act360 Web & IT
Blog

How to Evaluate an IT Company Before You Sign: An Ontario Checklist

An Ontario business owner’s checklist for vetting an IT company before signing — technical fit, security, proof, and exit terms.

Two professionals in a business meeting reviewing a clipboard, representing the evaluation process before choosing an IT company

QUICK ANSWER

Quick answer

Evaluate an IT company on technical fit, security practices, proof of results, and exit terms — not just price. Ask for specifics on each, since vague answers to direct questions are the clearest warning sign before you sign anything.

KEY TAKEAWAYS

What to remember

  • Evaluate technical fit, security practices, proof of results, and exit terms — not just price.
  • An IT provider has deep access to your systems; treat vetting them like any other critical vendor.
  • References and case studies matter less for content than for how willingly they're offered.
  • A missing or vague exit clause means the relationship is retained by contract length, not performance.
  • Vague answers to specific questions during the sales process are the clearest warning sign.
  • A rushed quote based only on headcount and device count skips the assessment step entirely.
In this article
  1. Technical Fit: Can They Actually Support What You Run?
  2. Security & Risk: What Happens With Access to Your Systems?
  3. Proof: Can They Show You, Not Just Tell You?
  4. The Exit: What Happens If It Doesn’t Work Out?
  5. The Full Checklist
  6. Signs You’re Being Sold, Not Assessed
  7. What This Looks Like at ACT360
  8. Final Thought

Signing with an IT company means handing over deep access to your systems, often for years. Here's what to actually evaluate before you do — technical fit, security, proof of results, and what happens if it doesn't work out.

Choosing an IT company is a bigger decision than it often gets treated as. You’re handing a third party ongoing access to your systems, your data, and often your team’s day-to-day productivity — usually for a multi-year relationship. Most businesses spend more time comparing quotes than they do actually evaluating whether a provider can deliver what they’re promising.

Evaluating an IT company means assessing a prospective provider’s technical fit, security practices, track record, and contract terms before signing — not just comparing pricing or a single sales conversation.

“I don’t want to give you a quote based on a headcount and a device list. Give me a week to actually look.”

— Adam Bowles, Partner & CEO, ACT360

The businesses that end up frustrated with an IT provider usually aren’t frustrated by bad luck. They’re frustrated by questions they didn’t ask before signing. Here’s what to ask instead.

Technical Fit: Can They Actually Support What You Run?

Before anything else, confirm the provider can genuinely support your specific environment, not just IT in general.

  • What industries and business sizes do you typically work with?
  • Do you support our specific software and systems, including anything industry-specific?
  • What’s your typical ratio of technicians to client devices or users?
  • Do you have in-house expertise for our platform, or does that get outsourced to a subcontractor?

A provider who’s vague about the last question — outsourcing specialized work without disclosing it — can create a coordination problem later, when it’s unclear who’s actually responsible for a given issue.

Security & Risk: What Happens With Access to Your Systems?

Red padlock resting on a computer keyboard, representing security due diligence when evaluating an IT provider

An IT provider typically has some of the deepest access to your business of any vendor you work with. The Canadian Centre for Cyber Security’s guidance on cyber supply chain security for small and medium organizations recommends treating critical vendors — a category that includes IT providers by definition — with the same scrutiny you’d apply to your own internal security posture, not just trusting that “they’re the IT people, they must have it covered.”

Questions worth asking directly:

  • What security certifications or frameworks do you follow internally?
  • How do you secure your own remote access tools, since those have deep access to our systems?
  • What’s your incident response process if something goes wrong on your end?
  • Do you carry cyber liability insurance, and at what coverage level?

A provider who bristles at these questions, rather than answering them plainly, is worth a second look.

Proof: Can They Show You, Not Just Tell You?

Business team in a meeting reviewing documents, representing checking references and proof of results

Every IT company says they’re proactive, responsive, and experienced. That’s meaningless without evidence attached to it.

  • Can you provide case studies or references from businesses similar in size and industry to ours?
  • What’s your average client tenure, and do you know why clients who’ve left, left?
  • Can I speak directly with a current client, not just read a testimonial?
  • What third-party reviews or recognitions can you point to?

References matter less for what they say and more for whether the provider is willing to offer them without hesitation. A provider confident in its own track record makes this easy.

The Exit: What Happens If It Doesn’t Work Out?

Two professionals shaking hands, representing agreeing to fair, clearly defined exit terms

This is the question most businesses skip, and it’s arguably the most important one. A relationship that starts well can still go sideways, and the contract terms determine how expensive that turns out to be.

  • What’s the length of the initial contract term, and what happens at renewal?
  • Is there a defined exit clause, or are we locked in regardless of performance?
  • Who owns our data, licenses, and documentation if we switch providers?
  • What’s the transition process if we decide to leave?

A provider that requires a long lock-in with no meaningful exit option is betting that inertia, not performance, will keep you as a client. That’s worth noticing before you sign, not after a year of frustration.

The Full Checklist

Pulling it together, here’s what a thorough evaluation covers before signing:

  • Technical fit confirmed for your specific systems and industry
  • Security certifications, remote-access safeguards, and incident response process disclosed
  • Cyber liability insurance coverage confirmed
  • References or case studies from comparable businesses provided willingly
  • Average client tenure and reasons for past departures discussed openly
  • Contract term length and renewal terms clearly explained
  • Exit clause or lack of one clearly stated
  • Data, license, and documentation ownership confirmed in writing
  • Transition process for leaving described in specific terms
  • SLA response and resolution commitments defined by severity, not a single blended number

Signs You’re Being Sold, Not Assessed

A few patterns during the sales process itself are worth paying attention to:

A quote before a real conversation. If a provider can price a contract from a headcount and a device list without ever asking about how your business actually operates, that quote is a guess, not an assessment.

Pressure to sign quickly. Urgency tactics (“this pricing is only good this week”) have more to do with sales targets than your business’s actual timeline.

Vague answers that circle back to reassurance. “We’re very proactive” isn’t an answer to “what’s your average response time by severity.” If a specific question keeps getting a general answer, that’s the pattern to notice.

What This Looks Like at ACT360

Every ACT360 engagement starts with Assess — the first step in our ACTION methodology — specifically because a real quote can’t come from a headcount and a device list. We’d rather spend a week actually looking at how a business runs than hand over a generic proposal on day one.

That’s also why every ACT360 managed IT contract includes a 90-day exit clause. If a provider is confident in what they deliver, a client shouldn’t need to be locked in to stay. It’s a concrete answer to the “what happens if it doesn’t work out” question above, rather than a vague reassurance.

Final Thought

The businesses that end up satisfied with their IT provider a year later usually asked harder questions before signing, not after something went wrong. None of the questions above are unreasonable to ask, and a provider worth working with should be comfortable answering all of them directly.

T: 705-739-2281 E: [email protected]

FAQ

Frequently asked questions

How long should the evaluation process take before signing with an IT company?

There’s no fixed number, but a provider that can produce a real proposal within a day or two of a first call likely skipped the assessment step. A few weeks that include an actual look at your environment is more typical for a meaningful engagement.

Is it reasonable to ask for references from an IT company?

Yes, and a provider confident in its work should offer them without hesitation. If references are difficult to obtain or heavily filtered, that’s worth factoring into your evaluation.

What's the biggest mistake businesses make when choosing an IT provider?

Comparing quotes without comparing what’s actually included. Two proposals with similar pricing can represent very different levels of service — see our breakdown of what managed IT actually includes for what should be in scope either way.

Should I choose the IT company with the lowest price?

Price matters, but it shouldn’t be the deciding factor on its own. A significantly lower quote than competitors often means something is excluded — fewer included hours, a narrower SLA, or less senior staff on your account — that isn’t obvious until later.

How important is industry experience when evaluating an IT company?

It depends on how specialized your industry is. A healthcare practice, law firm, or manufacturer has compliance or operational requirements a generalist provider may not have encountered. For less specialized businesses, general competence and communication matter more than a specific industry checkbox.

KEEP READING

Related Posts