What "maintenance" should include, and what is usually missing

Maintenance is the most sold and least defined item on a web invoice. What a real scope contains, line by line, and the five things a thin contract leaves out.

3 minread 665words last updated

The short answer

“Maintenance” appears on nearly every web proposal and means something different on each one. Sometimes it means a routine that keeps the site current, secure, watched and reported on. Often it means “we will fix things if you tell us they are broken, at an hourly rate”. The word is the same; the products are opposites.

A real maintenance scope can be written as a table of tasks with cadences. If a supplier cannot produce that table, they are selling the second product.

What real maintenance includes

PartTasksCadence
CurrentDependency and platform updates, tested before going live; removal of what is no longer usedWeekly or on release
SecureSecurity headers checked, scan run and findings fixed by priority, access reviewed, two-factor enforced, certificates confirmedMonthly, scan after every change
WatchedUptime, content, forms, certificates, DNS, errors and Core Web Vitals monitored from outside, alerting a named personContinuous
RecoverableFor a site with a database: backups to a second location, restored to a test location and timed. For a statically built site: the repository with full history plus the platform’s previous deploys, with a rollback that has been triedA stated recovery route for your kind of site, and a date when it was last proven
ImprovedA change budget for small improvements, content updates and fixes found by monitoringMonthly
ReportedA one-page report with what was done, what was found, the numbers and a recommendationMonthly

The five things usually missing

  1. Monitoring that alerts a person. Many contracts mention monitoring and mean a dashboard nobody looks at. The test: who is woken up at 3 a.m. if the site goes down?
  2. Tested backups. “Backups are included” without a restore test is a hope. The test: when was one last restored, and how long did it take?
  3. Security scans on a cadence. Updates are applied; nobody checks what the site actually exposes. The test: show me last month’s scan.
  4. A change budget. Everything beyond fixing is a new quote, so small improvements never happen. The test: what is included per month beyond keeping it alive?
  5. A report you can read. Work happens invisibly, or does not, and the client cannot tell which. The test: show me last month’s report.

Why the platform decides the bill

Maintenance effort follows the platform. A static site on a modern platform has no server to patch, renews its own certificates, absorbs traffic and has few dependencies; its maintenance is a light routine. A plugin-based content system needs frequent updates that break things, a server to keep secure and a public admin to protect; its maintenance is a heavy routine or, more often, a neglected one. Choosing the first is the largest maintenance saving available.

What this means for you

Compare maintenance offers by the table, not the word. Current, secure, watched, backed up, improved, reported, each with tasks and cadences and evidence from last month. If your current arrangement cannot produce that, you have support at best, and the routine that prevents incidents is not happening.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Our hosting includes maintenance. Is that enough?

Hosting maintenance means the provider keeps their platform running. It does not update your site's dependencies, watch your forms, scan your pages, test your backups or tell you anything. Platform maintenance and site maintenance are different jobs, and the second one is usually nobody's.

How much time does real maintenance take per month?

For a business website on a modern static platform, a few hours of routine plus whatever monitoring finds, because there is no server to patch and few dependencies. For a plugin-based site, considerably more, because updates are frequent and break things. The platform choice decides the maintenance bill.

What should the monthly report contain?

What was updated, what monitoring caught and what was done about it, the security scan result, the backup test result, the speed and visibility numbers with a trend, the change budget used, and what is recommended next. One page, written for the owner, five minutes to read.