A website maintenance plan is an ongoing schedule of technical and content tasks that keeps your site secure, live and effective. Every business with a customer-facing site needs one. If you take away one thing today, make it this: check that your backups are tested and that uptime monitoring is switched on before you worry about anything else.
TL;DR:
- Regular testing of backup restore processes is essential, with backups being recent, isolated, and verified to ensure data recovery in emergencies.
- Maintenance plans should specify clear response times for urgent issues, such as site outages or security breaches, and establish designated contacts for incident management.
- Basic or essential plans cover software updates, backups, and uptime checks, but may not provide active monitoring, which is crucial for sites handling customer data or online transactions.
- Security and compliance requirements, including unambiguous cookie consent and accessible privacy notices, are non-negotiable components of any maintenance agreement.
- Starting with a 30/60/90 day plan involves confirming backups work correctly, fixing urgent issues, and formalizing the maintenance agreement to prevent disputes and protect your site.
Table of Contents
- What a website maintenance plan covers
- A practical maintenance checklist by frequency
- Typical pricing shapes and how to read them
- Security, backups and compliance you must insist on
- A copy-and-use maintenance plan template
- Why Webnora is a practical option for small businesses
- How to start this month: a 30/60/90 day starter plan
- Get a site check from Webnora
- Sources
- FAQ
What a website maintenance plan covers
Maintenance is different from development. Development builds or redesigns your site; maintenance keeps the finished product running, safe and accurate once it is live. Confusing the two is how sites end up with neither a proper build plan nor anyone watching over them afterwards.
A solid plan works towards five goals: uptime, security, performance, legal compliance and content accuracy. Responsibility for these usually splits three ways.
- The site owner decides on content changes and approves updates.
- The hosting provider keeps servers, storage and network infrastructure running.
- The maintenance provider handles software updates, monitoring, backups and fixes.
Confusion over who owns what is one of the most common reasons small business sites drift into neglect. A written plan should say, in plain terms, who does each task and how often.
A practical maintenance checklist by frequency
Most maintenance work falls into five bands, from daily checks to an annual review. Use this as a baseline to judge an existing contract or to brief a new provider.
- Daily: automated backups, uptime checks and a quick test of any contact or order forms.
- Weekly: content management system and plugin updates, a security scan and removal of spam comments or submissions.
- Monthly: page speed tuning, a broken-link sweep and a look at analytics for traffic or conversion drops.
- Quarterly: a content and SEO review, plus spot checks against accessibility standards such as WCAG.
- Annual: domain and SSL certificate renewal, and a governance review of the plan itself against your business goals.
Backups need to be more than a tickbox. NCSC guidance for small organisations states that backups must be recent, tested and isolated from the live network to mitigate ransomware, meaning a copy you have never tried to restore is not a real safety net. Many hosts advertise "backups included" without a testable restore process, so ask for proof that a restore has actually worked, or keep an independent copy yourself.
Typical pricing shapes and how to read them
Maintenance pricing usually falls into three bands, and the difference between them is less about price and more about what happens when something breaks.
- Basic or essential plans cover software updates, backups and uptime checks, often with no active monitoring in between.
- Standard or managed plans add weekly security scans, monthly performance work and a faster response time when you report a problem.
- Fully managed plans include priority support, ongoing optimisation and strategic input, aimed at sites where downtime has a real cost.
A low-cost plan is fine for a simple brochure site with little traffic and no online transactions. It tends to fail once a site sells anything, holds customer data, or depends on search traffic for leads, because the gaps show up exactly when you cannot afford them. Watch for hidden costs too: hourly rates for anything outside the plan, emergency call-out fees, and paid add-ons for things like extra storage or form integrations that felt included at the sales stage.
Security, backups and compliance you must insist on
Three things should never be negotiable in a maintenance agreement, no matter which tier you choose.
First, backups. As above, NCSC's guidance recommends testing restores regularly, at least monthly, not just taking the copy and hoping. Second, incident response. NCSC's small business guidance on response and recovery recommends preparing a plan in advance: identify critical systems, assign shared responsibility so cover exists if one person is away, and keep a list of external contacts including your host and developer.
Preparation, not reaction, is what separates a bad day from a genuine crisis.
Third, compliance. Under UK rules, active and unambiguous consent is required before setting non-essential cookies, and a visible privacy notice is expected on any site acting as a customer channel. Webnora's own cookie policy shows one practical example of how this is documented.
Pro Tip: Ask any provider to show you a completed backup restore test, not just a backup schedule, before you sign a contract.

A copy-and-use maintenance plan template
Here are three sample tiers you can adapt or hand to a provider as a brief.
- Entry: daily backups, basic security scanning, minor content edits, 5 working day response time.
- Standard: weekly software updates, monthly performance checks, security monitoring, 24 to 48 hour response time.
- Managed: priority response, monthly optimisation, quarterly strategy review, documented incident escalation.
Whatever tier you choose, ask for these in writing:
- Response time for urgent issues (site down, security breach).
- Backup frequency and confirmation of restore testing.
- Who is contacted first in an incident, and their backup contact.
- What counts as included work versus billable extras.
A short, clear document like this avoids most of the disputes that come up later.
Why Webnora is a practical option for small businesses
A practical option for small businesses is to work with providers who build each site from scratch rather than reusing templates, with a mobile-first, SEO-ready approach designed for small business needs. Clients review and approve the finished site before any payment is made, which removes the usual risk of paying upfront for work you have not seen.
For maintenance, a good plan typically includes regular updates, monitoring and a clear point of contact, rather than a bare-bones setup that leaves gaps. If you are starting from scratch, the services page outlines how a project begins.

How to start this month: a 30/60/90 day starter plan
You do not need a perfect plan on day one, just a sequence.
In the first 30 days, confirm your backups actually restore, check your SSL certificate is valid, record emergency contacts, and switch on uptime monitoring. Between day 30 and 60, run outstanding software updates, fix any obvious broken links or errors, and set a recurring monthly slot to review analytics. By day 90, put the agreement in writing with your provider and schedule your first quarterly review.
— Ar
Get a site check from Webnora
If your site has been running without proper attention, the simplest next step is an honest check of where it stands rather than a guess. Webnora's approval-before-payment approach means you see the finished work before any money changes hands, which takes the financial risk out of getting started, whether that is a new build or a redesign of an ageing site.

Get in touch through the services page to request a tailored maintenance quote or ask about a site health check, and see completed examples on the portfolio.
FAQ
What are the 7 C's of a website?
Definitions vary across sources, but the concept generally refers to principles such as clarity, consistency, credibility, content, connectivity, customisation and communication that guide good website design. There is no single official version, so treat it as a rough framework rather than a fixed checklist.
How much does it cost to pay someone to maintain a website?
Costs depend heavily on the tier of service, ranging from basic update-only packages to fully managed plans with monitoring and priority support. Maintenance prices are not published, so the services page is the place to request a tailored quote.
What should a maintenance plan include?
At minimum, it should cover tested backups, software and security updates, uptime monitoring, performance checks and a clear incident response process with named contacts. It should also state response times and what counts as included work versus extra billable tasks.
How do I do website maintenance myself?
Start with the basics: confirm your backups can actually be restored, keep your content management system and plugins updated, and check your SSL certificate has not expired. Add a monthly habit of reviewing analytics and checking for broken links, following the NCSC's guidance on backups as a starting point for security practice.
