Mistake 1: an incomplete or overly vague specification
The first source of failure in IT outsourcing projects is the quality of the specification. Too often, French CIOs write 5-page specs when 50 would be needed. A complete specification must cover: the current application landscape, expected SLAs by service, security requirements (ANSSI, ISO 27001), reporting requirements and reversibility conditions.
Mistake 2: neglecting the provider's technical maturity
Not all IT providers are equal. Before signing, require a technical demonstration on your real environments, verifiable certifications (AWS, Azure, GCP Partner) and a presentation of the monitoring tools used. A provider who cannot show you your infrastructure status in real time should raise concerns.
Mistake 3: poorly calibrated SLAs without effective penalties
SLAs are the cornerstone of IT managed services. Loose SLAs (e.g. 95% availability = 18 authorised hours of downtime per month) offer no real protection. Best practice recommends a 99.9% availability SLA (= maximum 44 minutes/month) for critical systems, with progressive penalties from the first breach.
- Critical availability (ERP, CRM): ≥ 99.9% — penalty from first breach
- P1 (critical) resolution time: < 2 hours
- P2 (major) resolution time: < 4 hours
- P3 (minor) resolution time: < 24 hours
- Complete incident report: within 48 hours after resolution
Mistake 4: treating security as an option
In 2026, cybersecurity must be a non-negotiable contractual requirement, not an optional add-on. Your managed services contract must include: annual penetration tests (results shared), patch management within 72 hours for critical vulnerabilities, an active 24/7 SOC, and an ANSSI-compliant incident response plan.
Mistake 5: no exit plan from day one
Reversibility is often seen as a sign of distrust. It is in fact a clause of sound contract management. Define at negotiation stage: the duration of the reversibility period (minimum 6 months), notice period, documentation and successor training obligations, and what happens to data (migration to client or certified destruction).
