What is missing from your managed IT quote?
Two managed IT proposals can carry the same monthly price and cover completely different things. Open the quote in front of you, work through 22 checks, and see a clarity score plus the exact questions to send back before you sign. Built for Greater Toronto Area businesses by IT Rapid Support in Vaughan.
Scope & support
Does it state whether help desk support is unlimited, or capped at a number of hours, tickets or users?
Does it define what 24/7 means — engineers who can fix things, or a service that takes a message?
Are on-site visits included, and does it say how many and how quickly someone attends?
Is it explicit about what is being priced — every user, endpoint, server, site and network device — and what is excluded?
Does it say whether dealing with your other vendors — internet provider, phone system, line-of-business software — is included?
Security inclusions
Does it name multi-factor authentication as included — deployed and enforced, not merely available?
Does it name the endpoint security product, and say whether the licence sits inside the monthly fee?
Does it commit to patching on a stated schedule, and say whether third-party applications are included?
Does it include email authentication — SPF, DKIM and DMARC configured and moved to an enforcing policy?
Does it say who is watching security alerts outside business hours, and what they are allowed to do about one?
Does it say whether responding to a security incident is covered, or billed separately as project work?
Is security awareness training or phishing simulation named as included, or is it an add-on?
Backup & recovery
Does it state exactly what is backed up — servers, endpoints, and your Microsoft 365 data?
Does it commit to test restores — how often they run, and whether you are shown the result?
Does it put numbers on recovery — how much data you could lose, and how long you would be down?
Ownership & exit
Does it say who owns the Microsoft 365 tenant and holds the global administrator credentials — you or the provider?
Does it say you receive the documentation — network diagram, asset inventory, credentials — and in what format if you leave?
Does it say who holds your backup data, and how you get it back if the relationship ends?
Does it set out the term, the notice period, whether it auto-renews, and any early-termination charge?
Commercial terms
Is the line drawn between covered work and project work — migrations, new sites, hardware, licences?
Does it say how and when the monthly price can change?
Does it state the onboarding fee, how long onboarding takes, and what it covers?
How the score is built
Each of the 22 items carries a weight from 2 to 4 based on how expensive its absence tends to be after signing. Something written clearly costs nothing. Something mentioned without specifics costs half the weight, because a loose clause is still an argument you can have. Something absent costs the full weight. The points you keep, out of a possible 69, become a clarity score from 0 to 100.
The weights are ours and they are printed next to every item, so you can disagree with them. The heaviest items — help desk caps, what 24/7 means, MFA enforcement, endpoint licensing, backup scope, restore testing and who owns your Microsoft 365 tenant — are the ones that most often turn into an unexpected invoice or a painful exit.
The list itself comes from three places: the line-by-line inclusion matrix we publish on our own plans page, the questions we tell buyers to get in writing before signing with anybody, and the gaps we keep finding in agreements when businesses move to us from another provider. One item cites our own measurement: in a DNS scan of 479 GTA business domains in August 2026, 52.6% published a DMARC record but only 20.7% had it set to block forged mail — the full dataset is published here.
What this is not
It scores a document, not a company. A capable provider can write a thin proposal, and a polished proposal is no guarantee of good delivery. A low score means you cannot yet compare this quote with another one — not that you should walk away.
It is also not a legal review. If the agreement carries meaningful liability, indemnity or data-protection obligations, have a lawyer read it. This checklist covers the operational and commercial detail that decides what you actually get for the monthly fee.
Before you sign, also worth reading
What managed IT actually costs
Pricing models, the real drivers behind a monthly fee, and where quotes are made to look cheaper than they are.
Read the cost guideOur plans, line by line
Eighteen capabilities across three plans, written out in full, plus how the monthly price is put together.
See the inclusion matrixFree IT risk calculator
Fourteen weighted control areas scored in your browser, with your weakest points ranked and explained.
Score your own postureQuote checker FAQs
What does this managed IT quote checker do?
It walks you through 22 things that should be written into a managed IT or MSP proposal — help desk caps, what 24/7 actually means, on-site visits, MFA and endpoint protection, patching, email authentication, out-of-hours monitoring, incident response, backup scope and restore testing, recovery objectives, who owns the Microsoft 365 tenant, documentation and backup data on exit, term and auto-renewal, project boundaries, price changes and onboarding. For each one you mark whether it is in writing, vague, or absent. You get a clarity score out of 100 and a prioritised list of questions to send back to the provider.
Do I have to upload my contract or quote?
No. The tool never asks for the document, your company name, your email address or the provider’s name. You read your quote yourself and answer 22 yes/vague/no questions. The scoring runs entirely in your browser, nothing is transmitted to IT Rapid Support or anyone else, and your answers disappear when you close the tab.
Does a low score mean the provider is bad?
No, and it is important not to read it that way. The score measures the document, not the company. Plenty of capable providers write thin proposals, and a polished proposal is not proof of good delivery. What a low score tells you is that you cannot yet compare this quote against another one, and that several things which determine your real cost have not been agreed in writing.
Should I use this on an IT Rapid Support quote too?
Yes. The checklist is deliberately written to apply to any managed IT provider in the Greater Toronto Area, including us. If a proposal from IT Rapid Support does not answer one of these items, ask us the same question and we will put the answer in writing.
Why does email authentication appear in a quote checklist?
Because it is the clearest example of an item that gets marked complete without being finished. In our own DNS scan of 479 Greater Toronto Area business domains in August 2026, 52.6% published a DMARC record but only 20.7% had a policy that actually blocks forged mail. A provider can truthfully say DMARC is in place while spoofed invoices still land in your customers’ inboxes, which is why the quote should specify an enforcing policy and ongoing monitoring rather than just configuration.
How were the 22 items chosen?
They come from the inclusion matrix we publish on our own managed IT plans page, the seven questions we tell buyers to get in writing before signing with anyone, and the areas where scope is most often left undefined in the agreements we see when businesses switch to us. Each item is weighted by how much its absence tends to cost after signing, not by how difficult it is to answer.
Comparing two providers?
Run both quotes through the checker and compare the scores, not the prices. If you want a third proposal to measure them against, IT Rapid Support is in Vaughan and covers Toronto and the wider GTA.