Warranty and guarantees in web contracts

What a warranty on a website or software should cover, for how long, what it cannot cover, and how to tell a real guarantee from a phrase.

3 minread 659words last updated

The short answer

A warranty on a website or software covers defects: things that were specified, delivered, and do not work as specified, fixed at no charge for a defined period after launch. That is what it can honestly cover. It cannot cover changes in what you want, changes in the world such as browser, platform or third-party updates, or results such as rankings, traffic and sales, which depend on things the supplier does not control. A real guarantee is specific: what is covered, for how long, how to report a defect, how quickly it is fixed by severity, and what happens if it is not. After the warranty period, the maintenance contract takes over, and the two should meet without a gap. Check any statutory rights that apply to your contract with an advisor; what follows is what the contractual warranty should say.

What a warranty covers and what it cannot

CoveredNot covered, and honestly cannot be
Defects against the specification and acceptance criteriaNew requirements or changes of mind
Broken functionality present at deliveryBreakage caused by third-party changes after delivery: browsers, platforms, APIs, plugins
Failures of agreed thresholds at launch: accessibility, performance, security scanResults: rankings, traffic, conversion, sales
Errors in delivered content or configuration done by the supplierContent and data supplied by you
Security vulnerabilities in the supplier’s own code known at the timeAttacks exploiting later-discovered vulnerabilities in dependencies, which maintenance covers

What a real guarantee states

  1. What is covered: defects against the specification and thresholds, named.
  2. For how long: a defined period from launch or acceptance.
  3. How to report: a channel and what information to include.
  4. Response and fix times by severity: critical, important, minor.
  5. What happens if not fixed in time: a remedy, such as credit or the right to have it fixed elsewhere at the supplier’s cost.
  6. How it meets the maintenance contract: no gap between the warranty ending and maintenance beginning.

Warranty and maintenance together

The warranty covers what was wrong at delivery; maintenance covers keeping it right as the world changes. A site launched perfectly will still need dependency updates, platform adaptations and security fixes within months, and none of that is a defect. The contract should make the hand-off explicit: warranty for a defined period, maintenance from launch or from the end of warranty, with the same supplier or with a clean hand-over if not.

What this means for you

Expect a warranty that covers defects against a written specification for a defined period, with a reporting channel, fix times by severity and a remedy, and a maintenance contract that begins where it ends. Do not expect, or accept, guarantees of rankings or sales. The value of a warranty is decided before launch by whether the specification and acceptance criteria exist, because those are what it is measured against.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

How long should a warranty last?

Long enough for defects to surface in real use: typically a few months after launch for a website or a software release, sometimes longer for complex systems. Beyond that, problems are more often caused by changes in the world than by the original work, and the maintenance contract is the right instrument. Check with an advisor for any statutory minimums that apply to your contract.

Can a supplier guarantee search rankings or sales?

No, honestly. Rankings depend on search engines and competitors; sales depend on the market and your business. A supplier can guarantee what they control: the site meets the specification, passes the agreed accessibility and performance thresholds at launch, and defects are fixed. Anyone guaranteeing rankings is guaranteeing something they do not control.

What if the supplier says a problem is not a defect?

The specification and acceptance criteria decide. If the behaviour was specified and does not work, it is a defect. If it was never specified, it is a change. This is why written scope and acceptance criteria matter before launch; they are the reference the warranty is judged against, and without them every problem becomes a negotiation.