A CPA Firm’s First 90 Days With a New IT Provider Should Follow Three Clear Phases
During the first 90 days with a new managed IT provider, a CPA firm should expect three phases: discovery and stabilization during days 1–30, security and standardization during days 31–60, and strategic planning during days 61–90.
For a CPA firm with 25–50 employees, the provider should inventory every user, device, application, administrator account, vendor, backup system, and security control. It should also address urgent risks, introduce employees to the help desk, test critical recovery procedures, and produce a prioritized technology roadmap.
The goal is not to replace every system immediately. A successful onboarding gives the new provider control and visibility without creating unnecessary disruption. By day 90, firm leadership should understand the condition of the technology environment, the most important risks, the recommended improvements, and the expected budget for the next 12–24 months.
Why the First 90 Days Matter
The first three months establish how the CPA firm and its new provider will work together. Weak onboarding can leave outdated accounts, incomplete documentation, failed backups, unsupported devices, and unresolved security gaps hidden beneath the surface.
A structured onboarding process should produce measurable improvements in five areas:
- Employees know how to request and escalate support.
- The provider has documented administrative access to critical systems.
- Security and backup tools are installed, monitored, and tested.
- Urgent technical risks have assigned remediation plans.
- Leadership has a prioritized technology strategy and budget.
The process is particularly important for CPA firms because tax software, client portals, document-management systems, Microsoft 365, remote access, scanners, printers, and financial applications often depend on one another. A change made without understanding those dependencies can disrupt billable work or filing deadlines.
The 911 IT Three-Phase CPA Onboarding Framework
A practical 90-day onboarding process can be organized into three 30-day phases. Each phase should have defined activities, responsible parties, and measurable completion criteria.
Phase 1: Days 1–30 — Discover, Document, and Stabilize
The first 30 days should focus on understanding the environment, establishing support, securing administrative access, and resolving urgent problems.
Introduce Employees to the New Help Desk
Employees should receive simple instructions explaining:
- How to submit a support request
- Which telephone number or portal to use
- What information to include in a request
- How urgent issues are prioritized
- When after-hours support is available
- How to identify legitimate communications from the new provider
The provider should explain the difference between routine requests and emergencies. An employee who cannot print to one device may have a routine issue, while a firm-wide tax application outage or suspected account compromise requires immediate escalation.
911 IT provides access to live technical support 24 hours a day, helping employees reach a technician when problems affect evening, weekend, or tax-season work.
Inventory Users, Devices, and Applications
The provider should create a current inventory of the firm’s technology. This should include more than computers and servers.
The inventory should document:
- Permanent employees, seasonal staff, contractors, and vendors
- Desktops, laptops, servers, and mobile devices
- Microsoft 365 accounts and licenses
- Tax preparation and accounting applications
- Document-management systems
- Client portals and file-sharing services
- Remote-access tools
- Firewalls, switches, and wireless equipment
- Printers, scanners, and multifunction devices
- Internet and telephone services
- Cloud platforms and third-party integrations
- Backup and disaster-recovery systems
- Security, monitoring, and patch-management tools
Each critical application should be tied to its users, vendor, licensing information, hosting location, backup method, and technical dependencies.
Collect and Verify Administrative Access
The CPA firm should retain appropriate ownership and control over its technology. The new provider should collect and test administrative access for:
- Microsoft 365
- Domain registration and DNS
- Servers and virtualization platforms
- Firewalls and network equipment
- Backup systems
- Security platforms
- Cloud-hosting services
- Tax and accounting software
- Internet and telephone-provider portals
- Software licensing accounts
- Encryption recovery keys
Administrative accounts should use multi-factor authentication and individual credentials rather than shared passwords whenever possible. Access should be stored in a secure documentation platform and reviewed after the previous provider’s permissions are removed.
Deploy Support, Monitoring, and Security Tools
The new provider will generally install its remote-support, monitoring, endpoint-security, and patch-management tools during the first month.
Deployment should be tracked against the device inventory so that no workstation or server is unintentionally missed. The provider should verify that each device is checking in, receiving the correct policies, and generating alerts when expected.
Old security tools should not be removed until replacement protection is active and verified. A controlled overlap can prevent gaps during the transition.
Identify and Address Immediate Risks
The initial review may uncover problems that require prompt attention, such as:
- Inactive employee accounts that remain enabled
- Missing multi-factor authentication
- Unsupported computers or servers
- Failed backups
- Unprotected laptops
- Excessive administrator privileges
- Unpatched firewalls or applications
- Unmonitored antivirus alerts
- Publicly exposed remote-access services
- Unknown devices connected to the network
The provider should prioritize these findings according to likelihood, business impact, and urgency. A critical exposure should be corrected quickly, while a lower-risk improvement may be scheduled for a later project.
Validate Critical Tax-Season Workflows
Before making major changes, the provider should confirm that employees can use the systems required for client work.
Testing should cover:
- Tax preparation software
- QuickBooks and accounting applications
- Microsoft 365 and email
- Document-management systems
- Secure client portals
- Scanners and PDF workflows
- Remote access
- File shares and cloud storage
- Printers used for tax and financial documents
Testing with employees from several job roles helps identify permission or workflow issues that may not appear when an administrator performs the test.
Phase 2: Days 31–60 — Secure, Standardize, and Test
After the provider understands the environment and has stabilized urgent issues, the second phase should focus on reducing risk and creating consistent technology-management practices.
Complete a Cybersecurity Risk Assessment
The provider should evaluate the firm’s identity security, endpoints, email, cloud services, network, applications, backups, remote access, vendors, and employee practices.
The assessment should identify:
- The sensitive information the firm stores
- Where that information is located
- Who can access it
- Which threats could affect it
- Which safeguards are already in place
- Where control gaps exist
- Which improvements should be prioritized
Each significant finding should have an owner, target date, estimated cost, and method for verifying completion.
Learn more about the protections included in 911 IT’s cybersecurity services.
Strengthen Identity and Microsoft 365 Security
Microsoft 365 often contains email, files, calendars, contacts, and sensitive client conversations. The provider should review:
- Multi-factor authentication coverage
- Global administrator and privileged roles
- Inactive accounts
- Suspicious sign-ins
- Mailbox-forwarding rules
- External sharing
- Legacy authentication
- Third-party applications connected to user accounts
- Anti-phishing and impersonation settings
- Email-domain protection
Administrative privileges should be limited, and separate administrator accounts should be considered for users who perform privileged work.
Standardize Employee Onboarding and Offboarding
New hires and departing employees create recurring security and productivity risks when access changes are handled informally.
A documented onboarding checklist should define:
- Required equipment
- Microsoft 365 licensing
- Tax and accounting application access
- File and client-portal permissions
- Multi-factor authentication enrollment
- Security training
- Remote-access requirements
- Target completion dates
An offboarding checklist should include:
- Disabling accounts
- Revoking active sessions
- Recovering firm-owned devices
- Removing remote access
- Changing shared credentials
- Preserving required business records
- Reviewing mailbox forwarding and delegation
- Removing vendor and application access
Seasonal employees should receive access based on defined start and end dates, with permissions limited to their responsibilities.
Review Patching and Vulnerability Management
The provider should establish a consistent process for updating operating systems, browsers, tax applications, PDF tools, servers, firewalls, and network equipment.
The process should document:
- Which systems are managed
- How frequently updates are reviewed
- How urgent security patches are handled
- When devices are restarted
- How failed updates are detected
- How unsupported software is addressed
- How completion is reported
Vulnerability scans should be used to identify missing updates, weak configurations, exposed services, and unsupported technology. High-risk findings should be corrected first.
Review the Written Information Security Plan
The firm’s Written Information Security Plan, or WISP, should reflect its actual technology, procedures, personnel, vendors, and security controls.
The review should confirm that the plan addresses:
- Assigned security responsibilities
- Risk assessments
- Access control
- Passwords and multi-factor authentication
- Encryption
- Patch and device management
- Employee training
- Vendor oversight
- Backup and recovery
- Incident response
- Physical records
- Secure disposal
- Program testing and review
A template can provide a starting point, but the final document should match what the firm actually does. Review this guide to creating and maintaining a Written Information Security Plan.
Test Backups and Recovery Procedures
Backup monitoring confirms that jobs appear to complete. Recovery testing confirms that the firm can restore information and continue operating.
The provider should document:
- Which systems and cloud services are backed up
- Backup frequency
- Retention periods
- Storage locations
- Protection against unauthorized deletion
- Recovery-time expectations
- Recovery-point expectations
- The results of recent restoration tests
Testing should include critical application data and not only individual files. The provider should also identify any systems that are excluded from the backup strategy.
Explore business continuity services to understand how backup, disaster recovery, and operational planning work together.
Train Employees on Security and Support Procedures
Employees should receive practical guidance on:
- Recognizing phishing attempts
- Reporting suspicious messages
- Responding to unexpected MFA prompts
- Verifying payment and bank-account changes
- Sharing taxpayer information securely
- Protecting devices while working remotely
- Using the help desk
- Reporting lost devices
- Avoiding unapproved software
Training should be documented and reinforced throughout the year through short lessons, reminders, and simulated phishing exercises.
Phase 3: Days 61–90 — Plan, Budget, and Improve
The third phase should convert the provider’s technical findings into a practical business plan. Firm leadership should not receive a list of unexplained technical problems. It should receive priorities, options, costs, timelines, and expected business outcomes.
Create a Prioritized Technology Roadmap
The roadmap should organize recommended work into clear timeframes.
| Priority | Typical timeframe | Examples |
|---|---|---|
| Critical | Immediately or within 30 days | Failed backups, exposed accounts, unsupported security systems |
| High | Within 90 days | MFA gaps, aging firewalls, excessive administrator access |
| Medium | Within 3–12 months | Device replacement, network improvements, workflow standardization |
| Strategic | Within 12–24 months | Cloud migration, office expansion, application modernization |
Each recommendation should explain the risk or business problem, the proposed action, the estimated investment, and the expected benefit.
Develop a 12–24 Month IT Budget
The provider should help leadership forecast predictable operating costs and upcoming projects.
The budget may include:
- Managed IT support
- Cybersecurity services
- Microsoft 365 licensing
- Backup and disaster recovery
- Computer and server replacements
- Firewall and network upgrades
- Tax software infrastructure
- Cloud services
- Employee growth
- Office expansion or relocation
- Compliance and security projects
A useful budget distinguishes recurring monthly expenses from one-time capital or project costs. It should also show which investments are mandatory, recommended, or optional.
Prepare a Tax-Season Readiness Plan
The provider and firm should agree on how technology will be managed before and during peak filing periods.
The plan should address:
- Maintenance blackout dates
- After-hours and weekend support
- Urgent escalation procedures
- Tax application updates
- Remote-work capacity
- Internet and power contingencies
- Backup and recovery verification
- Seasonal employee onboarding
- Device availability
- Vendor support contacts
Major infrastructure changes should be scheduled outside peak season whenever possible. Critical security issues should still be corrected promptly, but lower-priority projects can wait until the risk of disruption is lower.
Establish Ongoing Strategy Meetings
Firm leadership should meet with its provider regularly to review:
- Support performance
- Recurring technical issues
- Security findings
- Backup and recovery status
- Upcoming technology replacements
- Employee and location changes
- Projects and budgets
- Compliance priorities
- Business goals
Quarterly reviews are a practical starting point for many firms. More frequent meetings may be appropriate during onboarding, mergers, office moves, major projects, or periods of rapid growth.
What Deliverables Should the CPA Firm Receive by Day 90?
By the end of the onboarding period, the firm should receive or have access to documentation covering the following areas:
- A complete user and device inventory
- An application and vendor inventory
- Verified administrative-access records
- A network and infrastructure overview
- A cybersecurity risk assessment
- A prioritized remediation plan
- Backup scope and recovery-test results
- Onboarding and offboarding procedures
- Help desk and escalation instructions
- A current Written Information Security Plan or update plan
- A tax-season readiness plan
- A 12–24 month technology roadmap
- A projected IT budget
- A schedule for recurring strategy and security reviews
The firm does not need unrestricted access to every technical tool, but it should understand what is being managed, who owns each account, and how critical information can be recovered if the provider relationship changes.
How Should Success Be Measured During the First 90 Days?
Firm leadership should evaluate onboarding using measurable outcomes instead of relying only on general impressions.
| Measurement | Desired outcome |
|---|---|
| Managed device coverage | 100% of approved devices inventoried and monitored |
| Endpoint-security coverage | 100% of supported endpoints protected |
| MFA coverage | 100% of applicable users and administrators enrolled |
| Backup validation | All critical systems reviewed and tested |
| Inactive accounts | Identified, reviewed, and disabled |
| Critical risks | Corrected or assigned documented remediation plans |
| Employee help desk readiness | All employees know how to request support |
| Technology roadmap | Reviewed and approved by leadership |
Support metrics may also include initial response time, time to resolution, ticket volume, recurring issues, employee satisfaction, and percentage of requests resolved remotely.
Seven Warning Signs of a Weak MSP Onboarding Process
1. The Provider Does Not Perform a Formal Assessment
A provider cannot manage risk effectively without understanding the systems, users, applications, vendors, and data it is responsible for protecting.
2. Employees Do Not Know How to Get Support
Confusion about telephone numbers, portals, and escalation procedures delays resolution and reduces confidence in the new relationship.
3. Administrative Access Is Incomplete
The provider should identify missing credentials early rather than discovering them during an emergency.
4. Security Tools Are Installed Without Verification
Deployment reports should be compared with the device inventory to ensure every approved endpoint is protected and communicating properly.
5. Backups Are Assumed to Work
The provider should review backup scope, retention, security, and recovery results rather than relying on a green status indicator.
6. Every Recommendation Is Treated as an Emergency
A mature provider prioritizes findings according to risk and business impact. Firm leadership should understand what must happen now and what can be planned.
7. There Is No Strategic Plan by Day 90
Managed IT should progress beyond reactive support. The provider should help the firm plan replacements, security improvements, budgets, and tax-season preparation.
What Should Not Happen During the First 90 Days?
A new provider should avoid introducing unnecessary disruption. Unless an urgent risk requires immediate action, onboarding should not include several major changes at once.
Potentially disruptive work that may need to be scheduled separately includes:
- Replacing every computer
- Migrating all applications to the cloud
- Changing tax software
- Moving offices
- Replacing the telephone system
- Redesigning the entire network
- Changing several security platforms simultaneously
Combining too many changes makes problems harder to diagnose and can overwhelm employees. Stabilize the environment, address critical risks, and then complete larger projects according to an approved roadmap.
The 911 IT 90-Day CPA Onboarding Checklist
Days 1–30
- Assign firm and provider onboarding leaders.
- Introduce employees to the help desk.
- Inventory users, devices, applications, and vendors.
- Collect and test administrative credentials.
- Deploy remote-support and monitoring tools.
- Verify endpoint-security coverage.
- Review Microsoft 365 administration.
- Identify failed backups and urgent risks.
- Test critical tax and accounting workflows.
- Document open issues from the previous provider.
Days 31–60
- Complete a cybersecurity risk assessment.
- Enforce multi-factor authentication.
- Review user and administrator access.
- Remove inactive accounts.
- Standardize onboarding and offboarding.
- Correct critical patching and vulnerability gaps.
- Review Microsoft 365 and email security.
- Validate backup scope and recovery.
- Review the Written Information Security Plan.
- Provide employee security training.
Days 61–90
- Create a prioritized remediation roadmap.
- Develop a 12–24 month technology budget.
- Document tax-season support procedures.
- Establish recovery objectives.
- Schedule major projects outside peak periods.
- Review support and security metrics.
- Confirm account and license ownership.
- Schedule recurring strategy meetings.
- Present findings and recommendations to leadership.
- Obtain approval for the next phase of improvements.
Real Client Experience: Learning the Business Before Recommending Technology
911 IT clients frequently describe the importance of working with a provider that learns their environment instead of applying generic recommendations. One client explained that the team took the time to understand the company and its industry before developing technology that improved its workflow and eliminated a difficult paper-based process.
“911 IT really took the time and put in the effort to learn about our business and industry to help our company succeed.”
Another client described 911 IT as an extension of the company’s internal team, emphasizing that the provider understood its goals, worked to reduce downtime, and considered the business’s success a shared priority.
That approach should begin during onboarding. The first 90 days should not be limited to installing software. The provider should learn how the firm serves clients, which systems support billable work, where deadlines create risk, and how technology can support long-term business goals.
How 911 IT Onboards CPA and Financial Firms
911 IT begins its process with a discovery call to understand the company’s technology challenges and goals. The next step is a comprehensive risk assessment designed to identify hidden issues within the IT environment. Based on those findings, the firm receives a customized IT blueprint outlining recommended services and improvements.
CPA and financial firms can receive support for:
- 24/7 help desk assistance
- Managed IT services
- Cybersecurity monitoring and protection
- Microsoft 365 management
- Backup and business continuity
- Employee onboarding and offboarding
- Tax-season readiness
- Risk assessments and WISP support
- Vendor coordination
- Technology budgeting and planning
911 IT has served businesses since 2004, answers support calls with live technicians, and backs its service with a 100% satisfaction guarantee.
Learn more about managed IT services, review IT support for CPA and financial firms, or read experiences from 911 IT clients.
Frequently Asked Questions
How long does managed IT onboarding take?
A 25–50 employee CPA firm can generally complete the core onboarding process in 60–90 days. More complex environments may require additional time, particularly when documentation is missing, multiple offices are involved, or the previous provider controls essential licenses and accounts.
Will employees experience downtime during onboarding?
A structured onboarding process should minimize downtime. Most early activities involve documentation, tool deployment, account review, and testing. Major infrastructure changes should be planned separately unless an urgent failure or security risk requires immediate action.
What information should we give the new IT provider?
Provide employee lists, device records, software information, vendor contacts, current contracts, administrative credentials, known technical issues, tax-season deadlines, security documentation, and details about upcoming business changes.
Should the new provider replace all existing security tools?
Not immediately. The provider should first determine which tools are effective, who owns the licenses, and whether existing services can be transferred. Replacement protection should be active before an old security product is removed.
When should the previous provider’s access be removed?
Remove access after required documentation and credentials have been transferred, replacement services are active, and the new provider has verified control of critical systems. Accounts should then be disabled, passwords changed, sessions revoked, and remote-access tools removed.
Should a risk assessment be completed before or after signing an agreement?
An initial assessment can help define the proposed service before signing. A more detailed assessment is often completed during onboarding after the provider receives appropriate access to the environment.
What is the difference between onboarding and a technology project?
Onboarding transfers support, documents the environment, establishes monitoring, identifies risks, and creates a management plan. A project makes a specific major change, such as replacing a server, migrating applications, or redesigning the network.
How soon should employees receive security training?
Employees should receive initial security guidance during the first 30–60 days, with recurring training throughout the year. New employees should complete training during onboarding.
What should happen if the new provider discovers a serious security problem?
The provider should explain the risk, recommend immediate containment, identify possible business effects, and document the remediation plan. Critical exposures should be addressed quickly, even when other improvements are scheduled for later.
What should firm leadership review at the 90-day meeting?
Leadership should review support performance, security findings, backup-test results, unresolved risks, recommended projects, tax-season readiness, the technology roadmap, and the projected 12–24 month budget.
Start the New IT Relationship With a Clear 90-Day Plan
The first 90 days should leave the CPA firm more secure, better documented, and easier to support. Employees should know how to get help, leadership should understand the most important technology risks, and the provider should have a clear plan for protecting systems and supporting future business goals.
Schedule a 10-minute discovery call with 911 IT to discuss your current technology environment, support concerns, tax-season requirements, and a structured onboarding plan for your CPA firm.
