What an IT support contract must include
A good IT support contract must clearly define the scope of the service, the SLA and response times, the limits of liability, data security and confidentiality obligations, the use of subcontractors, the pricing principles, termination terms together with data handover arrangements, and the provider’s liability if the agreed SLA and quality commitments are not met. If even one of these parts is missing from the contract — or described vaguely — the company will be in the weaker position in any dispute, no matter how good the service looked in the sales meeting.
The contract is the only document that matters when something goes wrong: a server goes down, data leaks, or the provider raises the price. It should therefore be read not as a formality but as a set of answers to the question of what happens if.
This guide lists the essential parts of the contract, the most common traps, and the clauses that contracts most often lack — so you can check both a new proposal and an agreement already in force.
The essential parts of an IT support contract
Scope of service
The contract must specifically list what is supported, and to what extent within each service: workplaces, servers, network equipment, cloud environments, business systems. Just as important is what falls outside the scope, and on what terms and at what rates out-of-scope work is performed. A vague phrase such as maintenance of IT systems means, in a dispute, whatever the provider decides it means.
SLA and response times
The service level agreement (SLA) defines how quickly the provider responds to a request, how quickly it resolves it, and how incidents are classified by criticality. It is important to understand the difference between response time (when the provider starts working on the issue) and resolution time — and the hours during which the SLA applies. How to choose the right level for your company is covered on the page about what SLA your company needs. If the provider supports business-critical systems or databases, the RTO and RPO parameters matter just as much — how quickly, and from how recent a copy, the provider will restore your data if the worst happens.
Limits of liability
Who is liable for lost data, downtime, or errors in third-party systems? The contract must define both the provider’s liability and its limits — and those limits must be proportionate to the potential damage, not symbolic.
Data security and confidentiality
In most cases an IT support provider has access to practically all of a company’s data, so the contract must include confidentiality obligations, personal data processing terms, and security requirements for the provider’s staff. Objective proof of trustworthiness comes from the provider’s certifications — for example, ISO 27001 for information security. More on security requirements is available on the IT security services page.
Subcontractors
May the provider pass work to subcontractors? If so, the contract must state that the provider is responsible for subcontractors’ work as for its own, and that the client is informed about who actually has access to its systems.
Pricing and indexation
The contract must make clear what is included in the fixed monthly fee — or in the fixed rate per supported unit of IT equipment — how additional work is charged, and under what conditions the price may change. The indexation formula must be defined in advance — not a general right for the provider to review prices, but a specific, verifiable rule. The factors that shape the price of the service overall are described on the page about how much IT support costs for a company.
Termination terms and handover procedure
The best contract is one that is easy to leave. It must define the notice period and — most importantly — the handover procedure: the provider commits to transferring all passwords, documentation, licence and configuration information to the new provider or the internal team. How this process works in practice is described in our guide to changing your IT support provider without risk.
Liability insurance
Professional liability and cyber risk insurance shows that the provider can actually compensate for damage, not merely acknowledge it. Ask for a copy of the insurance certificate and assess whether the insured amount is proportionate to your business risk.
Contract clauses: what to demand and where the traps are
| Contract clause | What to demand | The trap |
|---|---|---|
| Scope | A specific list of supported equipment and systems, with clear boundaries of what is excluded | Generic wording that turns most real work into extras billed separately |
| SLA | Response times by incident criticality, clearly defined SLA parameters and the hours during which they apply | An SLA covering response only, with no resolution commitments; SLA valid only during narrow hours |
| SLA quality | Proportionate liability limits and a clear compensation procedure | Liability with no financial amount and no formula behind it, or capped at a symbolic sum or at a single monthly fee for that service |
| Data security | Confidentiality, personal data processing terms, an access management procedure and an ISO 27001 certification | No definition of who holds which access rights, how they are revoked when the contract ends, or how data is stored |
| Subcontractors | Full provider responsibility for subcontractors and an obligation to disclose them | The right to hand work to anyone without the client’s knowledge; no subcontractor clause in the contract at all |
| Pricing | A clear fixed component, rates for additional work, and a defined indexation rule | A right to review prices with no formula and no client right to terminate if they disagree |
| Termination | An open-ended contract, a reasonable notice period (1–3 months) and a commitment to a smooth handover of all information | A long binding contract term, penalties for leaving early, and no obligation to hand over data on parting |
| Insurance | Proof of valid professional liability and cyber risk insurance | Declared liability the provider is financially unable to cover |
What IT support contracts most often lack
When reviewing contracts already in force, these are the elements most often missing:
- A handover procedure — the contract describes how to start the relationship but not how to end it. Without this clause, changing providers becomes a hostage situation.
- Ownership of documentation — who owns the infrastructure documentation, diagrams and configuration descriptions? They must belong to the client.
- A reporting obligation — the provider must regularly account for what was done, which incidents occurred and what state the IT estate is in, rather than operating as a black box.
- An access management procedure — how the provider’s staff are granted access to your systems, how that access is recorded, and how it is revoked.
- Backup responsibility — who is responsible for creating, testing and restoring backups. This topic is important enough that we dedicated a separate guide to backups and business continuity.
Open-ended or fixed-term contract
A fixed-term contract with a long lock-in period benefits the provider first and foremost: the client is locked in, and the motivation to perform naturally declines. An open-ended contract with a reasonable, short notice period reverses the relationship — the provider has to prove its value every day, because the client is free to leave if the quality stops satisfying them.
When assessing the contract type, look at three things: the length of the notice period, whether there are termination penalties, and whether a handover procedure is described. Altic IT contracts with clients are open-ended — we stay together for as long as you are happy. We believe this is the fairest model for both sides.
What an IT support contract must include
The NIS2 directive extends cybersecurity requirements into the supply chain: companies covered by the directive must manage the risks posed by their service providers — including IT support partners. In practice this means the IT support contract must include security requirements for the provider, incident notification obligations, and the client’s right to assess the provider’s security practices.
When selecting a provider, it is worth asking upfront whether it meets security standards itself and can document its practices — otherwise compliance will have to be dragged in through contract annexes. Whether the directive applies to your company and how to prepare is covered on the page about NIS2 requirements for companies.
Why Altic IT
A contract is only worth as much as the provider’s ability to deliver on it. Altic IT backs its commitments with verifiable facts:
- 180+ clients served, ~3,500 computers and mobile devices and ~350 servers under management;
- ISO 27001 (information security), ISO 20000 (IT service management) and ISO 14001 certifications;
- professional liability and cyber risk insurance of EUR 2 million;
- open-ended contracts with no lock-in — we stay together for as long as you are happy;
- IT estate management according to ITSM, ITIL and COBIT practices, with regular client reporting;
- every client is assigned an experienced external IT manager — a single point of contact, including third-party vendor management;
- the vast majority of clients come through referrals; they include the Bank of Lithuania, the State Tax Inspectorate, Bitė Lietuva, MV Group and other organisations for which contract quality is a critical requirement.
The full scope and principles of the service are described on the IT support services page.
Frequently asked questions
-
Is an SLA necessary for a small company?
Yes — only its level may differ from that of a large organisation. Even a company with a handful of workplaces needs to know how quickly the provider will respond when work grinds to a halt. Without an SLA in the contract, response speed depends solely on the provider’s goodwill.
-
What is the difference between response time and resolution time?
Response time is the time within which the provider starts working on an incident; resolution time is when the problem is actually fixed. Contracts often commit only to response, so it is important to understand exactly what your contract promises and how incident priorities are classified.
-
What should we do if our current contract has no handover procedure?
Initiate a contract amendment: agree with the provider on an annex defining the transfer of documentation, access rights and configurations at the end of the contract. An honest provider will not object to such a clause. If it resists, that is an important signal of how painful a future provider change will be.
-
Does the provider’s insurance really matter if the contract already defines liability?
Yes, because contractual liability without the financial capacity to honour it is only a declaration. Insurance ensures that in the event of serious damage there is something to compensate it from. Altic IT holds professional liability and cyber risk insurance of EUR 2 million.
-
Does NIS2 affect the contract if the directive applies to our company but not to the provider?
Yes. NIS2 obliges you to manage supply chain risks, so you must pass security requirements on to the provider through the contract: incident notification, documented security practices, and the right to assess them. A provider certified to ISO 27001 makes this process considerably simpler.
Get an IT support contract consultation
Preparing to sign an IT support contract, or want to assess the one you already have? Altic IT specialists will help you review the scope, SLA, liability and termination terms, and prepare a contract that protects your business. Get in touch via the contact page or call +370 5 2032018.