery needs.
- Normalize exact coverage, hours, work types, tools, licenses, projects, onsite service, and exclusions.
- Assign every decision and task to customer, provider, product vendor, carrier, facility, or joint ownership.
Gates four through six: delivery and security
- Verify named roles, staffing, qualifications, availability, escalation, supervision, and continuity.
- Define intake, severity, response, updates, escalation, closure, customer testing, and acceptance.
- Inspect privileged access, technician devices, remote tools, strong authentication, least privilege, logs, information handling, and incident notification.
Gates seven and eight: resilience and evidence
- Review subcontractors, critical products, provider dependencies, continuity, customer access during provider disruption, and tested recovery.
- Require metric definitions, source systems, samples, restoration results, change evidence, exceptions, corrective actions, and business context.
Gates nine and ten: economics and exit
- Compare onboarding, remediation, overlap, internal effort, licenses, minimums, growth, projects, after-hours work, hardware, and price changes.
- Test documentation, credentials, configurations, data, exports, knowledge transfer, contract termination, deletion, and transition support.
Next step for your environment
Require each finalist to answer all ten gates with named evidence, then score unresolved assumptions as decision risk.
Record the accountable owner, baseline, source date, decision, exceptions, acceptance evidence, and review trigger. Test consequential changes in a bounded environment, maintain a rollback path, and verify the real result before closing the work. Product names, availability, pricing, legal requirements, and security guidance can change; recheck the primary sources whenever the decision is renewed or the environment changes.
If you need an independent baseline before changing production systems, start with an ITECS technology and security assessment and keep the resulting evidence with the decision record.
Sources and update trigger
- NIST — SP 1305 Cybersecurity Supply Chain Quick-Start Guide
- NIST — Cybersecurity Framework 2.0
- CISA — Choosing Secure and Verifiable Technologies
Review trigger: Review after requirement, provider, proposal, staff, tool, supplier, incident, evidence, cost, contract, or exit changes.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles