A strong MSP proposal reads like a contract draft. A weak one reads only like a sales document.
You have a proposal in front of you. It runs thirty to eighty pages, a signature date is approaching, and most of it is template: a capability narrative at the front, named tooling and certifications in the middle, a few case-study summaries and team bios, and a commercial section at the back. The question underneath the page count is simple and uncomfortable: is this actually right, and what is hidden in the parts nobody has time to read as a contract?
Start where the risk usually hidesA strong proposal reads the same way backwards and forwards. The scope schedule names inclusions and exclusions with equal specificity. The service levels are defined with measurement method, exclusions and customer remedies. The operating model names who is accountable. The transition-out clause is a real deliverable, not a placeholder. A weak proposal is legible only as a sales document, persuasive at the front and silent exactly where the operational risk lives. This page sets out where to look, what good looks like in each place, and the evidence to ask for before you sign.
Scope is defined by what is explicitly included and what is explicitly excluded.
The most common scope pattern in weak proposals is inclusions by narrative and exclusions by silence. The capability section describes what the provider does in attractive terms, and there is no matching schedule listing what is specifically out of scope.
The stronger pattern is a named scope schedule with two columns, inclusions and exclusions, listed with equal specificity. "Microsoft 365 backup" becomes "Exchange Online mailboxes, OneDrive for Business, SharePoint sites and site configuration," with retention and restore testing stated.
Headline SLA numbers are almost always strong. The fine print is where the real commitment lives.
A 99.9% uptime SLA is near-meaningless without a definition of what counts as downtime, how it is measured, what exclusions apply, and what remedy exists if the SLA is missed.
The operational value of a service level is set by variables that rarely appear in the headline:
- Severity classification — and who decides it
- Response versus resolution — which one is actually committed
- Measurement method — and reporting cadence
- Exclusions — the events that pause the clock
- Remedies — what the customer actually gets when the SLA is missed
- Tier criteria — the definitions behind each severity level
Certifications are a prerequisite, not evidence.
The security section of most proposals is dominated by certifications and partnerships: ISO 27001, Essential Eight aligned, Microsoft Solutions Partner, vendor gold tiers. These are legitimate prerequisites, but they describe what a provider is entitled to do, not what they actually do in a live environment.
ACSC guidance is specific about the evidence a buyer should expect: incident-notice requirements timed in hours, least-privilege and attributable support access, and defined log retention. The test that separates strong providers from weak ones is whether they can produce sample evidence from a current managed environment, redacted where necessary and with permission.
The test is whether you can name who does what when something goes wrong at 2am.
The operating-model section usually describes capability, team structure and tooling. It rarely describes the mechanics of how work actually gets done. A capable proposal names the senior engineer accountable for the account and describes the RACI for a Severity 1 incident: who is responsible, who is accountable, who is consulted, who is informed.
Named accountability matters because the quality of judgement in managed services compounds with familiarity. A senior engineer who has run a specific environment for six months makes better decisions than a fresh engineer working from a ticket. The weak pattern is the team-pool model, where "the team" handles everything and no individual is accountable for knowing your environment well.
Onboarding quality is the strongest early predictor of steady-state service.
Onboarding is where a provider either takes the environment seriously or does not. The value of that work compounds over the whole relationship: the engineer who builds the initial runbook is the same engineer paged when something breaks eighteen months later, and the asset inventory built in week one is what makes the day-500 incident fast to resolve.
A strong onboarding produces:
- an asset inventory
- a network discovery
- a risk and remediation register
- a baseline security-posture assessment
- a documented runbook
Headline monthly fees are simple. The cost visibility behind them usually is not.
Most proposals quote a headline monthly fee per user or per device, with optional add-ons. The structure is easy for executives to compare across proposals, which is exactly the problem: two proposals at a similar headline rate can hide very different inclusions, exclusions and margins.
The stronger pattern:
- An unbundled price book — each service priced individually even when a bundled rate is offered
- Microsoft 365 licensing passed through at cost — with a documented margin
- Add-ons priced before they are needed — rather than discovered later
“Reasonable assistance at then-current rates” is not a transition-out commitment.
The transition-out section of a weak proposal is typically one undefined paragraph near the end of the schedule. The language is permissive and vague: transition assistance provided on a reasonable basis, at then-current rates.
The stronger pattern is a pre-agreed transition-out schedule that sits in the contract as a named deliverable, listing specific items to be handed over: tenant and subscription inventory, domain and DNS inventory, a backup inventory with restore validation, documentation, and credentials.
Open the proposal at the transition-out clause. If it reads "reasonable assistance at then-current rates", you have found the page most worth negotiating before you sign.
Bring in an independent view →No single signal is disqualifying. Clusters are.
Every proposal carries template language somewhere. What matters is pattern: where weak signals cluster, and whether the provider addresses them with specific, evidence-backed language when raised, rather than offering to "clarify in conversation." The signals below are drawn from ACCC unfair contract term enforcement, ACSC managed service provider guidance, ASBFEO small-business dispute patterns, and documented handover failures.
Three or more clustered in one proposal — especially in the transition-out, commercial or operating-model sections — is the threshold for getting an independent view before you sign.
If three or more of these signals cluster in the transition-out, commercial or operating-model sections, that is the threshold for an independent view before you sign — a senior-led review of the specific proposal in your hand, with findings documented whether or not you keep the incumbent.
Get an independent viewThe pre-signature hour is the highest-leverage hour you will have.
The leverage curve is steep. Before signature, you can require specific wording, specific evidence and specific deliverables. At renewal, amendment is possible but harder. After signature, remediation is partial and usually depends on provider cooperation you no longer have the commercial leverage to command. Every hour invested in reading the proposal as a contract pays back in far more leverage than the equivalent hour spent after the fact.
That is where an independent view helps. A senior-led review of the specific proposal in your hand, against the domains, weak signals and evidence requirements on this page, with the findings documented whether or not you keep the incumbent, and a written recommendation any competent engineering team could execute.
The point is not to talk you out of a provider. It is to make sure the written commitment matches the operational reality before it becomes the thing you live with.
FAQs about reviewing an MSP proposal.
Which sections most often hide risk?
What evidence should I request before signing?
How should I evaluate SLAs?
What does a weak transition-out clause look like?
Is this different from legal review?
When should I get an independent review?
Is there a proposal on the table right now?
An independent senior view before you sign is faster and cheaper than the relationship that follows a signature made on incomplete information — findings documented regardless of the outcome.
Get an independent view