System maintenance agreement review basics
Hello, this is Legal Agent.
System maintenance agreements attract far less attention than development agreements, yet a loosely drafted one only reveals its gaps the moment something breaks. If the boundary between what is included in the monthly fee and what is billed separately is unclear, the client assumes coverage that was never promised and the vendor assumes work that was never priced.
Maintenance is usually a quasi-mandate, but not always
A live system continues to need bug fixes, security patches and first response to incidents. Because the vendor is promising ongoing professional support rather than a completed result, maintenance agreements are usually closer to a quasi-mandate than a contract for work, except for discrete enhancement work, which often sits closer to a contract for work. It also helps to separate maintenance, meaning fixing and patching, from operation, meaning day-to-day account management, monitoring and backups, since the fee structure and responsibility differ depending on which is covered.
Response times only matter if they are realistic
A service-level commitment is only useful if the response window matches what the vendor can actually staff. Business-hours-only coverage, out-of-hours escalation, and whether email or chat is the primary emergency channel should all be spelled out, along with how maintenance windows and third-party cloud outages are excluded from any uptime commitment.
Cost boundaries and the incident-response sequence
The most contested issue in practice is where the monthly fee stops: additional development, after-hours work and on-site visits often need a defined hourly rate and approval process once a cap on hours is exceeded. The incident clause should define severity levels and lay out the path from detection through root-cause investigation to recovery report, because it is often unclear at the outset whether a fault sits in the application, the infrastructure or a third-party service.
Security, handover and lock-in
Where the vendor touches production systems, access-grant and revocation procedures, log management and breach-notification deadlines deserve their own clause. At termination, source code, configuration files and infrastructure diagrams held only by the vendor can leave the client unable to move to another provider, so documentation handover and transition support should be fixed in advance.