{"id":7727,"date":"2026-07-31T09:14:32","date_gmt":"2026-07-31T08:14:32","guid":{"rendered":"https:\/\/www.superdocu.com\/en\/blog\/msp-client-onboarding-checklist\/"},"modified":"2026-07-31T09:14:32","modified_gmt":"2026-07-31T08:14:32","slug":"msp-client-onboarding-checklist","status":"publish","type":"post","link":"https:\/\/www.superdocu.com\/en\/blog\/msp-client-onboarding-checklist\/","title":{"rendered":"MSP Client Onboarding Checklist (Free Template for 2026)"},"content":{"rendered":"<p>The first 30 days of an MSP engagement decide whether the client turns into a quiet, profitable account \u2014 or a support-ticket bonfire. What separates the two is not the technical work. It is whether onboarding was run from a repeatable process or improvised over Teams.<\/p>\n<p>Below is the MSP client onboarding checklist we recommend to managed service providers running Superdocu. It covers what to collect, when to collect it, and how to make sure the discovery, security baseline, and documentation are locked in before you own the environment.<\/p>\n<h2>Why MSP onboarding needs a real checklist<\/h2>\n<p>An MSP takes over responsibility for someone else&#8217;s infrastructure. That means you inherit their bad decisions, their undocumented workarounds, and their unpatched servers on day one. If you skip discovery, you find out about the unmonitored Hyper-V host during the first outage.<\/p>\n<p>A repeatable onboarding checklist gives you three things:<\/p>\n<ul>\n<li>A clean baseline of what the environment actually contains, not what the client says it contains<\/li>\n<li>A defensible audit trail if something breaks in month one<\/li>\n<li>A faster time to first monitoring, patching, and backup \u2014 usually 14 days instead of 45<\/li>\n<\/ul>\n<p>The rest of this guide walks through the exact sequence, broken into the same phases we use with MSPs running Superdocu workflows.<\/p>\n<h2>The full MSP client onboarding checklist<\/h2>\n<p>This is the complete list. Cut items that do not apply to the engagement type (a co-managed IT retainer needs less than a full white-glove takeover).<\/p>\n<h3>1. Contracts and legal<\/h3>\n<ul>\n<li>Signed master services agreement (MSA) with the agreed SLA<\/li>\n<li>Signed statement of work (SOW) for the initial 30-day onboarding<\/li>\n<li>Non-disclosure agreement (if not bundled in the MSA)<\/li>\n<li>Letter of authorization (LOA) for each SaaS vendor and ISP you will contact on the client&#8217;s behalf<\/li>\n<li>Data processing agreement (DPA) \u2014 required for EU clients, and increasingly expected in the US<\/li>\n<li>Business associate agreement (BAA) for HIPAA-regulated clients<\/li>\n<li>W-9 or equivalent tax form<\/li>\n<li>Insurance certificate (cyber liability, professional liability)<\/li>\n<\/ul>\n<p>Send these through e-signature. If you use Superdocu, the DocuSign integration is inside the workflow so the client signs and the countersigned PDF is filed automatically in the portal \u2014 no separate DocuSign inbox to babysit.<\/p>\n<h3>2. Company and stakeholder information<\/h3>\n<ul>\n<li>Legal company name, DBAs, and tax ID<\/li>\n<li>Registered address and all branch or remote-office addresses<\/li>\n<li>Primary billing contact and billing email<\/li>\n<li>Escalation contacts (name, role, phone, email) \u2014 technical, executive, after-hours<\/li>\n<li>Named decision maker for change approvals<\/li>\n<li>Preferred communication channels (email, ticket portal, Teams, Slack)<\/li>\n<li>Business hours, holidays, freeze windows<\/li>\n<\/ul>\n<p>Nail down the escalation contacts on day one. The number of MSPs that discover on day 20 they have no after-hours phone number is embarrassing.<\/p>\n<h3>3. Network discovery<\/h3>\n<ul>\n<li>List of all physical sites and remote-work locations<\/li>\n<li>Public IP ranges and ownership (client-owned vs ISP-assigned)<\/li>\n<li>ISP account details for each site (account number, contact, contract end date)<\/li>\n<li>Network diagram, if one exists (assume it does not)<\/li>\n<li>Firewall make, model, serial, and management interface<\/li>\n<li>Switch and access point inventory<\/li>\n<li>VLAN structure and IP scheme<\/li>\n<li>VPN configuration and users<\/li>\n<li>Wi-Fi SSIDs, encryption, and management access<\/li>\n<\/ul>\n<p>This is the section where the client typically says &#8220;we do not have that documented.&#8221; That is fine. Ask for what exists and plan a discovery scan in week one.<\/p>\n<h3>4. Server and endpoint inventory<\/h3>\n<ul>\n<li>Physical and virtual server list (hostname, OS, role, location)<\/li>\n<li>Hypervisor details (VMware, Hyper-V, Proxmox \u2014 versions and licensing)<\/li>\n<li>Domain controllers and Active Directory forest \/ domain structure<\/li>\n<li>File servers and shared storage (NAS, SAN)<\/li>\n<li>Endpoint list (laptops, desktops, thin clients) with rough count by department<\/li>\n<li>Operating system versions and patch status<\/li>\n<li>BYOD and remote worker devices<\/li>\n<li>Mobile device management (MDM) enrollment status<\/li>\n<\/ul>\n<p>If the client has fewer than 200 endpoints, a spreadsheet is fine. Above that, plan on running a discovery tool during week one to build the real inventory.<\/p>\n<h3>5. Credentials and access<\/h3>\n<ul>\n<li>Domain admin account (dedicated to the MSP, not a shared password)<\/li>\n<li>Local admin accounts on servers and endpoints<\/li>\n<li>Firewall and switch management credentials<\/li>\n<li>Cloud tenant admin access (Microsoft 365, Google Workspace, Azure, AWS, GCP)<\/li>\n<li>Backup software admin account<\/li>\n<li>Antivirus \/ EDR admin console<\/li>\n<li>Vendor portals (ISP, hardware manufacturer support, license portals)<\/li>\n<li>Line-of-business application admin credentials<\/li>\n<\/ul>\n<p>Do not accept a shared password document over email. Ask the client to create dedicated MSP accounts for each system, or receive credentials through a secure vault. This is the top compliance failure in MSP onboarding audits.<\/p>\n<h3>6. Backup, disaster recovery, and business continuity<\/h3>\n<ul>\n<li>Existing backup solution (vendor, version, licensing)<\/li>\n<li>Backup schedule and last successful test restore date<\/li>\n<li>Backup destinations (local, cloud, offsite)<\/li>\n<li>Retention policies and legal or regulatory requirements<\/li>\n<li>RPO and RTO for critical systems<\/li>\n<li>Existing disaster recovery plan (any format)<\/li>\n<li>Business continuity contacts and procedures<\/li>\n<\/ul>\n<p>Assume no backups are working until you have restored a real file from them. This is not paranoia; it is the leading cause of client crises in month two.<\/p>\n<h3>7. Security baseline<\/h3>\n<ul>\n<li>Current antivirus \/ EDR product and coverage report<\/li>\n<li>MFA enrollment status across email, remote access, and admin accounts<\/li>\n<li>Password policy (length, complexity, rotation)<\/li>\n<li>Existing SIEM or log aggregation<\/li>\n<li>Cyber insurance requirements the client must meet<\/li>\n<li>Compliance frameworks in scope (SOC 2, HIPAA, PCI DSS, ISO 27001, CMMC)<\/li>\n<li>Known security incidents in the last 24 months<\/li>\n<li>Existing security awareness training program<\/li>\n<\/ul>\n<p>The security baseline drives what you have to fix in the first 90 days. Get it in writing, tie the gaps to the SOW, and price the remediation separately.<\/p>\n<h3>8. Line-of-business applications<\/h3>\n<ul>\n<li>Application list (name, vendor, version, purpose)<\/li>\n<li>Number of users per application<\/li>\n<li>Vendor support contract details and renewal dates<\/li>\n<li>Integration points (SSO, ERP, accounting, CRM)<\/li>\n<li>Custom scripts, macros, or Access databases nobody wants to admit exist<\/li>\n<li>Application owners inside the client team<\/li>\n<\/ul>\n<p>Every MSP has a story about the mystery Windows Server 2008 running one payroll script. Discovery week is when you find yours.<\/p>\n<h3>9. Microsoft 365 or Google Workspace tenant<\/h3>\n<ul>\n<li>Tenant ID and primary domain<\/li>\n<li>Global admin access with dedicated MSP account<\/li>\n<li>Licensing summary (SKU, count, renewal date)<\/li>\n<li>Distribution lists and shared mailboxes<\/li>\n<li>Mail flow rules and connectors<\/li>\n<li>Existing conditional access policies<\/li>\n<li>Third-party app permissions granted in the tenant<\/li>\n<li>SharePoint \/ OneDrive storage usage<\/li>\n<\/ul>\n<p>Tenants are where hidden costs live. A single unmonitored app registration can leak client data for years. Audit the third-party apps before you take on management.<\/p>\n<h3>10. Documentation handoff<\/h3>\n<ul>\n<li>Existing runbooks, wikis, or SOP documents from the previous provider<\/li>\n<li>Network and server passwords (moved into your PSA \/ password manager)<\/li>\n<li>Vendor contact list<\/li>\n<li>Warranty and support contract PDFs<\/li>\n<li>Existing tickets or open incidents from the previous MSP<\/li>\n<li>Any pending change requests<\/li>\n<\/ul>\n<p>Get the previous MSP&#8217;s documentation, even if it is bad. Bad documentation is faster to rewrite than starting from a blank page.<\/p>\n<h2>MSP onboarding phases: a 30-day plan<\/h2>\n<p>Use the checklist above inside a phased plan so the client experiences steady progress instead of one giant discovery marathon.<\/p>\n<table>\n<thead>\n<tr>\n<th>Phase<\/th>\n<th>Days<\/th>\n<th>Owner<\/th>\n<th>Focus<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Kickoff<\/td>\n<td>1\u20132<\/td>\n<td>MSP + Client<\/td>\n<td>Contract signing, stakeholder introductions, portal handoff<\/td>\n<\/tr>\n<tr>\n<td>Discovery<\/td>\n<td>3\u201310<\/td>\n<td>MSP<\/td>\n<td>Site walks, scans, inventory building, tenant audits<\/td>\n<\/tr>\n<tr>\n<td>Documentation<\/td>\n<td>8\u201314<\/td>\n<td>MSP + Client<\/td>\n<td>Fill inventory gaps, network diagram, runbooks<\/td>\n<\/tr>\n<tr>\n<td>Security baseline<\/td>\n<td>10\u201320<\/td>\n<td>MSP<\/td>\n<td>Deploy EDR, enforce MFA, remediate critical gaps<\/td>\n<\/tr>\n<tr>\n<td>Tooling deployment<\/td>\n<td>12\u201325<\/td>\n<td>MSP<\/td>\n<td>RMM agents, backup agents, monitoring, patching<\/td>\n<\/tr>\n<tr>\n<td>Handoff<\/td>\n<td>25\u201330<\/td>\n<td>MSP + Client<\/td>\n<td>Walkthrough, first executive review, tickets go live<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The most common failure mode is trying to complete every phase in parallel. Run kickoff and discovery serially. Everything else can overlap.<\/p>\n<h2>Common MSP onboarding mistakes to avoid<\/h2>\n<p><strong>Skipping the LOAs.<\/strong> Without a signed LOA, most vendors will not talk to you. You end up looping the client into every ISP call for weeks. Batch all LOAs into the day-one signature pack.<\/p>\n<p><strong>Accepting the client&#8217;s inventory as gospel.<\/strong> Whatever the client tells you is missing at least 15% of the environment. Always run an independent discovery scan.<\/p>\n<p><strong>Deploying tools before discovery is finished.<\/strong> Pushing RMM agents to a network you have not mapped means you push to servers you did not know existed, break something, and start the relationship on a bad note.<\/p>\n<p><strong>Forgetting the previous MSP&#8217;s exit checklist.<\/strong> Confirm the outgoing provider has removed their tools, revoked their access, and returned any physical hardware. Otherwise you spend month two hunting rogue agents.<\/p>\n<p><strong>Not tracking document and certificate expirations.<\/strong> Cyber insurance certificates, SSL certs, warranty contracts, DPA renewals \u2014 miss one and you are exposed. Build a <a href=\"https:\/\/www.superdocu.com\/en\/blog\/document-expiration-tracking\/\">document expiration tracking<\/a> workflow so renewals nudge you automatically.<\/p>\n<p><strong>Treating onboarding as a one-time event.<\/strong> The environment drifts. Re-run a shorter version of the checklist every 12 months to catch changes the client forgot to mention.<\/p>\n<h2>How to actually run MSP client onboarding<\/h2>\n<p>Most MSPs still run onboarding from a mix of email, a shared Notion doc, and their PSA. It works for the first few clients and starts to fall apart at ten. Three patterns we see, ranked from worst to best.<\/p>\n<p><strong>Email plus a shared drive.<\/strong> The default. Client uploads to Google Drive, you email a spreadsheet of what is missing, someone forgets to update it. Works if you onboard one client per quarter.<\/p>\n<p><strong>PSA task list.<\/strong> A step up. Most PSAs (ConnectWise, HaloPSA, Autotask, HubSpot for smaller shops) support onboarding project templates. The gap: your client has to learn your PSA, and the PSA is not designed for external document collection. Most clients never log in twice.<\/p>\n<p><strong>A branded document collection portal.<\/strong> What we recommend. The client gets one link, sees your onboarding steps in order, uploads everything in one place, and your team gets a dashboard of who is at what stage. No PSA training for the client, no email chasing for you.<\/p>\n<p>This is what MSPs use Superdocu for. Build the MSP onboarding workflow once \u2014 sections that match the checklist above \u2014 and assign it to every new client. The portal is branded to your MSP, not to Superdocu. Documents get filed by section automatically. Reminders go out on their own if the client stalls. Read more about how <a href=\"https:\/\/www.superdocu.com\/en\/blog\/document-collection-app\/\">collecting documents from clients online<\/a> compares to the ad-hoc email approach.<\/p>\n<p>For MSPs that also run internal onboarding for new hires, the <a href=\"https:\/\/www.superdocu.com\/en\/blog\/employee-onboarding-best-practices\/\">employee onboarding best practices<\/a> guide covers the workflow you can layer on the same portal. And if you sit on the vendor side of a client contract, the <a href=\"https:\/\/www.superdocu.com\/en\/blog\/vendor-onboarding-checklist\/\">vendor onboarding checklist<\/a> breaks down the paperwork enterprise clients will send back at you.<\/p>\n<h2>What to do after the 30 days<\/h2>\n<p>Two things on day 31.<\/p>\n<p>First, run a formal handoff meeting. The onboarding lead briefs the service desk, the account manager, and the vCIO on what they inherited: the quirks, the workarounds, the fires still smoking. Fifteen minutes, no slides, just the headline for each system.<\/p>\n<p>Second, archive the onboarding portal in a read-only state. The environment will drift. The onboarding record is your baseline for the QBRs to come.<\/p>\n<p>If your MSP also handles annual compliance renewals (cyber insurance, DPAs, HIPAA BAAs, SOC 2 vendor questionnaires), reuse the same portal with a recurring workflow. Set the expiration date once and the client gets reminded automatically \u2014 no more chasing the same paperwork every year.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>What should be in an MSP client onboarding checklist?<\/h3>\n<p>A complete MSP client onboarding checklist covers ten areas: contracts and legal, company and stakeholder information, network discovery, server and endpoint inventory, credentials and access, backup and disaster recovery, security baseline, line-of-business applications, Microsoft 365 or Google Workspace tenant, and documentation handoff. Trim sections that do not apply to the engagement type.<\/p>\n<h3>How long does MSP client onboarding take?<\/h3>\n<p>Thirty days is a realistic target for a full-service takeover. Co-managed IT engagements can finish in 10 to 14 days because the client team owns most of the discovery. Anything past 45 days usually means the client stalled on providing access or the environment is far larger than the SOW assumed.<\/p>\n<h3>What is the best way to collect documents from new MSP clients?<\/h3>\n<p>A branded document collection portal, structured around the onboarding checklist, is the cleanest approach. The client gets one link with all requests grouped by phase, uploads files in the right place, and your team sees exactly who is at what stage. Email plus a shared drive works for one or two clients but breaks at scale.<\/p>\n<h3>What documents should MSPs collect during onboarding?<\/h3>\n<p>Contracts (MSA, SOW, DPA, BAA if applicable), letters of authorization for each vendor, insurance certificates, network diagrams, hardware inventory, credentials, backup reports, security audit results, application inventories, and any documentation from the outgoing provider. Everything else can be derived from a discovery scan.<\/p>\n<h3>How do MSPs handle credentials securely during onboarding?<\/h3>\n<p>The credentials should never come through email or an unsecured spreadsheet. Ask the client to create dedicated MSP accounts for each system so you can rotate them cleanly at the end of the engagement, and receive one-time credentials through a password vault or a secure document collection portal that encrypts at rest and in transit.<\/p>\n<h2>Run your next MSP onboarding without the chaos<\/h2>\n<p>If you are still running MSP onboarding out of a Google Doc, a ConnectWise task list, and a stack of email threads, you are leaving weeks on the table for every new client. Superdocu gives you a branded portal, a reusable workflow, and automatic reminders \u2014 so the client gets a clean experience and your team gets one dashboard for the whole book of business.<\/p>\n<p><a href=\"https:\/\/www.superdocu.com\/en\">Start your free 7-day trial of Superdocu<\/a> and run your next MSP onboarding from a single workflow. No credit card required.<\/p>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What should be in an MSP client onboarding checklist?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"A complete MSP client onboarding checklist covers ten areas: contracts and legal, company and stakeholder information, network discovery, server and endpoint inventory, credentials and access, backup and disaster recovery, security baseline, line-of-business applications, Microsoft 365 or Google Workspace tenant, and documentation handoff. Trim sections that do not apply to the engagement type.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How long does MSP client onboarding take?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Thirty days is a realistic target for a full-service takeover. Co-managed IT engagements can finish in 10 to 14 days because the client team owns most of the discovery. Anything past 45 days usually means the client stalled on providing access or the environment is far larger than the SOW assumed.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What is the best way to collect documents from new MSP clients?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"A branded document collection portal, structured around the onboarding checklist, is the cleanest approach. The client gets one link with all requests grouped by phase, uploads files in the right place, and your team sees exactly who is at what stage. Email plus a shared drive works for one or two clients but breaks at scale.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What documents should MSPs collect during onboarding?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Contracts (MSA, SOW, DPA, BAA if applicable), letters of authorization for each vendor, insurance certificates, network diagrams, hardware inventory, credentials, backup reports, security audit results, application inventories, and any documentation from the outgoing provider. Everything else can be derived from a discovery scan.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How do MSPs handle credentials securely during onboarding?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"The credentials should never come through email or an unsecured spreadsheet. Ask the client to create dedicated MSP accounts for each system so you can rotate them cleanly at the end of the engagement, and receive one-time credentials through a password vault or a secure document collection portal that encrypts at rest and in transit.\"\n      }\n    }\n  ]\n}\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The first 30 days of an MSP engagement decide whether the client turns into a quiet, profitable account \u2014 or a support-ticket bonfire. What separates the two is not the technical work. It is whether onboarding was run from a repeatable process or improvised over Teams. Below is the MSP client onboarding checklist we recommend [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":7728,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[26],"tags":[],"class_list":["post-7727","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-english"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/posts\/7727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/comments?post=7727"}],"version-history":[{"count":0,"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/posts\/7727\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/media\/7728"}],"wp:attachment":[{"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/media?parent=7727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/categories?post=7727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.superdocu.com\/en\/wp-json\/wp\/v2\/tags?post=7727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}