The proposal arrives in your inbox with a cheerful promise: a beautiful, high-performing website delivered by a talented team who understand your brand. The portfolio is full of sleek animations, smiling people in offices, and precisely the sort of abstract language that makes a £20,000 project sound both urgent and inevitable.
Then you ask who will maintain the site, how accessibility will be tested, and what happens if the agency disappears. The room gets quieter.
Choosing a web design agency in the UK is less about finding the team with the most dazzling homepage and more about discovering whether it can build something reliable, lawful and useful after the launch champagne has gone flat. A website is not a poster. It is a working business system, often connected to customer data, payments, analytics, hosting, internal processes and the occasional person who still insists on using Internet Explorer.
Start with the job the website must do
Before speaking to agencies, define the business problem in plain English. Do you need more qualified enquiries, an online shop, a recruitment platform, a membership area or a clearer way to explain a complicated service? These are different projects, even if they all involve a large button labelled Get Started.
Write down the audiences the site must serve, the actions you want visitors to take and the systems the website must connect to. Mention your content team, approval process, current CMS, CRM, payment provider and any technical restrictions. An agency that asks sensible questions about these details is showing more useful curiosity than one that immediately presents a ten-page visual concept.
Your brief should also distinguish between essential requirements and decorative wishes. A fast, accessible service page may be worth far more than a dramatic page transition. A searchable product catalogue may matter more than a cinematic homepage video. This is not an attack on design; it is a request for design to do a job.
The scale of the market makes that distinction increasingly important. In a UK business survey covering 3,860 companies with registration numbers, 24% said their website was fully managed by an external web developer or platform. Many organisations are therefore not just commissioning a website. They are choosing an outside party to help run a business-critical asset.
Inspect the agency’s work properly
A portfolio tells you what an agency wants to show. Ask to see examples that resemble your project in complexity, audience or regulatory demands. A stylish restaurant website offers limited evidence that the same team can handle a public-sector service, a multi-language catalogue or a website containing sensitive customer information.
Ask what the agency actually did on each project. Did it handle strategy, content, UX, development, testing, hosting and ongoing support, or did it provide the visual design while another supplier did the difficult parts? There is nothing wrong with collaboration, but you need to know who is responsible for which outcome.
Request references from recent clients and ask practical questions. Was the agency responsive after launch? Did the final cost match the proposal? Could the client update content without calling a developer for every comma? Were problems explained clearly, or disguised beneath a fog of acronyms?
You should also test a few live sites on a phone and a slower connection. Check whether navigation makes sense, forms behave properly and important information can be found without a treasure map. A portfolio can hide awkward details. Live websites usually cannot.
Treat the proposal as a technical document, not theatre
A strong proposal explains the route from discovery to launch. It should set out the research, information architecture, design process, development approach, content migration, integrations, testing, training and post-launch support. It should name the people doing the work rather than presenting an agency as a single magical creature called Our Team.
Look for specific deliverables and acceptance criteria. A phrase such as best-in-class user experience is pleasant but difficult to measure. A statement that the agency will deliver tested templates, agreed page types, documented CMS workflows and a defined performance target is much more useful.
The commercial section deserves equal attention. Ask how change requests are priced, what is included in revisions, whether content entry is part of the fee and what happens if your internal approvals take longer than expected. Confirm who owns the design files, code, content and domain. Clarify whether you can move the site to another hosting provider later.
A low initial quote may exclude the work that makes a website usable: content editing, redirects, accessibility fixes, analytics configuration, security hardening or support after launch. The cheapest proposal can become remarkably expensive once every missing piece acquires a separate invoice.
Make accessibility a contract requirement
Accessibility should not be left to a final visual sweep, as if someone can stroll through the site with a clipboard and discover that half the buttons are invisible to keyboard users. It needs to shape the design and development process from the beginning.
For public-sector work in the UK, check that the agency understands WCAG 2.2 at Level AA and can support the required accessibility statement. Even outside the public sector, accessible navigation, readable content, useful focus states, sensible form errors and keyboard support are basic signs of competent work rather than optional acts of charity.
Ask exactly how accessibility will be tested. You want measurable testing before launch, covering representative templates and key user journeys. Automated tools can identify some issues, but they do not replace manual checks with a keyboard, screen reader testing and careful review of content and interaction design.
Put those requirements in the contract. British government standards require teams to carry out their own testing before an external accessibility audit, a sensible arrangement for any serious project. An audit should not be the first moment anyone notices that the checkout cannot be completed without a mouse.
Check privacy, security and ownership
A web agency may gain access to your hosting account, CMS, customer records, forms, analytics or development environments. That makes its security practices part of your risk profile.
Ask how access is granted and removed, whether accounts use multi-factor authentication, how credentials are stored, how backups are handled and how vulnerabilities are reported. Find out which subcontractors or hosting providers may access the system. You do not need a dramatic security performance. You need clear answers.
The agency should be able to explain how the website will handle UK GDPR and the Data Protection Act 2018. The Data (Use and Access) Act 2025 did not replace those rules, so a new legal label is not a licence to forget the old responsibilities. Discuss contact forms, cookies, analytics, mailing lists, user accounts and retention periods before development begins.
If the agency can access hosting, your CMS or personal data, consider whether Cyber Essentials certification is appropriate. Between April 2025 and March 2026, 59,090 certifications were issued, and each certification is valid for 12 months. Certification does not turn a supplier into an impenetrable fortress, but it gives you a defined baseline to examine rather than a vague assurance that someone is very security-minded.
Ownership matters just as much. The contract should state who controls the domain, hosting account, source code, repositories, licences and third-party subscriptions. The agency may retain rights to reusable tools or frameworks, but you should not discover after launch that your own website is held hostage by an account nobody at your organisation can access.
Examine the people who will support the site
Launch day is often the easy part. The harder months arrive when a campaign needs a new landing page, a plugin breaks, a staff member deletes a menu or a search engine decides that several important pages no longer exist.
Ask what support includes and what it does not. Look for response times, maintenance windows, emergency procedures, software updates, backup restoration and a clear process for approving changes. Find out whether support is provided by the people who built the site or passed to a separate team with a shorter memory and a longer queue.
You should receive documentation and training that match the people who will use the CMS. A technically elegant system that nobody in your organisation understands is not elegant for very long. It is a locked cupboard with a monthly invoice.
Shortlist two or three agencies and give each the same brief. Compare the questions they ask, the risks they identify and the assumptions they make. Their differences will tell you more than their colour palettes.
Choose judgement over glitter
The right agency will not agree to everything instantly. It may challenge an unnecessary feature, question an unrealistic deadline or explain why your preferred platform is a poor fit. That can feel less exciting than a promise to reinvent your digital presence, but it is usually a better sign.
Look for an agency that can move between user needs, commercial goals and technical constraints without turning every conversation into a sales pitch. It should explain trade-offs in language your team can understand, accept responsibility for mistakes and show evidence of testing rather than treating launch as the moment quality control ends.
A good website should make the important things easier: finding information, completing tasks, managing content and trusting the organisation behind the screen. If the agency can deliver that without making you dependent on mysterious jargon, undocumented code or a single person named Darren who is apparently on holiday until September, you may have found the right partner.
