Switching IT providers does not have to mean weeks of disruption. For a North Carolina municipality, a well-planned transition can be organized into five phases over the first 90 days, starting with access, documentation, cybersecurity, and backups before moving into standardization and long-term planning.
The goal is continuity. Employees should know where to get support. Police, utilities, finance, administration, and other critical departments should remain operational. Security risks should be identified quickly. And by the end of the transition, municipal leadership should have a much clearer understanding of its technology environment.
Here is what the first 90 days should look like.
Quick 90-Day Municipal IT Transition Timeline
| Timeline | Primary Goal |
|---|---|
| Before Day 1 | Gather access, documentation, vendors, and contacts |
| Days 1–10 | Secure and document the environment |
| Days 11–30 | Stabilize support and address urgent risks |
| Days 31–60 | Standardize systems and remediate gaps |
| Days 61–90 | Build the long-term technology roadmap |
Phase 1: Before Day 1 — Prepare for the Transition
The best IT transitions begin before the former provider’s access is removed.
Municipal leadership and the incoming provider should gather:
- Microsoft 365 administrator access
- Domain registrar credentials
- Firewall credentials
- Server credentials
- Backup platform information
- Endpoint security information
- Network documentation
- Internet provider information
- Software vendor contacts
- Phone system information
- Copier and printer vendors
- Police and public-safety technology vendors
- Cloud applications
- Existing technology contracts
- Cyber insurance contacts
- Key department contacts
The municipality should also identify which technology accounts it owns and which accounts are currently controlled by an outside vendor.
Whenever practical, administrative accounts, subscriptions, domains, and critical technology services should remain under municipal control.
Build a Department Contact List
The incoming IT provider should know whom to contact in departments such as:
- Administration
- Finance
- Police
- Fire
- Public Works
- Utilities
- Parks and Recreation
This helps identify the systems that are most important to daily operations.
Phase 2: Days 1–10 — Secure and Document the Environment
The first ten days should focus on visibility and control.
The new provider should begin creating an inventory of:
- Users
- Computers
- Servers
- Firewalls
- Switches
- Wireless access points
- Microsoft 365 accounts
- Backup systems
- Security tools
- Software platforms
- Internet connections
- Critical vendors
Administrative access should also be reviewed.
That includes accounts belonging to:
- Former employees
- Previous vendors
- Old contractors
- Unnecessary administrators
- Remote-access tools that are no longer required
Credentials should be rotated or access removed where appropriate.
Verify Backups Early
One of the first questions should be:
If a critical municipal system failed today, could we restore it?
Do not assume that a successful backup notification means recovery will work.
The new provider should determine:
- What is being backed up
- How frequently backups occur
- Where copies are stored
- Who receives failure alerts
- When a restore was last tested
- Which systems should be recovered first
A backup strategy is only valuable when the municipality knows it can restore critical services.
Phase 3: Days 11–30 — Stabilize Support and Address High-Risk Gaps
By the end of the first month, employees should understand:
- How to request IT support
- Who to call during an emergency
- How after-hours support works
- What qualifies as a critical incident
- How technology purchases and changes are requested
The provider should also identify high-risk cybersecurity gaps.
Examples include:
- Missing multi-factor authentication
- Unsupported computers or servers
- Outdated firewalls
- Unprotected endpoints
- Failed backups
- Excessive administrative privileges
- Missing security patches
- Insecure remote access
- Incomplete documentation
Municipalities operating police departments or systems that access Criminal Justice Information should also review CJIS-related security requirements during this stage.
Phase 4: Days 31–60 — Standardize the Environment
Once urgent problems have been addressed, the next objective is consistency.
A standardized environment is generally easier to support, secure, document, and budget for.
Areas that may require standardization include:
- Computer configurations
- Endpoint protection
- Microsoft 365 policies
- New employee onboarding
- Employee termination procedures
- Patch management
- Backup policies
- Network configurations
- Hardware purchasing
- Documentation
- Vendor management
Define Who Owns Each Responsibility
This is particularly important when the municipality uses a co-managed IT model.
For example, internal IT may handle:
- Department relationships
- Application administration
- Local projects
- Day-to-day technology leadership
The managed IT provider may handle:
- Help desk support
- Cybersecurity monitoring
- Microsoft 365 administration
- Backup management
- Network management
- After-hours support
- Strategic planning
Clear ownership reduces the chance that tickets, security alerts, or important projects fall between teams.
Phase 5: Days 61–90 — Build the Technology Roadmap
By the third month, the conversation should begin moving beyond:
“What is broken?”
and toward:
“What should we improve over the next 12–36 months?”
Leadership should receive a prioritized roadmap that may include:
- Aging computers
- Server replacements
- Firewall lifecycle
- Network upgrades
- Microsoft licensing
- Cybersecurity improvements
- Backup and disaster recovery
- Cloud projects
- Department-specific technology
- Long-term budget planning
Projects can then be grouped into three categories.
Immediate Priorities
Issues that create unacceptable operational or cybersecurity risk.
12-Month Priorities
Projects that should be considered during the next municipal budget cycle.
24–36 Month Priorities
Long-term modernization and capital planning.
The objective is to move IT from unpredictable emergency spending toward planned technology investment.
What Can Go Wrong During an IT Provider Transition?
Common transition challenges include:
- Missing passwords
- Incomplete documentation
- Unknown cloud subscriptions
- Previous vendors retaining access
- Unclear ownership of accounts
- Backups that have never been tested
- Employees not knowing where to request support
- Important applications being discovered late in onboarding
A structured transition process is designed to uncover these issues early.
Should a Municipality Switch Everything at Once?
Not necessarily.
A new provider may assume responsibility for help desk support and monitoring immediately while separately scheduling higher-risk changes such as:
- Firewall changes
- Security tool deployments
- Server projects
- Microsoft 365 configuration changes
- Backup migrations
The objective should be controlled change, not changing technology simply because a new provider has arrived.
Frequently Asked Questions About Switching Municipal IT Providers
Can a municipality switch IT providers without disrupting Town Hall, police, utilities, or other departments?
Yes, if the transition is carefully planned. Critical systems and departments should be identified before major changes are made, and changes that could affect operations should be scheduled around municipal needs.
A transition should prioritize continuity first and modernization second.
What happens if our current IT provider will not give us passwords or documentation?
Start by identifying which accounts, systems, contracts, and subscriptions are owned by the municipality. Request administrative credentials, documentation, equipment inventories, vendor information, and configuration information from the outgoing provider.
If documentation is incomplete, the incoming provider can rebuild it through network discovery, account reviews, asset inventories, vendor interviews, and discussions with municipal staff.
Any contractual dispute over access, data, or documentation should be handled through the municipality’s appropriate management and legal channels.
How do we make sure the former IT provider no longer has access to our systems?
The incoming provider should perform a privileged-access review.
This may include reviewing:
- Microsoft 365 administrator accounts
- Firewall accounts
- VPN accounts
- Remote-management tools
- Server credentials
- Backup platforms
- Domain registrar accounts
- Cloud applications
- Vendor accounts
Accounts that are no longer authorized should be disabled, and appropriate administrative credentials should be changed or rotated.
How quickly should a new IT provider verify our backups and cybersecurity?
As early as possible.
During the first days of onboarding, the provider should identify critical backups, administrative accounts, endpoint protection, remote access, and major security gaps.
A municipality should not spend the first 60 days assuming its recovery systems are working.
What should municipal leadership expect during the first 30, 60, and 90 days?
A useful framework is:
By Day 30: Inventory, documentation, support stabilization, backup verification, and urgent-risk identification.
By Day 60: Standardization, remediation, access cleanup, and clearer responsibility between internal staff and the provider.
By Day 90: A prioritized technology roadmap with immediate, 12-month, and 24–36 month recommendations.
Should we expect additional onboarding costs when switching IT providers?
Possibly.
Municipalities should ask prospective providers whether their monthly agreement includes onboarding or whether additional charges may apply for:
- Initial assessments
- Security tool deployment
- Data migration
- Network upgrades
- Hardware replacement
- Microsoft 365 projects
- Major remediation work
Ask providers to identify these costs before the agreement is signed so leadership can distinguish recurring managed IT costs from one-time transition projects.
The Bottom Line
Changing IT providers should give municipal leadership more visibility and control, not more uncertainty.
A successful 90-day transition should accomplish five things:
- Document the environment
- Secure critical systems and accounts
- Stabilize employee support
- Standardize technology management
- Build a long-term roadmap
By Day 90, leadership should understand what technology the municipality owns, where its biggest risks exist, what needs improvement, and what investments should be planned over the next several budget cycles.
CW IT Support works with municipalities throughout North Carolina on managed IT, cybersecurity, CJIS support, co-managed IT, backup and disaster recovery, and strategic technology planning.
Considering changing IT providers? Contact CW IT Support to discuss your municipality’s transition strategy.

