← Back to Checklists

resources

Website Handover & Maintenance Checklist

34 checks

A practical guide to ensure every website handover runs smoothly, covering documentation, training, ongoing maintenance, and long-term sustainability.

A launch is not a finish. A handover fails when the client owns the site but cannot log in, cannot edit a page and does not know who to call. Settle access, documentation, training and the maintenance plan before the invoice closes.

Transfer ownership

  • Transfer the domain registration to an account the client controls.
  • Transfer DNS control, or document exactly who holds it.
  • Transfer hosting to the client’s account or billing.
  • Transfer the CMS administrator account to a named client email address.
  • Transfer the analytics, Search Console and tag manager properties.
  • Transfer the repository, or grant the client permanent read access.
  • Hand over every third-party account: email service, CDN, forms, payments.
  • Remove agency-only accounts that are no longer needed, and say which you removed.

Documentation

  • Write down where the site is hosted and how to reach support.
  • List every service the site depends on, with its renewal date and cost.
  • Document how to edit each content type, with screenshots.
  • Document the deployment process, if the client’s team will deploy.
  • Document the backup schedule and how to restore from a backup.
  • Record the design tokens, fonts and logo files, and where they live.
  • Record the decisions that are not obvious from the code.

Training

  • Run a live training session and record it.
  • Train on the tasks the client will actually do weekly, not on every feature.
  • Show how to add a page, edit content, upload an image and publish.
  • Show what not to touch, and explain what breaks if they do.
  • Give the client a test environment to practise in.
  • Agree a support window after launch for the questions that arrive late.

Security and backups

  • Confirm automatic backups run and are stored off the server.
  • Test a restore. An untested backup is a hope, not a backup.
  • Enforce strong passwords and two-factor authentication on admin accounts.
  • Remove unused accounts and unused plugins.
  • Set a schedule for CMS, plugin and dependency updates.
  • Confirm the SSL certificate renews automatically.
  • Set up uptime monitoring with an alert to a person, not to a shared inbox.

Ongoing maintenance

  • Agree what the maintenance plan covers and what it does not.
  • Set a monthly check: uptime, broken links, form submissions, backups.
  • Set a quarterly check: performance, accessibility, dependency updates, content review.
  • Set an annual review of the site against the business goals it was built for.
  • Name the person who reports a problem, and the channel they use.
  • Agree response times for a site outage and for a routine request.

Want us to run this for you?

We work through checklists like this one on every project. Book a call and we will tell you what your site fails on today.