What a Drupal Support SLA Should Cover for Higher Ed

About the Author

Mohammad Azouqa

VP of Business Development

Mohammad Azouqa is VP of Business Development at Vardot, a Drupal Diamond Certified Partner that builds and supports digital experiences for enterprise, nonprofit, higher education, and government organizations, including UNHCR and UNICEF. He helps clients protect their digital investment by matching them with the right care and support services for their goals. Mohammad holds an MBA from the New York Institute of Technology.

FAQs

They should be named explicitly either way, because an SLA that refers only to "the website" leaves subsite coverage to interpretation. Universities running separate builds for medicine, engineering, or business should list each property, state whether the same priority tiers and uptime figures apply, and name which internal teams may raise tickets for each. Where subsites sit on different infrastructure, the uptime commitment often cannot be identical, and the SLA should say so rather than imply parity.

Major Drupal version upgrades are usually excluded from standard support retainers and priced as separate work packages. Minor updates, such as Drupal 10.5 to 10.6, are typically included as routine maintenance. Universities that want major upgrades covered must state this in the RFP and specify how many upgrades the contract term should cover, or buy a monthly hour allocation that the upgrade can be drawn against.

The uptime figure should match the hosting plan the institution is buying. A 99.9% commitment permits about 8 hours 46 minutes of downtime per year, while 99.99% permits roughly 53 minutes. Universities with heavy registration-period traffic should also confirm that the hosting tier carries a contractual SLA rather than a best-efforts commitment, since on most platforms that guarantee only attaches to higher subscription tiers.

Drupal 10 reaches end of life on 9 December 2026, the same week Drupal 12 is released. After that date the Drupal Security Team stops issuing patches for the Drupal 10 branch. Universities running Drupal 10 should confirm now whether their support contract covers the major upgrade or treats it as separate work, because a quote requested inside that window will compete with every other institution in the same position.

Accessibility should appear in a support agreement as a defined conformance level, such as WCAG 2.1 AA or WCAG 2.2 AA, plus a scope boundary stating whether remediation of pre-existing issues is included. Remediating an existing site reaches into design decisions and is normally scoped as a project after an audit, not as routine maintenance. US public universities should also record which compliance deadline applies to them under the DOJ Title II rule.

The SLA should state the hours during which response targets apply, expressed in the university's own time zone, and whether they extend to weekends and academic holidays. A response target of 15 minutes is only meaningful if staff are working when incidents occur, so meaningful working-hours overlap is a functional requirement rather than a preference. Universities should treat it as a filter applied before technical evaluation.

Join the conversation +