
A website maintenance SLA should define the covered service, support hours, severity rules, response and communication targets, monitoring evidence, maintenance windows, client obligations, third-party dependencies, exclusions, reporting, and review process. It should distinguish what the agency can control from what it only coordinates.
Do not promise “resolution in two hours” for every critical incident if recovery depends on a hosting provider, registrar, payment platform, or client approval. Commit first to acknowledgement, active response, mitigation effort, escalation, and update cadence.
This guide provides operational structure, not legal advice. Have qualified counsel adapt the agreement to the parties, jurisdictions, data, insurance, tax, consumer, employment, and sector requirements.
A usable SLA answers:
An agency may use a stricter internal SLO than the contractual SLA to leave operating margin.
| Clock | Starts | Stops |
|---|---|---|
| Detection | first measurable impact | monitoring receives signal |
| Acknowledgement | valid request/alert received | ownership confirmed |
| Response | incident confirmed/declared | qualified work begins |
| Mitigation | incident declared | material impact reduced or workaround available |
| Resolution | incident declared | agreed recovery criteria met |
| Communication | update trigger | approved update sent |
State whether clocks run only during service hours or continuously, how duplicate reports are merged, and how waiting for required client action is recorded.
| Severity | Example impact | Coverage | Acknowledge | Active response | Update cadence | Resolution commitment |
|---|---|---|---|---|---|---|
| P1 | Critical journey unavailable or serious active security/data risk | 24/7 if purchased | 15 min | 30 min | 30 min | Best efforts + agreed escalation; target only if supportable |
| P2 | Major degradation or contained outage | Contract schedule | 30 min | 1 hour | 60 min | Target by service design |
| P3 | Limited non-critical failure | Business hours | 4 business hours | 1 business day | At milestones | Planned target |
| P4 | Cosmetic/improvement | Business hours | 1 business day | Scheduled | Normal workflow | Backlog/change request |
These numbers are examples. Calculate staffing, on-call cost, client criticality, vendor contracts, and historical workload before offering them.
A basic monthly availability calculation is:
availability = (measurement window - counted downtime) / measurement window × 100
The formula is useless without definitions:
For a lead-generation site, form delivery may be a more meaningful service indicator than homepage uptime alone.
# Website maintenance service level schedule
Version: [number]
Effective date: [UTC date]
Service provider: [agency legal entity]
Client: [client legal entity]
Related agreement: [reference]
## 1. Covered services
- Production websites: [URLs]
- Staging/test: [scope]
- Included components: [CMS, code, hosting coordination, DNS, CDN, monitoring]
- Critical journeys: [list and success conditions]
- Included integrations: [list]
- Excluded services: [explicit list]
## 2. Service hours
- Standard hours: [days/hours/time zone]
- On-call coverage: [scope]
- Holidays: [calendar/reference]
- Emergency reporting channel: [channel]
- Routine reporting channel: [help desk]
## 3. Severity
The parties use the P1–P4 definitions in [policy/version].
Severity is based on current impact, scope, workaround, and data/security risk.
Reclassification is recorded with timestamp and reason.
## 4. Service targets
[Insert agreed table for acknowledgement, response, updates, mitigation, resolution.]
## 5. Clock rules
- Clock starts when: [valid alert/request condition]
- Duplicate reports: [rule]
- Awaiting client/vendor: [recording rule]
- Out-of-hours P2–P4: [rule]
- Time source: [UTC/system]
## 6. Monitoring and evidence
- Source of truth: [system/check IDs]
- Measurement locations: [regions]
- Frequency and confirmation: [values]
- Retention: [value]
- Monthly evidence: [report fields]
## 7. Planned maintenance
- Standard window: [value]
- Notice: [value]
- Emergency maintenance authority: [role]
- Maximum suppression: [value]
- Post-change checks: [reference]
## 8. Client responsibilities
- Maintain authorised contacts and approvals.
- Keep vendor accounts funded and licences current unless delegated.
- Provide timely access and accurate system information.
- Notify the agency of third-party changes and campaigns.
- Protect client-controlled credentials and devices.
- Approve risk, downtime, or expenditure within [target].
## 9. Dependencies and exclusions
- Third-party providers: [treatment]
- Client or other-supplier changes: [treatment]
- Unsupported software: [treatment]
- Force majeure and legal exclusions: [counsel-reviewed clause]
- Security incident response: [separate plan/reference]
## 10. Reporting and review
- Monthly report: [date and contents]
- Incident report trigger: [criteria]
- Service review: [cadence]
- SLA change process: [process]
## 11. Remedies
[Counsel-reviewed credits, caps, exclusions, and claim process.]
Accepted by authorised representatives: [signatures/process]
Avoid the two extremes:
A practical allocation may say the agency does not control the provider's restoration time but does commit to detection, escalation, workaround assessment, evidence gathering, and client updates.
Examples include:
If the client must approve rollback but no approver can be reached, the SLA should describe the authorised fallback.
Define standard windows, notice, expected impact, approval, rollback, monitoring suppression, and validation. An unannounced production change is not automatically planned maintenance just because the engineer intended it.
Report more than a single percentage:
A store may exceed a homepage availability target while checkout fails for six peak hours. Conversely, a two-minute monitoring failure from one location may not represent customer downtime. The solution is not to abandon availability but to pair it with critical-journey indicators and explicit measurement rules.
An SLA defines commitments, measurement, responsibilities, and remedies. It cannot make failure impossible.
No. Coverage should match business criticality, staffing, price, and dependency support. Be explicit about out-of-hours treatment.
Only under clearly agreed rules, with evidence that the required action and deadline were communicated. Local counsel should review contractual treatment.
Define the source of truth. Independent external monitoring can reduce disputes, but its configuration and limitations must also be documented.
Reviewed: 8 August 2026.
Next: Critical user journey monitoring and client website inventory.
Pingvera can provide independent external evidence for selected SLA indicators. Confirm the exact service, check configuration, and retention before naming any monitoring source in a contract.
Pingvera watches whether an online business actually works — uptime, checkout, orders, domain, SSL and server — and alerts you in Telegram, email or a webhook before a customer has to tell you.
Start freeRead next: Monthly Website Maintenance Report: Template & Checklist · Web Agency Access Control Matrix Template · Accidental Noindex: How Agencies Detect It Fast · Ecommerce Unit Economics: Practical Template · Run a free site check.