Choosing a Managed IT Services Provider in Quebec: 12 Questions
The 12 questions we'd ask any MSP before signing, from response times and backup testing to Law 25 and contract fine print.
Somewhere between the third sales call and the fourth proposal PDF, most business owners admit they have no reliable way to compare managed IT services in Quebec. Every provider promises fast response, strong security and friendly technicians. The websites blur together. Pricing, when you can get it in writing at all, never lines up neatly against the next quote.
The fix is to stop comparing brochures and start comparing answers. We've onboarded plenty of companies that left another provider, and the regrets follow a pattern: slow response nobody measured, security that turned out to be a lone antivirus licence, a contract that renewed itself for three years while nobody was looking. Almost every one of those regrets could have been caught with a direct question asked before signing. Here are the 12 we'd want answered by any managed IT provider, including us.
Key Takeaways
- Get response time guarantees in writing, with consequences when they're missed.
- A provider serving Quebec businesses must know Law 25 in practice, not just by name.
- A backup that's never been restore-tested is a wish, not a plan.
- Watch contracts for long auto-renewals, per-incident billing and vague scope language.
- References from companies your size tell you more than any sales deck.
Why Choosing Managed IT Services in Quebec Is Different
Generic MSP checklists miss two realities of doing business here. The first is Law 25, Quebec's privacy law, which puts real obligations on any company that handles personal information: a designated privacy officer, breach reporting, privacy impact assessments for certain projects. Your IT provider doesn't carry that legal responsibility for you, but the technical controls that satisfy it (access management, encryption, logging, retention) usually live in systems your provider configures. A firm that has never heard of the Commission d'accès à l'information will leave you exposed.
The second is language. If your team works in French, English or both, support has to work in both too. A ticket that sits unresolved because the technician couldn't understand the request means downtime, plain and simple.
Keep both realities in mind as you work through the questions below. They come up more often than you'd think.
Questions 1 to 6: People, Response Times and Security
1. What response times do you guarantee in writing, and what happens if you miss them?
"We're usually pretty fast" is not an answer. Ask for the actual service level agreement: how quickly a critical issue is acknowledged, how quickly work starts, and how the provider reports against those targets. Then ask the harder question: what happens when a target is missed? Providers confident in their numbers will show you their ticket statistics. If the SLA lives only in the sales conversation and not in the contract, treat it as decoration.
2. Who answers when we call, and where is your team based?
Some providers answer with their own technicians. Others route you to an outsourced call centre that logs the ticket and promises a callback. Neither model is automatically wrong, but you should know which one you're buying. Ask whether the people resolving your issues are employees, where they work from, and whether you'll deal with the same small team over time. Familiarity matters: a technician who already knows your environment resolves issues faster than one reading your file for the first time.
3. What's in your security stack by default, and what costs extra?
Ask the provider to list exactly what the base fee includes. Endpoint detection and response, or just antivirus? Email filtering? Enforced multi-factor authentication? Security monitoring, and if so, watched by whom and during which hours? Many bad surprises trace back to a client assuming "managed" included security while the contract treated it as an add-on. A serious managed cybersecurity offering comes with a written list of included controls, each one explainable in plain language.
4. How do you protect our Microsoft 365 identities?
Most Quebec SMBs run on Microsoft 365, and most modern breaches start with a stolen password. So ask specifically: will you enforce multi-factor authentication for every user? Do you deploy Conditional Access policies, and which ones? If the person across the table can't describe how they'd block a sign-in made with a stolen password, that's a signal. We published our own Conditional Access baseline free of charge, precisely so businesses can compare what providers actually deploy.
5. How will you help us meet our Law 25 obligations?
The legal responsibility stays with you, but your provider controls many of the technical pieces: who can access personal information, how long it's retained, whether incidents get detected and documented. Ask how they support breach notification timelines, what logging they keep, and whether they can produce evidence for a privacy impact assessment. A good answer names concrete tools and processes. A bad answer is "we're compliant," which means nothing, since Law 25 applies to your business, not to them.
6. Can your team support us in French and in English?
Ask which languages the help desk operates in, and whether documentation, reports and user communications arrive in the language your employees actually work in. If you have staff in both languages, ask for an example of each. For a business subject to Quebec's language requirements, employee-facing IT communications in French are simply part of operating properly here.
Questions 7 to 12: Onboarding, Backups and the Fine Print
7. What do the first 90 days look like?
Switching providers is a project, and good MSPs treat it like one. Ask for the onboarding plan: documentation of your environment, credential handover, quick security wins, a baseline audit, and how day-to-day support runs during the transition. Ask who manages employee arrivals and departures afterwards too. If the provider has nothing resembling a structured process (something like our employee onboarding tech checklist, applied to a whole company), expect improvisation.
8. How is our data backed up, and when did you last test a restore?
Two traps hide in this one. The first is assuming Microsoft backs up your Microsoft 365 data for real-world scenarios like a departed employee's deleted mailbox; retention policies and true backup are different things, a distinction we unpack in our comparison of Microsoft 365 Backup and Dropsuite. The second is backup that exists but has never been restored. Ask for the date of the last successful restore test and what it covered. A provider running proper backup and recovery answers in seconds, because testing follows a schedule.
9. What should we watch for in your contract?
An honest provider walks you through the fine print without flinching. Watch for automatic renewal clauses that lock you in for another full term unless you cancel within a narrow window, months in advance. Watch for "all-inclusive" service with a long exclusions list that turns routine work into billable projects. And watch for per-incident or per-ticket pricing, which quietly rewards the provider when your systems misbehave. A flat monthly fee aligned with preventing problems keeps the incentives on your side.
10. How does your billing work, and what counts as out of scope?
Even flat-fee agreements have edges: new projects, hardware, after-hours emergencies, onsite visits. Ask for concrete examples of a typical invoice and of what triggered extra charges for existing clients in the past year. Providers comfortable with their model publish their structure, the way we do on our pricing page. If getting a straight number takes three meetings, budget conversations after signature won't be any easier.
11. What happens if we decide to leave?
Exit terms show how confident a provider is about earning renewal instead of enforcing it. Ask what offboarding includes: return of all credentials and administrative access, export of documentation, cooperation with the next provider, and any fees involved. Get it in writing that your passwords, licences and domain registrations belong to you. A provider who resists this conversation is telling you something important before you've paid a dollar.
12. Can we talk to two current clients similar to us?
Not a testimonial page. Actual conversations with businesses of your size, ideally in your industry, who've been clients for over a year. Ask those references two things: what happens when something breaks at the worst possible time, and what they'd change about the relationship. Every provider has a rough story somewhere; what matters is how it was handled. If references can't be produced, or they're all companies ten times your size, the fit probably isn't there.
How to Compare the Answers You Get
Don't score providers on charm. Put the 12 answers side by side in a spreadsheet and look for specifics: numbers, dates, named tools, written commitments. Vague answers cluster together, and so do precise ones. Two or three questions will matter more for your situation, so weight them. A manufacturer with production lines cares most about response times; a clinic handling health records should weight Law 25 and backup testing heavily.
And prefer evidence over promises. An independent IT assessment of your current environment is a fair test of any provider: it shows you how they analyze, document and explain before you've committed to anything.
FAQ
How much do managed IT services cost in Quebec?
Most providers charge a monthly fee per user or per device, and the total depends on what's included: security tooling, backup, onsite support and project work all move the number. Based on field observations, all-inclusive per-user pricing for SMBs usually lands somewhere between the cost of a cell phone plan and a modest software budget per employee. Ask every provider to break the fee into its components so quotes can be compared honestly.
What's the difference between managed IT services and break-fix support?
Break-fix means you call when something is broken and pay by the hour, so the provider earns more when you have more problems. Managed services means a flat monthly fee covering monitoring, maintenance and support, so the provider earns more when your systems stay healthy. For most businesses past a handful of employees, the aligned incentives and predictable budget of the managed model win out.
How long does it take to switch IT providers?
A structured transition usually runs 30 to 90 days from signature to steady state, covering documentation, credential transfer, a security baseline and user communication. The old and new providers often overlap briefly. A well-run switch is mostly invisible to employees, and a provider who has done it many times will show you the plan before you sign.
Does Law 25 really apply to small businesses?
Yes. Law 25 applies to any enterprise that collects or holds personal information about people in Quebec, regardless of size. That includes employee records and customer lists, so nearly every business is covered. The effort is proportional to the sensitivity of the data you hold, but the core obligations, including a designated privacy officer and breach reporting, apply to small companies too.
Twelve questions look like a lot until you compare them with the cost of two years in the wrong contract. If you'd like to see how we answer them, book a conversation or start with a no-obligation look at your current environment through our IT assessment. Bring the hard questions; they're the ones we like.
Related Articles
IT Budget Planning 2027: Costs and Grants for Quebec SMBs
IT budget planning 2027 for Quebec SMBs: Microsoft 365 renewals, Windows 10 ESU, backup, security and ESSOR grants. Learn how to build yours.
Windows 10 ESU Ends October 13, 2026: Your 10-Week Plan
Windows 10 ESU Year 1 ends October 13, 2026. Learn how to audit your fleet with Intune and finish your Windows 11 migration in 10 weeks.
The Employee Offboarding Checklist: Close Every IT Door
Learn how to disable Entra ID accounts, revoke access and reclaim licences with an employee offboarding checklist built for Microsoft 365.