A Newport Beach law firm sits down for their “free IT assessment” with a national MSP whose sales rep drove in from Riverside. The assessment consists of a 20 question checklist, a five minute external domain scan, and a two hour conversation about the firm’s current pain points. Ten days later, the firm receives a professionally designed 24 page report. The report identifies four “critical vulnerabilities,” six “moderate risks,” and lists a series of recommended solutions. Every single recommendation happens to be a service the MSP sells at premium tier pricing. The report costs the firm nothing. It also delivers, essentially, nothing.

This scenario plays out across Orange County several times a week. The IT assessment, once a legitimate diagnostic tool, has been quietly repurposed into the most common lead generation vehicle in the managed services industry. Most “free assessments” are professionally packaged sales pitches. Most paid assessments under $2,500 are the same product with a nicer cover. And the businesses that pay attention to them make investment decisions based on findings designed to justify a sale, not to help them.

Here is what a real IT assessment in Orange County should actually deliver, the specific artifacts a business should receive regardless of whether they hire the assessor, and the red flags that separate an honest diagnostic from a lead form dressed up in a suit.

$2,500
below this price, an assessment is a sales motion (industry benchmark)
20 Qs
the typical “free assessment” checklist depth (per open source MSP templates)
7
artifacts a real assessment produces, in writing, that outlast the assessor
24 mo
forward capacity planning horizon a real assessment covers

What most “IT assessments” actually deliver

The industry standard “free IT assessment” is a well engineered sales instrument. Understanding how it works is the first step to seeing through it. The typical structure:

The 20 question checklist. A short intake questionnaire covering approximate user count, whether MFA is deployed, whether backups exist, whether the business is in a regulated industry, and a handful of similar high level questions. Twenty questions is not an assessment. It is a lead qualification survey.

The external domain scan. A five minute automated scan of the business’s public facing internet presence. Any decent scanner will find something. That something becomes a “critical vulnerability” on the report.

The pain point conversation. A one to two hour discovery call in which the MSP’s salesperson asks about the business’s current frustrations. Every frustration mentioned reappears in the report as a “critical finding” that the MSP’s services can address.

The professionally designed report. A 20 to 40 page PDF, often with a business’s logo on the cover, listing findings, severity ratings, and recommendations. The design is polished. The findings are shallow. The recommendations all resolve to purchasing services from the assessor.

The industry critique is now explicit. Per Unio Digital’s 2026 IT infrastructure assessment guide: assessments priced under $2,500 are “a sales motion, not a real assessment.” The economics do not work otherwise. A serious assessment requires 40 to 80 hours of skilled engineering time, which cannot be delivered at zero cost. The “free assessment” is priced at zero because the intended revenue is the multi year managed services contract that follows.

What a real IT assessment should deliver

The industry has now converged on a clear standard for what a real IT infrastructure assessment produces. A complete assessment delivers seven specific artifacts, in writing, that a business can use regardless of whether they hire the assessor to implement any of it.

1. Executive summary. Two to four pages covering current state, top three risks, top three opportunities, and estimated investment required to move from current state to target state. Written for a business owner, not an IT technician.

2. Hardware, software, and SaaS inventory with end of life flags. A complete inventory of every server, workstation, network device, software license, and SaaS subscription. Not an approximation. Not “we counted the ones the client mentioned.” Every asset, discovered through actual environment scanning, with end of life dates flagged. Most businesses discover they are running 30 to 60 percent more SaaS subscriptions than anyone tracked.

3. Gap analysis by domain. A structured evaluation across eight domains: hardware, software, network infrastructure, storage and backup, security controls, cloud infrastructure, support and maintenance, and capacity planning. Each domain gets its own findings, current state description, and target state definition.

4. Risk register with severity and remediation owner. A prioritized list of every identified risk, with severity rating (critical, high, moderate, low), impact assessment, and named owner for remediation. Real risk registers get maintained; the assessment version is the starting point.

5. Twenty four month capacity plan. Forward projection of infrastructure capacity needs based on business growth plans, showing when specific systems will need expansion, replacement, or retirement. This is the artifact most “assessments” skip entirely because it requires actually understanding the business, not just scanning the systems.

6. Prioritized roadmap split into 30 day, 90 day, and 12 month initiatives. With timelines, dollar estimates, and success criteria for each initiative. This roadmap should be usable to justify budget requests and hold vendors accountable, regardless of which vendor executes it.

7. Vendor recommendations where outside help is needed. Specific recommendations for third party expertise (compliance consultants, specialized security firms, hardware vendors) with vendor names or vendor selection criteria. Honest assessors recommend vendors they do not benefit from when appropriate.

An assessment missing any of these seven artifacts is incomplete. An assessment missing five or six of them is a sales pitch with a report attached.

Sales pitch vs real assessment: side by side

Element Sales pitch assessment Real IT assessment
Price Free or under $2,500 $3,500 to $25,000 depending on scope
Discovery depth 20 question checklist plus one call 40 to 80 hours of environment scanning, interviews, and analysis
Inventory quality Client provided approximations Discovered through actual environment tools
Findings orientation Findings that map to services the assessor sells Findings that reflect actual risk, regardless of who fixes them
Roadmap “Next steps: sign here” 30 day, 90 day, 12 month prioritized initiatives with dollar estimates
Capacity planning None 24 month forward projection tied to business plans
Vendor recommendations All roads lead to the assessor Specific vendors recommended for specific work, including outside the assessor
Deliverable usability Useless without the assessor Usable to any third party, including your next MSP
Compliance context Generic mentions of frameworks Specific gap analysis against your applicable frameworks (HIPAA, CMMC, PCI, SOC 2)

The eight domains a real assessment covers

A complete IT assessment in Orange County should evaluate all eight of the following domains. If any are missing from the deliverable, the assessment is partial.

  1. Hardware and software inventory. Every physical asset (servers, workstations, network devices, printers, mobile devices) and every software title in use, with license status and end of life dates.
  2. Network infrastructure. Topology, segmentation, firewall configuration, wireless architecture, VPN, remote access. This is where the network segmentation gaps that produce most ransomware disasters get found.
  3. Storage and backup. Primary storage, secondary storage, backup architecture, retention policies, immutability, tested restore capability. The distinction between backup and disaster recovery matters here (most environments have backup, few have real DR).
  4. Security controls. Endpoint protection, EDR, MFA enforcement, access control, logging, monitoring, incident response. Real evaluation, not a checkbox on whether the tool is installed.
  5. Cloud infrastructure. Microsoft 365 configuration, Azure or AWS environment, cloud identity, third party SaaS integrations, cloud spend optimization. Cloud misconfigurations now yield the highest density of findings in any assessment domain.
  6. Support and maintenance operations. Ticket flow, response times, patch management cadence, change management, documentation quality. This is where the difference between reactive and proactive IT operations shows up.
  7. Capacity and growth planning. Business plan alignment, forecast of infrastructure requirements, budget implications over 24 months.
  8. Compliance and regulatory posture. Specific evaluation against the frameworks applicable to the business, whether that is CMMC for defense contractors, HIPAA for healthcare, PCI for payment card handling, SOC 2 for professional services, or California statutes (CCPA, CPRA, Civil Code Section 1798.82).
Red flag: If an “assessment” can be completed without anyone touching your actual environment, running discovery tools, examining logs, or interviewing more than one or two people at the business, it is not an assessment. Real diagnostic work requires access, time, and skilled engineering hours. The “free 30 minute IT health check” you were offered at a Chamber of Commerce event is a nice conversation, not an assessment.

Red flags to watch for during the sales conversation

You can often tell whether an assessment is real before it starts. Six specific signals to watch for during the initial sales conversation:

  • The proposal arrives without detailed discovery. Any provider giving you a proposal without asking detailed questions about your environment, compliance requirements, and specific pain points is pasting your user count into a pricing template. This is exactly what the assessment will look like.
  • The assessment scope is entirely vague. A real assessor tells you exactly what will be evaluated, how, by whom, and what artifacts you will receive. A sales driven assessor tells you it will be “thorough.”
  • The assessment is priced below $2,500 for a mid sized business. The economics of real engineering time do not support this. Someone else is subsidizing the work, and that someone else is you signing the follow on contract.
  • Every finding maps directly to a service the assessor sells. Ask upfront: “Will this assessment recommend solutions you do not provide?” A real assessment will. A sales pitch cannot.
  • The report is promised in five business days or less. A real assessment produces a report in two to four weeks because the underlying analysis takes that long. Faster than that means the report is a template with your logo dropped in.
  • The assessor cannot explain the difference between an assessment and a penetration test. These are different diagnostic tools with different purposes. Providers who conflate them are not serious about either.
Key takeaway: A real IT assessment in Orange County costs money, takes weeks, and produces a written deliverable you can hand to any third party (your next MSP, your CFO, your auditor, your board) and have it be immediately useful. If any of those three characteristics is missing, you are not evaluating an assessment. You are evaluating a sales presentation.

How to use a real assessment even if you never hire the assessor

Here is the honest litmus test for whether an assessment is legitimate. Ask the assessor upfront: “If I take this report to another IT provider and ask them to execute the roadmap, would you be comfortable with that?” A real assessor says yes without hesitation. A sales driven assessor becomes uncomfortable, because their business model depends on you not doing that.

The best assessments produce artifacts that outlive the relationship with the assessor. The executive summary becomes budget justification for the CFO. The inventory becomes the source of truth for asset management. The gap analysis becomes the roadmap for whoever the business hires to execute it. The compliance evaluation becomes evidence for auditors. The capacity plan becomes the input to the next fiscal year’s budget. None of these deliverables require the assessor to remain involved.

This is the ultimate test: an assessment that generates value only if you sign the follow on contract is not an assessment. It is a marketing document.

The honest version

The IT assessment industry, as it currently operates in Orange County, is largely broken. Most “assessments” are lead generation vehicles, professionally packaged to look like diagnostics. Businesses have been trained to expect them for free, which guarantees they cannot be serious. The paid tier has been undermined by the free tier’s marketing dominance. And the business owners making six and seven figure investment decisions based on these reports are, mostly, being sold to rather than served.

A real IT assessment costs $3,500 to $25,000 depending on scope, takes two to four weeks, requires access to your actual environment, produces the seven specific artifacts listed above, and delivers value that is independent of whether you hire the assessor for follow on work. Real IT services in Orange County start with real diagnostics, not with a preprinted report waiting to be filled in.

The good news is that a real assessment, once you have received one, changes the entire dynamic of every conversation about IT that follows. You know what you own. You know what is at risk. You know what needs to happen in the next 90 days and the next 24 months. You know what it should cost. You can shop the work, or execute it internally, or hire the assessor, and any of those paths is available to you. That freedom is worth the price of a real assessment, roughly one hundred times over. That freedom is exactly what the “free assessment” is designed to prevent.

Find out what a real IT assessment looks like, in writing.

Intelecis has been delivering real IT assessments to Orange County businesses since 2010. NSA-Accredited, with documented deliverables across healthcare, defense, legal, accounting, and manufacturing environments. Book a discovery call and we will walk you through exactly what our assessment includes (all seven artifacts, in writing) and what it would show for your specific business.

Book Your Discovery Call →

📞 949-266-2088 · Fullerton, CA · NSA-Accredited · Serving OC since 2010

Related reading:
Managed IT Services in Orange County ·
7 Questions Every CEO Should Ask Before Signing an IT Contract ·
The Penetration Test Results That Shocked 200 OC Business Owners ·
What White-Glove IT Actually Means ·
Book a Discovery Call