{"id":3505,"date":"2026-09-09T17:34:41","date_gmt":"2026-09-09T17:34:41","guid":{"rendered":"https:\/\/acatechsolutions.co.uk\/blog\/it-support-contract-checklist\/"},"modified":"2026-09-09T21:02:43","modified_gmt":"2026-09-09T21:02:43","slug":"it-support-contract-checklist","status":"publish","type":"post","link":"https:\/\/acatechsolutions.co.uk\/blog\/it-support-contract-checklist\/","title":{"rendered":"IT Support Contract Checklist: SLAs, Scope and Exit Terms"},"content":{"rendered":"<p><strong>An IT support contract should tell you what the provider owns, what your business still owns, when each priority receives attention, how security incidents are handled, and what happens when the relationship ends.<\/strong> If those answers depend on sales conversations rather than the signed documents, the service boundary is not yet clear.<\/p>\n<p><em>Reviewed: 9 September 2026<\/em><\/p>\n<h2>IT support contract checklist at a glance<\/h2>\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Area<\/th>\n<th scope=\"col\">The contract should answer<\/th>\n<th scope=\"col\">Evidence to request<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Scope<\/td>\n<td>Which people, devices, sites and services are covered?<\/td>\n<td>Current supported-estate schedule<\/td>\n<\/tr>\n<tr>\n<td>Service levels<\/td>\n<td>When does each response clock run and stop?<\/td>\n<td>Priority matrix and monthly report<\/td>\n<\/tr>\n<tr>\n<td>Security<\/td>\n<td>Who patches, monitors, backs up and responds?<\/td>\n<td>Responsibility matrix and incident route<\/td>\n<\/tr>\n<tr>\n<td>Charges<\/td>\n<td>What is included, variable or separately quoted?<\/td>\n<td>Price schedule and change process<\/td>\n<\/tr>\n<tr>\n<td>Exit<\/td>\n<td>How are access, data and documentation returned?<\/td>\n<td>Exit plan and handover checklist<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>This checklist supports a commercial review; it is not legal advice. Ask a qualified adviser to review terms where liability, regulated data, employment, sector rules or a material business dependency makes that appropriate.<\/p>\n<h2>1. Define the supported estate<\/h2>\n<p>List the users, devices, offices, cloud tenants, servers, networks and important applications included at the start. The contract should explain how additions, removals and acquisitions change the fee. It should also identify unsupported, end-of-life or third-party systems rather than leaving them in an implied grey area.<\/p>\n<ul>\n<li>Are contractors, seasonal users, shared terminals and home workers counted?<\/li>\n<li>Are mobiles, printers, network equipment and meeting-room systems included?<\/li>\n<li>Does support cover Microsoft 365 or Google Workspace administration, or only user troubleshooting?<\/li>\n<li>Which business applications receive best-effort help, vendor escalation or no support?<\/li>\n<li>Who maintains the inventory and how often is it reconciled?<\/li>\n<\/ul>\n<h2>2. Separate a response target from a resolution promise<\/h2>\n<p>A response target measures when the provider begins handling a request. Resolution depends on diagnosis, access, suppliers, parts, change approval and the fault itself. Do not let the two terms blur together.<\/p>\n<p>For each priority, record the business impact, supported hours, target response, update frequency, escalation route and any restoration or workaround objective. Explain whether the clock pauses while the provider waits for the customer or another supplier. Avoid definitions based only on words such as \u201curgent\u201d; a priority-one incident might instead mean a whole-site outage, active compromise or inability to take customer payments.<\/p>\n<h2>3. Confirm operating hours and contact routes<\/h2>\n<p>State the timezone, business days, bank-holiday treatment and out-of-hours arrangement. A 24\/7 monitoring service does not necessarily mean a 24\/7 staffed helpdesk or unlimited engineering work. Record how users open requests, how critical incidents are declared, who may authorise emergency changes and what happens if the normal portal or email service is unavailable.<\/p>\n<h2>4. Build a responsibility matrix<\/h2>\n<p>Write the recurring duties down by system. Useful rows include patching, endpoint protection, user administration, licence renewal, backup checks, restore tests, certificate renewal, domain and DNS control, network changes, supplier escalation, documentation and asset disposal. Give each row one accountable owner even where several parties perform work.<\/p>\n<p>The NCSC\u2019s current <a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/choosing-a-managed-service-provider-msp\" target=\"_blank\" rel=\"noopener\">MSP selection guidance<\/a> recommends clear contracts covering responsibilities, response times, third-party dependencies, backups, access, logs, incidents, reporting and exit arrangements.<\/p>\n<h2>5. Protect provider and administrator access<\/h2>\n<p>The agreement should describe how privileged access is granted, authenticated, reviewed and removed. Ask whether technicians use named accounts, strong multifactor authentication, least-privilege roles and controlled escalation. Shared permanent administrator passwords make accountability and offboarding harder.<\/p>\n<p>Confirm whether the provider can access systems without customer approval, whether sessions or actions are logged, and how emergency access is governed. Include the provider\u2019s own service failure or compromise in the incident route; supplier access is part of your risk, not outside it.<\/p>\n<h2>6. Specify patching, monitoring and end-of-life duties<\/h2>\n<p>Define which software and firmware the provider patches, the normal cadence, the route for actively exploited vulnerabilities, testing expectations, maintenance windows and rollback. Record who identifies unsupported products and who approves replacement or risk acceptance. \u201cManaged\u201d should not mean obsolete systems remain unnoticed until an incident.<\/p>\n<p>Monitoring needs named signals, alert thresholds, coverage hours and an action route. The provider should be able to show whether alerts were received, investigated and closed\u2014not merely that an agent was installed.<\/p>\n<h2>7. Make backup and recovery measurable<\/h2>\n<p>List the protected systems and data, backup frequency, retention, storage locations, encryption, access and monitoring. Define recovery point and recovery time objectives where they matter. Most importantly, agree what restore tests will be performed, how often and what evidence the customer receives.<\/p>\n<p>A backup licence is not a disaster-recovery plan. If the provider is responsible for recovery, identify application dependencies, recovery order, decision-makers, communications and any separately chargeable incident work.<\/p>\n<h2>8. Agree incident notification and evidence access<\/h2>\n<p>The contract should say what constitutes a security incident, who contacts whom, by which channel and within what agreed timeframe. Include incidents affecting the provider or a subcontractor where your service or data may be involved.<\/p>\n<p>Confirm log sources, retention and access. Your business or an appointed incident specialist may need exports during an investigation. Do not discover after an event that evidence was unavailable, overwritten or accessible only through an additional service.<\/p>\n<h2>9. Understand suppliers, licences and exclusions<\/h2>\n<p>Record important subcontractors and platforms used to deliver support. Clarify who holds each licence, who receives renewal notices, what happens when a vendor changes its price and whether the customer can continue using the product after exit. Ask the provider to label exclusions such as major projects, onsite travel, out-of-hours work, hardware, cloud consumption and specialist forensics.<\/p>\n<h2>10. Check price reviews and change control<\/h2>\n<p>The fee schedule should explain the charging unit, minimum commitment, onboarding cost, indexation or review mechanism, taxes and payment terms. A controlled change process should cover new offices, acquisitions, migrations and material scope increases. Compare the full first-year cost with ACA\u2019s guide to <a href=\"https:\/\/acatechsolutions.co.uk\/blog\/how-much-does-managed-it-support-cost-uk\/\">managed IT support pricing<\/a>.<\/p>\n<h2>11. Review data protection wording<\/h2>\n<p>If the supplier processes personal data on your behalf, the written terms should cover the required controller\u2013processor matters, including instructions, confidentiality, security, assistance, subprocessors and end-of-contract handling. The ICO\u2019s <a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/accountability-and-governance\/contracts-and-liabilities-between-controllers-and-processors-multi\/\" target=\"_blank\" rel=\"noopener\">contracts guidance<\/a> is under review following recent legislation, so use the live version and obtain advice for your circumstances.<\/p>\n<h2>12. Read the exit before signing<\/h2>\n<p>Check the initial term, renewal, notice, early termination and service-suspension provisions. The exit schedule should cover credential transfer, administrator access, configuration exports, asset and licence records, documentation, data return or deletion, domain and cloud ownership, final backups and reasonable transition help.<\/p>\n<p>Set timescales and charges for handover work. ACA\u2019s <a href=\"https:\/\/acatechsolutions.co.uk\/tools\/supplier-domain-handover-pack\/\">supplier and domain handover pack<\/a> can help turn those responsibilities into an acceptance checklist.<\/p>\n<h2>Questions to answer before approval<\/h2>\n<ol>\n<li>Can a manager explain the service boundary without calling the salesperson?<\/li>\n<li>Do priority definitions describe business impact and supported hours?<\/li>\n<li>Does every security and recovery responsibility have an accountable owner?<\/li>\n<li>Can the business access its systems, logs and documentation during an incident?<\/li>\n<li>Are variable charges and exclusions visible?<\/li>\n<li>Could another provider take over using the promised exit materials?<\/li>\n<\/ol>\n<p>For ongoing support, review ACA\u2019s <a href=\"https:\/\/acatechsolutions.co.uk\/it-support\/\">managed IT support for UK SMEs<\/a> and use this checklist to compare the proposed scope.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>Does an SLA guarantee that an issue will be fixed?<\/h3>\n<p>Not automatically. Many SLAs commit to response, updates or service availability rather than a fixed resolution time. Read the exact measure, exclusions and remedy.<\/p>\n<h3>Who should own administrator accounts?<\/h3>\n<p>The business should retain controlled ownership of its core tenants, domains and services. Providers can receive named delegated access appropriate to their work.<\/p>\n<h3>Should exit assistance be included?<\/h3>\n<p>Yes. The agreement should state what is handed over, when, in which format and whether transition work is included or chargeable.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Use this IT support contract checklist to compare scope, SLA response targets, security responsibilities, charges, reporting and exit terms before signing.<\/p>\n","protected":false},"author":1,"featured_media":3506,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17,21],"tags":[],"class_list":["post-3505","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information_technology","category-it_services_demystified"],"blocksy_meta":{"page_structure_type":"type-1","styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":7}},"_links":{"self":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=3505"}],"version-history":[{"count":1,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3505\/revisions"}],"predecessor-version":[{"id":3527,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3505\/revisions\/3527"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media\/3506"}],"wp:attachment":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=3505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=3505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=3505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}