What's Actually in a CRO Retainer (And What Isn't)

Most CRO retainers that go wrong do not fail on capability. They fail on scope.

The client expected development work that was never included. The agency expected feedback turnaround the client could not provide. Nobody agreed what a "test" meant, so four small copy changes and one full page rebuild were both counted as one.

By month four this surfaces as a disagreement about value, when it was actually a disagreement about scope that nobody had in month one.

Here is what a CRO retainer actually contains, month by month, and the boundaries worth confirming before you sign anything.

Phase One: The Setup Month

A retainer does not begin with testing. The first few weeks are foundation work, and an engagement that skips it produces unreliable results later.

GA4 events and implementation audit. Reviewing enhanced ecommerce and custom events, identifying what is missing or misfiring, and producing a recommended event schema for the programme. This matters because every test is measured against conversion data — if purchase fires twice or begin_checkout is missing on mobile, every subsequent result is distorted. Our guide to auditing GA4 ecommerce tracking without code covers what this involves.

UX audit and heuristic review. Identifying friction across the funnel. Low-hanging issues get implemented directly rather than tested — you do not need an experiment to establish that a broken mobile layout should be fixed.

Stakeholder discovery. Pain points, goals, and which KPI the programme is actually accountable for. Getting this wrong is how a programme optimises the thing nobody was measured on.

Testing tool and heatmap setup. Auditing or configuring your A/B testing platform, heatmaps and session recording.

This phase happens once. It is why month one produces no test results, and why judging a retainer on its first month is judging the wrong thing.

Phase Two: The Monthly Loop

From month two onward, the same six steps repeat.

1. Research and audit. Reviewing GA4, heatmaps and session recordings for drop-offs and behavioural patterns, plus heuristic evaluation of the pages in scope. Our guide to spotting conversion drop-offs using GA4 funnel reports covers the quantitative half of this.

2. Hypothesis development and prioritisation. Converting findings into testable, data-backed hypotheses and ranking them. Every hypothesis should name a specific observation, the change, the expected impact and how it will be measured.

3. Experiment planning. Variant wireframing, design mockups, variant copywriting, development scope breakdown and handoff, with everything documented.

4. Implementation and QA. Experiment setup in your testing platform, cross-browser and cross-device QA before and after launch, goal and metric configuration. The QA step is where loosely-run programmes cut corners, and a poorly QA'd test produces a result that looks valid and is not.

5. Launch and monitoring. Launch supervision and weekly significance checks mid-test — monitoring, not peeking-and-stopping.

6. Analysis and reporting. Test analysis, a final report with insights and an implementation guide, and GA4 events implemented for winners so the change is measurable going forward.

On volume: a typical month covers around five hypotheses — which might be two landing page designs, or four tests with end-to-end implementation. Those are different amounts of work, which is why "number of tests" alone is a poor way to compare proposals.

What You Actually Receive

Documents, not just activity:

  • Hypotheses document and testing roadmap

  • Test configuration plans and variant documentation

  • Post-test performance reports

  • Monthly conversion rate progress report

  • ARPU uplift report at quarterly check-ins

That last one matters more than the monthly reports. Conversion rate can rise while revenue per visitor falls, so a programme reporting only conversion rate is reporting half the picture. Our post on why most brands measure conversion rate wrong covers why the blended figure misleads.

What's Included That People Don't Expect

Worth confirming explicitly, because these vary between agencies:

  • A dedicated project manager, rather than a shared account contact

  • Uncapped design rework on variants - you should not be rationing feedback rounds on a mockup

  • Monthly pre and post performance analysis, so change is measured against a documented baseline

  • A CRO KPI dashboard, so you are not waiting for a monthly deck to see where things stand

  • GA4 implementation for winners, so shipped changes remain measurable

What Isn't Included

The section that prevents most disputes. A standard CRO retainer does not cover:

Backend or CMS development. Variant implementation for a test is in scope. Rebuilding your checkout logic is a development project.

Full site UI/UX redesign. Testing within your existing site is CRO. Replacing the site is a different engagement with a different risk profile and it destroys the baseline you would need to measure whether anything worked.

General website copywriting. Variant copy for tests is included. Rewriting your About page is not.

Paid media optimisation. CRO improves conversion of traffic you already have. Campaign management is a separate discipline.

CRM or CDP integrations. Connecting your customer data platform is an infrastructure project.

Performance marketing reporting. Channel reporting sits with whoever manages the channels.

None of these are refusals. They are scope boundaries, and most can be added which is the next section.

Common Add-Ons

Usually quoted separately rather than bundled:

  • Full funnel UX audit

  • Heatmap and session recording analysis as a standalone deliverable

  • Additional tests beyond the monthly count

  • A Looker Studio funnel dashboard

  • Paid landing page CRO

  • Quarterly CRO strategy workshops

  • Page or full website redesign

A proposal that includes everything without naming prices for the extras is usually under-scoping somewhere.

Terms That Actually Matter

Three operational details that determine whether the engagement runs smoothly:

Feedback turnaround. Most retainers specify a window, commonly three business days after which timelines shift. This is not a technicality. A test that waits a week for mockup approval loses a week of runtime, and at typical D2C traffic volumes that can be a quarter of the test.

Revision rounds. Usually one round per month on the hypotheses document and test reports. Worth knowing before you plan a multi-stakeholder review process around it.

Engagement length. Three to six months is typical, and shorter engagements rarely produce compounding results. Month one is setup, months two and three produce the first results, and the pattern only becomes visible from month four.

Notice period. Commonly fifteen days' written notice.

Who owns the output. You should own the hypotheses, roadmap, reports and uplift documentation. Most agencies retain the right to anonymise results for portfolio use unless you restrict it.

How to Read a Retainer Proposal

Five questions that surface scope gaps before they become disputes:

"What counts as one test?" A copy change and a full page rebuild are not equivalent units of work. Get the definition in writing.

"What happens in month one?" If the answer involves tests going live in week two, either the setup phase is being skipped or it was done elsewhere.

"Based on our conversion volume, how many tests can realistically reach significance per month?" The answer should be a calculation from your numbers. A store with modest volume cannot support four tests a month, and a proposal priced around that count is selling capacity you will not use.

"Who implements the winners?" Shipping a winning variant permanently is often a development task. Confirm whether that sits with the agency, your team, or neither.

"What do you do if the tracking turns out to be broken?" The answer tells you whether testing pauses while it is fixed, or continues on data everyone knows is unreliable. Our guide to what a CRO agency actually does covers why this is the question that separates rigorous programmes from busy ones.

One Expectation Worth Setting Early

Most tests do not win. Industry win rates for well-run programmes sit around 20–30%, which means roughly seven in ten tests produce no significant positive result.

That is what rigorous experimentation looks like, not underperformance. A programme claiming a much higher rate is usually calling tests early, testing only changes that cannot lose, or measuring against an inflated baseline.

A retainer's value is the compounding effect of validated improvements over several quarters, plus the hypotheses it eliminates. Both are real outputs. Only one of them shows up as a win.

The Short Version

A CRO retainer is a setup month followed by a repeating six-step loop, producing documented hypotheses, tested variants, and implemented winners.

It does not include development work beyond variant implementation, site redesign, copywriting outside tests, or anything related to paid media.

Most disputes come from one of those boundaries being assumed rather than agreed. Confirm them in month one and the engagement is far more likely to reach month six.

Considering a CRO retainer and want to know what it would actually cover for your store? Talk to FunnelFreaks, we will scope it against your traffic and your funnel before anyone discusses a monthly commitment.