Support contracts for websites and software: what to look for

The support contract decides what happens after launch. Eight terms that count, clauses that favour the supplier, and what fair looks like.

4 minread 798words last updated

The short answer

A support contract decides what happens after launch, which is when the site or software actually matters. Judge it on eight terms: what is covered, severity levels and response times, the hours those apply, what is excluded, how changes are handled, what monitoring and reporting are included, how you exit and what hand-over includes, and the price with what can change it. Read for the clauses that quietly favour the supplier: vague coverage, critical issues answered only in business hours, auto-renewal with long notice, and exit terms that leave you without access. Fair contracts exist, and they are not hard to recognise.

The eight terms

TermWhat to look forThe quiet trap
1. CoverageA specific list: hosting, DNS, code, integrations, content changes, security, performance”Support for the website” with no list
2. Severity and responseA table: critical, important, standard, planned, each with a response time and a resolution targetA single “we aim to respond within one business day”
3. HoursHours that match what an outage costs you: monitoring at any hour in every case, and a person outside business hours where downtime costs money immediatelyHours chosen by the supplier rather than by your exposure, with no severity table to say which is which
4. ExclusionsNamed and reasonable: new features, third-party outages, content writingExclusions broad enough to cover anything that goes wrong
5. ChangesA monthly change budget or a clear rate, with a request and approval processEvery change a separate quote, or unlimited changes that are never done
6. Monitoring and reportingUptime, errors, security and performance monitored; a monthly report of incidents, changes and metricsNo monitoring; you find out from customers
7. Exit and hand-overNotice period of one to three months; documented hand-over included; everything already in your nameTwelve months, auto-renewal, hand-over charged extra, accounts in the supplier’s name
8. PriceA fixed monthly fee and a statement of what changes itIndexed increases with no ceiling, or a low fee with everything billed on top

What fair looks like

  1. A written severity table with response and resolution targets, and on-call coverage for critical issues.
  2. Monitoring included, with alerts that go to the supplier before you notice.
  3. A monthly report showing incidents with times, changes made, and metrics: uptime, speed, security posture.
  4. Preventive maintenance listed: updates, backup tests, dependency reviews, performance checks, on a stated cadence.
  5. A change budget you can see being used, with anything beyond it quoted before work starts.
  6. Everything in your name from day one, so exit is a hand-over of knowledge, not of access.
  7. Exit at one to three months’ notice with a documented hand-over included.

Matching the contract to what you run

A static business website needs a lighter contract than a plugin-based site or a piece of custom software: less reactive support, the same monitoring, ownership and exit terms. Software with a database, integrations and users needs more: staging, release procedures, a larger change budget and a clear line on what counts as a bug versus a new feature. The eight terms apply to both; the numbers under them differ.

What this means for you

Read the support contract for the eight terms before you sign, not after the first incident. Insist on the severity table, monitoring, a monthly report, everything in your name and a short exit with hand-over included. Distinguish maintenance from support and make sure both are there. A fair contract is boring, specific and easy to leave, and that is exactly why you will not want to.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

What is the difference between support and maintenance?

Support reacts: something is broken or unclear and someone fixes or answers. Maintenance prevents: updates, monitoring, backups tested, security reviewed, performance watched. A contract that offers only support leaves the preventive work undone until it becomes an incident. Ask for both, described separately.

Is a support contract worth it for a static website?

A static site needs less reactive support than a plugin-based one, which is part of its appeal, but it still needs monitoring, dependency updates, backups, content changes and someone to call. A lighter contract, yes; none at all leaves the domain, DNS and hosting with no owner when something goes wrong.

What notice period is reasonable?

One to three months, in either direction, with a documented hand-over included in the price. Twelve-month lock-ins with long notice periods and hand-over charged separately exist to make leaving painful. A supplier confident in their service does not need them.