Content & Answer Pages · 9 min read · July 15, 2026
What IT decision-makers really ask AI before they shortlist an MSP
Your buyers are asking a machine before they ask you. ChatGPT was at 900 million weekly users by February 2026, Google's AI Overviews at more than two billion monthly, and Copilot is already licensed inside the Microsoft tenants you sell into. The first cut on your next managed-services deal happens in a conversation you never see. This is what IT decision-makers actually ask about SLAs, security, price and migrations, what the evidence says about how those answers get sourced, and what to publish so your name is in them.
How the assistant became the first cut
When an IT manager starts looking for a new managed-service partner, the first move is rarely a search page and almost never a returned cold call. It is a prompt to ChatGPT or Perplexity or the assistant bundled into the tools they already pay for: "which managed-service providers support a Microsoft 365 estate with a 24/7 SLA in our region?" What comes back is a list of three to five names, and that list is the shortlist. Miss it and you are never asked to pitch, however good your references are.
The uncomfortable part is that this cut leaves no trace on your side. No form, no session, no line in your analytics. Pew Research watched the real browsing of 900 US adults across 68,879 Google searches and found people clicked through to a website in 8% of visits when an AI summary appeared, against 15% when it did not, and clicked a link inside the summary itself in 1% of visits. SparkToro puts 68% of US Google searches in early 2026 ending with no click at all. You are being compared and dropped in a room you cannot watch.
Generative Engine Optimization (GEO) is the work of getting into that room. It is not a rerun of ranking: an Ahrefs comparison found only 6 to 8% of the URLs ChatGPT cites also sit in Google's top ten for the same query, and roughly 80% do not rank in the top hundred at all. What decides the outcome is whether a language model can find a specific, checkable claim to attach your name to. Managed-services buyers ask by criteria: certification scope, response and resolution targets, sector and stack. Answer those in plain text and you are quotable. Leave them soft and you are a logo the model has nothing to say about.
SLA and response-time questions: the numbers you have to publish
Nothing gets asked more often than service levels. Real prompts look like "what response time is realistic for a P1 incident", "which SLA tiers do mid-market MSPs offer", "what does 24/7 support cost against 8/5". The engine answers from what it can find written down, and "fast response times" gives it nothing to work with. "P1: 15-minute response, four-hour resolution target, service credits beyond that" gives it a sentence it can lift with your name attached.
Buyers also ask the assistant to explain the thing before they shop for it: the difference between response time and resolution time, how to spot an SLA that exists only on paper. Answer those yourself, in public, and you become the source for the explanation and a candidate on the list at the same time. The one peer-reviewed study here (Aggarwal et al., SIGKDD 2024) found that adding statistics and cited sources moved its visibility scores by roughly a quarter, though it measured a simulated engine and the authors' own metrics rather than live traffic, so take the direction and not the number.
Consistency does real work. If your service page, your PDF datasheet and your last conference talk give three different numbers, you have handed the model three candidates and no reason to pick one. And these systems state wrong things with total confidence: Columbia's Tow Center ran 1,600 source-attribution queries across eight AI search tools and got incorrect answers more than 60% of the time, with over half of Gemini's and Grok-3's citations pointing at fabricated or broken URLs. Settle your SLA tiers once, then repeat them identically everywhere. The repetition is not padding, it is what removes the ambiguity.
Security, compliance and the certifications an engine can read
Security is usually the first knock-out. The prompts are specific: which providers hold ISO 27001 and can evidence GDPR-compliant processing, who runs a SOC out of a data center in Germany, which providers can carry NIS2 obligations for an in-scope operator. An engine can only answer that if your certifications exist as words, with scope, issuing body and date, rather than as a row of seal graphics in the footer.
Models read what is written and nothing else. A JPEG of a certification seal is invisible; a sentence like "ISO 27001 certified since 2021, audited by TUV Sued, scope: operation of managed cloud services" is not. Add where data is processed, which region the data centers sit in, and how you handle subprocessors. These are the lines that decide tenders anyway. The only change is that buyers now pull them up before the RFP instead of during it.
NIS2 and DORA are generating the sharpest questions right now, largely because most of the market still answers them vaguely. Publish the specifics: which obligations attach at which size and sector, what an operator has to evidence, where a managed partner takes the load. Nobody outside the platforms can tell you how retrieval weights that content, and OpenAI, Perplexity and Anthropic publish no scoring formula, so treat confident claims about weighted signals as inference. What you control is being the clearest correct answer on a page an engine can retrieve.
Price questions, and what to say without a rate card
Price transparency is the industry's sore spot, which is exactly why buyers take the question to an assistant instead of to you. "What does managed IT cost per seat per month", "which billing models do MSPs use", "what hidden costs come with managed services". Most providers publish no figure at all, so the answer gets assembled from market averages and other people's posts, and your name never enters it. You contributed nothing on the one topic every buyer raises.
You do not need a rate card to be in that answer. Publish the shape of it: per device, per user, or an all-in monthly fee; a range and what moves you within it; what the base fee covers and what stays project work. That answers the question the buyer actually asked, in a form that can be quoted. It also reads as more credible than a brochure promising something tailored to your needs.
The price content that earns citations usually corrects a mistake. Why the cheapest hourly rate becomes the most expensive contract. How onboarding is priced and why it is not free. What a co-managed model saves against a full outsource. Those are the follow-up questions inside the same conversation, and Profound's read of roughly 730,000 ChatGPT conversations found citation frequency falling from about 12.6% of opening turns to 3% by turn twenty. Being the source that answers the first question well is worth more than arriving on the twentieth.
Migration and exit questions, where the real fear sits
A large block of questions is about the transition itself: how an on-premises to Azure move works with a managed partner, how to change MSPs without downtime, how long onboarding takes with a new provider. Underneath all three sits the same fear, which is losing control of a running estate. Write the process out with phases, elapsed time and named owners, and you have given the engine the material for a reassuring, specific answer with your name on it.
Buyers want the risk quantified. A published migration roadmap, with discovery, a pilot group, staged cutover with a rollback point and documented handover, separates you from a page that promises a smooth migration. So does one project written up in detail: for example, "we moved a 120-seat estate in eight weeks with no production downtime, and here is what went wrong in week three." Described work is something a model can match to "low-risk changeover". An adjective is not.
Exit questions come up too: how do I get out of this contract later, who owns the runbooks, how do I get my data back. Answering openly costs you nothing and reads as confidence, so publish your offboarding steps, notice periods and data-return format. This is the question buyers are slightly embarrassed to put to a salesperson, which is exactly why they put it to a machine. Be the provider whose answer is already written down.
Industry and stack specifics beat generic references
Almost nobody asks the generic version. They ask which provider knows tax firms and DATEV, who runs IT for manufacturers with OT on the same site, which MSP has handled clinical software for an in-scope operator. That specificity is the matching surface. If your site says "customers across the mid-market", there is nothing to match against. Name the sectors, the systems and the situations, and you become the answer to a narrow question, which is the only kind anyone asks.
References work differently here. A model can use a described project, with sector, starting state, what you did and what changed, and can do nothing with a wall of anonymous logos. Write up the document-management rollout you delivered for a law firm, availability target included, and you are matchable for every similar query. Third-party coverage matters more than most on-page work: across roughly 75,000 brands, Ahrefs found web-mention frequency correlated with AI citation rate at about 0.66, against 0.22 for backlinks. Getting written about is the strongest lever anyone has evidence for.
Vocabulary precision is the rest of it. DATEV, Microsoft 365 GCC High, SAP Basis, Veeam, OT segmentation: these are the words buyers type, so they have to appear on your pages, in the places they honestly belong. Do not scatter them. The same academic study found keyword stuffing produced no meaningful gain, and Google explicitly warns against writing content for engines rather than readers, which it treats as scaled-content abuse. Fit is the lever. Volume of terms is not.
How to make your facts extractable without writing for machines
A good answer that cannot be extracted is not an answer. What works is dull: real headings, question-and-answer blocks, short paragraphs, one claim per sentence. An FAQ that uses your buyers' own wording on SLA, price and security is worth building, because that shape lifts cleanly into a generated answer. Add structured data such as Organization and FAQ schema to make the same facts machine-readable, but be clear about what that buys you. Schema improves extraction and cuts down invented details like price or opening hours; Google has said since 2018 that it is not a direct ranking factor, and no engine has confirmed it as a citation signal.
Your load-bearing facts have to exist as text on an indexable page. Response times, certification scope, locations and service tiers belong in HTML, not locked inside a PDF, an image or a JavaScript widget a crawler has to guess at. Google's own guidance is blunt about the rest: no special markup, schema or AI-specific file is required for AI Overviews or AI Mode, and a page qualifies as a supporting link by being indexed and eligible to show with a snippet. Write each key sentence so it survives on its own, because that is how it gets quoted.
Maintenance matters, though not in the way "post more" implies. Ahrefs' pass over 1.4 million ChatGPT prompts found cited pages had a median age around 500 days, so engines lean on material that has sat there being correct. What hurts is staleness that is wrong: an expired certification scope or a two-year-old price produces a confidently wrong answer about you, and the buyer catches the contradiction the moment they land on your site. Revisit the pages carrying numbers, and skip the AI-specific side files: John Mueller confirmed in 2025 that no Google Search system reads llms.txt, and an Ahrefs look at about 137,000 sites publishing one found roughly 97% got no measurable referral traffic from it.
How to measure it, and how long it actually takes
GEO is a loop, not a launch. Start with an honest count: put your buyers' real questions to the assistants yourself and write down whether you appear, in what position, and which claim gets attached to your name. The first pass is usually bleak and always useful, because it shows you which questions you have published nothing about and where a model is repeating something about you that is out of date. Keep the log, since the answers move as you publish and as the systems re-crawl.
The gaps are your roadmap. No clear SLA page? That is the next article. Not named for a sector you genuinely serve? That is the next write-up. Keep that going for a year and you have a knowledge base built around the questions being asked rather than the ones you enjoy answering. Expect months, not weeks: Profound's sample of roughly 730,000 ChatGPT conversations found only about 18% trigger a web search at all, so much of what an assistant says about your market still comes from training data you cannot edit this quarter. Continuity is the advantage a one-off campaign cannot buy.
The short version: your buyers moved their research, and the first cut now happens in a conversation you are not part of. That is an opening rather than a threat, because most of your competitors still publish adjectives. Write down your numbers, your certification scope, your sectors and your process, keep them consistent and current, and you become the answer. Citation pays on its own terms too: Ahrefs measured about 35% more organic clicks for pages cited in an AI Overview than for pages ranking without being cited. Start with the question you get asked most.
Common questions
How do I check whether ChatGPT or Perplexity recommends my managed-services firm?
Run your buyers' real questions yourself. Ask something like "which managed-service providers support Microsoft 365 with a 24/7 SLA in our region", then log whether your name appears, where in the list it lands, and what claim comes with it. Vary the wording, the sector and the engine, because ChatGPT, Gemini, Copilot and Perplexity do not agree with each other. Twenty prompts in a spreadsheet, rerun monthly, will tell you which questions you have published nothing about.
Do I have to publish prices to appear in AI answers?
No rate card required. Publish the model and the range: per device, per user or an all-in monthly fee, a typical band, and what sits inside the base fee against what stays project work. That answers the question buyers are actually asking and gives an engine something quotable. Say nothing about price and the answer still gets written, out of market averages someone else published, without you in it.
Why do my ISO 27001 and GDPR details never show up in AI answers?
Usually because of how they are presented. A seal graphic in the footer is unreadable to a language model. Write the facts out as text, with scope, issuing body and date, for example "ISO 27001 certified since 2021, audited by TUV Sued, scope: operation of managed cloud services", and put them on an indexable page rather than in a PDF. Organization structured data helps a machine parse the same facts, but treat it as extraction help rather than a ranking lever.
Read on