Skip to content
LokalMatch

IT Support Companies

IT Support Companies near you

Most American small and mid-sized businesses do not employ a full-time systems administrator. They buy IT support from an outside firm, often called a managed service provider, and that firm ends up holding the keys to everything: the domain administrator account, the email tenant, the backup console, the firewall. That access, not the help desk phone number, is the real subject of the contract.

Tell us what you need and we’ll help you find IT support companies who serve your area.

Free for homeowners · No obligation to hire

On this page

What the provider is actually responsible for varies enormously. Some sell blocks of hours and fix things when you call. Some charge a flat monthly fee per user or per device and take on patching, monitoring, backup and endpoint protection. Some work alongside an in-house technician, an arrangement the industry calls co-managed. The label on the invoice tells you much less than the service description attached to it.

No state licenses IT support as a trade and there is no federal registration. What does bind a provider is the law that follows the data it touches. A firm supporting a medical clinic is a HIPAA business associate and must sign a business associate agreement with the practice. A firm supporting a mortgage broker or tax preparer sits inside the FTC Safeguards Rule's service provider requirements. Those obligations are the closest thing to a licence this field has.

How IT support is sold in the US: break-fix, block hours and managed services

  • Break-fix means you call when something is broken and pay by the hour, with no obligation on either side between calls.
  • Block hours are prepaid time drawn down as you use it, which smooths billing but still leaves nobody watching the systems.
  • Managed services charge a recurring fee per user or per device and bundle monitoring, patching, backup and a help desk into it.
  • Co-managed IT puts an outside firm behind an internal technician, typically taking over after-hours coverage, security tooling or a specific platform.
  • Project work sits outside all three: a server replacement, an office move or a migration is quoted separately even under a managed contract.
  • Staff augmentation places a technician on your site for set days, which is closer to temporary hiring than to a service agreement.

What onboarding a new IT provider actually involves

The first weeks are discovery, not support. A competent firm inventories every machine, every server, every cloud tenant and every line-of-business application, then documents how they connect. Until that inventory exists, nobody can honestly promise a response time, because nobody knows what is out there.

Next comes the credential handover. Domain admin, the Microsoft 365 or Google Workspace global admin, the domain registrar, the DNS host, the firewall, the backup platform and the phone system all have to change hands or be reissued. This is the moment to insist the accounts are created under your organization's name, not your provider's, and that you keep a copy of the credentials in your own password vault.

Only then should monitoring agents, patch management and endpoint protection go on. A provider that installs its tooling on day one and documents the environment later is working blind, and you will discover which machines were missed the first time something fails.

Service level agreements: response time is not resolution time

Almost every managed contract promises a response time by severity: an hour for a site-down event, four hours for a single user, next business day for a request. Response means somebody acknowledges the ticket and begins work. It does not mean the problem is fixed, and most agreements deliberately make no promise about resolution, because a failed hard drive or a vendor outage is outside the provider's control.

Read what coverage hours mean. Business hours support that ends at six in the evening Eastern is a different product for a firm with a West Coast office. Check whether after-hours work is billable, whether there is an on-call number that reaches a human, and what the escalation path is when the first technician cannot solve it.

Also check what the remedy is when the agreement is missed. In practice the usual remedy is a service credit against the next invoice, which is small. The more useful protection is a short termination notice period and a written exit obligation, so a provider that keeps missing its own targets can be replaced without a fight.

HIPAA business associate agreements and the FTC Safeguards Rule

HHS says plainly that an IT contractor or vendor, including a managed services provider, that provides maintenance or support for systems and in doing so creates, receives, maintains or transmits electronic protected health information is a business associate of the covered entity. So is a cloud service provider engaged to store or process that information. The practice must obtain a written business associate agreement before disclosing patient information, and the business associate is directly liable for certain provisions of the HIPAA Rules, not merely contractually liable to the clinic.

The chain keeps going. HHS states that a business associate must have its own agreement in place with a subcontractor before disclosing protected health information to it, and that all downstream subcontractors are themselves business associates. If your IT firm uses an offshore help desk or a third-party backup vendor, those agreements have to exist too.

For firms handling customer financial information, the FTC's Safeguards Rule requires a written information security program with nine elements, including designating a qualified individual to run it, a written risk assessment, multi-factor authentication, and oversight of service providers through contracts that spell out security expectations. The FTC notes the rule reaches many non-bank businesses defined by activity rather than by name, such as mortgage lenders, tax preparation firms and investment advisers. If you are one of those, your IT provider is a service provider under that rule and the contract needs to say so.

Who owns the administrator accounts, tenants and licences

  • Microsoft 365, Google Workspace and cloud subscriptions should be registered to your business as the tenant owner, even if the provider resells and bills them.
  • Keep at least one break-glass global administrator account that only your own staff can use, stored offline and tested occasionally.
  • The domain name registration and DNS are the single most damaging thing to lose in a dispute, so verify who the registrant of record is today, not who set it up.
  • Backups should be readable without the provider's console, and you should confirm once that you can restore a file yourself or watch them do it.
  • Documentation of the environment is a deliverable, not a trade secret, and the contract should say a current copy is handed over on request.
  • An offboarding clause should set a fixed window for credential transfer, data export and cooperation with the incoming firm, agreed before you ever need it.

CISA Cyber Essentials and the NIST framework as a baseline

CISA publishes Cyber Essentials as a guide for leaders of small businesses and small government agencies, organised around six areas it calls Yourself, Your Staff, Your Systems, Your Surroundings, Your Data and Your Crisis Response, with a toolkit that breaks each into smaller actions. It is a reasonable checklist to hand a prospective provider and ask which items they cover and which they do not.

The NIST Cybersecurity Framework 2.0 is the broader reference. NIST describes it as a taxonomy of high-level cybersecurity outcomes usable by any organization regardless of size, sector or maturity, and in February 2024 NIST added a sixth Function, Govern, alongside Identify, Protect, Detect, Respond and Recover. Version 2.0 is explicitly aimed at all organizations, not only critical infrastructure.

Neither is a certification and neither is mandatory for a private business. Their value here is as a common vocabulary: if a provider can map its monthly service to named outcomes, you can see what is in scope. If it cannot, the gaps stay invisible until an incident finds them.

What happens when your provider finds a breach

The United States has no single federal breach notification law for ordinary business data. The FTC's data breach guide for business states that all states, the District of Columbia, Puerto Rico and the Virgin Islands have enacted legislation requiring notification of security breaches involving personal information, so the obligation depends on where the affected people live, not where your office is. A company with customers in a dozen states may face a dozen slightly different clocks and content requirements.

Some states also require a report to the state attorney general. California, for example, requires any person or business that must notify more than 500 California residents of a single breach to send a sample copy of the notice electronically to the Attorney General.

If patient information is involved, the HIPAA Breach Notification Rule sets its own clock: individuals must be notified without unreasonable delay and no later than 60 days after discovery, and a business associate must notify the covered entity within the same 60 days. Your contract should say the provider tells you immediately, preserves logs, and cooperates with a forensic investigator, rather than quietly cleaning up and moving on.

What moves the monthly price of managed IT

  • Per-user pricing usually assumes an average device count per person, so a designer with three machines is priced differently from a receptionist with one.
  • Servers, whether physical or virtual, are normally billed on top of user counts because they carry patching and backup work of their own.
  • Security tooling such as endpoint detection, email filtering and managed detection is often a separate line rather than part of the base fee.
  • Coverage hours matter more than most buyers expect, and round-the-clock support can be a large multiple of business-hours support.
  • Compliance work for a regulated client, including evidence gathering and annual attestations, is usually quoted separately from day-to-day support.
  • Onboarding is typically a one-time project fee, and a provider that waives it entirely may be recovering it through a long minimum term.

IT Support Companies: frequently asked questions

Does an IT support company need a licence in the United States?

No state licenses IT support or managed services as a trade, and there is no federal registration. What matters instead is what the firm is contractually and legally on the hook for once it touches your systems. If you handle health information, HHS treats an IT contractor or managed services provider that maintains or supports systems holding electronic protected health information as a business associate, which means a signed business associate agreement and direct liability under parts of the HIPAA Rules. If you handle customer financial information, the FTC Safeguards Rule requires you to select service providers capable of maintaining safeguards and to bind them by contract. Those obligations are worth more scrutiny than any certificate on the wall.

What should a managed services contract say about ending the relationship?

It should set a notice period, a fixed handover window, and a list of what is returned: administrator credentials for every system, the domain registrar and DNS, the email tenant, backup data in a readable format, network documentation and any licences bought in your name. Say explicitly that documentation and configuration records belong to you. Without that clause the practical leverage during a dispute sits entirely with the outgoing provider, because it holds the accounts. Agreeing this at the start costs nothing; negotiating it while you are unhappy is a different conversation.

Is my IT provider responsible if we get breached?

That depends on what the contract says and on the facts, and it is a question for your own counsel. What is clearer is the notification duty. There is no general federal breach notification statute for business data, and the FTC notes that every state plus the District of Columbia, Puerto Rico and the Virgin Islands has a breach notification law, so the duty usually falls on the business that owns the customer relationship. Under HIPAA, a business associate must notify the covered entity of a breach of unsecured protected health information without unreasonable delay and no later than 60 days from discovery, and the covered entity remains responsible for notifying individuals.

What is the difference between an SLA response time and getting the problem fixed?

Response time is the promise to acknowledge the ticket and start work within a stated window for that severity level. Resolution is when the issue is actually gone, and most agreements make no commitment on it, because the cause may be a hardware failure or a third-party outage. When you compare providers, look at severity definitions, coverage hours, whether after-hours work is billable and what the escalation path is. A one-hour response promise that only applies from nine to five is a narrower product than it sounds.

Should we keep our own administrator account?

Yes. Keep at least one emergency administrator account for the email tenant and the network that only your own staff control, store the credentials outside any system the provider manages, and test it occasionally so you know it still works. It is not a statement of distrust; it is what you fall back on if the provider is itself compromised, goes out of business, or the relationship ends badly. Confirm too that the domain name registration lists your business as the registrant, because losing control of a domain takes email and the website down at once.

How do I tell a real security offering from an antivirus subscription?

Ask what outcomes the monthly fee covers and ask for them in plain language. CISA's Cyber Essentials, written for small business leaders, is organised into six areas covering leadership, staff, systems, access, data and crisis response, and a provider should be able to say which of those it handles, which you handle and which nobody currently handles. The NIST Cybersecurity Framework 2.0 gives a fuller vocabulary with six Functions, including the Govern Function added in 2024. Neither is a certification, but either exposes the gap between monitoring software and an actual security program.

Sources

  1. HHS: Business Associates (HIPAA)
  2. HHS: HIPAA Breach Notification Rule
  3. FTC: Safeguards Rule, what your business needs to know
  4. FTC: Data Breach Response, a guide for business
  5. CISA: Cyber Essentials
  6. NIST releases version 2.0 of the Cybersecurity Framework
  7. California Attorney General: Submitting data security breach notifications

Written by the LokalMatch editorial team. Last reviewed September 22, 2026. How we write and check our guides

Find IT support companies by city

California

Show 186 cities

Florida

Show 82 cities

Texas

Show 79 cities

What affects the fees IT support companies charge

Fees depend on the work involved and how the professional bills. We only publish fee ranges when they’re backed by real LokalMatch data or reliable sources. Until then, here’s what usually changes the fee:

  • Scope and complexity of the work
  • How the firm bills: hourly, per project or on a monthly retainer
  • Experience of the team
  • Timeline and how urgent the work is
  • Ongoing support after the work is delivered

How to compare IT support companies before you hire

  • Ask for examples of similar work for clients like you.
  • Read reviews and ask for references you can contact.
  • Make sure the scope, deliverables and timeline are written down before work starts.
  • Ask who will do the work: an in-house team, freelancers or subcontractors.
  • Compare two or three proposals before you decide.

Questions to ask IT support companies before you hire

  • Have you done work like this before, and can I see examples?
  • Who will work on this, and who is my main contact?
  • How do you charge: hourly, per project or monthly?
  • What is included, and what costs extra?
  • How long is the contract, and how can either side end it?
  • How will you report on progress?
  • Who owns the work, files and accounts you set up for me?

Licences and registration

This kind of work is often limited to licensed or registered professionals, and the rules depend on where you are. Ask which body they’re registered with, and check their status on that body’s public register before you hire.

Ready to contact IT support companies?

Tell us what you need in a few sentences.