In most small firms a website is treated like a building project: there is a kick-off, a stressful middle phase and a date on which everything is finished. After that, nothing happens for years. Anyone who has ever landed on the site of a business whose opening hours date back to the last refurbishment knows the result: the site is still there, but it is no longer true. This article replaces the usual appeal with a plan that has a rhythm — monthly, quarterly, yearly, each with an owner, a deadline and a stand-in. And it says plainly how differently the ongoing effort turns out, depending on how a site is technically operated.
A website is a working asset, not a project
A company van gets serviced, because nobody seriously expects it to keep running forever after purchase. A till gets reconciled, a tool inventory gets checked, a warehouse gets counted. With the website, that way of thinking usually ends on the day it goes live — even though for many firms it is the most frequently used point of contact with the market, more frequent than the shop floor and more frequent than the phone. The sheer scale shows how ordinary that address has become: the registry for the German country domain currently lists around 18.05 million .de domains (DENIC), and its 2025 annual statistics reported around 17.7 million (DENIC). Every one of those addresses is tied to a contract, to contact details and to a renewal that eventually falls due.
The difference between a project and a working asset is not a matter of wording. A project has an end date; an asset has a condition. An asset can be in good order or not, and whoever does not look at that condition regularly will learn about it from outside: through a call because the listed number no longer works, through a complaint because a 2023 price is still on the page, or through an enquiry that never arrived because the form has been going nowhere for months. Which pages that inventory should contain in the first place is covered in the article on the pages a business website needs — upkeep assumes you know your own inventory.
What this article deliberately leaves out
Condition, not an end date
A working asset is never finished, it is in a certain condition. The only question that counts: when did somebody last look, and what did they find?
Ownership, not chance
What belongs to nobody gets maintained by nobody. One named person with a fixed deadline beats any well-meant declaration of intent by a team.
Rhythm, not occasion
Anyone who only acts once something is noticed acts too late. A fixed cadence turns a series of emergencies into a short, plannable routine.
The monthly pass: the details that go stale fastest
The monthly pass covers everything that changes in day-to-day operations anyway and therefore goes wrong on the website first. In our experience it rarely takes longer than 20 minutes (project experience), provided it is worked through as a fixed list rather than as a treasure hunt. The practical trick: do not start with the home page, start with the details customers actually use — opening hours, phone number, address, prices, contact people.
- Opening hours and holidays: Are the regular hours still correct? Are company holidays, bridging days and changed hours entered for the coming month — and last month's entries removed again?
- Phone, email, address: Are all three current and identical to what appears in the imprint and in search results? Differences between those places are the most common silent error.
- Prices and terms: Is there an amount somewhere that is no longer offered in that form? Prices age faster than prose, which is why they are checked first on every pass.
- Contact people: Is the named person still with the firm, still responsible for this topic and reachable on the extension given?
- Current notices: Is a banner still running for a campaign, a trade fair or a date that has long passed?
- Skim the home page: Does the opening paragraph still describe what the business actually offers today?
With opening hours it pays to look beyond the running text. Anyone who marks their hours up in machine-readable form stores them in a dedicated structure, and search engines read exactly those values. Google's documentation describes local business markup covering opening hours, departments and reviews, and names the business name and a complete postal address as required properties, plus a phone number as the primary contact method including country and area code (Google Search Central). For seasonal or time-limited hours, the same documentation explicitly provides a validity window with a start and end date (Google Search Central). Using it means less to clean up later: time-limited hours expire by themselves instead of sitting there until somebody stumbles across them. How structured markup affects results is described in the article on structured data in search results.
The two-minute rule
Submit the form yourself — and confirm it arrived
No part of a business website fails as quietly as the contact form. It still looks the same, and after submission it still politely reports that the message has been received — it just does not land anywhere. The causes are mundane and therefore widespread: the recipient address belonged to someone who left, a spam filter now sorts the notifications out, a mailbox is full, or a forwarding rule was lost during a provider change. That is why the monthly pass needs an action that cannot be replaced by looking: submit it yourself, once.
Submit with a marker
Send a test message with the date in the subject or the message field, for example Check 03/2026. That keeps it traceable later when the last successful check took place.
Confirm arrival
Look in the real mailbox rather than trusting the success message in the browser. Open the spam folder too — form notifications end up there particularly often.
Check the reply path
Reply to the test message as if it were real. In one step that also verifies whether the sender address leads back and whether an automatic acknowledgement arrives.
A second recipient costs nothing
While you are in the form anyway, check two more things: whether all required fields still make sense, and whether the consent wording matches the current privacy notice. What else a form should do to turn a visit into an enquiry is covered in the article on setting up contact forms properly; the data protection side is described in the article on GDPR and consent.
Dead links and expired campaigns
Links die quietly. A reference to a leaflet that now lives elsewhere, to a partner page that no longer exists, or to one of your own sub-pages renamed during the last rebuild: for visitors that is a dead end, and for search engines it is a clear signal. Google's documentation states that content from URLs returning a 4xx status code is not used and that previously indexed pages returning such codes are removed (Google Search Central). Conversely, a successful 2xx status code is no assurance of indexing either (Google Search Central). A page that shows an error message but formally reports success is flagged in Search Console as a so-called soft 404 (Google Search Central).
The second perennial issue is expired campaigns. An offer that has not been valid for six months is not merely embarrassing; it can edge towards a bait offer — an advertised service that is not actually available. The German consumer advice organisation warns about exactly this situation and advises checking advertised offers against real availability (Verbraucherzentrale). For a business that means: every time-limited statement gets an expiry date in the calendar when it is created, not when somebody finally tidies up.
- Your own references first: Internal links to renamed or deleted sub-pages are the most common case and the easiest to fix.
- Outbound links by sample: References to authorities, associations, manufacturers and leaflets change without anyone telling you.
- Do not forget files: Price lists, forms and data sheets for download are links like any other — and they age faster than the text around them.
- Redirect old addresses instead of deleting them: Anyone removing a sub-page should redirect the old address to a suitable target. How to do that without losing visibility is described in the article on relaunching without ranking loss.
- Remove expired notices: Campaigns, trade fair dates, job ads and holiday notices get an end date on which they disappear.
A website does not age because it looks old, but because it claims things that are no longer true. The first is a matter of taste; the second costs orders.
Quarterly: legal pages, team and service scope
Four times a year a slightly more thorough look pays off, one that goes beyond day-to-day accuracy. It typically takes around 60 minutes (project experience) and concerns the details that go wrong rarely but fundamentally. Legal pages come first. In Germany the imprint is not only a mandatory disclosure but, for many people, the first credibility test. The consumer advice organisation puts the consumer view bluntly: a missing imprint is always a no-go (Verbraucherzentrale). The elements it expects there are a postal address, the authorised representative, an email address and, where applicable, the commercial register number (Verbraucherzentrale).
- Imprint: Check legal form, management, address, register number, VAT identification number and supervisory authority against the current paperwork.
- Privacy notice: Does it still match what the site actually does — form, embeds, reach measurement, job applications?
- Terms and conditions: The consumer advice organisation names badly translated or evidently copied terms as a warning sign for consumers (Verbraucherzentrale). Your own texts age more quietly, but just as reliably.
- Seals and awards: A seal without a verifiable link is worthless; the consumer advice organisation notes that a seal without a corresponding link may indicate a forgery (Verbraucherzentrale). Expired certificates of your own belong off the page.
- Team and responsibilities: Remove people who have left, add new ones, reconcile photos and job titles.
- Service scope: Does the firm still offer everything listed there — and conversely, is something missing that has been requested for months?
The quiet classic: the service that no longer exists
While you are going through the texts anyway, check in the same pass whether they are still understandable. Jargon creeps in over the years because it becomes self-evident internally. How to spot that and how to stop it is described in the article on writing website copy people understand. For the formal requirements of imprint and privacy notice there is a dedicated overview in the article on mandatory details in legal pages.
Yearly: domain, certificates and the credential inventory
Once a year the subject is not content but contracts, deadlines and access. The effort is roughly three hours (project experience), usually spread across several people — and it is the part of upkeep that is done least often and turns out most expensive when it is missing. The starting point is the domain. It is not property but a contract, and that contract depends on current contact details. The German registry's domain guidelines require complete and accurate information: first and last name, or the full company name including its legal form, a street address — a post office box is explicitly not sufficient — as well as an email address and a telephone number (DENIC). If the data provides obvious indications of being incorrect or incomplete, the request can be rejected (DENIC).
What happens when those details go stale is regulated in surprisingly concrete terms. If the previous provider drops out or the domain contract is terminated, the domain is not deleted immediately but temporarily administered by the registry itself (DENIC). The holder is notified by letter and then has one month to decide between a provider change, releasing the domain and a chargeable continuation of registry administration (DENIC). The decisive sentence sits right next to it: to be reachable at all, your contact details held by the registry must be up to date (DENIC). Anyone who still has the address of an accountant from ten years ago or the email of a dissolved department on file will not receive that letter — and in the worst case loses the address under which the business has been found for years. The same logic applies to technical reachability: the guidelines provide that the technical prerequisites for connecting the domain must be in place within four weeks (DENIC).
| Yearly checkpoint | Concrete question | What goes wrong without it |
|---|---|---|
| Domain contract | Is the domain registered to the business, not to a private person or a former service provider? | The address belongs to somebody else the moment you part ways. |
| Contact details at the registry | Are address, email and phone current and reachable? | Important post does not arrive; deadlines pass unnoticed. |
| Renewal dates | When do domain, hosting and mailboxes renew, and who pays? | The site goes offline because an invoice sat in the wrong mailbox. |
| Certificate | How and by whom is the security certificate renewed? | The browser warns visitors before they read the first sentence. |
| Credentials | Who has access to what, and which of them still work here? | People who left keep access; people who stayed cannot get in. |
| Backup | When was a restore last actually attempted? | The backup exists but does not work when it matters. |
The credential inventory is the least popular and most effective item on the list. It does not mean a password collection but a plain overview: which accesses exist, who holds them, what they are needed for, and what happens if that person is unavailable. Germany's Federal Office for Information Security sets out the matching rule in building block ORP.4 of the IT-Grundschutz compendium: grant rights according to necessity, follow the principle of least privilege and withdraw access when staff change roles or leave (BSI IT-Grundschutz-Kompendium, ORP.4). For a firm with eight employees that does not mean a role concept but a table with four columns — and a quarter of an hour once a year in which somebody goes through it.
Test the backup instead of only creating it
Almost every business says, when asked, that a backup exists. Far fewer can say when somebody last restored anything from it. That is precisely the difference between a backup and a way back. The BSI describes the requirements for a data backup concept in building block CON.3 of the IT-Grundschutz compendium and names, among other things, encryption of the backup data and regular restore tests (BSI IT-Grundschutz-Kompendium, CON.3). The test is the step that is almost always missing in practice — and it is the only one that answers whether the backup is worth anything at all.
Why that is worth the effort becomes clear from the wider picture. In its survey of more than 1,000 companies, the German digital association Bitkom reports that 34 percent of companies were affected by ransomware, and 15 percent of those affected paid a ransom (Bitkom, Wirtschaftsschutz 2025). A verified way back is exactly what spares a firm that decision. That size offers no protection is made clear by the BSI situation report: of 950 reported ransomware attacks in the reporting period, around 80 percent hit small and medium-sized companies (BSI, Die Lage der IT-Sicherheit in Deutschland 2025).
- Try a restore: Once a year, bring back a page or a state from the backup — not in theory but for real, with the date written down.
- Check completeness: Are content, images, form settings and legal pages included, or only part of them?
- Clarify access in an emergency: Who can reach the backup when the usual logins are unavailable, and is it stored separately from the running system?
- Measure the duration: How long does a realistic restart take — hours or days? That figure matters more than any size statistic about the backup file.
- Set the order: What has to work first? Usually reachability and a contact route, and only then the rest.
Walk through the restart in your head
For the planned case — a rebuild, a move, extended maintenance — search engine guidance is clear as well: if you have to restrict operations temporarily, keep the site online and only limit its functionality rather than removing it entirely, because "removing a site completely from Google's index is a significant change that can take quite some time to recover from" (Google Search Central). If a site has to be disabled briefly, the 503 status code is the intended route, with the explicit caveat not to use it for robots.txt, because that blocks crawling altogether (Google Search Central).
Who does it, by when, and who stands in
Most maintenance plans do not fail because of the list but because of ownership. "We look at it regularly" is not ownership, it is hope. Three decisions are enough, and they fit on half a page: one named person, one deadline per type of change, and one stand-in rule. Everything beyond that is organisational folklore.
One person, not a circle
The responsible person is named, not defined as a department. They do not have to implement anything themselves, but they notice when something is left undone and they follow up.
Deadline per change type
Price change within two working days, new contact person within a week, new service page within a month. Without a deadline, every change is equally unimportant.
Stand-in in writing
Holidays, illness and resignations are the normal case, not the exception. A stand-in needs access, knowledge of the list and permission to correct things without asking first.
One place for change requests
A single place where change requests land — a mailbox, a list, a folder. Requests raised in passing reliably disappear again.
A record with a date
After every pass, one line: date, name, what was checked, what was changed. That is not bureaucracy, it is the only way to notice gaps at all.
Access when people leave
When someone leaves, access is withdrawn rather than only having passwords changed — in line with the requirement to withdraw permissions when staff change (BSI IT-Grundschutz-Kompendium, ORP.4).
Ownership comes with an uncomfortable follow-up question: how quickly can somebody reach the site when the responsible person is unavailable? If the answer is "then we call the agency and hope they read email while on holiday", the chain is too long. For short-notice corrections — a wrong phone number, a changed opening time, a cancelled appointment — somebody inside the business should be able to act. That in turn assumes changes are possible without technical knowledge; how the path from an edit to a published page looks is shown in the overview of how XICflow works.
The ongoing effort, honestly compared
So far this has been about content upkeep. Alongside it sits a second block that usually stays invisible until it causes trouble: technical upkeep. How large that block is depends almost entirely on whether a page is generated on every request or delivered as a finished file. In the first case program code, extensions and a database run permanently, and all of it has to be kept current. How much material there is for that is shown by the BSI situation report: in the reporting period an average of 119 new software vulnerabilities per day were added, around 24 percent more than in the previous period (BSI, Die Lage der IT-Sicherheit in Deutschland 2025). In building block OPS.1.1.3 the BSI recommends assessing, prioritising and applying available updates promptly and documenting the decision in a traceable way (BSI IT-Grundschutz-Kompendium, OPS.1.1.3).
| Ongoing task | Page generated on every request | Page delivered as a static file |
|---|---|---|
| System updates | regular, with a test run after every change | not part of the delivery path |
| Extensions and add-on modules | each vendor with its own maintenance state and rhythm | no publicly running add-on modules |
| Database | backup and upkeep in addition to the files | not part of the public delivery |
| Access protection | publicly reachable login to secure permanently | editing separated from delivery |
| Certificate and delivery | with the firm or the provider, depending on the contract | included centrally in the operating model |
| Content upkeep | necessary | necessary — and the remaining main part |
The table is not a verdict on any particular setup but a cost calculation. Running a system with many extensions buys functionality and flexibility; it also takes on a permanent maintenance item that does not shrink. That this item regularly goes untended in small firms is not an insinuation: small and medium-sized companies meet on average only around 56 percent of the basic IT security requirements (BSI, Die Lage der IT-Sicherheit in Deutschland 2025). Not out of negligence, but because between jobs, sites and bookkeeping there simply is no time. What else the delivery model affects is described in the articles on PageSpeed and static delivery and on a website's attack surface; the side-by-side view of the approaches is in the comparison.
What upkeep means with XICflow
The maintenance plan on a single page
A maintenance plan longer than one page does not get used. So here is the short version, ready to print and pin to the wall. Three cadences, one name, one deadline — that is all it takes to keep a website from drifting away from reality.
- Monthly, about 20 minutes: opening hours and holidays, phone and address, prices, contact people, submit the form yourself and confirm arrival, remove expired campaigns, sample-check your own links.
- Quarterly, about 60 minutes: read through imprint, privacy notice and terms, reconcile team and responsibilities, review the service scope, refresh images and references, test redirects.
- Yearly, about three hours: check the domain contract and contact details, clarify renewal dates and payment routes, confirm certificate renewal, work through the credential inventory, restore from the backup, walk through the restart.
- Fixed permanently: one named person, one deadline per type of change, a written stand-in rule, one place for change requests and a dated record after every pass.
Anyone who keeps to this plan for a year ends up with a website that is not spectacularly different — just correct. That is unremarkable and precisely why it is valuable: customers do not notice accurate details, but they notice inaccurate ones immediately. What that looks like in practice is shown in the demos; if you would like an estimate of the upkeep effort for your specific case, a short conversation via contact is usually faster than any checklist. And if local visibility matters to you, it depends on the same details anyway — as described in the article on local visibility for small businesses.
Sources and studies