Already have an IT provider

Switching IT providers

Most of the pain in changing IT companies is not technical. It is discovering, three weeks in, that something you assumed you owned is registered to someone else.

This page is written to be used by the business doing the switching, not by either provider. Work through it while you still have a relationship with the outgoing one. Everything here is easier to obtain from a provider who is still being paid.

Who actually changes provider

Managed service providers describing where their new clients come from.

33%
say most new clients are switching from another provider
49%
see a mix of switchers and first-time buyers
12%
say most new clients are outsourcing IT for the first time

Source: Kaseya 2026 State of the MSP Report , Figure 4.

Start here

Before you give notice

Three checks decide how hard a switch will be, and all three can be done today without telling anyone.

Your contract

Find the termination clause. Write down the end date, the notice period, and what the agreement says comes back to you.

Your domain

Log in to the registrar yourself. If you cannot, or the registrant is your provider, settle that now. Email stops with the domain.

Your tenant

Your company should hold at least one Global Administrator account in Microsoft 365 or Google Workspace that is not your provider's. Asking for one is normal.

The review below goes further. It asks fifteen questions about what your provider gives you, and every one of them maps to a published outcome in the NIST Cybersecurity Framework 2.0. The result is a governance finding you can take to your own management rather than a complaint about service.

Self-assessment

Is your IT provider doing the job?

Fifteen questions about what your current IT provider gives you, each mapped to a NIST Cybersecurity Framework 2.0 outcome. This checks whether the basics of provider oversight are in place; it is not an audit of your provider and it does not assess your security posture.

  1. 1. Could your provider hand you a current list of every computer, server and network device they manage for you, today, without preparing it first? higher weight

    NIST CSF 2.0 ID.AM-01: Inventories of hardware managed by the organization are maintained

  2. 2. Do you have a current list of the software and cloud services in use across your business, including who owns each license?

    NIST CSF 2.0 ID.AM-02: Inventories of software, services, and systems managed by the organization are maintained

  3. 3. Is there a current network diagram showing how your sites, internet connections and key systems connect?

    NIST CSF 2.0 ID.AM-03: Representations of the organization's authorized network communication and internal and external network data flows are maintained

  4. 4. Has anyone reviewed who holds administrator access to your systems in the last 12 months, and can you see that review? higher weight

    NIST CSF 2.0 PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

  5. 5. Does your own organization, rather than your provider, hold the top-level administrator account for your Microsoft 365 or Google Workspace tenant? higher weight

    NIST CSF 2.0 GV.SC-10: Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

  6. 6. In the last 12 months, has your provider shown you evidence of a successful test restore, rather than only a report that backups ran? higher weight

    NIST CSF 2.0 PR.DS-11: Backups of data are created, protected, maintained, and tested

  7. 7. Do you receive regular evidence that operating systems and third-party software are being patched, with named exceptions?

    NIST CSF 2.0 PR.PS-02: Software is maintained, replaced, and removed commensurate with risk

  8. 8. Are you told which known vulnerabilities exist in your environment and what is being done about them?

    NIST CSF 2.0 ID.RA-01: Vulnerabilities in assets are identified, validated, and recorded

  9. 9. Is someone actually watching your network and endpoints for suspicious activity outside business hours? higher weight

    NIST CSF 2.0 DE.CM-01: Networks and network services are monitored to find potentially adverse events

  10. 10. Is there a written incident response plan naming who does what, and have you seen it?

    NIST CSF 2.0 RS.MA-01: The incident response plan is executed in coordination with relevant third parties once an incident is declared

  11. 11. Do you know how long your business would be down after a serious failure, and has that figure been agreed rather than assumed?

    NIST CSF 2.0 RC.RP-01: The recovery portion of the incident response plan is executed once initiated from the incident response process

  12. 12. Has your organization formally recognized that your IT provider is a critical supplier, with the oversight that implies?

    NIST CSF 2.0 GV.SC-04: Suppliers are known and prioritized by criticality

  13. 13. Does your contract state measurable obligations, such as response times and security requirements?

    NIST CSF 2.0 GV.SC-05: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

  14. 14. Do you meet your provider on a set schedule to review performance against numbers, rather than only when something breaks?

    NIST CSF 2.0 GV.SC-07: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

  15. 15. Do you know your contract end date, your notice period, and what you would get back on the day the relationship ended? higher weight

    NIST CSF 2.0 GV.SC-10: Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

Handover

What to get back

An outgoing provider who is professional hands all of this over without argument, and many do. If yours resists, that resistance is itself information about the relationship you are leaving.

Credentials and ownership

  • Domain registrar login, with the registrant listed as your company
  • DNS hosting access, wherever the records actually live
  • A Microsoft 365 or Google Workspace Global Administrator account your company holds
  • Local administrator credentials for servers and workstations
  • Firewall and switch administrative access
  • Wi-Fi controller access
  • Backup system console access
  • Remote access and VPN administration
  • Line-of-business application administrator accounts
  • Any password manager vault, exported in a portable format

For each item, confirm the account is in your own name. Access granted through a provider's tenant disappears when the relationship does.

Licenses and subscriptions

  • A list of every subscription, showing the license holder and renewal date
  • Microsoft or Google licenses moved into your own tenant where they sit in a provider's
  • Antivirus, EDR and email security subscriptions, with ownership confirmed
  • Backup software or storage subscriptions
  • Any hardware still under lease or finance, with the agreement itself

Licenses bought through a provider's agreement are often not transferable. Find out which ones before you move.

Documentation

  • Current network diagram
  • Hardware inventory with serial numbers, warranty status and location
  • Software and systems inventory
  • IP addressing scheme and VLAN layout
  • Firewall rule base, with the non-obvious rules explained
  • Backup configuration: what is backed up, how often, where it goes, how long it is kept
  • The most recent successful restore test result
  • Standard operating procedures for anything specific to your business
  • A list of every third party with access to your systems, and why

Ask for it in a format you can read without the provider's tooling. A documentation platform you lose access to at termination is not documentation you have.

Data

  • Confirmation of where every copy of your data physically resides
  • A current backup copy in your own possession, verified as restorable
  • Email archives and journaling, if either is in use
  • File shares, including any sitting in a provider's cloud
  • A written statement of what the outgoing provider will delete, and when

You are entitled to know when copies of your data stop existing on someone else's systems. If you are regulated, you may be obliged to know.

Operational

  • Open ticket list at the point of handover
  • Known outstanding problems, including anything deferred or accepted as a risk
  • Vendor support contracts and the account numbers to use them
  • Maintenance and renewal calendar for the next twelve months
  • Any monitoring or alerting that needs to be pointed somewhere new

Without this, week one with a new provider is spent finding out what you already paid someone else to know.

Failure modes

Three things that go wrong most often

01

The domain

It is the one item that stops email, and it is the one most often registered to a provider rather than to the business. Check it first.

02

The Microsoft 365 tenant

If the tenant was created under a provider's partner agreement and you hold no Global Administrator account, you depend on their cooperation to move. Settle this before notice is served.

03

Undocumented work

Scripts, integrations and one-off fixes that live in an engineer's head and nowhere else. Ask what exists that is not documented, and get it written down while someone still remembers it.

Common questions

Changing provider

Don't see yours? Call (714) 694-4573 or email contact@advran.com.

Should I tell my current provider that I am looking? +

Not before you have checked who owns your domain, your Microsoft 365 or Google Workspace tenant, and your licenses. Everything on the handover list is easier to obtain from a provider who is still being paid. You also do not need to explain why you are asking. Updating your supplier records is a sufficient and accurate reason.

What if I am in the middle of a contract? +

Read the termination clause and write down three things: the end date, the notice period, and what the agreement says is returned to you on termination. If the agreement is silent on what gets returned, assume nothing is, and ask for it in writing before you serve notice. Work out the cost of any overlap early. It is a poor thing to discover at signature.

How long does a handover take? +

The limiting factor is almost never the technical work. It is how much documentation exists and who holds which account. A business with a current network diagram, an owned tenant and a known license position moves quickly. A business that has to reconstruct all three first does not. That is why the questions on this page ask about records and ownership.

Will my email go down? +

Only if the domain or the tenant is not under your control at cutover. Email follows the domain, so a domain registered to your provider is the single most disruptive thing to recover. Verify that you can log in to the registrar yourself before anything else happens.

Do I have to move everything at once? +

No. Monitoring, endpoint security, backup and help desk can be taken over in stages, and staging reduces the risk of a single bad weekend. What does need to be settled up front is ownership: domain, tenant and licenses. Those determine what is even possible afterwards.

What does AdVran need in order to quote? +

A device and user count, where your sites are, what compliance obligations apply, and whatever documentation you already hold. If the documentation does not exist, say so. That is a common answer. Call (714) 694-4573 or email contact@advran.com.

Bring us what you found

If the review above produced a list of gaps, that list is the agenda for a first conversation. We serve Orange County, Los Angeles, the Inland Empire and Ventura County from Anaheim, with 24/7/365 SOC and critical support.

AdVran headquarters

155 N Riverview Dr #111
Anaheim, CA 92808