Every CRO process you find online has the same shape: analyse, hypothesise, test, learn, repeat. It is tidy, it is correct, and it tells a business owner almost nothing about what will actually happen on their site next month.
The gap is that those guides assume tens of thousands of visitors, where the test is the hard part. On a Malaysian SME site with 4,000 visitors and 30 enquiries a month, the answer comes from the four steps before the test.
This guide walks through the six steps as they run in practice: what each one produces, where owners usually skip ahead, and four datasets from ZenWeb-managed accounts showing which steps do the heavy lifting. If you are new to the topic, start at the ZenWeb home page or with how a conversion rate is calculated.
Not sure which step your site is stuck on?
Most sites are stuck at step one, with no reliable count of enquiries by device. See how our web design and conversion work runs →
The short overview below covers the standard framework before we get into how each step behaves on a small site.
Source video: 4-Step Conversion Rate Optimization Framework on YouTube
Quick Answer: The CRO process runs in six steps: measure what happens now, research why it happens, rank the leaks by size and effort, write a falsifiable hypothesis, read the change with a test or a fixed before-and-after window, then decide and start again. Each step produces one document the next step depends on.
The six steps are a loop, not a project. Here is what each one is supposed to produce before you move on:
Notice what is missing: “redesign”. A CRO process changes one thing at a time so the result stays readable. Ship five changes together and you have a new website with no idea which part earned the lift. That is the line between conversion work and a rebuild, and part of what conversion rate optimisation services include.
Quick Answer: Step one of the CRO process is a working baseline: every enquiry action counted in one place, split by device and source, with at least four clean weeks behind it. Roughly half the SME sites we take on are miscounting on day one, usually double-counting or missing WhatsApp taps entirely.
This step is boring and it is where most cycles quietly fail. If the numbers are wrong, every later step inherits the error, and you spend a quarter optimising a page that was never the problem.
A usable baseline needs four things:
Decide here what counts as a conversion. Counting every newsletter signup as a win flatters the report and misleads the ranking, so it helps to define a qualified lead before you spend. The mechanics are in setting up conversion tracking in GA4 properly, and the page most sites forget to track is the thank you page. Then check your number against conversion rate benchmarks for Malaysian SMEs.
Quick Answer: Across ZenWeb-managed accounts, session recordings and form field data produced about half of every change that later showed a measurable lift. Ideas that came from an opinion in a meeting — nobody’s data, just a strong view — accounted for 7% of the winners and a much larger share of the failures.
| Evidence source | Share of winning changes | % |
|---|---|---|
| Session recordings | 28% | |
| Form field drop-off data | 21% | |
| Device and source splits in GA4 | 18% | |
| Sales team call notes | 15% | |
| Heatmaps and scroll maps | 11% | |
| Opinion in a meeting | 7% |
Source: ZenWeb client tracking, 12 industries, 2024–2026. Licence.
The top two rows share a quality: both show a person failing, not a number describing failure. You watch someone tap a phone number that is not a link, or abandon at the field asking for a company name they do not have.
Budget research time accordingly. Twenty recordings of mobile visitors who left without enquiring teach you more than a week in the analytics dashboard. Start with what a heatmap actually shows you, then pick tooling from the best heatmap tools for Malaysian websites. What to look for is listed in our 15-point conversion audit, and form behaviour in how to stop losing people mid-form.
Quick Answer: Step three turns research into an ordered queue. Score each leak on two numbers you can defend — how many visitors per 1,000 it affects, and how many days the fix takes — then work down the list. The ranking, not the testing, is where most of the value in a CRO process is created.
Below is a leak list from a services site with roughly 4,000 monthly visitors. The estimates are deliberately rough; the point is the order, not the decimal places.
| Rank | Leak found | Affected per 1,000 | Build days | Est. enquiries/mo |
|---|---|---|---|---|
| 1 | Enquiry point sits four screens down on mobile | 620 | 1.0 | +6 |
| 2 | Form asks for nine fields including budget | 231 | 0.5 | +4 |
| 3 | No WhatsApp option anywhere on mobile | 580 | 0.5 | +3 |
| 4 | Hero headline does not match the ad that sent them | 340 | 2.0 | +3 |
| 5 | Service page loads its main image in 4.1 seconds | 1,000 | 5.0 | +2 |
Source: ZenWeb operational data, 500+ Malaysian SME campaigns, 2024–2026. Licence.
Row five is the instructive one. It affects every single visitor, so instinct puts it first — but it costs five build days and returns the least. Speed still matters: Google treats a Largest Contentful Paint of 2.5 seconds or less as good and 4 seconds as poor, measured at the 75th percentile of loads. It simply is not the first job here.
Rows one and three both point at phones, which is the pattern nationally. With 44.0 million active cellular connections in Malaysia at the end of 2025, equal to 122% of the population, mobile is the default screen for enquiries. The fixes are covered in why phone visitors never enquire and the sticky call button most SMEs miss.
Want a leak list like this for your own site?
We will watch real sessions and hand you the ranked queue, not a slide deck. Start with the 15-point conversion audit →
Quick Answer: A usable hypothesis names the change, the metric, the expected direction and the audience it applies to. “Improve the homepage” fails all four. If there is no result that would prove you wrong, the change cannot teach you anything, whatever the numbers do afterwards.
This is the cheapest step in the CRO process and the one most often skipped, because it feels like paperwork. It is not paperwork — it is the thing that stops a flat result being argued away three weeks later.
Compare two versions of the same idea:
The second version is falsifiable. If mobile enquiries move 1%, the hypothesis is wrong, and that is useful — the contact method was never the barrier. Keep every hypothesis to a single change; two changes in one release means an unreadable result, however clean the tracking is.
Common hypotheses worth borrowing sit in live chat versus a WhatsApp button, whether multi-step forms really get more enquiries, and 12 landing page fixes that lift leads.
Quick Answer: A split test needs enough enquiries per variant to separate a real lift from a quiet week. At 20 enquiries a month, even a 20% improvement takes over half a year to read. Below roughly 150 enquiries a month, fixed before-and-after windows are the honest method.
| Enquiries per month | Weeks to read a 20% lift | Weeks to read a 10% lift | Sensible method |
|---|---|---|---|
| 20 | 30+ | Not readable | Fix defects, before-and-after |
| 50 | 14 | 50+ | Before-and-after windows |
| 150 | 5 | 20 | Split test one page only |
| 400 | 2 | 8 | Split test, one at a time |
| 1,000 | 1 | 3 | Continuous testing programme |
Illustrative model: even traffic split, 5% baseline enquiry rate, standard significance sizing. Source: ZenWeb, Malaysia, 2026. Licence.
The right-hand column is the practical instruction. A before-and-after read is not a lesser method when volume is thin. It is the only one that finishes inside a quarter, provided you state the caveats: four clean weeks either side, no ad changes, no seasonal shift.
Two habits protect the read. Concentrate the test on one page so the sample is not spread across twenty URLs, and never call a result early because week one looked good. The mechanics are in A/B testing for marketers, and the recovery path in what to do when a test comes back inconclusive. The tactic most often misread is whether exit intent popups still work in Malaysia.
Quick Answer: When all six steps run, roughly 47% of shipped changes lift enquiries and 12% make things worse. When the change comes straight from an opinion, the win rate drops to 22% and more than a quarter of changes actively reduce enquiries. The process is the difference, not the talent.
| How the change was decided | Lifted enquiries | No change | Reduced enquiries |
|---|---|---|---|
| All six steps followed | 47% | 41% | 12% |
| Ranked, but no written hypothesis | 34% | 48% | 18% |
| Idea from opinion, measured after | 22% | 49% | 29% |
Source: ZenWeb client tracking, 12 industries, 2024–2026. Licence.
Read the middle column before the first. Even with full discipline, four changes in ten do nothing at all. That is normal, and it is why the sixth step exists: revert cleanly, keep the note, and let the next cycle inherit the finding.
The right-hand column is the argument for the whole method. Shipping on instinct is not neutral — nearly a third of those changes cost enquiries, and without a baseline nobody notices for months. The work usually goes next into a page rebuild, covered in a landing page design service built to convert, or a wider look at demand in inbound versus outbound leads.
Running the loop without a spare team?
We handle measurement, research and build in one cycle so nothing stalls between steps. See what our conversion and web design work covers →
Quick Answer: Three failures account for most stalled cycles: enquiries arriving on WhatsApp where nobody counts them, a rebuild landing mid-test and destroying the baseline, and the loop stopping after one round because the first change came back flat.
The steps are not hard. Keeping them running for six months while the business does everything else is hard. The usual break points:
The last one matters most. Conversion work raises the return on visitors you already have; it cannot manufacture interest that was never there. If that is your problem, weigh the risks of buying leads outright before spending another quarter on button placement, and read the wider picture in conversion rate optimisation basics for Malaysian websites.
Quick Answer: Run the CRO process in order, one change at a time, with the reading method matched to your enquiry volume. Measure for four weeks, research for one, rank honestly, predict a number, read it cleanly, then decide and go again.
The winning test at the end of the six steps is the smallest part of the work. It gets the attention because it is visible, but it only exists because the four steps before it narrowed a hundred possible changes down to one worth reading.
If you want the loop running without pulling your team off other work, ZenWeb runs measurement, research and build inside our web design services, so no step waits on another supplier.
Measure what is happening now, research why it happens, then rank the leaks by people affected and effort. Next, write a hypothesis with a predicted size and read the change with a split test or a fixed before-and-after window. Finally, decide to keep, revert or retest.
About eight to ten weeks on a typical Malaysian SME site. Four weeks for a clean baseline, roughly one week of research and ranking, a few days to build the change, then four weeks to read the result. Sites with heavier traffic can read a split test in one to two weeks instead.
No, but traffic decides the reading method. Below roughly 150 enquiries a month, split tests take too long to finish inside a quarter, so you fix evidence-backed defects and measure with fixed before-and-after windows. The first four steps work identically at any size.
Three categories: an analytics tool counting every enquiry action by device and source, a session recording and heatmap tool, and a way to build the change. A dedicated split testing tool only becomes necessary once your volume can actually read a test.
Revert it and keep the note. Around 12% of changes reduce enquiries even when the full process is followed, which is exactly why the reading step exists. A negative result that you caught in four weeks costs far less than a redesign nobody measured.
Ready to run this on your own site?
Book a free 30-minute strategy session — we’ll review your site, your Google ranking, and your competitors, then give you a concrete 90-day plan with realistic CPL and pipeline targets.
Complete the form and our team will contact you to discuss your goals. Let’s grow your business.

Online