1. Before you give notice
Start with your current agreement and an inventory of what the provider actually manages. Your support contract, broadband, software subscriptions and leased equipment may have different suppliers and end dates. Record each separately before choosing a switching date.
- Check the exit terms. Find the notice deadline, required notice method, renewal date, handover assistance and any agreed exit charges in the signed documents. Resolve unclear terms with the supplier before relying on a date.
- Agree the incoming scope. List the users, sites, devices and applications covered. Confirm support hours, on-site arrangements, escalation contacts and which work is separately chargeable.
- Name a business decision-maker. Give both providers one contact who can approve changes and accept the handover. Ask each provider to name a technical lead.
- Plan the overlap. Write down who owns incidents while access and tools are changing. Schedule disruptive changes around your business, with an agreed way to recover if a check fails.
The NCSC advises organisations to make supplier security responsibilities clear and to specify the return and deletion of information and assets when a contract ends or transfers. Use its supply chain security guidance to frame that conversation.
2. Your MSP handover checklist
Assign a named person and due date to every relevant row. Mark anything outside your setup as not applicable, with a reason. A task is complete when the receiving person has checked the evidence.
Keep account passwords, recovery codes and other secrets out of this worksheet. Transfer them through an agreed secure credential-sharing process; record only who confirmed access.
| Handover area | Agree responsibility | Evidence to check |
|---|---|---|
| Contract and notice | Business owner + outgoing provider | Written end date, notice acknowledgement, handover scope and agreed charges. |
| Domains and DNS | Business owner + both providers | Registrar account owner, renewal contact, DNS export and named person approving changes. |
| Cloud and administrator access | Business owner + incoming provider | Customer-controlled recovery access tested; incoming access approved; outgoing access removal scheduled. |
| Licences and subscriptions | Business owner + both providers | Product, quantity, billing owner, commitment end date and agreed transfer or replacement plan. |
| Backups and recovery | Incoming provider + business data owner | Systems covered, retention, restore test result and access to any retained older backups. |
| Devices and security tools | Both providers | Device inventory and agreed sequence for replacing management, monitoring and endpoint protection. |
| Network and connectivity | Both providers | Network diagram, firewall configuration, circuit details and escalation contacts. |
| Business applications | Business application owners | Application contacts, integrations, service accounts and dependencies confirmed. |
| Support and open issues | Both providers + business owner | Open ticket summary, new helpdesk details, escalation route and support start time. |
| Completion and access removal | Business owner + both providers | Acceptance tests signed off; old access revoked; data return and deletion arrangements confirmed. |
Download the editable worksheet to add a responsible person, due date, evidence reference and status. Store the completed copy in your own business records.
3. Treat access and licences as separate jobs
Ask the incoming provider to confirm how your business retains control of its domain, cloud accounts and recovery methods. Record which access belongs to your staff, which belongs to each provider, and when old access will be removed. Test the replacement access before depending on it.
If you use Microsoft 365
Microsoft lets customers review and remove a partner’s granular delegated admin privileges (GDAP) through Partner relationships in the Microsoft 365 admin centre. Follow Microsoft’s customer-led GDAP removal guidance with your incoming provider once support responsibility has transferred.
Removing GDAP does not end the reseller relationship. Microsoft confirms this in its GDAP FAQ. Confirm subscription billing, commitments and any reseller transfer separately; changing support provider does not itself settle those arrangements.
For management and security software, agree the removal and installation sequence. Ask both providers how they will avoid a gap in monitoring or protection and identify tools that could conflict. Include remote access software, local administrator accounts, application integrations and service accounts in the access review.
4. Test before you accept the handover
Choose acceptance checks that reflect a normal working day. Ask a representative staff member to sign in, send and receive email, open shared files and use a critical business application. Test remote working and on-site equipment where they are part of your support scope.
Check recovery as well as everyday access. The NCSC recommends knowing how to restore a backup and checking that it contains your important data. See its backup guidance for small organisations. Agree a safe restore test with your incoming provider and record the result, the data recovered and any unresolved gaps.
- Send a test support request and confirm who receives it, including the out-of-hours escalation route if purchased.
- Confirm who can recover older backups after the previous service ends, and for how long.
- Record remaining issues with an owner and resolution date before signing off.
- Confirm old access removal and the agreed treatment of retained data after acceptance.
5. Common switching questions
How long does switching MSP take?
Build the schedule from your notice terms, access readiness, system complexity and any separate migrations. Ask the incoming provider for milestones and dependencies before accepting a date. A support handover and an email or server migration are different pieces of work; identify which you are buying.
Can I keep my email and software?
Ask which existing accounts and subscriptions can stay in place and which need a transfer, replacement or migration. Record the answer for each product, including its billing and renewal arrangements. Do not assume that a change in the helpdesk requires moving all your data.
What if the outgoing provider has not supplied access?
Document exactly what is missing and the business impact. Ask your named outgoing contact for a written handover plan and involve the business account owner. Confirm the relevant vendor’s account recovery process before changing anything that could lock people out. Keep unresolved access items visible in the plan.
6. Compare your next provider
Give each shortlisted MSP the same support scope and handover requirements. Ask them to separate ongoing support, onboarding, migration work, licences and any overlap costs in their proposal.
WhatMSP lets you browse and compare UK MSPs for free. Directory information is a starting point; confirm current services, credentials, availability and contract terms directly with each provider.