What's in an MSP Contract? SLAs, Terms & the Red Flags That Lock You In
A managed IT services contract is two documents doing one job. The Master Services Agreement (MSA) sets the rules of the relationship. The Service Level Agreement (SLA) sets the performance you are owed and what happens when you do not get it. Together they decide how good your managed IT services actually are. Not the sales deck. The contract.
Most companies sign it backward. They fall for the demo, like the account rep, and treat the agreement as a formality to clear on the way to "yes." Then a server is down for six hours, they open the contract for the first time, and they learn the response time they assumed was a promise was never written down.
Here is the uncomfortable part. According to ITIC's 2024 survey, 57% of small businesses say a single hour of downtime costs them more than $100,000. Your contract is the only thing standing between you and that number, and you have leverage over it exactly once. Before you sign.
This guide walks through what is actually in a managed IT services contract, what the SLA numbers mean, and the six clauses that should make you put the pen down.

What a managed IT services contract actually is
People use "MSA," "SLA," and "contract" as if they are the same thing. They are not, and the difference matters when something breaks.
The Master Services Agreement is the legal frame. It covers term length, payment, liability, confidentiality, data ownership, and how either side exits. The Service Level Agreement is the performance contract sitting underneath it: response times, uptime targets, what counts as a "critical" issue, and what you get when the provider misses. Some agreements add a Statement of Work (SOW), a third layer that lists the specific systems and tasks covered, separating routine support from project work that bills separately.
The distinction between the MSA and the SOW is where most scope disputes start. The MSA says the provider supports "your network." The SOW is where you find out whether "your network" includes the warehouse Wi-Fi, the two servers in the closet nobody documented, and the executive who insists on a personal device.
One sentence to remember: the MSA governs the relationship, the SLA grades the work, and the SOW defines the boundaries. If a provider hands you one document and calls it all three, that is your first data point.

The 7 things every MSP contract must spell out
A complete managed IT services contract answers seven questions. If any one is vague, that is the part that will cost you later.
1. Scope: what is covered, and what is billable
Scope is the single most fought-over line in the agreement. A good contract lists what is included (monitoring, patching, helpdesk, backup oversight, incident response) and, just as important, what is excluded and billed separately (one-time migrations, application development, cabling, unsupported operating systems, after-hours projects).
The trap is the word "support." Two providers can both promise to "support your environment" and mean completely different things. One includes your Microsoft 365 tenant, your firewall, and your line-of-business app. The other quietly excludes anything it did not install. Ask for the exclusions list in writing. A provider that will not put it on paper is telling you something.
2. SLA metrics: response, resolution, and uptime
This is where the SLA earns its name. Three numbers carry most of the weight, and you need to understand what each one actually promises.
- Response time is how fast someone acknowledges your ticket and starts working it. Not how fast it is fixed. The industry benchmark for a critical incident is around 15 minutes.
- Resolution time is how fast service is restored. Reasonable targets run four hours for critical issues, longer for low-priority requests.
- Uptime is the percentage of time covered systems stay available. 99.9% is the common baseline, which still allows roughly 8.76 hours of downtime a year. 99.99% cuts that to about 52 minutes.
Here is the catch most buyers miss. A response time is only as real as its definition of "critical." If the provider decides what counts as a critical ticket, a 15-minute response promise means nothing. Make sure the contract defines severity levels and ties response times to each one. And confirm how performance gets reported. A number you cannot audit is marketing, not a commitment.
3. Pricing model: per-user, per-device, or flat fee
How you are billed shapes how the provider behaves. There are three common managed services pricing models:
- Per-device: a flat rate for each supported asset, often something like $69 per workstation and $299 per server. Easy to quote, but it gets messy as people add phones and tablets.
- Per-user: one monthly fee per employee, covering all their devices. It is the most common model heading into 2026 because it scales with headcount instead of hardware.
- Flat fee: a single monthly number for everything. Clean and predictable, but it only works when your environment is stable and well understood.
None of these is automatically right. What matters is that the contract names the model, lists the per-unit rate, and spells out how things get added or removed. "Custom pricing" with no formula is how a $4,000 monthly bill becomes $6,000 by the third quarter.
4. Security and backup commitments
This is the section that separates a real managed security partner from a help desk with antivirus. A contract should put the provider on the hook for specific controls, not vague reassurance.
Canada's national cyber agency, in its recommended contract clauses for cloud and managed services, spells out what to demand: defined patch cadence and patch windows, vulnerability scanning with named remediation responsibilities, an incident response process covering triage, containment, escalation, and communication, plus your right to review the provider's security policies and audit results.
Backup deserves its own lines. The contract should state backup frequency, retention period, and how recovery is tested, because backup and disaster recovery you have never verified is a guess, not a safety net. If security is described in one sentence and that sentence contains the word "antivirus," you are looking at a red flag, not a security program.
5. Data and tenant ownership
Ask one question and watch the room. When this contract ends, who controls my Microsoft 365 tenant?
If your licenses sit inside the provider's tenant or bill through the provider's account, you may own the licenses but not the configuration. Leaving means migrating to a brand-new tenant, which is slow, expensive, and exactly the kind of pain that keeps companies stuck with a provider they have already fired in their heads. Your tenant should be yours, billed to you or cleanly transferable. The contract should say so in plain language, and it should state that your data is returned to you in a usable format on exit.
6. Liability and indemnification
Now the math gets uncomfortable. Most managed services contracts cap the provider's liability at one to six months of fees. A lot of them sit at the low end: one month.
Put that next to the downtime number. If you pay $5,000 a month and the cap is one month, the most you can recover when a preventable outage costs you six figures is $5,000. The provider's worst case is refunding part of a single invoice. Yours is a week of lost revenue. That imbalance is legal and common, which is exactly why you negotiate it. For a regulated business, or any company where downtime hurts, push for a cap of three to six months minimum and an exit right if the provider misses SLAs two months running.
7. Term, renewal, and exit
Contract length is where providers build the lock-in. Most managed services agreements run one to three years. Longer terms buy better pricing and cost you flexibility. That is a fair trade, as long as you can actually leave when the term ends.
The clause that catches people is auto-renewal. A typical agreement renews for a full term unless you give written notice 60 to 90 days before the renewal date. Miss that window by one day and you are locked in for another year with zero leverage. Read the renewal language first, set a calendar reminder for the notice deadline the day you sign, and confirm what transition help you get on the way out. The best contracts include free offboarding assistance: documentation, admin credentials, and a clean data handoff.

Service credits: what an SLA breach is actually worth
When a provider misses an SLA, you usually get a service credit. It sounds like accountability. Read the fine print before you believe it.
A service credit is a discount on next month's invoice, not compensation for what the outage cost you. A common structure refunds 5% to 10% of the monthly fee per breach. On a $5,000 contract, a missed SLA might earn you a $250 credit against a day that cost you far more. Credits also tend to come with conditions: you have to request them in writing, within a set window, and they often cap at one per month no matter how many times the provider missed.
Service credits are not worthless. They create a small financial sting that keeps a provider honest. Just do not mistake them for a remedy. The real protection is in the liability cap and the exit clause, which is why providers are happy to talk about credits and reluctant to talk about either of those.

6 red flags that should stop you from signing
Across hundreds of agreements, the warning signs repeat. Any one of these is a conversation. Two or more is a reason to walk.
- Auto-renewal with a long notice window. A three-year term that silently renews unless you cancel 90 days out is designed to keep you, not serve you. SerenIT's review of contract clauses flags this as the most common lock-in mechanism in the industry.
- A one-month liability cap paired with a security promise. If the provider is responsible for your security but liable for one month of fees, the incentive math does not work in your favor.
- "Antivirus" as the entire security section. Basic AV is not a security program. No patch cadence, no backup testing, no incident response means no real commitment.
- Your Microsoft 365 tenant living in the provider's account. Convenient on day one, a hostage situation on the day you try to leave.
- Vague scope and "custom" pricing. If you cannot tell from the contract what is covered or what it costs to add a user, you are signing a blank check.
- Evasiveness during the review itself. If a provider gets cagey when you ask plain questions about exit terms or liability now, imagine how they answer when something is on fire.
The questions to ask before you sign
You do not need to be a lawyer to pressure-test an agreement. You need a short list of direct questions and the patience to wait for direct answers. Most experienced buyers work from something like this:
- What is excluded from scope and billed separately?
- How do you define a "critical" ticket, and what is the response time for it?
- What is the liability cap, and will you raise it?
- Who owns my Microsoft 365 tenant when this ends?
- What is the renewal notice window, and what does offboarding include?
- Can I see a sample SLA performance report?
If the answers are clear, written, and easy to get, that tells you as much as the answers themselves. A provider confident in its service does not need a contract built to trap you. The cleanest way to start is with an independent IT assessment so you walk into the negotiation knowing what your environment actually needs covered, and what your compliance requirements add to the list.

How Consilien writes its IC24 agreement
We write contracts from the buyer's side of the table because we have sat on the other side of bad ones. Our IC24 managed services agreements name the scope in a Statement of Work, define severity levels and the response time attached to each, and put our security and backup commitments in writing rather than in a brochure.
We do not park your Microsoft 365 tenant in our account, and we do not hide the exit. Strategic oversight comes built in through our vCIO model, so the contract is reviewed against where your business is going, not just what broke last week. If you already have an internal team, our co-managed IT structure splits responsibilities in writing so nothing falls through the gap between you and us.
If you are weighing a new agreement or trying to read one you have already been handed, our team will walk through it clause by clause. Start with our managed IT services in Los Angeles and bring the contract. We will tell you where the leverage is.