Managed service provider agreement

A managed services agreement for an MSP providing ongoing IT, cloud or security services, drafted from the provider's side for a fixed fee of £995 in five working days.

Share

Managed service provider agreement

A managed service provider agreement for an MSP delivering IT, cloud or security services to business customers, drafted for how managed services are sold and run, covering the service catalogue and what is in scope, service levels and monitoring, access to the customer's systems and authorisation, third-party licences and cloud subscriptions, data protection and security, change control and projects, and term, termination and transition. £995, delivered in five working days.

Buy now, £995

A managed service provider runs part of its customers' businesses for them, and the agreement has to say which part: a service catalogue that defines what is managed and what is not, service levels the provider can meet, the authorisation the provider needs to access systems it does not own, the position on third-party licences and subscriptions it resells, the data protection terms its access requires, and a transition out that does not leave the customer stranded or the provider working for free. I draft that agreement for a fixed fee of £995, delivered in five working days.

Who this is for

Managed service providers in England and Wales delivering IT support, infrastructure, cloud, backup, security or communications services to business customers under a monthly contract, who need a standard agreement for every customer.

What matters in a managed service provider agreement

The service catalogue and what is in scope

The agreement should refer to a service catalogue or schedule that defines each service (help desk, device management, patching, backup, monitoring, cloud administration), the systems and users covered, the hours, and the exclusions: projects, hardware, software not on the supported list, and problems caused by unsupported changes; work outside the catalogue is chargeable at stated rates under a change or a statement of work. The provider's obligation is to deliver the services with reasonable care and skill under section 13 of the Supply of Goods and Services Act 1982 as the catalogue describes, and a catalogue the customer can read is what prevents the phrase 'we thought that was included'.

Service levels, monitoring and reporting

The agreement should set response and resolution times by priority, availability commitments for services the provider hosts, exclusions for the customer's systems and third parties, the monitoring the provider performs and the alerts it acts on, monthly reporting, and service credits or a review mechanism as the remedy, with a termination right for persistent failure; an MSP's service levels should be drafted for the least reliable customer site rather than the best.

Access to the customer's systems and authorisation

The provider holds administrator credentials and remote access to the customer's systems, and the agreement should record the customer's authorisation for the provider to access, configure, monitor and modify the systems in scope, which keeps the provider on the right side of the Computer Misuse Act 1990, set the provider's obligations on credential management, logging and staff vetting, and require the customer to tell the provider about changes and to keep its own access controls; the agreement should also say who owns configurations, scripts and documentation the provider creates, under the Copyright, Designs and Patents Act 1988.

Third-party licences, cloud subscriptions and resale

Where the provider resells software licences and cloud subscriptions, the agreement should say that the vendor's terms apply to the customer's use, that the provider's obligation is to procure and administer rather than to warrant the vendor's product, that vendor price changes are passed through on notice, and that subscriptions have their own minimum terms that survive termination of the managed service unless transferred. The customer's obligations under licences (compliance, audits) should be the customer's, with the provider assisting.

Data protection, security and confidentiality

The provider processes personal data in the customer's systems as a processor, and the agreement must contain the provisions Article 28 of the UK GDPR requires, state security under Article 32 including the provider's own certifications, list subprocessors and locations with transfers under Article 46, and provide breach notification in time for the customer's obligations under Article 33; the provider's access to everything the customer holds makes confidentiality and staff obligations central, and the agreement should also record the customer's responsibility for its own security policies and end-user conduct.

Change control, fees, term, termination and transition

The agreement should provide a change control process for scope and user numbers, monthly fees with annual review by index or notice, interest under the Late Payment of Commercial Debts (Interest) Act 1998, suspension for non-payment after notice, an initial term with renewal, and termination for breach and insolvency. On exit the provider should provide transition assistance at stated rates, hand over credentials, documentation and data, and cooperate with the new provider, and both parties should recognise that the Transfer of Undertakings (Protection of Employment) Regulations 2006 may transfer staff dedicated to the customer where the service moves in-house or to another provider. Liability should be capped under section 11 of the Unfair Contract Terms Act 1977 with third-party rights excluded under the Contracts (Rights of Third Parties) Act 1999.

What it costs

Reseller or partner agreement, £995. Channel, referral or white label arrangements. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

A customer expects us to fix a problem caused by software we do not support. Do we have to?

Not under the managed service, if the catalogue lists the supported software and excludes the rest; the work is chargeable at the stated rates. The catalogue is what makes that answer stick.

The customer is leaving. Do we have to help the new provider?

The agreement provides transition assistance at stated rates, handover of credentials and documentation, and cooperation, because a customer that cannot leave cleanly is a customer that stops paying. The staff transfer rules may also apply and the agreement addresses them.

Do the cloud subscriptions we resell end when the managed service ends?

Not automatically: the vendor's minimum terms survive unless the subscriptions are transferred to the customer or a new provider. The agreement says so, which avoids the customer's surprise.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.