A service level agreement (SLA) is the part of a service contract that turns “we’ll keep it running” into numbers: how available the service will be, how fast the provider responds when something breaks, how that’s measured, and what the customer gets back when targets are missed. IT providers, hosting and software companies, managed service providers and outsourced support desks all sign them. This free SLA template is written to attach to a main services contract.
What does an SLA actually commit a provider to?
It commits the provider to measurable targets, not to perfection. NIST’s glossary, quoting its interconnection guidance, describes an SLA as a commitment between a service provider and one or more customers covering specific aspects of the service, such as responsibilities, the expected performance level (reliability, acceptable quality, response times), and requirements for reporting, resolution and termination. That’s a good checklist for what yours should include.
The key word is measurable. “Fast support” can’t be enforced. “First response to a Severity 1 ticket within 30 minutes, 24/7” can.
Where does an SLA fit with your other contracts?
An SLA usually lives inside something bigger. The main agreement handles price, confidentiality, ownership, liability and termination, and the SLA handles performance. If you work with a client on repeat projects, put the SLA under a master service agreement. For a one-off job, a service agreement may be all you need, since there’s no ongoing service to measure. If your concern is protecting information the provider sees rather than uptime, an NDA is the document you want.
What should a service level agreement include?
Service description and hours
What’s covered, what isn’t, and when the clock runs. A customer-facing web app might be 24/7. A payroll help desk might be weekdays 8 to 6 Eastern. Be explicit about time zones.
Availability target and how it’s calculated
The uptime percentage and the formula. Our template measures availability monthly: total minutes in the month, minus excluded downtime, minus unplanned outage minutes, divided by total minutes minus excluded downtime. Pick a target you can actually hit. For a sense of scale, 99.9% allows about 43 minutes of downtime in a 30-day month; 99.5% allows about 3.6 hours.
Measurement
Who measures, with what, and how disputes about the numbers get resolved. Usually the provider’s monitoring counts, with the customer allowed to submit its own evidence. Define “unavailable” tightly, for example “the login page or API returns errors or doesn’t respond for five consecutive one-minute checks from two regions.”
Support severity levels and response times
A table of severity levels with a definition, a response target and an update frequency for each. Response time is not fix time. Most small providers can commit to responding quickly; far fewer can promise a fix within a set time, so the template separates the two.
Service credits
What the customer gets when availability falls short, usually a percentage of that month’s fee on a sliding scale, capped at some share of the monthly fee. The template requires the customer to claim credits within a set window and treats them as a price adjustment, not a penalty.
Exclusions
Downtime that doesn’t count: scheduled maintenance with notice, the customer’s own systems or misuse, third-party internet outages, force majeure events, and suspension for non-payment. Keep the list honest. An SLA with more exclusions than commitments isn’t worth signing.
Reporting and chronic failure
A monthly report, plus a way out: if the provider misses the target in, say, three months out of any six, the customer can terminate without penalty.
How would this work in practice?
Suppose a managed IT provider supports a 40-person accounting firm for $3,200 a month, with a 99.9% availability target for the firm’s hosted file server. In February, a failed storage update takes the server down for 95 minutes on a Tuesday afternoon. February has 28 days, or 40,320 minutes, so availability comes out at about 99.76%. Under the credit table in our template, that falls in the “below 99.9% but at least 99.5%” band, which earns a 10% credit, or $320 off March’s invoice, once the firm submits a claim. Nobody has to argue about what “reasonable uptime” means.
How do you fill it in and get it signed?
- Describe the service and the covered hours, including time zone.
- Set the availability target and credit bands that fit your price. Higher targets cost the provider more to meet.
- Write severity definitions that match real incidents you’ve seen, and set response targets your team can staff.
- List scheduled maintenance windows and notice periods.
- Attach the SLA to your main agreement and sign both together.
The federal ESIGN Act says a contract can’t be denied legal effect just because it’s in electronic form, so SLAs and their amendments can be e-signed like any other business contract. Our guide to getting a document signed by multiple people helps when both companies need more than one signer.
Download it, fill in the blanks, and send it for e-signature with any tool you like. (If you’d like to try SignWren when it launches, join the waitlist.)
This template and guide are general information, not legal advice. For a specific contract or dispute, talk to a lawyer licensed where you are.
Template from signwren.com. General information, not legal advice. Check your state's rules and adapt it before you use it.
SERVICE LEVEL AGREEMENT
This Service Level Agreement ("SLA") is made on [date] between:
Customer: [Customer's full legal name], of [address] ("Customer"), and
Provider: [Provider's full legal name], of [address] ("Provider").
This SLA forms part of the [name of main agreement, e.g. "Master Service Agreement"] between the parties dated [date] (the "Main Agreement"). If this SLA and the Main Agreement conflict about service levels or service credits, this SLA controls. On every other subject, the Main Agreement controls.
1. Covered Service
This SLA applies to the following service (the "Service"): [describe the service, e.g. "hosted accounting file server and remote backup," "customer-facing web application at [URL]," "IT help desk for Customer's staff"].
Not covered: [e.g. Customer-owned hardware, third-party software not supplied by Provider, or "Nothing else"].
Service hours: ☐ 24 hours a day, 7 days a week ☐ [days], [start time] to [end time] [time zone], excluding [holidays].
2. Definitions
Monthly Minutes means the total number of minutes in a calendar month.
Unavailable means [define precisely, e.g. "the Service returns errors or does not respond to Provider's monitoring checks from at least two locations for five or more consecutive minutes"].
Downtime means the total minutes in a month during which the Service is Unavailable, not counting Excluded Downtime.
Excluded Downtime means minutes of unavailability caused by the events listed in Section 7.
Incident means any event reported by Customer or detected by Provider that disrupts or degrades the Service.
3. Availability Target
Provider will make the Service available at least [99.9]% of the time in each calendar month (the "Availability Target").
Monthly availability is calculated as:
(Monthly Minutes minus Excluded Downtime minus Downtime) ÷ (Monthly Minutes minus Excluded Downtime) × 100
4. Measurement and Reporting
Provider will measure availability using [monitoring tool or method] checking the Service at least every [number] minute(s). Provider will send Customer a report within [number] business days after the end of each month showing monthly availability, each Incident, its cause and its duration.
If Customer disagrees with a report, it may give Provider its own evidence within [number] days, and the parties will review both sets of data in good faith.
5. Support and Response Times
Customer may report Incidents by [phone number, email, support portal]. Provider will respond and update Customer as follows:
| Severity |
Definition |
First response |
Updates |
Target resolution or workaround |
| 1: Critical |
Service Unavailable or a core function unusable for all users |
[30 minutes], [24/7] |
Every [1] hour |
[4 hours] |
| 2: High |
Core function seriously degraded, or unusable for some users, with no workaround |
[2 hours], service hours |
Every [4] hours |
[1 business day] |
| 3: Normal |
Non-core function affected, or a workaround exists |
[1 business day] |
As progress is made |
[5 business days] |
| 4: Low |
Questions, requests, cosmetic issues |
[2 business days] |
As agreed |
As scheduled |
Provider assigns the initial severity in good faith, based on Customer's description, and will change it if the facts change. Response time means a qualified person has acknowledged the Incident and started work. Resolution targets are goals Provider will use reasonable efforts to meet; missing them does not by itself earn service credits unless the table in Section 6 says otherwise.
6. Service Credits
If monthly availability falls below the Availability Target, Customer will receive a credit against the monthly fee for the Service for that month, as follows:
| Monthly availability |
Credit (% of that month's fee for the Service) |
| Below [99.9]% but at least [99.5]% |
[10]% |
| Below [99.5]% but at least [99.0]% |
[25]% |
| Below [99.0]% |
[50]% |
☐ In addition, if Provider misses the Severity 1 first response time more than [number] times in a month, Customer will receive a credit of [percentage]% of that month's fee.
Claiming credits. Customer must request a credit in writing within [30] days after receiving the monthly report. Provider will apply approved credits to the next invoice, or refund them if the Main Agreement has ended.
Cap. Total credits in any month will not exceed [50]% of that month's fee for the Service.
Nature of credits. Credits are a price adjustment reflecting the reduced value of the Service, not a penalty. Credits are Customer's sole monetary remedy for failing to meet the Availability Target, but they do not limit Customer's rights under Section 9 or any rights under the Main Agreement for other breaches.
7. Exclusions
The following are Excluded Downtime and do not count against the Availability Target:
- scheduled maintenance, if Provider gives at least [number] days' notice and it takes place within [maintenance window, e.g. "Sundays 1 a.m. to 5 a.m. Eastern"], up to [number] hours per month;
- emergency maintenance to fix a security vulnerability, if Provider notifies Customer as soon as practical;
- problems caused by Customer's equipment, software, network, or use of the Service against the Main Agreement or Provider's documented instructions;
- failures of the public internet or of third-party services that Provider does not control and did not select, [or list excluded third parties];
- events beyond Provider's reasonable control as described in the Main Agreement; and
- suspension of the Service under the Main Agreement for non-payment or misuse.
8. Customer Responsibilities
Customer will report Incidents promptly through the channels in Section 5, provide the information and access Provider reasonably needs to investigate, and keep its own contact list for Incident notices current.
9. Chronic Failure
If monthly availability falls below [99.5]% in any [three] months within a rolling [six]-month period, Customer may end the Main Agreement as it applies to the Service by written notice within [30] days after the third such month, without any early termination fee. Provider will refund any fees paid in advance for the period after termination.
10. Review and Changes
The parties will review this SLA at least ☐ every six months ☐ annually. Provider will not reduce any service level during the term. Any change to this SLA must be in writing and signed by both parties.
11. General Terms
Governing law. This SLA is governed by the laws of the State of [State], unless the Main Agreement chooses a different law, in which case that law applies.
Severability. If any part of this SLA is found invalid, the rest stays in effect.
Counterparts and electronic signatures. The parties agree this agreement may be signed electronically and in counterparts, and an electronic signature has the same effect as a handwritten one.
Signatures
Customer
Signature: ______________________________
Name: [full name]
Date: [date]
Provider
Signature: ______________________________
Name: [full name]
Date: [date]