What should be in an IT support contract?
A clause-by-clause checklist to hold against any IT support contract before you sign it, from scope and service levels to GDPR, ownership of your admin accounts, and how you get out.

Most IT support contracts get read twice. Once, quickly, the week before signing. Then again, slowly, on the day something has gone wrong and the invoice does not match what you thought you had bought.
By the second reading it is too late. Here is the list to hold against the draft before you sign, clause by clause.
What should the scope section cover?
Scope is where most disputes start. The contract should list the services included in the monthly fee in plain words: service desk, remote and on-site support, proactive monitoring, patching, backup management, user onboarding and offboarding, licence administration. It should list the exclusions just as plainly.
Then look for the grey areas. Is a new starter's laptop set-up included, or chargeable? Is your line-of-business software covered, or only on a best-efforts basis? Does the price cover replacement hardware? Are projects, office moves, new sites and out-of-hours work billed separately, and at what hourly rate?
If the answer to any of those is "we'd sort that out at the time", get a rate card attached as a schedule. What the monthly fee itself should look like is covered in our guide to managed IT support costs in the UK.
What service levels should an IT support contract include?
A service level agreement (SLA) only works if it has numbers in it. You want four things written down.
- Response targets by priority, for example a critical fault acknowledged within 15 minutes and worked on within 60 minutes.
- Resolution or workaround targets by priority, because acknowledging a ticket quickly fixes nothing.
- How the clock is measured: from when you log the ticket, not when an engineer picks it up, and only within the contracted hours of cover.
- What happens when targets are missed: a monthly report, and service credits that come off the next invoice without you having to chase.
Check the hours of cover against your business, not the provider's. If your warehouse starts at 6am, support that starts at 9am leaves a three-hour hole every day. The NCSC's guidance on choosing a managed service provider suggests urgent issues should get a response in under an hour. We have set out what a slow IT response actually costs if you need the sum to justify a tighter target. And you, not only the provider, should have a say in what counts as critical.
Who is responsible for security and your data?
The NCSC guidance is blunt on this point: the contract should set out what the provider takes responsibility for and what stays with you. Ambiguity here is what turns an incident into an argument. The contract should name who does each of these, and to what timescale:
- Patches operating systems and applications. The NCSC expects critical and high-risk updates applied within 14 days.
- Runs backups and tests restores, and how often. Someone has to confirm a restore actually worked.
- Enforces two-step verification and least-privilege access.
- Keeps security logs, for how long, and whether you can see them.
- Tells you about a security incident, within what timeframe, and leads the response.
The data protection clause you cannot skip
If your provider can handle personal data (and anyone with admin rights to your email and files can), they are a processor under UK GDPR and you are the controller. Article 28(3) requires a written contract between you. The ICO lists what that contract must include: processing only on your documented instructions, staff confidentiality, appropriate security measures, rules on sub-processors, help with data subject requests and breach notification, deletion or return of data at the end, and your right to audit.
The ICO is also clear that the controller stays responsible for its processors' compliance and can face corrective orders and fines. If the draft has no data processing terms, or a one-line nod to "complying with applicable law", send it back. Our article on cyber security from your IT provider covers what good looks like day to day.
Ownership, term and exit
These clauses look like boilerplate until you want to leave.
Who owns the keys?
You should own, in your name, every admin credential, your cloud tenant, your domain names, your licences and the documentation of your own network. The provider holds them on your behalf and hands them over on request, within a stated number of days, without a fee. A provider who keeps the global admin account to themselves has a hold over you that no SLA makes up for.
Term, notice and auto-renewal
A 12-month term is normal. A 36-month one is a long time to be wrong. Whatever the term, find the renewal clause: many contracts roll over automatically for another full term unless you give notice inside a narrow window, sometimes 90 days before the end date. Better still, prefer a contract that renews month to month after the initial term.
Price changes
A rise tied to a published inflation index once a year, with written notice, is reasonable. "Prices may be varied from time to time" is not. Per-user pricing should also go down when headcount does.
Exit and handover
The contract should oblige the provider to cooperate with a handover for a stated period, pass on documentation and credentials, release your domain names and tenant, and return or delete your data as the ICO requires. Switching feels frightening mostly because the outgoing contract said nothing about any of this. We wrote about how to switch IT provider without downtime because it should not be.
Liability caps
Almost every provider caps liability, often at the fees paid over the previous 12 months. Check the carve-outs: data protection breaches and the provider's own negligence should not be capped at a trivial sum, and the provider should hold professional indemnity and cyber insurance and show you the certificate.
Four red-line clauses
If you see any of these, do not sign until it is changed.
- Automatic renewal for a further fixed term with a notice window shorter than 60 days.
- Admin credentials, domain names or the cloud tenant held in the provider's name.
- An SLA with response targets but no resolution targets and no service credits.
- A right to change prices or scope unilaterally, without notice and without a right for you to terminate.
One more thing, and it is the honest bit. A contract cannot make a bad provider good. It gives you remedies when things go wrong. It does not make the phone get answered any faster. The check that matters most happens before the contract: references, a visit to the service desk, a look at their certifications, and the questions to ask an IT support company. Our guide to choosing an IT support provider covers the rest.
What we do
Systemwork has supported businesses across Leeds and Yorkshire since 2005, at a fixed monthly price per user. You are welcome to hold our agreement against this checklist before you sign. If you are weighing up a draft from someone else, bring it to the free IT audit and we will tell you what is missing, even if you then sign with them.
Book a free IT audit. Call 0113 898 0565 or use the button below.
Frequently asked questions
Is a written IT support contract legally required?
Not in general, but if the provider handles personal data on your behalf, UK GDPR Article 28(3) requires a written contract covering specific processor terms. In practice almost every IT provider with admin access does handle personal data, so treat the processor agreement as mandatory. The ICO publishes a checklist of what it must contain.
What is a reasonable notice period for an IT support contract?
For a rolling contract after the initial term, 30 to 90 days is common and workable. The clause to watch is auto-renewal into another fixed term, where missing a narrow notice window locks you in for another year or more. Ask for monthly rolling terms after year one, or at least a 60-day window you have diarised.
Does my IT provider need a data processing agreement?
Yes, if they can access personal data about your staff, customers or suppliers, which anyone with admin rights to your email, files or line-of-business systems can. The agreement can sit as a schedule inside the main contract. Without it, you as the controller are the one in breach, not just the provider.
What liability cap is normal in an IT support contract?
A cap equal to the fees paid in the previous 12 months is the most common position. What matters more is what sits outside the cap: the provider's own negligence and data protection breaches should carry a higher limit, backed by professional indemnity and cyber insurance. Ask to see the insurance certificates before you sign.
