Managed IT

How to choose your IT provider in Switzerland

Concrete criteria for evaluating an IT provider in Switzerland: guaranteed response time, local presence, data sovereignty, contract clarity and reference checks.

David Cunha

David Cunha

Published on January 15, 2026 7 min read
MANAGED IT

Choosing an IT provider is a decision that commits your company for several years. A poor choice is expensive, not only in money, but in wasted time, unresolved incidents and potentially poorly protected data. Here are the criteria that really matter, in the order in which they matter.

6 criteria
to seriously evaluate an IT provider
4 business hrs
critical-incident response in a good SLA
24 months
commitment period beyond which to stay cautious

1. The guaranteed response time. in writing

The first criterion, and often the most poorly assessed during a tender, is the guaranteed response time in the event of an incident. Ask the question directly: if a server fails on a Tuesday morning at 9am, how long before a technician starts working on the problem?

The answer must be in the contract, in the form of an SLA (Service Level Agreement) with defined criticality levels. "We are very responsive" is not an SLA. An SLA is, for example: "Critical incident: handled within 4 business hours", with a clear scope.

If the provider cannot show you their standard SLA, ask why. Either they don't have one (that's a red flag), or they don't want to commit (that's another red flag).

2. A real local presence

In French-speaking Switzerland, many providers display a local address but subcontract to teams in France, Belgium or India. This is not necessarily a problem for certain types of support, but it is for several important reasons:

  • Physical interventions (hardware failure, equipment deployment) require someone who can travel quickly to the site
  • A relationship of trust is easier to build with a contact who knows your region, your constraints, and who speaks your language
  • Data sovereignty is easier to guarantee with a provider whose teams and systems are in Switzerland

Ask where the teams that actually manage your contract are based. Ask whether you can visit their premises. A solid provider has nothing to hide.

3. Data sovereignty

Since the revised Swiss Data Protection Act (FADP) came into force in September 2023, Swiss companies must be able to document where their personal data is stored and processed, and to guarantee an adequate level of protection.

Ask your future provider these questions:

  • Where is your supervision and monitoring data hosted?
  • Are backups stored in Switzerland?
  • Are the tools used (ticketing, RMM, PSA) subject to the US CLOUD Act?
  • Which subcontractors does the provider work with to process your data?

These questions may seem technical, but a good provider must be able to answer them clearly. If the answer is "we don't know exactly", that's a real problem, not only for compliance, but for the security of your data.

4. Contract clarity

A managed IT contract must specify, in black and white:

  • The exact scope covered (which equipment, which software, which sites)
  • What is included in the monthly fee and what is billed in addition
  • The SLAs for each incident criticality level
  • The exit terms (notice period, data portability, termination costs)
  • The procedure in case of subcontracting

Beware of contracts that define the scope vaguely ("the company's IT infrastructure") without a precise asset list. In the event of a dispute, you will have no recourse.

The commitment period is also important. A 6-month commitment is reasonable for a managed IT contract (setup takes time). Beyond 24 months, be cautious. especially if the early exit penalties are high.

5. Verifiable references

Any provider can say they have "dozens of satisfied clients". What matters is being able to talk to one or two of them directly. Ask for references in your sector or your company size, and contact them.

Useful questions to ask references:

  • How long does the provider take to respond to an urgent ticket?
  • Have there been any poorly managed incidents? How did it go?
  • Is the monthly report useful and readable?
  • Would you recommend this provider to a company similar to yours?

If the provider refuses to provide references or cannot give any in your sector, factor that into your decision.

6. The ability to say "no" or "I don't know"

A provider who answers "yes" to all your questions and promises everything you want to hear is suspect. A good IT provider must be able to tell you:

  • "This problem is out of scope, here's what it would cost"
  • "I'm not sure, let me check"
  • "That solution you saw online isn't suited to your situation, here's why"

Technical competence is also assessed by the quality of the questions the provider asks during your first conversation. If they ask for your budget before understanding your situation, that's telling.

In summary

Evaluate an IT provider on these six points: a documented and contractual SLA, local teams, clarity on data sovereignty, a precise and balanced contract, verified references, and intellectual honesty in conversations.

Price is not on this list. not because it doesn't matter, but because a cheaper provider that responds within 48h, hosts your data anywhere and dodges the hard questions will cost more than expected.

At AlpenData, these six criteria shape our AlpenCare managed IT offering: a documented SLA, a French-speaking Switzerland team based near Lausanne and client services operated primarily on Swiss infrastructure.

David Cunha

Written by

David Cunha

Co-founder · Technical director, AlpenData

A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.

More about AlpenData →

First IT recommendations

Want to know where your SME is exposed?

Request a 30-minute conversation with an AlpenData engineer. You walk away with first recommendations on your security, your backups and your IT priorities, with no commitment.