How to Switch IT Support Provider Without Downtime: The 2026 UK Handover Checklist

24th August 2026

The short answer: Switching IT support provider takes most UK businesses 30 to 60 days and should involve no downtime at all if it is sequenced properly. Start 90 days before your renewal date, because most contracts require 30 to 90 days written notice and many auto-renew if you miss the window. Before you serve notice, confirm in writing who holds administrative control of your Microsoft 365 tenant, domains, DNS, backups, firewall and licences. Your business owns its data, and under UK GDPR Article 28(3)(g) your outgoing provider is contractually obliged to delete or return all the personal data it processed for you. Failed transitions are almost never caused by the act of switching. They are caused by missing admin access, unclear ownership, or services being cancelled before the new provider is ready.

That is the executive version. The rest of this guide is the detail that keeps the switch boring, which is exactly what you want it to be.

GRAY IT

Why do businesses switch IT support provider?

Very few businesses leave over a single incident. They leave over a pattern. The common triggers we see across Kent SMEs are consistent:

  • Tickets get resolved, but the same problems keep recurring, which means nobody is fixing root causes
  • The provider is reactive rather than proactive, so you find out about problems before they do
  • Security and compliance are treated as an upsell rather than part of the service
  • You have outgrown them, or they have grown past you and you are now their smallest account
  • Costs have crept upward through out-of-scope charges you were never warned about
  • Backups exist but nobody has ever tested a restore
  • Documentation is thin, so a single engineer holds all the knowledge in their head

If two or more of these sound familiar, the question is no longer whether to move. It is how to move without breaking anything.

One piece of context worth knowing before you start. The government’s Cyber Security Breaches Survey 2025/2026 found that just 15% of UK businesses formally review the risks posed by their immediate suppliers. Your IT provider is very likely the supplier with the deepest access to your systems and your data. A provider change is the natural moment to carry out the review you have probably never done.

How long does it take to switch IT support providers?

A typical transition runs 30 to 60 days from notice to full handover, though complexity drives that range considerably. Plan on the following shape:

Phase Typical duration What happens
Contract review and planning Week 1 to 2 Read your agreement, find the notice period and renewal date, build the asset register
Provider selection and discovery Week 2 to 4 New provider audits your environment, produces scope and fixed quote
Serve notice Aligned to your notice period Written notice, ideally after the new provider is appointed
Technical handover Week 4 to 8 Admin credentials, documentation, monitoring agents, backup verification
Parallel running 1 to 2 weeks Both providers have visibility, new provider takes the tickets
Cutover and closure Final week Old provider access revoked, data returned or deleted, final invoice settled

The single biggest scheduling mistake is serving notice before you have chosen a replacement. That leaves you negotiating with a new provider while a clock runs down, which is the weakest possible position. Choose first, then serve notice.

What does your IT support contract actually say?

Before anything else, read the agreement you signed. Five clauses matter more than the rest.

  1. Notice period. Usually 30, 60 or 90 days, and almost always required in writing. Email is normally acceptable but check whether the contract specifies post.
  1. Auto-renewal. Some agreements contain evergreen clauses that roll you into another 12 month term if you fail to give notice inside a narrow window before the anniversary. This is the clause that traps most businesses. Diarise your renewal date today.
  1. Early termination charges. How are they calculated, and do they apply if you are terminating for repeated service failure rather than convenience?
  1. Exit and handover obligations. Does the contract oblige the provider to cooperate with an incoming provider, hand over documentation, and transfer administrative control? Is there a charge for it? Many contracts are silent here, which is worse than a bad clause because it leaves everything to goodwill.
  1. Ownership. Whose name is on the Microsoft 365 tenant, the domain registration, the antivirus subscriptions, the backup repository and the firewall licences? If the answer is your provider’s, you have a dependency rather than a supplier.

If you are also weighing up what the replacement should cost, our guide to IT support costs in the UK sets out realistic per user pricing and the questions that expose a badly scoped quote.

What does UK GDPR say about your data when you leave?

This is the part almost every switching guide skips, and it is the part that gives you actual leverage.

Your IT support provider processes personal data on your behalf. In data protection terms, your business is the controller and your provider is a processor. That relationship must be governed by a written contract, and the ICO is explicit about what that contract has to contain.

Under Article 28(3)(g), the contract must say that at the end of the contract the processor must, at the controller’s choice, delete or return all the personal data it has been processing, and delete existing copies unless UK law requires it to be stored. The choice is yours, not theirs.

The ICO adds a practical caveat that is worth quoting to any provider who claims immediate deletion is impossible. It recognises that data in backups or archives may not be deletable straight away, and accepts that this is reasonable provided appropriate safeguards are in place, such as the data being put immediately beyond use, with deletion following on the provider’s next destruction cycle. So “we cannot delete it yet” is an acceptable answer. “We will keep it indefinitely and not tell you what we do with it” is not.

Two further clauses help you:

  • Article 28(3)(h) requires your provider to give you all the information needed to demonstrate it has met its Article 28 obligations, and to allow for and contribute to audits and inspections carried out by you or an auditor you appoint. That is a contractual right to ask for evidence, not a favour.
  • Article 28(3)(a) requires the processor to act only on your documented instructions. A written instruction to transfer administrative control to your incoming provider on a specific date is exactly that.

Put plainly: when you leave, you are entitled to your data back in a usable form, entitled to written confirmation of what has been deleted, and entitled to evidence. Send these requests in writing and reference the clause. Conversations that were vague tend to become precise very quickly.

If your data map is unclear in the first place, a GDPR and cyber security audit establishes what personal data you hold, where it sits and who can reach it. Doing that before a provider change is far easier than reconstructing it afterwards.

The IT provider handover checklist

This is the document that decides whether your switch is uneventful. Build it before you serve notice, and treat anything you cannot complete as a risk rather than an admin task.

Accounts and administrative control

  • Microsoft 365 or Google Workspace global admin, and confirmation the tenant is registered to your business
  • Domain registrar account and DNS control panel
  • Firewall, router and switch admin credentials
  • Wi-Fi controller and access point management
  • Server and hypervisor administrator accounts
  • Antivirus and endpoint detection console
  • Backup platform console, plus the repository location
  • Remote monitoring and management agent removal plan
  • Telephony, VoIP and broadband provider portals
  • Line of business application admin accounts and vendor support contacts

Documentation

  • Network diagram and IP addressing scheme
  • Asset register: users, devices, servers, warranties, ages, specifications
  • Licence inventory with renewal dates and who the licences are registered to
  • Password vault export, transferred securely, never by email
  • Open tickets, known faults and planned projects
  • Supplier contacts and account numbers

Security and data

  • Written confirmation of what personal data the outgoing provider holds
  • Instruction to delete or return, under Article 28(3)(g), with your choice stated
  • Confirmation that all outgoing provider accounts, VPN access and admin credentials are disabled at cutover
  • A full password and credential rotation after handover, without exception
  • A verified backup restore test carried out by the incoming provider before the old provider’s access ends

That last point deserves emphasis. Do not accept a backup report as proof. Ask the incoming provider to restore something and show you the file. Our guide on whether Microsoft 365 backs up your data explains why native retention is not the safety net most businesses assume it is, and a provider change is precisely when that gap becomes visible.

How do you switch IT providers without downtime?

Downtime during a transition is a sequencing failure, not an inevitability. Four rules prevent almost all of it.

Overlap, never gap. Keep the outgoing contract live until the incoming provider has confirmed full administrative control and a successful backup restore. Paying for two weeks of overlap is cheap compared with a day of lost trading.

Change one thing at a time. Resist the temptation to bundle a server migration, a firewall replacement and a Microsoft 365 restructure into the handover. Transition first, improve second, so that if something breaks you know what caused it.

Cut over out of hours. DNS changes, credential rotation and agent swaps belong to an evening or a weekend, with an agreed rollback point.

Name one owner on your side. One person maintains the checklist, approves each stage and confirms who is responsible for what. Transitions drift when three people each assume another has it.

Do not cancel anything early. Cancelled licences, expired domains and terminated broadband contracts cause more transition outages than technical faults do. Nothing gets cancelled until the replacement is live and verified.

Should you tell your current provider you are leaving?

Yes, but the order matters. Appoint your new provider first, agree the handover plan, then serve formal written notice. Doing it the other way round means negotiating under time pressure with no alternative in place.

Be professional about it. Most handovers go smoothly, and the industry in Kent is small enough that reputations travel. Keep the correspondence factual, put every request in writing, and reference contractual and regulatory obligations where you need to. If cooperation stalls, a written reminder of the Article 28(3)(g) and 28(3)(h) obligations is usually enough. If it is not, you can raise a complaint with the ICO, though it very rarely reaches that point.

What should you look for in a new IT support provider?

Use the switch to buy a better specification, not just a lower price:

  • Proactive by design. Ask what they do to stop tickets being raised, not just how fast they close them.
  • Security inside the fee. Patching, endpoint detection, email security and backup monitoring should be included rather than bolted on. Ask which of the five Cyber Essentials controls they will implement and maintain.
  • Documentation as standard. Ask to see a sample asset register and network diagram from another client, redacted.
  • Tested restores, not backup reports. Ask how often restores are tested and whether you get the evidence.
  • Clean exit terms in your new contract. Insist on a written offboarding clause, confirmation that all licences and tenants are registered to you, and a defined handover obligation. Negotiating your exit on day one is the single most useful thing you can do.
  • Realistic onsite response. A provider in Maidstone or Medway can reach most of Kent inside an hour. A London-based provider may look cheaper and arrive considerably later.

Switching IT support provider in Kent

Gray IT takes on businesses mid-contract and mid-transition regularly, across Medway, Maidstone, Rochester and Chatham. We run the handover checklist for you, deal with the outgoing provider directly so you do not have to, and verify a restore before anyone’s access is switched off. Our IT support contracts state ownership and exit terms in plain English, because a contract you can leave easily is a contract worth staying in.

Thinking about moving? Book a free, no-obligation IT and security review. We will audit what you currently have, tell you plainly what your existing provider controls that you should, flag which Cyber Essentials controls are missing, and give you a fixed quote and a transition plan. No pressure, and no obligation to switch. Get in touch with Gray IT.

Frequently asked questions

How long does it take to switch IT support providers? Typically 30 to 60 days from serving notice to full handover, depending on contract terms, network complexity and how much documentation exists. Start planning at least 90 days before your renewal date so that your notice period and provider selection do not overlap awkwardly.

Will switching IT providers cause downtime? It should not. Downtime during transitions is almost always caused by sequencing errors rather than the switch itself, most commonly cancelling services too early, missing administrative credentials, or attempting infrastructure changes during the handover. Keep the outgoing contract live until the incoming provider has confirmed full control and a verified backup restore.

Who owns my data if I leave my IT provider? Your business does. Your provider processes data on your behalf as a processor under UK GDPR, and Article 28(3)(g) requires the contract to state that at the end of the contract the processor must, at your choice, delete or return all personal data it has been processing, and delete existing copies unless UK law requires storage.

What notice period do IT support contracts usually have? Most require 30 to 90 days written notice. Check carefully for auto-renewal or evergreen clauses that roll you into a further 12 month term if notice is not served inside a specific window before the anniversary date.

Can my current IT provider refuse to hand over admin access? They should not, and in practice it is rare. Where personal data is involved, Article 28(3)(a) requires the processor to act on your documented instructions and Article 28(3)(h) requires them to provide information demonstrating compliance and to contribute to audits. Put requests in writing, cite the clauses, and escalate to the ICO only if cooperation genuinely fails.

Should I tell my current IT provider before I find a replacement? No. Appoint the new provider and agree the handover plan first, then serve formal written notice. Serving notice first leaves you selecting a replacement against a deadline, which weakens your negotiating position and increases transition risk.

What should I change immediately after switching IT provider? Rotate every credential the outgoing provider held, including admin accounts, service accounts, Wi-Fi keys, VPN access and shared passwords. Disable their remote access tooling and remove their monitoring agents. Confirm in writing that their accounts have been deactivated and that your data has been returned or deleted.

Is it worth switching IT provider if I am mid-contract? It can be, depending on early termination charges and how much service failure you are absorbing. Compare the exit cost against the annual cost of recurring problems, out-of-scope charges and unmanaged risk. Where the contract is not being performed, exit charges are often negotiable.