Free IT Service Agreement
Template
A managed IT / MSP services contract between an IT provider and a client — covering the coverage model (managed or break-fix), a Service Level Agreement (uptime, response times, service credits), data security and breach notification, backup and disaster recovery, IP and third-party licenses, liability, and clean offboarding of data and access. Download and send in minutes.
- No signup required
- Free forever
- Reviewed June 2026
- Covers all U.S. states
Branding (optional)
1 — Provider
2 — Client
3 — Services & Coverage
4 — Service Levels (SLA)
5 — Term & Renewal
6 — Payment
7 — Legal
PDF: choose "Save as PDF" in the dialog that opens.
IT Service Agreement
Date: enter date above
1. Parties
This IT Service Agreement is entered into as of enter date above between Provider name ("Provider"), and Client name ("Client").
2. Services & Coverage
Coverage model: Managed Services
Description: describe the services above
Work beyond the agreed scope (major projects, new deployments, cabling, custom development) is out of scope and billed separately by written approval. Client will provide timely access, accurate information, and keep systems reasonably current.
3. Service Levels (SLA)
Support hours: Business hours (Mon–Fri, 8am–6pm)
Uptime target: 99.9% for systems under Provider's management, measured monthly and excluding scheduled maintenance, client-caused issues, and third-party outages.
Critical (P1) response: 1 hour target; lower-priority tiers carry longer targets set out in the full template.
4. Term & Renewal
Engagement: Ongoing / Recurring
Term: Begins start date for an initial term ending end date.
5. Fees & Payment
Fee structure: Recurring — Monthly | Currency: USD ($)
Fee: USD ($) amount
Payment: Invoices due within Net 30 of issue date. Late amounts accrue interest at 1.5%/month after a 7-day grace period. Provider may suspend Services after 14 days of non-payment without waiving any rights.
6–9. Standard Clauses
Data security & breach notification (reasonable safeguards; notice within 24–72 hrs; FTC Safeguards Rule + pending CIRCIA backdrop) · Data backup, disaster recovery & client data ownership (no guarantee of zero loss) · IP + third-party licenses (custom work assigned on full payment; vendor products pass through) · Confidentiality, data privacy (CCPA/CPRA + 2026 state laws) & independent-contractor status · Optional AI tools disclosure (USCO Part 2 2025; Thaler v. Vidal 2026) · Mutual indemnification & 12-month liability cap (no consequential damages, incl. lost data)
10. Termination, Offboarding & Governing Law
Either party may terminate with 30 days notice, or for cause after a 10-day cure period. On exit, Provider returns/exports Client data, hands over credentials, and removes its access. Governed by the laws of governing state. Provider is an independent contractor. This Agreement is the entire agreement between the parties.
Provider
Signature
Print name: _______________
Date: _________________
Client
Signature
Print name: _______________
Date: _________________
Template preview
Parties
1. Parties
This IT Service Agreement ("Agreement") is entered into as of [Date] between [Provider Name], trading as [Business Name], [Address] ("Provider"), and [Client Name / Company], Attn: [Client Contact Name], [Client Address] ("Client"). The Provider agrees to provide, and the Client agrees to pay for, the information-technology services described below on the terms of this Agreement.
Services & Coverage
2. Services & Coverage
Coverage model: [Managed Services / Break-Fix / Block Hours / One-time Project]
Description: [e.g. Monitoring, patching and help-desk support for all workstations and servers; M365 administration; antivirus and backup management.]
Supported environment: [e.g. 25 workstations, 3 servers, 1 M365 tenant, 1 firewall]
Work beyond the agreed scope — major projects, new deployments, hardware procurement, cabling, custom development — is out of scope and billed on written approval. The Client provides timely access, accurate information, a point of contact, and keeps its systems reasonably current and licensed.
Service Levels (SLA)
3. Service Levels (SLA)
Support hours: [Business hours / Extended / 24×7×365]
Uptime target: [99.9% / 99.5% / 99%] for systems under the Provider's management, measured monthly and excluding scheduled maintenance, client-caused issues, and third-party outages.
Response targets (time to begin work): Critical/P1 [1 hour]; High/P2 4 business hours; Normal/P3 1 business day; Low/P4 3 business days.
Service credits: [optional] — if the Provider misses a committed level in a month, the Client's sole remedy is a service credit against the next month's fees.
Data Security & Breach
6. Data Security & Breach Notification
The Provider maintains commercially reasonable, industry-standard safeguards and notifies the Client of a confirmed security incident [within 24 / 48 / 72 hours] of confirmation. The Client stays responsible for its own reporting — e.g. a non-banking financial institution must report a breach of 500+ consumers to the FTC within 30 days under the amended Safeguards Rule (in effect since May 13, 2024), and critical-infrastructure entities should track the pending CIRCIA federal rule (72-hour incident / 24-hour ransomware reporting; not yet in force as of 2026). The Provider supports, but does not assume, these obligations.
Download the full template — also includes term & auto-renewal, fees & payment, data backup & disaster recovery, client data ownership, IP & third-party licenses, confidentiality & independent-contractor status, an optional AI tools clause, a 12-month liability cap, and termination with data & credential offboarding.
Download the full template — free
Fill in your details above and download a ready-to-send contract.
What's included in this template
How to use this template
Pick the coverage model and write the scope concretely
The single most common reason IT-support disputes happen is a fuzzy scope. First choose a coverage model: managed services (you proactively monitor and maintain everything for a recurring fee), break-fix (you bill per incident or per hour), or block hours (the client pre-buys a bank of time). Then describe what's actually covered in concrete terms — which systems, how many users or devices, and the clear limits (for example "monitoring, patching and help-desk for all endpoints; major projects and procurement quoted separately"). List the supported environment so there's no argument later about what you agreed to manage.
Set the SLA deliberately — and write down the exclusions
The Service Level Agreement is what turns "we'll keep an eye on things" into a measurable promise. Set the support hours (business hours, extended, or 24×7), an uptime target only for systems you actually control (99.9% is common for managed environments; break-fix usually has none), and a target response time per priority tier — response means time to begin work, not to resolve. Decide whether service credits apply if you miss a target. Just as important, keep the exclusions explicit: scheduled maintenance windows, outages caused by the client or by third-party vendors, and force-majeure events should never count against your uptime, or the SLA becomes a promise you can't keep.
Nail down security, backups, data ownership and the liability cap before you get access
IT work means touching the client's systems and data, so settle responsibility up front. Agree the breach-notification window (24–72 hours) and remember the client keeps its own regulatory duties — a financial-services client still owes the FTC a 30-day breach report under the Safeguards Rule, for example. State plainly who is responsible for backups and that no one can promise zero data loss. Confirm the client owns its data and that custom scripts and configurations transfer on full payment, while you keep your reusable tooling (Background IP). Then read the limitation-of-liability clause: it caps each side at the fees paid in the prior 12 months and excludes consequential damages like lost profits and downtime — essential when a small monthly fee could otherwise expose you to a six-figure outage claim.
Sign, exchange access securely, and agree the offboarding
Don't take over a client's systems on a handshake. Get the agreement signed first, then exchange admin credentials through a password manager rather than email, and document the offboarding terms now — on exit you'll return or export the client's data and remove your access, and the client isn't left locked out of its own domains and servers. Use Bonsai to collect the signature and automate recurring monthly invoices, or PandaDoc if you manage many client agreements and need reusable templates with an approval pipeline.
Frequently asked questions
- An IT service agreement is a contract between an IT provider — typically a managed service provider (MSP), IT support company, or independent consultant — and a client that sets out which IT services are delivered, to what service levels, who is responsible for data and security, and how the relationship can end. It is a specialized service agreement: on top of the usual scope, fees, and termination terms, it adds the things that matter for technology work — a defined coverage model (managed vs. break-fix), a Service Level Agreement (SLA) with uptime and response targets, data-security and breach-notification obligations, backup and disaster-recovery responsibilities, and clear handling of credentials and client data when the contract ends. Without a written IT service agreement, support expectations are vague, no one is clearly responsible for backups or a breach, and the client can be locked out of its own systems on a bad exit.
- An SLA (Service Level Agreement) is the part of an IT service agreement that defines measurable performance commitments. A good SLA includes: support hours (business hours, extended, or 24x7x365); an uptime or availability target for systems the provider controls (commonly 99.9%, 99.5%, or 99%); priority or severity tiers with a target response time for each (for example, 1 hour for a critical outage, next business day for a low-priority request); and, optionally, service credits — a fixed refund or fee reduction if the provider misses the committed targets. Equally important are the SLA exclusions: scheduled maintenance windows, outages caused by the client or by third-party vendors, and force-majeure events are normally carved out so the provider is measured only on what it actually controls. This template lets you set the uptime target, critical-response time, support hours, and whether service credits apply.
- It depends on how the provider charges and how much risk each side wants. Under a managed-services model the provider proactively monitors and maintains the client's systems for a recurring monthly or annual fee — predictable cost, broad coverage, and an SLA that makes sense because the provider controls the environment. Under a break-fix model the provider is paid per incident or per hour only when something needs fixing — lower baseline cost but no proactive maintenance, and uptime SLAs are harder to commit to because the provider is not continuously managing the systems. A block-hours model sits in between: the client pre-purchases a bank of support hours. This template supports all of these through the coverage-model selector, and adjusts the fee block accordingly; choose managed services if you want uptime guarantees and predictable budgeting, break-fix if support needs are occasional.
- Whoever the contract says — which is exactly why it must be written down. This template makes backup responsibility explicit: under a managed-services scope the provider performs and monitors backups to an agreed schedule, but no provider can guarantee zero data loss, so the clause sets recovery expectations rather than an absolute promise. On security, the provider agrees to maintain reasonable, industry-standard safeguards and to notify the client of a confirmed security incident without undue delay (you can set a 24-, 48-, or 72-hour window). The client, however, remains responsible for its own regulatory obligations: for example, a client that is a non-banking financial institution must itself report a qualifying breach to the FTC within 30 days under the amended Safeguards Rule (in effect since May 13, 2024), and critical-infrastructure entities should track the pending CIRCIA federal reporting rule (72-hour incident and 24-hour ransomware-payment reporting; final rule expected but not yet in force as of 2026). The provider supports those obligations; it does not assume them.
- The client owns its own data at all times, and the agreement requires the provider to return or export that data on termination. For work the provider creates specifically for the client — custom scripts, documentation, or configurations — this template assigns ownership to the client on full payment, as a work made for hire under 17 U.S.C. §101 with a backup assignment under §204. The provider keeps its pre-existing tools, scripts, and methodologies (Background IP) and licenses them to the client only as embedded in the delivered work. Third-party products are treated separately: hardware, software, and cloud subscriptions the provider resells or procures are licensed to the client directly under the vendor's terms and at the client's cost, carrying only the manufacturer's or publisher's warranty, and open-source components remain governed by their own licenses. This keeps the client in control of its data while avoiding any accidental transfer of the provider's reusable tooling or a vendor's IP.
- Yes. Either party can usually terminate for convenience with written notice (commonly 30 days) or immediately for cause — such as material breach or non-payment — after a short cure period. The exit is where IT contracts most often go wrong, so this template adds offboarding terms: on termination the provider returns or exports the client's data in a usable format, hands over or documents necessary credentials, and removes its own administrative access to the client's systems, while the client pays for services rendered up to that date. Obligations that must outlast the contract — confidentiality, data security during the handover, the client's data ownership, IP assignment, indemnification, and the limitation of liability — survive termination. Agreeing the offboarding process up front prevents the common nightmare of a departing provider holding the client's systems, domains, or admin passwords hostage.
Bonsai sends the agreement, collects a signature, and automates the recurring monthly invoices that managed-services contracts depend on — so you can focus on the work, not chasing payments.