What should a website care plan cover?
A care plan should cover seven things in writing: updates, backups with restore tests, monitoring, security patches, a set amount of small changes, response times, and reporting. If a plan does not name each one, you do not know what you are paying for. Plans that say only "maintenance and support" or "peace of mind" are the ones that lead to arguments when something breaks.
This post is written from how we think a plan should be built. It applies to a plan from anyone, including us. The questions at the end work the same way with any provider.
What does each part mean in practice?
Updates
Every site depends on software it did not write: the framework, the content system, libraries, the server's operating system and the database. These get new versions, and old versions stop being supported.
What to expect in writing: which components are updated, how often, and how an update is tested before it reaches the live site. A good answer includes a separate staging copy where the update is tried first. We work with separate staging and production environments for that reason.
Backups, with restore tests
Ask three things: what is backed up (database, uploaded files, configuration), how often, and where the copies are kept. CISA recommends protecting backups with encryption and keeping offline or off-site copies, so one failure does not take out both the site and its backups.
Then ask the question most plans skip: when did you last restore one? CISA advises testing the backup procedure so a team can restore data both fully and partially, and so you can roll back at least seven days if needed. A written promise of "daily backups" without restore tests is half a promise. A good plan names how often a restore is tested and gives you the result.
Monitoring
Someone or something should notice a problem before your customers do. That usually means:
- an uptime check that requests your site at a regular interval and alerts a person
- error reporting for the application
- a check on certificates and domains expiring, since an expired certificate shows visitors a warning page
- disk space and server health on a server you host
The plan should say who gets the alert, and during which hours they act on it.
Security patches
Security patches are updates that cannot wait for the next scheduled cycle. The plan should say how you are told about a serious vulnerability in something your site uses and how quickly the provider acts. It should also say what is not promised: a provider can patch what it knows about, and cannot guarantee that nothing will ever happen.
Small changes
Text edits, a new image, a changed form field, a new page of an existing type. Ask how many hours or requests are included per month, what counts as "small", and what happens when you go over: does it roll over, is it billed, is it declined? A vague "reasonable changes" is where disagreements start.
Response times
A response time is how long until someone starts, not how long until it is fixed. A good plan separates severity: site down or checkout broken, something degraded, a question. It states hours of coverage and time zone. If a provider will not commit to numbers, treat that as the answer.
Reporting
You should get a short written report on a regular schedule: what was updated, what was found, what was restored or tested, what changed on request, and what the provider recommends next. The report is the proof the plan is working. If you never see one, you cannot tell a working plan from an unused one.
What should a care plan not be sold as?
- A guarantee against hacking or downtime. Nobody can sell that honestly.
- Unlimited changes. Unlimited work is not a thing; it ends in a limit nobody wrote down.
- A replacement for a project. New features, redesigns, new integrations and big content migrations are separate work with their own scope.
- A fix for an unmaintained build. If the site is years behind on updates, expect a one-off catch-up job before a care plan can begin. A provider who says it is all included may be setting up a dispute later.
- A way to keep you from leaving. You should be able to end the plan and keep the code, the content and the access. Our clients own their code, and we think any care plan should be built on that.
- A warranty. A warranty covers defects in what was delivered. A care plan covers ongoing work. They should be two separate lines.
Which questions should you ask any provider?
Use this as a checklist before you sign anything:
- What exactly is updated, and how often?
- Is there a staging copy where updates are tested first?
- What is backed up, how often, how long are copies kept, and where?
- When was a restore last tested, and can you see the result?
- What is monitored, who is alerted, and during which hours?
- How are security issues handled, and how fast do you act?
- How many small changes are included, and what is "small"?
- What are the response times, split by severity?
- What does the report contain, and how often do I get it?
- What is not included, and how is that work quoted?
- If I end the plan, what do I keep: code, content, hosting access, domain, backups?
- Who do I contact, and what happens when that person is away?
If an answer is vague, ask for it in writing. A provider who is comfortable with the work will have the answers ready.
When this is not for you
- If your site is a single static page that you rarely change and have no data on it, a care plan may be more than you need. A yearly check may be enough.
- If you manage your own hosting and updates and have someone in-house who does it, you may only need on-demand help.
- If the site was built by someone else on a platform we do not work with, we may not be the right provider for its care. We will tell you.
- If you expect a care plan to include new features every month, it is the wrong product. That is project work.
What should you do next?
If you already have a plan, run the twelve questions against it and see how many answers are in writing. If you do not, bring your site and we will tell you plainly what it needs and what it does not. You can book a free call and we will go through it with you.



