Choosing an MSP: What Turkish Companies Actually Want
Demand for managed services in Türkiye is rising while satisfaction stays low. What buyers look for in an MSP, and how to evaluate one properly.

Short answer: Companies in Türkiye are no longer buying cheap capacity from an MSP; they are buying the transfer of operational risk, and that has rewritten the selection criteria. The order is clear: demonstrable security and compliance capability, where the data physically sits, measurable SLAs, and transparent reporting. Even so, only 14% of decision-makers say they are satisfied with the outcome of their outsourcing transformation. The gap lies more in the buyer's preparation than in the provider's capability: a relationship entered without a defined scope, a written exit clause and agreed metrics will stall in the same place regardless of who is on the other side.
This article looks at what Turkish companies actually want from an MSP, which new obligations have made that decision unavoidable, and how the evaluation should be run, using current data from the Turkish market.
Why is demand for managed services accelerating in Türkiye?
Three concrete pressures are driving the demand, and all three are rising at once.
Cloud went mainstream, and complexity came with it. According to the Türkiye Corporate Cloud Research 2026 by vMind and M2S Araştırma, cloud adoption among organizations with 200+ employees rose from 49% to 63% in a single year, and 56% expect their cloud spend to increase. As the number of platforms grows, so does the operational load of keeping them running, and that load grows faster than most in-house IT headcounts.
The expertise gap has itself become the reason to buy. In TÜİK's 2025 data, 74.2% of enterprises not using AI cite "lack of relevant expertise" as the reason, ahead even of cost (67.4%). The same pattern holds for Kubernetes, observability, database engineering and security operations. We covered this in detail in our article on enterprise AI in Türkiye: the obstacle is less access to technology than the discipline to operate it.
Regulation turned a technical preference into a management decision. We deal with that separately below, but its effect already shows in the numbers: in the same cloud study, 41% of organizations plan to invest in managed services within the next 18 months, up from 37% a year earlier, with managed security services the strongest category. The study's own conclusion sums up this article's thesis: companies are buying operational risk transfer, not technology.
What buyers actually look for in an MSP
The questions a buyer asks in an MSP conversation have changed over the past five years. "How many engineers, at what hourly rate?" has been replaced by these:
Security and compliance capability as the foundation, not an add-on. In KPMG's Managed Services Outlook 2026, a survey of 1,224 senior leaders across 12 countries at organizations with revenues above $100 million, the top two investment priorities are AI management and cybersecurity, followed closely by regulatory compliance. In Türkiye that ranking is sharper still, because compliance now has legal teeth.
Where the data sits. In the Türkiye Corporate Cloud Research, 61% of organizations with 500+ employees require data to remain in Türkiye. In most tenders it has moved from a preference to an elimination criterion: which data center, under which jurisdiction, is a first-round question.
Measurable commitment. This is where buyers have matured most visibly: "24/7 support" on its own no longer counts as a commitment. They want an SLA that separates response time from resolution time, states who assigns severity, and specifies what happens when the target is missed. Where recovery targets are concerned, they rely on calculating RPO and RTO from business cost instead of the provider's promise.
Transparency. Incident counts, root cause analyses, recurring problems and risks left open, in place of a monthly "all green" report. A mature buyer wants to see the state of their own systems independently of the provider's narrative.
The Cybersecurity Law rewrote the criteria
Türkiye's Cybersecurity Law No. 7545, in force since March 19, 2025, turned MSP selection from a technical purchase into a compliance decision. The obligations it imposes include regular penetration testing, log management infrastructure, a current asset inventory, an incident response plan with clear allocation of responsibility, and employee awareness training. You can check whether you are in scope against the fifteen critical infrastructure sectors the law names.
Two provisions bear directly on provider selection: organizations must assess their suppliers and service providers for cybersecurity compliance, and must define cybersecurity obligations explicitly in the contract. For public institutions and critical infrastructure operators the bar is higher still: they may procure cybersecurity products and services only from providers authorized by the Cybersecurity Directorate. Administrative fines range from 100,000 TL to 100 million TL depending on the violation, and for certain forms of non-compliance can reach up to 5% of a company's annual gross sales revenue.
In practice, your MSP's security maturity is now part of your compliance exposure. EY Türkiye's assessment makes the same point: alongside technical controls, the law expects policies, inventories and a response framework. A provider saying "we can do that" is not the same as a provider able to show it.
Why most relationships fall short
This is the part MSP marketing does not discuss. PwC Türkiye's analysis of strategic IT outsourcing reports the following:
- 80% of IT organizations planning to outsource lack an adequate strategy grounded in business objectives.More than 60% of processes fail to define scope properly, producing incomplete, inconsistent proposals that cannot be compared against one another.Only 14% of decision-makers are satisfied with the outcome of the transformation.25% of contracts auto-renew without any review; only 17% go through a fresh procurement process.
Put side by side, these figures locate the problem. Most dissatisfaction comes from nobody ever having defined what was promised, rather than from an MSP performing badly. In a relationship with an undefined scope, both parties are right by their own definition, which is the hardest kind of dispute to resolve.
Seven questions that tell MSPs apart
For a team that wants to judge an MSP by its answers rather than its slide deck:
- What is outside the scope? A good MSP answers this precisely. "Everything is included" signals that scope was never thought through.Who assigns severity? If the provider defines what counts as critical, the provider effectively controls your SLA.Is the commitment to response time or to resolution time? The real service level lies entirely in the gap between the two.Where does the data sit and who can access it? Jurisdiction, access logs and an authorization matrix should be in writing.How do exit and handover work? When the contract ends, how are documentation, automation code and access handed back? Without a defined exit, the relationship becomes a dependency.What does the report show? The number of tickets closed is not a performance indicator; recurring root causes and risks left open are.Who will actually do the work? The architect in the sales meeting, or the team you meet after onboarding?
What these questions have in common is that they measure how well defined the relationship is; none of them measures how good the provider is. According to the Turkish data, that is what makes the difference.
The right question is not "which provider"
The managed services market in Türkiye is growing because the problem companies have to solve got bigger: more platforms, fewer specialists, heavier obligations. But the 14% satisfaction rate alongside that growing demand suggests the maturity problem in this market is not on the provider side.
Before entering an MSP relationship, answer three questions: which outcomes are being transferred, how will that be measured, and what remains when the relationship ends? If those three are in writing, finding the right provider is straightforward. If they are not, even the best MSP will fall short.
How Eclit defines those three is set out on the managed platform services page.
Sources
- KPMG Managed Services Outlook: global demand and satisfactionPwC Türkiye: strategic IT outsourcingEY Türkiye: how ready companies are for the Cybersecurity LawCloud adoption rate in TürkiyeLaw No. 7545 entering into forceCompany obligations under the lawHow we do this work: managed platform services