IT managed services agreement

An IT support and managed services agreement for a provider supporting business customers' IT, drafted from the provider's side for a fixed fee of £995 in five working days.

Share

IT managed services agreement

An IT managed services agreement for a provider supporting a customer's IT estate, drafted from the provider's side, covering the supported estate and the service desk, response and resolution and the escalation path, procurement of hardware and software and the vendor terms, cybersecurity baseline and the customer's responsibilities, access, credentials and authorisation, fees, users and annual review, and exit, handover and staff. £995, delivered in five working days.

Buy now, £995

An IT support contract is a promise to keep a business running on systems the provider did not choose and does not own, and the agreement has to define the promise: what estate is supported, what the service desk does and how fast, what the provider procures and on whose terms, what security the provider maintains and what the customer must do itself, and how the provider gets in and out of the customer's systems. I draft that agreement for a fixed fee of £995, delivered in five working days.

Who this is for

IT support companies and managed service providers in England and Wales providing help desk, on-site support, device management, network and server support and related services to business customers under a monthly contract.

What matters in an IT managed services agreement

The supported estate and the service desk

The agreement should list the supported estate by site, user count, device types, servers, network equipment and applications, say that items not listed are out of scope unless added by change, define the service desk hours and channels, the services performed remotely and on site, and the standard tasks included (user changes, patching, backups, monitoring), with work outside the list chargeable at stated rates. The provider's obligation is to perform the services with reasonable care and skill under section 13 of the Supply of Goods and Services Act 1982, as the schedule describes.

Response, resolution and escalation

The agreement should set response times by priority as commitments and resolution times as targets, define each priority by business impact, provide an escalation path, exclude problems caused by unsupported changes, third parties and the customer's own actions, and provide a remedy of service credits or a service review with a termination right for persistent failure; on-site attendance should have its own response time and charges where it is outside the monthly fee.

Procurement of hardware and software and the vendor terms

Where the provider procures hardware, software licences and cloud subscriptions for the customer, the agreement should say that the vendor's terms apply to the customer's use, that the provider's obligation is to procure with reasonable care rather than to warrant the vendor's product, that hardware is sold with the manufacturer's warranty and the implied terms under the Sale of Goods Act 1979 limited where reasonable under the Unfair Contract Terms Act 1977, and that subscriptions have their own terms and minimum periods which survive termination of the support contract unless transferred.

The cybersecurity baseline and the customer's responsibilities

The security services the provider in fact performs (patching, endpoint protection, backups, monitoring) and the standard it works to are stated, the customer must either adopt the provider's recommended baseline or have its refusal recorded, and the customer stays responsible for its own policies, its users' conduct, passwords and physical security, with an express statement that the provider gives no guarantee against security incidents. For the personal data it touches the provider is a processor, so the agreement carries the terms Article 28 of the UK GDPR calls for, security to the standard in Article 32, and breach notification that lets the customer meet Article 33.

Access, credentials and authorisation

Administrator credentials for the customer's whole estate sit with the provider, so the agreement records an express authorisation from the customer for the provider to access, monitor, configure and change the supported systems, the authorisation that keeps that access on the right side of the Computer Misuse Act 1990. In return the provider commits to secure credential storage, logging of privileged activity, vetting of the staff who hold access and confidentiality, while the customer keeps its own access controls current and tells the provider promptly about leavers and changes.

Fees, users, annual review, exit, handover and staff

The fee is set per user, per device or as a fixed sum, with a mechanism for adding users and sites, an annual review by index or on notice, statutory interest on late payment under the Late Payment of Commercial Debts (Interest) Act 1998, suspension after notice for unpaid invoices, an initial term that renews, and termination for breach or insolvency. Exit is where an IT contract is tested: credentials, documentation and data are handed over, the incoming provider is assisted at the rates stated, and both sides face the Transfer of Undertakings (Protection of Employment) Regulations 2006, under which staff dedicated to the customer can move with the work. The liability cap is drafted to pass the test in section 11 of the Unfair Contract Terms Act 1977 and third-party rights are shut out under the Contracts (Rights of Third Parties) Act 1999.

What it costs

SaaS or technology contract, £995. One contract drafted for how your product or service is sold, delivered and supported. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

A customer refused our security recommendations and was then hit by ransomware. Are we liable?

Not for a risk the customer declined to address, if the agreement records the recommendation and the refusal and says that the provider does not guarantee against incidents. The record is the defence, and the agreement requires it to be kept.

Does the customer own the documentation we created about their network?

What the agreement says. The usual position is that documentation about the customer's estate is handed over on exit, while the provider's tools and scripts remain its own.

The customer is moving to a new provider. Do our staff go with them?

Possibly, under the staff transfer rules, if staff were dedicated to that customer. The agreement addresses it so that neither party discovers the point at the handover meeting.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.