An MSP contract in Texas is usually 5 documents, not 1. Read them in order, check which one wins a conflict, and find the page listing what you owe the provider. Texas law adds a few twists, including a 2 year floor on lawsuit deadlines and sales tax on part of the bill. For what the service itself should cover, start with our managed IT services in Texas hub.
In an MSP contract, look for a written scope with an exclusions list, a clause saying which document wins a conflict, the page listing your own obligations, security and breach duties, and exit terms you could live with. Texas buyers should add 4 checks that national guides skip.
Most guides stop at the clause list. This one doesn’t.
I’m the Vice President of Operations at Uprite, which means my team is the one that has to deliver whatever the contract says after the sales conversation ends. Not the pitch. We work from the service schedule, the SLA and the page of client responsibilities that almost nobody reads before signing, the same 3 documents a technician pulls up at 2 in the morning when something breaks and the contract is the only thing that says who fixes it and how fast. So I read these agreements differently than a buyer does. Differently than a lawyer, too. I read them for what happens on a Tuesday.
This guide is the statewide version, written for a Texas business comparing 2 or 3 providers. It covers how the documents fit together, what Texas law changes, and who should review which part. It won’t repeat our clause by clause work. For that, read Houston MSP contract terms, which walks through renewal windows, exclusions and exit language line by line. Still choosing a provider? Start with the managed IT services checklist instead.

What is an MSP contract?
An MSP contract is the set of documents that governs a managed IT relationship. It usually includes a master services agreement for the legal terms, a service schedule for the scope, a service level agreement for performance targets, and an order form for pricing. Together they define what gets done, how fast, for how much, and how either side leaves.
Buyers tend to treat it as a single PDF. It rarely is. Not even close.
Here’s the usual stack, and who should actually read each piece.
| Document | What it decides | Who should read it | The common surprise |
|---|---|---|---|
| Master services agreement (MSA) | Liability, indemnity, term, renewal, governing law | Owner and attorney | A claims deadline shorter than Texas allows |
| Service schedule or statement of work | What’s covered and what’s excluded | Whoever runs operations | Inclusions listed, exclusions missing |
| Service level agreement (SLA) | Response targets, severity levels, credits | Operations and your IT lead | Targets that pause when you miss an obligation |
| Order form or quote | Price, user count, term, start date | Owner and finance | Tax, onboarding and recount rules left off |
| Data or compliance addendum | Breach notice, data handling, subcontractors | Compliance lead and attorney | Notice promised promptly, with no hours stated |
Buyers skip 2 of these. The order form gets read because the price is on it, and the MSA gets skimmed because it looks like every other contract that has ever crossed the owner’s desk. The service schedule and the SLA are where my team lives, and they’re the 2 documents most buyers open last, usually after the first disagreement about whether something was covered under the flat monthly rate or billed separately at the hourly rack rate.
Which document wins when 2 of them disagree?
The order of precedence clause decides it. It’s usually a single sentence near the end of the MSA, and it ranks the documents so a conflict between them already has an answer. Short clause. Big consequences.
Here’s a hypothetical. Say the proposal promised onsite support within 4 hours, the SLA says next business day, and the MSA says the MSA and its schedules control. You’re getting next business day. Nobody lied. The documents just disagreed, and the clause picked a winner before you noticed there was a fight.
Then find the entire agreement clause. Lawyers call it a merger clause. Same idea, sharper teeth. It says the signed documents are the whole deal, which means the sales deck, the email thread and the friendly promise on the reference call don’t count toward what you can actually enforce later. That’s standard. It isn’t a trick. But it does mean every promise you care about has to move into a schedule or an exhibit before signature, and the simplest way I know to do that is to reply to the proposal with a list titled things we were told, then ask which document each item lives in.
Silence is the worst outcome. With no precedence clause at all, a conflict gets settled by argument rather than by a sentence you both signed months before anyone was upset. If you ran a formal MSP RFP process, attach your requirements list as an exhibit for the same reason.
What does the contract expect from you?
This is the page I’d read first. Almost nobody does.
Every managed services agreement has a section on client responsibilities, sometimes called minimum standards or customer obligations. Typical items include keeping hardware under warranty, running supported operating systems, holding valid licenses, naming a point of contact who can approve work, giving the provider access, and reporting issues through the ticket system instead of texting a technician directly. Fall short, and many agreements suspend the SLA or move the work to the hourly rate card without much warning.
That’s not a trap. Honestly, I’d worry more about a provider with no minimum standards at all, because it suggests nobody has thought hard about what can actually be supported at the response times printed on the proposal. No one can promise a 4 hour fix on a server the manufacturer stopped supporting years ago. The problem comes when the list is vague. Or when you first hear about it during an outage. That’s the worst time.
CISA makes the same point from the security side. Its risk guidance for MSP customers tells businesses to define roles in the vendor agreement using a shared responsibility model, spelling out what the provider owns, what the customer owns and what’s shared between them. It gives plain examples, such as which party applies patches, maintains hardware or trains employees on phishing awareness. The same document says something buyers don’t love hearing. Outsourcing IT doesn’t outsource risk.
Ask for 3 things here.
- A numbered list of your obligations, with the consequence of missing each one written next to it.
- A responsibility matrix naming who patches, who backs up, who manages vendors and who trains staff.
- A grace period, so a lapsed warranty triggers a notice and a fix window before it suspends your SLA.
Running an internal IT person alongside the provider? Then the matrix matters twice as much. No exceptions. Our co-managed IT services page shows how that split usually gets drawn.

What does Texas law change in an MSP contract?
Quite a bit. And I should be plain about my lane. I run operations. I’m not an attorney, and nothing here is legal advice. Read that twice. What follows is the list I’d hand your attorney so the hour you pay for goes to the right paragraphs instead of the ones that read the same in every state, the ones a template drafted for a generic vendor in a generic jurisdiction would never touch.
| Texas rule | What it says | Where it touches the contract |
|---|---|---|
| No auto-renewal statute for business contracts | Nobody owes you a renewal reminder | Term and notice clauses |
| Civil Practice and Remedies Code 16.070 | A contract can’t cut the time to sue below 2 years | Claims deadline in the MSA |
| Business and Commerce Code 521.053 | Notify affected people within 60 days, and the attorney general within 30 days at 250 or more Texans | Breach notice clause |
| Business and Commerce Code Chapter 542 | Under 250 employees, a maintained security program blocks exemplary damages | Security schedule and framework language |
| Tax Code 151.351 | Data processing services are taxable, with 20% of the charge exempt | Order form and invoices |
| Fair notice doctrine | Clauses shifting a party’s own negligence must be conspicuous | Indemnity and release paragraphs |
We’ve covered the first row at length elsewhere. Our guide to exiting an MSP contract in Texas explains why the notice date is yours alone to track. The other 5 deserve a few lines each.
The 2 year floor on lawsuit deadlines
Plenty of vendor paper says any claim must be brought within 1 year. In Texas that sentence is void. Section 16.070 of the Civil Practice and Remedies Code says a contract can’t limit the time to sue on it to less than 2 years, and a clause that tries is void in this state, with a narrow carve-out for the sale of a business valued at $500,000 or more. Not your situation. Check the governing law clause too. If the agreement picks another state’s law, this protection may not travel with you, and that’s a question for your attorney rather than for me.
Breach clocks that start with your provider
Under Section 521.053 of the Business and Commerce Code, a Texas business that owns sensitive personal data has to notify affected people without unreasonable delay, and no later than 60 days after determining a breach happened. If 250 or more Texans are involved, the attorney general has to hear about it within 30 days of that same determination date. Those clocks are yours. Not the provider’s.
The same statute says a company that maintains data it doesn’t own must notify the owner immediately after discovering a breach, with no grace period built in for anyone. So read the notice clause with a stopwatch in mind. A contract that promises notice promptly, or within a commercially reasonable time, leaves you guessing while your 30 days run. Ask for a number of hours. In writing.
Texas added a carrot in 2025. Senate Bill 2610 created Chapter 542 of the Business and Commerce Code, effective September 1, 2025. A business with fewer than 250 employees that maintained a qualifying cybersecurity program at the time of a breach can’t be hit with exemplary damages over it. The bar scales with headcount. Under 20 employees, it’s password policies and staff training. From 20 to 99, it’s CIS Controls Implementation Group 1. From 100 to 249, it’s a full framework such as NIST or the ISO 27000 series. If your provider runs those controls, the security schedule should name the framework and say who keeps the evidence. Our Texas SB 2610 compliance guide covers the program side.
Sales tax that isn’t in the quote
Here’s one I almost never see in a buyer’s guide. Most buyers never check. Texas taxes data processing services. The Comptroller’s taxable services publication lists data storage, offsite backup, web hosting and software as a service as examples, and Tax Code Section 151.351 exempts 20% of the charge from tax entirely. So 80% of those line items is taxable at the 6.25% state rate plus up to 2% local, which tops out at 8.25% combined.
Run the math on a made-up invoice. A $1,500 monthly line for backup and hosting has a taxable base of $1,200 once the 20% exemption is applied. At 8.25% that’s $99 a month, or $1,188 a year, that wasn’t on the proposal. Not every line is taxable. And the Comptroller rewrote its data processing rule effective April 2, 2025, which Grant Thornton’s summary notes puts the burden on the taxpayer to show when a bundled service isn’t taxable, so bundled agreements got more complicated rather than less. Ask 2 questions. Is tax included in the quoted figure? Which line items does the provider treat as taxable? Then let your CPA check the answer.
Why the liability paragraph is in capitals
Ever wonder why 1 paragraph of the MSA is shouting? Texas courts apply what’s called the fair notice doctrine to clauses that shift the cost of a party’s own negligence onto the other side. The Texas Supreme Court set it out in Dresser Industries v. Page Petroleum in 1993, and Jackson Walker’s summary of the rule puts it simply. The intent has to be stated clearly inside the contract, and the language has to stand out in the document rather than blend into the paragraph around it. That’s why indemnity and release language shows up in capitals or bold. Treat that as a flag. The loudest paragraph in the document is often the one moving risk onto you, so it’s the one your attorney should read twice, line by line, before either of you signs anything.

Who should review an MSP contract before you sign?
More than 1 person. Up to 5, and each gets a different section.
| Reviewer | Sections to hand them | The question to bring |
|---|---|---|
| You or your operations lead | Service schedule, SLA, client responsibilities | Can we actually meet our side of this? |
| Attorney | MSA, liability, indemnity, governing law, claims deadline | Which of these terms are unusual for Texas? |
| Insurance broker | Security schedule, breach notice, provider’s insurance | Does this match what we told our cyber carrier? |
| CPA or controller | Order form, tax treatment, recount rules | What will month 13 cost, tax included? |
| Internal IT lead, if you have one | Responsibility matrix, access and admin rights | Who holds which credentials on day 1? |
A correction is due here. We’ve written before that most of a contract read doesn’t require a lawyer, and I’d sharpen that now that I’ve laid the stack out this way. You don’t need counsel for the whole stack. Four pages. That’s it. CISA says it flatly in the same guidance, telling organizations to work with their counsel on a legal review of MSP contracts before signature, not after something has already gone wrong.
The broker row is the one people skip. It’s also the expensive one. Worth the 20 minutes.
In 2022 Travelers asked a federal court in Illinois to rescind a cyber policy it had issued to a company called International Control Services. Insurance Journal reported that the application said the company used multifactor authentication for administrative access, while the investigation after a ransomware attack found MFA protected only the firewall and nothing else the attacker touched.
Here’s the connection to your MSP contract. Your insurance application makes promises about MFA, backups and endpoint protection. Your provider is usually the one delivering them. If the security schedule doesn’t commit the provider to the same controls you attested to, there’s a gap between what you swore and what you bought, and it’s the kind of gap an insurer finds during a claim rather than during underwriting. Our walkthrough of the cyber insurance application shows the questions carriers ask. Put the 2 documents side by side. It takes 20 minutes.
How to read an MSP contract in 60 minutes
Order matters more than speed. Here’s the sequence I’d use.
- Find the order of precedence and entire agreement clauses. Now you know which pages count.
- Read the client responsibilities section. List anything you can’t meet today.
- Read the service schedule. Circle the exclusions list, or note that it’s missing.
- Read the SLA definitions before the targets. Check what pauses the clock.
- Read term, renewal and exit together. Put the notice date in your calendar.
- Read the security schedule and breach notice clause against your insurance application.
- Send the liability, indemnity and claims deadline paragraphs to your attorney. The order form goes to your CPA.
Steps 4 and 5 have their own deep guides. Our piece on what Texas response time contracts actually say covers clocks, credits and chronic failure rights. Already mid-term rather than pre-signature? Then when to re-evaluate your managed IT contract is the better starting point.
What should the provider hand you before signature?
CISA’s guidance includes a list of what to request before contract award. Most small businesses have never seen it. For a Texas company under 250 people, these 6 items matter most. Ask for all 6.
- Performance SLAs that separate IT operations from security services.
- A commitment to notify you if the provider’s ownership or leadership changes.
- Incident management guidelines, including the provider’s own response duties and compensation for outages.
- Notice of any subcontractors who could touch your data, with the provider responsible for their actions.
- A transition plan, with any required downtime scheduled at a time you choose.
- Documentation of the provider’s financial health and any past legal issues.
A provider who has these ready has been asked before. One who stalls on the subcontractor question has told you something too, just not in words. Score the answers the way you’d score anything else, and our MSP scorecard has a weighting you can borrow.
Sign, negotiate or walk away?
Every finding lands in 1 of 3 piles. Here’s how I’d sort them.
| What you found | The call | Why |
|---|---|---|
| Exclusions list attached, obligations numbered, breach notice in hours | Sign | The boundaries are written down, which is what prevents most disputes before they start |
| Claims deadline under 2 years | Negotiate | It’s void in Texas anyway, so removing it costs the provider nothing |
| Breach notice promised promptly | Negotiate | Your 30 and 60 day clocks need a number |
| Tax treatment missing from the order form | Negotiate | A single line now beats a surprise on the first invoice |
| Liability capped at 12 months of fees | Usually accept | It’s standard, and your negotiating capital is better spent elsewhere |
| No precedence clause, and the provider won’t add one | Walk | Conflicts get settled by argument |
| Provider won’t list your obligations or its subcontractors | Walk | You can’t manage risk you can’t see |
Notice what isn’t in the walk pile. A long term. A liability cap. A minimum standards page. Ordinary paper. Those are normal, and treating them as red flags just burns goodwill you’ll want later, goodwill that matters far more in month 14 of the relationship than it does on signature day. I’d rather you spend your negotiating capital on the 3 or 4 items that change your actual risk than fight every paragraph and start the relationship tired. Pricing structure is its own conversation, and MSP pricing models explained covers which ones are fair.
How Uprite’s agreements handle this
You should know how our own paper reads, since I’m the one who has to deliver on it. Fair warning. Our scope comes with an exclusions list attached rather than referenced. Onboarding is quoted as a fixed figure before signature. After the initial term, the agreement continues month to month. Documentation, credentials and configuration exports belong to the client and go back on request at no charge, whether the parting is friendly or not. Every engagement carries a 120 day satisfaction guarantee. Our help desk averages under 5 minutes to first response against a sub-10-minute triage SLA, and we’ve supported Texas businesses since 1999 with a team of 42.
We’re not the right call for everyone, though. Say so plainly. A 5 person office with a single cloud app and no compliance duties may not need a contract this heavy, and a simpler arrangement built around fewer moving parts could serve it just as well without the overhead nobody there would ever use. If your business is past that point, see what our managed IT services include before you compare agreements.
Questions Texas buyers bring us about MSP agreements
What should an MSP contract include?
A complete MSP contract includes a master agreement, a scope with exclusions, an SLA with defined terms, pricing, security and breach duties, client responsibilities and exit terms. If any of those 7 is missing, ask where it lives before you sign. Missing usually means undefined, and undefined gets decided later by whoever has more bargaining power that day.
Do I need a lawyer to review a managed services agreement?
For about 4 pages, yes. Have an attorney read liability, indemnity, governing law and the claims deadline. The service schedule and SLA are operational documents, and you or your operations lead will catch more there than outside counsel will. CISA’s customer guidance recommends a legal review of MSP contracts as well.
Is a managed IT contract taxable in Texas?
Partly, and the taxable share depends on what’s in the bundle. Texas taxes data processing services, which the Comptroller says include data storage, offsite backup and hosted software, and 20% of that charge is exempt. Ask the provider which line items it treats as taxable and whether the quote includes tax. Then have your CPA confirm it.
Can an MSP contract limit how long I have to sue in Texas?
Only down to 2 years. Under Section 16.070 of the Civil Practice and Remedies Code, a contract term setting a shorter deadline is void in Texas. A 1 year claims clause is common in vendor paper, so check whether another state’s law governs the agreement, because that can change the answer entirely.
What’s the difference between an MSA and an SLA?
The MSA holds the legal terms and the SLA holds the performance promises. One covers liability, renewal and governing law. The other covers response targets, severity levels and credits. When they conflict, the order of precedence clause decides which one controls, so find that sentence early rather than assuming.
Does the proposal count as part of the contract?
Usually not, and that surprises people every time. Most agreements carry an entire agreement clause saying the signed documents are the whole deal. Anything promised in a proposal, an email or a sales call has to be written into a schedule or exhibit before signature, or it isn’t enforceable later, however clearly it was said.
Get a second read before you sign
Got a managed services agreement on your desk? Send it over. My team will read the service schedule, the SLA and the client responsibilities page the way we’d read our own, then tell you what we’d push back on. No charge, and no obligation to move.
Speak to an IT Expert








