B BROCENT

Managed vs Co-Managed IT Services for Your China Office

A practical comparison of managed vs co-managed IT for a China office — when each model fits, how MLPS and PIPL compliance change the calculation, and a related procurement-before-entity challenge.

Two IT engineers collaborating over laptops at a modern office desk, representing a managed or co-managed IT partnership for a China office
The short answer: Managed IT hands your China office's entire IT operation — helpdesk, security, infrastructure and MLPS/PIPL compliance — to one accountable vendor. Co-managed keeps your own in-house hire or team in the driver's seat, with a partner filling specific gaps: after-hours coverage, specialist security skills, on-site dispatch, or compliance filings. The right model depends on your headcount, your in-house team's bandwidth, and how much regulatory work you can realistically own without outside help.

Every multinational running, or planning, a China office eventually asks the same question: should we hand IT over entirely to a managed service provider, or keep our own person in charge and bring in outside help only where we need it? There is no single right answer — a five-person representative office and a 200-person manufacturing site have very different IT realities — and China adds a layer most HQ IT teams have not dealt with elsewhere: MLPS (等保) classification and filing, PIPL's consent and cross-border transfer rules, and a fapiao-based invoicing system that changes how procurement and IT spend actually get booked. This guide breaks down what "managed" and "co-managed" actually mean in a China context, when each model fits, how compliance changes the calculation, and where a related but distinct challenge — procuring IT before your entity and bank account exist — fits into the picture.

This question tends to surface at a handful of predictable moments: a new China office is about to open and IT has not been figured out yet; an existing office's one-person IT department just resigned; a compliance review flagged that nobody can clearly explain who owns MLPS filing status; or a global IT leader is simply reviewing every regional support model at renewal time and wants to know whether the current setup is still the right one. Each of those moments points toward a different answer, which is exactly why "managed vs co-managed" deserves a real decision rather than a default.

Managed vs. Co-Managed IT for a China Office: What Is the Actual Difference?

The distinction is not really about tools or ticketing systems — most competent providers use similar platforms. It is about where accountability sits. Under a fully managed model, the provider owns end-to-end responsibility for the environment: they run the helpdesk, own the monitoring and alerting, patch and secure the infrastructure through managed IT and cloud services, dispatch engineers when hardware fails, and — critically for China — take responsibility for the technical and procedural side of MLPS and PIPL compliance as part of the contracted scope. Your HQ has one number to call and one SLA to hold them to.

Under a co-managed model, you retain an internal IT hire, or a small internal team, who owns strategic decisions, vendor relationships and day-to-day priorities, while a partner fills in the gaps that a single hire or small team cannot realistically cover alone — after-hours and weekend incident response, specialist cybersecurity monitoring, overflow on-site dispatch across multiple cities, or dedicated support for MLPS assessment paperwork. The internal hire stays the primary point of contact for the business; the partner is largely invisible to end users but does real, clearly scoped work behind the scenes.

Neither model is inherently better — they solve different problems. Fully managed removes the need to hire, retain and back up an internal IT function in a market where good bilingual IT talent is competitive and turnover-prone. Co-managed lets you keep institutional knowledge and business context in-house while outsourcing the parts that are either specialist (security operations, MLPS filing mechanics) or simply hard to staff for internally (24/7 coverage, multi-city dispatch).

The commercial structure differs too. A fully managed contract is typically priced as a single recurring fee covering an agreed scope, which makes budgeting predictable but means the whole relationship lives inside one vendor negotiation. A co-managed arrangement usually prices the partner's slice separately — a smaller retainer for defined services, sometimes supplemented with block or ad-hoc hours for overflow work — while your internal headcount cost sits on your own payroll, entirely outside the vendor contract. Neither structure is more "cost-effective" in the abstract; it depends on what you would otherwise be paying to build the same coverage entirely in-house.

When Does Fully Managed IT Fit a China Office?

Fully managed tends to make the most sense in a few recurring situations:

  • You are opening a new China office and have not hired IT yet. Standing up a fully managed relationship on day one, including IT infrastructure deployment services for the new site, avoids the multi-month gap between "we need IT" and "we found and onboarded the right local hire," and gives HQ a single accountable party from the outset.
  • Your China headcount is too small to justify a dedicated IT hire. A five-to-thirty-person office rarely has the budget or workload to keep one person fully occupied on IT alone, and a single hire is also a single point of failure — one resignation and you have zero IT coverage overnight.
  • HQ wants one accountable vendor for compliance, not a shared responsibility model. If your compliance or legal team wants a single contract that names who owns MLPS filing status and PIPL-aligned technical controls, fully managed is structurally cleaner than splitting that ownership across an internal hire and a vendor.
  • You need 24/7 or near-24/7 coverage from day one. Building genuine round-the-clock monitoring and response with one or two internal hires is close to impossible; a managed provider spreads that coverage across a team as standard.

Taken together, these situations share a common thread: they are all cases where the cost and risk of building internal redundancy outweighs the cost of paying a provider to already have it. A new office does not yet have the local relationships or track record to hire well; a small office cannot amortise a full IT function; and a compliance-sensitive HQ often prefers one throat to choke over a shared arrangement it has to referee.

When Does Co-Managed IT Fit a China Office?

Co-managed tends to fit when some of the pieces are already in place:

  • You already have one local IT hire, or a small team, who knows the business. Co-managed lets that person keep strategic ownership and stakeholder relationships while offloading the parts that do not scale with one person — after-hours incidents, specialist security monitoring, or on-site dispatch to a second or third city via full-time on-site IT support services.
  • Your global IT organisation wants a local delivery partner, not a full outsource. Larger multinationals often run standardised global tooling — identity, endpoint management, ticketing — and want a China-based partner to execute locally within that framework, rather than replace it with the provider's own stack.
  • You need MLPS or PIPL specialist support without giving up day-to-day control. MLPS classification and filing is a specific, periodic body of work most generalist IT hires have not done before; co-managed lets you keep daily operations in-house while a partner owns the compliance-filing mechanics.
  • Your office has outgrown one person but does not yet need a full internal team. Co-managed is a natural middle step between "one generalist IT hire" and "build a full in-house department," letting you scale support without immediately scaling headcount.

The common thread here is the opposite of the fully managed case: you already have something worth preserving — institutional knowledge, a trusted local hire, an existing global tooling investment — and the goal is to protect that asset while patching its specific, well-defined gaps, rather than replacing it wholesale.

How Do MLPS and PIPL Change the Calculation?

China's Multi-Level Protection Scheme, commonly known as MLPS or 等保, and the Personal Information Protection Law, or PIPL, are not optional extras layered on top of ordinary IT support — for most foreign-invested offices operating network systems in mainland China, they are a mandatory part of running compliant IT at all. MLPS requires classifying your information systems by risk level, registering that classification with local public security authorities, implementing the corresponding technical and management controls, and going through periodic assessment, typically annually for higher-graded systems, by a qualified third party. PIPL adds its own layer on top: consent requirements for processing personal information, technical and organisational controls proportionate to the sensitivity of the data, and specific rules, including in some cases a security assessment, for transferring personal information out of mainland China.

This changes the managed-vs-co-managed calculation in a very concrete way. A generalist IT hire, even a capable one, is unlikely to have handled an MLPS filing before, understand exactly which systems fall in scope, or know how to structure a PIPL-compliant cross-border data flow for HQ reporting. Under a fully managed model with a China-registered delivery entity, this becomes part of the contracted scope: the provider takes on classification guidance, coordinates the assessment process, and builds PIPL-aligned technical controls — encryption, access logging, data-flow mapping — into the environment through managed IT security services as standard, rather than as a bespoke, ad hoc project.

Under a co-managed model, the compliance split needs to be explicit rather than assumed. Decide, in writing, who owns MLPS classification and filing status, who is accountable if an assessment turns up a gap, and who owns the PIPL-side technical controls versus who executes day-to-day changes to systems that fall under those controls. The most common failure mode we see in co-managed setups is not bad intent on either side — it is an unstated assumption that "someone" owns MLPS, discovered only when a filing deadline or an assessment gap actually surfaces.

The timeline matters as much as the requirement itself. Classification and filing for a new system is not a same-week exercise — expect a process measured in weeks once scoping, documentation and the relevant public-security engagement are accounted for, and higher-graded systems then carry an ongoing annual assessment cadence rather than a one-time event. Budget for it as a recurring compliance-operations cost, not a one-off project fee, whichever support model you choose, since the assessment itself typically recurs regardless of who is executing it.

Whichever model you choose, MLPS and PIPL compliance for a China office is detailed enough to deserve its own dedicated checklist — treat this section as the calculation it changes for your support-model decision, not as the full compliance picture on its own.

Procuring IT Before Your China Entity Exists: A Related but Distinct Challenge

Many multinationals run into a China IT problem that sits chronologically before the managed-vs-co-managed decision even comes up: how do you procure laptops, network equipment and cloud accounts for a new China office when your local entity and bank account do not exist yet? Chinese suppliers generally require a local, licensed entity with proper fapiao capability to sell to, which creates a real gap between "we have signed a lease" and "our WFOE can legally purchase hardware."

This is a genuinely different problem from choosing your ongoing support model — it is solvable through a domestic partner acting as an interim procurement and deployment bridge, regardless of whether you eventually land on fully managed or co-managed support once your entity is live. We cover this specific challenge, including the domestic-purchase and device-as-a-service structures that keep your books clean once your entity exists, in our detailed guide to procuring IT hardware for a new China office before your entity and bank account exist — worth reading alongside this one if you are still in the pre-entity stage.

It is worth being explicit that solving the pre-entity procurement gap does not commit you to a particular managed-vs-co-managed answer down the line. Some offices that use an interim domestic-partner bridge to get hardware in place before entity registration go on to build a strong internal IT hire and land on co-managed; others find the bridge relationship works well enough operationally that they simply extend it into a fully managed contract once the entity and bank account are live. Treat the two decisions — how you procure before you have a legal entity, and how you support IT once you do — as sequential but separate questions.

Fully Managed (via Brocent's 博迅) vs. Co-Managed vs. In-House-Only

Fully Managed vs. Co-Managed vs. In-House-Only

  • Fully Managed (via Brocent's 博迅 mainland entity) — one contract, one SLA, one accountable vendor for helpdesk, on-site dispatch, security monitoring and MLPS/PIPL-aligned compliance support; no internal IT hire required, fastest to stand up for a new office, and the China-registered entity can transact directly with local suppliers and issue proper fapiao.
  • Co-Managed — your internal hire or team keeps strategic ownership and business context; a partner fills defined gaps — after-hours response, specialist security, multi-city dispatch, MLPS filing support — under a scoped agreement; requires clear, written ownership boundaries to avoid compliance and support gaps falling between the two parties.
  • In-House-Only — full direct control with no third-party contract to manage; workable for larger offices that can afford a genuinely resourced internal team, but a single hire or small team is a real single point of failure, rarely delivers 24/7 coverage as standard, and typically has to build MLPS/PIPL compliance expertise from scratch rather than drawing on a provider's existing playbook.

The mistake we see most often is treating this purely as a cost comparison between three price points. A cheaper in-house hire who cannot handle an MLPS assessment, or a co-managed split with no written compliance ownership, is not the same risk profile as a fully managed contract that already accounts for both — it is a different exposure wearing a similar-looking budget line.

Frequently Asked Questions

What does "co-managed IT" actually mean for a China office?

It means your internal IT hire, or small internal team, keeps ownership of strategy, vendor relationships and day-to-day priorities, while an external partner delivers specific, clearly scoped pieces — after-hours incident response, specialist security monitoring, on-site dispatch to additional cities, or compliance-filing support. It is a blend of accountability, not a full handover, and the split should be written into the agreement rather than left implicit, ideally down to a simple table of "who owns what" that both sides sign off on before day one.

Can we get IT support in China before our WFOE is registered?

Yes, generally through a domestic partner that can procure hardware and deliver interim managed services while your entity registration and bank account are still in progress, since Chinese suppliers typically need a licensed local entity to sell to directly. This pre-entity stage is a distinct problem from the managed-vs-co-managed decision — see the linked procurement guide above for how that bridge is usually structured, and note that solving it does not lock you into any particular support model once your entity is registered.

Who handles MLPS filing under each model?

Under fully managed, the provider's China-registered entity typically takes on classification guidance and coordinates the periodic assessment as part of the contracted scope. Under co-managed, this needs to be explicitly assigned — either to the partner as a defined line item or retained internally — because MLPS is specialised, periodic work that most generalist in-house hires have not done before, and leaving it unassigned is the single most common gap we see in co-managed contracts that were drafted without a compliance lens.

Does co-managed work if we already have one local IT hire?

Yes — that is usually the ideal scenario for co-managed, since your hire already has institutional knowledge and stakeholder relationships. The partner's role is to cover what one person structurally cannot: after-hours coverage, specialist security operations, dispatch to a second city, or MLPS filing mechanics, without displacing that person's day-to-day ownership or becoming a second, competing point of contact for the business.

How does fapiao invoicing work under managed vs. co-managed?

Under fully managed through a China-registered entity, the provider invoices your WFOE directly with proper fapiao for the full scope of services, which simplifies bookkeeping since it is a single vendor line. Under co-managed, you typically receive fapiao for the partner's defined scope of work — for example, after-hours support or MLPS filing assistance — while your internal team's costs run through your own payroll and any other vendor contracts separately, so your finance team ends up reconciling two or more lines instead of one.

Can we switch from co-managed to fully managed later, or the reverse?

Yes, and it is a common transition in both directions — offices often start fully managed while opening, then shift toward co-managed once they hire a strong local IT lead, or start co-managed and move to fully managed if the internal hire leaves and headcount does not justify replacing them immediately. Build a transition clause into your contract so the shift does not require renegotiating from scratch, and revisit the question at each contract renewal rather than only when something breaks.

Does a dual-entity structure — Hong Kong plus a mainland entity — affect data residency?

It can, depending on how your environment is architected — a mainland-registered delivery entity is generally what allows a provider to operate systems and hold MLPS filing responsibility inside mainland China, while a Hong Kong entity typically supports regional coordination and contracting. Confirm with your provider exactly which entity holds which systems and data, since that detail matters for both MLPS scope and PIPL cross-border transfer assessment, and ask for it in writing rather than assuming it mirrors your own corporate structure.

How do we decide between these three models if we are genuinely unsure?

Start by listing what you already have — a trusted local hire, existing global tooling, an established compliance process — rather than starting from price. If the honest answer is "we have none of that yet," fully managed removes the most risk fastest. If the honest answer is "we have a good person but real gaps," co-managed protects what you have while closing them. In-house-only is rarely the right starting answer for a China office unless you are already large enough to fund a genuinely resourced internal team, including its own compliance and after-hours coverage.

Choosing the Right Model for Your China Office

There is no universally correct answer between managed, co-managed and in-house-only — the right choice depends on your current headcount, whether you already have a trusted local IT hire, how much MLPS and PIPL compliance work you are prepared to own internally, and how quickly you need coverage in place. What matters is making the choice deliberately, with the compliance ownership and after-hours coverage questions answered in writing rather than assumed, instead of defaulting to whichever model your last office happened to use. Revisit the decision at each major inflection point — opening a second city, a compliance audit, a key hire leaving — rather than treating it as a one-time choice made at office launch and never reconsidered. If you would like to walk through your specific headcount, compliance exposure and existing team structure against these three models, get in touch and we can map the right fit for your China office.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →