IT Provider Transition Checklist: A 30/60/90 Plan
A phase-by-phase plan for switching IT providers without a coverage gap: contract review and admin access first, sign before notice, parallel agents, a verified test restore, and a clean 90-day decommission.
Introduction
Most businesses do not leave an IT provider after one catastrophic failure. They leave because tickets sit for three days, nobody can explain what the backups protect, and the same problem returns with a new ticket number. Then the instinct is to send the termination email today and sort out the rest next week.
That is the most expensive mistake here. A rushed switch creates a coverage gap: the window where the outgoing provider has stopped investing and the incoming one has not been given the keys. That is where ransomware lands and where a failed backup goes unnoticed for six weeks. Everything below keeps that gap at zero days.
For the strategy behind this checklist, read our switching guide; for an outside read before you commit, start with a free IT assessment.
Why the Overlap Matters More Than the Notice Date
Nearly every transition horror story has one root cause: notice was given before a replacement was signed, and cooperation evaporated the moment it landed.
- Notice starts a countdown, not a partnership. After termination the outgoing provider owes you what the contract says in writing, nothing more.
- Documentation disappears first. Passwords, diagrams, and license records live in their tools, not yours.
- Monitoring stops silently. Agents get pulled, alerts stop routing, and nobody notices until something breaks.
- Backups are the worst place to find a gap. A job that stopped 40 days ago looks identical to one that ran last night, until you need it.
The fix takes discipline: sign the incoming provider before you give notice, and build in 30 days of deliberate overlap. Paying two providers for one month is cheap insurance.
Days 1 to 10: Read the Contract Before Anything Else
You cannot plan a timeline until you know what the paperwork requires. Pull the agreement and every amendment, then find five things.
- Notice period. 30, 60, and 90 days are all common. This number sets your entire calendar.
- Auto-renewal date. Many agreements renew unless notice lands inside a specific window. Miss it by a week and you are locked in for another term.
- Offboarding and data return clause. Is the provider obligated to hand over documentation, credentials, and configurations, and at what fee?
- License and hardware ownership. Firewalls, backup appliances, and Microsoft 365 seats often sit under the provider's name.
- Early termination penalties. Know the number before you negotiate.
Silence on offboarding is useful too: it means post-notice cooperation is voluntary, which raises the value of everything you collect first.
Days 1 to 10: Secure Your Own Access and Inventory What You Own
This is the step most companies skip, and it decides whether the rest is easy or painful. Before anyone knows you are shopping, confirm you hold independent administrative control of what you own.
- Global Admin on Microsoft 365 or Google Workspace: a break-glass account in a company mailbox, MFA enabled, credentials in your own password manager.
- Domain registrar. Registered to your company, accessible to you, auto-renew on. A lapsed domain takes down email and the website at once.
- DNS control. DNS is the lever that moves email and web traffic at cutover.
- Firewall and network gear. Local admin credentials, not just the provider's console.
- Line-of-business applications. Every ERP, EMR, or accounting system needs an owner-held admin account.
A healthy provider will not object. If yours does, you have just confirmed the decision.
The one-page inventory
Alongside access, write down what you have. This becomes the scope document behind every proposal:
- Endpoints and users, split by workstation, laptop, and server, including shared mailboxes.
- Locations, how they connect, and remote worker count.
- Applications that would stop the business if unavailable for a day.
- Compliance obligations: HIPAA, CMMC, PCI DSS, or cyber insurance requirements.
- Current tooling for antivirus, backup, monitoring, and email filtering, with renewal dates.
A provider that quotes confidently against unknown scope is guessing, and that guess becomes a change order later.
Days 10 to 25: Evaluate and Sign Before You Give Notice
Talk to two or three candidates, not eight, and give each the same inventory so proposals are comparable.
Questions that separate real answers from sales language
- What is included, and what is billed hourly? Unlimited support with a long exclusion list is not unlimited. Get the exclusions in writing.
- How are response and resolution targets measured? An SLA nobody reports against is a marketing sentence. Ask for a sample monthly report.
- Who owns the tools and licenses? If you leave in three years, do the agents, licenses, and documentation follow you?
- What does onboarding look like week by week? A provider who cannot describe their own transition process will improvise on yours.
- How are after-hours emergencies handled? Separate automated monitoring that runs continuously from human response during business hours with after-hours emergency escalation. Both matter; they are not the same thing.
Compare structures, not just monthly totals. Hourly break-fix billing rewards a provider when things break; a flat managed agreement rewards them when things do not. Our guides on how to choose an MSP and managed IT services pricing cover typical market structures.
Then sign. The countersigned agreement turns your new provider from a prospect into a party with obligations during the overlap.
Days 25 to 30: Discovery While the Outgoing Provider Is Still Responsible
This is the highest-leverage window in the timeline, and the one most companies waste. The outgoing provider is still under contract and has not been told.
- Network discovery scan of every subnet: device list, IPs, roles, firmware versions.
- Credential export into your own password manager, owned by a company account.
- Backup configuration review: what is protected, how often, where copies live, and the date of the last successful restore test.
- License and subscription audit with renewal dates and the billing account for each.
- Vendor contacts for the internet circuit, phone system, business software, and hardware.
- Open ticket snapshot so nothing in flight is dropped at handoff.
Every item captured here is one you never have to request from a provider with no reason left to answer.
Day 30: Written Notice and a Formal Handover Request
Send notice in the exact form the contract requires, to the address it names. Email alone is often insufficient. Keep it factual; you may need cooperation for another 30 days. Attach a handover request listing deliverables with a due date:
- Complete credential and documentation export
- Network diagrams and firewall configuration files
- Backup job configurations and recent restore verification records
- License keys, subscription assignments, and transfer instructions
- The exact date monitoring and support coverage ends
- A named technical contact for transition questions
A named contact turns a vague obligation into somebody's assignment.
Days 30 to 60: Tenant Ownership, Parallel Agents, and a Verified Backup
The technical work starts here, and the rule is add before you remove. Every new system goes in alongside the old one and is proven working before anything is decommissioned.
Transfer tenant ownership
- Move the Microsoft 365 or Google Workspace partner relationship to the incoming provider, or to direct billing.
- Reassign delegated administration and remove the outgoing provider's standing privileged access on a scheduled date.
- Point registrar and DNS recovery contacts at company mailboxes.
Deploy new agents in parallel
- Install the incoming provider's monitoring, patching, and endpoint security agents while the old ones still run.
- Coordinate the endpoint protection overlap so the two products do not fight. Two agents briefly is an annoyance. Zero agents over a weekend is an incident.
- Reconcile agent count against the inventory. A device without an agent is a device nobody is watching.
Stand up a new backup and prove it with a real restore
- Configure the new platform independently and keep the old one running until the new one is verified.
- Run an actual test restore: a file, a mailbox item, and a full server or virtual machine recovery. A green dashboard is not evidence. A restored file you can open is.
- Document recovery point and recovery time objectives against what the business can tolerate.
With internal IT staff, this is where a co-managed IT arrangement earns its keep, because your people know the quirks no scan will surface. Otherwise a full managed IT services engagement should absorb this as onboarding rather than bill it as a project.
Days 30 to 60: Schedule the Cutover With a Rollback Position
Pick a date, publish it, and define failure in advance. Cutovers go wrong less because something breaks than because nobody decided who could call it off.
- Schedule outside business hours and give staff a support contact for the first morning after.
- Sequence changes so reversible ones happen first and irreversible ones last.
- Shorten DNS TTLs for 48 hours on either side so a rollback propagates in minutes.
- Write the rollback plan down, including who can trigger it and the deadline for that call.
- Do not cancel old tooling on cutover day. Leave the outgoing backup and monitoring running until the new stack is clean for two weeks.
A transition is also the moment to close gaps the old arrangement tolerated: MFA everywhere, no shared administrator logins, and endpoint protection with real detection and response rather than legacy antivirus. Our cybersecurity services overview covers a defensible baseline.
Days 60 to 90: Decommission, Verify Coverage, Read the First Report
The last 30 days close the loop. Half-finished transitions leave orphaned access behind, and that is a breach vector.
- Remove old agents and confirm removal against the inventory, not a dashboard that only shows machines still checking in.
- Disable then delete orphaned admin accounts: service accounts, delegated partner access, VPN accounts, vendor-created local admins.
- Rotate every credential the outgoing provider held: firewall admin, switch and wireless passwords, service accounts, shared logins.
- Confirm full endpoint coverage for monitoring, patching, backup, and security. The one device with a gap is the one that bites you.
- Cancel old subscriptions only after new coverage is verified.
- Review the first monthly SLA report against the proposal: ticket volume, first-response time, resolution time, patch compliance, backup success rate.
That first report is your leverage moment. If the numbers do not match the sales conversation, raise it in month one while the relationship is easy to correct, not month nine after the pattern has set. Budget for one month of double coverage plus a contingency for what discovery uncovers.
Where to Start
- Find your contract and read the notice and auto-renewal clauses. Every other date depends on those two.
- Confirm you hold Global Admin on your own tenant and control of your domain registrar. If you do not, fix that before any other conversation.
- Get an independent read on your environment. Our free IT assessment takes a few minutes and produces a specific picture of coverage gaps.
Then work the phases in order: contract and access, selection and signature, discovery, notice, and only then migration. Reversing that order is what creates the gap. To map this against your renewal date, get in touch. LayerLogix brings 20+ years of experience and 100% Texas-based support to transitions across the state.
Frequently Asked Questions
How long does switching IT providers actually take?
Plan for 90 days. The first 30 cover contract review, provider selection, and discovery before notice. Days 30 to 60 handle tenant ownership transfer, parallel agent deployment, a verified test restore, and the cutover. Days 60 to 90 cover decommissioning, credential rotation, and the first SLA review.
Should I give notice before or after signing a new provider?
Always sign the incoming provider first. Giving notice without a replacement under contract creates a coverage gap where nobody new has authority to act. Sign, run discovery while the current provider is still responsible, then send written notice. One month of overlap costs far less than one uncovered outage.
What if my current provider refuses to hand over documentation?
Check whether the contract has an offboarding or data return clause and reference it in writing. If there is none, cooperation is voluntary, which is exactly why discovery belongs before notice. A competent incoming provider can rebuild most of it through network discovery, tenant auditing, and credential rotation.
Will my business experience downtime during the transition?
A properly planned transition should produce no unplanned downtime. New monitoring, security, and backup agents deploy alongside the existing ones rather than replacing them, so there is never a moment without coverage. Riskier changes such as DNS or email routing happen outside business hours with a written rollback plan.
Who owns my Microsoft 365 tenant and licenses after I switch?
Your organization should own the tenant, with at least one Global Administrator account in a company-controlled mailbox secured with MFA. What usually transfers is the partner or reseller billing relationship, which can move to the incoming provider or convert to direct billing. Verify this in the first ten days rather than assuming it.
Geographic Coverage
LayerLogix supports IT provider transitions across Texas, including managed IT services in Houston, The Woodlands, Sugar Land, Dallas, Fort Worth, and Austin. Whether you need a full managed IT services engagement or a co-managed model alongside your internal team, the sequence is the same: overlap first, cutover second, decommission last. Call 888-792-8080, or 713-571-2390 in Greater Houston.
Need Help With Network Technology?
LayerLogix provides expert network technology solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.