Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
Managed services make one provider accountable for how your IT runs every day, billed flat per user per month. Professional services make a provider accountable for one defined project, billed by milestone or by time. Most Canadian SMBs of 15 to 200+ users run managed coverage and buy project work separately.
Even the federal government buys along this split: Public Services and Procurement Canada (canadabuys.canada.ca) defines task-based IT professional services as finite assignments with a set start date, end date, and deliverables, which is exactly the professional-services side of the model.
The choice between managed services and professional services is a choice between two accountability structures. One vendor answers for how your systems run every day. The other answers for whether one defined piece of work shipped on scope. The pricing model and the escalation path both follow from that single split. This guide compares both for Canadian SMBs in the 15 to 200+ user band.
| Dimension | Managed services | Professional services |
|---|---|---|
| Engagement | Ongoing, multi-year | Project-based, fixed scope |
| Billing | Flat per-user/month or per-device/month | Milestone or T&M |
| Contract | MSA + SLA | SOW + acceptance criteria |
| Scope | Broad: operate, monitor, support, advise | Narrow: design, build, migrate, train |
| Accountability | Outcome (uptime, response time, FCR) | Deliverable (the migration completes, the firewall ships) |
| Best when | You need IT to run reliably and quietly | You have a defined one-time change |
| FC fit | 15 to 200+ user Canadian SMBs without internal IT | Project layered on a managed retainer, or standalone for SMBs with internal IT |
| Our recommendation | Default for a 50-seat firm with no internal IT | Add on top when a discrete change lands |
If you already run an internal IT team of 1 or 2 people, the closer comparison is co-managed IT services, which splits daily operations between your staff and an external provider. Buyers weighing a reactive hourly relationship instead should read hourly IT vs managed services.
Managed services in 60 seconds
According to the Canadian Centre for Cyber Security (2020), a small or medium Canadian organization should hold 13 baseline controls in place continuously, covering patching, backups and incident response. Managed services exists because those 13 controls need an owner every week of the year, and not only on the week they were installed.
Managed services means an external provider runs a defined slice of your IT continuously, billed at a flat per-user or per-device rate. The paperwork is a Master Service Agreement carrying a service level agreement that names response and resolution targets.
Performance is numeric here: uptime, first-contact resolution rate, mean time to repair. Fusion Computing runs both models, and the managed side is now the default for Canadian SMBs without a full internal IT team. A published SLA is easier to budget against than reactive hourly billing.
Professional services in 60 seconds
According to Microsoft (2026), FastTrack is a deployment benefit included with eligible Microsoft 365 subscriptions at no extra cost, built to get a tenant onboarded and data migrated. That is professional services in its purest shape: a scoped deliverable with an end date and no promise about what happens on day 400.
Professional services means a vendor scopes and delivers a finite project. A Microsoft 365 migration. A firewall replacement. A SOC 2 readiness sprint. The paperwork is a Statement of Work with acceptance criteria and a defined end date.
A cloud move is the classic scoped project. The ten cloud migration challenges that derail Canadian SMBs explain why the statement of work matters more than the platform.
Billing is milestone-based or time and materials, usually invoiced against 3 or 4 milestones. The vendor answers for the artifact it agreed to ship, so the project either meets the acceptance criteria or it does not. When the SOW closes, the engagement closes with it. The phone number you were calling stops being yours.
Side-by-side: when each model wins
According to Statistics Canada (2024), 16% of Canadian businesses were hit by a cyber security incident in 2023. National spending on recovery doubled over the same stretch, from roughly CA$600 million in 2021 to CA$1.2 billion in 2023. Recovery spend is the line item that decides this comparison, because only one of the two models is on the hook for it.
Five dimensions decide the fit for most Canadian SMBs. Order matters here. Cost is rarely the deciding factor, and accountability usually is.
Cost over 3 years
A managed retainer compounds. A professional services engagement hits hard at month zero, then drops to zero. For a 50-seat Canadian SMB, a one-time Microsoft 365 and Intune migration typically runs CA$12,000 to CA$22,000 fixed-scope.
After that migration, ongoing managed support starts at CA$180 per user per month, with a security-inclusive plan closer to CA$230. Across our 40+ Canadian SMB client engagements we measured the same shape every time: over three years, managed costs several times more in absolute dollars. The useful question is what the extra spend buys.
The recurring side of that math is broken out by service area in managed IT services for a 50-employee business, which prices the same per-user tiers against 50 seats.
SLA and who answers on Friday afternoon
Managed services sells an operating state. Professional services sells a deliverable. The practical gap shows up at month four, when something breaks at 4:45 on a Friday.
Under a managed SLA, the response clock starts when you open the ticket. Response time, escalation thresholds and remediation paths are written into the MSA before signing. Under a closed SOW, the call routes to a sales line and the answer is a change order. That gap is the most common reason Canadian SMBs convert from project-only relationships to managed retainers.
Speed-to-value
Professional services ships fast. A scoped firewall refresh or Microsoft 365 migration delivers value in weeks. Managed services compounds slowly. Month one looks like cost, and month twelve looks like reliability. The trade-off turns on whether the value you need is the change itself or the operating state that follows it.
Strategic vs operational scope
Most managed contracts include a strategic layer: a virtual CIO, a quarterly business review, a roadmap document refreshed every 12 months. Project shops sell the build and stop there.
Cybersecurity is where that shows up hardest. A SOC 2 readiness project closes when the report ships. The control programme that keeps SOC 2 valid year after year is managed work. Treating the two as one engagement is the most common scoping mistake we see in the Canadian SMB market.
Exit and transition
Managed agreements in the Canadian SMB market typically run an initial 12 to 36 month term, then continue with a notice period written into the MSA. Project agreements end at completion. The lock-in objection usually conflates the two. Managed services concentrates operations with one provider, while ownership of the assets stays with you: the Microsoft tenant, the device inventory and the password vault all stay registered in the client name.
Decision checklist: five criteria that settle the choice
According to the Center for Internet Security (2024), CIS Controls v8.1 defines 18 controls with a governance function layered across them. Governance is the word that settles this comparison. A project can stand up a control, and only a standing contract keeps that control running once the project team has moved on.
Answer these five questions honestly. Three or more answers in the left column point at a managed contract as the spine of IT for a 15 to 200+ user Canadian firm.
- Revenue exposure. Does revenue stop when email or line-of-business software stops? A yes puts you in managed territory.
- Internal capacity. Do you have at least one full-time technical person? No internal IT points at managed; one or two people points at co-managed.
- Change frequency. Is the work a single defined change, or a rolling set of small ones? One change is a Statement of Work.
- Regulatory load. Do PIPEDA, PHIPA, or a client security questionnaire apply? Continuous evidence needs a continuous owner.
- Budget shape. Can you carry a flat monthly line, or only a capital project? Flat monthly favours a retainer.
Our recommendation for a 50-seat Canadian firm with no internal IT: sign the managed contract first, then layer projects. If you want that scored against your own numbers, walk the five criteria through with Mike Pearlstein before you go to market.
What each model requires from your internal team
According to the Canadian Centre for Cyber Security (2025), the speed at which an incident is detected and contained drives its final cost. Detection speed is an operating capability rather than a project artifact, which is why the internal effort each model asks of you differs so sharply after go-live.
A professional services engagement requires the most from you at the front. Someone internal has to own scope, sign off on acceptance criteria, and chase the punch list. Budget 40 to 60 hours of internal time on a 50-seat migration.
A managed contract requires the most from you at onboarding, then very little. In our practice the internal load settles to a monthly ticket review and a quarterly business review inside 90 days.
What that monthly review can see depends on the support model underneath it. A queue that only closes tickets and a desk that keeps problem and change records read very differently, which is the split in help desk vs service desk.
An FC internal benchmark from Q2 2026 puts that settling point at 60 to 90 days for a 50-seat firm. Roughly two in three of our clients name the drop in internal coordination time as the change they noticed first, ahead of ticket volume or cost.
When SMBs combine both
According to the Office of the Privacy Commissioner of Canada (2012), PIPEDA Principle 4.1.3 makes an organization responsible for personal information transferred to a third party for processing. Neither contract model moves that duty off your desk, which is the strongest argument for keeping one accountable operator across both.
The dominant pattern in the Canadian SMB book is project-on-managed. A managed retainer acts as the operating spine, and professional services projects layer on when a discrete change is needed.
A typical sequence: a 50-seat client engages on a fixed-scope Microsoft 365 migration, converts to a managed contract within 18 months, then adds projects as the business changes. A SOC 2 readiness sprint. A Toronto office network refresh. A Vancouver onboarding when a second site opens. Most project-only engagements at Fusion Computing convert to managed inside that window.
What is an MSA, and what is a SOW?
According to AWS (2026), its managed offering monitors workloads 24x7x365 with proactive alarms and a full incident management lifecycle. That description is a service level commitment, and a service level commitment lives in a master agreement rather than in a project scope document.
A Master Service Agreement, or MSA, is the standing contract. It sets the SLA, the security obligations, the data handling terms, the notice period and the rate card. It has no natural end date, and it governs everything the provider does for you.
A Statement of Work, or SOW, is a single project under that umbrella. It names the deliverable, the acceptance criteria, the milestones and the price.
Two practical tests. Read the SLA in the MSA before you read the price. Then check that every SOW acceptance criterion is measurable by somebody on your side inside 30 days of handover. If you want a second pair of eyes on either document, send the draft over and we will read it with you.
How AWS, Microsoft, and Google name these
According to AWS (2026), AWS Professional Services sells scoped engagements across migration, modernization, data and AI, plus security at scale. The hyperscalers draw the same line the Canadian channel draws, and they use almost the same two words to draw it.
AWS Managed Services sells the operating layer instead: monitoring, incident management, security, patching and backup. Microsoft FastTrack sells onboarding as a benefit attached to eligible Microsoft 365 subscriptions.
When a Canadian SMB asks whether to engage a hyperscaler professional services team or its own provider for a workload migration, the sharper question is who operates the workload the morning after cutover. For a broader view of the buying decision, see how to choose an IT company or the numbers behind what managed IT costs in Canada.
Editorial pick: what FC would choose for a 50-seat Canadian SMB
“For a 50-seat Canadian SMB with no internal IT, we would sign managed services as the spine and buy professional services as scoped layers on top. A Microsoft 365 migration. A firewall refresh. A SOC 2 readiness sprint. The reason is accountability continuity. When the project ends, somebody still has to answer the phone at 2 a.m.”
Talk to Mike about your engagement model
Frequently asked questions
Are managed services more expensive than professional services?
Over 1 year, professional services usually costs less in absolute dollars, because the spend is scoped to a single project. Over 3 years, managed services costs several times more, because the spend never stops. The comparison worth running is cost per outcome: a closed project on one side, and an operating state with a published SLA on the other.
Can we use both at the same time?
Yes, and that is the most common Canadian SMB pattern. A managed retainer covers ongoing operations, support and advisory. Professional services projects layer on top when a discrete change is needed: a Microsoft 365 migration, a network refresh, a SOC 2 readiness sprint. The 2 contracts run in parallel, and the managed provider often executes or coordinates the project work.
How long is a typical managed services contract in Canada?
Most Canadian SMB Master Service Agreements run an initial 12 to 36 month term, then continue on a notice period set out in the agreement. The term funds the engineering bench, the tooling and the onboarding effort the provider carries up front. Ask any provider to show you the notice clause and the renewal terms before signing, and read them alongside the SLA.
Does AWS Professional Services do managed services?
No. AWS Professional Services scopes finite engagements such as cloud migrations, well-architected reviews, and security baselines. AWS Managed Services is a separate offering that operates workloads continuously, with 24x7x365 monitoring and incident management. The 2 offerings are complementary, sold under different contracts, and often combined the same way a Canadian provider combines project and managed work.
Which model should a 50-person Canadian company choose first?
Sign the managed contract first if you have no internal IT, then layer projects on top. A 50-person firm generates roughly 60 to 120 tickets a month, which is more than a project vendor will absorb between engagements. If you already employ 1 or 2 internal technical staff, price co-managed IT services against full managed before you decide, because the split changes the per-user rate.
Who is accountable for a data breach under a managed services contract?
You are, in law. PIPEDA Principle 4.1.3 keeps your organization responsible for personal information transferred to a third party for processing, so the contract shifts the work rather than the duty. What a managed contract should give you is evidence: named security obligations in the MSA, breach notification timelines and a documented incident response path you can hand to a regulator or an insurer.
Fusion Computing is a CISSP-led Canadian provider running both models for firms across Toronto, Hamilton and Metro Vancouver. To see how the split would work for your team, book a working session with Mike, or start with the managed IT services overview.

