Disclosure: This post contains affiliate links. If you click and purchase, I may earn a commission at no extra cost to you.
Last Updated: August 17, 2026
Most small businesses overpay for VoIP by somewhere between 20% and 40% — not because they negotiated badly, but because they never audited what they actually use. A 2023 Metrigy research report found that SMBs use an average of only 30–40% of their purchased VoIP feature sets. The rest sits idle while the monthly invoice keeps climbing. If you’re evaluating a managed VoIP provider right now, the single most important thing you can do before talking to any sales rep is understand your own usage baseline. This guide walks you through exactly that process — from auditing your current phone bill to assessing network security risks that most VoIP buyers completely overlook. For more details, see our guide on comprehensive guide to evaluating managed VoIP providers. For more details, see our guide on avoid getting locked into unfavorable VoIP contracts. For more details, see our guide on how to compare provider pricing and support quality. For more details, see our guide on ranked provider comparisons for Central Florida SMBs.
Marcus Webb is a cybersecurity analyst with over 10 years of experience in endpoint protection, email security, and identity management for SMBs. The security sections of this guide reflect real-world VoIP threat patterns he’s observed across dozens of small business deployments.
[IMAGE: alt=”Managed VoIP vs Hosted VoIP vs UCaaS comparison infographic showing three-column feature and pricing differences” | filename=”managed-voip-vs-hosted-voip-vs-ucaas-comparison.jpg”]
What Do Small Businesses Actually Need From a VoIP Provider?
TL;DR: Most SMBs need reliable call quality, a basic auto-attendant, and mobile softphone access — not enterprise contact center modules. The label on the product (hosted VoIP, managed VoIP, or UCaaS) directly affects what you pay, so getting the terminology right before you shop matters. For more details, see our guide on virtual front desk solutions that integrate with VoIP systems.
Managed VoIP is a hosted phone service where the provider actively monitors, maintains, and supports your phone system — including hardware, software updates, and call quality troubleshooting. Hosted VoIP is a broader term: your phone system runs in the cloud rather than on-premise hardware, but the level of ongoing management varies widely by provider. UCaaS (Unified Communications as a Service) bundles voice, video conferencing, team messaging, and sometimes contact center tools into a single platform — and prices accordingly. For more details, see our guide on what SMBs actually save by switching to managed VoIP. For more details, see our guide on managed vs in-house models for business technology services.
The practical difference? A managed VoIP plan might run $25–$40 per user per month with proactive support included. A UCaaS platform from a major carrier can run $50–$85 per user per month, with features your team will never open. For a 15-person business, that gap is $375–$675 per month — or up to $8,100 per year in unnecessary spend. For more details, see our guide on similar cost-optimization framework for managed security services.
Feature bloat is real, and it’s by design. VoIP carriers structure their tier pricing so the “middle” plan looks like the safe choice, even when the entry-level plan covers 90% of what a small business actually does. The Metrigy data backs this up: SMBs consistently activate fewer than four out of ten available features.
Key takeaway: Choosing the right VoIP label — managed VoIP vs. UCaaS — is a pricing decision as much as a technical one; most SMBs pay for UCaaS-tier features they never use when a managed VoIP plan would fully cover their needs.
What Should You Gather Before Evaluating Any VoIP Provider?
TL;DR: Pull three months of phone bills, document your headcount and locations, test your internet upload speed, and write down your compliance requirements before you speak to a single vendor. Walking into a VoIP sales call without this information is how businesses end up locked into five-year contracts with features they don’t need.
Here’s the pre-evaluation checklist:
- Last three months of phone bills — identify your average monthly spend, total line count, and any overage charges. Overages often signal that your current plan is misconfigured, not that you need a bigger one.
- Headcount and location count — remote workers, satellite offices, and hybrid team members each add complexity. A five-person office with two remote employees has different requirements than a five-person office where everyone sits in the same room.
- Internet connection specs — VoIP quality depends on upload bandwidth and latency. The standard rule of thumb is 100 Kbps per concurrent call. Run a speed test at peak business hours, not at 7 a.m. on a Sunday.
- Must-have vs. nice-to-have feature list — auto-attendant, voicemail-to-email, mobile app, call forwarding, basic call recording. Write these down before any vendor conversation.
- Compliance requirements — HIPAA-covered entities need a Business Associate Agreement (BAA) from their VoIP provider. Businesses that process card payments should confirm PCI DSS scope with their provider. Don’t assume compliance — ask for documentation.
- Existing contract terms — early termination fees from your current provider can run $500–$3,000 depending on contract length. Factor this into your switching timeline and total cost comparison.
A free VoIP readiness assessment — where someone reviews your internet specs, current usage, and compliance requirements before recommending anything — is worth asking for from any managed IT or VoIP provider before you commit. If they won’t do it, that tells you something.
Key takeaway: Gathering your phone bills, network specs, headcount, and compliance requirements before any vendor conversation gives you the leverage to reject upsells and compare providers on an apples-to-apples basis.
Step 1: How Do You Audit Your Current Phone Usage to Set a True Baseline?
TL;DR: Request a usage report from your current provider, count active users versus licensed seats, and calculate your true cost per user per month. Most businesses discover they’re paying for 20–30% more capacity than they actually use.
Log into your provider’s admin portal or call their support line and request a call detail record (CDR) export for the last 90 days. What you’re looking for:
- Peak concurrent calls — the maximum number of simultaneous calls during your busiest hour. This is the number that actually determines how many lines you need, not your total headcount.
- Active users vs. licensed seats — count how many employees made or received at least one call per week over the 90-day period. Compare that to your licensed seat count.
- Feature activation rate — which features are enabled in your account vs. which ones show actual usage in the logs. Conference bridge with zero calls in 90 days? That’s a candidate for removal.
- Average call duration — relevant for metered plans and for understanding whether your team’s call patterns are inbound-heavy, outbound-heavy, or balanced.
Here’s a concrete example of what this audit reveals in practice: a 15-person accounting firm running a 25-seat UCaaS plan with video conferencing enabled. After pulling 90 days of usage data, they found that only 11 employees made regular calls, peak concurrent calls never exceeded six, and the video conferencing feature had been used exactly twice. Switching to a lean managed VoIP plan sized to their actual usage saved $340 per month — $4,080 per year — with no change to how their team worked day-to-day.
I’ll be honest: at first I assumed the savings in scenarios like this came from negotiating a better rate. It almost never does. The savings come from right-sizing the seat count and dropping features that were never activated.
Key takeaway: A 90-day call detail record audit almost always reveals that businesses are paying for 20–30% more seats and features than their actual usage requires — and that gap is recoverable without any disruption to operations.
[IMAGE: alt=”Sample VoIP usage audit spreadsheet showing active users versus licensed seats and feature activation rates” | filename=”voip-usage-audit-spreadsheet-example.jpg”]
Step 2: How Do You Build a Feature List That Prevents Upsell Pressure?
TL;DR: Classify every VoIP feature into one of three buckets — Must-Have, Nice-to-Have, and Never-Need — before you talk to any vendor. This single exercise consistently reduces first-year VoIP spend by 15–30% by giving you a documented basis to decline upsells.
The three-tier classification works because it forces specificity. “We need good call quality” is not a feature requirement. “We need an auto-attendant with three menu options, voicemail-to-email, and a mobile softphone app for six remote employees” is a feature requirement — and it’s one a sales rep can’t easily inflate.
Here’s how the tiers typically break down for a small business:
- Must-Have: Auto-attendant/IVR, voicemail-to-email transcription, mobile softphone app, call forwarding rules, basic call recording (if required for compliance or quality review)
- Nice-to-Have: CRM integration (HubSpot, Salesforce), SMS/text messaging from a business number, basic call analytics dashboards, video conferencing for internal meetings
- Never-Need (for most SMBs): AI sentiment analysis, enterprise contact center modules, operator console licenses, global PSTN bundles, workforce management tools
The bundled pricing trap is worth calling out specifically. Some providers include “free” video conferencing or “free” team messaging in their base plan — but those features are priced into the per-seat cost whether you use them or not. If you’ve already decided video conferencing is a Nice-to-Have and you have a separate tool you’re happy with, a bundle that includes it isn’t a deal. It’s a price anchor.
Build this list as a simple spreadsheet before your first vendor call. Bring it to every demo. When a rep shows you a feature that isn’t on your Must-Have list, your answer is: “That’s not in our requirements. What does the plan look like without it?”
Key takeaway: A written three-tier feature classification — created before any vendor contact — gives you a documented baseline that makes upsell pressure factually easier to decline and keeps your evaluation focused on actual business requirements.
[IMAGE: alt=”Three-column VoIP feature matrix table with Must-Have, Nice-to-Have, and Never-Need categories filled with example features” | filename=”voip-feature-matrix-must-have-nice-to-have-never-need.jpg”]
Step 3: How Do You Compare VoIP Pricing Models Without Getting Misled by ‘Starting At’ Quotes?
TL;DR: Always request an all-in monthly cost quote in writing for your exact user count and feature set. “Starting at” pricing is a marketing number, not a contract number — and the gap between the two often runs 25–40% once fees are added.
The three most common VoIP pricing structures each suit different usage patterns:
- Per-user/month — predictable and simple. Works best for businesses with stable headcount. Watch for minimum seat requirements that force you to pay for more users than you have.
- Per-line/month — charges by phone number or channel rather than by employee. Can be more economical for businesses where multiple employees share lines or where call volume is low.
- Metered/usage-based — you pay for minutes used. Works well for very low-volume callers (a five-person office with mostly inbound calls). Becomes expensive fast if your team makes significant outbound calls.
“Unlimited” plans deserve specific scrutiny. The word “unlimited” in a VoIP contract almost always comes with a fair-use policy buried in the terms of service. Providers can throttle or surcharge accounts that exceed undisclosed usage thresholds. Ask for the fair-use policy in writing before signing.
Hidden fees are the other variable that makes “starting at” pricing misleading. Common additions include: number porting fees ($20–$50 per number), E911 compliance fees (required by the FCC — see the FCC’s VoIP and 911 guidance), regulatory recovery fees, and hardware leasing markups if the provider is supplying desk phones. Ask for a full fee schedule — not a rate card — before you sign anything.
Seasonal staffing is another variable to account for. If your business scales headcount up and down across the year, confirm whether the provider allows seat count adjustments mid-contract and whether there are fees for scaling down.
Key takeaway: Request a written all-in monthly quote for your exact configuration — including E911 fees, porting fees, and any regulatory surcharges — before comparing providers; “starting at” pricing routinely understates true monthly cost by 25–40%.
Step 4: How Do You Assess Network Readiness and VoIP Security Before Committing?
TL;DR: VoIP security failures — toll fraud, SIP trunk hijacking, and call eavesdropping — are among the most underreported threats in SMB environments. Network readiness and security configuration should be evaluated before you sign with any provider, not after call quality problems or a fraud event forces the issue.
VoIP runs over your internet connection, which means your network configuration determines call quality as much as the provider does. Quality of Service (QoS) is the router/firewall configuration that prioritizes VoIP traffic over other data traffic on your network. Without QoS rules in place, a large file upload or a video stream can degrade call quality even if your total bandwidth is technically sufficient. Most business-grade routers support QoS configuration — but it has to be deliberately set up. It doesn’t happen automatically.
The security threats specific to VoIP are ones I want to spend time on, because they’re consistently underestimated by businesses that are otherwise reasonably security-conscious:
- Toll fraud — attackers gain access to your SIP credentials and make high-volume international calls billed to your account. Losses can reach thousands of dollars in a single weekend. The FBI has documented PBX/VoIP toll fraud as a persistent threat against SMBs.
- SIP trunk hijacking — an attacker intercepts or spoofs your SIP authentication to redirect or monitor calls. Unencrypted SIP traffic is particularly vulnerable on shared or public networks.
- Call eavesdropping — if SIP signaling and RTP media streams are not encrypted, calls can be intercepted on the same network segment. This is especially relevant for businesses handling sensitive client conversations.
Before committing to any provider, ask these specific questions:
- Is SIP signaling encrypted using TLS (Transport Layer Security)?
- Is media traffic encrypted using SRTP (Secure Real-Time Transport Protocol)?
- Do you offer real-time fraud monitoring and call anomaly alerts?
- What are your account lockout and authentication requirements for the admin portal?
The NIST Special Publication 800-58 on VoIP security provides a thorough framework for evaluating these controls — it’s worth reviewing even as a non-technical decision-maker, because it gives you the vocabulary to ask informed questions.
One compliance point that gets missed consistently: if your business handles protected health information, your VoIP provider must sign a Business Associate Agreement (BAA) under HIPAA. Not every VoIP provider will sign one. Confirm this before you evaluate pricing — it’s a disqualifying criterion if they won’t, and finding out after you’ve signed a contract is an expensive problem. The HHS HIPAA covered entity guidance outlines exactly when a BAA is required.
Side note: I’ve seen toll fraud incidents surface in the data during periods of unusual network activity — one case happened over a holiday weekend when no one was monitoring the admin portal. The business came back Tuesday morning to an invoice for $4,200 in international calls. The provider’s fraud monitoring had flagged it, but no one had set up alert notifications. Configure alerts on day one.
Key takeaway: VoIP security — specifically SIP/SRTP encryption, toll fraud monitoring, and BAA compliance for healthcare businesses — must be evaluated before signing with any provider; these are not add-on concerns but baseline requirements for any managed VoIP deployment.
[IMAGE: alt=”Diagram showing VoIP security threats including toll fraud SIP hijacking and eavesdropping with mitigation controls” | filename=”voip-security-threats-smb-diagram.jpg”]
Frequently Asked Questions About Choosing a Managed VoIP Provider
How much should a small business expect to pay for managed VoIP per user per month?
A managed VoIP plan for a small business typically runs $20–$45 per user per month for a right-sized configuration — meaning seat count and features matched to actual usage. UCaaS platforms from major carriers often start at $40–$85 per user per month when enterprise features are bundled in. The difference between a well-scoped managed VoIP plan and a default UCaaS tier for a 15-person business can easily reach $300–$600 per month.
What is the difference between managed VoIP and hosted VoIP?
Hosted VoIP means your phone system runs in the provider’s cloud rather than on hardware at your location — but the level of ongoing support varies widely. Managed VoIP specifically means the provider takes active responsibility for monitoring, maintaining, and troubleshooting your phone system. With a managed VoIP provider, call quality issues, configuration changes, and security updates are the provider’s job. With a basic hosted VoIP plan, those tasks often fall back on you or your IT staff.
Do VoIP providers have to sign a HIPAA Business Associate Agreement?
Yes — if your organization is a HIPAA-covered entity or business associate and your VoIP system transmits or stores protected health information (PHI), your VoIP provider must sign a Business Associate Agreement (BAA). This includes voicemail systems that store patient messages. Not every VoIP provider offers a BAA, so this should be one of your first qualification questions. The HHS Office for Civil Rights has confirmed that VoIP systems handling PHI fall within HIPAA’s technical safeguard requirements.
What hidden fees should I look for in a VoIP contract?
The most common hidden fees in VoIP contracts include: number porting fees ($20–$50 per number), E911 compliance fees (federally required, but the amount varies by provider), regulatory recovery fees (a catch-all surcharge that can add 5–15% to your base rate), and hardware leasing markups if the provider supplies desk phones. Always request a complete fee schedule in writing — not a rate card — and ask for the total monthly cost for your specific user count and feature configuration before signing.
What security questions should I ask a VoIP provider before signing a contract?
Ask whether SIP signaling is encrypted with TLS and whether media streams use SRTP. Ask whether the provider offers real-time toll fraud monitoring and what their alert and response process looks like. Ask about multi-factor authentication requirements for the admin portal. Ask whether they’ve had documented security incidents in the past 24 months and how they responded. A provider that can’t answer these questions clearly is one that hasn’t prioritized security architecture — which is a meaningful risk signal for any SMB deploying VoIP at scale.
Ready to compare specific providers against the criteria in this guide? See our managed VoIP provider roundup for SMBs — where we’ve evaluated eight platforms across pricing transparency, security controls, and feature-to-cost ratio using the same framework outlined here.