Co-Managed IT Services: Contract Structure Guide

Co-managed IT is not outsourcing your team — it is augmenting it. An external provider supplements your internal staff, taking specific functions such as security monitoring, escalation support, or specialist projects. At $45 to $175 per user per month, the model is attractive, but its value collapses if the contract does not draw the responsibility line and name the exclusions. Here is how to structure it.

By Morten Andersen

What Co-Managed IT Actually Is

A co-managed IT services contract supplements — rather than replaces — your internal IT team, with the external provider handling specific functions such as security monitoring, endpoint management, or Tier 2 and Tier 3 escalation support. It is the middle path between fully retained IT and full outsourcing, and it suits organisations that have capable internal staff but lack depth in security, cloud architecture, or after-hours coverage. Because responsibility is shared rather than transferred, the contract structure matters even more than in a full IT outsourcing deal — ambiguity here means work falls through the cracks between two teams.

The Responsibility Split

The defining decision is where the line sits. Typically the internal team handles Tier 1 — password resets, basic troubleshooting, onboarding — while the MSP owns Tier 2 and Tier 3 escalations, security monitoring, and specialist functions such as endpoint detection and response, automated patch management, and compliance reporting against frameworks like NIST CSF. The contract must state this split explicitly against each function, not in general terms, so accountability is unambiguous. This is the same scope-line discipline that governs cloud managed services contracts, applied to a shared-team model.

In co-managed IT, the gap between the two teams is where incidents live. If the contract does not say who owns patching, who owns the SOC alert, and who owns the after-hours call, both teams will assume the other has it — write the split function by function.

Pricing and the Exclusion Trap

Co-managed IT typically ranges from $45 to $175 per user per month for mid-market organisations, with a common band of $65 to $120 where the MSP provides after-hours coverage, specialist work, tooling, and escalation. The trap is exclusions: most co-managed quotes cover steady-state management only, and project work, vCIO advisory time, after-hours incident response, compliance documentation, and software licensing are commonly excluded from the base rate — the single most frequent source of budget variance in these engagements. Require the contract to list inclusions and exclusions explicitly and to set a rate card for excluded work, then benchmark the all-in figure as you would in outsourcing benchmarking.

ElementTypical 2026 positionBuyer note
Tier 1 supportInternal teamPassword resets, onboarding
Tier 2 / 3 escalationMSPSpecialist and after-hours
Per-user price$45–$175 / user / moCommon band $65–$120
Common exclusionsProjects, vCIO, after-hours IR, licencesTop cause of budget variance

RACI and Decision Rights

A shared model needs a shared map. A RACI matrix across incident response, change control, security, patching, and reporting removes the ambiguity that a co-managed structure invites, and it should sit inside the same governance framework — dashboards, monthly reviews, and a quarterly business review — you would apply to any outsourcing relationship. Define who is accountable for each function, who is consulted, and who is merely informed, so a security alert at 2am has an owner before it arrives, not after.

Security and Exit

Co-managed providers often own the security stack — EDR, SOC monitoring, patch management — which makes the security and exit terms critical. Hold the MSP to the same standards as a full provider: the right-to-audit, annual assurance, and remediation SLAs set out in security requirements, and the data-return and tooling-handover obligations in your exit strategy, so a change of provider does not leave you locked out of your own monitoring. For the full structure, download the IT Outsourcing Negotiation Guide, explore our IT outsourcing negotiation service, or request a confidential briefing on your co-managed agreement.

Common Questions

Co-Managed IT Services: FAQ

What is a co-managed IT services contract?
It is an agreement where an external provider supplements — rather than replaces — your internal IT team, taking specific functions such as security monitoring, endpoint management, or Tier 2 and Tier 3 escalation support. It suits organisations with capable internal staff who lack depth in security, cloud architecture, or after-hours coverage. Because responsibility is shared, the contract must draw the split explicitly or work falls between the two teams.
How much does co-managed IT cost in 2026?
Co-managed IT typically ranges from $45 to $175 per user per month for mid-market organisations, with a common band of $65 to $120 where the MSP provides after-hours coverage, specialist work, tooling, and escalation. Watch the exclusions: project work, vCIO time, after-hours incident response, compliance documentation, and software licensing are commonly excluded from the base rate and are the top cause of budget variance.
How do I split responsibilities in a co-managed contract?
Typically the internal team handles Tier 1 — password resets, basic troubleshooting, onboarding — while the MSP owns Tier 2 and Tier 3 escalations, security monitoring, EDR, patch management, and compliance reporting. State the split explicitly against each function, then formalise it with a RACI matrix across incident response, change control, security, and reporting so every task has a named owner before an incident arrives.

Structure a Co-Managed Deal That Actually Works

We draw the responsibility line, price the exclusions, and lock in the security and exit terms — so your co-managed IT contract augments your team instead of confusing it.

Request a Confidential Briefing See Our Outsourcing Case Study

IT Outsourcing Intelligence

Monthly briefings on outsourcing rates, SLA benchmarks, and contract tactics — from advisors who have been on both sides of the table.