Guides & Checklists
IT support contracts: terms, notice periods and exclusions to check
What to check in a UK IT support contract before signing: minimum term, auto-renewal, notice, pricing basis, exclusions, exit terms, liability and SLA credits.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
Before signing an IT support contract, check the minimum term and how it renews, the notice period, whether pricing is per user or per device and what counts as a device, the exclusions and out-of-scope rates, the SLA and any credits, the liability cap, and above all the clause that hands documentation, credentials and data back to you on exit.
Most IT support contracts are signed after a good sales meeting and read properly for the first time when something has gone wrong. This guide sets out the clauses that matter and what a reasonable position looks like for a UK business of up to 250 people. It is not legal advice, but it will tell you where to look.
Minimum term and renewal
The minimum term is how long you are committed for. Twelve months is the most common in UK managed IT contracts. Longer terms of 24 or 36 months are offered in exchange for lower rates, and rolling monthly terms exist at a premium.
A longer term is not in itself a problem. What makes it a problem is the combination of a long term, no break clause and unclear exit terms. Check:
- How it renews. Many contracts auto-renew for another full term unless notice is served in a window, sometimes as narrow as 30 days, before the anniversary. Miss the window and you are committed for another year. A fairer position is renewal onto a rolling monthly or quarterly term.
- Whether prices change at renewal. Look for an uplift clause. Indexed to a published inflation measure with a cap is reasonable. "At the provider's discretion" is not.
- Break clauses. The right to terminate early for persistent SLA failure, a change of control at the provider, or insolvency.
Put the renewal date and the notice window in your own calendar the day you sign.
Notice period
Ninety days is common and practical, because a handover to a new provider takes several weeks and you want the outgoing provider still under contract while it happens. Thirty days is generous. Six months is too long for a small business.
Two things to check beyond the number. First, when notice can be served: it should run from the day you give it, not from the next anniversary. Second, what the provider is obliged to do during the notice period. The contract should require them to continue delivering the full service, cooperate with the incoming provider, and hand over documentation and credentials. The process is described from your side in how to switch IT support provider.
Pricing basis: per user or per device
The contract should state exactly what you are paying for.
Per user. Define "user". Is a part-timer a user? A shared reception account? A contractor with a mailbox? A leaver whose mailbox is retained for legal hold? Each of these can be billed if the definition is loose.
Per device. Define "device". Is a monitor a device? A mobile phone? A printer? A virtual server? Our own indicative rates are per device with each category priced separately (computers £17.50, desk phones £16.50, network printers £10, routers and firewalls £25, servers £150 per month, February 2025 figures, subject to confirmation), and the pricing page sets out what each covers.
Either model is fine. What you want is a definition, a mechanism for adding and removing users or devices mid-term (monthly true-up is normal), and a statement of whether removals reduce the bill or only additions increase it.
Scope and exclusions
This is the section that determines whether you are buying a managed service or a break-fix arrangement with a monthly fee. Read it before you read the price.
Included should cover, at minimum: remote helpdesk during stated hours, monitoring of computers and servers, scheduled patching of operating systems and common applications, managed endpoint security, backup monitoring, user onboarding and offboarding, and network management. If any of those are missing, ask why.
Excluded normally covers: projects (migrations, office moves, new servers), hardware and software purchases, out-of-hours work, on-site visits beyond an allowance, third-party application support beyond liaison with the vendor, personal and home devices, unsupported operating systems, and problems caused by your own changes.
Exclusions are normal and honest. What you need is:
- A list, not a general statement that "other services may be chargeable".
- A rate card for out-of-scope work, including out-of-hours multipliers and minimum charges.
- Approval rules. No chargeable work without written authorisation from a named person at your business.
- Confirmation that security and backup essentials are in scope. A contract that puts patching or backup checks in the chargeable bucket is not a managed service.
Full detail on what a scope usually contains is in what is managed IT support?.
The SLA
The service level agreement is where "responsive" becomes measurable. Check that the contract contains:
- A priority table (P1 to P4) with definitions and examples.
- Response targets per priority, with response meaning an engineer starting work, not an automated acknowledgement.
- Resolution targets, or at least update intervals, per priority.
- Covered hours, including bank holidays, and what happens outside them.
- Reporting against the targets.
- Remedies: service credits, a review trigger, or a right to terminate after repeated failure.
If the SLA is on the website but not in the contract, it does not exist. The mechanics are explained in what an IT support SLA is.
Data, credentials and documentation on exit
This is the clause most often missing from small-business contracts and the one that causes the most pain when you leave.
Throughout the contract, your business should own every account, licence, domain, tenant and piece of data. The provider holds administrative access in order to work, not ownership. At the end of the contract, the provider should hand over:
- Global administrator access to Microsoft 365 and any other cloud tenants, with their own accounts removed.
- Credentials for the domain registrar, DNS, firewall, switches, Wi-Fi controllers, servers, backup systems, RMM and remote-access tools.
- The documentation built during the contract: network diagrams, device inventory, configurations, licence records, recovery procedures.
- Any data held on the provider's systems, such as backups, in a usable format.
The contract should say this explicitly, set a timescale (30 days is reasonable), and state that it is at no charge. It should also say that the provider will remove its own monitoring agents and access once handover is complete, and that any backups it holds are deleted after an agreed retention period, with confirmation.
If a prospective provider resists this clause, that tells you something.
Liability, insurance and data protection
Liability cap. Most contracts cap the provider's liability at the fees paid in the preceding 12 months and exclude indirect and consequential loss. That is standard and you are unlikely to move it much. What you can check is that the cap does not exclude the provider's own negligence or breach of confidentiality, and that there is an obligation to carry professional indemnity and public liability insurance with stated minimums.
Data processing. An IT provider with administrative access to your systems is a data processor under UK GDPR, and the contract must include the processor terms required by Article 28: processing only on your instructions, confidentiality, security measures, sub-processor rules, assistance with data subject requests and breaches, and deletion or return of data on exit. The ICO's guidance for organisations sets out what is required. A provider who does not know what a data processing agreement is should not have your admin passwords.
Confidentiality. Mutual, surviving termination.
Subcontracting. Whether the provider can subcontract, and whether you are told. Out-of-hours helpdesks are often subcontracted.
Other clauses worth a look
- Change control. How changes to scope or price are agreed and recorded.
- Service reviews. A commitment to periodic reviews, with reporting.
- Hardware supply. Whether procurement is included, what margin applies, and whether the provider or you own the relationship with the manufacturer for warranty.
- Licence pass-through. Whether Microsoft 365 is billed at Microsoft's price or marked up, and what happens to licences on exit.
- Non-solicitation. Reasonable if mutual and time-limited.
A pre-signing checklist
- Minimum term, renewal mechanism and notice window noted in your calendar.
- Notice period runs from the date given, provider obliged to cooperate with handover.
- Pricing basis defined, with mid-term add and remove mechanics.
- Inclusions listed and cover patching, monitoring, security, backup checks, joiners and leavers.
- Exclusions listed with a rate card and an approval rule.
- SLA table in the contract with hours, reporting and remedies.
- Exit clause returning credentials, documentation and data, free, within a timescale.
- Liability cap, insurance minimums and Article 28 processor terms present.
- Price uplift mechanism capped or indexed.
- Break clause for persistent SLA failure.
Most providers will agree to reasonable versions of all ten. The ones who will not are telling you how the relationship will go.
What to do next
If you are comparing proposals, ask each provider to confirm their position on the ten points above in writing before you compare prices. If you would like to see how a contract that meets them reads, contact us and we will send our standard agreement so you can check it against this list before any conversation about scope or cost.

