While every business is unique, successful MSPs rely on a core set of clauses to manage expectations and risk. These aren't just legal "fine print"; they are the practical rules that govern how you work every day.
Let’s break down the most critical elements you should include in your document.
This is where most MSPs fail. Don't just say "IT Support." Be specific. Does support include mobile phones? Home offices? Third-party software vendors? Precision in your scope prevents friction.
List every service included in the monthly fee: monitoring, patching, help desk, backup management, and security posture. Then, create a "Excluded Services" section that is even more detailed. Mention that hardware costs, on-site travel, and major version upgrades are outside the scope.
In an age of ransomware and sophisticated cyberattacks, you cannot afford to be the client's insurance policy. Your agreement must clearly state that you are not liable for lost profits, data loss, or business interruption, especially if the client has declined your security recommendations.
Commercial Tip: Use these clauses to drive security adoption. If a client refuses MFA, have them sign a waiver or acknowledge that your liability is further limited for incidents related to that refusal.
Relationships end, and you need a graceful way to exit. Define the notice period—typically 60 or 90 days—and what happens during the offboarding phase.
Crucially, state that offboarding is a billable service. You shouldn't be expected to hand over years of documentation and setup to a competitor for free. Clear terms here prevent "hostage" situations and keep transitions professional.
Your costs go up every year. Vendor licenses increase, and salaries rise. Your MSP service agreement must allow for annual price adjustments, often tied to a Consumer Price Index (CPI) or a flat percentage (e.g., 3-5%).
Luis Navarro’s Insight: Many MSP owners are afraid of this clause, but it’s vital for long-term health. If you don't build in these increases, your most loyal, long-term clients eventually become your least profitable ones.
The role of the MSP has shifted from "fixing PCs" to "protecting the business." Your agreement needs to reflect this shift. Cybersecurity is no longer an optional add-on; it is a fundamental part of the service.
However, you must be careful not to over-promise. Avoid using absolute terms like "bulletproof," "impenetrable," or "100% secure." No system is, and promising it creates an impossible legal standard.
Your agreement should outline the Shared Responsibility Model. You provide the tools and the expertise, but the client is responsible for their employees' behaviour and for approving necessary security investments.
If you recommend a security upgrade and the client rejects it, the agreement should protect you. This creates accountability and encourages the client to take your recommendations seriously during their next Security Review.
Be clear about your SLAs in the context of security incidents. A response time (when you start working) is different from a resolution time (when the problem is fixed).
For complex security breaches, you cannot guarantee a resolution time because you don't control the variables. Your MSP service agreement should reflect this reality to manage client expectations during a crisis.
A 20-page legal document can be intimidating. If a client doesn't understand it, they won't sign it—or worse, they’ll sign it and be surprised later. Your job is to translate the "legalese" into business value.
Instead of focusing on the clauses, focus on the outcomes. "This agreement ensures you have 24/7 protection, predictable costs, and a clear path for when we need to upgrade your systems."
Don't just email the PDF. Schedule a brief meeting to walk through the key points. Highlight the parts that protect them, such as data privacy and SLAs.
Explain that the "Excluded Services" section is there to ensure they aren't paying for things they don't need, but it also gives them a menu of options for future growth. This turns a contract review into a strategic planning session.
As you grow, having multiple different versions of your MSP service agreement becomes a nightmare. Try to get all clients onto a single, standardised template.
This makes billing easier, helps your account managers know what is included for each client, and ensures that your technical team provides a consistent level of service. If a client insists on major changes, consider if the extra administrative burden is worth their business.
Even experienced MSPs make mistakes that can lead to legal headaches or financial loss. At Totality Services, we refined our agreements constantly based on real-world lessons. Here are the most common traps to avoid.
It’s tempting to offer "instant" response to win a deal. But can you deliver that at 2
AM on a Sunday? If you fail to meet your SLAs, you might owe the client credits or give them a reason to terminate for cause.
Practical Advice: Under-promise and over-deliver. Set realistic SLAs that your team can consistently hit even during busy periods. Use your agreement to manage expectations, not just as a sales pitch.
Phrases like "all labour included" are dangerous. Does that include moving 50 workstations to a new office? Does it include setting up a new subsidiary?
Be explicit. Use a list of included items and state that anything not on that list is subject to additional charges. This protects your engineers from being pulled into unbilled projects that distract them from maintaining the client’s core environment.
If you bill based on the number of users or devices, you must have the right to audit those numbers. Clients aren't always great at telling you when they hire new people.
Include a clause that allows you to reconcile your seat counts monthly or quarterly. This ensures you are being paid fairly for the actual work you are doing and the licenses you are providing.
As the MSP industry matures, agreements are becoming more sophisticated. We are seeing a move away from simple labour-based contracts toward value-based pricing and specialised security agreements.
Understanding these trends can help you stay ahead of the competition and build a more resilient business.
If you are working alongside an internal IT team, your MSP service agreement needs to be even more precise. Who is responsible for what? If the internal admin makes a mistake that takes down the network, are you responsible for fixing it for free?
Clearly define the boundaries of responsibility between your team and the client’s internal staff. This prevents finger-pointing and ensures that everyone knows their role in maintaining the environment.
Even in the US, data privacy is becoming a major legal concern. Your agreement should address how you handle client data and your role as a "data processor."
Ensure you have the necessary language to comply with state-level regulations and that you are not assuming the client’s legal compliance obligations. You provide the tools to help them be compliant, but the legal responsibility remains theirs.
The Master Service Agreement (MSA) is the general legal contract that covers the entire relationship, including payment terms, liability, and termination. The Service Level Agreement (SLA) is a specific document or section that defines the technical performance standards, such as how fast you will respond to a support ticket.
Generally, it is better to keep hardware separate or use a "Hardware as a Service" (HaaS) addendum. Including hardware in the main agreement can complicate your tax obligations and make the contract less flexible. Most MSPs prefer to quote hardware as a separate capital expense or a specific monthly add-on.
You should review your template at least once a year. The technology landscape and legal requirements change rapidly. You don't necessarily need to resign every client every year, but you should ensure that all new clients are on the latest version and use QBRs to transition older clients to new terms.
Yes, provided your MSP service agreement includes a clause that defines "Out-of-Scope Work" and specifies the hourly rate for such tasks. It is always best practice to get a quick email confirmation or a simple SOW signed before starting significant out-of-scope work to avoid billing disputes.
This is a commercial decision. If the old agreement is exposing you to risk or is no longer profitable, you may need to issue a notice of non-renewal. Building a profitable MSP requires having clients who respect your professional standards and business requirements. Sometimes, letting a client go is the best way to grow.
Include a clause that allows for an annual increase based on a specific index or a set percentage. Give the client 30 to 60 days' notice before the increase takes effect. If you explain that the increase is to maintain the quality of service and cover rising vendor costs, most clients will understand.
Your MSP service agreement is the blueprint for your business. It protects your team, secures your revenue, and sets the stage for a professional relationship with your clients.
Luis Navarro built MSP Agenda to help MSPs bridge the gap between technical complexity and commercial success. By focusing on clear communication and practical standards, you can turn your agreements into a powerful engine for growth.
Remember, a client who understands the value of your agreement is a client who trusts your expertise. They aren't just buying IT support; they are buying peace of mind and a partnership that helps their business thrive.
Make sure your contract reflects that reality.