Exiting a Maintenance Contract Cleanly
By CodexierPublished 4 min read
Ending a maintenance contract for a website or app is usually straightforward on paper: give notice, wait out the period, move on. The risk lies in the details. Access is held by the old supplier, backups exist only on their servers, and nobody wrote down how the deployment works. Handled in the wrong order, you end up with a site nobody can update. This guide gives the order that avoids that.
Notice periods and terms
Business maintenance contracts often run month to month with one to three months' notice, but some are fixed for a year and renew automatically. Check whether the contract says anything about exit assistance, handover or the return of data; if it does, reference that clause in your notice. If it does not, ask for a handover as part of the remaining period, and agree any extra hours in writing before they are spent.
Collecting access and backups
| Item | What to secure | Watch out for |
|---|---|---|
| Domain and DNS | Registrar login in your company's name | Domain registered on the supplier's account |
| Hosting and server | Owner or admin access, billing in your name | Hosting bundled in the supplier's account |
| CMS or app admin | Your own administrator account | Only the supplier's personal login exists |
| Code repository | Ownership or a full copy of the repository with history | Code only on the supplier's machines |
| Backups | A recent full backup of files and database you store yourself | Backups only on the supplier's servers |
| Third-party services | Admin in analytics, Tag Manager, email sending, CDN, app stores | Accounts created with the supplier's email |
| Licences | Premium plugins, themes and fonts in your name | Licences tied to the supplier's agency account |
If ownership is unclear, our guide on who owns your website explains the rules.
Documentation to request
- How the site or app is deployed, and from where.
- Environment variables and configuration, with secrets handed over securely.
- List of integrations: what connects to what, with which account.
- Scheduled jobs, cron tasks and background processes.
- Known issues, workarounds and pending updates.
- Custom code that deviates from the standard platform, and why.
- Monitoring and alert settings, and where alerts are currently sent.
Much of this may not exist in writing. Ask for a short recorded walkthrough if that is faster; a thirty-minute screen recording is better than nothing.
Handover to the new supplier
Let the new supplier review what you have collected before the old contract ends. They can confirm that access works, that the backup can be restored and that the documentation is enough to deploy an update. If something is missing, there is still time to ask. A health audit at this point also gives a clear baseline, so the new supplier is not blamed for problems that existed before.
Verify access
The new supplier logs in to every system with their own accounts.
Test a restore
Restore the backup to a staging environment and confirm it works.
Deploy a small change
Push a harmless update through the full process, so you know it can be done.
Removing old access
- Remove the old supplier's user accounts in CMS, hosting, registrar and third-party tools.
- Revoke SSH keys, API keys and deploy tokens they created or held.
- Change shared passwords and move them to your own password manager.
- Remove their email addresses from alerts, billing and recovery settings.
- Transfer any remaining subscriptions and licences to your company.
- Confirm in writing that the supplier has deleted any copies of your personal data, as your processor agreement requires.
Removing access too early is a common mistake: a forgotten dependency breaks and nobody can fix it. Removing it too late is a security risk. Do it the day the new setup is verified. If you are changing to our monthly maintenance package, we run this handover with you; see pricing. When not to switch: if the real problem is one unresolved issue, raise it formally with your current supplier first. To plan an exit, book a free call.
Frequently asked questions
Can the old supplier refuse to hand over access?
They can make it difficult, especially if accounts are in their name. Your contract and proof of payment are your strongest tools. Most suppliers cooperate when asked clearly and in writing during the notice period.
Do we have to pay for handover help?
It depends on the contract. Some include exit assistance; otherwise it is usually billed by the hour. Agree the scope and price in writing before the work starts.
How long does a supplier handover take?
For a typical small business website, a few days of calendar time once access is available. Apps and custom systems with several integrations take longer. Start early in the notice period.
What if the supplier has already stopped responding?
Then it is a recovery rather than a handover. Start with the domain and hosting; our guide on what to do when your web agency disappeared lays out the order.
Planning to change maintenance supplier?
Tell us what you have access to today. In fifteen minutes we will draft the handover order for your site or app.
Book a free 15-minute call