What Should Be in a Managed IT Services Agreement?
Managed IT services can cover everything from occasional help-desk calls to complete responsibility for devices, networks, cloud systems, backups, and security. If the agreement only says "IT support," you and the provider may be imagining very different services.
You should expect a managed IT services agreement to define the systems covered, response commitments, security responsibilities, access, records, pricing, and what happens when the relationship ends.
Define what is managed and what is excluded
List the offices, users, computers, servers, network equipment, cloud accounts, business applications, and vendors within scope. The agreement should distinguish ongoing maintenance from projects, after-hours work, new-user setup, equipment purchases, and support for systems the provider did not recommend.
Avoid vague limits such as "reasonable support" without a measurable service description. Ask whether support is unlimited, capped by hours, limited to named users, or billed separately when a request falls outside the plan.
Make response commitments specific
A response time is not the same as a resolution time, because a provider can acknowledge a critical outage in fifteen minutes while taking hours to begin meaningful work unless the agreement defines priority levels, escalation, coverage hours, and the action expected at each stage.
You should ask how the provider classifies a company-wide outage, one employee who cannot work, a suspected security incident, and a routine request. Also identify who can declare an emergency and how you reach a real person when the normal ticket system is unavailable.
Put shared security responsibilities in writing
An IT provider can reduce risk, but it cannot assume responsibilities that were never assigned. CISA's risk considerations for managed service provider customers call for clear contractual requirements, shared responsibilities, incident-management duties, log retention, data separation, and continuity planning.
The agreement should address:
- multifactor authentication and privileged access;
- patching and vulnerability remediation;
- backup ownership, frequency, retention, and restore testing;
- security monitoring and log availability;
- incident notification and evidence preservation;
- remote access and subcontractors; and
- cyber insurance or compliance requirements that apply to your business.
Do not accept "backups included" without knowing what is backed up, where copies are stored, how long they remain available, and who tests recovery, because a successful backup job is not the same as a successful restoration.
Protect your ownership and exit path
Your business should retain ownership or documented control of its domains, tenant accounts, licenses, configurations, and business data. You should know which administrator accounts exist, whether credentials are unique to your company, and how access will transfer if the provider changes.
The termination section should define notice, final billing, data export, credential handoff, documentation, equipment return, and a reasonable transition period. A provider may manage your systems, but the relationship should not make your own technology inaccessible to you.
Review the agreement against a real failure
Imagine your email and file systems stop working on a Friday afternoon. Who notices, who responds, what records are available, how employees receive updates, and what recovery work is included?
If the contract cannot answer those questions, it is not ready. A good agreement does not promise that nothing will fail. It makes responsibilities and decisions clear enough that a failure does not become an argument about what everyone thought the service included.