← Digital, E-Commerce & AI

Digital · IT operations

IT maintenance and technical support agreement

After launch, a system enters a period when availability and security depend on updates, diagnosis and intervention. The agreement must show what maintenance includes, what is a separate project and who prioritises requests.

preventive and corrective ticketing and escalation security updates
Scope distinctionMaintenance, support, enhancements and projects
Work unitTicket with severity, owner and history
Risk addressedUnsupported versions and unremediated vulnerabilities
01

What maintenance includes

Corrective maintenance fixes defects, preventive maintenance reduces risk and adaptive maintenance responds to environmental changes. Enhancements add functions and require separate estimates unless included in a clear budget.

The agreement identifies covered applications, versions, infrastructure and third-party components. An attached technical inventory avoids support implicitly expanding to every connected system.

02

Ticketing, severity and escalation

Every request must enter through a tracked channel and receive a justified classification. The client’s stated priority may be recalibrated against actual impact through an agreed procedure.

  • Persons authorised to open and close tickets.
  • Minimum information: system, version, steps, logs and impact.
  • Severities based on affected functions and users.
  • Response, workaround and target remediation times.
  • L1, L2 and L3 levels and escalation timing.
  • Monthly reporting, recurring problems and preventive action.
03

Updates, dependencies and vulnerabilities

The provider must know whether it may apply patches unilaterally, needs client approval and who bears responsibility when an update is delayed. Test environments, backups, rollback and maintenance windows are defined.

For vulnerabilities, monitoring sources, classification, deadlines and confidential communication are established. The Cyber Resilience Act introduces phased obligations for products with digital elements, including reporting from 11 September 2026 for covered situations.

04

Handover when changing providers

Termination must include handover of repositories, documentation, accounts, configurations, passwords through secure channels and incident history. Transition assistance duration and fees are agreed before conflict arises.

The agreement clarifies which copies are deleted, which data is lawfully retained and when the former team’s access ends. For data processing services, Data Act provider-switching rules may become relevant.

05

How we work together

  1. 01
    Mapping the service

    We clarify the product, users, technical workflows, commercial model and documents already in use.

  2. 02
    Legal analysis

    We establish the B2B or B2C regime, the parties’ roles, applicable legislation and risks to be allocated.

  3. 03
    Drafting and alignment

    We prepare the maintenance and support agreement documents and coordinate them with the interface, proposal, technical processes and schedules.

  4. 04
    Implementation

    We deliver the final version and a clear set of observations for publication, signature, configuration or operational use.

QUESTIONS

Frequently asked questions

Does maintenance automatically include new features?

No. New features must be expressly included or handled through estimated and approved change requests. Defect correction is assessed against existing specifications.

Can a fixed deadline be promised for every fix?

Differentiated targets and an efforts obligation for complex issues are usually more realistic, alongside firm response and workaround deadlines.

Who is responsible if the client refuses an update?

The agreement must provide for risk analysis, notification and effects of refusal. The provider should not bear an entire risk it cannot control.

Need an IT maintenance and support agreement?

Send your documents for a legal assessment and a solution tailored to your commercial objective.