- Managed services agreement (MSA)
- The master contract that defines the relationship — scope of covered services, covered environment, exclusions, service levels, fees, term, renewal, liability and termination. Everything an MSP argues about later is decided here.
- Per-user vs per-device pricing
- Per-user charges a flat monthly fee per employee covering all of that person's devices — it matches how an owner thinks about headcount and travels well when staff carry a laptop, phone and desktop, but it is unprofitable in device-heavy environments like manufacturing or labs. Per-device charges by workstation, server, firewall or network device — predictable to deliver and easy to audit, but it penalizes a clean estate and forces a pricing conversation every time a machine is added.
- Tiered flat-fee packaging
- Good/better/best bundles — typically support-only, support plus security, and a compliance or advisory tier. Simplifies selling and creates a natural upgrade path, at the cost of clients who want to buy one item out of the middle tier.
- All-you-can-eat vs block hours vs break-fix
- Three commercial postures. All-you-can-eat (unlimited remote support for a fixed fee) aligns the provider's incentive with stability. Block hours pre-purchase a bucket of time. Break-fix bills by the incident and pays the provider more when things break — the model managed services was invented to replace.
- Monthly recurring revenue (MRR) and the valuation multiple
- MRR is contracted revenue that recurs every month without a new sale — the core operating metric of the industry. It is also the basis on which practices are valued: buyers price an MSP as a multiple of adjusted EBITDA, and the multiple is driven by recurring-revenue share, contract quality and assignability, client concentration, growth, retention and owner-independence. A dollar of contracted recurring revenue is worth materially more than a dollar of project or hardware resale revenue.
- Effective rate per endpoint
- Total monthly contract revenue divided by the number of managed endpoints. Reveals what the provider is really charging once bundles, discounts and grandfathered agreements are stripped out, and makes wildly different pricing models comparable.
- Gross margin per seat
- Revenue per user minus the direct cost to serve that user — licensing, security stack, tooling and the labor consumed. The number that decides whether growth makes a provider stronger or just busier.
- Service delivery cost as a percentage of revenue
- All delivery labor and tooling divided by managed-services revenue. The standard efficiency benchmark for a support organization; drift upward almost always traces to unbilled scope, poor onboarding or unresolved root causes.
- Technician utilization and billable ratio
- The share of a technician's paid hours spent on client-facing work, and the share of that work that is chargeable. Low utilization is a scheduling and dispatch problem; high utilization with low margin is a pricing problem.
- Tickets per endpoint per month
- Support volume normalized by the size of the estate. The single best early-warning indicator of an unprofitable client — a rising rate means unresolved root causes, poor standardization or an environment that was never remediated after onboarding.
- Mean time to resolution (MTTR)
- Average elapsed time from ticket creation to verified fix. Should always be read alongside volume and priority mix, since closing easy tickets quickly can mask a queue of unresolved hard ones.
- First-call resolution
- Share of issues fixed on the first contact without escalation or a return visit. Drives client satisfaction more than raw speed and is the clearest measure of tier-one capability and documentation quality.
- SLA response vs resolution targets
- A response target promises how quickly a human engages; a resolution target promises when the issue is fixed. Most MSP agreements commit only to response, and buyers routinely misread that as a repair guarantee — the most common expectation gap in the industry.
- Escalation tiers
- The tier-one to tier-three structure that routes work by complexity, with defined criteria and time thresholds for handoff. Well-run tiers protect senior engineers' time; poorly run ones simply delay the right person seeing the ticket.
- NOC and SOC
- The network operations center watches infrastructure health — alerting, patching, backup verification and routine remediation — and is frequently outsourced to a wholesale NOC provider even by MSPs that market it as in-house. The security operations center is the 24/7 analyst function that triages detections, hunts threats and initiates containment; it is genuinely expensive to staff, which is why most small MSPs buy it as managed detection and response rather than build it. Buyers should ask which is actually staffed by the provider and which is a subcontract.
- Help desk vs service desk
- A help desk fixes incidents. A service desk owns the whole service relationship — incidents plus requests, changes, problems, assets and communication. The distinction signals process maturity, and clients feel it in how requests and changes are handled.
- vCIO (virtual CIO)
- A fractional executive relationship providing strategy, budgeting, roadmap, risk and vendor governance to a business too small for a full-time CIO. The role that separates a strategic partner from a support vendor, and the main defense against price-based displacement.
- Technology business review (QBR)
- The recurring — typically quarterly — meeting where the provider presents ticket trends, security posture, project status, lifecycle risk and next-period budget. The primary retention and upsell mechanism, and often the only time the client's owner sees value made visible.
- Technology roadmap and budget planning
- A multi-year plan for refresh cycles, license renewals, end-of-support deadlines, security investments and projects, expressed as a spending forecast an owner can approve. Converts reactive emergency spending into planned capital.
- Onboarding, discovery assessment and offboarding
- Onboarding is the structured intake at the start of an engagement — network and asset discovery, credential and license takeover, documentation build, risk findings and a first-90-days remediation plan; skipping or underpricing it is the most reliable way to lose money on an account for its entire life. Offboarding is the mirror image: returning documentation and credentials, transferring tenant and domain ownership, removing agents and management tooling, and a defined transition-assistance period. A provider's offboarding terms are a fair proxy for how it treats clients generally.
- Client concentration risk
- The share of revenue coming from the largest one or few clients. High concentration depresses valuation and gives a single account veto power over pricing, scope and staffing decisions.
- Contract term, auto-renewal and right to audit
- Initial term, renewal mechanics, notice period and price-escalation clauses decide whether a provider can absorb vendor cost increases and whether the revenue is transferable in a sale — longer contracted terms with clean assignment language are what MSP buyers actually pay for, while aggressive auto-renewal with short notice windows erodes client trust. A right-to-audit clause gives the client the ability to inspect the provider's controls, subcontractors and evidence; regulated clients and their auditors increasingly demand it, and providers usually satisfy it with a SOC 2 report instead.
- Limitation of liability
- The contractual cap on the provider's exposure, commonly tied to fees paid over a recent period. It creates the structural mismatch at the center of the industry: a modest monthly fee against a breach that can cost the client many multiples of the entire contract value.
- Cyber insurance requirements flowing down
- Carrier questionnaires now require MFA, EDR, tested and immutable backups, email filtering, privileged-access separation and training. The client must attest to these, so the MSP effectively inherits the underwriting checklist as a delivery requirement — and a misrepresented control can void a claim.
- Incident response retainer
- A pre-negotiated engagement with a specialist IR firm guaranteeing response time and rates before an incident. Cheaper and faster than negotiating during a live ransomware event, and increasingly expected by insurers and boards.
- RMM (remote monitoring and management)
- The agent-based platform that inventories, monitors, patches, scripts and remotely controls managed endpoints. The operational backbone of an MSP — and, because it holds privileged access to every client, its single largest security liability.
- PSA (professional services automation)
- The system of record for the practice: tickets, time entry, contracts, projects, procurement and invoicing. Where the business is actually managed; the quality of PSA data determines whether any of the delivery metrics can be trusted.
- Endpoint detection and response (EDR)
- Behavior-based endpoint security that records process activity, detects malicious patterns rather than known signatures, and supports isolation and rollback. Now a baseline requirement rather than an upsell, largely because insurers demand it.
- Managed detection and response (MDR)
- EDR plus a human analyst team doing 24/7 triage, investigation and response on the client's behalf. The dominant way small businesses obtain security operations, and the fastest-growing line on most MSP price lists.
- SIEM (security information and event management)
- Central collection and correlation of logs from endpoints, identity, network and cloud, with alerting and retention. Frequently required for compliance evidence; log volume and tuning effort are what make it costly to deliver.
- MFA and conditional access
- Requiring a second factor, and shaping access by user, device compliance, location and risk signal. The highest-leverage control available to a small business, and the one item every cyber-insurance questionnaire asks about first.
- Privileged access management (PAM)
- Controlling and recording administrative credentials — vaulting, just-in-time elevation, separate admin identities, removing standing local-admin rights. Critical for MSPs specifically, whose own technicians hold the keys to every client.
- Patch cadence and vulnerability management
- A defined schedule and testing ring for operating-system, third-party and firmware updates, paired with scanning and risk-based remediation. Measured by patch compliance percentage and time-to-patch on critical vulnerabilities.
- 3-2-1 backup rule and immutable backups
- Three copies of data on two media types with one off-site — extended in the ransomware era with immutable or air-gapped copies that cannot be altered or deleted within a retention window, because modern attackers target the backups first.
- RTO and RPO
- Recovery time objective is how long the business can be down; recovery point objective is how much data it can afford to lose. Set with the client per system and per budget, then designed to — and, critically, tested against.
- Disaster recovery testing
- Scheduled restore verification, failover exercises and tabletop drills that prove recovery objectives are achievable. Untested backups are the most common finding in post-incident reviews and a standard audit exception.
- Business continuity plan (BCP)
- The wider plan for operating through disruption — alternate work locations, communication trees, manual workarounds, vendor contacts and decision authority. Broader than IT recovery and increasingly requested by clients' own customers and insurers.
- Email security and DMARC/SPF/DKIM
- Filtering plus the three DNS-based authentication records that let receivers verify a sender's domain. SPF authorizes sending hosts, DKIM signs messages, DMARC sets policy and reporting — now effectively mandatory for reliable bulk delivery and a common first deliverable in an onboarding remediation.
- Phishing simulation and security awareness training
- Recurring simulated phishing campaigns with targeted micro-training and reporting on click and report rates. Cheap, measurable, contractually useful for compliance evidence, and one of the few controls that produces a metric an owner immediately understands.
- Zero trust and least privilege
- Assume no implicit trust from network location; verify every request against identity, device posture and context, and grant each account only the access its role requires. In practice for an SMB this means conditional access, device compliance, admin-rights removal and segmentation — not a product purchase.
- CIS Benchmark hardening
- Applying the Center for Internet Security's consensus configuration baselines to Windows, macOS, Microsoft 365, browsers and network gear. Gives an MSP a defensible, citable standard for 'secure by default' instead of house opinion.
- Asset inventory
- A current, authoritative list of hardware, software, cloud services, identities and data locations. The first CIS Control for good reason — nothing else can be patched, secured, backed up or budgeted if it is not known to exist.
- Shadow IT
- Software, SaaS subscriptions and now AI tools adopted by staff outside IT's knowledge. Creates unmanaged data locations, orphaned accounts, duplicate spend and compliance exposure; discovery and a sanctioned-tool path work better than prohibition.
- License true-up
- Reconciling assigned licenses against actual headcount and entitlement at renewal. Recovers real money on both sides — unassigned seats after turnover, and under-licensing that surfaces as an audit liability.
- Microsoft 365 tenant management
- Day-to-day administration of the environment where most SMB work now happens: identity and groups, conditional access, Intune policy, sharing and retention governance, secure-score remediation, and third-party backup of the tenant's data.
- CSP and distribution margin
- Buying Microsoft and vendor subscriptions through the Cloud Solution Provider program or a distributor such as Pax8, then reselling with a margin and owning the billing relationship. A meaningful profit line, and the reason vendor price increases hit MSP margins directly.
- Co-managed IT
- A shared model where an internal IT person or team keeps ownership of some functions while the provider supplies tooling, after-hours coverage, security operations, project capacity and escalation depth. Sold as augmentation rather than replacement, which removes the internal team's incentive to block the deal.