Most launches get planned like a finish line. The website goes live, the app clears review, the final invoice is paid, and the project gets filed as done.
It isn’t done. On launch day a piece of software stopped being a deliverable and became a thing that runs: against real traffic, on infrastructure that moves underneath it, calling third-party services that have no obligation to keep working the way they did in March.
Maintenance is what keeps a well-built product working. Here’s what it consists of, what it costs, and what happens when you skip it.
The first week is still the build
The week after launch is the tail of the project. Scope it as part of the build, and budget it there too.
Start by watching real traffic. Test traffic is polite. Real users arrive on old Android phones, on café wifi, with ad blockers, from a link somebody pasted into a group chat with the tracking parameters mangled. The first week is when you find out which of your assumptions were wrong.
Read the error log daily for those first weeks, not weekly. Every deployment surfaces exceptions that never appeared in testing: a null where a field was assumed, a timezone, a payment webhook arriving twice. They’re cheap to fix while the code is still fresh in someone’s head and expensive four months later.
Then confirm the boring things actually happened. Analytics firing on the pages that matter. Transactional email arriving instead of sitting in a spam folder. The contact form reaching an inbox someone reads. Search engines allowed to index the site, because the noindex that protected the staging version has to come off, and you want to check that rather than assume it.
Last, take a backup and restore it. Not “backups are configured”. Restore one into a scratch environment and confirm you get a working system back. Until someone has done that, you don’t know whether the backup works.
What needs doing, and how often
After the first weeks, maintenance settles into a routine. It’s easier to budget and easier to delegate when you split it by how often it has to happen instead of treating it as one block of “support”.
| How often | What gets done | What breaks if you skip it |
|---|---|---|
| Continuous | Uptime checks, error tracking, alerts routed to a named person | An outage lasts until a customer reports it |
| Monthly | Security patches, dependency and plugin updates, certificate and credential checks, page weight and image review | A known vulnerability stays open, and the site gets slower one photograph at a time |
| Quarterly | Analytics review, failed searches, support-request patterns, unused features | You keep paying to run things nobody uses, and never find the thing people wanted |
| Annually | Domain, certificate and developer-account renewals, major OS and framework versions, accessibility and SEO audit | Something with an expiry date takes the business offline on a date you did not choose |
Continuously
Monitoring turns an outage into a short, contained event instead of a Monday-morning discovery. Nobody looks at the dashboard. What matters is that a person gets told automatically when the thing breaks, and that you’ve agreed in advance who that person is.
Businesses rarely look unreliable because of their uptime figures. They look unreliable because of how long the outage ran before anyone noticed.
Monthly: patches and page weight
Every application sits on a stack of other people’s code, and that code publishes vulnerabilities on its own schedule. A dependency left alone for two years doesn’t stay still. It accumulates a migration, and the bill arrives all at once, under pressure, because something finally broke. The same holds for the platform layer: CMS and plugin updates, the runtime version, the server’s operating system, and the certificate that renews automatically right up until the day it doesn’t.
Performance degrades for more ordinary reasons. Usually images. A site that launched fast carries several megabytes of unresized JPEG on a product page within a year. Sometimes it’s the database, where a query that returned in ten milliseconds against a few hundred test rows behaves very differently against a few hundred thousand real ones. Both are cheap to catch monthly and unpleasant to diagnose during a sale.
Quarterly: the review that isn’t technical
Once a quarter, someone should ask what the software is doing for the business. Which pages convert and which are dead weight. What people typed into the search box and got nothing back. Which feature that took three weeks to build is used by no one. Where support requests cluster, because clustered support requests usually point at a design problem.
In our experience this is the first thing clients drop, and it returns the most. The rest of the list protects what you already have. This is the part that makes it better.
Annually: the things with expiry dates
Domain renewals. Certificates. API credentials that expire. Apple Developer and Google Play accounts, which stop working quietly and take your app listing with them. An accessibility and SEO audit against standards that have moved since launch.
None of it is difficult. All of it is the kind of thing that takes a business offline when nobody owns it. Put each item in a calendar with a named owner.
Why the patching matters more than it used to
Skipping the monthly work used to be a slow-burning risk. It is now the most common way in.
Verizon’s 2026 Data Breach Investigations Report found that exploiting software vulnerabilities has become the single most common initial access vector in the breaches it analysed — ahead of stolen credentials — at 31% of cases. That dataset skews to larger organisations, so read the mechanism rather than the number: for most small businesses, the internet-facing software they own is the website.
The WordPress figures make the shape of it concrete, and they matter because WordPress accounts for 58.8% of the sites W3Techs finds running a known CMS. Patchstack’s State of WordPress Security in 2026 recorded 11,334 new vulnerabilities across the WordPress ecosystem during 2025, up 42% on the previous year. Ninety-one percent were in plugins — not in WordPress itself. Nearly half had no patch available on the day they were disclosed.
That inverts the advice most owners have absorbed. The platform is rarely the problem. The seven plugins somebody installed to add a booking form are the problem, and the number of them is the risk.
Sucuri’s 2023 hacked-website report, published in 2024, found 39% of the sites it cleaned were running an out-of-date CMS at the point of infection. Treat that as directional rather than definitive: it describes Sucuri’s own customer base rather than the web at large, the data behind it is three years old, and Sucuri sells malware cleanup. It points the obvious way regardless.
Roughly what it costs
Every maintenance plan is two things in one number: infrastructure, which is close to a commodity, and labour, which isn’t.
Infrastructure — domain, hosting, certificate, backups — runs roughly $100–800 a year on entry-tier hosting, and from about $1,600 on fully managed hosting. Labour is the variable half. Published Montreal maintenance plans sit at roughly $99–125 a month at the entry tier and around $995 for a plan including ten hours of work. Quebec agencies publish all-in annual figures of about $800–1,500 for a brochure site and $3,000–6,000 for e-commerce.
The single most useful thing you can do with any quote is divide the monthly fee by the hours it includes. A $99 plan with half an hour in it is about $200 an hour — you’re buying access and insurance, which is a reasonable thing to buy. A $995 plan with ten hours is under $100 an hour, which is bulk labour. Knowing which one you’re being sold tells you whether to expect availability or output.
None of these are our numbers; they’re what the Canadian market publishes, and they vary by a factor of ten for work described in almost identical words. We’ve broken the whole thing down — what’s in each half, how to compare two quotes, and where the ranges come from — in what you’re actually paying for in a website maintenance plan.
If you operate in Quebec, French is not optional
Any business carrying on activities in Quebec has to make its site available in French. Another language is permitted alongside it, provided the French version is reachable on conditions at least as favourable. French is the half you don’t get to drop, and no employee count exempts you from it. That’s a Charte de la langue française obligation, and it changes the maintenance arithmetic more than people expect at the quote stage.
It also predates Bill 96. The OQLF prosecuted a business over an English-only website and won a conviction in the Court of Québec in October 2021, months before the newer Act took effect. The fine was $600; the finding is the part that matters. What Bill 96 added was the phrase quel qu’en soit le support, regardless of medium, and an express duty to respect the customer’s right to be informed and served in French. It sharpened the obligation rather than inventing it.
The obligation doesn’t stop at the marketing pages. Section 52 covers commercial publications regardless of medium, which the OQLF reads as the whole of a business site: form labels, validation messages and confirmation screens included, at equivalent quality. Section 57 separately requires invoices, receipts and quittances to be in French, and section 55 extends that to documents attached to an adhesion contract. Transactional email isn’t named in the Act, but where it carries an invoice or a receipt it inherits the same rule. That’s the surface that quietly falls out of sync, because it’s the surface nobody looks at after launch.
Practically, every content change becomes two, every new page becomes two, and the review step doubles. Budget the ongoing content work at roughly double a single-language site, and agree at the outset who is responsible for the second language — the business, the agency, or a translator. Left unassigned, it defaults to whoever notices, which means nobody.
If you handle personal data, Loi 25 also has aftercare obligations that outlive the build. It doesn’t set a retention period. It sets a purpose test: once the purposes you collected the data for are accomplished, you destroy it or anonymise it. It also splits breach notification in two, which is the part that genuinely belongs in a contract. Your service provider has to notify your privacy officer of a confidentiality incident without delay, and you notify the Commission d’accès à l’information and the people affected where there’s a risk of serious injury. Agree who does what before there’s an incident, not during one.
If you shipped a mobile app
Mobile has a maintenance floor that web doesn’t, and you can’t opt out of it.
- The platforms ship every year. iOS and Android release major versions annually, and each release can change permissions, background behaviour, push delivery or interface conventions. An app that hasn’t been tested against the new version breaks for a share of its users on a date you didn’t choose.
- Store policy moves. Privacy declarations and data-safety forms have to keep matching what the app actually collects, which means revisiting them every time a new SDK or analytics tool goes in.
- The two stores enforce their version floors differently. Google Play sets a target API level: every new app and every update has to target Android 16, and an app that stays below Android 15 stops reaching new users on newer devices. It isn’t removed, and existing installs keep working. Apple enforces at submission instead: anything uploaded to App Store Connect has to be built with a current Xcode and SDK, so a stale toolchain blocks your updates without touching your listing. Apple’s removal risk is a separate rule. An app not updated in three years that also falls below a minimum download threshold gets ninety days’ notice, then comes off the store.
- Framework and SDK upgrades. In a React Native codebase, the framework and the native modules under it move continuously. Staying within a version or two of current is routine work. Falling several behind turns a routine upgrade into a rewrite.
- Signing keys and certificates. The keystore is the file that proves an update came from you. Lose it, or let the distribution certificate lapse, and you cannot ship an update to your own app.
What you can own, and what you cannot
There’s no reason to pay somebody for work you can do yourself.
You can own: content updates, product listings, photographs if you have somewhere to resize them, social posting, review responses, and telling someone when something looks wrong. If the build was done properly, that’s exactly what the admin surface exists for and no developer should be needed for it. An agency that has to be called every time an opening hour changes has sold you something badly built.
You need a technical owner for: security patching, dependency and framework upgrades, backup verification, monitoring and incident response, performance regressions, integration and API deprecations, mobile release management, and anything touching the deployment pipeline.
Nobody does that second list enthusiastically at 9pm. It works when it’s someone’s defined job, with hours and a name against it, instead of a favour asked of whoever built the thing whenever it breaks.
What it costs to get this wrong
Statistics Canada found that 16% of Canadian businesses were hit by a cyber security incident in 2023. The number underneath it is the more useful one: what Canadian businesses spent recovering from incidents roughly doubled between 2021 and 2023, from around $600 million to $1.2 billion, with small businesses accounting for about $300 million of the 2023 figure. That’s a nominal doubling across a high-inflation period, so some of it isn’t a real increase — but not most of it. One limit is worth knowing before you use these numbers: the survey only counts businesses with ten or more employees, and small there means 10 to 49. A four-person business is outside the sample entirely.
An earlier cycle of the same survey, covering 2017, found only 7% of small businesses carried cyber liability insurance, against 24% of large ones. Coverage has broadened since. Twenty-two percent of Canadian businesses held cyber risk insurance in 2023, up from 16% in 2021. But Statistics Canada has not published a breakdown by business size since that 2017 cycle.
So whether the smallest businesses are still the least insured is something the published data no longer tells you. What it does tell you is that they absorb about a quarter of a national recovery bill that doubled in two years. That’s the argument for the boring monthly work — not that something dramatic will happen, but that when something ordinary happens, nothing absorbs it for you.
What to ask for in a maintenance agreement
If you’re arranging this with whoever built the product, insist on four things.
- A response time in writing, by severity. An outage and a typo are not the same request and shouldn’t have the same window. Ask what happens on a Saturday.
- Maintenance scoped separately from new features. Where the two share a budget, security patching loses to the next feature every single time, because the feature has someone asking for it and the patch has no one.
- Every account in the business’s name. Domain registrar, DNS, hosting, repository, app signing keys, store accounts. If a supplier holds these in their own name, you don’t have a maintenance arrangement. You have a supplier who can switch you off, and you want that resolved before you need it resolved.
- A handover clause. What you receive if you leave, and in what state. A supplier confident in the work won’t object to being asked.
The short version
Budget for the year, not for the launch. Software belongs in the same budget line as insurance and accounting, not furniture. Our own bet is that what a business gets out of software depends more on keeping it current than on what it spent building it.
Agree the schedule before you go live, name the owner, and restore one backup to prove it works.
Canaan builds software and maintains it afterwards. A maintenance plan covers security and dependency updates, CMS and platform upgrades, uptime monitoring, verified backups, content updates, performance review, and a defined response time. If something of yours is live and no one currently looks after it, talk to us before it becomes urgent.
Sources
- Verizon, 2026 Data Breach Investigations Report
- Patchstack, State of WordPress Security in 2026, published February 2026
- Sucuri / GoDaddy, 2023 Hacked Website & Malware Threat Report, published June 2024, covering calendar year 2023
- Statistics Canada, Impact of cybercrime on Canadian businesses, 2023, released 21 October 2024. Covers businesses with ten or more employees; the small-business band is 10 to 49 employees
- Statistics Canada, Impact of cybercrime on Canadian businesses, 2017, released 15 October 2018. Source of the 7% and 24% cyber liability insurance figures, which are for reference year 2017; no size breakdown has been published in later cycles
- W3Techs, Usage statistics and market share of WordPress, continuously updated, retrieved September 2026
- Office québécois de la langue française, Langue du commerce et des affaires, retrieved September 2026. Source for sections 52, 55 and 57 of the Charte de la langue française (RLRQ c. C-11); the words quel qu’en soit le support were added to section 52 by the Act respecting French, the official and common language of Québec, in force 1 June 2022, and the section 55 rule on documents attached to an adhesion contract took effect 1 June 2023
- Court of Québec, 15 October 2021: conviction of Dress2impress on an Office québécois de la langue française prosecution under section 52 of the Charte de la langue française for an English-only business website; fine $600. No public judgment URL was located at the time of writing
- Commission d’accès à l’information du Québec, Incidents de confidentialité et mesures de sécurité, retrieved September 2026. Two-step notification is sections 18.3 and 3.5 of the Act respecting the protection of personal information in the private sector (RLRQ c. P-39.1); destruction or anonymisation once the purposes of collection are accomplished is section 23 of the same Act
- Google Play, Target API level requirements for Google Play apps, retrieved September 2026. Android 16 (API 36) for new apps and all updates as of the 31 August 2026 deadline; Android 15 (API 35) or higher to stay available to new users on devices running a newer Android than the app targets
- Apple Developer, Upcoming requirements, retrieved September 2026. Since 28 April 2026, App Store Connect uploads must be built with Xcode 26 and the iOS 26 SDK or later
- Apple Developer, App Store Improvements, retrieved September 2026. An app not updated in three years and below a minimum download threshold over a rolling twelve months is flagged, the developer has 90 days to ship an update, and a removed app keeps working for users who already have it and can be reinstated
Cost ranges are observed minimum and maximum published list prices, not medians, collected on 22 September 2026 from eight pricing sources: three Montreal agency price lists, three host pricing pages (two of them American, quoting USD and converted at the Bank of Canada rate for 21 September 2026), Shopify’s Canadian pricing page, and the Bank of Canada daily rate itself. The agency ranges rest on those three price lists and no more. List prices are what firms advertise, not what clients pay. The full breakdown is in the companion post.