Skip to contact form
← BlogBuyer guideAugust 15, 2026 · 14 min read

What does website maintenance actually include?

Separate monitoring, security, dependency updates, backups, content support, incident response and improvement into an accountable post-launch plan.

aunch changes a project from a controlled build into a live service. Real users submit unexpected data, external providers change, dependencies release security fixes, content becomes outdated and staff access changes. Maintenance is the routine that keeps those ordinary changes from becoming an outage, a security incident or a product nobody is confident enough to update.

  • Availability: uptime checks, error reporting, form delivery and key transaction monitoring.
  • Security: dependency and runtime updates, access reviews, secret rotation and vulnerability response.
  • Recovery: automated backups, retention rules and tested restoration.
  • Product: browser and device checks, broken journeys, accessibility and performance.
  • Content and compliance: pricing, team details, policies, consent and data practices kept current.
  • Operations: named owners, escalation routes, supplier renewals and documented release procedures.

Confirm what is backed up: databases, uploaded files, configuration, content and any encryption material needed to read the result. Keep copies away from the same failure that could affect production. Periodically restore into a safe environment and record how long recovery takes. A green “backup completed” message does not prove the business can recover.

Use individual accounts, multi-factor authentication and the least access each person needs. Remove leavers promptly and review administrators, recovery addresses and connected applications. The UK's National Cyber Security Centre specifically groups account protection, email, devices, backups and recognising attacks as core guidance for small organisations; a website maintenance contract cannot compensate for weak business-account control.

A warranty normally covers faults in the agreed work for a defined period. Maintenance covers the moving environment after that: platform updates, dependency changes, monitoring and operational support. New features, redesigns and changing business rules are product work. Naming these categories prevents both the client and supplier from treating every future request as either free or an emergency.

A simple marketing site and a portal processing customer data do not need identical operations. Review critical alerts continuously, security updates promptly, account access regularly, and broader content and performance on a planned cadence. The plan should state who decides severity, response targets, what is outside support hours and how the service is handed to another team.

  • Monitoring: uptime, errors, performance, certificate and domain health.
  • Security: dependency review, access control, secret rotation and incident response.
  • Reliability: backups, restore tests, database care and third-party failure handling.
  • Compatibility: framework, browser, operating-system and integration updates.
  • Content operations: publishing support, redirect hygiene, broken-link checks and accessibility review.
  • Improvement: measured changes to conversion, search, usability and operational efficiency.

A maintenance agreement should name response hours, severity levels, included effort, exclusions, release process, backup retention and who can approve work. “Unlimited support” is not useful without channels, response targets and boundaries.

The client should retain access to code, hosting, domains, analytics, vendor accounts, documentation and backups. The incumbent agency can still operate them day to day, but continuity should not depend on one personal login or undocumented deployment ritual.

Want this kind of thinking on your project?

This is how we work through real decisions. If you're weighing a build of your own, tell us about it — we reply within one working day.