The verdict in three sentences
A Berlin fintech's public website is part of its attack surface: onboarding landing pages, pricing disclosures and support forms attract credential phishing, bot sign-ups and injection attempts. A serious maintenance contract must cover at least weekly security patching, daily backups retained for 30 days, a 99.9 % uptime target and written response times by severity, with logs you can show a supervisor. In 2026 a Berlin agency charges roughly 900 to 6,000 EUR a month depending on the level, and most Series A to C fintechs land in the middle tier.
Three service levels compared
| Service | Core, about 900 EUR/month | Standard, about 2,500 EUR/month | Regulated, about 6,000 EUR/month |
|---|---|---|---|
| CMS and dependency updates | Monthly | Weekly | Weekly, critical patches within 24 h |
| Backups | Daily, 30 days | Daily, 30 days, EU region | Daily, 30 days, second EU region, quarterly restore test |
| TLS and security headers | Auto renewal | Renewal plus CSP and HSTS review | Full header policy, monitored |
| Web application firewall | Basic managed rules | Tuned rules, bot management | Tuned rules, rate limits per endpoint |
| Uptime monitoring | 5 minute checks | 1 minute checks, 99.9 % target | 1 minute checks, 99.95 % target, status page |
| Reporting | Quarterly | Monthly uptime report | Monthly report mapped to ICT risk register |
| Change hours | 4 h/month | 10 h/month | 20 h/month |
These are 2026 estimates for the marketing site and public onboarding pages, not the core banking or payments platform, which follows your own engineering and change management process.
Response times and the regulatory angle
Since the Digital Operational Resilience Act started applying in January 2025, BaFin-supervised firms must manage ICT third-party risk, including the agency that runs your website. That means a register entry, exit strategy and incident classification you can align with your own.
| Severity | Example | Response | Restore target |
|---|---|---|---|
| Critical | Site down, injected phishing page | 2 hours | 8 hours |
| High | Onboarding form or app store links broken | 4 hours | 24 hours |
| Medium | Outdated fee table, broken legal link | 24 hours | 72 hours |
| Low | Copy change, new blog post | 48 hours | 5 working days |
| Planned | Terms and conditions update after a product change | Agreed date | Agreed date |
For GDPR, ask the agency to document which logs it keeps (access, admin actions, form submissions), for how long, and where. Admin action logs kept for 12 months and form data purged on a defined schedule is a defensible default.
Clauses that matter beyond patching
| Clause | Why it matters | Typical 2026 cost if billed separately |
|---|---|---|
| Penetration test window | Agreed dates so testers are not blocked by the WAF | External test 8,000 to 25,000 EUR |
| Restore testing | An untested backup proves nothing | Quarterly in the Regulated tier |
| Exit and reversibility | Code, access and backups returned within 10 days | Free if written in the contract |
| Data processing agreement | GDPR Article 28 terms with the agency | Included |
| EU hosting | Data residency expectations of partners and auditors | 1,200 to 6,000 EUR a year |
| Subcontractor list | DORA third-party visibility | Included |
For smaller teams or a secondary product site, a remote provider can be enough: Kolonell maintenance plans cost 38, 76 or 115 EUR a month, with weekly updates and daily backups, but a regulated core site usually needs a Berlin partner with on-call engineers in your time zone.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Illustrative example: Lena, CTO of a fictional Berlin payments fintech with 220,000 users, picks the Standard tier at 2,500 EUR a month, or 30,000 EUR a year, plus 12,000 EUR for an annual external penetration test. Total: 42,000 EUR a year. The year before, a compromised marketing CMS led to a two-day outage of the onboarding page during a campaign. With 1,100 expected sign-ups lost and a customer acquisition cost of 45 EUR already spent in ads, the incident wasted about 49,500 EUR of paid acquisition, more than the full annual contract.
FAQ
How much does fintech website maintenance cost in Berlin in 2026?
Roughly 900 to 6,000 EUR a month depending on service level, change hours and monitoring depth. Penetration tests and hosting are usually budgeted separately.
How often should security patches be applied?
Weekly as a baseline and within 24 hours for a critical published vulnerability. Monthly patching leaves up to 30 days of exposure.
Does DORA apply to our website agency?
If the agency provides ICT services supporting your operations, it belongs in your third-party register with an exit plan. A marketing site is rarely critical, but documenting it takes about 2 hours and avoids audit findings.
What uptime should we require?
99.9 % a month, which allows about 43 minutes of downtime, is a reasonable standard for a fintech public site. 99.95 % costs more and suits sites carrying live onboarding.
How long should backups be kept?
Thirty days of daily backups in an EU region is the common baseline. Add a second region copy and a quarterly restore test if the site handles personal data.
Let's scope your project. Tell us your stack, traffic and audit requirements and we will propose the right maintenance level with written response times and annual cost. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.