Sora Yazılım
Network security, server and software solutions from Türkiye

What Is a Server Maintenance Agreement? Scope and Contract Checklist

In short: A server maintenance agreement is a service contract that sets out who maintains your servers' hardware, firmware, operating system, patches and backups, how often and on what terms. It complements the manufacturer's warranty rather than replacing it. With Windows Server support dates changing phase in October 2026, now is the time to pin down scope and responsibilities.

What is a server maintenance agreement and what problem does it solve?

A server maintenance agreement is a contract under which a provider maintains specific servers on a schedule for a set period, defines how it responds to failures and reports on its work. The aim is to cut risk through scheduled work and to know in advance who does what when something breaks.

A server maintenance contract is not a warranty. A warranty or vendor support plan fixes faults in the product itself, under the plan's terms; a maintenance agreement covers the processes around the server, such as patching, firmware, backup checks and monitoring. Break-fix service only starts when something fails.

CriterionWarranty or vendor support planServer maintenance agreementBreak-fix service
Main focusRepair or replacement of faulty hardware (per plan terms)Preventive maintenance, patching, monitoring, reporting, incident coordinationOnly the failure at hand
Patching and configurationDepends on the plan; check the contractIncluded as far as written into scopeEach request is a separate job
When does it fall short?When patching, backup and configuration are not in the planWhen the scope list is vagueWhen a critical server fails often or for long

The models are usually combined; trouble starts when the gaps between them belong to nobody.

Why is server maintenance back on the agenda in October 2026?

Because several Windows Server versions change lifecycle phase at about the same time. According to Microsoft Learn lifecycle pages and endoflife.date data (accessed 7 October 2026):

VersionLast day of mainstream supportLast day of extended supportNote
Windows Server 2012 / 2012 R29 October 201810 October 2023Last day of the final ESU year: 13 October 2026
Windows Server 201611 January 202212 January 2027In its final support phase
Windows Server 20199 January 20249 January 2029In extended support
Windows Server 202213 October 202614 October 2031Moves to extended support
Windows Server 202513 November 202914 November 2034In mainstream support

Microsoft gives end times as the next morning, Pacific Time (e.g. "1/13/2027 6:59:59 AM PT" for Windows Server 2016); the table shows the last full day. See also the Windows Server 2022 and Windows Server 2012 R2 pages.

Microsoft's Fixed Lifecycle Policy defines the phases: mainstream support brings security and non-security updates; extended support brings security updates only; after end of support, security updates come only through an ESU program where one is offered, which Microsoft's ESU FAQ calls "a last resort paid option".

So a business on Windows Server 2022 keeps getting security updates after 13 October 2026 but can no longer request non-security fixes, while for Windows Server 2012/2012 R2 the end of ESU means the end of regular security updates. For Windows Server 2016, our Windows Server 2016 end-of-support migration plan covers the options.

CISA's Known Exploited Vulnerabilities (KEV) catalog shows the cost of delay. By our count, the catalog (version 2026.10.04) holds 43 entries added since 1 January 2025 with Microsoft as vendor and "Windows" in the product field (client and server combined). These flaws are known to be exploited in the wild; on a server without updates they can only be mitigated, not patched.

What should a server maintenance agreement cover?

A good server maintenance agreement lists every layer from hardware to backup and answers "who, how often, with what evidence" for each. Inclusions are set in the contract; this scope map is a starting point.

LayerTypical tasksQuestion to settle in the contract
HardwareDisk and RAID status, power supply, fan and temperature alerts; event logs from iDRAC (Dell's remote access controller) or iLO (HPE Integrated Lights-Out)Who supplies a failed part, and through which channel?
Firmware and BIOSTracking BIOS, BMC (iDRAC/iLO), RAID controller and network card firmware versionsHow often, with whose approval and with what rollback plan are updates applied?
Operating systemSecurity updates, service and event log checks, disk usageIn which window and after which test step are patches applied?
VirtualisationHypervisor updates, cleanup of old snapshots, resource usageHow are virtual machines moved or stopped during host maintenance?
BackupChecking backup job results, regular restore testsWho runs the restore test and how is it documented?
SecurityEndpoint protection (antivirus/EDR), local admin accounts, remote access logsHow is privileged access granted and logged?
Documentation and lifecycleInventory, warranty and OS end-of-support dates, capacity trendsHow far ahead are end-of-support dates flagged?

Firmware is often the most neglected layer, yet NIST SP 800-193 notes that a successful attack on platform firmware could leave a system inoperable, perhaps permanently. For update order and BMC network isolation, see our server firmware, BIOS and iDRAC/iLO update guide.

Brand and model shape the hardware scope, since tools, firmware and parts channels differ by manufacturer. Browse the Dell PowerEdge server range and the HPE ProLiant server family, for which Sora Yazılım provides selection, procurement and installation. The firewall at the network edge is a separate discipline, covered by our firewall maintenance and management service.

How do manufacturer support, the provider and in-house IT split the work?

The manufacturer covers product and parts, the provider runs the process, and in-house IT owns priorities and approvals. If this is not written down, each party waits for the others during an outage; attach a table like this to the contract.

TaskManufacturer (warranty or plan)Maintenance providerIn-house IT or business
Replacing a failed partSupplies the part if coveredDiagnoses, opens and follows the vendor caseApproves access and downtime
Firmware and driver updatesPublishes them with release notesAssesses fit, applies in the windowApproves the window
Operating system patchesOS vendor (e.g. Microsoft) publishes themTests, applies, reportsJoins testing of critical applications
Backup and restore testingNo roleRuns and reports the testConfirms restored data is correct
Lifecycle planningPublishes end-of-support datesTracks dates, prepares migration optionsDecides budget and timing

This split is an example; yours is set in the contract. After warranty, parts and firmware access need re-planning; our comparison of post-warranty server support from the manufacturer or a third party covers the options.

How do you build a preventive maintenance calendar?

A preventive maintenance calendar spreads tasks across weekly, monthly, quarterly and yearly cycles. In NIST SP 800-40 Rev. 4's example, on-premises servers are patched in scheduled outage windows except in emergencies. Below is our suggested template; adapt it to your risk assessment.

FrequencyHardware and firmwareOS and applicationsBackup and securityRecords
WeeklyiDRAC/iLO alerts, disk and RAID statusCritical services, event log errorsBackup job successOpened and closed tickets
MonthlyTemperature, fan and power supply trendsAssessing security updates and applying them in the windowEndpoint protection status, admin accountsMonthly report
QuarterlyFirmware, BIOS and BMC versions compared with current vendor releasesDisk usage and capacity trendRestore test on a sample serverRisk register update
YearlyWarranty end dates, physical cleaning and cablingOS support dates and upgrade planDisaster recovery exercise, access reviewScope and inventory re-approval

The report is the proof: maintenance without "done, result, next date" is invisible in an audit. Testing that backups really restore is also a core ransomware defence; see our ransomware protection guide for SMBs. Without a backup platform, a solution such as Acronis Cyber Backup can be added to scope.

How should the contract define patching and emergencies?

The contract should define a path for each of the four risk response scenarios in NIST SP 800-40 Rev. 4, so an actively exploited flaw does not wait for the monthly cycle.

  1. Routine patching: Updates go first to a small group of servers ("canary" assets, in NIST's words), then roll out in the maintenance window if no problems appear. Write down the window, test group and deployment time.
  2. Emergency patching: For a severe or actively exploited flaw, the same approach runs on a much faster schedule. Define who declares an emergency and how out-of-window work is approved.
  3. Emergency mitigation: If no patch exists or it causes problems, a temporary measure applies, such as disabling a service or isolating the server. NIST recommends scheduling its replacement with a permanent fix.
  4. Unpatchable assets: Out-of-support servers, or those that must run without interruption, get long-term measures such as isolation, reassessed regularly. Windows Server 2012/2012 R2 servers whose ESU ends on 13 October 2026 belong here.

Türkiye has no single general patching timeframe, but the UK National Cyber Security Centre's Cyber Essentials requirements are a useful reference. Version 3.3 (April 2026), which also covers servers, requires software to be licensed and supported, and updates fixing "critical" or "high risk" vulnerabilities (CVSS v3 base score 7 or above) to be applied within 14 days of release. It is a UK rule, not binding in Türkiye, but a good yardstick.

What should you check before signing a server maintenance contract?

Read each clause asking "is it measurable, who owns it, how is it proven?" Use this checklist when comparing quotes; times and frequencies are set per environment.

  1. Device list: Is every server's model, serial number or service tag and location in an annex?
  2. Layer boundaries: Which of hardware, firmware, OS, virtualisation and backup are included; are applications in scope?
  3. Priority levels: Are "critical", "high" and "normal" incidents defined, with numeric first-response and resolution targets?
  4. Support hours: Are support days and hours, and out-of-hours terms, clear?
  5. Spare parts: Who supplies parts (warranty, provider or you); are genuine-part rules and lead times defined?
  6. Failed disks: How are failed disks containing data returned or destroyed?
  7. On-site support: Which locations are covered, and when is on-site work done?
  8. Patch policy: Are paths and windows defined for routine, emergency, mitigation and unpatchable scenarios?
  9. Firmware: Are frequency, approval and rollback for BIOS, BMC and controller updates written down?
  10. Backup: Are the owner, frequency and reporting of backup monitoring and restore tests clear?
  11. Access and security: Are remote access method, multi-factor authentication, named accounts and access logs defined?
  12. Personal data: If servers hold personal data, are confidentiality, processing and breach notification clauses included?
  13. Reporting and lifecycle: Are report contents and notice periods for warranty and support end dates defined?
  14. Exit terms: Are documents, configurations and admin credentials handed over in full at the end; are renewal and termination terms clear?

For businesses in Türkiye, the personal data clause deserves attention. The Personal Data Protection Authority (KVKK) states on its data security obligations page that a data controller is jointly responsible with those processing data on its behalf for the necessary measures, and that processors must take measures too. Review your provider's position with your legal adviser; our KVKK technical measures checklist covers the technical side.

Want to apply this checklist to your own server inventory and define the scope together? Write to us. Get a Quote

Which maintenance approach suits which server?

The right approach depends on business importance, support status and recoverability.

SituationPriority approachClause to emphasise
Under warranty, OS supported (e.g. Windows Server 2022 or 2025)Preventive calendar and routine patchingMaintenance window, reporting
Warranty expired, OS supportedRe-planning parts and firmware accessSpare-part source, firmware access
OS out of support or leaving within 12 months (e.g. Windows Server 2012/2012 R2 or 2016)Migration plan and interim isolationUnpatchable-asset scenario, migration timeline
Single business-critical server without backupBackup, restore testing, standby hardware planRestore testing, critical priority definition
Host running many virtual machinesHypervisor and firmware compatibility, coordinated windowVM migration and downtime approval

Where to start? A three-criterion priority score

Score each server from 1 to 3 on three criteria, add them up and start with the highest total:

  • Business impact: 1 = an outage affects a few people; 2 = it stops a department; 3 = it stops sales, production or customer service.
  • Support status: 1 = OS and hardware supported; 2 = one leaves support within 12 months; 3 = one is already unsupported.
  • Recoverability: 1 = backup exists and a restore was tested; 2 = backup exists but untested; 3 = no current backup.

The highest totals form the first maintenance and migration wave; on a tie, higher business impact goes first. The score aids prioritisation but does not replace a risk assessment.

How do you plan a server maintenance agreement with Sora Yazılım?

Sora Yazılım is a Türkiye-based technology company that offers server maintenance agreements and provides selection, procurement, installation and support for Dell and HPE servers. Response times, on-site support, spare parts and reporting are set in the contract per customer inventory, so this article promises no ready-made package. Learn more on our About us page.

To make the quote discussion productive, prepare:

  1. Server list: brand, model, serial or service tag, location.
  2. OS version and critical applications per server.
  3. Warranty or support plan end dates.
  4. Backup solution and last restore test date.
  5. Acceptable maintenance windows and required support hours.
  6. Servers holding personal data and access restrictions.

FAQ

Is a server maintenance agreement the same as a warranty?

No. A warranty or vendor support plan fixes faults in the product itself under the plan's terms. A server maintenance agreement covers patching, firmware tracking, backup checks, monitoring, reporting and incident coordination. Neither replaces the other: a server under warranty still needs maintenance, and after the warranty ends spare parts must be planned separately.

How is response time set in a server maintenance contract?

It depends on the incident's priority and the server's importance, and it should appear in the contract as a number. Define "critical", "high" and "normal" incidents first, then set first-response and resolution targets for each and state how they are measured. The right figure depends on your cost of downtime.

We run Windows Server 2022. What changes after 13 October 2026?

According to Microsoft's lifecycle page, Windows Server 2022 mainstream support ends on 13 October 2026 and extended support runs until 14 October 2031. Under the Fixed Lifecycle Policy, security updates continue in this phase, while non-security updates and design change requests end. Update your plan accordingly.

We still have Windows Server 2012 R2. Is a maintenance agreement enough?

A maintenance agreement helps manage risk, but it cannot make an unsupported operating system safe. The last day of ESU for Windows Server 2012/2012 R2 is 13 October 2026; after that, no security updates are released. In NIST's terms it is an unpatchable asset: isolate it, restrict access and put the migration timeline in the contract.

Should firmware and BIOS updates be part of the agreement?

Yes, we recommend it, because flaws in firmware and the BMC (iDRAC/iLO) are not fixed by operating system patches. The contract should state frequency, approval method, maintenance window and rollback plan. NIST SP 800-40 Rev. 4 also lists firmware among software to patch on on-premises servers. For steps, see our firmware update guide.

What determines the cost of a server maintenance agreement?

The main factors are the number and age of servers, layers in scope, support hours, on-site needs and number of locations, who handles spare parts, and how often reports and exercises are required. A figure can only be calculated once inventory and scope are clear; send your server list via our quote form.

Conclusion

  • A server maintenance agreement complements the warranty by putting preventive maintenance and incident coordination in writing.
  • Windows Server 2022 mainstream support and 2012/2012 R2 ESU both end on 13 October 2026; Windows Server 2016 extended support ends on 12 January 2027.
  • The contract should spell out NIST's four patching scenarios, firmware maintenance, restore testing and numeric response terms.

Sora Yazılım defines the scope of your server maintenance agreement with you, based on your inventory and priorities; for Dell and HPE servers, selection, procurement, installation and maintenance can come from one company.

Get a Quote · WhatsApp: WhatsApp Support · Phone: +90 544 785 21 87 · Email: talep@sorayazilim.com

Sources

  1. Windows Server 2016 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
  2. Windows Server 2022 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
  3. Windows Server 2012 R2, including ESU years — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
  4. Windows Server 2019 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
  5. Windows Server 2025 — Microsoft Learn (Lifecycle). learn.microsoft.com (accessed 7 October 2026)
  6. Fixed Lifecycle Policy — Microsoft Learn. learn.microsoft.com (accessed 7 October 2026)
  7. Lifecycle FAQ – Extended Security Updates — Microsoft Learn. learn.microsoft.com (accessed 7 October 2026)
  8. Windows Server release data — endoflife.date. endoflife.date (accessed 7 October 2026)
  9. NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology — NIST, April 2022. csrc.nist.gov (accessed 7 October 2026)
  10. NIST SP 800-193, Platform Firmware Resiliency Guidelines — NIST, May 2018. csrc.nist.gov (accessed 7 October 2026)
  11. Cyber Essentials: Requirements for IT Infrastructure v3.3 — NCSC (UK), April 2026. ncsc.gov.uk (accessed 7 October 2026)
  12. Veri Güvenliğine İlişkin Yükümlülükler (Data security obligations) — Personal Data Protection Authority (KVKK), Türkiye. kvkk.gov.tr (accessed 7 October 2026)
  13. Known Exploited Vulnerabilities Catalog, version 2026.10.04 — CISA (GitHub data repository). raw.githubusercontent.com (accessed 7 October 2026)

How this article was prepared

Prepared by: Sora Yazılım Team. This article was prepared with AI assistance; technical information was checked against the manufacturer and official sources linked in the text as of 7 October 2026.

Related articles

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support