OKTO Solutions
Buyer's guide

How to choose a managed IT provider in Quebec: 12 criteria

Hiring a first IT provider, or switching IT providers, is a decision you make on criteria, not on a feeling. This guide gives the 12 points to check before signing a managed IT services agreement in Quebec, the exact question to ask each provider, and the red flag to watch for in the answer. It is written to be useful to you even if you do not choose OKTO Solutions.

Choosing a managed IT provider in Quebec, taking notes on a client's needs
Definition

What is a managed IT services provider, and why choose one in Quebec?

A managed IT services provider, often called an MSP, is a company that takes charge of an organization's IT on an ongoing basis, for a predictable monthly amount, instead of case by case whenever something breaks. It handles user support, monitoring of workstations and servers, updates, security, backups and planning.

In Quebec, that choice has become structural for three reasons. Law 25 imposes precise obligations on the protection of personal information that few small businesses can carry alone. IT security now demands continuous monitoring and a fast reaction, not just an antivirus installed once. And hiring qualified technicians remains hard, in the regions as much as in the large cities.

The 12 criteria below exist so you can compare providers on the same basis, before signing anything. They apply just as much to a first contract as to switching IT providers.

In short

What to check before signing an IT services agreement

If you only have ten minutes, check these eight points. The rest of the page explains each one in detail.

A written service commitment, with a clear definition of what counts as an emergency
A real presence on your territory, not just an address in a directory
Service in your language, during every hour you work
A clear position on Law 25 and on the country where your data is hosted
Cybersecurity and backup included in the service, not sold after you sign
Verifiable public reviews and references you are allowed to call
A contract that reads clearly end to end, with no punitive exit clause
The documentation of your environment, which belongs to you and follows you if you leave
The 12 criteria

The 12 criteria for comparing managed IT providers

Every criterion is laid out the same way: what it is, why it matters, the exact question to ask the provider, and the red flag to watch for in the answer.

01

Response time and the service agreement

What it is. The service agreement, or SLA, states in writing how fast the provider picks up your call, how fast the work starts, and what counts as an emergency.

Why it matters. Without a written definition, a promise to answer quickly means nothing. A cash register frozen on a Friday afternoon and a flickering screen should not carry the same priority.

The question to ask"Show me your priority levels and the response time you commit to for each one."

Red flag. A response time promised out loud that the provider will not write into the agreement.

02

Local presence and on-site service

What it is. The ability to send someone to your site when a problem cannot be solved remotely, and how often they visit when nothing is broken.

Why it matters. A dead server, a burned-out switch or an office move are not fixed from a keyboard. The real distance between the provider and you decides what happens that day.

The question to ask"Where does the person who would come to our site start from, and how many clients do you already have in our region?"

Red flag. A long list of cities on a website, without a single client or a single person on the ground.

03

Service in your language

What it is. Being able to speak, write and read your reports in English or in French, from the first call through to the technical documentation.

Why it matters. Your employees describe a problem in their own words. A service desk that answers in one language only makes every exchange longer and loses information along the way.

The question to ask"Do the person who answers the phone, the person who writes the reports and the person who travels all work in our language?"

Red flag. Phone service in your language, but a portal, reports and alerts in another one.

04

Partner status and verifiable certifications

What it is. Official partnerships with software vendors, Microsoft first among them, and certificates you can check yourself at the source.

Why it matters. A partnership opens the door to vendor support when a problem goes beyond the provider. A logo pasted on a website proves nothing on its own.

The question to ask"Under exactly what name are you registered with Microsoft, and where can I check it myself?"

Red flag. Partner logos with no registered name, or a partnership level announced on the site that matches nothing public.

05

Law 25 compliance and where your data lives

What it is. What the provider actually does about the protection of personal information: access management, encryption, logging, an incident register, and the country where your data and your backups are hosted.

Why it matters. In front of the Commission d'accès à l'information, the responsibility stays yours. A provider who cannot answer leaves you carrying the risk alone.

The question to ask"In what country are our data and our backups hosted, and what exactly do you do the day a privacy incident happens?"

Red flag. A generic answer along the lines of "we are compliant", without naming a single measure or a single document.

06

Cybersecurity included in the service

What it is. Protection for workstations and servers, multi-factor authentication, email filtering and alert monitoring, included in the package rather than sold on the side.

Why it matters. Protection billed as an extra often ends up never being turned on. And a security tool nobody watches protects nobody.

The question to ask"Who looks at the security alerts, at what hours, and what happens when an alert fires at 2 a.m.?"

Red flag. An antivirus presented as complete cybersecurity, with no monitoring and no incident response.

07

Backup and disaster recovery that are actually tested

What it is. Copies of your data taken automatically, kept somewhere other than your own servers, and above all restored for real at regular intervals.

Why it matters. A backup that has never been restored is not a backup, it is an assumption. Most bad surprises show up on the day of the restore.

The question to ask"When did you last run a restore test at a client, and can you show me the report?"

Red flag. A provider who talks about Microsoft 365 data as if backup were already included in the Microsoft subscription.

08

A contract and an invoice you can read

What it is. Knowing what the monthly amount covers, what is billed on top, how the amount moves when you hire someone, and how the agreement ends.

Why it matters. Bad relationships with a provider almost always start with a surprise invoice or with an exit clause nobody had read.

The question to ask"Give me three examples of work that is not covered by the package, and tell me the minimum term."

Red flag. A long term, automatic renewal and an exit penalty, presented as a simple formality.

09

Verifiable client reviews and references

What it is. Public reviews attached to real names, and current clients you can call before you sign.

Why it matters. A public rating puts the provider's reputation on the line. An anonymous testimonial on a web page commits nobody.

The question to ask"Can you give me two clients my size, in my sector, that I can call this week?"

Red flag. No public review profile at all, or references that go back several years.

10

Strategic guidance and the IT master plan

What it is. Someone who looks at your IT over three years: master plan, budget, equipment replacement, security priorities. That is the IT director role, rented part time, usually called a vCIO.

Why it matters. Without that role, you pay to put out fires and the same fires come back. It is also what lets you plan spending instead of absorbing it.

The question to ask"How often do you meet us when nothing is broken, and what does a master plan you have already delivered look like?"

Red flag. No meeting on the calendar outside of emergencies.

11

The provider's tooling and who owns your documentation

What it is. The tools the provider uses to run your environment: monitoring, tickets, passwords, documentation. And what belongs to you in all of that.

Why it matters. The day you change providers, the quality of the documentation decides whether the transition takes two weeks or six months. A provider that builds its own tools can also fix a problem without waiting in a vendor's queue.

The question to ask"If we left in a year, what exactly do we receive, in what format, and how fast?"

Red flag. Documentation that lives in one technician's head, or a refusal to hand back administrative credentials.

12

The ability to support automation and artificial intelligence

What it is. The provider's ability to go past break-fix: automating repetitive tasks, framing how artificial intelligence tools get used, and building a small tool when nothing on the market does the job.

Why it matters. Your employees already use artificial intelligence tools, with or without guardrails. And a lot of the time lost in a small business goes to manual tasks nobody has taken the time to automate.

The question to ask"Have you already automated a process at a client, and how do you frame the use of artificial intelligence with company data?"

Red flag. Talk about artificial intelligence without a single example delivered at a client.

The meeting

The questions to ask an IT provider in the interview

The 12 criteria can be covered in a one-hour meeting. Here are the questions in the order that works best, from the most concrete to the most committing. Ask them word for word to each of the two or three providers you meet.

Who will answer when my employee calls, and where does that person work?
What response time do you commit to, and how do you classify emergencies?
What do you do during the first 90 days at a new client?
What tools do you use to monitor and document our environment?
In what country are our data and our backups hosted?
When did you last test a restore?
What is not included in the package?
How often do you meet us when everything is fine?
What happens when the person who knows our file is away?
If we leave, what do we get back and how fast?
Meeting a managed IT services provider, walking through an infrastructure audit
Warning signs

The red flags that should make you hesitate

None of these signs is fatal on its own. Two or three of them together, in the same meeting, are reason enough to look elsewhere.

  • The provider talks mostly about its own tools and never about your operations.
  • No written response commitment, or one that does not tell an emergency apart from an ordinary request.
  • Cybersecurity and backup are presented as options to add later.
  • Nobody can name the last time a restore was tested.
  • The contract renews on its own and leaving it costs a lot.
  • No public reviews, or references you are not allowed to call.
  • The documentation of your environment stays the provider's property.
  • One person knows your file and there is no backup when that person is away.
Method

How to switch IT providers in four steps

Switching IT providers takes preparation. Here is the order that avoids bad surprises, whether you choose OKTO Solutions or someone else.

  • Take inventory of what you have

    Count the workstations, servers, licences, printers, line-of-business software and accounts. Write down who manages what today. Without that inventory, two quotes are never comparable, because they do not cover the same thing.

  • Write down what you expect

    One page is enough: your real business hours, the systems that cannot go down, your compliance obligations, how long an interruption you can absorb, and the budget you want to make predictable.

  • Meet two or three providers with the same checklist

    Ask the 12 questions above, in the same order, to each one. Take notes during the meeting. The gaps jump out when the questions are identical.

  • Plan the transition before you sign

    Ask for the plan for the first 90 days: what gets taken over, in what order, who talks to the outgoing provider, and when your employees see a change. An improvised transition is what hurts, not the change itself.

Transparency

How OKTO Solutions measures up on these criteria

In the interest of transparency, here is what can be verified on our side, and what cannot be yet.

Head office in Trois-Rivières, in the Mauricie region, with clients in Quebec City, Rouyn-Noranda, Lavaltrie, Laval, Mont-Tremblant, Baie-Comeau and Lévis
A 5.0 rating across 34 public Google reviews
Microsoft Partner
Azure Trusted Signing code signing certificate, verified publisher "OKTO Solutions": our applications install without a Windows security warning
Four tools built in house instead of resold: OKTO RMM, OKTO PSA, OKTO Sign and OKTO Flux
A team that has supported more than 100 organizations over more than 15 years
Service in English and in French, from the first call through to the reports

What we do not post: no response time in numbers until it has been measured over a full period, and no office in a city where we do not have one. On the South Shore and in Montreal, we work remotely with planned visits, from Trois-Rivières. Our one commitment on timing: we answer the phone in under 2 minutes.

Frequently asked questions

Frequently asked questions about choosing a managed IT provider

There is none. MSP is short for managed services provider. In Quebec you will also see managed IT services, outsourced IT, and in French infogérance or impartition informatique. One warning if you search the web: the acronym MSP on its own mostly returns results that have nothing to do with IT.

Two or three is enough, as long as you ask them exactly the same questions. Past that, the meetings blur together and the decision drags. What makes the difference is not how many providers you see, it is having written down your expectations before the meetings.

By planning the transition before you sign. The incoming provider should describe the first 90 days: taking over the documentation and the credentials, installing its monitoring, validating the backups, then moving the support over. Most bad transitions come from an improvised handover, not from the change itself.

It depends on your size and on your systems. Many small and mid-sized businesses hand everything to a provider. Those that already have someone in house often keep a co-managed model: the internal person handles the line-of-business applications and the day-to-day, while the provider covers security, monitoring, servers and vacation periods.

Law 25 requires, among other things, naming a person responsible for the protection of personal information, keeping a register of confidentiality incidents, notifying the people concerned and the Commission d'accès à l'information when an incident carries a risk of serious harm, and framing how information is shared outside Quebec. An IT provider does not take those obligations off your hands, it equips you to meet them.

Yes for everything that is handled remotely, which is most requests. Distance costs you the day someone has to be there in person: hardware failure, network, a move, a new office. The right question is not the distance in kilometres, it is who travels, from where, and how often.

At a minimum: the list of equipment and services covered, the priority levels and the response times attached to them, the service hours, what is billed on top, each party's responsibilities, how the agreement ends, and what you are handed at that point.

Next step

Compare us with this checklist

Take these 12 questions and put them to us. We answer in one meeting, with no commitment, and we will tell you straight when another model would suit your situation better.

Write to us through the contact page or call 450 231-3836. You can also read why choose OKTO Solutions or compare the Base, Standard and Complete plans.

Our territory

Where we deliver this service

This service is delivered across Quebec. Our office is in Trois-Rivières. We work remotely and travel on site when the mandate calls for it.