Ownership & aftercare

What Happens After Launch: Website Maintenance and Costs

What a live site or app actually needs after launch, what maintenance costs in Canada, and the four things to insist on in a maintenance agreement.

Published
Length15 min read
Statusdraft — not indexed

Most launches get planned like a finish line. The website goes live, the app clears review, the final invoice is paid, and the project gets filed as done.

It isn’t done. On launch day a piece of software stopped being a deliverable and became a thing that runs: against real traffic, on infrastructure that moves underneath it, calling third-party services that have no obligation to keep working the way they did in March.

Maintenance is what keeps a well-built product working. Here’s what it consists of, what it costs, and what happens when you skip it.

The first week is still the build

The week after launch is the tail of the project. Scope it as part of the build, and budget it there too.

Start by watching real traffic. Test traffic is polite. Real users arrive on old Android phones, on café wifi, with ad blockers, from a link somebody pasted into a group chat with the tracking parameters mangled. The first week is when you find out which of your assumptions were wrong.

Read the error log daily for those first weeks, not weekly. Every deployment surfaces exceptions that never appeared in testing: a null where a field was assumed, a timezone, a payment webhook arriving twice. They’re cheap to fix while the code is still fresh in someone’s head and expensive four months later.

Then confirm the boring things actually happened. Analytics firing on the pages that matter. Transactional email arriving instead of sitting in a spam folder. The contact form reaching an inbox someone reads. Search engines allowed to index the site, because the noindex that protected the staging version has to come off, and you want to check that rather than assume it.

Last, take a backup and restore it. Not “backups are configured”. Restore one into a scratch environment and confirm you get a working system back. Until someone has done that, you don’t know whether the backup works.

What needs doing, and how often

After the first weeks, maintenance settles into a routine. It’s easier to budget and easier to delegate when you split it by how often it has to happen instead of treating it as one block of “support”.

How often What gets done What breaks if you skip it
Continuous Uptime checks, error tracking, alerts routed to a named person An outage lasts until a customer reports it
Monthly Security patches, dependency and plugin updates, certificate and credential checks, page weight and image review A known vulnerability stays open, and the site gets slower one photograph at a time
Quarterly Analytics review, failed searches, support-request patterns, unused features You keep paying to run things nobody uses, and never find the thing people wanted
Annually Domain, certificate and developer-account renewals, major OS and framework versions, accessibility and SEO audit Something with an expiry date takes the business offline on a date you did not choose

Continuously

Monitoring turns an outage into a short, contained event instead of a Monday-morning discovery. Nobody looks at the dashboard. What matters is that a person gets told automatically when the thing breaks, and that you’ve agreed in advance who that person is.

Businesses rarely look unreliable because of their uptime figures. They look unreliable because of how long the outage ran before anyone noticed.

Monthly: patches and page weight

Every application sits on a stack of other people’s code, and that code publishes vulnerabilities on its own schedule. A dependency left alone for two years doesn’t stay still. It accumulates a migration, and the bill arrives all at once, under pressure, because something finally broke. The same holds for the platform layer: CMS and plugin updates, the runtime version, the server’s operating system, and the certificate that renews automatically right up until the day it doesn’t.

Performance degrades for more ordinary reasons. Usually images. A site that launched fast carries several megabytes of unresized JPEG on a product page within a year. Sometimes it’s the database, where a query that returned in ten milliseconds against a few hundred test rows behaves very differently against a few hundred thousand real ones. Both are cheap to catch monthly and unpleasant to diagnose during a sale.

Quarterly: the review that isn’t technical

Once a quarter, someone should ask what the software is doing for the business. Which pages convert and which are dead weight. What people typed into the search box and got nothing back. Which feature that took three weeks to build is used by no one. Where support requests cluster, because clustered support requests usually point at a design problem.

In our experience this is the first thing clients drop, and it returns the most. The rest of the list protects what you already have. This is the part that makes it better.

Annually: the things with expiry dates

Domain renewals. Certificates. API credentials that expire. Apple Developer and Google Play accounts, which stop working quietly and take your app listing with them. An accessibility and SEO audit against standards that have moved since launch.

None of it is difficult. All of it is the kind of thing that takes a business offline when nobody owns it. Put each item in a calendar with a named owner.

Why the patching matters more than it used to

Skipping the monthly work used to be a slow-burning risk. It is now the most common way in.

Verizon’s 2026 Data Breach Investigations Report found that exploiting software vulnerabilities has become the single most common initial access vector in the breaches it analysed — ahead of stolen credentials — at 31% of cases. That dataset skews to larger organisations, so read the mechanism rather than the number: for most small businesses, the internet-facing software they own is the website.

The WordPress figures make the shape of it concrete, and they matter because WordPress accounts for 58.8% of the sites W3Techs finds running a known CMS. Patchstack’s State of WordPress Security in 2026 recorded 11,334 new vulnerabilities across the WordPress ecosystem during 2025, up 42% on the previous year. Ninety-one percent were in plugins — not in WordPress itself. Nearly half had no patch available on the day they were disclosed.

That inverts the advice most owners have absorbed. The platform is rarely the problem. The seven plugins somebody installed to add a booking form are the problem, and the number of them is the risk.

Sucuri’s 2023 hacked-website report, published in 2024, found 39% of the sites it cleaned were running an out-of-date CMS at the point of infection. Treat that as directional rather than definitive: it describes Sucuri’s own customer base rather than the web at large, the data behind it is three years old, and Sucuri sells malware cleanup. It points the obvious way regardless.

Roughly what it costs

Every maintenance plan is two things in one number: infrastructure, which is close to a commodity, and labour, which isn’t.

Infrastructure — domain, hosting, certificate, backups — runs roughly $100–800 a year on entry-tier hosting, and from about $1,600 on fully managed hosting. Labour is the variable half. Published Montreal maintenance plans sit at roughly $99–125 a month at the entry tier and around $995 for a plan including ten hours of work. Quebec agencies publish all-in annual figures of about $800–1,500 for a brochure site and $3,000–6,000 for e-commerce.

The single most useful thing you can do with any quote is divide the monthly fee by the hours it includes. A $99 plan with half an hour in it is about $200 an hour — you’re buying access and insurance, which is a reasonable thing to buy. A $995 plan with ten hours is under $100 an hour, which is bulk labour. Knowing which one you’re being sold tells you whether to expect availability or output.

None of these are our numbers; they’re what the Canadian market publishes, and they vary by a factor of ten for work described in almost identical words. We’ve broken the whole thing down — what’s in each half, how to compare two quotes, and where the ranges come from — in what you’re actually paying for in a website maintenance plan.

If you operate in Quebec, French is not optional

Any business carrying on activities in Quebec has to make its site available in French. Another language is permitted alongside it, provided the French version is reachable on conditions at least as favourable. French is the half you don’t get to drop, and no employee count exempts you from it. That’s a Charte de la langue française obligation, and it changes the maintenance arithmetic more than people expect at the quote stage.

It also predates Bill 96. The OQLF prosecuted a business over an English-only website and won a conviction in the Court of Québec in October 2021, months before the newer Act took effect. The fine was $600; the finding is the part that matters. What Bill 96 added was the phrase quel qu’en soit le support, regardless of medium, and an express duty to respect the customer’s right to be informed and served in French. It sharpened the obligation rather than inventing it.

The obligation doesn’t stop at the marketing pages. Section 52 covers commercial publications regardless of medium, which the OQLF reads as the whole of a business site: form labels, validation messages and confirmation screens included, at equivalent quality. Section 57 separately requires invoices, receipts and quittances to be in French, and section 55 extends that to documents attached to an adhesion contract. Transactional email isn’t named in the Act, but where it carries an invoice or a receipt it inherits the same rule. That’s the surface that quietly falls out of sync, because it’s the surface nobody looks at after launch.

Practically, every content change becomes two, every new page becomes two, and the review step doubles. Budget the ongoing content work at roughly double a single-language site, and agree at the outset who is responsible for the second language — the business, the agency, or a translator. Left unassigned, it defaults to whoever notices, which means nobody.

If you handle personal data, Loi 25 also has aftercare obligations that outlive the build. It doesn’t set a retention period. It sets a purpose test: once the purposes you collected the data for are accomplished, you destroy it or anonymise it. It also splits breach notification in two, which is the part that genuinely belongs in a contract. Your service provider has to notify your privacy officer of a confidentiality incident without delay, and you notify the Commission d’accès à l’information and the people affected where there’s a risk of serious injury. Agree who does what before there’s an incident, not during one.

If you shipped a mobile app

Mobile has a maintenance floor that web doesn’t, and you can’t opt out of it.

What you can own, and what you cannot

There’s no reason to pay somebody for work you can do yourself.

You can own: content updates, product listings, photographs if you have somewhere to resize them, social posting, review responses, and telling someone when something looks wrong. If the build was done properly, that’s exactly what the admin surface exists for and no developer should be needed for it. An agency that has to be called every time an opening hour changes has sold you something badly built.

You need a technical owner for: security patching, dependency and framework upgrades, backup verification, monitoring and incident response, performance regressions, integration and API deprecations, mobile release management, and anything touching the deployment pipeline.

Nobody does that second list enthusiastically at 9pm. It works when it’s someone’s defined job, with hours and a name against it, instead of a favour asked of whoever built the thing whenever it breaks.

What it costs to get this wrong

Statistics Canada found that 16% of Canadian businesses were hit by a cyber security incident in 2023. The number underneath it is the more useful one: what Canadian businesses spent recovering from incidents roughly doubled between 2021 and 2023, from around $600 million to $1.2 billion, with small businesses accounting for about $300 million of the 2023 figure. That’s a nominal doubling across a high-inflation period, so some of it isn’t a real increase — but not most of it. One limit is worth knowing before you use these numbers: the survey only counts businesses with ten or more employees, and small there means 10 to 49. A four-person business is outside the sample entirely.

An earlier cycle of the same survey, covering 2017, found only 7% of small businesses carried cyber liability insurance, against 24% of large ones. Coverage has broadened since. Twenty-two percent of Canadian businesses held cyber risk insurance in 2023, up from 16% in 2021. But Statistics Canada has not published a breakdown by business size since that 2017 cycle.

So whether the smallest businesses are still the least insured is something the published data no longer tells you. What it does tell you is that they absorb about a quarter of a national recovery bill that doubled in two years. That’s the argument for the boring monthly work — not that something dramatic will happen, but that when something ordinary happens, nothing absorbs it for you.

What to ask for in a maintenance agreement

If you’re arranging this with whoever built the product, insist on four things.

  1. A response time in writing, by severity. An outage and a typo are not the same request and shouldn’t have the same window. Ask what happens on a Saturday.
  2. Maintenance scoped separately from new features. Where the two share a budget, security patching loses to the next feature every single time, because the feature has someone asking for it and the patch has no one.
  3. Every account in the business’s name. Domain registrar, DNS, hosting, repository, app signing keys, store accounts. If a supplier holds these in their own name, you don’t have a maintenance arrangement. You have a supplier who can switch you off, and you want that resolved before you need it resolved.
  4. A handover clause. What you receive if you leave, and in what state. A supplier confident in the work won’t object to being asked.

The short version

Budget for the year, not for the launch. Software belongs in the same budget line as insurance and accounting, not furniture. Our own bet is that what a business gets out of software depends more on keeping it current than on what it spent building it.

Agree the schedule before you go live, name the owner, and restore one backup to prove it works.


Canaan builds software and maintains it afterwards. A maintenance plan covers security and dependency updates, CMS and platform upgrades, uptime monitoring, verified backups, content updates, performance review, and a defined response time. If something of yours is live and no one currently looks after it, talk to us before it becomes urgent.

Start a project


Sources

Cost ranges are observed minimum and maximum published list prices, not medians, collected on 22 September 2026 from eight pricing sources: three Montreal agency price lists, three host pricing pages (two of them American, quoting USD and converted at the Bank of Canada rate for 21 September 2026), Shopify’s Canadian pricing page, and the Bank of Canada daily rate itself. The agency ranges rest on those three price lists and no more. List prices are what firms advertise, not what clients pay. The full breakdown is in the companion post.

← All writing