What Should Be Included in an IT AMC Contract: A 2026 Checklist
Most SME IT AMC contracts were written for on-premise servers, not the cloud-connected, security-exposed environment businesses run today. Here's what a 2026-ready AMC should actually cover.
// Contents+
- Why the Standard IT AMC Contract of a Few Years Ago No Longer Cuts It
- The Core Coverage Every AMC Should Still Include
- The New Must-Haves: Cloud, Cybersecurity, and Monitoring
- Where SME Contracts Usually Have Gaps — and How Disputes Happen
- The 2026 IT AMC Checklist at a Glance
- How Al Aida IT Structures AMC Contracts to Close These Gaps
A 2026-ready IT AMC contract should explicitly name coverage for cloud and Microsoft 365 management, cybersecurity services (endpoint protection, email filtering, incident response), and proactive AI-assisted monitoring — not just on-premise hardware and a helpdesk number. If any of these aren't written into the scope-of-service schedule, they should be assumed excluded, which is exactly where most SME coverage disputes originate.
- 01Legacy AMC contracts scoped for on-premise hardware often exclude cloud, Microsoft 365, and cybersecurity coverage entirely unless these are named as explicit line items.
- 02Response times and escalation paths should be documented as a tiered, SLA-backed structure with a named asset schedule — vague phrases like 'IT infrastructure' are where coverage disputes originate.
- 03Proactive monitoring, backup/disaster recovery terms, third-party vendor coordination, and mid-contract scalability for new sites or users are frequent gap areas SMEs overlook until an incident occurs.
- 04Al Aida IT scopes every AMC against the client's actual environment — including Microsoft 365/Azure management as a Microsoft CSP, cybersecurity, and documented backup terms — rather than offering a generic hardware-support package.
Want this handled for you instead of DIY?
Why the Standard IT AMC Contract of a Few Years Ago No Longer Cuts It
For most SMEs in construction, engineering, and industrial sectors across the UAE, the IT Annual Maintenance Contract (AMC) used to be a simple document: a list of covered hardware, a helpdesk number, and a promise that someone would show up when a printer or server failed. That model made sense when 'IT' meant a server room, a few desktops, and a local network.
It doesn't describe how these businesses actually operate anymore. Project teams work from site offices and client locations using Microsoft 365 and cloud-hosted project files. Finance and procurement systems increasingly sit on cloud platforms rather than an on-premise server. And the threat landscape has shifted from occasional virus infections to organized ransomware and phishing campaigns that specifically target mid-sized firms because they are seen as easier targets than large enterprises with dedicated security teams.
The result is a mismatch: many SMEs are still signing (or renewing) AMC contracts written for 2018-era infrastructure, while their actual environment is hybrid, cloud-connected, and exposed to risks that older contracts never anticipated. This gap doesn't show up on paper — it shows up during an incident, when a business discovers that cloud outages, email compromise, or a ransomware event fall outside what their AMC provider is contractually obligated to handle.
A 2026-ready AMC contract has to be renegotiated with this reality in mind. That means going through the contract line by line and asking not 'what did we cover last year' but 'what does our business actually run on today, and is every part of it named in this agreement.'
The Core Coverage Every AMC Should Still Include
Before adding newer elements, it's worth confirming the fundamentals are properly specified, because vague wording on basics is where many disputes still originate.
A properly scoped AMC should name, in writing, the exact assets covered — not 'IT infrastructure' as a blanket phrase, but a schedule listing servers, workstations, network switches, firewalls, printers, and any specialized site equipment such as project management workstations or CAD/BIM machines used by engineering and construction teams. Anything not on that list is, by default, outside scope, and that ambiguity is exactly what causes arguments when equipment fails.
The contract should also define how support is delivered: remote helpdesk access, on-site visits, and the circumstances that trigger each. For firms with active construction sites or industrial facilities, on-site response terms matter more than for a typical office — site connectivity issues, on-site server rooms, or CCTV and access-control systems often need physical attendance rather than remote fixes.
Finally, every AMC should state its response-time framework in qualitative, tiered terms — critical outages handled with priority over routine requests — backed by a defined SLA structure, along with an escalation path naming who to contact if first-line support doesn't resolve an issue. The specific figures attached to each tier should be documented in the SLA schedule your provider issues, not left as a verbal assurance.
The New Must-Haves: Cloud, Cybersecurity, and Monitoring
This is where most older AMC contracts fall short, and where the 2026 checklist needs the most attention.
Cloud and Microsoft 365 support should be an explicit line item, not an assumption. If your business runs Exchange Online, SharePoint, Teams, or Azure workloads, the contract needs to state clearly whether your AMC provider manages licensing, tenant configuration, identity and access management, and troubleshooting for these services — or whether it only covers on-premise hardware while your cloud environment is left to whoever set it up originally (often nobody, on an ongoing basis).
Cybersecurity coverage needs the same treatment. A modern AMC should specify what security services are actually included: endpoint protection and patch management, email security and anti-phishing filtering, firewall management, and a defined process for incident response if a breach or ransomware event occurs. Many legacy contracts only cover antivirus software updates — a fraction of what a genuine security posture requires today. If cybersecurity monitoring, threat detection, and incident response aren't named separately in the contract, assume they aren't included.
Proactive and AI-assisted monitoring is the third pillar. Rather than waiting for a user to report a failed backup or a server running out of disk space, modern remote monitoring and management (RMM) tools flag anomalies — unusual login patterns, failing hardware, storage thresholds — before they become outages. The contract should state whether this kind of continuous, automated monitoring is part of the service, what it covers (servers, endpoints, network devices, cloud tenants), and how alerts are triaged and acted on, not just logged.
Backup and disaster recovery terms also belong in this section rather than being treated as an afterthought. The contract should specify what is backed up, how frequently, where backups are stored, and what the recovery process looks like — details that determine whether a ransomware incident is a manageable event or a business-ending one.
Where SME Contracts Usually Have Gaps — and How Disputes Happen
The most common source of conflict between SMEs and their IT providers isn't poor service — it's mismatched expectations that were never resolved at contract signing. A business assumes 'IT support' means everything technology-related; the contract, read literally, covers a narrower list.
Typical gap areas worth checking explicitly: coverage for remote and hybrid workers using personal or company devices outside the office; support for line-of-business or industry-specific software (ERP, project management, or engineering design tools) versus only generic office software; responsibility boundaries when a third-party vendor (an ISP, a software vendor, or a cloud platform) is the actual source of an issue; and whether after-hours or emergency support during weekends and public holidays is included or billed separately.
Another frequent gap is scalability. Construction and engineering firms often have project-based headcount swings — a new site brings on temporary staff and equipment, then scales down. If the AMC contract doesn't address how new users, devices, or locations are added or removed mid-term, businesses either overpay for unused capacity or discover new sites simply aren't covered at all.
The fix isn't complicated, but it does require discipline: before signing or renewing, walk through every system the business actually depends on — cloud platforms, on-site servers, security tools, industry software, remote access — and confirm each one is named in the contract's scope-of-service schedule, not assumed to be covered by a general phrase like 'IT support services.'
The 2026 IT AMC Checklist at a Glance
This table isn't exhaustive for every industry, but it's a practical starting point for reviewing an existing AMC or evaluating a new proposal. If a provider can't answer clearly on any row, that's the row to negotiate before signing.
| Coverage Area | What to Confirm Is in Writing |
|---|---|
| Asset schedule | Every server, workstation, network device, and site-specific equipment listed by name |
| Helpdesk & on-site support | Channels available, on-site visit triggers, and coverage for site offices or remote locations |
| Response & escalation | Tiered priority handling backed by a defined SLA, plus a named escalation path |
| Microsoft 365 / cloud | Tenant management, licensing, identity/access administration, and cloud troubleshooting |
| Cybersecurity | Endpoint protection, email/phishing filtering, firewall management, and incident response process |
| Proactive monitoring | Continuous monitoring of servers, endpoints, network, and cloud tenants, with defined alert handling |
| Backup & disaster recovery | What's backed up, frequency, storage location, and recovery process |
| Third-party coordination | Who liaises with ISPs, software vendors, or cloud providers when they're the root cause |
| Scalability | Process for adding/removing users, devices, or sites mid-contract |
| Reporting | Regular reporting on tickets, patching status, security posture, and monitored assets |
How Al Aida IT Structures AMC Contracts to Close These Gaps
Al Aida IT builds its AMC contracts around this exact checklist, because we've seen firsthand what happens when SMEs in the UAE discover coverage gaps mid-incident rather than at contract review. Rather than offering a generic hardware-support package, we scope each AMC against the client's actual environment: on-premise infrastructure, Microsoft 365 and Azure workloads, line-of-business applications, and site-specific needs for construction, engineering, and industrial clients with multiple locations or project sites.
As a Microsoft CSP, we include cloud and Microsoft 365 management as a core part of our AMC offering — not a bolt-on — covering tenant administration, licensing, identity and access management, and day-to-day troubleshooting for the Microsoft stack our clients already depend on. Cybersecurity is scoped the same way: endpoint protection, email security, firewall management, and an incident response process are written into the contract, along with continuous monitoring of servers, endpoints, and cloud tenants so issues are flagged and triaged before they escalate into downtime.
Every Al Aida IT AMC includes a defined, SLA-backed response and escalation structure and a documented asset schedule agreed with the client before the contract is signed, so there's no ambiguity about what's covered when a system goes down. Backup and disaster recovery terms — what's protected, how often, and how recovery works — are spelled out rather than assumed.
If your current AMC hasn't been reviewed since before your business moved workloads to the cloud or expanded its site footprint, that's a strong signal it's due for a rewrite. Al Aida IT will walk through your existing contract against a checklist like the one above, identify the gaps, and put together an AMC scoped to how your business actually runs in 2026 — not how it ran when the contract was first signed.
Frequently asked questions
Does a standard IT AMC contract automatically include cybersecurity services?+
No. Most legacy AMC contracts only cover antivirus software updates, not full cybersecurity services. Endpoint protection, email/phishing filtering, firewall management, and incident response need to be listed as explicit line items — if they're not named in the contract, they should not be assumed to be included.
Should Microsoft 365 and cloud support be part of our IT AMC, or a separate agreement?+
It can be structured either way, but it must be explicit. If your business runs on Microsoft 365 or Azure, confirm in writing whether your AMC provider manages tenant configuration, licensing, identity/access administration, and cloud troubleshooting, or whether the AMC only covers on-premise hardware, leaving cloud management as a gap.
What's the most common reason SMEs end up in disputes with their IT AMC provider?+
Mismatched expectations around scope. A business assumes 'IT support' covers everything technology-related, while the contract, read literally, only covers a specific asset list. The fix is confirming every system the business depends on — cloud platforms, industry software, remote access, security tools — is named explicitly in the contract's scope-of-service schedule.
How does Al Aida IT handle backup and disaster recovery within its AMC contracts?+
Al Aida IT documents backup and disaster recovery terms directly in the AMC — what data and systems are backed up, how frequently, where backups are stored, and the recovery process — so clients know exactly what protection they have before an incident occurs, rather than discovering the terms during a crisis.
More from our knowledge base
Need help applying this to your business?
Our Dubai-based engineers can audit your setup and recommend the right next steps.
