codexier.

Pricing & Buying

Exiting a Maintenance Contract Cleanly

By CodexierPublished 4 min read

Ending a maintenance contract for a website or app is usually straightforward on paper: give notice, wait out the period, move on. The risk lies in the details. Access is held by the old supplier, backups exist only on their servers, and nobody wrote down how the deployment works. Handled in the wrong order, you end up with a site nobody can update. This guide gives the order that avoids that.

Notice periods and terms

Business maintenance contracts often run month to month with one to three months' notice, but some are fixed for a year and renew automatically. Check whether the contract says anything about exit assistance, handover or the return of data; if it does, reference that clause in your notice. If it does not, ask for a handover as part of the remaining period, and agree any extra hours in writing before they are spent.

Collecting access and backups

ItemWhat to secureWatch out for
Domain and DNSRegistrar login in your company's nameDomain registered on the supplier's account
Hosting and serverOwner or admin access, billing in your nameHosting bundled in the supplier's account
CMS or app adminYour own administrator accountOnly the supplier's personal login exists
Code repositoryOwnership or a full copy of the repository with historyCode only on the supplier's machines
BackupsA recent full backup of files and database you store yourselfBackups only on the supplier's servers
Third-party servicesAdmin in analytics, Tag Manager, email sending, CDN, app storesAccounts created with the supplier's email
LicencesPremium plugins, themes and fonts in your nameLicences tied to the supplier's agency account

If ownership is unclear, our guide on who owns your website explains the rules.

Documentation to request

  • How the site or app is deployed, and from where.
  • Environment variables and configuration, with secrets handed over securely.
  • List of integrations: what connects to what, with which account.
  • Scheduled jobs, cron tasks and background processes.
  • Known issues, workarounds and pending updates.
  • Custom code that deviates from the standard platform, and why.
  • Monitoring and alert settings, and where alerts are currently sent.

Much of this may not exist in writing. Ask for a short recorded walkthrough if that is faster; a thirty-minute screen recording is better than nothing.

Handover to the new supplier

Let the new supplier review what you have collected before the old contract ends. They can confirm that access works, that the backup can be restored and that the documentation is enough to deploy an update. If something is missing, there is still time to ask. A health audit at this point also gives a clear baseline, so the new supplier is not blamed for problems that existed before.

Verify access

The new supplier logs in to every system with their own accounts.

Test a restore

Restore the backup to a staging environment and confirm it works.

Deploy a small change

Push a harmless update through the full process, so you know it can be done.

Removing old access

  1. Remove the old supplier's user accounts in CMS, hosting, registrar and third-party tools.
  2. Revoke SSH keys, API keys and deploy tokens they created or held.
  3. Change shared passwords and move them to your own password manager.
  4. Remove their email addresses from alerts, billing and recovery settings.
  5. Transfer any remaining subscriptions and licences to your company.
  6. Confirm in writing that the supplier has deleted any copies of your personal data, as your processor agreement requires.

Removing access too early is a common mistake: a forgotten dependency breaks and nobody can fix it. Removing it too late is a security risk. Do it the day the new setup is verified. If you are changing to our monthly maintenance package, we run this handover with you; see pricing. When not to switch: if the real problem is one unresolved issue, raise it formally with your current supplier first. To plan an exit, book a free call.

Frequently asked questions

Can the old supplier refuse to hand over access?

They can make it difficult, especially if accounts are in their name. Your contract and proof of payment are your strongest tools. Most suppliers cooperate when asked clearly and in writing during the notice period.

Do we have to pay for handover help?

It depends on the contract. Some include exit assistance; otherwise it is usually billed by the hour. Agree the scope and price in writing before the work starts.

How long does a supplier handover take?

For a typical small business website, a few days of calendar time once access is available. Apps and custom systems with several integrations take longer. Start early in the notice period.

What if the supplier has already stopped responding?

Then it is a recovery rather than a handover. Start with the domain and hosting; our guide on what to do when your web agency disappeared lays out the order.

Planning to change maintenance supplier?

Tell us what you have access to today. In fifteen minutes we will draft the handover order for your site or app.

Book a free 15-minute call