A Checklist for Choosing Any IT Supplier
Nine checks that apply whether you are buying managed IT, CCTV, connectivity or hosting — and three answers that should end the conversation early.
The Seek Tech editors7 July 2026
The six categories on this site are different trades with different licences, but the diligence underneath them is largely the same. If you are buying any of it and do not have a technical person of your own, this is the short list.
1. Check the company actually exists, as quoted
Get the registered company name and registration number, and check it against Malaysia’s companies register. Two specifics matter more than the existence check itself:
- The entity on the register should be the entity on the contract and the invoice. Brand names and trading names are common and fine; a mismatch you only discover when chasing a refund is not.
- Note how long it has been registered. Not disqualifying either way — but a company incorporated four months ago quoting a five-year support contract is a question worth asking out loud.
2. Get the licence for the specific work
Different work, different credential:
- Connectivity and voice — the MCMC licence class, and the licence holder’s name.
- Penetration testing and outsourced SOC — the cybersecurity service provider licence, where the service is licensable.
- Security systems and alarm monitoring — ask what permits apply to the monitoring element, which is regulated differently from installation.
- Anything touching mains electrical work — the contractor’s electrical competency, which is not an IT credential at all.
A general “we are certified” is not an answer. The answer is a class, a number and an issuing body.
3. Verify certificates with the issuer, not the supplier
Any certificate worth citing is verifiable: ISO certificates through the certification body, CREST through its member directory, vendor partner status through the vendor’s own partner locator. A PDF is not evidence, and checking takes minutes.
Read the scope on anything you verify. Certificates are frequently narrower than the way they are presented.
4. Ask who does the work
Subcontracting is normal, especially for cabling, civil work and out-of-state sites. Undisclosed subcontracting is the problem.
Ask whether any part of the job is subcontracted, to whom, and who carries responsibility if that party fails. Then ask for the named individuals on your engagement and what they hold. Firms sell with senior people and deliver with juniors — this is not a scandal, but you should know which you are getting.
5. Ask for two references you can actually call
Not logos. Two customers of comparable size, in a comparable trade, who agreed to be contacted. Then ask them one question that gets past politeness: what happened the last time something went wrong?
A supplier who cannot produce a single contactable reference for work like yours is telling you they have not done work like yours.
6. Make the deliverables physical
“Full documentation provided” means nothing. List what arrives and in what format: network diagram, asset and licence inventory, credential list, configuration backup, camera and coverage plan, IP schedule, recovery procedure.
Then agree when each arrives. Documentation promised at project end and never delivered is the single most common quiet failure in this industry.
7. Establish who owns the accounts
For every system involved, ask whose name it is registered in: the domain, the cloud tenant, the firewall management console, the CCTV cloud platform, the phone numbers, the backup console.
Your name on all of them, with an administrator credential you hold. Anything else converts a future supplier change into a migration.
8. Ask what leaving looks like
Before signing, ask what happens at termination: notice period, transition assistance in hours, what is handed over, in what format, and at what cost. A supplier confident in their service is relaxed about this question.
9. Check for the single point of failure
Some of the best value in this market is a two-person outfit that genuinely knows its work. That is a real option, but understand the risk: what happens when the one person who knows your setup is unavailable for a month? Ask who the second person is. If there is not one, put the documentation requirement in clause 6 at the top of your list.
Three answers that should end the conversation
- “Don’t worry about the contract, we’re flexible.” The contract is the only thing that exists at 2am.
- “We’ll put the tenant under our account, it’s easier.” It is easier. For them.
- A price that only holds if you sign today. Nothing about IT procurement is improved by hurry.
What this checklist is not
It will not tell you whether the work will be good. Nothing you do before signing will. What it does is remove the failures that are foreseeable — the unlicensed reseller, the unverifiable certificate, the account in someone else’s name, the documentation that never arrives — so that what remains is an ordinary commercial judgement about people.
That is the part where you should be talking to two or three suppliers, not one.
The company registration number, the licence covering the specific work, and two contactable references.
Category-level guidance. It is not a statement about any company listed on this site, and it is not legal advice — confirm current requirements with the issuing body before you rely on them.