What Is Included in a Managed IT Services Agreement?
July 13, 2026
Most people evaluating a managed IT services agreement flip to the pricing page first. That’s the easiest part to compare and the least useful part to read carefully. What actually determines whether the agreement will hold up is scope, service level agreements (SLAs), security specifics and exclusions, and how those four sections talk to each other. The pricing is almost never where the surprises come from.
The Scope Section Is the Whole Deal
Scope defines what the provider is responsible for. Vague scope language is where most disputes start, and phrases like “general IT support” or “comprehensive coverage” belong in marketing brochures, not contracts.
A strong scope section names the systems being covered. That means workstations, servers, firewalls, network equipment, cloud tenants and the line-of-business applications your team uses every day. It also names the categories of work included:
- Help desk
- Endpoint management
- Patching
- Monitoring
- Backup verification
- Network administration
- Cloud administration
If an application isn’t listed, assume it’s out of scope until the provider confirms otherwise in writing.
Documentation deliverables belong in this section too. A strong managed IT operation is built on integrated tooling that includes network diagrams, asset inventories, credential documentation and configuration records that stay current throughout the relationship. Without those, changing providers becomes painful and continuity within the current provider becomes fragile.
SLAs That Mean Something
Response time isn’t resolution time, and confusing the two is the most common way SLA language misleads buyers. A response commitment says how fast the provider will acknowledge a ticket. A resolution commitment says how fast service will be restored. A strong SLA specifies both.
Meaningful SLAs are tiered by severity. Critical incidents (business-down situations) should carry the fastest response and resolution targets. High-impact issues get slightly longer windows. Medium and low-priority requests fall further down. Coverage hours need to be defined specifically. “24/7” with an asterisk isn’t the same as 24/7. If your business operates on evenings or weekends, the SLA needs to reflect that in the base agreement, not in a premium add-on.
The measurement method matters as much as the numbers. Confirm the provider monitors proactively, so downtime is logged from the moment service fails rather than the moment a ticket is opened. And confirm the SLA has teeth. Service credits, escalation rights and termination triggers for chronic misses are what turn commitments into accountability. Without them, the numbers are marketing copy.
Security Specifics, Not Security Promises
“We handle security” isn’t a security clause. A meaningful managed IT services agreement names the security controls being run, the monitoring cadence, the patching schedule and the incident response process.
Patching is the clearest example. NIST Special Publication 800-40, the federal guide to enterprise patch management, frames patching as preventive maintenance and expects organizations to work from a risk-based prioritization framework with defined timeframes for critical, high, medium and low severity vulnerabilities. A strong agreement documents the cadence the provider commits to, not just that patching happens.
Ransomware and breach response should be inside scope, not carved out as separate emergency work billed at premium rates. If the MSP carries cyber liability insurance, the coverage limits should be documented in the contract. Breach notification timelines belong in the agreement, with 24 to 72 hours as a reasonable window for the provider to notify you if their environment is compromised. And the security tools running behind the scenes should be integrated with the ticketing and documentation platforms, not scattered across systems that don’t talk to each other.
The Exclusions That Cost Businesses the Most
Exclusions get read last, usually after something has already gone wrong. The most common ones that surprise clients:
- Major projects like migrations, office moves and hardware refreshes
- Specialized cybersecurity work beyond baseline monitoring
- Compliance audit support
- Third-party vendor coordination beyond a defined threshold
- After-hours work outside defined severity levels
- Line-of-business application support that isn’t specifically named
None of these are unreasonable to exclude. Project work legitimately sits outside a recurring fee. Compliance audits require dedicated attention that doesn’t fit into ongoing support. The problems start when exclusions aren’t discussed until the invoice arrives.
A well-written agreement pairs the exclusions section with pricing for those categories, so the client knows the cost of anything that falls outside the base fee before signing. It also documents client responsibilities: who owns hardware refresh cycles, licensing decisions, user training and internal approvals. When responsibility is clearly assigned to one side or the other, the gray areas disappear.
Reading a Managed IT Services Agreement Like Someone Who Has Seen One Before
Scope, SLAs, security specifics and exclusions have to be read together. What’s included only matters relative to how the SLA measures it and what’s carved out on the other side. To talk through what should be in your next IT agreement, contact James Moore Technology Services.
All content provided in this article is for informational purposes only. Matters discussed in this article are subject to change. For up-to-date information on this subject please contact a James Moore professional. James Moore will not be held responsible for any claim, loss, damage or inconvenience caused as a result of any information within these pages or any information accessed through this site.