The reason is ordinary rather than technical. A site you cannot update yourself means every price change, every new service, and every correction requires somebody else, which introduces cost and delay for changes that should take two minutes. Businesses with a site they cannot edit tend to stop editing it, and a site frozen at the moment it launched slowly diverges from what the business actually does.
The choice splits into two categories. Hosted platforms bundle the editing tools, hosting, security, and updates into one subscription, which means less to manage and less control. Self hosted systems give you more flexibility and put maintenance, updates, and security on you or on whoever you pay. For a first year business without technical staff, the hosted route is usually correct, and the flexibility argument for the alternative is mostly relevant to needs you do not yet have.
The question that should decide it is not features. It is whether you can get your content out. Every system will tell you it is easy to use. Fewer will let you export your pages, your posts, and your images in a standard format you could take elsewhere. Ask before committing and test it once you are set up, because content trapped inside a proprietary system is the version of this decision that becomes expensive later.
Whichever you choose, spend an hour learning to do the three things you will actually do: change text on a page, add a page, and update an image. Businesses that never learn those revert to asking somebody every time, which recreates the original problem while paying for a system meant to solve it.
Whichever system you choose, find out who is responsible for updates and backups before you need either. On a hosted platform the answer is the provider, which is part of what you are paying for. On a self hosted system the answer is you, or whoever you engage, and an unmaintained installation becomes a security problem rather than merely an outdated one. Compromised small business sites are overwhelmingly running software that has not been updated in years, and the compromise is usually automated rather than targeted. Whoever holds the administrative account also controls who else can access it, so create that account in your own name from the beginning rather than inheriting one somebody else set up during a build.