# What is a Service-Level Agreement (SLA) in Security?

> A security service-level agreement is the contractual commitment defining what a provider will deliver — response times, availability, coverage, notification duties — and what happens when it falls short.

- Canonical URL: https://yellowcube.eu/glossary/service-level-agreement/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

In security services, SLAs may cover monitoring hours, alert and escalation times, incident response start times, reporting cadence, staffing, and remedies such as credits or termination rights. They sit beside contracts describing scope, liability, data handling, and termination.

### Key points

- **Beyond the headline number:** Check what triggers the clock (detection, notification, analyst engagement), what is excluded, how severity is defined, and who declares an incident.
- **Internal obligations:** Provider commitments do not replace internal response, legal notification, or regulator deadlines under frameworks like NIS2 or DORA.
- **Important limitation:** An SLA is a commercial promise, not a security outcome. Credits compensate for breach of the promise; they do not undo a missed detection or a lost hour during an incident.

### Related terms

[Managed security service provider (MSSP)](<https://yellowcube.eu/glossary/managed-security-service-provider/>) · [Managed detection and response (MDR)](<https://yellowcube.eu/glossary/managed-detection-and-response/>) · [Security operations center as a service (SOCaaS)](<https://yellowcube.eu/glossary/security-operations-center-as-a-service/>) · [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Supply-chain security](<https://yellowcube.eu/glossary/supply-chain-security/>)

### Sources

[NIST SP 800-35, Guide to Information Technology Security Services](https://csrc.nist.gov/pubs/sp/800/35/final) · [NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

