Most businesses stay with an IT provider they have outgrown for longer than they should, and the reason is almost always the same: the switch looks risky. Your current provider holds the credentials, the documentation, and the institutional knowledge. Changing feels like handing over the keys mid-journey.
It is a manageable process, but the risk is real and it is concentrated in a specific place — the handover. Here is what actually happens, and what to secure before you give notice.
Before you give notice
This is the part most businesses skip, and it is the part that determines how the rest goes. Do these while the relationship is still cordial.
- Read your contract. Find the notice period, the auto-renewal date, and any offboarding fees. A 90-day notice window that renewed last month changes your timeline substantially.
- Establish who owns what. Domain registration, Microsoft 365 or Google Workspace tenant, backup data, firewall configuration, licences. If any of these are registered to your provider rather than your business, resolve it before anything else.
- Get your documentation. Network diagrams, asset inventory, credential list, vendor account details. You are contractually entitled to this in most agreements, and it is far easier to obtain before you have given notice.
- Verify your backups independently. Confirm they exist, cover what matters, and can be restored. Do not rely on a report.
That second item is where transitions genuinely go wrong. A domain or tenant registered under the provider's account rather than yours is the single most common source of a difficult exit, and it is entirely avoidable if you check early.
A realistic timeline
For a business of 20 to 60 people with a reasonably typical environment, a well-run transition runs four to six weeks from engagement to full handover. Compressing it below three is possible and is where mistakes happen.
Week 1 — Discovery
The incoming provider documents your environment independently rather than trusting inherited documentation. Every device, server, network component, cloud tenant, licence and vendor relationship. This is also when the gap between what you were told you had and what you actually have becomes visible.
Week 2 — Tooling and access
Monitoring and management agents deployed, ticketing set up, documentation platform populated, backup verified independently. Your new provider should be able to see the environment before they are responsible for it.
Weeks 3–4 — Parallel running
Both providers have access. The new one begins taking tickets; the outgoing one remains available for escalation. This overlap is the single most valuable part of the process and the first thing sacrificed when businesses rush.
Weeks 4–6 — Cutover and remediation
Outgoing provider access revoked, all credentials rotated, remediation of whatever discovery surfaced. That last item is frequently a separate project with its own budget, and any provider who tells you otherwise before seeing your environment is guessing.
What usually goes wrong
- Undocumented dependencies. A scheduled task, a legacy integration, a script on someone's machine that nobody knew was load-bearing until it stopped.
- Credentials nobody has. Vendor portals, line-of-business software, a certificate authority — often held personally by an engineer who has left.
- Licensing surprises. Software licensed under the provider's agreement rather than yours, which does not transfer.
- A hostile outgoing provider. Uncommon, but it happens, and it is why the documentation should be obtained before notice is given.
- Discovered debt. Unsupported operating systems, failing hardware, backups that were never working. This is not caused by the transition — it is revealed by it.
That last point is worth dwelling on. A transition frequently surfaces problems that have existed for years, and it can feel as though the new provider has broken something. Almost always they have simply looked properly for the first time.
Credential rotation is not optional
When the transition completes, every credential the outgoing provider held must be changed. Administrative accounts, service accounts, network device passwords, cloud tenant global administrators, backup platform access, vendor portals.
This is not a comment on their integrity. It is standard practice, it protects both parties, and a professional outgoing provider will expect it. Ask your incoming provider for written confirmation when it is complete.
How to keep it uneventful
- Do not switch during your busiest period. For accounting firms that rules out the first quarter; for retail, the fourth.
- Insist on overlap. Refuse a hard cutover with no parallel period.
- Tell your staff what is happening and how to get help during the transition. Most transition complaints are communication failures rather than technical ones.
- Budget for remediation separately. Assume discovery will find something.
- Get the offboarding terms of your new agreement in writing at signing — because one day this will happen again, and you will want it to be easier.
Handled properly, most of your staff should notice a change of contact details and very little else. That is the standard to hold a provider to.