Regulated clients (and their auditors and insurers) increasingly treat the company that runs their website as part of their supply chain. Under NIS2, essential and important entities must manage supply-chain security; under DORA Art. 28–30, financial entities must contractually govern ICT third-party providers — and "our website is outsourced" increasingly counts. This checklist lists what a regulated client will demand from its maintenance vendor, so you can answer before being asked.
| Clause | What it should say |
|---|---|
| Service description | Explicit list of services: updates, backups, patching, monitoring, incident handling — with scope per site. |
| Security measures | Vendor commits to defined technical/organisational measures (access control, least privilege, encrypted storage of credentials). |
| Audit / evidence right | Client may request documentation of performed work (change logs, backup test records) at reasonable notice. |
| Incident notification | Vendor notifies client of any security incident affecting the site within an agreed window (e.g. 24h) with a named contact. |
| Subcontracting | Any subcontractor (hosting, tooling) is disclosed and bound by equivalent obligations. |
| Data location | Data and backups stored within the EU / EEA; jurisdiction specified. |
| Termination & exit | On termination, full handover: current backups, change history export, credentials returned/deleted. |
| Liability cap | A realistic cap tied to fees — neither zero nor unlimited. |
AuditedWP provides white-label WordPress maintenance for EU web agencies with a revision-ready audit trail built in: every update, backup, patch and restore documented per site, EU hosting and DPA as standard. You keep the client relationship and the margin; we run the operations and hand you the evidence.