We use cookies to understand how the site is used and to improve your experience. Privacy policy

    Skip to main content

    6 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)

    What an MSSP Contract Should Include: The SLA, Scope and Exit Clauses That Decide Everything

    Most managed security contracts are written by the provider and read by nobody until an incident. These are the clauses to check before you sign, for MSSP, MDR and SOC as a service agreements alike.

    Why the contract matters more than the brochure

    A managed security service is a promise about what someone else will do under pressure. The brochure describes the service on a good day. The contract describes it at 03:00 on a bad one: which sources are watched, how fast an alert becomes an investigation, who may isolate a server, what you receive afterwards, and what happens to your data when you leave. The gap between the two is where incidents become disputes.

    The checklist below is organised by the order in which the clauses matter during an incident, then by what matters at audit time, then by what matters at exit. It applies to MSSP, MDR and SOC as a service contracts; the differences between those models are covered in our comparison guide.

    Part 1: the clauses that matter during an incident

    If any of these is vague, the service will be vague when you need it.

    Scope: which sources, systems and locations are monitored

    A named list: endpoints by count and platform, identity providers, cloud accounts, network devices, SaaS applications, log sources. Anything not listed is not watched. Include a change procedure for adding sources, with the price impact stated.

    Detection SLA: time from event to triage

    The committed time between a telemetry event arriving and an analyst looking at it, by severity. Ask how the clock is measured and where the evidence lives. A promise of 24/7 monitoring without a triage time is not an SLA.

    Response SLA and authority: who may act, and how fast

    For MDR: the containment actions the provider may take without asking (isolate host, disable account, block indicator), the ones that need your approval, and the committed time for each. For MSSP and SOC services: the escalation path, contact tiers and the maximum time to reach a named person on your side.

    Escalation and communication

    Named contacts on both sides, 24/7 reachability, the channel for critical alerts (phone, not email), and a war-room procedure for major incidents including who leads.

    Incident reporting that serves your legal duties

    NIS2 requires an early warning within 24 hours and a notification within 72; DORA and the GDPR have their own clocks. The contract should commit the provider to deliver the facts you need for those notifications within the time you need them.

    Part 2: the clauses that matter at audit time

    Your auditor will ask for evidence the provider has to produce. Put the obligation in the contract.

    Reporting cadence and content

    Monthly service reports with alert volumes, mean time to triage and respond, open findings and SLA performance, plus quarterly reviews. Specify that reports map to the frameworks you answer to (ISO 27001, SOC 2, NIS2, DORA).

    Provider assurance

    The provider's own certifications and audit reports (ISO 27001, SOC 2 Type II), the right to receive them annually, and notification when they lapse. DORA Article 28 and NIS2 supply-chain requirements expect you to have this.

    Log retention and evidence preservation

    Retention periods per source, where logs are stored (jurisdiction), who can access them, and the procedure for preserving evidence during an incident or legal hold.

    Testing rights

    Your right to have the service tested by an independent penetration test or red team, including detection objectives, at least annually, and the provider's obligation to cooperate and to report what they saw. A provider that refuses this clause is telling you something.

    Part 3: the clauses that matter at exit

    Every managed security contract ends. Decide the terms now, while you can.

    Data ownership and export

    Your telemetry, alerts, cases and reports belong to you. The contract should commit to a full export in a usable format within a defined period at termination, and deletion certification afterwards.

    Tooling ownership

    If the provider deploys agents, sensors or a SIEM, state what you keep. Licences in your name survive the exit; licences in theirs do not. Decide which you want before onboarding.

    Term, notice and transition assistance

    Initial term, renewal mechanics, notice period, and a committed transition period during which the provider keeps monitoring while the successor onboards. Thirty days of transition is common; ninety is safer for a full MSSP.

    Liability, insurance and sub-processors

    Liability caps that reflect the risk, professional indemnity and cyber insurance with limits stated, and a list of sub-processors with notification of changes, as GDPR Article 28 requires.

    Red flags in managed security contracts

    If you see these, negotiate or walk away.

    • Monitoring described as 24/7 without a triage or response time by severity
    • Scope defined as 'the customer environment' instead of a named list of sources
    • Containment actions left entirely to the provider's discretion, or entirely to yours, without a pre-agreed matrix
    • No right to test the service, or testing allowed only with the provider's tools
    • Reports that are dashboards you can view but nothing you can hand to an auditor
    • Data export at termination 'on request' with no format, period or deletion commitment
    • Automatic renewal with a notice window shorter than the transition the successor needs

    How HackersHub writes its agreements

    Our managed security and MDR agreements state the monitored sources by name, the triage and response times by severity, the containment actions we may take and those we will ask about, the reports you receive and the frameworks they map to, your data and tooling ownership, a transition period at exit, and your right to test us, which we encourage because we test ourselves. Ask for the template before a scoping call; it is easier to compare providers on paper than on promises.

    Frequently asked questions

    Want to see an agreement before a sales call?

    We share our managed security template up front, with sources, SLAs, containment matrix, reporting and exit terms in plain language. Talk to an expert.