What should a small-business hosting package actually include?
Judge a hosting package by what you can verify and recover, not by the size of the numbers on the pricing page. A small-business site rarely fails for lack of computing power; it fails because there was no restorable backup, nobody could reach support, or leaving turned out to be harder than staying. This is the checklist that actually matters — none of it argues for a bigger server.
The non-negotiables
- Backups you can restore. Automatic, covering files and databases, kept in more than one generation — with a restore process you can verify and initiate yourself, or failing that, through support with a documented response time. "We make backups" without a testable restore is asking and hoping; test a restore before you need one.
- TLS included and automatic. Certificates for your domain, issued and renewed without manual ceremony or surcharges. HTTPS is baseline, not an add-on.
- Current software, maintained. Supported runtime versions, with enough version choice to test upgrades before they're enforced, and the host applying security updates to the platform underneath. Ask how end-of-life versions are handled — a silent forced upgrade can break a site overnight, and a never-upgraded platform is worse.
- Access to your logs. Error logs at minimum, access logs ideally. Without them, every problem is a support ticket into the dark.
The operational comforts
- A staging or preview mechanism — even a simple one — so changes can be tested before going live.
- Honest resource limits. Every shared plan has limits on memory, processes, storage and mail sending; good hosts publish them, and tell you when you hit them, before your visitors find out.
- Support that answers. Test it before you commit: send a real pre-sales question and see how long the answer takes and whether it actually answers — a vague pre-sales answer rarely becomes a precise technical one after you've paid. Ask what hours support covers, too; office-hours support with continuously monitored infrastructure can be fine, as long as you know which you're buying.
- A defined migration process. Know who moves the files, databases, mail and DNS into the new package, what gets tested afterwards, and who's responsible if something is missing — the host-move guide shows what "everything" means.
- Status transparency — a status page or incident notifications, so you're not diagnosing the host's outage as your own bug. Pair it with your own external monitoring of both availability and a real page or function; no host reports its own downtime perfectly.
The ownership questions
- The account is yours. Contract and account in your business's name, with named access for whoever manages it — not a package inside a web agency's own account.
- Account security. Multi-factor authentication available, named users where possible, and a recovery route that doesn't depend on one employee's personal mailbox or phone.
- Direct control of DNS. You or your administrator can view and change the DNS records without going through the web developer — and you know what happens to the zone if the hosting is canceled, and whether it can be exported.
- Email separable from web. Bundled mail is convenient until a host move or web problem threatens the mailboxes. Prefer setups where mail is a separate service, or at least where MX records can point elsewhere independently.
- A clean exit. Can you export everything — files, databases, mailboxes, DNS zone — in standard formats, yourself? What notice does cancellation need, and what happens to backups and mail afterwards? Domains should never be locked to the hosting. The measure of a good host is that leaving would be easy — that's also the best predictor you won't want to.
A hosting package is a promise that someone else will keep your foundation standing. Read the promise the way you'd read a lease — the fine print about getting out matters more than the brochure photos.
What to do
- Confirm backups cover files and databases, in multiple generations, with a restore process you can verify — ideally self-service. Then test one.
- Check TLS is included and automatic, and that supported runtime versions are offered with a sane upgrade policy.
- Confirm you get error and access logs without asking support.
- Send a real support question before signing up, time the answer, and ask what hours support covers.
- Put the account in the business's name with MFA and named users, keep email separable, and confirm direct DNS access.
- Ask the exit questions up front: what can you export, how, and with what notice.
Frequently asked questions
- Is the cheapest hosting plan good enough for a small business?
- Often yes, technically — a small site needs little computing power. The real differences at the bottom end are the operational ones: whether backups exist and you can restore them yourself, whether support answers, how honest the resource limits are, and how painful leaving would be. Judge the package on those, not on the advertised gigabytes.
- Should my email be hosted with my website?
- Keeping them separable is the safer default. When web and mail live in one bundle, a website problem, a host move, or a canceled package can take your mailboxes with it. This doesn't necessarily mean two companies — it means the web hosting can be changed or canceled without automatically terminating the mail service, and the MX records can point elsewhere independently.
- Do I need a VPS or dedicated server?
- Not until a real, measured constraint says so — sustained traffic the shared plan can't serve, software the host won't run, or compliance needs. A managed shared plan with good backups, updates and support beats a self-managed server nobody patches. Upgrade in response to evidence, not in anticipation of it.
Looking for more? Browse all the website tips.
Source: “What should a small-business hosting package actually include?” — https://www.siteadvice.be/articles/what-a-hosting-package-should-include/ · © 2026 EUREGIO.NET AG. All rights reserved.