The best way to pick an IT company in Los Angeles is to score a short list against the same written criteria, in the same order, and to make every provider answer the same ten questions. This page is that scorecard. It covers the ten criteria that actually separate one LA managed service provider (MSP) from another, how much weight each one deserves, the questions that force a specific answer, the red flags worth walking away from, and what the market charges.
Disclosure: Be Structured Technology Group publishes this page, and we are one of the companies you might be evaluating. We have not ranked ourselves against anyone here, and we do not name other providers. The criteria below are the ones we would want a buyer to hold us to. Use them on us too.
Start by naming what you are buying
Three different purchases get called “IT support” in Los Angeles, and they have different vendors, different prices, and different failure modes.
- Fully managed IT. The provider owns the help desk, monitoring, patching, security, backups, and vendor management for a flat monthly fee. This is the right shape when you have no internal IT staff.
- Co-managed IT. You keep an internal person or team and buy the parts they cannot cover alone: after-hours coverage, a security stack, escalation engineering, documentation. The scope split is what makes or breaks this one, so get it in writing.
- Project work. A network build, an office move, a Microsoft 365 migration, a cabling job. Priced per project, no ongoing obligation on either side.
Deciding this before your first call is what keeps you from paying for coverage you do not need, and it narrows the field immediately. A provider who cannot tell you which of the three they are best at is telling you something.
The ten criteria for evaluating an LA MSP
Ordered by how often they turn out to be the thing that mattered. Each one names what to ask and what a real answer sounds like.
-
Written response commitment, by severity. Ask: what is your guaranteed response time for a critical, business-down issue, and where does that number appear in the contract? A real answer names a severity scale, a target for each tier, and the page of the agreement it is written on. A weak answer is a single number quoted verbally with nothing behind it, or a “typical” response time, which is an average and not a commitment.
-
On-site coverage for your actual address. Los Angeles is a drive-time problem, not a map problem. Ask: where are your engineers physically based, how long does it take one of them to reach my office at rush hour, and how many site visits are included in the monthly fee? A provider with no LA staff can still deliver good remote support, but they cannot put hands on a failed switch in your suite.
-
The security stack, named by product. Ask: which endpoint detection and response (EDR) product do you deploy, who watches its alerts and at what hours, what identity controls come standard, and is any of it an upsell? Named products can be researched. “Enterprise-grade security” cannot.
-
Who holds the administrative credentials, and where. Ask: which accounts will you hold in my tenant, are they named accounts or shared, is privileged access behind multi-factor authentication, and do I get a copy of the credential store? The answer tells you what an exit looks like before you are in one.
-
Documentation ownership. Ask: what documentation do you produce about my environment, how often is it updated, and do I get an export on request during the contract, not just at the end of it? Documentation you can only see through their portal is documentation you do not own.
-
Contract term, notice period, and exit terms. Ask: what is the initial term, does it auto renew, how much notice do I owe, and what exactly do you hand over on the last day? Get the offboarding obligations written into the agreement you sign, because that is the only moment you have leverage over them.
-
Pricing model, and the list of exclusions. Ask for the flat per-user or per-device rate, then ask for the list of work that falls outside it. Projects, after-hours work, hardware, third-party licensing, and on-site visits are the usual exclusions. A provider who says nothing is excluded has not read their own agreement.
-
Compliance experience that matches your obligations. A law firm, a medical practice, a CPA firm, and a defense subcontractor all have different homework. Ask which of your specific frameworks they have supported, and how they describe their role. The honest framing is that a provider helps you meet requirements and does not issue certifications, and any provider who claims to certify you is describing something that does not exist.
-
References at your size, in your industry. Ask for three clients in your vertical within roughly your headcount, and call them. Ask the references one question that matters: what happened the last time something went badly wrong? Awards and directory listings are secondary signals. A client who will pick up the phone is a primary one.
-
Bench depth and after-hours reality. Ask: how many engineers do you employ, who answers at 2 a.m., is that person an employee or an answering service, and what happens when your senior engineer is on vacation during my outage? Small teams can be excellent, but you should know the size of the bench you are buying.
How to weight the criteria
Not every criterion deserves the same vote. The weights below are a starting point for a 10 to 250 person business with no internal IT team. Shift them to your situation: if you already run a compliance program, criterion 8 goes up; if your staff is fully remote, criterion 2 goes down.
| Criterion | Weight | Why it carries that weight |
|---|---|---|
| 1. Written response commitment | 15 | It is the only part of service quality you can enforce. |
| 2. On-site coverage for your address | 10 | Remote support cannot replace a hardware failure visit. |
| 3. Named security stack | 15 | The largest single difference in outcome between providers. |
| 4. Credential custody | 10 | Determines whether you can ever leave cleanly. |
| 5. Documentation ownership | 10 | Same reason, and it shortens every future onboarding. |
| 6. Contract term and exit terms | 10 | Cheap to negotiate now, expensive to fix later. |
| 7. Pricing model and exclusions | 10 | Surprise invoices are the most common source of a bad relationship. |
| 8. Compliance experience | 10 | Situational. Raise it if you are regulated, lower it if you are not. |
| 9. References at your size | 5 | Confirms the rest; rarely changes a decision on its own. |
| 10. Bench depth and after-hours | 5 | Matters most when something breaks on a holiday weekend. |
| Total | 100 |
The evaluation scorecard
Score each provider 1 to 5 on every criterion, multiply by the weight, and add it up. Fill one column per provider and do it on the same day, while the calls are fresh.
| Criterion | Weight | Score (1 to 5) | Weighted | Evidence you were given |
|---|---|---|---|---|
| Written response commitment | 15 | Contract clause number | ||
| On-site coverage for your address | 10 | Engineer location, drive time quoted | ||
| Named security stack | 15 | EDR product name, who monitors it | ||
| Credential custody | 10 | Named vs shared accounts, export policy | ||
| Documentation ownership | 10 | Sample document, export on request | ||
| Contract term and exit terms | 10 | Term, notice period, offboarding clause | ||
| Pricing model and exclusions | 10 | Rate card plus written exclusion list | ||
| Compliance experience | 10 | Frameworks named, role described | ||
| References at your size | 5 | Three names, three phone calls made | ||
| Bench depth and after-hours | 5 | Engineer headcount, who answers overnight | ||
| Total | 100 |
Two practical rules. A score of 1 or 2 on criterion 1, 3, or 4 should disqualify a provider no matter how the total comes out, because those three are the ones you cannot repair later. And if two providers land within about 5 points of each other, the scorecard has told you they are equivalent; decide on the people you would be working with.
Ten questions to ask any LA MSP
Ask these in the first meeting, in this order, and write down the answers verbatim. The value is in the specificity of the reply, not the reply itself.
- What is your guaranteed response time for a business-down issue, and which clause of the agreement contains it?
- Where are your engineers based, and how long is your on-site response to my address during business hours?
- Which EDR product do you deploy, who reviews its alerts, and during what hours?
- Which administrative accounts will you hold in my Microsoft 365 or Google Workspace tenant, and are they named to individuals?
- What documentation do you keep about my environment, and can I export it on request while we are still under contract?
- What is the term, what is the notice period, and what precisely do you hand over on the last day?
- What work falls outside the flat monthly fee?
- Which compliance frameworks have you supported for clients like me, and how do you describe your role in them?
- Can you give me three references in my industry at roughly my headcount?
- Who answers the phone at 2 a.m., and are they your employee?
Red flags
- No written service level, at any severity. If the response commitment lives only in the sales conversation, it does not exist.
- Refusal to name the security products. Every provider uses specific tools. Declining to name them usually means the stack is thinner than the pitch.
- Shared administrative accounts. A single admin login used by the whole provider team means no audit trail and no clean revocation on the day you leave.
- Vague or missing offboarding language. Ask to see it before you sign. Providers who intend to hand over cleanly have already written it down.
- A promise to make you compliant or to certify you. An MSP supports readiness. Certification bodies and assessors certify, and they are not your MSP.
- Pricing that cannot be explained without a discovery call. A range with the variables behind it is reasonable. A total refusal to talk about money is a preview of the invoices.
- No references you can call. Confidentiality is a real constraint, but a provider with no client willing to speak has a pattern, not a policy.
- Break-fix billing sold as managed services. Hourly billing means the provider earns more when your systems fail. That is the incentive you are trying to leave behind.
What it costs, so you can sanity check a quote
Most Los Angeles small and mid-size businesses pay between $125 and $300 per user per month for fully managed IT, with the position inside that band set by seat count, security tier, compliance obligations, and how much on-site work you need. Our full breakdown of what moves the number is in the Los Angeles managed IT services pricing guide. A quote far below that band usually excludes the security stack; a quote far above it usually includes project work you have not scoped yet. Either can be right, so ask which it is.
How Be Structured answers these questions
Since we published the criteria, here is where we stand on them, in the same order. We have been a Los Angeles company since 2007, working out of 500 S. Grand Avenue in downtown, so criterion 2 is answered by the address rather than by a claim. We are a managed security services provider as well as an MSP, so the security stack, the monitoring, and the identity controls come from the same team that runs the help desk. On compliance, we help clients meet requirements and prepare for assessments; we are not an official certifying body or auditor, and we describe our role as support and readiness. On credentials and documentation, ask us for the export policy in writing, the same way you should ask anyone else.
If you would rather compare us against a provider you already have, the provider handover guide covers what to demand from an outgoing MSP.
➤ Get Your Free IT Assessment
