Managed Services Packages Details
Version 2.0 | Effective April 17, 2026
Supersedes v1.3 (October 2, 2025)
The authoritative service catalog for ACS Managed Services. Defines the services included in the Basic and Pro packages, the optional Per-User Services Bundle, and Add-On Services available for custom-quoted engagement.
About This Document
This document describes the services included in ACS’s Managed Services packages (Basic and Pro), the optional Per-User Services Bundle, and the Add-On Services available for custom-quoted engagement. It is incorporated by reference into each Client’s Statement of Work (SOW) and is subordinate to both the SOW and the Master Services Agreement (MSA) published at acsapp.com/msa.
The services identified in a given SOW’s Service Selection section are the services delivered under that SOW. Nothing in this document guarantees any service to any Client independent of the Client’s executed SOW. Labor included in Managed Services versus labor billed at Time & Materials is defined by the Client’s SOW.
Services are delivered remotely except where an onsite visit is specifically called for. All service hours are expressed in the Client’s local time zone unless otherwise stated.
Package Overview
ACS offers two per-device Managed Services packages and one per-user add-on bundle. Package selection and applicable pricing are set forth in each Client’s SOW.
| Offering | Billing Basis | Who It’s For |
|---|---|---|
| Basic | Per managed device, per month | Essential proactive IT management — monitoring, patching, endpoint protection, support during business hours |
| Pro | Per managed device, per month | Complete managed IT with strategic account management, 24/7 security operations, and service guarantees |
| Per-User Services Bundle | Per licensed M365 user, per month — add-on, optional on either package | Users and email/SaaS-layer security: phishing simulation, DLP, M365 backup, email security, behavior monitoring |
| Add-On Services | Custom quoted, billed separately | HAAS, BCDR, MDM, SIEM, compliance, penetration testing, and other specialty services |
Assurances
(All Managed Services Packages)
Information Privacy
We protect Client proprietary business information with the same diligence as our own confidential data and do not disclose it to third parties except as permitted by the MSA or required by law. See acsapp.com/privacy-policy.
Third-Party Cybersecurity Audits
ACS partners with a third-party Chief Information Security Officer (CISO) firm that performs continuous monitoring and evaluation of our cybersecurity framework.
Commitment to Rectify Shortcomings
If our services fall short of the standards in the MSA and SOW, we take immediate action to address and resolve the issue.
Adherence to Service Level Expectations (SLEs)
We hold our teams to the SLEs set forth in each Client’s SOW and use a probabilistic approach to forecasting realistic work timelines.
Satisfaction Commitment
If any aspect of our service fails to meet the standards set forth in the MSA and SOW, we take corrective action consistent with those agreements.
Live Answer for Service Phone Calls
All client support calls are answered directly by a service coordinator during business hours (Monday–Friday, 8:00 AM – 5:00 PM Client local time), excluding holidays. Holiday schedule: acsapp.com/holidayschedule. Support line: 877-404-8224.
Pro Guarantees
(Pro Package Only)
The following guarantees are contractual and apply only to Pro Clients. Exact mechanics, triggers, and exclusions are set forth in each Pro Client’s SOW.
No Service Voicemails Policy
Calls to the ACS support line (877-404-8224) during Regular Support Hours will be answered by a service coordinator without voicemail. If a voicemail is required due to ACS oversight during those hours, Client may request a $25 credit on the next invoice by emailing billing@acsapp.com within 30 days, including the date and time of the voicemail. Does not apply to voicemails via automated prompts or to calls outside Regular Support Hours.
30-Day Money-Back Guarantee (New Clients Only)
For new Clients, if Client is dissatisfied within the first 30 days following the SOW Effective Date, Client may terminate and receive a full refund of the one-time Onboarding Fee and the first month’s recurring service fee. Does not apply to T&M, projects, third-party licensing, or hardware. Exercise of this guarantee is Client’s sole and exclusive remedy for dissatisfaction within the 30-day window. A “new Client” has never previously engaged ACS or any entity acquired by ACS.
Onsite, On-Time Notification
For scheduled onsite visits, if ACS reasonably anticipates arriving late, ACS notifies the Client Primary or Technical Contact at least 30 minutes before the scheduled appointment time. Emergency delays beyond ACS’s reasonable control are excused with prompt notice.
Support
Remote Support
Included in Basic. Remote support is provided for managed business users, computers, servers, sites, mobile devices, and tablets during Regular Support Hours: Monday through Friday, 8:00 AM – 5:00 PM Client local time, excluding holidays. First-response time commitments differ by package and are set forth in the Client's SOW.
Included in Pro. Remote support is provided for managed business users, computers, servers, sites, mobile devices, and tablets during Regular Support Hours: Monday through Friday, 8:00 AM – 5:00 PM Client local time, excluding holidays. First-response time commitments differ by package and are set forth in the Client's SOW.
Onsite Support
Included in Basic. Onsite support is available when deemed necessary by ACS for managed Client infrastructure during Regular Support Hours. Onsite support is not unlimited; work that meets the Project definition in the SOW requires a signed Change Order and is billed separately.
Included in Pro. Onsite support covers managed infrastructure during Regular Support Hours and additionally covers regularly scheduled maintenance visits. Onsite support is not unlimited; Project work requires a signed Change Order and is billed separately.
Support Channels
Phone, email, client portal, and Microsoft Teams integration. Ticketing system for submitting and tracking requests. First-response commitments per the SLE table in each SOW. Support line: 877-404-8224.
Phone, email, client portal, and Microsoft Teams integration. Ticketing system for submitting and tracking requests. First-response commitments per the SLE table in each SOW. Support line: 877-404-8224.
After-Hours & Weekend Support
Not included. Available on demand at the multipliers set forth in the Client's SOW (typically 1.5× for after-hours and 2× for weekends, applied to the applicable T&M rate). After-hours is defined as 5:01 PM – 7:59 AM Client local time, Monday through Friday.
Not included. Available on demand at the multipliers set forth in the Client's SOW (typically 1.5× for after-hours and 2× for weekends, applied to the applicable T&M rate). After-hours is defined as 5:01 PM – 7:59 AM Client local time, Monday through Friday.
Holiday Support
Not included. Available on demand at the multiplier set forth in the Client's SOW (typically 2.5× the T&M rate). Applies to any 24-hour period on a day listed on ACS's holiday schedule.
Not included. Available on demand at the multiplier set forth in the Client's SOW (typically 2.5× the T&M rate). Applies to any 24-hour period on a day listed on ACS's holiday schedule.
Dedicated Onsite Resource
Not included. Available as an add-on in four-hour increments; custom quoted.
Not included. Available as an add-on in four-hour increments; custom quoted.
Basic Package
Basic is a per-device managed services package providing essential proactive IT management. It includes monitoring, maintenance, endpoint protection, and business-hours remote and onsite support for managed devices, users, and sites.
4.1 Core IT Management
- 24/7/365 Device Monitoring & Alerting.
Continuous monitoring with real-time alerts for all managed devices. - AI-Powered Endpoint Protection (EDR).
AI- and machine-learning-driven detection and prevention of malware, ransomware, and behavioral threats on managed endpoints. - Antivirus & Malware Protection.
Continuous protection against viruses and malware on managed endpoints, with detection, blocking, and removal. - Ransomware Detection & Alerting.
Real-time detection of ransomware activity with automated alerting to enable rapid response. - Planned Preventative Maintenance.
Routine preventative maintenance on eligible managed computers and servers. - Microsoft Patch Management.
NOC-driven identification, approval, and automated installation of essential security patches at scheduled times.
* Clients may request supplementary patch management; subject to approval by ACS. - Proactive Alert Escalation.
Automated escalation of alerts to qualified engineers for timely management. - Self-Healing Service Automation.
Recurrent problems are managed proactively with automation for quick, consistent resolution. - System Health Checks.
Continuous monitoring of CPU, RAM, disk, and related performance indicators. - Automated Maintenance Tasks.
Scheduled disk cleanup, reboots, and other routine maintenance. - Remote Access for Troubleshooting.
Secure remote access for technicians to diagnose and resolve issues.
4.2 Network & Site Management
- Proactive Network Monitoring.
Insight into network traffic flows with monitoring and alerting to diagnose slow-downs or infrastructure interruptions. - Network Management & Support.
Management, troubleshooting, and support for office infrastructure, with best-effort handling of end-of-life hardware or vendor coordination when necessary. - IT Documentation Portal (MyGlue).
Secure, shared access to critical IT documentation — passwords, configurations, SOPs, guides, and instructions. - Licensing & Asset Management.
Device inventory tracking and software license tracking where supported.
4.3 User Management
- User Management & Troubleshooting.
Expert troubleshooting for user-related challenges including access permissions and group membership configurations. - Centralized Password Management.
Password manager storing credentials in one encrypted location. - Multi-Factor Authentication (MFA) Support.
Configuration and support of additional security verification steps. - M365 License Management.
Procurement and maintenance of M365 licenses, with support and troubleshooting for managed accounts (excludes development services).
4.4 Server & Backup Management
- Server Monitoring, Maintenance, and Patching.
All Section 4.1 services apply to managed servers. - Managed Server Backup.
1TB of backup storage pooled per Client environment, retained for 90 days. Additional storage and longer retention available as an add-on.
* Client compliance requirements may dictate longer retention periods where applicable. - Proactive Backup Monitoring.
24/7/365 monitoring of backup systems with prompt issue remediation. - Server Break/Fix Support.
Remote server support and managed software troubleshooting. Onsite repair available if remote resolution is not possible.
4.5 Proactive Account Management
- Cybersecurity & Tech Tips.
Weekly educational cybersecurity and technology tips distributed to all users. - Self-Service Client Portal.
Tools to pull reports, examine tickets, and access custom ticket templates. - ACS Monthly Newsletter.
Monthly newsletter covering technology news and ACS updates. - Streamlined Payment Portal.
Secure platform accepting credit card and ACH payments. - Ongoing Quality Assurance Communication.
Your dedicated Account Manager reaches out monthly for check-ins and relationship maintenance. - Onboarding/Offboarding Tooling.
Self-service forms for employee and device onboarding and offboarding, with hands-on assistance from our team.
Pro Package
Pro includes everything in Basic, plus the additional services below. Pro is designed for Clients who want complete managed IT with strategic account management, 24/7 security operations, and contractual service guarantees.
5.1 Strategic Account Management
- Dedicated Account Manager.
Your Account Manager is your main point of contact, dedicated to overseeing delivery of all services. - Technology Business Reviews (TBRs).
Periodic strategic reviews aligning an IT roadmap and predictable budget to your business goals, enabling proactive planning of major projects and expenses. - Monthly Executive Summary Report.
A monthly executive summary covering network health, ticket trends, and SLE performance. - Real-Time Dashboard.
Instant visibility into ticket statuses, SLE reports, survey scores, and key performance indicators. - Monthly Dark Web Insight Reports.
Monthly reporting and alerting on identified dark-web breaches involving the Client organization, with automatic ticket creation.
5.2 Security Operations
- Managed Detection & Response (MDR) / SOC.
A dedicated team of cybersecurity experts actively monitors and remediates threats, analyzing behavioral data from PCs and servers to detect suspicious activity. Threat hunters work proactively to identify signs of compromise. - Cyber Attack Remediation — Priority Response.
ACS reacts to cyber attacks with priority coverage. Remediation work is billed at Time & Materials per the Client’s SOW; priority access is the Pro-tier benefit. - Dark Web Credential Monitoring.
Monitoring of the dark web for compromised credentials tied to the Client organization, with alerts and automatic ticket creation. - Web Gateway & Content Filtering Security.
Web content filters built and maintained based on client-defined website categories.
* Firewall required. - Managed Computer & Server Encryption.
ACS oversees drive encryption on managed devices that support encryption.
5.3 Advanced Computer & Server Management
- Support & Fix Computer Issues — Advanced Troubleshooting.
Remote break/fix troubleshooting beyond basic remote support, with ACS acting as technical liaison for unsupported hardware or software. No onsite hardware troubleshooting; ACS can facilitate vendor-warranty onsite visits. - Azure / InTune Environment & License Support.
Performance and security optimizations for Azure and InTune environments, with license management under client guidance.
* Requires appropriate Microsoft licensing, MDM, and client-defined parameters. - Managed M365 Access & Security.
Advanced policy creation ensuring that only approved users and devices can access Client M365 infrastructure.
* Requires appropriate Microsoft licensing, MDM, and client-defined parameters. - Managed Software Automation.
Automatic software deployments to managed devices, with efficient updates and installations.
* Unmanaged software deployment at scale is available at additional cost. - Tailored Alert Configuration.
Custom alerts for services and applications based on Client request. - Computer Provisioning Service.
ACS configures managed computers to match Client-approved specifications for new hires, ensuring compliance with ACS baseline requirements (hardware, CPU, RAM, storage, OS).
* Labor only; hardware and software costs additional. - New Software Installation Service.
Installation and troubleshooting for managed software, with best-effort support for unmanaged applications.
* Labor only; installations must meet project scope criteria: under 2 hours, fewer than 5 steps, limited to 5 users/devices. Installations exceeding these criteria become Projects (see SOW).
Per-User Services Bundle
Optional add-on — available with either Basic or Pro.
The Per-User Services Bundle provides an additional layer of email, SaaS, and user-identity security on top of the device-layer protections in Basic and Pro. It is billed per licensed Microsoft 365 user account, counted monthly from the Client M365 tenant.
6.1 Email & SaaS Security
- AI-Driven Email Security.
Multi-layered, AI-powered email protection stopping phishing, business email compromise (BEC), spam, and malware before they reach user inboxes. - Tailored Email Filtering.
Allow- and block-list configuration for precise control over permitted and blocked senders. - SaaS Application Management.
Best-practice management and security configuration for M365, Google Workspace, and other SaaS applications.
* Requires appropriate Microsoft licensing and client-defined parameters. - SaaS Event Alerting.
Alerting on security events such as cross-country access, password changes, or data deletion. - Automatic SaaS Account Locking.
Automatic account lock on M365 and Google accounts when security events are detected. - Suspected Attack Detection for M365.
Vigilant monitoring of M365 accounts to identify and address threat-actor activity.
* Requires appropriate Microsoft licensing and client-defined parameters. - Cloud Account Threat Detection.
Tracking of mass data deletions and downloads on managed accounts to identify insider risk or threat-actor activity.
* Requires appropriate Microsoft licensing and client-defined parameters.
6.2 M365 / SaaS Backup
- Secure M365 & SaaS Backups.
256-bit encryption at rest, 128-bit encryption in transit, with frequent daily snapshots for fast, reliable recovery from accidental deletion or cyber incidents.
6.3 Identity, Access & Data Protection
- Access Permissions Violation Monitoring.
Access controls and User Behavior Analytics (UBA) with alerting for failed logins, unauthorized region-based logins, and activities outside typical user patterns.
* Requires appropriate Microsoft licensing and client-defined parameters. - Client-Defined Sensitive Data Controls.
Tailored controls for PII, PCI, PHI, and NPI implemented via email and device monitoring.
* Requires appropriate Microsoft licensing and client-defined parameters. - Data Loss Prevention Policies.
Custom policies regulating who and which devices can access managed M365 infrastructure and data.
* Requires appropriate Microsoft licensing, Mobile Device Management (MDM), and client-defined parameters.
6.4 User Security Awareness
- Advanced Phishing Simulation.
Automated phishing tests drawing from a broad library of templates with unlimited simulations for optimal security awareness. - Cybersecurity User Awareness Training.
Ongoing security training to help users recognize and respond to phishing, social engineering, and other cyber threats.
Add-On Services
Available to Basic and Pro Clients as separately priced options. Unless otherwise noted, each Add-On is custom quoted based on Client environment and requirements and documented in the Client’s SOW or a signed Change Order.
7.1 Network & Remote Access
- HAAS Firewall (Hardware as a Service).
Firewall hardware, ongoing management, software updates, configuration, and replacement bundled into a single monthly fee. Custom quoted. - Network Equipment Rental.
Switches and wireless access points available on a rental basis. Custom quoted. - Advanced Firewall Security Service.
Enterprise-grade IDS/IPS continuous monitoring and analysis of network events to identify and mitigate security threats. Custom quoted. - Secure VPN for Remote Users.
Reliable VPN solution keeping remote users connected securely. Custom quoted. - SIEM Logging & Incident Monitoring.
SIEM system logging behind-the-scenes activities (network access, security changes, permission modifications), with alerts on unusual or malicious behavior and traceback of security incidents. 30-day retention included; extended retention available.
* Requires appropriate Microsoft licensing and client-defined parameters. - Dark Web Monitoring (Standalone).
Continuous scanning of the dark web for compromised credentials tied to the Client organization, with 24/7/365 alerting. Note: Dark Web Monitoring is included in Pro by default — this standalone add-on is primarily for Basic Clients.
7.2 Backup & Disaster Recovery
- Backup & Disaster Recovery (BCDR) Appliance.
BCDR appliances delivered to Client office locations, supporting bare-metal server backups and continuous file- and folder-level backup processes for managed servers. Custom quoted. - Image-Based / Bare-Metal Server Backup.
Full-image server backup for entire-machine recovery. Custom quoted. - Computer File Backup Service.
Endpoint file backup for PCs. Custom quoted. - Additional Computer Backup Storage.
Available in 50GB increments. Custom quoted. - Additional Server Storage Beyond 1TB.
For Clients whose server backup needs exceed the 1TB pooled allocation included in Basic/Pro. Custom quoted.
7.3 Email Security
- Mail Protector — Spam & Security Filtering.
Third-party email spam and security filtering. Separate from and additional to the AI-Driven Email Security included in the Per-User Services Bundle. - Mail Protector — Email Encryption.
Third-party email encryption service.
7.4 Mobile & Tablet Management
- Managed Tablet.
MDM for business-owned tablets, with remote support, always-on VPN, and application control. Remote support does not include hardware repair. Custom quoted.
* Requires appropriate Microsoft licensing, MDM, and client-defined parameters. - Managed Mobile.
MDM for business-owned mobile devices, with remote support, always-on VPN, and application control. Remote support does not include hardware repair. Custom quoted.
* Requires appropriate Microsoft licensing, MDM, and client-defined parameters.
7.5 Compliance, Risk & Governance
- ACS Vulnerability Management — GRC Center.
Custom governance, risk, and compliance portal to plan, track, and document compliance to standards such as PCI DSS, HIPAA, NIST CSF, SOC, Cyber Insurance, GDPR, CIS v8, FTC Safeguards, and NYDFS. One standard per purchased compliance agreement. Includes written policies, POAM, network diagrams, audit log creation and review, monthly compliance reports, vendor compliance management, disaster-recovery plans and testing, data-flow chart mapping, and network/security assessment reporting. Custom quoted. - vCISO Services.
Virtual CISO engagement. ACS can be listed as Client’s certified and qualified CISO. Custom quoted. Services include:- Up to 4 executive leadership meetings per year
- Up to 2 board member meetings per year (if applicable)
- Strategic and business continuity updates, ROI and security budget planning
- Review and reporting of vulnerability assessments and security posture
- Inventory and data-asset analysis
- Threat intelligence reporting
- Security deliverable tracking aligned to Client’s System Security Plan
- Written Information Security Plan (WISP).
Curated information security plan based on Client business needs. Custom quoted.
* Requires client involvement and end-user interviews. - Internal & External Vulnerability Scanning.
Scheduled scanning of Client environment as required. Custom quoted. - Penetration Testing.
Simulated penetration tests against Client’s managed digital environment as required. Custom quoted. - Security Vendor Management.
Managing security vendor relationships and validating vendor adherence to Client security and compliance standards. Custom quoted.
7.6 Additional Labor
- Dedicated Onsite Resource.
A dedicated ACS resource onsite at Client premises. Purchased in 4-hour increments. Custom quoted.
Scope, Exclusions & General Terms
Scope Boundary
Managed Services cover only the devices, users, servers, sites, and services expressly identified as in-scope on the Client’s SOW and managed in the ACS RMM. Anything not specifically identified as included is excluded.
Projects Not Included
Project work is excluded from all Managed Services packages. A “Project” is defined in each Client’s SOW (typically any request exceeding 4 hours of ACS labor, affecting more than 4 users, or expected to take more than 4 calendar days). Projects require a signed Change Order and are billed at Time & Materials rates.
Excluded Services
- Printer, copier, and scanner hardware repair, mechanical issues, and vendor coordination
- Physical hardware repair (drives, screens, motherboards, other mechanical failures)
- Work performed on unmanaged or client-controlled networks (development, staging, sandbox, vendor networks, etc.) — billed at Time & Materials
- Onsite support for legacy network equipment outside ACS’s standard recommended set (Fortinet FortiGate, Ubiquiti APs and switches) — billed at Time & Materials
- Security remediation work arising from actual or suspected incidents — billed at Time & Materials per SOW
- Regulatory compliance — services may support compliance efforts but do not, alone, bring Client into compliance with any regulation
- Discovery, audit, or subpoena responses related to lawsuits, compliance regulations, or third-party audits — labor billable
Service Prerequisites
Certain services require Client to maintain appropriate Microsoft licensing, MDM, or other prerequisites, as noted in the asterisk footnotes throughout this document. Services requiring prerequisites are not delivered until prerequisites are in place; delay to deliver such services is not a breach.
Co-Managed Engagements
Co-managed packages may vary from the standard services outlined in this document. See the applicable SOW or speak with your Account Manager for scope details.
Labor Billing
Labor for Managed Services is defined in each Client’s SOW. Whether specific labor is included in the monthly fee or billed at Time & Materials rates is governed by the SOW. In the event of conflict between this document and the Client’s SOW, the SOW prevails.
Relationship to MSA and SOW
This document describes service offerings only. It does not create contractual obligations independent of the MSA and SOW. The MSA and each Client’s SOW govern the legal relationship; in any conflict, the MSA governs legal terms, the SOW prevails on commercial terms, and this document is informational only.
Change Log
| Version | Effective Date | Summary of Changes | Author |
|---|---|---|---|
| 2.0 | April 17, 2026 | Restructured to the two-tier device + per-user add-on model. Per-User Services moved from Pro-only inclusion to a per-user optional add-on available on either Basic or Pro. Remote and onsite support confirmed as included in both Basic and Pro. Dark Web Monitoring clarified as Pro-only by default, with a Basic-tier add-on alternative. Removed “coming 2025” language (all listed services are live). Added explicit Pro Guarantees section with mechanics. Aligned language with ACS Statement of Work v2.0 and the Client Proposal deck. Added document version, effective date, and this change log. | ACS |
| 1.3 | October 2, 2025 | Prior authoritative version. Superseded by v2.0. | ACS |