Three months after launch the team photo still shows someone who left, the prices are last year’s, and the privacy policy has not been touched since the day it was generated. Nobody noticed, because nobody looked. The industry sells maintenance as security patches, and the patches were fine the whole time.
What actually goes out of date?
Five things go out of date, and all of them are non-technical: whether the company information is still correct, whether the copy still matches how you position yourself, whether the images are still relevant, whether the team page is current, and whether the legal material is right. On the sites I run I go through that list at least once every three months.
| What to check | What goes wrong | The two-minute version |
|---|---|---|
| Company information | Address, phone number, opening hours, bank details and VAT number drift after any change | Read your imprint and contact page against reality, out loud |
| Copy against positioning | You changed what you sell. The homepage still sells the old thing | Read the first screen and ask whether you would say that on a call today |
| Images | Old premises, discontinued products, people who left, a stock photo you have gone off | Scroll the site on your phone and stop at every picture |
| Team page | Someone left months ago and is still smiling at visitors | Compare the page against your payroll |
| Legal pages | Imprint, privacy policy and terms fall behind while you change nothing | Check them against the current legal duties for an Austrian business website |
The team page is the embarrassing row, the legal pages are the expensive one. The copy row does the quietest damage. A business changes what it sells long before it changes its homepage, nobody schedules the catch-up, and a year later the site is describing a company that no longer exists.
Does the technical side matter at all?
It does, and it is the half you can hand to someone else, because the work is the same every month. Updates, backups, uptime checks and certificates run on a schedule, and somebody else can hold that schedule. Included in an ongoing plan, it just happens. Bought as a separate retainer, it is the first line cut when budgets tighten.
Patchstack’s State of WordPress Security in 2026 counted 11,334 new vulnerabilities in the WordPress ecosystem during 2025, a 42% increase on the year before, and found that 91% of them sat in plugins and 9% in themes, with only six reported in the WordPress core. If your site runs on WordPress, that plugin layer is the exposure, and the 30-plugin backdoor attack is what it looks like in practice. It is one reason businesses start looking at WordPress alternatives when a rebuild comes round.
Does accessibility stop being your problem once the site is live?
No. Austria’s Barrierefreiheitsgesetz has applied since 28 June 2025, and for a service in scope § 14 (3) BaFG asks for suitable procedures so the accessibility requirements are met at all times, not on launch day. The same paragraph says changes to the harmonised standards have to be taken into account. That is upkeep, written into the statute.
Two details worth having straight:
- The law names no conformance level. WKO describes the BaFG as working through a presumption: a site that complies with the European standards is taken to be accessible. The statute itself never names a level. The standard in question is currently EN 301 549, which in turn references WCAG 2.1, and WKO recommends already working to the newer WCAG 2.2. We build to Levels A and AA as a professional bar.
- You report yourself. Under § 14 (4) BaFG, if you are in scope and your service does not meet the requirements, you have to take corrective measures and inform the Sozialministeriumservice without delay. Nobody has to catch you first.
Because the standards keep developing, and because whether a service still meets them has to be re-evaluated at least every five years, WKO’s own conclusion is that accessibility on the web is better treated as a running process. Whether the law reaches your site at all is a separate question, and most microenterprises are outside it. We worked that through in does my business website need to be accessible.
What breaks accessibility after launch is ordinary content work:
- An image uploaded without a text alternative
- A new PDF that is a scan of a printed page
- A button in a fresh brand colour that no longer has enough contrast
- A form field added without a label
- A heading faked with large bold text instead of a real heading
Every one of those arrives through someone doing their job and not thinking about accessibility. That puts it on the quarterly list.
The bill that arrives in year two
The domain renews. The card on file has expired. The person who set up the DNS is a freelancer you last spoke to in January.
In every project I have taken over, collecting the account data for domain, DNS and the rest was the painful part. The reason is structural. A password manager gives logins a shape and everyone uses it. For the ownership of a domain there is nothing equivalent, so the information ends up spread across an old email, a colleague’s browser and a single invoice.
Write these five down once, in a document that lives outside anyone’s inbox:
- Which registrar holds the domain, and whether your business is the registered holder
- Where the DNS is run, and who can change a record
- Who pays the renewal, and on which card
- Where the source code lives
- Whose account the CMS, the analytics and the contact form destination sit under
Who has access to your website works through the full register with the question of who should hold each entry, and DNS, domains and email explains what the pieces actually do.
What to do this week
- Put a recurring twenty-minute entry in your calendar, once a quarter.
- Walk the five content rows above with the site open on your phone.
- Write the domain and access list into one shared document.
- If a visitor can book, buy or subscribe on your site, work out whether the accessibility duty reaches you.
All of that is content and truth, and none of it happens unless it is somebody’s job every month. The technical half already is, under an ongoing plan. You can see what that covers in our plans and pricing.