A managed IT buyers checklist for a CEO covers 5 decisions the chief executive owns personally, the coverage model, the cost of downtime, regulatory exposure, insurance requirements, and exit terms. Vendor features come after those 5 are settled, not before.
Nearly every managed IT checklist is written for whoever runs your IT. This one isn’t. It covers the 5 decisions a CEO signs off on personally, and it assumes you’re not going to read a single SOC 2 report yourself. Work through it before the first vendor call. It takes about an hour, and it changes what you end up asking for.
There’s a reason the second vendor call always goes better than the first. By then you’ve worked out what you’re actually buying. Which is backwards. This checklist moves that discovery to where it belongs, ahead of the first conversation, so that the questions you ask are shaped by your own numbers rather than by whichever provider happened to call you back soonest. It’s worth the hour. If you want the technical version that scores providers point by point, that’s our managed IT services checklist. For the service category itself, start with managed IT services.
What a CEO’s managed IT checklist actually covers
A CEO’s managed IT checklist is a pre-purchase decision framework, not a vendor scorecard. It settles what your company is buying, what failure costs you, which rules already bind you, what your insurer requires, and how you leave. Those 5 answers shape every proposal you’ll receive.
Your IT lead evaluates the provider. You evaluate the decision. Those are different jobs and they use different evidence.
| Decision | Who owns it | What it depends on |
|---|---|---|
| Coverage model and scope | CEO | Headcount, growth plan, whether you keep internal staff |
| Budget ceiling and term length | CEO | Revenue, margin, cash timing |
| Regulatory and contract exposure | CEO with counsel | Customer contracts, industry rules, employee count |
| Insurance requirements | CEO with broker | Carrier control list at renewal |
| Exit terms and data ownership | CEO with counsel | Contract language, credential custody |
| Ticket SLAs, tooling, stack fit | IT lead or vCIO | Current environment, applications in use |
| Security control depth | IT lead or vCIO | Risk assessment, framework selected |
Notice how few rows belong to you. That’s the point. Delegate the rest. Five decisions and an hour of work is the whole ask.
The 5 decisions only the CEO can make
Work them in order. Each one narrows the next.
1. Decide which coverage model you’re buying
Three models exist and they cost different amounts. Fully managed means the provider runs everything and you keep no internal IT staff. Co-managed means you keep your IT person or team and the provider fills specific gaps, usually security monitoring, after-hours coverage, and project capacity. Security-only means you keep IT in house and buy monitoring and response as a separate line.
Pick the model first. A proposal priced for fully managed and a proposal priced for co-managed aren’t comparable documents, and sitting them side by side is how companies end up paying twice for the same coverage.
The test is simple. If your IT person quit tomorrow, would the business keep running for 2 weeks? A yes points to co-managed. A no points to fully managed, whatever your org chart says. Org charts lie here. Our breakdown of co-managed IT cost in Texas has the per-seat math if you’re leaning that direction.
2. Put a number on an hour of downtime before you get quotes
You can’t evaluate a response time SLA without this number, and almost nobody calculates it before shopping. Here’s the arithmetic. Take your annual revenue, divide by roughly 2,000 working hours, then multiply by the share of revenue that stops when systems stop. For a distributor where every order flows through one ERP, that share is close to 1. For a firm where billable work continues on laptops, it might be 0.3.
A $40M company with a 0.6 dependency factor is looking at about $12,000 an hour. Do that math first. It takes 10 minutes, and it converts every subsequent conversation from a debate about service tiers into a comparison between a number you calculated and a commitment somebody is willing to put in a contract. That number is yours alone.
That figure decides whether a 4-hour resolution target is generous or insulting. It also tells you what recovery time your backups need to hit, which is a different question from how often they run. IBM’s 2026 Cost of a Data Breach report puts the mean time to identify and contain a breach at 247 days, the first increase after 5 straight years of decline, so the recovery conversation is getting longer, not shorter. For what the market actually commits to in writing, we published MSP SLA benchmarks for 2026.
3. Check which rules already bind you
Your customer contracts probably impose security obligations you’ve never read. So does your industry. And since September 1, 2025, Texas has offered something in return.
Senate Bill 2610 created a safe harbor for Texas businesses under 250 employees. If you maintained a qualifying cybersecurity program at the time of a breach, a court can’t award exemplary damages against you. Actual damages still apply. The requirements scale with headcount, which makes your employee count a compliance variable, not just an HR number.
| Employee count | What the program must include | Practical read |
|---|---|---|
| Fewer than 20 | Password policies and appropriate employee cybersecurity training | Achievable in a quarter |
| 20 to 99 | CIS Controls Implementation Group 1 | Roughly 56 safeguards, a real project |
| 100 to 249 | A recognized framework such as NIST, ISO/IEC 27000-series, or FedRAMP | Budget for an assessment |
| 250 or more | No safe harbor available | The cliff nobody plans for |
Read the bottom row again. A company that grows from 240 to 260 people loses this protection entirely, and the growth plan you’re approving this year is what moves you across that line. That’s a planning problem. The full bill text sits at capitol.texas.gov, and we walk through qualification in our Texas SB 2610 guide.

Defense suppliers have a second thing to track. The Department of War suspended CMMC Phase 2 third-party assessment requirements on July 13, 2026, and launched a reform review. The underlying obligations didn’t go anywhere. DFARS 252.204-7012 and NIST 800-171 still apply, and Phase 1 self-assessment still applies, as the Department’s own announcement makes clear. Treating the pause as a reprieve is a mistake your primes will catch.
If you handle consumer financial data, the FTC Safeguards Rule requires a written information security program and reporting to the FTC within 30 days of a breach touching 500 or more consumers. Auto dealers, mortgage brokers, and title companies are all in scope and most of them don’t know it.
4. Get your insurance requirements in writing first
Call your broker before you call a provider. Ask one question. What controls does our carrier require at renewal, and what happens if we can’t evidence them? Get it in writing.
The list is short. It usually includes multi-factor authentication on remote access and privileged accounts, endpoint detection and response on every device, immutable and tested backups, a written incident response plan, and security awareness training. What changed in 2026 is the evidence standard. Carriers want logs and documentation, not attestations on an application form, and a control you claimed but can’t prove is the most common reason a claim gets denied.
Hand that list to every provider you talk to and make it a scope requirement. It converts a vague security conversation into a purchase order line item. Coalition’s 2026 Cyber Claims Report, drawn from more than 100,000 policyholders, found 64% of closed claims in 2025 resolved with zero out-of-pocket loss for the policyholder, which is what good controls plus a real policy buys you.
5. Own the exit before you own the onboarding
Nobody negotiates the exit during the honeymoon. Do it anyway. You’ll never have more room to negotiate than the week before you sign.
Four things belong in the contract. Your data comes back in a usable format on request. Domain registrar, Microsoft 365 tenant, and firewall admin credentials are held in your name, not the provider’s. Documentation transfers at termination. And there’s a defined notice period with a stated offboarding fee, or none.
Credential custody is the one that bites. That’s the trap. A provider holding your Microsoft 365 tenant inside their own partner account can stretch what should be a 30-day transition into a 90-day one, and for most of those extra 60 days you’re paying two providers at once for a single set of users. We covered the mechanics in how to exit an MSP contract without downtime.

The 2026 checklist, in one page
Print this. Work down it before the first vendor meeting.
- Coverage model chosen, fully managed or co-managed or security-only
- Cost of one hour of downtime, calculated from your own revenue
- Recovery time objective set for your 3 most critical applications
- Employee count checked against the SB 2610 tiers
- Customer contract security clauses reviewed by counsel
- Carrier control list from your broker, in writing
- Budget ceiling and contract term agreed internally
- Exit terms, data return, and credential custody drafted
- Named internal owner for the relationship, with time allocated
- Success measures defined for day 90 and day 365
The last item gets skipped the most and matters the most. Nobody does it. If no one inside your company owns the relationship, the provider sets the agenda by default, quarterly business reviews quietly become annual ones, and the roadmap you were promised in the sales cycle turns into a renewal conversation 11 months later.
What managed IT costs in Texas in 2026
Published rates are rarer than they should be in this market. We publish ours. Here are ours alongside the broader Texas bands we see in competing proposals.
| Model | Texas market range | Uprite rate | Best fit |
|---|---|---|---|
| Fully managed, per user per month | $100 to $200 | $138 | No internal IT staff |
| Co-managed, per user per month | $60 to $130, most at $85 to $110 | $100 | One IT lead who needs depth |
| Remote-only support, per user per month | Varies widely | $110 | Distributed or small-site teams |
| Security monitoring only, per user per month | $35 to $75 | $40 | Capable IT team, thin security |
Licensing sits on top and it’s worth knowing the real numbers before a provider bundles them. Microsoft 365 Business Premium with Copilot lists at $32.00 per user per month on an annual subscription, and Defender for Business as a standalone runs $3.00. That second figure is the useful one. The tooling is almost never what stops a company from being secure. The operating discipline is.

Worldwide IT spending will reach $6.37 trillion in 2026, up 14.2%, according to Gartner. Most of that growth is AI infrastructure, which means your vendors’ costs are rising for reasons unrelated to your service. Ask what happens to your rate in year 2. Then ask for it in writing.
Metro pricing moves a little. We break it out by market in the Houston buyers guide, the Dallas Fort Worth guide, and the San Antonio guide.
Where this checklist gets used wrong
We used to lead every proposal with our response time. Sub-10-minute triage, right at the top of page 1. It’s a real number and we still hit it, but putting it first taught buyers to compare providers on the wrong axis. A 5-minute triage that routes your ticket to someone reading from a script is worse than a 20-minute triage that routes it to an engineer who already knows your network, and we watched prospects choose the script for two years before we understood what our own page 1 was doing. It wasn’t working. We moved it to page 3.
The second misuse is treating the checklist as a scoring rubric. It isn’t one. It’s a set of decisions you make before scoring anyone, and a provider can’t fail an item on this list because none of the items are about the provider.
If you’ve got a competent full-time IT director, a documented environment, and a stack that isn’t fighting you, you may not need a managed provider at all. You might need project capacity twice a year and a security layer. That’s a $40 per user conversation, not a $138 one. Providers who don’t tell you that are hoping you won’t work it out.
Governance is the piece that survives whichever way you go. NIST added a Govern function to Cybersecurity Framework 2.0 specifically because setting risk tolerance and naming accountable owners sits with executives, not with whoever holds the admin password. CISA’s small business guidance says the same thing in plainer words, and their cyber guidance for small businesses is a genuinely good 20-minute read for a CEO.
How we answer each item
Fair to show our own work. Uprite has run IT for Texas businesses since 1999. We’re 42 people, and we currently support 2,227 users and 444 servers across Houston, San Antonio, Dallas, and Fort Worth at a 98.4% satisfaction rating. We completed a SOC 2 Type 1 examination in 2023 and we’ve placed on the MSP 501 for 7 consecutive years, most recently at number 264.
On coverage model, we price all 4 models separately and we’ll tell you which one fits after we look at your environment, including when the answer is the cheaper one. On exit, our contracts carry a 120-day no-penalty guarantee, so if the first 4 months don’t work you leave without a termination fee. On budget, published per-user rates and a year-one rate lock. That answers the year-2 question before you ask it.
On the rest of it, the regulatory review, the insurance control list, the risk decisions, that work belongs to a strategist rather than a help desk. It’s what our vCIO services exist to do, and it’s the part of this checklist you shouldn’t hand to a ticket queue. Current rates for every model are on our pricing page.
Questions CEOs ask before signing
What should a CEO check before signing a managed IT contract?
Five things. The coverage model, your calculated downtime cost, your regulatory exposure, your insurer’s required controls, and the exit terms. Everything else on a standard evaluation checklist can be delegated to an IT lead or an outside advisor.
Is a CEO checklist different from an MSP evaluation checklist?
Yes, and the difference matters. An MSP evaluation checklist scores providers against each other. A CEO checklist settles what you’re buying and what it’s worth before any provider is scored. Run the CEO version first, then hand the evaluation version to your IT lead. Our MSP RFP process guide covers the formal version if you’re running a competitive bid.
How much should a Texas company budget for managed IT in 2026?
Plan on $100 to $200 per user per month fully managed, or $60 to $130 co-managed. Uprite charges $138 and $100 respectively. Add Microsoft licensing separately, roughly $32 per user for Business Premium with Copilot.
Budget for onboarding too. It’s usually a one-time fee in the range of 1 to 2 months of recurring spend, and providers who waive it entirely are often recovering it in the contract term.
Does Texas SB 2610 actually protect my company after a breach?
Partially. It shields businesses under 250 employees from exemplary damages if a qualifying cybersecurity program was already in place when the breach happened. Actual damages, regulatory penalties, and contractual liability are all untouched by it.
There’s no grace period either. The program has to exist at the moment of the breach, which is why it belongs in a buying decision rather than a remediation plan.
Do we need to switch providers, or can we fix what we’ve got?
Often you can fix it. Run this checklist against your current contract before you go to market, because roughly half the problems CEOs bring us are scope and governance gaps rather than provider failures.
If the answer turns out to be a switch, the transition itself is well understood. Response time commitments, escalation paths, and who owns your credentials are the three places existing contracts tend to be thin. Our breakdown of what Texas IT support contracts actually say is a useful comparison point.
Who owns the IT decision if we don’t have a CIO?
You do, with an advisor. Companies between 25 and 250 employees rarely justify a full-time CIO, which is why fractional vCIO arrangements exist. The decisions in this checklist don’t disappear because the role is unfilled.
Work through the 10 items above and your first vendor conversation will be about 20 minutes shorter and considerably more useful. If you’d rather do it with someone who sits through these every week, get in touch and we’ll walk it with you, whether or not we turn out to be the right fit. No pitch.










