How to Evaluate an IT Company in Los Angeles: Criteria, Scorecard, and Questions to Ask

Best IT companies in Los Angeles

The best way to pick an IT company in Los Angeles is to score a short list against the same written criteria, in the same order, and to make every provider answer the same ten questions. This page is that scorecard. It covers the ten criteria that actually separate one LA managed service provider (MSP) from another, how much weight each one deserves, the questions that force a specific answer, the red flags worth walking away from, and what the market charges.

Disclosure: Be Structured Technology Group publishes this page, and we are one of the companies you might be evaluating. We have not ranked ourselves against anyone here, and we do not name other providers. The criteria below are the ones we would want a buyer to hold us to. Use them on us too.

Start by naming what you are buying

Three different purchases get called “IT support” in Los Angeles, and they have different vendors, different prices, and different failure modes.

  • Fully managed IT. The provider owns the help desk, monitoring, patching, security, backups, and vendor management for a flat monthly fee. This is the right shape when you have no internal IT staff.
  • Co-managed IT. You keep an internal person or team and buy the parts they cannot cover alone: after-hours coverage, a security stack, escalation engineering, documentation. The scope split is what makes or breaks this one, so get it in writing.
  • Project work. A network build, an office move, a Microsoft 365 migration, a cabling job. Priced per project, no ongoing obligation on either side.

Deciding this before your first call is what keeps you from paying for coverage you do not need, and it narrows the field immediately. A provider who cannot tell you which of the three they are best at is telling you something.

The ten criteria for evaluating an LA MSP

Ordered by how often they turn out to be the thing that mattered. Each one names what to ask and what a real answer sounds like.

  1. Written response commitment, by severity. Ask: what is your guaranteed response time for a critical, business-down issue, and where does that number appear in the contract? A real answer names a severity scale, a target for each tier, and the page of the agreement it is written on. A weak answer is a single number quoted verbally with nothing behind it, or a “typical” response time, which is an average and not a commitment.

  2. On-site coverage for your actual address. Los Angeles is a drive-time problem, not a map problem. Ask: where are your engineers physically based, how long does it take one of them to reach my office at rush hour, and how many site visits are included in the monthly fee? A provider with no LA staff can still deliver good remote support, but they cannot put hands on a failed switch in your suite.

  3. The security stack, named by product. Ask: which endpoint detection and response (EDR) product do you deploy, who watches its alerts and at what hours, what identity controls come standard, and is any of it an upsell? Named products can be researched. “Enterprise-grade security” cannot.

  4. Who holds the administrative credentials, and where. Ask: which accounts will you hold in my tenant, are they named accounts or shared, is privileged access behind multi-factor authentication, and do I get a copy of the credential store? The answer tells you what an exit looks like before you are in one.

  5. Documentation ownership. Ask: what documentation do you produce about my environment, how often is it updated, and do I get an export on request during the contract, not just at the end of it? Documentation you can only see through their portal is documentation you do not own.

  6. Contract term, notice period, and exit terms. Ask: what is the initial term, does it auto renew, how much notice do I owe, and what exactly do you hand over on the last day? Get the offboarding obligations written into the agreement you sign, because that is the only moment you have leverage over them.

  7. Pricing model, and the list of exclusions. Ask for the flat per-user or per-device rate, then ask for the list of work that falls outside it. Projects, after-hours work, hardware, third-party licensing, and on-site visits are the usual exclusions. A provider who says nothing is excluded has not read their own agreement.

  8. Compliance experience that matches your obligations. A law firm, a medical practice, a CPA firm, and a defense subcontractor all have different homework. Ask which of your specific frameworks they have supported, and how they describe their role. The honest framing is that a provider helps you meet requirements and does not issue certifications, and any provider who claims to certify you is describing something that does not exist.

  9. References at your size, in your industry. Ask for three clients in your vertical within roughly your headcount, and call them. Ask the references one question that matters: what happened the last time something went badly wrong? Awards and directory listings are secondary signals. A client who will pick up the phone is a primary one.

  10. Bench depth and after-hours reality. Ask: how many engineers do you employ, who answers at 2 a.m., is that person an employee or an answering service, and what happens when your senior engineer is on vacation during my outage? Small teams can be excellent, but you should know the size of the bench you are buying.

How to weight the criteria

Not every criterion deserves the same vote. The weights below are a starting point for a 10 to 250 person business with no internal IT team. Shift them to your situation: if you already run a compliance program, criterion 8 goes up; if your staff is fully remote, criterion 2 goes down.

Criterion Weight Why it carries that weight
1. Written response commitment 15 It is the only part of service quality you can enforce.
2. On-site coverage for your address 10 Remote support cannot replace a hardware failure visit.
3. Named security stack 15 The largest single difference in outcome between providers.
4. Credential custody 10 Determines whether you can ever leave cleanly.
5. Documentation ownership 10 Same reason, and it shortens every future onboarding.
6. Contract term and exit terms 10 Cheap to negotiate now, expensive to fix later.
7. Pricing model and exclusions 10 Surprise invoices are the most common source of a bad relationship.
8. Compliance experience 10 Situational. Raise it if you are regulated, lower it if you are not.
9. References at your size 5 Confirms the rest; rarely changes a decision on its own.
10. Bench depth and after-hours 5 Matters most when something breaks on a holiday weekend.
Total 100

The evaluation scorecard

Score each provider 1 to 5 on every criterion, multiply by the weight, and add it up. Fill one column per provider and do it on the same day, while the calls are fresh.

Criterion Weight Score (1 to 5) Weighted Evidence you were given
Written response commitment 15 Contract clause number
On-site coverage for your address 10 Engineer location, drive time quoted
Named security stack 15 EDR product name, who monitors it
Credential custody 10 Named vs shared accounts, export policy
Documentation ownership 10 Sample document, export on request
Contract term and exit terms 10 Term, notice period, offboarding clause
Pricing model and exclusions 10 Rate card plus written exclusion list
Compliance experience 10 Frameworks named, role described
References at your size 5 Three names, three phone calls made
Bench depth and after-hours 5 Engineer headcount, who answers overnight
Total 100

Two practical rules. A score of 1 or 2 on criterion 1, 3, or 4 should disqualify a provider no matter how the total comes out, because those three are the ones you cannot repair later. And if two providers land within about 5 points of each other, the scorecard has told you they are equivalent; decide on the people you would be working with.

Ten questions to ask any LA MSP

Ask these in the first meeting, in this order, and write down the answers verbatim. The value is in the specificity of the reply, not the reply itself.

  1. What is your guaranteed response time for a business-down issue, and which clause of the agreement contains it?
  2. Where are your engineers based, and how long is your on-site response to my address during business hours?
  3. Which EDR product do you deploy, who reviews its alerts, and during what hours?
  4. Which administrative accounts will you hold in my Microsoft 365 or Google Workspace tenant, and are they named to individuals?
  5. What documentation do you keep about my environment, and can I export it on request while we are still under contract?
  6. What is the term, what is the notice period, and what precisely do you hand over on the last day?
  7. What work falls outside the flat monthly fee?
  8. Which compliance frameworks have you supported for clients like me, and how do you describe your role in them?
  9. Can you give me three references in my industry at roughly my headcount?
  10. Who answers the phone at 2 a.m., and are they your employee?

Red flags

  • No written service level, at any severity. If the response commitment lives only in the sales conversation, it does not exist.
  • Refusal to name the security products. Every provider uses specific tools. Declining to name them usually means the stack is thinner than the pitch.
  • Shared administrative accounts. A single admin login used by the whole provider team means no audit trail and no clean revocation on the day you leave.
  • Vague or missing offboarding language. Ask to see it before you sign. Providers who intend to hand over cleanly have already written it down.
  • A promise to make you compliant or to certify you. An MSP supports readiness. Certification bodies and assessors certify, and they are not your MSP.
  • Pricing that cannot be explained without a discovery call. A range with the variables behind it is reasonable. A total refusal to talk about money is a preview of the invoices.
  • No references you can call. Confidentiality is a real constraint, but a provider with no client willing to speak has a pattern, not a policy.
  • Break-fix billing sold as managed services. Hourly billing means the provider earns more when your systems fail. That is the incentive you are trying to leave behind.

What it costs, so you can sanity check a quote

Most Los Angeles small and mid-size businesses pay between $125 and $300 per user per month for fully managed IT, with the position inside that band set by seat count, security tier, compliance obligations, and how much on-site work you need. Our full breakdown of what moves the number is in the Los Angeles managed IT services pricing guide. A quote far below that band usually excludes the security stack; a quote far above it usually includes project work you have not scoped yet. Either can be right, so ask which it is.

How Be Structured answers these questions

Since we published the criteria, here is where we stand on them, in the same order. We have been a Los Angeles company since 2007, working out of 500 S. Grand Avenue in downtown, so criterion 2 is answered by the address rather than by a claim. We are a managed security services provider as well as an MSP, so the security stack, the monitoring, and the identity controls come from the same team that runs the help desk. On compliance, we help clients meet requirements and prepare for assessments; we are not an official certifying body or auditor, and we describe our role as support and readiness. On credentials and documentation, ask us for the export policy in writing, the same way you should ask anyone else.

If you would rather compare us against a provider you already have, the provider handover guide covers what to demand from an outgoing MSP.

➤ Get Your Free IT Assessment

Frequently Asked Questions About Choosing an IT Company in Los Angeles

How should I compare IT companies in Los Angeles?

Score them against the same written criteria on the same day. The ten that matter most are the written response commitment, on-site coverage for your address, the named security stack, who holds administrative credentials, documentation ownership, contract and exit terms, the pricing model and its exclusions, compliance experience, references at your size, and bench depth. Weight them, score each provider 1 to 5, and multiply. The scorecard on this page is the format we would want to be judged by.

What questions should I ask an IT company before signing a contract?

Ten of them, and the value is in how specific the answers are: the guaranteed response time and the clause it lives in, where the engineers are based and the on-site response time to your address, which EDR product they deploy and who watches it, which admin accounts they will hold in your tenant, what documentation you can export while under contract, the term and notice period and what they hand over on the last day, what falls outside the flat fee, which compliance frameworks they have supported, three references in your industry, and who answers the phone at 2 a.m.

How much do IT companies in Los Angeles charge?

Most LA small and mid-size businesses pay between $125 and $300 per user per month for fully managed IT. Where you land in that band depends on seat count, the security tier, compliance obligations, and how much on-site work is included. Break-fix hourly billing looks cheaper on a quiet month and is usually more expensive across a year, because the provider earns more when things break. The variables behind the range are broken down in our managed IT services pricing guide.

What is the difference between an IT company and a managed service provider?

An IT company is any business that sells technology services, from a solo consultant to a national integrator. A managed service provider takes ongoing responsibility for your whole environment under a flat monthly fee: monitoring, help desk, patching, security, backups, and vendor management. The distinction that matters to a buyer is the incentive. An hourly provider is paid more when systems fail; an MSP is paid the same either way, so keeping things running is the profitable outcome.

What are the biggest red flags when evaluating an LA MSP?

Four of them are disqualifying on their own: no written response commitment at any severity level, refusal to name the security products they deploy, shared administrative accounts instead of named ones, and missing or vague offboarding language in the agreement. Add to that any provider who promises to make you compliant or to certify you, since an MSP supports readiness and does not issue certifications.

Should I hire a local Los Angeles IT company or a national provider?

It depends on whether you need hands in your office. A national provider with a strong remote practice can run your help desk well. What they usually cannot do is reach your suite in an hour when a switch fails, a cable run is damaged, or a new office needs building out. Ask any provider where the engineer who would come to your address actually sits, and how long that drive takes at 4 p.m. on a Wednesday.

How long does it take to choose and onboard a new IT provider?

Plan on two to four weeks to evaluate and 30 to 90 days to complete a handover from an existing provider. The evaluation is short because the scorecard is short. The handover is longer because it involves credential transfer, documentation, licensing, DNS and domain control, backup verification, and a monitoring cutover. Our provider handover guide sets out the 30, 60, and 90 day sequence.

Does the number of awards or online reviews tell me anything useful?

They are secondary signals, useful for confirming a shortlist and close to useless for building one. Awards say a company entered an awards program. Reviews say something about the average client experience but rarely about how a provider behaves during an outage or a breach. A reference at your size and in your industry who will take your call is worth more than either.

About Chad Lauterbach

Founder & CTO at Be Structured Technology Group, Inc., a Los Angeles-based provider of Managed IT Services for small businesses. I desire to help small businesses better utilize technology by assisting in high-level planning to make sure that new systems will benefit them both operationally and financially. I am careful to implement and support systems using industry best practices. I am a CMMC Registered Practitioner Advanced (RPA) with the Cyber AB.