Skip to content
CTS Field Notes

Field Notes

Before You Change HVAC Contractors

Changing a building-service contractor is a practical time to check who controls equipment accounts, remote access, and recovery information—and verify that the incoming provider can take over.

Before You Change HVAC Contractors

When you replace an HVAC contractor, put the building’s login credentials on the handover list alongside maintenance records, warranties, and the date of the next service visit.

Ask the outgoing company to identify every way it can reach the system. That might include a manufacturer’s portal, a remote connection to a computer in the building, or an administrator account used by its technicians. Find out who controls those accounts and what has to happen for the incoming contractor to take over.

Do this while everyone is still answering the phone.

A contractor change is a useful time to work through these details because the people involved have an immediate reason to cooperate. Someone needs to accept responsibility for the equipment. Someone needs to demonstrate that it works. Access belongs in that conversation.

Find out whose account it is

Consider a possible arrangement: a contractor installed a heating-control system several years ago and registered the management portal using an employee’s email address. The customer pays for the service and owns the equipment, but password resets go to the contractor’s employee.

The arrangement may have worked perfectly well. Trouble begins when the employee leaves, the contractor changes, or the customer needs to make an adjustment without calling for help.

Before the handover, establish whether the business has its own administrator access, who receives recovery messages, and whether the manufacturer requires a formal transfer. Ask the incoming contractor to explain any account or subscription it expects to control.

A leased building adds another conversation. The property manager may own the system, while the tenant depends on its operation. In that case, the tenant needs a named contact, an escalation route, and a clear account of who can authorize changes. Buying another service contract will not settle those responsibilities.

The same exercise applies to badge readers, cameras, alarm notifications, and environmental monitors. Each may have a different installer, portal, and support arrangement. Start with the systems whose failure would interrupt work or affect access to the building.

Test the handover before closing it

A list of usernames is a poor substitute for watching the new arrangement work.

Have the incoming provider demonstrate an authorized routine task with the person responsible for the building. Depending on the equipment, that could mean reviewing a schedule, retrieving a configuration backup, or checking where a notification goes. Confirm that the business can reach support and that recovery messages arrive at an address it controls.

Then review the old access. Individual accounts, shared credentials, remote-support software, and manufacturer permissions may need different treatment. A password change in one portal does not tell you whether a separate remote connection remains available.

Coordinate removals with the people responsible for operating the equipment. Abruptly disabling an account can create its own problems if it supports an integration or an essential service. Record what was removed, what remains, and the reason for any temporary exception.

NIST’s September 2026 draft of its Guide to Operational Technology Security provides context for this work. It includes building automation and physical-access systems within operational technology and addresses security alongside the equipment’s reliability and safety requirements. The draft also expands guidance on asset management and protection of system-management functions. It remains a draft open for public comment.

For a smaller business, a contractor handover is a manageable opportunity to put that thinking into practice. Facilities knows how the equipment behaves. The contractor knows how to service it. IT can help examine accounts, authentication, and network access. Bring those people together around a specific system and a specific change.

Keep the resulting record with the service agreement. Include the equipment and location, account owner, support contacts, access methods, and the date the transfer was tested. Store passwords in the organization’s approved password manager.

Before closing the job, ask the person responsible for the building to explain what they would do if the system stopped responding tomorrow morning. They should be able to find the right contact, reach the necessary records, and describe any approved manual fallback. If the answer still depends on calling the former contractor, there is another item to finish.

NIST SP 800-82 Rev. 4, Guide to Operational Technology Security, initial public draft