Skip to content

What should managed website hosting actually include?

Learn what managed hosting should cover: monitoring, tested backups, security, support, ownership, and the limits every small business plan should state.

Updated August 27, 2026

Managed website hosting should mean that a named provider takes responsibility for defined parts of keeping your website available, recoverable, secure and supported after launch. The caveat matters more than the definition: the contract matters more than the label.

“Managed” is not a standard package. One company may manage the server while leaving the website to you. Another may update a WordPress site but exclude plugin conflicts. An agency may watch the whole customer journey and make small content edits. Before comparing monthly prices, compare responsibilities.

Why “managed” can mean five different things

Current provider documents make the difference visible. Squarespace describes hosting as part of its all-in-one website subscription. SiteGround describes managed hosting in terms of infrastructure, security, backups and WordPress tools, but its support scope excludes many problems in the website itself. Kinsta provides WordPress-specific hosting tools and support while explicitly saying that development remains the customer’s responsibility. (Squarespace, SiteGround, Kinsta)

That comparison leads to a practical conclusion: “managed” tells you that some work has moved to the provider, but not which work. The written scope has to name the system being managed, the actions included and the limits of support.

The table below shows typical positions, not promises. Any provider can define its service differently.

Hosting model What is usually managed What you usually still manage Portability Best fit
Basic shared hosting Server hardware, network and a control panel Website software, updates, troubleshooting, security response and content Often portable, but migration is your job A simple site with someone technical available
Hosted website builder Platform, hosting, builder updates and core infrastructure Content, design choices, account access and many third-party integrations Content may export; the exact site often cannot move unchanged A straightforward do-it-yourself marketing site
Managed CMS hosting Infrastructure plus CMS-specific caching, backups, tools and some updates Custom code, premium licenses, compatibility problems and work outside support scope Usually portable with an application and database export WordPress or another supported CMS
Agency-managed hosting Infrastructure plus an agreed layer of website monitoring, maintenance and human support Anything excluded by the care plan, often larger edits, campaigns and new features Depends on ownership and handover terms A small business that wants one accountable contact
Managed custom application hosting Application infrastructure, deployment, logs, backups and operational response as specifically designed Product decisions, feature development and third-party business systems unless added Depends on source, data and infrastructure documentation Booking systems, portals, marketplaces and business-critical tools

The higher fee is not necessarily buying “more hosting.” It may be buying human attention, application knowledge and a shorter path from alert to action. A low-cost plan can still be the right choice if you understand and can cover the work left with you.

Start with the kind of website you have

Equal-looking websites can have very different operational needs.

Static marketing sites

A static site serves prebuilt pages and assets without generating each page from a database. There may be less software exposed to the internet and less changing data to protect. Management should still define deployments, certificate renewal, DNS, uptime checks, form delivery, source-code access and rollback. “Daily database backups” add no value if there is no database; a recoverable source repository and known deployment process do.

CMS sites

A content management system adds an application, database, user accounts, themes or templates, plugins and media. A credible plan should say who inventories components, applies updates, checks compatibility, makes a pre-change backup and rolls back a failed release. OWASP’s current Top 10 includes security misconfiguration, software supply-chain failures, and logging and alerting failures among major web-application risks. That does not make every update an emergency, but it does make an ongoing update and monitoring process part of real management. (OWASP Top 10:2025)

Ecommerce sites

An online store carries changing orders, customer records, inventory and payment integrations. Its acceptable data-loss window may be much shorter than a brochure site’s. Monitoring should cover more than the homepage: product pages, cart behavior, checkout handoff, payment notifications and order confirmation may all matter. The plan must also separate the host’s role from the ecommerce platform, payment processor, tax service and fulfillment system.

Custom applications

A booking system, portal or internal tool can include databases, background jobs, APIs, user permissions, queues and integrations. It needs application-aware logging, deployment rollback, database migration procedures and checks for its critical workflows. Calling the server “managed” does not automatically make the application managed.

What a managed hosting plan should define

Monitoring: what is checked, how often and who responds?

Basic uptime monitoring sends a request to a URL and checks for an expected status or piece of content. Google Cloud’s documentation notes that standard uptime checks do not load page assets or run JavaScript. That means a green check can coexist with a broken menu, form or booking flow. (Google Cloud)

Ask for three layers where the site warrants them:

  1. Infrastructure availability: Can the network, hosting platform and origin respond?
  2. Application health: Does the correct page load with expected content, without a known application error?
  3. Business transaction health: Can a visitor complete the important journey, such as submitting an enquiry or reaching booking confirmation?

The plan should name check frequency, alert channels, coverage hours, the person responsible for triage and what happens after an alert. “Monitored” can mean an email is sent to you. It can also mean a person investigates. Those are different services.

Backups: what is copied, where and for how long?

A backup is not a plan until somebody has tested the restore.

A backup job can report success while omitting the database, media, configuration, encryption key or recent transaction you actually need. Define what is backed up, frequency, retention, storage location and whether copies are isolated from the live environment. Then define restoration: who starts it, what approval is required, the expected recovery window and how a restored site is validated.

This is a normal operational discipline, not disaster theater. AWS offers scheduled restore testing specifically to evaluate whether recovery points can be restored and how long the job takes. (AWS Backup) A small website may need a simpler manual test, but it still needs evidence that files, data, configuration and key workflows come back together.

Updates: installation is not the same as maintenance

The agreement should distinguish operating-system and platform patches from CMS core, themes, plugins, libraries and custom code. It should also state whether updates are automatic or reviewed, whether they are tested away from the live site, and who handles a compatibility failure.

CISA advises regular patching of software and internet-facing systems, while noting that managed cloud services reduce rather than eliminate maintenance roles. (CISA #StopRansomware Guide) The useful promise is therefore not “we update everything.” It is “we track the components in scope, assess relevant updates, apply them through a defined process and have a rollback path.”

Security: prevention, detection and response are separate

TLS, a web application firewall, DDoS mitigation and software updates are controls, not a guarantee that no incident will occur. Cloudflare describes DDoS mitigation as traffic analysis and rules that identify and act on attack patterns; that is narrower than repairing a compromised CMS or investigating stolen credentials. (Cloudflare)

Ask who handles suspicious traffic, malware, a vulnerable dependency, unauthorized admin access and a data incident. Does the provider only notify you, or also contain the problem, restore service, rotate credentials and preserve logs? CISA recommends MFA for administrative access and describes logging and monitoring as a way to detect unusual behavior and support faster response. (CISA on MFA, CISA on logging)

Certificates, CDN, DDoS protection and DNS

These terms are related, but not interchangeable.

  • TLS certificates support encrypted connections and need correct issuance, configuration and renewal. Ask whether both visitor-to-edge and edge-to-origin connections are protected where a proxy is used. Cloudflare’s documentation distinguishes the edge certificate presented to visitors from the rest of the connection. (Cloudflare SSL/TLS)
  • A CDN stores eligible content in distributed locations closer to visitors, which can reduce origin load and improve delivery. It does not by itself prove the application is healthy. (Cloudflare Cache)
  • DDoS mitigation attempts to identify and limit abusive traffic. It does not replace application security, access control or incident response.
  • DNS directs domains and subdomains to the services that answer for them. A wrong record can take down the website or email, so the plan should name who controls changes and keeps an export. (Cloudflare DNS)

The business should retain access to its domain registrar and DNS account even when a provider administers them.

Support, content edits and analytics

“Support included” needs a channel, coverage window and response target. Ask whether the target is an acknowledgement or a resolution, and how urgent business-impacting incidents are escalated. A promise of 24/7 infrastructure support is not the same as 24/7 access to the developer who understands your website.

Content changes need their own allowance: what counts as “small,” how much time is included, whether unused time rolls over and how larger requests are priced. Analytics also needs boundaries. Installation, consent configuration, dashboard access, reporting and interpretation are different tasks. Ideally, the business owns the analytics and search accounts and grants access to the provider.

What usually is not included

Unless the agreement says otherwise, managed hosting usually does not include:

  • Writing new pages, producing photography or ongoing content publishing
  • Ongoing SEO strategy, keyword research, local listings or link acquisition
  • Major design changes, new integrations or feature development
  • Third-party subscriptions for a CMS plugin, booking platform, email service, payment processor, analytics product or stock assets
  • Repairing every failure inside a third-party service
  • Compliance advice or a guarantee against outages and security incidents

Hosting, website build costs, maintenance and growth work overlap, but they are not the same budget. If a plan includes any of the items above, get the allowance and exclusions in writing.

Copyable request-for-clarification checklist

Send this with any hosting quote:

  • What exact website, environments and third-party services are in scope?
  • What do you monitor: infrastructure, pages, errors, forms, bookings or checkout?
  • How often are checks run, who receives alerts and who takes action?
  • What is backed up: code, files, media, database, configuration and DNS?
  • How often are backups made, where are they stored and how long are they retained?
  • When was the restore process last tested, and what did the test validate?
  • What recovery time and maximum data-loss window is the plan designed for?
  • Which platform, CMS, plugin, theme and dependency updates are included?
  • Are updates tested before release, and who fixes or rolls back a failed update?
  • What security controls are included, and what happens when an incident is suspected?
  • Who manages TLS certificates, renewals, CDN, DDoS settings and DNS changes?
  • Which support channels and hours apply? Are response and resolution targets different?
  • Are content edits included? If so, what limit and what counts as an edit?
  • Are analytics setup, consent, reporting or interpretation included?
  • Who owns the domain, source code, content, data, analytics and vendor accounts?
  • What is the cancellation notice, and are there termination, migration or export fees?
  • What export is provided, in what format, and how long is transition help available?
  • What third-party fees or licenses are billed separately?

Exit and handover should be designed before you sign

A usable exit is more than a ZIP file. The handover should match the system and include the current source code, uploaded media, a database export where applicable, build and deployment instructions, environment-variable names, redirect rules, DNS records and a list of external services. Credentials should be transferred securely, not pasted into a document.

Confirm who owns each account, when the final backup is taken, how much overlap is allowed for migration, when billing stops and when the old provider deletes retained data. For a custom application, add infrastructure configuration, scheduled jobs, logs, data schema, integration notes and a tested deployment from the handed-over materials.

Ownership changes the risk of every hosting decision. CMT Web’s hosting service is optional and separately priced; its live service page currently lists global deployment, SSL, DDoS protection, daily backups, uptime monitoring, software updates, security patches and small content changes. Its pricing terms describe monthly service with 30 days’ notice, while its about page states that clients keep their domain, code and content and receive a working export without a termination fee. Those are useful written boundaries—not a reason to assume anything that is not listed.

If you are comparing plans, line up the responsibilities first and the monthly prices second. If you want a second set of eyes, send CMT Web the plan. We can review what is included, what is missing and whether the level of management matches the website you actually run.

Sources

Got a question this didn't answer?

Send it over. We'll give you a straight answer whether or not there's a project in it.