The Website Maintenance Contract: The Five Gaps in Scope
Most maintenance contracts cover updates and backups. The failures that actually take a B2B site down are certificates, redirects and the person who left.
A standard maintenance contract covers the software. The failures that take a B2B site down are usually not the software. They are an expired certificate, a redirect map somebody cleaned up, and a tracking event that stopped firing four months ago.
None of those three is normally in scope, and none of them produces an error message. That combination is why the site is technically maintained and commercially broken at the same time.
This page sets out what a typical contract covers, the five things it leaves open, and how to test whether yours works before you need it to.
What standard scope covers, and what that is worth
Not a criticism. It is genuinely useful, and it is a narrower thing than most buyers assume.
Platform and plugin updates. Applying releases, checking nothing broke. Real value, especially where a content management system has a large dependency surface.
Backups. Taking them, storing them, retaining them for a stated period.
Uptime monitoring. Alerting when the site stops responding.
Security patching. Applying fixes when a vulnerability is disclosed in a component you use.
A support channel. Someone to contact, with a stated response time.
What all five have in common. They protect the software from becoming broken or unsafe. That is a legitimate and complete job description, and it is not the same job as protecting what your marketing depends on.
Gap one: the redirect map
The one with a documented retention period attached, and no owner.
What the platform says. That redirects should be kept for as long as possible, generally at least one year, because that period allows signals to transfer to the new addresses, including recrawling and reassigning links on other sites.
What a maintenance contract lists. Updates, backups, monitoring, patching. Rarely a redirect map, because it is a configuration rather than a component.
How it gets removed. A server cleanup. A configuration migration. A new provider taking over and rebuilding the rules from the current site rather than from history. Nobody involved knows why those hundreds of lines exist.
Why the damage is invisible. The site works perfectly afterwards. Only inbound links and old search results break, and they break for people who never arrive to complain.
The fix, which is a line of text. Name an owner for the redirect map, and record the earliest date it may be reviewed, at least twelve months from the migration that created it.
And the compounding version. Two migrations produce chains. Google supports up to ten hops but advises three or fewer. Without a maintained map, nobody knows how deep the chain is.
Four more, each with the same property: silent failure.
Certificates. An expired TLS certificate takes the entire site down, browsers refuse it loudly, and the failure date is known months in advance. It is the most avoidable outage available, and renewal ownership is usually assumed rather than assigned. Put it in scope, with a named escalation path for renewal failure.
Tracking integrity. Your form event stops firing because a template was renamed, a form vendor updated its embed, or a consent banner changed its category names. No error, no alert, and none of those changes came from your maintenance provider.
Why that one compounds. If a conversion event breaks, the advertising platform optimising toward it receives fewer signals, and delivery degrades for a real algorithmic reason caused by a measurement artefact. You will spend weeks diagnosing the campaign.
The accessibility statement. A document rather than code, so it falls outside technical scope by default. It is also, in at least one jurisdiction, the single obligation for which a private company above the revenue threshold can actually be sanctioned. Decide explicitly who writes and updates it.
Ownership continuity. Configurations, redirect rules, tracking implementations and integrations built by people who have since left. They keep running, they appear in reports, and nobody is accountable for them.
Why that last one is the root cause. Every gap above is really an ownership gap. The certificate has no owner, so nobody renews it. The redirect map has no owner, so somebody deletes it. The tracking has no owner, so nobody notices it stopped.
The failure sequence nobody plans for
Worth walking through, because it is the same sequence almost every time and it takes months.
Month zero. Someone builds a form, a tracking event, a redirect rule or an integration. It works. They know why it exists.
Month four. That person changes role, or leaves. Nothing is handed over, because nothing was written down and nothing is currently broken.
Month nine. A release renames a template, or a vendor updates an embed. The event stops firing. No error is raised anywhere.
Month ten. Conversions look lower. The advertising platform, optimising toward that event, receives fewer signals and reduces delivery. Cost per lead rises for a genuine algorithmic reason caused by a measurement artefact.
Month eleven. The campaign gets blamed. Creative is refreshed, budgets are moved, audiences are rebuilt. None of it works, because none of it is the problem.
Month thirteen. Somebody eventually submits a test form and discovers the notification never arrives.
What would have caught it at month nine. A list. Each key event, counted monthly against the previous four weeks. That is the entire control, and it costs a few minutes.
The control that catches it at month nine is a monthly list of event counts. That is the whole thing. Source : Method (2026)
How to test a contract before you need it
Four exercises, all cheap, none of which most contracts have ever been put through.
Ask for a restore, into staging, timed. Not confirmation that backups exist. An actual restore, with the duration recorded. This is the single most informative test available and it is rarely run before the day it matters.
Send yourself a lead and time the notification. This tests the form, the routing, the notification, the tracking event and the follow-up process in one action that takes two minutes.
Check the certificate expiry date yourself. Then ask who renews it and what happens if the renewal fails. If the answer takes more than a sentence, that is the finding.
Ask for the redirect map. If it cannot be produced, or if nobody can say why the rules exist, you have found the gap before it costs you.
And one question for the annual review. What broke this year that nobody noticed at the time? A provider who can answer that honestly is worth keeping. A provider who says nothing broke is not looking.
Most contracts have never been exercised this way, which is why the results are informative. Source : Method (2026)
The certificate has no owner, so nobody renews it. The map has no owner, so somebody deletes it. Source : Method (2026)
The clauses worth adding
Six additions, all short, none of which should meaningfully change the price.
The redirect map is a maintained object. Named owner, review date not earlier than twelve months after the migration that created it, and a rule that it is never rebuilt from the current site alone.
Certificate renewal is in scope, with a named escalation path if automatic renewal fails.
A monthly key-event check. Each conversion event counted against the previous four weeks, as a list, not a dashboard. Anything at zero or down by more than half gets investigated.
An annual restore test, with the duration recorded in the report.
An inventory of who owns what. Every configuration, integration and tracking implementation, with a current name against it. Reviewed when anyone leaves.
And a stated exclusion list. What the contract deliberately does not cover, so that both parties know where the boundary is. A contract that lists nothing as excluded has not been thought about.
One thing not to add. A guarantee about rankings or traffic. No provider controls those, and a contract that promises them is either misinformed or selling something else.
Standard scope protects the software: updates, backups, monitoring, patching, support. That is a complete job and a narrow one.
The redirect map is the clearest gap. Google says keep redirects generally at least a year; contracts rarely list the map as maintained.
Certificates are the most avoidable outage there is, because the failure is total and the date is known months ahead.
Tracking breaks silently, from template renames, form embed updates and consent banner changes, none of which your provider caused.
And it compounds: a broken conversion event starves the advertising platform of signals, so delivery degrades for a real reason caused by a fake one.
The accessibility statement is a document, not code, so it sits outside technical scope while being the one thing a private company can be sanctioned for in at least one jurisdiction.
Every gap is really an ownership gap, created when the person who built something leaves.
The most informative test is a timed restore into staging, which most contracts have never been put through.
Ask for a restore this month, and ask who owns the redirect map. Book a diagnostic, or see how we approach B2B websites.
Frequently asked questions
What does a standard maintenance contract usually cover?
Platform and plugin updates, backups, uptime monitoring, security patching and a support channel. All useful, and all concerned with the software rather than with what your marketing depends on.
What is the most commonly missed item?
The redirect map. Google states redirects should be kept generally at least a year, but they are rarely a maintained object, so they get removed during a cleanup by someone who does not know why they exist.
Why do certificates matter so much?
Because their failure is total and scheduled. An expired certificate takes the whole site down, browsers refuse it loudly, and the failure date is known in advance, which makes it the most avoidable outage there is.
Does maintenance cover my tracking?
Almost never. Analytics and advertising events break when a template is renamed or a form embed updates, none of which produces an error, and none of which the maintenance provider caused or watches.
Should the accessibility statement be in scope?
Worth deciding explicitly. It is a document rather than code, so it falls outside technical scope by default, while being the one accessibility obligation a private company can be sanctioned for in at least one jurisdiction.
How do I test whether the contract works?
Ask for a restore. Not whether backups exist, but a full restore into staging, timed. Most contracts have never been exercised this way and the result is usually informative.
What is the real root cause of these gaps?
Ownership. Configurations built by people who have since left keep running with nobody accountable, so nothing surfaces until it fails and nobody knows why it was there.
What should I add to the contract this week?
A named owner and review date for the redirect map, certificate renewal in scope with an escalation path, a monthly key-event check, and an annual restore test with a recorded duration.