I'm looking for a managed service provider in the Chicago area that offers transparent, predictable pricing instead of a low base fee followed by vague "additional services billed at prevailing rates" charges. I'm willing to pay more for reliable support and responsive people, but I want to understand the full scope and likely costs up front. PCI compliance may also be relevant to us, possibly at Level 2, though I'm still confirming the details. We would have someone internally as the main point of contact, but we'd need an MSP to handle areas such as networking, security, cloud services, backups, and larger projects.
4 Answers
The biggest factor is defining the scope before comparing quotes. Spell out your number of users and devices, servers and network equipment, cloud applications, backup and retention requirements, security expectations, compliance obligations, support hours, and project needs. The more standardized your technology stack is, the easier it is for an MSP to offer predictable pricing. Also look for a provider familiar with your industry and its compliance requirements.
You may be better suited to a co-managed arrangement than a traditional full-service help desk. Look for pricing based on endpoints or users, with day-to-day support separated from infrastructure, security, and project work. Some providers include a discounted block of project hours each month or year, which makes larger upgrades easier to budget and avoids treating every improvement as an unexpected billable add-on.
We do have someone on staff who can act as the primary contact, but they aren’t equipped to handle advanced networking and infrastructure work. A co-managed or flexible full-service model could work if the responsibilities are clearly defined.
For a very small organization, an MSP can be a good fit. Once the business grows, compare the total cost against building internal IT and hiring specialists for specific projects. MSP staff turnover can affect continuity, so ask how accounts are staffed, who covers vacations, how projects are documented, and whether you’ll have a consistent escalation path.
When evaluating providers, ask for a sample agreement and a list of exactly what is included: onboarding, after-hours support, onsite visits, monitoring tools, antivirus and security services, Microsoft or other cloud administration, backups, compliance assistance, and project labor. Ask them to describe common items that trigger extra charges. Several Chicago and Midwest providers advertise flat-rate or all-inclusive plans, but you’ll still want references and a written definition of “included.”

That makes sense. PCI compliance is probably relevant for us, possibly Level 2, so I’ll include that in the requirements and verify the exact classification before requesting revised proposals.