MSP Contracts and the MSA

Last updated

Why handshake deals fail

Managed services has an ugly cash-flow curve: you lose money at the start of every client relationship. Onboarding a 100-seat client typically costs $10,000–15,000 in tool deployment, documentation, monitoring setup, and security baselining before the agreement earns its first dollar of profit, and typical payback lands around month nine or ten. A client who walks in month four of a verbal, month-to-month arrangement is a straight loss – you paid to onboard them and never got it back.

That math is why "we'll just work on a handshake" is the classic new-MSP mistake. The damage goes beyond one bad exit:

  • Undefined scope. With nothing in writing, every "can you also just..." becomes free work. Scope creep on verbal deals is invisible until you notice a client quietly eating your payroll.
  • Uncapped liability. No contract means no limitation of liability. If a client suffers data loss or a breach, your exposure is whatever a court decides – not a defined cap your insurance can plan around.
  • Depressed valuation. MSPs with strong written recurring contracts are worth far more at exit than firms running on project work or verbal agreements. Your contract stack is literally part of what a buyer is buying.

Month-to-month terms can work, but as a deliberate premium offer, not a default: they generally only make sense with 95%+ retention, and they are typically priced around 25% above the equivalent 36-month term. If you offer month-to-month, price it that way on purpose – see MSP pricing models for how term length and price interact.

The structure: one evergreen MSA, many attachments

The standard structure – reflected in Scott & Scott LLP's template guidance, developed across roughly 150 MSP contracting engagements – separates the legal shell from the services:

  • The MSA is evergreen. It holds the legal terms: liability, indemnification, data ownership, termination, dispute resolution. It rarely changes.
  • Orders, Service Attachments, and SOWs define what you deliver – the managed services plan, projects, add-ons – and are incorporated into the MSA by reference. A new service line means a new attachment, not a renegotiated contract.
  • An order-of-precedence clause states which document wins when they conflict.
  • Response-time commitments live in an SLA attachment, not the MSA body, so you can revise them without reopening legal terms. Setting those numbers well is its own discipline – see Designing your SLAs.

Define services in the attachments, never in the MSA body. Your service catalog will change every year; your legal terms shouldn't have to.

The clauses that matter

Scope of services and exclusions. Enumerate the covered services, then explicitly exclude what is not covered: projects, after-hours work, hardware and software outside the supported list, and anything not named. State that undocumented requests default to time-and-materials at your current rates. This clause is what converts "can you also just..." from free work into billable work.

Third-party vendor waiver. A clear, unequivocal waiver of the client's right to sue you for failures of third-party services. When Microsoft 365 goes down, the ISP drops, or a SaaS vendor gets breached, the client's recourse is against that vendor under its EULA – not against you.

Limitation of liability. Cap recoverable damages, commonly at the fees the client paid over the prior 6–12 months, and exclude consequential damages such as lost profits and business interruption. Include specific carve-out language for backup failures and security incidents – the two scenarios where MSPs actually get sued.

Mutual indemnification, aligned to your insurance. Indemnity should run both ways, not one-way against you. You indemnify for your own errors, omissions, and negligence; the client indemnifies for its own licensing gaps, changes it demanded over your objection, and client-side privacy violations. Critically, align the indemnity language with your E&O and cyber policies so the contract and the coverage match – see MSP legal and insurance. Indemnities should survive termination, because regulatory fines arrive late.

Client obligations. The client must provide access, maintain licensing compliance, and keep independent backups; you disclaim data-loss responsibility where the client failed those obligations. Require the client to carry its own cyber insurance.

Data ownership. The client owns its data, full stop. You own your "Provider Work" – scripts, tooling, documentation methodology – with the client receiving a license that expires at termination. Confidentiality is mutual: their passwords and configs, your pricing.

Term, auto-renewal, and termination. Auto-renew with a defined non-renewal notice window (30–90 days is common). Include an early-termination fee – commonly the remaining contract value or a defined buyout. Fee escalators are standard; pairing them with a client termination right above a stated threshold makes them easier to sign.

Offboarding obligations. Define the transition assistance you will provide, at what rate, and the condition that all invoices are paid before data and credentials are handed over. Writing this down before you need it is what makes a clean exit possible – the mechanics are covered in the client offboarding process.

The boilerplate that isn't boilerplate. A 12-month non-solicitation of your employees with liquidated damages (clients do try to hire your best tech), arbitration or dispute-resolution terms with a claim deadline (around six months is typical), and survival, severability, and entire-agreement clauses.

Where to get templates

  • An MSP-specialist attorney. Scott & Scott LLP is the best-known US firm in this niche and sells a Contracts-as-a-Service subscription – templates kept current as ransomware and cyber-liability risk evolves. Monjur, founded by an MSP attorney, offers subscription contracts on a similar model. Best fit: once you have real MRR to protect.
  • The Tech Tribe. A paid MSP community (roughly $60/month tier as of 2026) whose customizable agreement templates plus SOPs are widely cited on r/msp as the best-value starting point for a young shop.
  • Vendor templates. Free MSA templates from RMM/PSA vendors are a floor, not a finish.

Whatever you adopt, have local counsel review it before you use it. Enforceability – especially liability caps and non-solicitation – is state-specific, and a template that has never met a lawyer in your jurisdiction is a guess.

Review it annually

A contract is not a one-time artifact. Cyber-liability language that was fine three years ago may not match what insurers require today, so align contract reviews with your insurance renewal and keep indemnities and coverage in sync. The annual review is also when you exercise fee escalators, add proper attachments for new service lines instead of bolting them on informally, and migrate clients still sitting on old paper.

Where to start

If you have clients on handshakes today: get a real MSA from one of the sources above, have local counsel adapt it, and move every client onto it at the next renewal or price change – clients accept new paper most easily when something else is changing anyway. Every new client, starting with onboarding, signs before the first agent is deployed. The contract you sign on day one determines the margin you keep in year three and the multiple you're offered at exit.