What Website Maintenance Should Actually Include

A maintenance plan should name the systems, preventive work, monitoring, response, exclusions, and owner of every recurring risk.

What Website Maintenance Should Actually Include — Troiana insight cover

In short

Website maintenance should include monitoring, tested backups, software and dependency updates, access review, form and journey checks, expiry ownership, performance and error review, incident response, and a change record. The agreement should separate preventive work, defect support, and new improvements.

Maintenance is an operating responsibility

A website does not remain healthy because nobody changes it. Domains expire, certificates renew, APIs change, dependencies age, editors leave, forms fail, content becomes wrong, and third-party scripts grow.

A useful maintenance agreement names the system, the risks being managed, the checks performed, and the response when a check fails.

The maintenance baseline

Availability and error monitoring

Monitor representative public URLs, server errors, failed jobs, and important third-party dependencies. An uptime check that requests only the homepage can miss a broken form, search endpoint, checkout, or CMS build.

Define who receives alerts, which hours are covered, and what severity deserves interruption.

Backups and restore tests

Back up the content, database, configuration, assets, and any infrastructure definitions needed to recover. A successful backup notification is not proof of recovery; test restoration periodically in a safe environment.

Record retention, storage location, encryption, access, and the recovery owner.

Software and dependency updates

Review CMS, plugins, frameworks, packages, server software, and integrations. Updates should be tested before production when the system's importance warrants it.

“Always update immediately” and “never touch a working site” are both poor policies. Prioritise security, compatibility, and known defects; keep a rollback path.

Access and account review

Remove former staff and suppliers, review administrator roles, confirm multi-factor authentication where available, rotate shared credentials out of use, and keep recovery details current.

The company should control the domain, hosting, code repository, CMS, analytics, and paid services even when a partner operates them.

Critical-journey checks

Test the actions whose failure would matter:

  • contact and application forms;
  • booking or checkout;
  • login and password recovery;
  • search and filtering;
  • downloads;
  • CRM or email delivery;
  • consent choices;
  • scheduled publishing.

Use automation for repeatable checks and manual review for behaviour tools cannot judge.

Domain, DNS, certificate, and licence ownership

Record renewal dates, payment owners, and expiry alerts. Automatic renewal can fail when a card expires or an employee's account closes.

Security and vulnerability response

Track relevant advisories, suspicious events, exposed credentials, unsupported software, and dependency risk. Define the response path before an incident. Maintenance is not a substitute for a proper security programme on systems handling sensitive or regulated data.

Performance regression review

Watch real-user Core Web Vitals, page weight, third-party scripts, image handling, and representative templates. Performance often erodes through many individually reasonable additions.

Use Troiana's web performance guide to separate field evidence from one-off lab tests.

Search-health checks

Monitor unexpected indexation changes, sitemap errors, broken redirects, canonical mistakes, blocked resources, and important 404s. This is technical preservation—not a complete SEO or content programme.

Content accuracy and expiry

Assign owners and review triggers for prices, people, policies, opening times, product details, claims, case studies, and screenshots. Content maintenance belongs in the operating model even when a technical supplier does not perform it.

Preventive, corrective, and improvement work

Separate three categories:

Category Example
Preventive Updates, monitoring, backup tests, access review
Corrective Repair a failed form or integration
Improvement Add a new content type or redesign a journey

The price and approval path may differ. If a retainer includes a time allowance for all three, explain which work takes priority when an incident consumes the month.

What the report should show

A useful maintenance report is short and operational:

  • checks completed;
  • alerts and incidents;
  • updates made and rollback status;
  • backup and restore evidence;
  • performance or search regressions;
  • licences or renewals approaching;
  • work recommended, with consequence and priority;
  • time used where relevant.

A green checklist with no evidence gives little assurance. A thirty-page automated scan gives little direction.

Questions for the agreement

  1. Which production and staging systems are included?
  2. Which checks run automatically and manually?
  3. How often are updates assessed?
  4. When was restoration last tested?
  5. Which journeys are actively checked?
  6. What counts as an incident and a defect?
  7. What response is promised by severity?
  8. Are diagnosis and repair both included?
  9. What remains the client's responsibility?
  10. What is explicitly excluded?
  11. Who owns accounts, code, data, and documentation?
  12. How does handover work when the service ends?

Common questions

How often should website maintenance happen?

Monitoring may run continuously, while updates, access, backups, performance, and content have different review intervals. Frequency should follow rate of change and consequence of failure.

Does website maintenance include content updates?

Only if the agreement says so. Technical maintenance, routine content entry, copywriting, SEO, and design improvement are distinct responsibilities.

Does maintenance include fixing bugs?

It should define which defects are included, how they are prioritised, and whether the fee covers diagnosis, repair, or a time allowance. Warranty defects may be handled separately.

Do managed website builders need maintenance?

Yes, though the vendor handles much of the platform. The business still owns content, users, domains, integrations, forms, analytics, consent, and operational checks.

What should happen when maintenance ends?

The supplier should hand over current access, code, documentation, backups, open risks, renewal details, and monitoring ownership without locking the company out of its own system.

Have something worth building right?