Ask an agency how often a nonprofit should redesign its website and you will usually be told every three to five years. The figure appears across the sector's marketing content with remarkable consistency and almost no supporting evidence. It is worth noticing who publishes it: organisations whose revenue depends on redesign projects, quoting figures that are rarely traceable to any study.

That does not make the number wrong. It makes it unaccountable — which is a different problem, and a more serious one for an organisation that has to justify the spend to a Board.

The Calendar Is the Wrong Instrument

A website's age tells you almost nothing about whether it is serving the organisation. A four-year-old site on a maintained platform, with current governance documents, a working donation flow and no accessibility violations, is doing its job. An eighteen-month-old site built for a strategy the organisation has since abandoned is not, however recent its launch date.

The three-to-five year convention persists because it is easy to plan around and easy to sell. It fails as a governance standard for a simple reason: it produces the same recommendation regardless of what the website is actually doing. Any framework that returns the same answer whatever the evidence is not a framework.

What Actually Triggers a Rebuild

Four conditions genuinely justify a full rebuild. Each is observable, and none of them is a date.

The organisation the website describes no longer exists. A merger, a significant change in charitable objects, a shift in the primary beneficiary group, or a strategic repositioning can leave a site describing an organisation that has moved on. This is a credibility failure, not an aesthetic one, and it matters most to the audiences least likely to tell you about it — institutional funders conducting due diligence, and regulators.

The platform is no longer maintained. A CMS that no longer receives security updates is an unmanaged risk sitting on the risk register, and it belongs there. This trigger is binary and verifiable: either the platform receives security patches or it does not.

Accessibility failures are structural rather than editorial. There is an important distinction here that determines whether you need a rebuild or a remediation programme. Missing alt text, poor link labelling and inconsistent heading order are editorial failures — they are introduced by content publishing and are fixed by content and process, not by a new build. Failures baked into templates, component markup or the colour system are structural, and remediating them page by page costs more than rebuilding the templates once.

The distinction matters because the sector's accessibility problem is overwhelmingly ongoing rather than one-off. The WebAIM Million 2026 report found detectable WCAG failures on 95.9% of the top one million home pages — up from 94.8% the previous year, reversing six consecutive years of improvement — with an average of 56.1 errors per page. Six categories have accounted for the overwhelming majority of detected errors for seven consecutive years. A rebuild resets the count. It does not change the publishing behaviour that raises it again.

The team cannot maintain the site without external help. If publishing a programme update, correcting a trustee listing or adding an annual report requires a developer, the organisation does not control its own institutional record. That is a governance problem, and it is the one most likely to justify rebuilding a site that otherwise looks fine.

What Looks Like a Trigger but Is Not

Several common justifications do not survive examination.

A new Communications Director who dislikes the design. A peer organisation launching something visually striking. Declining traffic, which is far more often a search or content problem than a design problem. Slow load times, which are usually caused by uncompressed images and accumulated tracking scripts — both fixable in days. A donation flow underperforming, which needs the flow diagnosed, not the site replaced.

Each of these is a real problem. None of them is evidence that the answer is a rebuild. The failure mode is consistent: a symptom is observed, a rebuild is commissioned, and eighteen months later the same symptom reappears on a new site because nobody diagnosed the cause.

The Questions That Replace the Calendar

Reviewed annually, these five questions produce a defensible answer where a date cannot.

  1. Does the site describe the organisation as it exists today — current strategy, current programmes, current leadership, current governance documents?
  2. Can a funder conducting due diligence find the annual report, the trustee listing and the registration details without using search?
  3. Does the platform receive security updates, and does the team hold the credentials?
  4. Can the team publish, correct and remove content without a developer?
  5. Are accessibility failures editorial, or are they built into the templates?

Answer these honestly and the redesign question usually answers itself — frequently with "not yet, and here is what to fix instead".

Diagnose Before You Scope

The uncomfortable structural fact about this market is that the organisations best placed to advise on whether you need a rebuild are usually the ones who would deliver it. That is not an accusation of bad faith; it is a description of an incentive.

The practical protection is to separate diagnosis from delivery, and to treat the diagnostic as the smaller, earlier purchase. In the UK, published pricing for independent website and accessibility assessment sits broadly between £600 for a light health check and around £5,000 for a full professional review — AbilityNet's Digital Accessibility Review, for example, is fixed at £4,950 plus VAT for up to ten pages or components. Set against rebuild budgets that commonly run well into five figures, a diagnostic that prevents an unnecessary rebuild pays for itself several times over, and a diagnostic that confirms one produces a far better brief.

Ask any prospective partner directly: under what circumstances would you tell us not to rebuild? A partner who cannot answer that question concretely has told you something useful about how the recommendation will land.

Taking It to the Board

Boards approve website spend when it is framed as risk management or institutional capability, and hesitate when it is framed as appearance. "Our site looks dated" invites debate about taste. "Our CMS stopped receiving security patches in March, our accessibility statement is inaccurate, and our annual report takes four clicks to reach from the homepage" invites a decision.

The second framing also survives the question a good trustee always asks: what happens if we do nothing for another year? Stated as risk, that question has an answer. Stated as aesthetics, it does not.

The Standard Worth Adopting

Review annually against the five questions. Maintain continuously. Remediate when findings are editorial or contained. Rebuild when the organisation has changed, the platform is unsupported, the failures are structural, or the team cannot maintain its own institutional record.

For most established nonprofits this produces a rebuild cycle somewhere between five and eight years, with continuous maintenance in between — longer than the sector's conventional wisdom, and considerably cheaper. Organisations that maintain deliberately rebuild less often. Organisations that rebuild in place of maintaining rebuild constantly.

The Blueprint Audit is a structured diagnostic that answers the rebuild question with evidence — including, where the findings support it, the recommendation not to rebuild.