What Is a Server Maintenance Agreement? Scope and Contract Checklist
In short: A server maintenance agreement is a service contract that sets out who maintains your servers' hardware, firmware, operating system, patches and backups, how often and on what terms. It complements the manufacturer's warranty rather than replacing it. With Windows Server support dates changing phase in October 2026, now is the time to pin down scope and responsibilities.
What is a server maintenance agreement and what problem does it solve?
A server maintenance agreement is a contract under which a provider maintains specific servers on a schedule for a set period, defines how it responds to failures and reports on its work. The aim is to cut risk through scheduled work and to know in advance who does what when something breaks.
A server maintenance contract is not a warranty. A warranty or vendor support plan fixes faults in the product itself, under the plan's terms; a maintenance agreement covers the processes around the server, such as patching, firmware, backup checks and monitoring. Break-fix service only starts when something fails.
| Criterion | Warranty or vendor support plan | Server maintenance agreement | Break-fix service |
|---|---|---|---|
| Main focus | Repair or replacement of faulty hardware (per plan terms) | Preventive maintenance, patching, monitoring, reporting, incident coordination | Only the failure at hand |
| Patching and configuration | Depends on the plan; check the contract | Included as far as written into scope | Each request is a separate job |
| When does it fall short? | When patching, backup and configuration are not in the plan | When the scope list is vague | When a critical server fails often or for long |
The models are usually combined; trouble starts when the gaps between them belong to nobody.
Why is server maintenance back on the agenda in October 2026?
Because several Windows Server versions change lifecycle phase at about the same time. According to Microsoft Learn lifecycle pages and endoflife.date data (accessed 7 October 2026):
| Version | Last day of mainstream support | Last day of extended support | Note |
|---|---|---|---|
| Windows Server 2012 / 2012 R2 | 9 October 2018 | 10 October 2023 | Last day of the final ESU year: 13 October 2026 |
| Windows Server 2016 | 11 January 2022 | 12 January 2027 | In its final support phase |
| Windows Server 2019 | 9 January 2024 | 9 January 2029 | In extended support |
| Windows Server 2022 | 13 October 2026 | 14 October 2031 | Moves to extended support |
| Windows Server 2025 | 13 November 2029 | 14 November 2034 | In mainstream support |
Microsoft gives end times as the next morning, Pacific Time (e.g. "1/13/2027 6:59:59 AM PT" for Windows Server 2016); the table shows the last full day. See also the Windows Server 2022 and Windows Server 2012 R2 pages.
Microsoft's Fixed Lifecycle Policy defines the phases: mainstream support brings security and non-security updates; extended support brings security updates only; after end of support, security updates come only through an ESU program where one is offered, which Microsoft's ESU FAQ calls "a last resort paid option".
So a business on Windows Server 2022 keeps getting security updates after 13 October 2026 but can no longer request non-security fixes, while for Windows Server 2012/2012 R2 the end of ESU means the end of regular security updates. For Windows Server 2016, our Windows Server 2016 end-of-support migration plan covers the options.
CISA's Known Exploited Vulnerabilities (KEV) catalog shows the cost of delay. By our count, the catalog (version 2026.10.04) holds 43 entries added since 1 January 2025 with Microsoft as vendor and "Windows" in the product field (client and server combined). These flaws are known to be exploited in the wild; on a server without updates they can only be mitigated, not patched.
What should a server maintenance agreement cover?
A good server maintenance agreement lists every layer from hardware to backup and answers "who, how often, with what evidence" for each. Inclusions are set in the contract; this scope map is a starting point.
| Layer | Typical tasks | Question to settle in the contract |
|---|---|---|
| Hardware | Disk and RAID status, power supply, fan and temperature alerts; event logs from iDRAC (Dell's remote access controller) or iLO (HPE Integrated Lights-Out) | Who supplies a failed part, and through which channel? |
| Firmware and BIOS | Tracking BIOS, BMC (iDRAC/iLO), RAID controller and network card firmware versions | How often, with whose approval and with what rollback plan are updates applied? |
| Operating system | Security updates, service and event log checks, disk usage | In which window and after which test step are patches applied? |
| Virtualisation | Hypervisor updates, cleanup of old snapshots, resource usage | How are virtual machines moved or stopped during host maintenance? |
| Backup | Checking backup job results, regular restore tests | Who runs the restore test and how is it documented? |
| Security | Endpoint protection (antivirus/EDR), local admin accounts, remote access logs | How is privileged access granted and logged? |
| Documentation and lifecycle | Inventory, warranty and OS end-of-support dates, capacity trends | How far ahead are end-of-support dates flagged? |
Firmware is often the most neglected layer, yet NIST SP 800-193 notes that a successful attack on platform firmware could leave a system inoperable, perhaps permanently. For update order and BMC network isolation, see our server firmware, BIOS and iDRAC/iLO update guide.
Brand and model shape the hardware scope, since tools, firmware and parts channels differ by manufacturer. Browse the Dell PowerEdge server range and the HPE ProLiant server family, for which Sora Yazılım provides selection, procurement and installation. The firewall at the network edge is a separate discipline, covered by our firewall maintenance and management service.
How do manufacturer support, the provider and in-house IT split the work?
The manufacturer covers product and parts, the provider runs the process, and in-house IT owns priorities and approvals. If this is not written down, each party waits for the others during an outage; attach a table like this to the contract.
| Task | Manufacturer (warranty or plan) | Maintenance provider | In-house IT or business |
|---|---|---|---|
| Replacing a failed part | Supplies the part if covered | Diagnoses, opens and follows the vendor case | Approves access and downtime |
| Firmware and driver updates | Publishes them with release notes | Assesses fit, applies in the window | Approves the window |
| Operating system patches | OS vendor (e.g. Microsoft) publishes them | Tests, applies, reports | Joins testing of critical applications |
| Backup and restore testing | No role | Runs and reports the test | Confirms restored data is correct |
| Lifecycle planning | Publishes end-of-support dates | Tracks dates, prepares migration options | Decides budget and timing |
This split is an example; yours is set in the contract. After warranty, parts and firmware access need re-planning; our comparison of post-warranty server support from the manufacturer or a third party covers the options.
How do you build a preventive maintenance calendar?
A preventive maintenance calendar spreads tasks across weekly, monthly, quarterly and yearly cycles. In NIST SP 800-40 Rev. 4's example, on-premises servers are patched in scheduled outage windows except in emergencies. Below is our suggested template; adapt it to your risk assessment.
| Frequency | Hardware and firmware | OS and applications | Backup and security | Records |
|---|---|---|---|---|
| Weekly | iDRAC/iLO alerts, disk and RAID status | Critical services, event log errors | Backup job success | Opened and closed tickets |
| Monthly | Temperature, fan and power supply trends | Assessing security updates and applying them in the window | Endpoint protection status, admin accounts | Monthly report |
| Quarterly | Firmware, BIOS and BMC versions compared with current vendor releases | Disk usage and capacity trend | Restore test on a sample server | Risk register update |
| Yearly | Warranty end dates, physical cleaning and cabling | OS support dates and upgrade plan | Disaster recovery exercise, access review | Scope and inventory re-approval |
The report is the proof: maintenance without "done, result, next date" is invisible in an audit. Testing that backups really restore is also a core ransomware defence; see our ransomware protection guide for SMBs. Without a backup platform, a solution such as Acronis Cyber Backup can be added to scope.
How should the contract define patching and emergencies?
The contract should define a path for each of the four risk response scenarios in NIST SP 800-40 Rev. 4, so an actively exploited flaw does not wait for the monthly cycle.
- Routine patching: Updates go first to a small group of servers ("canary" assets, in NIST's words), then roll out in the maintenance window if no problems appear. Write down the window, test group and deployment time.
- Emergency patching: For a severe or actively exploited flaw, the same approach runs on a much faster schedule. Define who declares an emergency and how out-of-window work is approved.
- Emergency mitigation: If no patch exists or it causes problems, a temporary measure applies, such as disabling a service or isolating the server. NIST recommends scheduling its replacement with a permanent fix.
- Unpatchable assets: Out-of-support servers, or those that must run without interruption, get long-term measures such as isolation, reassessed regularly. Windows Server 2012/2012 R2 servers whose ESU ends on 13 October 2026 belong here.
Türkiye has no single general patching timeframe, but the UK National Cyber Security Centre's Cyber Essentials requirements are a useful reference. Version 3.3 (April 2026), which also covers servers, requires software to be licensed and supported, and updates fixing "critical" or "high risk" vulnerabilities (CVSS v3 base score 7 or above) to be applied within 14 days of release. It is a UK rule, not binding in Türkiye, but a good yardstick.
What should you check before signing a server maintenance contract?
Read each clause asking "is it measurable, who owns it, how is it proven?" Use this checklist when comparing quotes; times and frequencies are set per environment.
- Device list: Is every server's model, serial number or service tag and location in an annex?
- Layer boundaries: Which of hardware, firmware, OS, virtualisation and backup are included; are applications in scope?
- Priority levels: Are "critical", "high" and "normal" incidents defined, with numeric first-response and resolution targets?
- Support hours: Are support days and hours, and out-of-hours terms, clear?
- Spare parts: Who supplies parts (warranty, provider or you); are genuine-part rules and lead times defined?
- Failed disks: How are failed disks containing data returned or destroyed?
- On-site support: Which locations are covered, and when is on-site work done?
- Patch policy: Are paths and windows defined for routine, emergency, mitigation and unpatchable scenarios?
- Firmware: Are frequency, approval and rollback for BIOS, BMC and controller updates written down?
- Backup: Are the owner, frequency and reporting of backup monitoring and restore tests clear?
- Access and security: Are remote access method, multi-factor authentication, named accounts and access logs defined?
- Personal data: If servers hold personal data, are confidentiality, processing and breach notification clauses included?
- Reporting and lifecycle: Are report contents and notice periods for warranty and support end dates defined?
- Exit terms: Are documents, configurations and admin credentials handed over in full at the end; are renewal and termination terms clear?
For businesses in Türkiye, the personal data clause deserves attention. The Personal Data Protection Authority (KVKK) states on its data security obligations page that a data controller is jointly responsible with those processing data on its behalf for the necessary measures, and that processors must take measures too. Review your provider's position with your legal adviser; our KVKK technical measures checklist covers the technical side.
Want to apply this checklist to your own server inventory and define the scope together? Write to us. Get a Quote
Which maintenance approach suits which server?
The right approach depends on business importance, support status and recoverability.
| Situation | Priority approach | Clause to emphasise |
|---|---|---|
| Under warranty, OS supported (e.g. Windows Server 2022 or 2025) | Preventive calendar and routine patching | Maintenance window, reporting |
| Warranty expired, OS supported | Re-planning parts and firmware access | Spare-part source, firmware access |
| OS out of support or leaving within 12 months (e.g. Windows Server 2012/2012 R2 or 2016) | Migration plan and interim isolation | Unpatchable-asset scenario, migration timeline |
| Single business-critical server without backup | Backup, restore testing, standby hardware plan | Restore testing, critical priority definition |
| Host running many virtual machines | Hypervisor and firmware compatibility, coordinated window | VM migration and downtime approval |
Where to start? A three-criterion priority score
Score each server from 1 to 3 on three criteria, add them up and start with the highest total:
- Business impact: 1 = an outage affects a few people; 2 = it stops a department; 3 = it stops sales, production or customer service.
- Support status: 1 = OS and hardware supported; 2 = one leaves support within 12 months; 3 = one is already unsupported.
- Recoverability: 1 = backup exists and a restore was tested; 2 = backup exists but untested; 3 = no current backup.
The highest totals form the first maintenance and migration wave; on a tie, higher business impact goes first. The score aids prioritisation but does not replace a risk assessment.
How do you plan a server maintenance agreement with Sora Yazılım?
Sora Yazılım is a Türkiye-based technology company that offers server maintenance agreements and provides selection, procurement, installation and support for Dell and HPE servers. Response times, on-site support, spare parts and reporting are set in the contract per customer inventory, so this article promises no ready-made package. Learn more on our About us page.
To make the quote discussion productive, prepare:
- Server list: brand, model, serial or service tag, location.
- OS version and critical applications per server.
- Warranty or support plan end dates.
- Backup solution and last restore test date.
- Acceptable maintenance windows and required support hours.
- Servers holding personal data and access restrictions.
FAQ
Is a server maintenance agreement the same as a warranty?
No. A warranty or vendor support plan fixes faults in the product itself under the plan's terms. A server maintenance agreement covers patching, firmware tracking, backup checks, monitoring, reporting and incident coordination. Neither replaces the other: a server under warranty still needs maintenance, and after the warranty ends spare parts must be planned separately.
How is response time set in a server maintenance contract?
It depends on the incident's priority and the server's importance, and it should appear in the contract as a number. Define "critical", "high" and "normal" incidents first, then set first-response and resolution targets for each and state how they are measured. The right figure depends on your cost of downtime.
We run Windows Server 2022. What changes after 13 October 2026?
According to Microsoft's lifecycle page, Windows Server 2022 mainstream support ends on 13 October 2026 and extended support runs until 14 October 2031. Under the Fixed Lifecycle Policy, security updates continue in this phase, while non-security updates and design change requests end. Update your plan accordingly.
We still have Windows Server 2012 R2. Is a maintenance agreement enough?
A maintenance agreement helps manage risk, but it cannot make an unsupported operating system safe. The last day of ESU for Windows Server 2012/2012 R2 is 13 October 2026; after that, no security updates are released. In NIST's terms it is an unpatchable asset: isolate it, restrict access and put the migration timeline in the contract.
Should firmware and BIOS updates be part of the agreement?
Yes, we recommend it, because flaws in firmware and the BMC (iDRAC/iLO) are not fixed by operating system patches. The contract should state frequency, approval method, maintenance window and rollback plan. NIST SP 800-40 Rev. 4 also lists firmware among software to patch on on-premises servers. For steps, see our firmware update guide.
What determines the cost of a server maintenance agreement?
The main factors are the number and age of servers, layers in scope, support hours, on-site needs and number of locations, who handles spare parts, and how often reports and exercises are required. A figure can only be calculated once inventory and scope are clear; send your server list via our quote form.
Conclusion
- A server maintenance agreement complements the warranty by putting preventive maintenance and incident coordination in writing.
- Windows Server 2022 mainstream support and 2012/2012 R2 ESU both end on 13 October 2026; Windows Server 2016 extended support ends on 12 January 2027.
- The contract should spell out NIST's four patching scenarios, firmware maintenance, restore testing and numeric response terms.
Sora Yazılım defines the scope of your server maintenance agreement with you, based on your inventory and priorities; for Dell and HPE servers, selection, procurement, installation and maintenance can come from one company.
Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com
Sources
- Windows Server 2016 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
- Windows Server 2022 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
- Windows Server 2012 R2, including ESU years — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
- Windows Server 2019 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
- Windows Server 2025 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
- Fixed Lifecycle Policy — Microsoft Learn. learn.microsoft.com (accessed 7 October 2026)
- Lifecycle FAQ – Extended Security Updates — Microsoft Learn. learn.microsoft.com (accessed 7 October 2026)
- Windows Server release data — endoflife.date. endoflife.date (accessed 7 October 2026)
- NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology — NIST, April 2022. csrc.nist.gov (accessed 7 October 2026)
- NIST SP 800-193, Platform Firmware Resiliency Guidelines — NIST, May 2018. csrc.nist.gov (accessed 7 October 2026)
- Cyber Essentials: Requirements for IT Infrastructure v3.3 — NCSC (UK), April 2026. ncsc.gov.uk (accessed 7 October 2026)
- Veri Güvenliğine İlişkin Yükümlülükler (Data security obligations) — Personal Data Protection Authority (KVKK), Türkiye. kvkk.gov.tr (accessed 7 October 2026)
- Known Exploited Vulnerabilities Catalog, version 2026.10.04 — CISA (GitHub data repository). raw.githubusercontent.com (accessed 7 October 2026)
How this article was prepared
Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical information was checked against the manufacturer and official sources linked in the text as of 7 October 2026.
Related articles
- Windows Server 2016 end-of-support migration plan — Options before 12 January 2027.
- Post-warranty server support: manufacturer or third party? — Support models after warranty.
- Server firmware, BIOS and iDRAC/iLO update guide — Order, window and rollback steps.
- Rack or tower? Choosing a server form factor — For new server purchases.
