Free Website Audit: Discover what's holding your digital presence back
← Back to Checklists
resources
Website Handover & Maintenance Checklist
34 checks
A practical guide to ensure every website handover runs smoothly, covering documentation, training, ongoing maintenance, and long-term sustainability.
A launch is not a finish. A handover fails when the client owns the site but cannot log in, cannot edit a page and does not know who to call. Settle access, documentation, training and the maintenance plan before the invoice closes.
Transfer ownership
- Transfer the domain registration to an account the client controls.
- Transfer DNS control, or document exactly who holds it.
- Transfer hosting to the client’s account or billing.
- Transfer the CMS administrator account to a named client email address.
- Transfer the analytics, Search Console and tag manager properties.
- Transfer the repository, or grant the client permanent read access.
- Hand over every third-party account: email service, CDN, forms, payments.
- Remove agency-only accounts that are no longer needed, and say which you removed.
Documentation
- Write down where the site is hosted and how to reach support.
- List every service the site depends on, with its renewal date and cost.
- Document how to edit each content type, with screenshots.
- Document the deployment process, if the client’s team will deploy.
- Document the backup schedule and how to restore from a backup.
- Record the design tokens, fonts and logo files, and where they live.
- Record the decisions that are not obvious from the code.
Training
- Run a live training session and record it.
- Train on the tasks the client will actually do weekly, not on every feature.
- Show how to add a page, edit content, upload an image and publish.
- Show what not to touch, and explain what breaks if they do.
- Give the client a test environment to practise in.
- Agree a support window after launch for the questions that arrive late.
Security and backups
- Confirm automatic backups run and are stored off the server.
- Test a restore. An untested backup is a hope, not a backup.
- Enforce strong passwords and two-factor authentication on admin accounts.
- Remove unused accounts and unused plugins.
- Set a schedule for CMS, plugin and dependency updates.
- Confirm the SSL certificate renews automatically.
- Set up uptime monitoring with an alert to a person, not to a shared inbox.
Ongoing maintenance
- Agree what the maintenance plan covers and what it does not.
- Set a monthly check: uptime, broken links, form submissions, backups.
- Set a quarterly check: performance, accessibility, dependency updates, content review.
- Set an annual review of the site against the business goals it was built for.
- Name the person who reports a problem, and the channel they use.
- Agree response times for a site outage and for a routine request.
Want us to run this for you?
We work through checklists like this one on every project. Book a call and we will tell you what your site fails on today.