What Should Be in an IT Support Contract: SLAs, Response Times and Red Flags
An IT support contract is one of the few agreements where the interesting parts are the ones people skip. The monthly fee is on page one. What happens when something goes badly wrong is on page six, if it is there at all. Here is what a good contract contains and what should make you pause.
Response times, and why one number is a red flag
If a contract promises "a 1 hour response" with no further detail, it is marketing rather than a service level. Real service levels split issues by severity, because a whole office being offline is not the same as one person needing a password reset.
A sensible structure looks like this:
- Critical (business stopped, multiple users, no workaround): response within 1 hour, worked continuously.
- High (one user stopped, or a system degraded): response within 4 business hours.
- Medium (an issue with a workaround): response within 1 business day.
- Low (requests, changes, new starters): response within 2 to 3 business days, scheduled.
Response is not resolution
This is the single most misunderstood part of any IT contract. "Response within 1 hour" means somebody acknowledges you within an hour. It does not mean the problem is fixed within an hour, and no honest provider will guarantee a fix time for a fault they have not seen yet. What they can commit to is that work starts and continues.
What to look for instead of a resolution guarantee: a commitment to continuous work on critical issues, and a defined escalation path with timeframes. "If it is not resolved in 4 hours it goes to a senior engineer, and at 8 hours you get a call from the director" is worth more than a fix-time promise nobody can keep.
Business hours, defined
Check what "business hours" means, whether it covers UK bank holidays, and what out-of-hours costs. If your business runs Saturdays and your contract does not, you will find out at the worst moment.
What is actually included
The scope section should be specific enough that you could settle an argument with it. Look for:
- Which devices and users are covered, and how that count is adjusted when you grow or shrink
- Whether servers, network equipment, printers and mobile devices are in scope
- Whether third-party software is supported, and to what extent (for example, will they liaise with your accounting software vendor, or just tell you to call them?)
- Whether onsite attendance is included, and how quickly
- Whether Microsoft 365 or other licences are included in the price or billed on top
The exclusions worth reading
Every contract has exclusions and that is reasonable. The ones to check:
Need Reliable IT Support for Your Business?
Our managed IT support services keep your systems secure, monitored, and running efficiently.
- Projects. Migrations, office moves and rollouts are usually out of scope. Fine, but ask how they are quoted and whether you are obliged to use them.
- Legacy systems. Unsupported operating systems and end-of-life software are commonly excluded. If you are running something old, get its position in writing before you sign.
- Hardware failure. Support covers the labour, not usually the replacement part. Know which side of that line you are on.
- Cover for problems caused by others. If your previous provider left something broken, is fixing it in scope?
Security responsibilities, in writing
This section is often thin and should not be. It should state clearly:
- Who is responsible for patching, and to what schedule
- What endpoint protection is deployed and who monitors alerts
- Whether multi-factor authentication is enforced, and who decides exceptions
- Who monitors backups, and how often a restore is tested
- What happens in the first hour of a suspected breach, and who calls whom
Ask the restore question specifically. A backup that has never been restored is a theory. Any provider who cannot tell you when they last tested one is telling you the answer.
Data, access and ownership
This is the part that determines how trapped you are, and it is worth more attention than the monthly fee.
- Your Microsoft 365 tenant should be yours, with your own global administrator account that you control. A provider holding the only admin account is a serious problem, both for lock-in and for business continuity if they disappear.
- Your domain names should be registered to you, not to your IT provider.
- Backups should be accessible to you or restorable to a location you control.
- Documentation of your setup, passwords and licences should be handed over on exit, in a usable format, within a stated number of days.
Exit terms
Look for the notice period, any minimum term, and whether the contract auto-renews. A 12 month term with 90 days notice and automatic renewal means the window to leave is narrow and easy to miss. Thirty days notice on a rolling contract is the sign of a provider who expects to keep you by doing good work.
Also check for offboarding fees. A modest charge for handover time is fair. A large one is a hostage arrangement.
Clauses to push back on
- Unlimited support with an undefined fair use policy. Ask for the actual threshold.
- Automatic price rises above inflation with no cap.
- Provider owns the documentation. You paid for it.
- Sole discretion clauses, where the provider alone decides whether an SLA was met. Ask how performance is reported and how often.
- No reporting at all. You should get regular visibility of tickets raised, response times achieved and backup status.
The question that tells you most
Ask a prospective provider: "Show me an example of your monthly report, and tell me about a time you missed an SLA and what you did." A good provider has both answers ready. The response to that single question will tell you more than the contract will.
Talk to us
If you would like a second opinion on a contract you have been sent, we are happy to read it and tell you what we would question. Call 0207 112 4812.
Looking for proactive IT support instead of reactive fixes?
Speak to our team today and discover how IT-MSP can transform your business technology.







