05 October, 2026
Umbraco CMS

What owning an Umbraco site actually requires

Paying a developer by the hour does not make anyone responsible for your website. Someone still has to notice that work is needed, decide how urgent it is and make sure it gets done. On an Umbraco site, that work arrives whether or not anyone asks for new features.

This is for whoever holds the budget or the supplier relationship for an Umbraco site going into 2027: what that responsibility covers, roughly what it costs, and how to decide who should carry it.

min reading time

Hours are not ownership

Maintenance work starts with someone noticing something: a security advisory, a package that no longer works with the current version, a support deadline getting close. If nobody has that job, the work waits until something breaks or a deadline is near, and then it gets done in a hurry.

Three kinds of change create that work on an Umbraco site:

  • Security fixes. On August 18, 2026, Umbraco fixed a high-severity authorization flaw in the backoffice API. Exploiting it required a backoffice login, though not an administrator's. It affected Umbraco 17.0.0 to 17.6.1 and was fixed in 17.6.2. A site that launched on Umbraco 17 and was never updated was on a supported version and still exposed. I went through the advisory in a separate post.

  • Regular updates. Umbraco keeps releasing fixes for as long as a version is supported; Umbraco 17 has had seven minor releases since November 2025. Microsoft releases .NET updates on Patch Tuesday, the second Tuesday of the month, and requires systems to stay current on them to remain supported.

  • Everything around the CMS. Third-party packages need versions that work with your Umbraco version. Integrations stop working when the system on the other side changes its API. Certificates expire, and backups need an occasional test restore to show they can actually be used.

Budget for upgrades separately

Routine updates keep a version current. Moving to a new major version is a separate project, and it comes around on a calendar Umbraco publishes in advance.

Long-term support (LTS) versions get three years of support, which means roughly one major upgrade every two years, with about a year to carry it out. Umbraco 13 to 17 is that window now: 17 was released on November 27, 2025, and 13 reaches end of life on December 14, 2026. The next LTS, Umbraco 21, is currently scheduled for December 9, 2027, a little under a year before Umbraco 17 reaches end of life on November 27, 2028. Standard-term (STS) versions such as Umbraco 18 get 12 months, so following them means a major upgrade at least once a year. For a business site without a specific need for the newest features, I recommend LTS.

Passing end of life does not suddenly make an upgrade more expensive. It means you can no longer rely on security fixes arriving when a vulnerability is discovered. The August advisory made that risk concrete: affected releases of Umbraco 14, 15 and 16 were already out of support, and Umbraco confirmed they would not be patched. If a vulnerability is exploited, the business may face a data breach, downtime and recovery work alongside the upgrade it was already going to need. Planning ahead gives you time to budget and schedule the work before an incident sets the deadline for you.

That planning needs to cover the whole stack. Umbraco 13 runs on .NET 8, which loses support on November 10, 2026—a month before Umbraco 13 itself. Working only toward the CMS deadline leaves the underlying platform unsupported in the meantime. Use the earlier date when planning your upgrade. If that timetable is difficult, I compared paid extended support with upgrading in Umbraco 13 XLTS vs upgrading.

What it costs

In How much does an Umbraco website cost in 2026?, I suggested budgeting 10–20% of the build cost per year for security patching and minor version upgrades. Treat that as a first planning figure. Build cost is only a rough proxy for maintenance effort: a design-heavy site can be technically simple, while a cheaper site with several integrations can need far more attention. What decides the actual figure is how many packages and integrations the site depends on, how critical it is to the business, and the condition of the code today.

Maintenance costs

For a site that cost €40,000 to build, the rule gives €4,000–8,000 a year, or three to eight hours a month.

That figure covers development work only. It covers Umbraco security patches and minor updates, server software updates, technical SEO like broken links, obvious errors and general best practices. It does not include hosting costs, licenses for commercial packages or other suppliers' charges.

Major version upgrades

Major version upgrades are a project with their own scope. I covered what that involves in Upgrading Umbraco 13 to 17: what actually breaks. Budget for one in the year it falls due, or spread the cost over the two years before.

New development fund

Adding pages or changing content with the blocks you already have is typically handled by your own content editors. Creating a new page type, block or integration is development and needs a separate budget from keeping the existing site running.

For a website that you expect to develop actively, I suggest setting aside 15–25% of the initial development cost each year as a starting point. You do not need to spend that amount every year: some can fund smaller improvements, while the rest builds a reserve for more substantial changes.

Over time, your services, customer expectations and internal processes will change. Your website may need new functionality, a revised design or eventually a more extensive rebuild to keep supporting the business. This fund gives you room to plan those changes. Adjust it to your actual priorities, and keep it separate from the maintenance and major CMS upgrade budgets above.

Who should own it

The work can be bought in three ways. The choice depends less on hourly rate than on whose job it is to notice when something needs doing.

  • Ad hoc. You bring in a developer when you need one and pay for the hours. This works well when the site rarely changes and someone on your side follows Umbraco's advisories and support dates and acts on them.

  • Retainer. You reserve a fixed number of hours a month with a developer who knows the solution. With my retainers, that buys three things: continuity, because I already know the code and do not have to relearn it for each request; agreed availability, with retainer clients first in the queue when production breaks; and responsibility for tracking updates, advisories and the next upgrade. Monitoring and incident response times are not automatic in any retainer, mine included. They are terms to agree.

  • Internal team. If you already have developers who work with .NET, they can own the site without a dedicated hire. The questions are whether they have the time and the Umbraco experience, and whether the site gets attention among their other priorities.

The same rule of thumb as on my retainer page applies here: if a site really only needs a few hours a year, buying them as you go is cheaper.

Check what your host already covers

Some of this may already be handled. When Umbraco published the August advisory, projects on Umbraco Cloud received the CMS and Forms fixes automatically. A site you host yourself, on Azure or elsewhere, gets nothing automatically. Establish what your host covers, what your developer covers, and who checks what falls between them, such as third-party packages and integrations.

What to agree before you sign

Whoever you choose, these terms are worth having in writing:

  • What the hours cover. Are security updates, monitoring and the next major upgrade included, or charged separately?

  • Response to incidents. How quickly does someone respond when the site is down, and what counts as an incident?

  • Unused hours. Do they roll over to the next month, expire, or go to agreed backlog items?

  • Ownership and access. The code repository, hosting account, domain and licenses should be in your name, with access granted to the developer.

  • Documentation. Setup, deployment and decisions should be written down.

  • Ending the arrangement. Notice period, and what a handover includes.

The last three matter even when the arrangement works well, because they decide how easily someone else could take over.

Next step for your 2027 budget

If you want a second opinion on what your site needs, get in touch. It helps if you can tell me your Umbraco version, where the site is hosted and roughly how much it has changed over the past year. Anything more, such as the .NET version, packages and integrations, is useful but not required. That is enough for a first view on whether a retainer makes sense or ad hoc work is cheaper. An actual maintenance estimate needs a look at the implementation and at what the site has to do for the business. Retainers start at five hours a month.

Release and support dates checked on October 3, 2026 against Umbraco's support policy, Umbraco's security advisory of August 18, 2026 and Microsoft's .NET support policy.

Free consultation

The first conversation is free. We spend an hour going through your technical setup, your hosting and how the site is used, and you come away knowing whether ad hoc help or a retainer suits you, and whether we work well together.

Before the call, I also take a free look at your live site: performance, usability, technical SEO and anything else that may need attention.

An actual maintenance estimate needs access to the code itself, and that is paid work. Retainers start at five hours a month.



Share this article