The first 90 days with a managed IT provider should establish control and shared evidence, not rush every system through a single cutover. Exact timing varies with environment size, access, documentation, vendors, risk, and contract scope. Use phases and acceptance gates instead of a guaranteed calendar.
Current as of 2026-08-15
CISA’s MSP guidance emphasizes identity, monitoring, logging, remote access, and contractual responsibilities. These controls should be verified during onboarding, not assumed from the proposal.
Decision summary
- Protect continuity and preserve the outgoing provider’s records and access until handoff is verified.
- Use named accounts and reconcile every privileged path.
- Validate backups and monitoring with evidence.
- Do not declare steady state until users, systems, vendors, and executives accept the operating model.
Days 0–30: establish control
- Confirm scope, owners, contacts, service levels, escalation, and change authority.
- Inventory users, devices, servers, networks, cloud, domains, certificates, vendors, and applications.
- Create named provider identities, MFA, least privilege, and emergency revocation.
- Transfer documentation, credentials, licenses, warranties, and open issues.
- Protect backups and capture a known-good baseline.
Days 31–60: stabilize operations
- Deploy monitoring and support tooling in approved stages.
- Reconcile missing assets and duplicate or stale agents.
- Prioritize critical patch, identity, endpoint, email, and backup gaps.
- Test ticket routing, after-hours escalation, and vendor coordination.
- Document exceptions and proposed changes with rollback.
Days 61–90: prove steady state
- Run restore, incident, and escalation exercises.
- Review service trends, recurring problems, risks, and lifecycle needs.
- Confirm logging, reports, access reviews, and executive cadence.
- Close or transfer every onboarding exception.
- Approve the as-built responsibility matrix and exit package.
Evidence that onboarding is complete
Completion evidence should include an accepted inventory, access register, responsibility matrix, support and escalation test, backup and restore results, monitoring coverage, outstanding risk register, vendor list, current diagrams, and an executive review. Record unresolved exceptions with owners and deadlines.
Next step
Turn the provider proposal into a 90-day acceptance matrix with owners, evidence, exceptions, and stop conditions. For an environment-specific baseline, request an ITECS technology and security assessment.
Primary Sources
- CISA — Joint advisory for MSPs and customers
- CISA — SMB vendor and MSP assessment guidance
- FTC — Vendor security guidance
Review trigger: Review before each provider transition and when contract scope, systems, owners, or security requirements change.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles