← Blog

What a website maintenance plan should cover

Maintenance is the least explained line on most website quotes. What should actually be happening every month underneath it, who's responsible for which part, and how to tell whether it's real work or a line item.

A website maintenance plan should say clearly what happens to the site every month, not just what it costs. Most quotes list maintenance as one line item with no detail, and the gap between the two only shows up once the site goes down or a form stops arriving and nobody notices first.

Updates and patches

Software that runs a website needs updating the same way software on a phone does, and it matters more the longer it's left. The Australian Cyber Security Centre's small business guide lists updating your software as one of the basic steps and recommends turning on automatic updates wherever that's an option. A maintenance plan should be doing this as a matter of course, not as a callout job after something's already gone wrong.

Backups worth testing

A backup nobody has restored is a hope, not a backup. Files existing somewhere is the easy half; the other half is someone actually pulling a backup down and checking it opens, ideally every few months rather than the day disaster strikes and everyone finds out at once whether the process worked.

Someone watching it

A site going down without anyone noticing until a customer mentions it is the most avoidable failure on this list. Uptime monitoring, an expired certificate warning, a server error that starts appearing on a specific page: someone should be watching for all of it, and hearing about it before you do. The same logic applies to the contact form. We've covered testing your own enquiry pipeline in detail elsewhere, and it belongs inside a maintenance plan, not as a separate thing you remember to do occasionally.

The small edits

A phone number changes. Hours change for a public holiday. A finished job gets added to the gallery. These shouldn't need a ticket, a quote and a wait each time. A working maintenance arrangement absorbs the small stuff as part of what you're already paying for, which is the model behind our own Growth plan.

Who's actually responsible for each part

Hosting, the site's code or platform, and the content on it are three different jobs, and a maintenance plan should say clearly who does which. It should also never mean only one person holds every login. We've written about who should hold the actual accounts in full, and it applies here as much as anywhere: the business holds the logins, and whoever's doing the maintenance gets invited in as a user, not the other way around.

How to tell whether it's actually happening

Ask for a plain list covering the last three months: updates applied and when, the last date a backup was actually restored and checked, and any downtime and what caused it. A real maintenance arrangement can produce that list in a few minutes, because someone is already keeping it. If nobody can produce it, ask for it in writing before renewing.