Website Maintenance and Support Plans: What Should Actually Be Included
What "Maintenance" Actually Covers
Launch day gets all the attention, but a website or app doesn't stay finished - it needs ongoing work just to stay as good as it was on day one. "Maintenance" gets used loosely to mean everything from fixing a broken button to rebuilding a whole feature, which is exactly why so many businesses sign a support contract without a clear idea of what it actually includes.
At minimum, a real maintenance arrangement covers four things: keeping the software patched and secure, keeping the site or app actually online and backed up, fixing bugs that appear after launch, and a defined way to reach someone when something breaks. Everything past that - new features, redesigns, content changes - is a separate conversation, not an assumption baked silently into "support."
Security Patching and Dependency Updates
Every framework, library, and plugin a site or app is built on gets security patches over time, and skipping them is how a perfectly fine site slowly turns into a liability. This is invisible work - nobody notices a dependency update the way they'd notice a new feature - which is exactly why it's the first thing to get skipped when there's no maintenance plan holding anyone accountable for it.
- Framework and library updates applied on a regular schedule, not only after something breaks.
- SSL certificate renewal tracked before expiry, not discovered when a browser starts warning visitors.
- A documented process for urgent, out-of-cycle patches when a serious vulnerability is disclosed in something the site depends on.
This connects directly to the basics we cover in our website performance and security guide - most of the security gaps that show up on small business sites are exactly the ones a maintained site shouldn't have.
Hosting, Backups, and Uptime Monitoring
A support plan worth paying for treats "is it actually online right now" as something to monitor, not something to find out from a customer complaint. The basics worth confirming in writing:
- Automated, regular backups - and, just as important, a tested restore process. A backup nobody has ever restored from is a hope, not a plan.
- Uptime monitoring that alerts someone the moment the site goes down, rather than relying on a customer noticing first.
- Hosting renewal and domain renewal tracked on someone's calendar - an expired domain is an entirely avoidable way to lose a business's entire online presence overnight.
Small Fixes vs. New Features: Where the Line Is
This is the single biggest source of friction between businesses and their support provider, because "fix this" and "build this" often look similar from the outside but cost completely different amounts of effort.
- A bug fix restores something that used to work and stopped - a form that stopped submitting, a broken layout on a specific phone, a checkout error. This is what a maintenance plan should cover.
- A new feature is something the site never did before - a new page type, an added integration, a redesigned section. This is new development, usually quoted and billed separately, even under an active support plan.
- A gray area worth naming upfront: content updates, minor copy or image swaps, and small design tweaks. Some plans include a set number of hours for these each month; others treat them as billable extras. Neither is wrong - but it needs to be decided before the first request, not argued about after it.
Response Time: What's Realistic to Expect
"24/7 support" sounds reassuring on a sales page and means very little without a specific number attached to it. A real service-level agreement (SLA) states, in writing, how quickly different kinds of issues get a response:
- Critical issues (site down, checkout broken, payments failing) - typically a response within a few hours, any day of the week, for a plan that actually justifies calling itself priority support.
- Standard bugs (a display glitch, a non-critical error) - commonly a 1-2 business day response is reasonable for most small business sites.
- Requests and questions - a few business days is typical, and fine, as long as it's stated rather than assumed.
Ask for these numbers in writing before signing, not as a verbal assurance during the sales conversation - it's the difference you'll actually notice the first time something breaks on a Thursday evening.
How Support Plans Are Typically Priced
Maintenance and support is usually priced one of three ways, and each fits a different kind of business:
- A flat monthly retainer covering security updates, backups, monitoring, and a set number of hours for fixes and small changes - the most predictable option, and the most common for businesses that want one number to budget against.
- Pay-as-you-go / hourly for whatever comes up, with no ongoing monthly commitment - simpler for a site that rarely needs attention, but riskier if something urgent happens and there's no existing relationship or priority queue to fall back on.
- A hybrid - a smaller monthly fee that covers the security and monitoring basics, with fixes and changes billed separately as they come up. This is a reasonable middle ground for a lot of growing businesses.
Whichever model you choose, ask what happens if the monthly hours aren't used - some agencies roll them over, most don't - and get clear pricing for work that exceeds the plan before you need it, not after.
Questions to Ask Before You Sign
- What exactly counts as a "fix" versus a "new feature" under this plan, and who makes that call if we disagree?
- What's the actual response time for a critical issue, in writing, not "as soon as possible"?
- How often are backups taken, and has a restore ever actually been tested?
- Who owns the hosting account, domain, and admin credentials - us or the agency? (The answer should always be your business, regardless of who manages it day to day.)
- What happens to our access and our data if we want to switch providers later?
A provider that answers these clearly and in writing is telling you something important about how they'll handle the moment something actually goes wrong - which is the only moment a support plan is really being tested.
Do You Need a Retainer, or Just a Point of Contact?
Not every business needs a full monthly retainer from day one. A brand-new site with low traffic and no payment processing might be fine with a lighter arrangement: security updates handled on a schedule, and a known point of contact for anything else. A retainer earns its cost once the site is taking payments, generating leads that matter to revenue, or simply too important to the business to risk a slow, ad-hoc response when something breaks.
If you're not sure which side of that line your business is on, we're happy to look at what you have today - who's hosting it, whether it's backed up, how patched it is - and give you a straightforward recommendation rather than a one-size-fits-all plan.
Not sure what your current support setup actually covers?
Tell us who built your site and how it's currently maintained, and we'll tell you plainly what's covered and what's missing.