Website Maintenance (TMA) for Tunisian SMEs: What a Good Contract Covers
A website without maintenance degrades silently until it fails publicly. Here is what a serious TMA contract includes — updates, backups, monitoring, security patches, SLA — and what Tunisian SMEs typically budget for it.
Von Innovation T Team
Most Tunisian SMEs treat a website like a construction project: you pay, it is delivered, it is finished. In reality a website is running software on a stack that changes every week, and "finished" only means "not yet broken". This guide explains what a maintenance contract — commonly called TMA in the Tunisian market — should actually contain, and what neglect ends up costing.
What is TMA, and why is a "finished" website a myth?
TMA (tierce maintenance applicative — third-party application maintenance) is the ongoing contract under which a provider keeps your website or application updated, backed up, monitored, and secure after launch. It exists because every layer under your site — CMS, plugins, frameworks, server software — keeps changing whether you touch the site or not.
Concretely, a site left alone degrades on several fronts at once:
- Security: vulnerabilities are discovered continuously in the software your site is built on; unpatched, they accumulate.
- Compatibility: PHP versions, browsers, and third-party APIs evolve; features silently stop working.
- Performance: databases grow, images pile up, and pages get slower until visitors leave.
- Trust: an expired SSL certificate or a hacked page can appear on the very day a prospect checks you out.
None of these announce themselves. That is the entire argument for a maintenance contract: paying a modest, predictable amount to prevent unpredictable and much larger ones.
What does neglecting maintenance actually cost?
More than the contract you were avoiding — that is the pattern we see consistently. A compromised or long-broken site typically costs an SME the emergency cleanup fee, days or weeks of downtime, lost orders and leads during that period, and damaged trust that no invoice ever captures. One serious incident usually exceeds several years of maintenance fees.
The most common bills we encounter in practice:
- Emergency cleanup of a hacked site: charged at urgency rates, often with no guarantee the backdoor is fully removed if no clean backup exists.
- Blacklisting: browsers and search engines flag compromised sites; traffic collapses and recovery takes time even after the fix.
- A dead certificate or expired domain during a campaign — entirely preventable, surprisingly frequent.
- Rebuild from scratch when the CMS is so outdated that updating is riskier than starting over.
There is also a regulatory angle: if your site collects customer data, a breach can put you in a difficult position under Tunisia's data-protection framework (Law 2004-63, overseen by the INPDP). Verify your exact obligations with the INPDP — "we never maintained the site" is not a defence you want to rely on. Our data protection checklist for SMBs covers the basics.
Which updates and security patches should the contract cover?
The contract should name every layer it updates: CMS core, plugins and themes, the framework and its dependencies, and the server runtime (PHP, Node, database). It should commit to a routine cadence — monthly is a common baseline — plus out-of-band emergency patching when a critical vulnerability is published.
What good practice looks like:
- Updates are applied to a staging copy first, then to production — never live-tested on your customers.
- Critical security patches are applied within days, not bundled into next month's routine visit. The ANCS, Tunisia's national cybersecurity agency, publishes advisories on actively exploited vulnerabilities; a provider who monitors such sources reacts faster than one who waits for the monthly checklist.
- A short changelog is sent after each intervention: what was updated, what was tested, what remains.
- End-of-life software is flagged early. When your PHP version or CMS branch stops receiving security fixes, you want a migration plan, not a surprise.
What should the backup clause actually guarantee?
Not "backups are included" — that sentence protects the provider, not you. The clause should specify frequency, retention, storage located off the production server, and above all periodic restore tests. A backup that has never been restored is an assumption, not a safeguard.
Minimum terms worth writing down:
- Frequency: daily for the database of an active site; at least weekly for files.
- Retention: several restore points across weeks, not one rolling copy — you may discover corruption late.
- Isolation: copies stored outside the hosting server, so a compromise or disk failure does not take the backups with it.
- Restore tests: at a defined cadence (quarterly is reasonable), with the result reported to you.
- RPO/RTO in plain words: how much data you can lose at most, and how long a full restore takes.
We wrote a dedicated guide on backups you can actually restore — hold your maintenance provider to that standard.
What should be monitored continuously — and who gets the alert?
At minimum: uptime, SSL certificate expiry, domain expiry, and error rates, with alerts going to the provider first and to you in defined cases. Monitoring is what turns a maintenance contract from a monthly visit into an actual safety net — problems are caught in minutes instead of being reported by a customer.
A reasonable monitoring scope for an SME site:
- Uptime checks every few minutes from outside the hosting network.
- SSL and domain expiry warnings weeks in advance — two of the cheapest disasters to prevent.
- Performance baselines: page load times tracked over time, so degradation is visible before visitors feel it.
- Integrity and blacklist checks: file-change detection and search-engine flags on a compromised site.
- If you sell online, payment-flow checks matter too: a card gateway (under BCT supervision) or a La Poste e-Dinar integration can fail silently while ads keep sending traffic to a broken checkout.
What security work belongs in the contract beyond patching?
Patching closes known holes; a good TMA contract also reduces the attack surface. Expect access hygiene (least privilege, two-factor authentication on admin accounts), a web application firewall or equivalent filtering, removal of unused plugins, and a written commitment on incident response: who acts, how fast, and what you receive afterwards.
Items to look for:
- Admin access review: former employees and former agencies still holding valid credentials is one of the most common findings when we audit small-business websites.
- Hardening: disabling unused features, limiting login attempts, keeping the admin interface off the public radar.
- Incident response commitment: containment steps, communication to you, and a post-incident summary. Notification duties may apply — verify with the INPDP and, for incident handling, the ANCS.
What makes an SLA worth the paper it is written on?
An SLA is only real if it defines severity levels, response times, resolution targets, coverage hours, and consequences — numbers, not adjectives. "Rapid intervention" is marketing; "critical incidents acknowledged within 2 business hours, workaround within 8" is a contract.
Clauses that separate a real SLA from a decorative one:
- Severity grid: site down and checkout broken are not the same emergency as a typo; each level gets its own clock.
- Response vs resolution: acknowledging a ticket in one hour means little if resolution is open-ended. Both need targets.
- Coverage window: business hours are fine for a showcase site; an e-commerce operation should price the extended option consciously rather than discover the gap on a weekend.
- Reporting: a monthly summary of interventions, uptime, and pending risks. If nothing is ever reported, nothing is probably being done.
- Exit terms: on termination, everything — code, database, credentials, DNS — is handed over within a defined delay.
How much does TMA typically cost in Tunisia?
As an order of magnitude, based on what we see in the market: a small showcase site generally runs 100 to 300 TND per month, an e-commerce site roughly 250 to 800 TND per month, and custom applications from about 800 TND per month upward. Annual contracts around 10 to 15 percent of the original build cost are another common formula. Scope moves these numbers substantially.
How to read a maintenance quote:
- Below these ranges, ask precisely what is included — very cheap "maintenance" is often just hosting renewal with a new name.
- Above them, ask for the SLA and the reporting that justify the difference; both should be verifiable.
- Compare against your cost of downtime: a day of lost orders or leads usually settles the budget conversation.
- Startups labelled under the Startup Act (administered by Smart Capital) sometimes have support mechanisms that offset technology costs — verify current conditions with Smart Capital directly.
How Innovation T helps
Innovation T runs maintenance contracts for Tunisian SMEs from our base in Sousse: scheduled updates with staging, off-server backups with tested restores, 24/7 monitoring, security hardening, and an SLA with numbers in it — plus a monthly report so you can see the work. We can also audit your current maintenance arrangement and tell you honestly whether it protects you.
Ask us for a maintenance quote — send us your site address and we will come back with a concrete, itemised proposal.
FAQ
Is TMA the same thing as hosting?
No, and the confusion is expensive. Hosting keeps the server running; maintenance keeps your application updated, backed up, monitored, and secure on top of it. Many "maintenance included" offers are actually hosting renewal with nothing applicative behind them. Ask what was updated on your site last quarter — the answer tells you what you have been paying for.
Can I maintain a WordPress site myself?
Technically yes, and for a hobby site it is fine. For a business site the honest question is whether someone will really apply updates weekly, test them on a staging copy, verify backups, and react to a security advisory within days — every week, including August. If the answer is no, self-maintenance is simply unmanaged risk with extra steps.
What response time is realistic to demand from a Tunisian provider?
For business-hours coverage, acknowledgement of a critical incident within one to two business hours and a same-day workaround is a reasonable ask; full resolution depends on the fault. Extended or 24/7 coverage exists at a higher price. What matters is that the numbers are written, measured, and reported — an unmeasured SLA is a decoration.
My showcase site rarely changes. Do I still need maintenance?
Yes, because the risk is not in your content but in the software underneath it. An untouched site still runs a CMS, plugins, and a server runtime that accumulate vulnerabilities. A lighter contract — monthly updates, backups, uptime and certificate monitoring — is usually enough, at the lower end of the ranges above.
What should happen when I terminate a maintenance contract?
The provider should hand over everything within a defined delay: source code, database export, all credentials, DNS control, and the latest backups, with no release fee. This reversibility clause must be negotiated at signature, not at exit — a provider who resists writing it down is showing you how the exit will go.
Bereit, mit Innovation T zu bauen?
Ob Sicherheit, Wachstum oder Engineering, unser Team hilft Ihnen, es gut umzusetzen.