Skip to content
Expertise2 min read
Back to blog

IT outsourcing in France: 5 critical mistakes companies make


Mistake 1: an incomplete or overly vague specification

The first source of failure in IT outsourcing projects is the quality of the specification. Too often, French CIOs write 5-page specs when 50 would be needed. A complete specification must cover: the current application landscape, expected SLAs by service, security requirements (ANSSI, ISO 27001), reporting requirements and reversibility conditions.

Mistake 2: neglecting the provider's technical maturity

Not all IT providers are equal. Before signing, require a technical demonstration on your real environments, verifiable certifications (AWS, Azure, GCP Partner) and a presentation of the monitoring tools used. A provider who cannot show you your infrastructure status in real time should raise concerns.

Mistake 3: poorly calibrated SLAs without effective penalties

SLAs are the cornerstone of IT managed services. Loose SLAs (e.g. 95% availability = 18 authorised hours of downtime per month) offer no real protection. Best practice recommends a 99.9% availability SLA (= maximum 44 minutes/month) for critical systems, with progressive penalties from the first breach.

  • Critical availability (ERP, CRM): ≥ 99.9% — penalty from first breach
  • P1 (critical) resolution time: < 2 hours
  • P2 (major) resolution time: < 4 hours
  • P3 (minor) resolution time: < 24 hours
  • Complete incident report: within 48 hours after resolution

Mistake 4: treating security as an option

In 2026, cybersecurity must be a non-negotiable contractual requirement, not an optional add-on. Your managed services contract must include: annual penetration tests (results shared), patch management within 72 hours for critical vulnerabilities, an active 24/7 SOC, and an ANSSI-compliant incident response plan.

Mistake 5: no exit plan from day one

Reversibility is often seen as a sign of distrust. It is in fact a clause of sound contract management. Define at negotiation stage: the duration of the reversibility period (minimum 6 months), notice period, documentation and successor training obligations, and what happens to data (migration to client or certified destruction).


📋 Request a quote