# How Much Should You Budget for Software Maintenance?

Source: https://dijituldevelopments.co.uk/guides/software-maintenance-budget/
Updated: 2026-10-10

> Budget for software maintenance every year, not just the initial build: hosting, security updates, framework and API changes, bug fixes and small improvements. A widely quoted rule of thumb is 15 to 20 per cent of the build cost each year. dijitul quotes maintenance and new work at a fixed price after a free chat.

## Key facts

- CodeStringers and other industry sources cite 15 to 20 per cent of build cost per year as a rule of thumb
- Language and framework versions lose security support on published dates
- Third-party APIs change on the provider's timetable, not yours
- Hosting, backups, monitoring and SSL certificates are recurring costs
- Systems that change often need more budget than stable ones
- Skipping maintenance usually leads to a larger, riskier upgrade later

## What maintenance actually covers

- **Security patching.** Operating system, web server, PHP or Node.js, framework (Laravel, Next.js) and package updates as vulnerabilities are announced.
- **Version upgrades.** PHP, Node.js and frameworks each have published support periods. When security support ends, you need to upgrade, which can involve code changes.
- **Third-party changes.** Payment gateways, accounting APIs and ecommerce platforms change their APIs, authentication and pricing. Shopify retiring REST in favour of GraphQL and Xero changing its developer pricing in March 2026 are recent examples.
- **Bug fixes.** Issues found in real use, browser changes, edge cases.
- **Hosting and operations.** Servers, backups, monitoring, uptime alerts, SSL certificates, email deliverability.
- **Small improvements.** New reports, fields, tweaks as the business changes.

Agree in writing which of these your support arrangement covers, so nothing falls between the gaps.

## How much to budget

A long-standing rule of thumb, repeated by CodeStringers and many other software firms, puts annual maintenance at roughly 15 to 20 per cent of the original development cost, while some sources quote up to 25 per cent. It is a starting point, not a law. Adjust it:

- **Lower** for stable internal tools with few integrations, on mainstream frameworks, used by a small team.
- **Higher** for customer-facing systems, payment handling, many integrations, regulated data, or software that is still actively evolving.

Split the budget into a fixed part (hosting, monitoring, security updates) and a flexible part (fixes and improvements), so planned work does not crowd out urgent work.

## What happens when you skip it

Unmaintained software does not stay still: the world around it moves. Unsupported PHP versions stop receiving security fixes. Payment integrations break when providers retire old API versions. Libraries with known vulnerabilities stay in place. Eventually a forced upgrade arrives all at once, under time pressure, costing more than steady maintenance would have. Our guides to legacy migration and rescuing failed projects describe where that path leads.

There is a hidden cost as well. Developers asked to change neglected code spend longer understanding it, working around outdated libraries and testing by hand, so every small improvement becomes slower and more expensive. Steady maintenance keeps the cost of change low, which matters as much as keeping the system secure.

## Ways to keep maintenance costs down

- Build on mainstream, long-lived technology rather than niche frameworks.
- Keep dependencies few and up to date little and often.
- Have automated tests, so upgrades can be checked quickly.
- Use repeatable deployments (for example Docker and a CI pipeline), so updates are routine.
- Monitor errors and uptime, so problems are fixed before users report them.
- Keep documentation current, so any developer can pick it up.

## A simple annual maintenance plan

Rather than reacting to problems, plan the year. A one-page plan for a typical business web app might include:

- **Monthly:** apply security updates to the server, language runtime and dependencies; review error logs and uptime reports; check backups have run.
- **Quarterly:** test a full restore from backup to a separate environment; review user accounts and remove leavers; check third-party API change notices (Stripe, Xero, Shopify, Microsoft) for anything due in the next six months; review performance as data grows.
- **Annually:** check the support dates for your PHP or Node.js version and framework, and schedule upgrades before security support ends; renew domains and review hosting capacity and cost; run a security review or penetration test for systems handling sensitive data; review the roadmap of improvements with the people who use the system.
- **Ad hoc:** urgent security patches when a serious vulnerability is announced.

Put the dates in a shared calendar with named owners. Pair it with a small improvements budget, so useful changes requested by staff are not endlessly postponed. The plan makes maintenance visible and predictable, which is exactly what budget holders want, and it turns surprise emergencies into routine scheduled work.

## When to talk to dijitul

dijitul builds software with maintenance in mind and provides software maintenance for systems we built and those we inherit. For ongoing support plans and help desk cover, our sister company dijitul support can help. Development work, upgrades and improvements are quoted at a fixed price after a free chat, so you can plan the year's budget.

## FAQs

### How much does software maintenance cost per year?

A common rule of thumb, cited by CodeStringers and other industry sources, is 15 to 20 per cent of the original build cost per year. Stable internal tools often need less; customer-facing systems with many integrations often need more.

### What is included in software maintenance?

Security patches, language and framework upgrades, fixes for third-party API changes, bug fixes, hosting, backups, monitoring and small improvements. Larger new features are usually budgeted separately as development work with their own scope and price.

### Do I need maintenance if my software works fine?

Yes. Even unchanged software sits on servers, languages and libraries that receive security fixes and lose support over time, and it talks to APIs that change. Without maintenance, risk builds up until a forced, expensive upgrade.

### Can dijitul maintain software built by someone else?

Yes. dijitul typically starts with a review of the code, hosting and dependencies to understand the risks, then agrees a maintenance plan. Any upgrade work is quoted at a fixed price after a free chat.

### Should maintenance be a monthly retainer or ad hoc?

A retainer suits business-critical systems that need guaranteed response times and steady updates. Ad hoc work can suit stable, low-risk tools. Many businesses combine a small fixed plan for security and hosting with quoted projects for improvements.

## Pricing and contact

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data. Book a free chat: https://dijituldevelopments.co.uk/contact/ · 01623 650333 · info@dijitul.uk
