
Most MSPs learn a company changed IT providers after the fact. The record often exists earlier, in public: a filing to move offices, a permit for a renovation, a dissolution notice for a small IT company, each one a decision on a date the firm did not choose.
This page covers nine signals from our pillar guide, 18 buying signals that show a company is about to change IT providers, grouped by what each one shows: where a firm is going, how it is being restructured, and what deadline is forcing its hand.
Public records predict an IT-provider decision because they record events that force one. An office move or build-out means new cabling, network, firewall, printers, door access, and a rewrite of the firm's written security plan. A breakaway, a merger, or an out-of-state firm opening a local office means email, devices, and document systems must be set up or combined by a fixed date. A firm growing past the size where a stricter regulator takes over inherits that regulator's cybersecurity exams. Paid tax preparers confirm every renewal season that a written information security plan is required by law. A defense contract award names a company that must hold its cybersecurity status on record. When a small IT company dissolves or is bought, its clients may soon need a new provider. Each event is filed in public before the IT work begins, which gives an outbound system a dated reason to reach the owner while the decision is still open.
1. Places: moves, build-outs, and arrivals
Office move. An office move is a business-address amendment filed with the state Secretary of State, and it predicts an IT decision because the new office needs cabling and a rewritten security plan. For a registered investment adviser, the same move also requires a Form ADV amendment filed on the SEC's Investment Adviser Public Disclosure site (IAPD). By hand, nobody re-reads the register. The firm now needs new cabling, a network build, and a rewritten written security plan before the move date.
Office build-out. An office build-out is an interior renovation permit on the city or county building permit portal, naming the tenant and the scope, and it predicts an IT decision because the space needs cabling and a network before move-in. Few IT sales teams read permits, because by hand it means checking every city in a territory. The tenant now needs cabling, a network, and a firewall installed before move-in.
Firm arriving in a new state. A firm arriving in a new state is a foreign qualification filed with the destination state's Secretary of State, and it predicts an IT decision because a real office needs local setup. By hand, nothing marks the ones with a real office. The firm now needs local network setup, phones, and devices before opening the office.
2. Structure: breakaways, mergers, regulatory lines, and providers closing
Breakaway firm. A breakaway firm is a new-entity formation filing with the Secretary of State, filed by professionals who left an established firm, and it predicts an IT decision because the founders must stand up email and document systems from nothing. For an advisory firm, the same breakaway also produces a new Form ADV on IAPD or a new firm record on FINRA BrokerCheck. By hand, it looks like any other new business. The founders now need email, devices, a document system, and security controls set up from scratch.
Merger. A merger is articles of merger filed with the Secretary of State, and for advisers an amended Form ADV, and it predicts an IT decision because the firms must merge two email systems and two document systems before closing. A press release may accompany it, but the filing is the record. By hand, nobody connects the filing to an IT decision. The combining firms now need their two email systems and two document systems merged before the closing date.
Crossing a regulatory line. Crossing a regulatory line is a firm's public filing showing growth past a size threshold into stricter oversight, and it predicts an IT decision because the new regulator examines governance and vendor oversight the old provider never documented. The filing is Form ADV Part 1, Item 5.F, which reports regulatory assets under management on the SEC's Investment Adviser Public Disclosure site (IAPD). The SEC's examination priorities for fiscal year 2026 name governance, data loss prevention (controls that stop files leaving the firm), access controls, oversight of third-party vendors, and controls against new risks from artificial intelligence. The amended Regulation S-P (the SEC's privacy and safeguards rule) requires a written incident response program and customer notice after a breach. By hand, spotting this means reading each adviser's filing and knowing where the line sits. The adviser now needs written policies, access controls, vendor oversight records, and an incident response program on file before the first exam.
IT providers closing or bought. An IT provider closing is a Secretary of State dissolution filing, or an asset purchase or business sale record where the state publishes one, and it predicts an IT decision because the closing company's clients must find a new provider. By hand, the filing names the IT company, never its clients. Those clients now need continuity of their systems and contracts through the transition.
3. Deadlines: tax-season security plans and defense work
Tax-season security plan. A tax-season security plan is the written information security plan (WISP) every paid preparer confirms on a public renewal form, and it predicts a decision because the FTC Safeguards Rule (16 CFR Part 314) requires one. Preparers confirm this every year on the renewal form, Form W-12. By hand, there is nothing to spot: every preparer renews in the same season, so the only way to learn who lacks a plan is to ask. The practice now needs a current written security plan kept up to date, not just filed once.
Defense work. Defense work is a public contract award naming a company bound by federal cybersecurity clauses, and it predicts an IT decision because the award requires security controls the awarded company's current provider may not support. The award is published as a contract on SAM.gov or USAspending.gov. Contracts carrying the Department of Defense cybersecurity clause (DFARS 252.204-7012) require the contractor to protect covered defense information under NIST SP 800-171 (a federal security standard) and to pass the clause down to subcontractors. The CMMC clause (Cybersecurity Maturity Model Certification), DFARS 252.204-7021, requires a current CMMC status at the contract's level for the life of the contract. By hand, awards sit in a record few people outside government contracting read. The contractor now needs security controls at the contract's CMMC level, documented and kept current for the life of the contract.
4. What an MSP sells into these signals
An office move sells as a relocation project: network and phones ready before move-in. The office manager or owner decides, fearing downtime.
An office build-out sells as a standalone cabling and network install tied to the renovation schedule, then a managed service. Ownership decides, fearing rework before the design is final.
A new-state arrival sells as a local network and device setup, often with an ongoing support contract. The branch or regional manager decides, fearing no local hands.
A breakaway firm sells as a from-scratch buildout: email, devices, document management, and security. The founding partners decide, fearing lost client files.
A merger sells as a systems-integration project: merging two email and document systems on a fixed timeline. The lead operating partner decides, fearing data loss during the combination.
Crossing a regulatory line sells as a compliance readiness project matched to the new regulator's exam scope. The compliance officer or managing partner decides, fearing an exam finding with nothing on file.
A tax-season security plan sells as a written plan built and kept current, not a one-time document. The practice owner decides, fearing an audit with nothing on file to show.
Defense work sells as a compliance buildout to the contract's required security level. The contractor's owner or facility security officer decides, fearing the loss of the contract over an unmet requirement.
A provider closing or being bought sells as a transition project, taking over its systems and contracts without disrupting daily operations. The client's owner or office manager decides, fearing a service gap during the handoff.
| Signal | What changes at the firm | What it needs | Service model | Who decides |
|---|---|---|---|---|
| Office move | Address change filed with the regulator | Cabling, network, firewall, security plan | Relocation project | Office manager or owner |
| Office build-out | Renovation permit filed for the space | Cabling, network, firewall before move-in | Standalone install, then managed service | Ownership |
| Firm arriving in a new state | Out-of-state company registers locally | Local network, phones, devices | Local setup plus support contract | Branch or regional manager |
| Breakaway firm | New firm registered by departing professionals | Email, devices, document system, security | From-scratch buildout | Founding partners |
| Merger | Articles of merger filed with the state | Two email and document systems merged | Systems-integration project | Lead operating partner |
| Crossing a regulatory line | Filing shows growth into federal oversight | Written policies, access controls, vendor oversight | Compliance readiness project | Compliance officer or managing partner |
| Tax-season security plan | Preparer confirms WISP requirement on renewal | Current written security plan | Ongoing plan maintenance | Practice owner |
| Defense work | New award naming the contractor | Security controls at the required level | Compliance buildout | Owner or facility security officer |
| IT providers closing or bought | Dissolution or sale record naming a small IT firm | Continuity of systems and contracts | Transition project | Client's owner or office manager |
5. Two caveats before building a list on this
Nobody buys the day the event happens. The move is filed months before the boxes arrive. The decision follows weeks later, and the filing stays the reason for reaching out.
The sharpest signals are low volume. Those go to the top of a list, but they are not the list. The list is built to the MSP's ideal-client definition: size, industry, geography, and buying role. That is how SiteSmith builds target lists around signals like these.
Questions owners ask
Why do public records predict an IT decision before the company calls anyone?
Filings and permits exist because the law requires them, not because the firm is shopping for a provider. But the events they record, like a move or a merger, still force a decision about who runs the network and the email.
Does a public filing mean the company is unhappy with its current IT provider?
No. Many of these firms are happy with their provider and will stay with them. The filing only shows an event that requires new IT work, not client dissatisfaction with the provider already in place.
Why do MSPs miss these signals if the records are public?
The records sit in dozens of separate places, city permit offices, state business registries, and federal contract databases. Reading all of them by hand for one territory takes more time than most sales teams have.
Which signal is the strongest one to act on?
None of them is strongest on its own. A breakaway or a merger is rarer and more urgent, but every signal only matters if the company also fits the client the MSP wants: the right size, industry, and location.
Do these signals work outside the nine covered on this page?
Yes. This page covers filings and public records specifically. Other signal groups cover system and vendor changes, hiring moves, and what owners say in public, each working on the same idea: a dated public fact that shows a decision is coming.
Where to go from here
Filings are one of four groups in 18 buying signals that show a company is about to change IT providers. Next, read Systems-change signals: AI rollouts, vendor switches, and projects before launch. To put any signal to work, our guide to how to build an MSP outbound system covers the rest.
Sources and editorial note
SiteSmith publishes practical operating guidance and cites external sources for factual industry and security claims. This article is not legal, regulatory, or cybersecurity advice.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements
- IRS, Instructions for Form W-12 (PTIN renewal), WISP acknowledgment
- SEC, amendments to Regulation S-P (May 2024)
- SEC Division of Examinations, Fiscal Year 2026 Examination Priorities