Three services in one sentence
A very common request for proposal today has a single line of scope: "website hosting, maintenance and content updates for a period of 12 months". It sounds clear. It is not.
Three services fit in that sentence, with very different costs and risks. One vendor reads "hosting" and quotes a server plan. Another reads "maintenance" and quotes an on-call team. A third reads "content updates" and pictures two banner swaps a month. All three proposals arrive on the same day, with figures that have nothing to do with each other, and whoever asked is left with no way to compare.
This article is for both sides of the table, the person writing the request and the person answering it. It covers what each part means, a scope template and what happens in an ordinary month of maintenance, with examples from gusta.click itself.
What each word in the request means
Hosting is where the site lives: server, domain, DNS and SSL certificate. It is the cheapest part and the easiest to compare, because it has list prices.
Maintenance is keeping all of that working and safe. Updating the system and plugins, keeping an eye on the PHP version, running backups and testing that they restore, monitoring uptime, fixing things when they break. One example with a date: PHP 8.2, still common on shared hosting, stops getting security fixes on December 31, 2026. The cost here is people's time.
Content updates are editorial work with a technical hand. Changing copy, publishing news, uploading banners, building a new page now and then. The cost depends on volume and turnaround, and it is the item that causes the most arguments mid-contract.
Bundling all three into one price is perfectly fine. The problem is not saying how much of each is included.
A scope template you can actually compare
| Item | What to write in the request | How to measure it |
|---|---|---|
| Hosting | Where it lives and who owns the account and domain | Account and domain in the company name |
| Backups | Frequency, where they are stored and for how long | A dated restore test |
| Updates | System, plugins, theme and PHP version | Monthly log of what was updated |
| Uptime | Monitoring and time to react when the site goes down | Alerts and response time |
| Fixes | What counts as a fault and the time to fix it | Tickets opened and closed |
| Content | How many changes per month and how fast | Requests delivered on time |
| Reporting | Performance, accessibility, SEO and incidents | Monthly report |
A request with just this table filled in already gets proposals that look far more alike. And vendors can price each line instead of guessing one lump sum.
What a real month of maintenance looks like
I will use our own site, because it is the example I have with dates. In September 2026, gusta.click went through four things that only surfaced because someone was watching.
An old file served by the CDN. After an update on the 15th, the site kept serving an old version of a JavaScript file. The server treated every .js file as immutable for a year, which makes sense for files with a version in their name, but not for that one. The fix was a version in the URL and a one-hour cache for that file only.
Accessibility dropping unnoticed. The same week, Lighthouse started scoring every blog post 96 for accessibility. Two small pieces of text had low contrast, one of them in a component that appears on every page. Nobody had complained. Once fixed, it went back to 100.
Invalid structured data. On the 19th, an SEO tool flagged errors on eight product pages: the price was missing from the offer the site describes to Google. We fixed it and validated it in the rich results test the same day.
A deploy that failed. One of the automated deploys timed out while connecting to the server. It ran again and went through. It sounds trivial, but if nobody checks, the previous version stays live and everyone assumes the change was made.
None of these took the site down. All of them would have cost visits, Google rankings or credibility if they had sat there for months. That is basically what maintenance is, a pile of small things someone has to notice before your customers do.
The report has to show what is not good
The report above is real and it is not all green. Best practices sit at 78 because the site runs a behaviour analytics tool that sets third-party cookies. It is a trade-off we made on purpose: we lose points there and gain session recordings that show where people get stuck on the page.
A report that only shows pretty numbers does not help anyone decide anything. What is worth asking for is simple: the month's numbers, what changed from the previous month, what was fixed, what is still pending and why.
Content updates: agree on volume and turnaround
The editorial side is where contracts fight the most. Three agreements prevent almost every argument.
- What counts as one change. Swapping a piece of copy is one. A new page with a form is several.
- How fast. A turnaround in business days, counted from a request with complete material.
- Who approves. One named person on the company side. Without that, publishing sits and waits.
When a site publishes often, as in the Vixting case study, it stops being a project with a start and an end and becomes part of the operation's routine. Then the contract has to reflect the routine, not the launch.
What it costs
| Item | Reference in September 2026 | Detail |
|---|---|---|
| .com.br domain | R$ 40 a year | Fee charged by Registro.br, the Brazilian registry |
| SSL certificate | Free | Let's Encrypt, included by most hosts |
| Shared hosting, entry plan | R$ 5.90 to R$ 10.09 a month | Promotional prices at Hostinger, Locaweb, HostGator and KingHost, with 24 to 48-month terms |
| VPS, entry plan | R$ 15.90 to R$ 32.90 a month | Same providers, not counting whoever runs the server |
Hosting prices are promotional and depend on long terms. Where the page shows the renewal price, it is two to four times higher. The per-provider detail is in our comparison of shared hosting, VPS and cloud.
Hosting is the smallest part of the bill. What weighs is people's time: who updates, who tests, who responds when the site goes down and who publishes content. That is why proposals usually come in one of these formats.
- A monthly fee with a bundle of hours. Predictable for both sides. Check what happens to unused hours and to extra ones.
- An hour bank. Good for irregular demand. It needs clear usage reporting.
- On demand. Cheap in quiet months and expensive in a month with problems. Rarely a fit for a 12-month request.
When the buyer is a public body
A request for quotes with a short deadline and a one-line scope is common in public sector price research in Brazil. In that case a detailed scope helps everyone, because comparing proposals is required by the rules themselves.
Brazil's public procurement law, Law 14,133/2021, lists direct research with at least three suppliers, through a formal request for quotes, among the parameters used to estimate the price of a contract. Quotes older than six months before the tender is published do not count.
For the federal administration, Normative Instruction SEGES/ME 65/2021 sets the minimum a supplier quote must contain: a description of the object with unit and total price, the supplier's tax ID, physical and email address, phone number, issue date and the full name of the person responsible. States and cities can have their own rules, so check which one applies to whoever is asking.
For the buyer, the scope table above is the simplest way to get comparable quotes. For the vendor, it pays to send a proposal priced per item, with a validity date and anything out of scope spelled out plainly.
A new site, or unsure about the server?
If the site still has to be built, or rebuilt, our guide to building a business website shows what needs to be in place before maintenance starts. And if the open question is where the site should live, our comparison of shared hosting, VPS and cloud explains what changes in cost and in work.
Frequently asked questions
Can I contract hosting only?
Yes, and for a small site that rarely changes it can make sense. Just know that updates, tested backups and fixes do not come with a hosting plan, and someone will have to do them.
Whose name should the domain be in?
The company's, with someone in-house as the contact. A domain registered in the vendor's name is the most common source of headaches when a company decides to switch providers.
What happens if I switch vendors mid-contract?
It depends on what the contract says about exit. Plan for the handover of a full backup, access, code and documentation, with a deadline, so the switch does not leave anyone held hostage.
How often should backups run?
For most company websites, daily, with a copy stored off the web server. And a restore test every so often, because a backup that has never come back is not a guarantee.
Does maintenance include building new pages?
Only if the contract says so. New pages usually fall under content updates, with a monthly limit, or become a separate project. What matters is having it in writing before the request comes in.
Sources
Prices and rules checked on official pages on September 23, 2026: Registro.br, Let's Encrypt, Hostinger, Locaweb, HostGator, KingHost, Law 14,133/2021 and Normative Instruction SEGES/ME 65/2021.
CTA
Have a website hosting, maintenance and content update request to answer, or want to write one that brings back comparable proposals? Talk to GUSTA. We send the proposal back item by item, with turnaround times and reporting defined in the contract.
Comments
No comments yet. Be the first to comment.