Web Design & Development

What a Website Maintenance Contract Should Cover: Guide

Maintenance starts the day a site goes live. What a solid maintenance agreement includes and what it does not: security, backups, support hours.

rabbitclip teamPublished: 4 min read

Short answer

A solid maintenance contract spells out four things clearly: security updates, regular backups, response times for support, and exactly what content changes are included. Without those four written down, the word 'maintenance' means something different to each side, and when something goes wrong nobody is sure who is supposed to do what.

A site can look finished the day it launches, but the software running underneath it, the CMS, plugins, libraries, starts accumulating security gaps over time. Closing those gaps is ongoing work, not a one-off job.

Below are the four parts of a maintenance contract, and the questions worth asking before signing one.

Who handles security updates

The software a site runs on, the content management system, plugins, server components, needs updating on a regular schedule; a plugin left unpatched can open the door to malicious access through a known vulnerability. The contract should state clearly who does this and how often.

If this step gets skipped on a law firm's site and it gets compromised, working out whose responsibility that was becomes an argument; a clause written down at the start removes that uncertainty entirely.

Backups: how often, kept where

A backup is the only way to roll a site back to an earlier state. The contract should state how often backups are taken (daily or weekly), how many copies are kept, and whether they are stored somewhere separate from the site itself; a single backup kept on the same server is worthless the moment that server goes down.

A restore test is worth running now and then too; a backup being taken does not by itself prove that backup actually works.

Support hours and what falls outside scope

A maintenance contract usually includes a set number of hours or requests per month; a text change or an image update falls inside that. A new page design, a new feature or an integration usually falls outside it and needs a separate quote.

If that line is not drawn from the start, a small 'could you also add this' request quietly turns into a project outside scope, and both sides end up in a disagreement neither one saw coming.

Emergency response time

The contract should state how many hours it takes to get a first response when a site goes down completely or becomes unreachable. If a catering firm's order form breaks over a weekend, waiting until Monday means real lost revenue; that is why urgent and routine requests get separate response times.

  • Urgent (site unreachable, form broken): first response within a few hours
  • Routine (text change, small fix): within a few working days
  • Out of scope (new feature, redesign): separate quote and timeline

Questions worth asking before signing

Who holds the source code and admin access, how the site gets handed over if the contract ends, where backups are kept, what the monthly scope actually covers: these need a written answer before signing, not a verbal one. A spoken agreement protects nobody once a disagreement starts.

Are performance and content audits part of maintenance

A maintenance contract usually covers technical updates and backups, but a speed report or a check on whether content is still current stays outside scope unless it is written in as its own line item. It is common for a site to stay technically healthy for six months while nobody has looked at its speed report once.

If a campaign banner added six months ago is still sitting on a catering firm's site, that says something about whether content review falls under maintenance too; spelling that line out in the contract clears up what both sides actually expect.

Who tracks SSL certificate and domain renewal

SSL certificate and domain expiry are two items a maintenance contract commonly leaves out; if neither renews automatically, a browser shows visitors a security warning once the certificate lapses, and the site becomes completely unreachable once the domain lapses.

If a spa chain's booking site goes dark for a day because a domain renewal got missed, that loss shows up directly in revenue; the contract should state in writing who checks these two items and on what date.

SSL certificates can usually be set to renew automatically now; but whether that automation is actually working, and when it last renewed, is worth checking by hand once a year too, since automation can quietly break.

A solid maintenance contract settles, in advance, who does what when a site runs into trouble. rabbitclip hands over a written maintenance scope with every site it delivers; if you already have a contract, we can review it against these four points together.

FAQ

Is a maintenance contract legally required?

No, but a site left without security updates and backups quietly accumulates risk over time.

Who should hold the source code?

It should be stated clearly in the contract; ideally the code and access sit under the business's own account.

What counts as an emergency?

Situations that cause direct lost revenue, such as the site being completely unreachable or a form or payment flow failing.

Does a new page fall under maintenance?

Usually not; a new page or feature needs a separate quote and timeline.

How does a speed report get added to a maintenance contract?

As its own clause, stating clearly how often a report gets pulled and who reviews it.

Share

Related serviceSoftware DevelopmentTurning an idea into a working product takes longer than it looks. From web and mobile apps to bespoke systems that automate your operations, we build software that’s simple and solid.

Related articles

If you don’t know where to start, that’s fine; you’re in the right place.

Your project might already be clear in your head, or still just an idea. Either works. On a short call we talk through where you are and where you could go, together.

Let’s set up a call
Let’s talk about your project