According to Gartner, global spending on IT services will exceed $1,870 billion in 2026. In Italy, IT outsourcing is growing at an annual rate of 7%, on track to reach 13.9 billion in 2029.
- Managed services: outsourced management of servers, networks, workstations, and applications with guaranteed service levels.
- Global IT spending in 2026: $6.310 trillion, with IT services as the leading sector (Gartner).
- IT outsourcing in Italy: approximately $9.9 billion in 2024, a 7% annual increase (Statista).
- Service levels, penalties, and a liability matrix govern the outsourcing contract.
- The supplier needs certifications of quality, safety, and compliance with recent European standards.
Managed services and IT outsourcing have become strategic levers for large organizations. A shortage of specialized skills, budget pressures, and new European regulations are driving the outsourcing of increasingly critical activities. Furthermore, the adoption of artificial intelligence and cloud computing is expanding the scope of services entrusted to external providers. As a result, selecting a partner requires objective criteria: measurable service levels, clear accountability matrices, and verifiable certifications.
Managed Services and IT Outsourcing: What Do They Mean?
“Managed services” refers to the practice of entrusting an external provider with the installation, maintenance, and updating of systems, networks, and applications, governed by measurable service levels.
Managed services: a subset of IT services in which an organization outsources the operational management of infrastructure and applications under a contract with defined service levels and responsibilities.
The scope of outsourcing has expanded in recent years. In fact, in addition to traditional server management, organizations today outsource hybrid cloud environments, distributed workstations, and complete application platforms. The rationale is the same: to transfer repetitive yet critical operational tasks to external specialists, with guaranteed response times. This allows the in-house IT department to focus on higher-value projects, such as digital transformation and the adoption of artificial intelligence. The technological areas typically entrusted to a managed service provider are as follows.
- Servers and virtual machines: physical systems in the data center and virtual instances in the cloud.
- Workstations and mobile devices: corporate endpoints, including installation, updates, and support.
- Local and geographic networks: network equipment, connectivity between locations, and remote access.
- Complex systems: architectures consisting of interconnected software applications and databases.
- Cloud applications: systems delivered as SaaS (Software as a Service).
Which IT activities can be outsourced?
Organizations can outsource the entire operational lifecycle of their IT infrastructure: monitoring, incident management, patching, and user support. The reasons for this choice range from the need to optimize costs to the need to acquire certified expertise that is difficult to develop in-house. Furthermore, companies are increasingly delegating key aspects of cybersecurity.
What will be the value of the managed services market in 2026?
According to Gartner, global IT spending will reach $6,310 billion in 2026, up 13.5%. IT services will exceed $1,870 billion and will be the largest segment.
The global IT services market is experiencing strong growth. Demand for computing power for artificial intelligence, the shift to the cloud, and regulatory pressure regarding security are driving record investments. In particular, organizations are asking external providers to manage increasingly complex and distributed infrastructures. Outsourcing is thus becoming an operational necessity to keep pace with innovation, not merely a cost-saving measure.
According to Gartner (April 2026), global IT spending will grow by 13.5% in 2026 and reach $6,310 billion. IT services, which include implementation and managed services, will exceed $1,870 billion: this is the largest segment in absolute terms (Gartner 2026 forecast).
What are the drivers of growth in IT spending?
Artificial intelligence, cloud computing, and cybersecurity are the three main drivers of enterprise IT spending in 2026. Managed service providers are meeting this demand with specialized expertise and flexible delivery models.
- Generative artificial intelligence: According to Gartner, spending on models in Europe will grow by 78.2% in 2026.
- Public cloud: 24% growth expected in Europe, with a growing focus on digital data sovereignty.
- Data centers: Investment in infrastructure optimized for artificial intelligence is accelerating across all geographic regions.
- Cybersecurity: European regulatory requirements are driving up demand for managed protection and monitoring services.
The Italian and European IT Outsourcing Market
The IT outsourcing market in Italy is valued at approximately $9.9 billion in 2024 and is growing at an average annual rate of 7%. In Europe, the IT services market will reach nearly $540 billion in 2026.
The European landscape confirms the strength of demand for outsourcing. Organizations across the continent are tackling digital transformation, compliance requirements, and a shortage of skilled personnel with growing budgets. However, growth is not uniform: more mature markets show much higher absolute figures. Italy, however, is showing positive and steady growth, driven by both large companies and the public sector.
According to Gartner (November 2025), European spending on IT services will grow by 10.1% in 2026. The figure will rise from $490.4 billion to $539.9 billion (Gartner forecast for Europe).
For Italy, Statista Market Insights estimates IT outsourcing revenues of approximately $9.9 billion in 2024. Growth is expected to average 7% annually, reaching approximately $13.9 billion by 2029 (Statista, IT Outsourcing Italy). In addition, average spending per employee is rising—a sign of more mature demand that is not solely driven by an increase in the number of client companies.
How does Italy compare to Germany and France?
The Italian IT outsourcing market has a profile similar to that of Spain, while Germany and France show significantly higher figures. The difference stems from the greater presence of large organizations, which are more likely to outsource a significant portion of their IT spending. The supply side, however, remains fragmented: alongside large international system integrators, there is a vast array of smaller, specialized providers. For client companies, this market structure makes it even more important to evaluate certifications, financial stability, and service levels.
Why do organizations choose to outsource their IT?
The main reasons are cost optimization, access to specialized and certified expertise, and the ability to focus internal resources on activities with greater strategic value.
The decision to outsource almost always stems from a combination of economic and organizational factors. First and foremost, the subscription model transforms investments and variable costs into a predictable and comparable expense. Furthermore, the IT labor market makes it difficult to hire and retain specialists in all the technologies in use. A qualified provider, on the other hand, spreads its expertise across many clients and keeps the certifications required by the market up to date.
- Cost optimization: reduction of TCO (Total Cost of Ownership) and conversion of fixed costs into predictable fees.
- Specialized skills: access to technical professionals who are difficult to find and retain in-house.
- Certifications: quality and safety requirements that are difficult to meet using only internal resources.
- Cybersecurity: Delegating aspects of corporate security to dedicated specialists.
- Scalability: Rapid adaptation of services to new locations, acquisitions, or project peaks.
How to Manage a Contract: SLAs and the RACI Matrix
The SLA (Service Level Agreement) defines response times, resolution times, and penalties. The RACI matrix assigns execution and accountability roles for each outsourced activity.
The quality of an IT outsourcing service is measured against explicit contractual parameters. Consequently, response times, liabilities, and penalties must be defined before the contract is signed, not during emergencies. The stated response times thus become an objective benchmark for evaluating the provider over time. Let’s look at the two fundamental tools for contract management.
What should an IT outsourcing SLA include?
An IT outsourcing SLA must specify, at a minimum, the response time for each activity window: business hours, nighttime, and holidays. The wording depends heavily on the type of operation to be performed. Often, but not always, the agreement also specifies the timeframes for resolving or completing the task. For problems without an immediate solution, the agreement specifies mitigation measures—that is, steps to reduce the operational impact.
- Case Acceptance: Maximum response time for the provider for each service window.
- Solution or Mitigation: Stated timeframes for resolving the problem or, where that is not possible, for limiting its effects.
- Service hours: coverage during business hours, extended hours, or 24/7 service.
- Penalties: Direct monetary compensation or a credit against future payments if the agreed-upon targets are not met.
What is the RACI matrix used for?
The RACI matrix clearly assigns the roles of execution, accountability, consultation, and information for each activity in an outsourced process. The name is derived from the initials of the four roles in English. Assigning a matrix to each activity prevents overlaps and gaps in responsibility between the company and the supplier.
La matrice RACI
| Ruolo | Denominazione | Funzione nel processo |
|---|---|---|
| R | Responsible | Svolge operativamente il lavoro |
| A | Accountable | Delega, supervisiona e approva il lavoro svolto |
| C | Consulted | Collabora con il Responsible e fornisce pareri tecnici |
| I | Informed | Viene informato all’avvio o al completamento dell’attività |
An SLA with clear penalties and a RACI matrix for each activity make service performance measurable and reduce incident resolution times.
What certifications should you ask a managed services provider for?
The core certifications are ISO 9001 for quality management systems and ISO 27001 for information security, in addition to full compliance with European data protection regulations.
Certifications provide verifiable proof of the quality of a supplier’s processes. In addition to the most widely used ones, there are industry-specific schemes, particularly for financial services and critical infrastructure. Furthermore, in recent years, European lawmakers have raised security requirements for the entire ICT supply chain. Two standards deserve special attention when selecting an outsourcing partner.
NIS2 (Network and Information Security 2): a European directive on cybersecurity that imposes obligations regarding risk management and incident reporting, which also extend to suppliers in the ICT chain.
DORA (Digital Operational Resilience Act): a European regulation on digital operational resilience in the financial sector, which sets out detailed rules governing contracts with third-party ICT providers.
Finally, the agreement must include the appropriate privacy-related representations and allocations of liability. This ensures that the outsourcing remains compliant with the GDPR (General Data Protection Regulation) and with the guidelines issued by the supervisory authorities.
Retelit's Perspective on Managed Services
Retelit integrates a granular portfolio of managed services—including SLAs, penalties, and continuous activity reporting—into its network, voice, cloud, and data center offerings.
Retelit operates as a provider of ICT infrastructure services for the telecommunications market and of ICT solutions for businesses and the public sector. The managed services—developed in-house or in collaboration with specialized and qualified partners—are characterized primarily by their granularity. As a result, each organization can tailor the solution that best suits its needs without paying for unnecessary components. The portfolio currently includes six service groups.
- Spoc (Single Point of Contact): First-level support via phone, email, and a dedicated portal.
- Monitor: Proactive and reactive monitoring of workstations, mobile devices, and infrastructure.
- Service: Management of IT incidents and change requests for servers, networks, workstations, and the cloud.
- Patches: Installation of system or application patches and software deployment on workstations.
- Third Parties: A single point of contact with external IT vendors for managing hardware and software support.
- MWM: Management of Microsoft 365 and Active Directory environments.
Retelit holds the necessary certifications and qualifications to provide these services. The list covers security and compliance (ISO 27001, GDPR) and IT service management (ITIL, COBIT). It also includes cybersecurity (CompTIA Security+, CISSP, CEH) and cloud (Microsoft Azure Expert MSP, AWS Managed Service Provider, Cisco CCNP, and CCIE). Contracts always include SLAs and penalty clauses. They also include a monitoring and reporting service that documents the results achieved and areas for improvement over time.
To evaluate a customized outsourcing solution, the page dedicated to managed IT and telecommunications services for businesses presents the complete portfolio and sales contacts.
Frequently Asked Questions About IT Outsourcing
IT outsourcing refers to the outsourcing of entire IT functions, often involving the transfer of assets and personnel. Managed services, on the other hand, are modular and granular services governed by SLAs specific to each activity. In practice, the two terms overlap and refer to the management of systems entrusted to qualified external providers.
IT outsourcing refers to the outsourcing of entire IT functions, often involving the transfer of assets and personnel. Managed services, on the other hand, are modular and granular services governed by SLAs specific to each activity. In practice, the two terms overlap and refer to the management of systems entrusted to qualified external providers.
An SLA with penalties must specify response and resolution times for each service window. It must also specify the financial compensation or credit to be granted to the customer when the parameters are not met.
The core certifications are ISO 9001 for quality and ISO 27001 for information security. In regulated industries, compliance with NIS2 and DORA, as well as certifications from major technology vendors, are also required. The contract must include provisions regarding GDPR responsibilities.
NIS2 and DORA extend security responsibilities to the entire ICT supply chain. As a result, contracts must include incident notification obligations, operational resilience requirements, and audit rights with respect to the supplier.
Paolo Annoni, Digital Marketing, Retelit