[ Website operations · Full playbook ]
// 09 / 20The buyer's playbook.
The working reference behind Website Maintenance Cost & Support Plans 2026: what to ask, what to watch and how to run the first 90 days.
← Back to the guide[ RFP questions ]// 01
Questions that reveal real capability.
Ask for a relevant example, the decision made, the result or learning, and the person who would own the work.
- 01Exactly what is monitored and maintained?
- 02Which updates are automatic, tested or excluded?
- 03How are severity and response/restoration targets defined?
- 04What backup, restore and disaster-recovery evidence is tested?
- 05Who owns hosting, domains, DNS, certificates and accounts?
- 06How are vulnerabilities triaged outside business hours?
- 07What change capacity and rollover rules apply?
- 08How will service transition at termination?
[ Risk ]// 02
Make failure visible before signature.
| Risk | Early warning | Control |
|---|---|---|
| Ambiguous coverage | Everything called support | Service catalogue |
| Untested backup | Restore never rehearsed | Recovery tests |
| Patch delay | No risk SLA | Vulnerability process |
| Retainer waste | Unused hours | Backlog and cadence |
| Provider lock-in | Accounts inaccessible | Client ownership |
[ Value case ]// 03
Measure outcomes—not activity.
01Availability and critical errorsBaseline ________
90-day target ________
90-day target ________
02Response and restoration timeBaseline ________
90-day target ________
90-day target ________
03Patch complianceBaseline ________
90-day target ________
90-day target ________
04Backup restore successBaseline ________
90-day target ________
90-day target ________
05Change throughputBaseline ________
90-day target ________
90-day target ________
06Recurring incident rateBaseline ________
90-day target ________
90-day target ________
[ First 90 days ]// 04
Move from evidence to operating rhythm.
01
Days 1–30
Inventory assets, risks, demand and service requirements
Exit evidenceBaseline, owners, approved requirements and risks
02
Days 31–60
Transition access, monitoring, backups, backlog and runbooks
Exit evidenceWorking outputs, evidence and decision record
03
Days 61–90
Operate reviews, test recovery and improve recurring causes
Exit evidenceMeasured result, operating owner and next backlog
[ Reference desk ]// 05
Speak the same language.
| Term | Plain-language meaning |
|---|---|
| SLA | Service-level agreement. |
| Response time | Time until support acknowledges and begins work. |
| Restoration time | Time until service is usable again. |
| RPO | Maximum acceptable data-loss period. |
| RTO | Target time to restore service. |
| Runbook | Documented operational procedure. |
[ Playbook in hand? ]