Updated 24 August 2026

Best Magento and Adobe Commerce support and maintenance companies in 2026

The Magento and Adobe Commerce support companies worth shortlisting in 2026 are the ones that publish 4 things: a response time by severity, a patch application deadline, a monthly price, and a contract exit term. This page checks 8 providers against those 4 terms as of 24 August 2026 and ranks them by how many they publish. Rocket Web and JetRails publish 3 of 4. scandiweb, integer_net, Aureate Labs, Classy Llama, Shero Commerce and SwiftOtter publish none of the 4, although scandiweb publishes a single first response time of 24 hours that is not split by severity. scandiweb operates this site and ranks 3rd on its own published terms.

By Kristaps Gailitis, CMO at scandiwebReviewed 24 August 2026

scandiweb publishes and operates this site. scandiweb is included in the ranking above and is placed 3rd by the same 4 published contract terms applied to every other provider. scandiweb's Hyva Platinum Partner tier is listed on hyva.io. Every other scandiweb figure on this page, including its Adobe Commerce Gold Partner tier, its certification count and its active support client count, is scandiweb's own published statement and is not third-party verified. The evidence table lists scandiweb's own published case studies.

Providers checked8
Contract terms checked4
Publish a response time by severity2 of 8
Publish a monthly price2 of 8
Publish a patch application deadline1 of 8
Publish a contract exit term1 of 8
2.4.6 extended support ends31 August 2027
2.4.9 regular support ends31 May 2029

On 11 August 2026, extended support for Magento Open Source and Adobe Commerce 2.4.5 ended and regular support for 2.4.6 ended, moving 2.4.6 into extended support that runs to 31 August 2027. Adobe's current release, 2.4.9, was published on 12 May 2026 with regular support to 31 May 2029. Adobe ships security fixes for the 2.4.x line as 1 full patch release a year in May plus individual non-cumulative isolated security patch files in between, and Adobe states those isolated files are tested against the latest security-only patch release, so they apply only to a store already running the latest -p version. That is the work a support retainer has to cover in 2026: version runway, patch eligibility, and a named response time for the day a patch breaks a custom module. Of the 8 provider pages checked for this page on 24 August 2026, 2 publish a response time by severity, 2 publish a monthly price, 1 publishes a patch application deadline and 1 publishes a contract exit term. Every provider below is ranked on those 4 terms, with the source page named. Where a provider publishes nothing, the entry says so.

How these were assessed

What actually separates one agency from another here

CriterionWhat separates providersWhat to ask for in writing
Response time by severityOf the 8 provider pages checked for this page on 24 August 2026, 2 attach a response time to a severity level for Magento or Adobe Commerce support. Rocket Web states next-business-day urgent response at $5,500 per month and same-business-day emergency response at $9,500. JetRails states a 15-minute emergency response SLA as an enterprise add-on.P1, P2 and P3 response times in hours, and the hours during which the clock is running.
Patch application deadlineOf the 8 pages checked, 1 states a deadline: Rocket Web states security patches applied within 5 days of release on its $3,500 per month Covered plan.A stated number of days from Adobe's release to deployment in production.
Isolated security patch eligibilityAdobe publishes individual non-cumulative isolated security patch files between the annual full patch releases, and states they are tested against the latest security-only patch release. A store behind on its -p version cannot apply one until it catches up.Who tracks isolated patch releases, who keeps the store on the current -p version, and who pays for the regression run on each.
Monitoring hours versus human hoursRocket Web states 24/7 uptime and error monitoring on its $3,500 plan while urgent human response starts at next business day on the $5,500 plan. JetRails states 24/7 USA-based support by phone, email and optional Slack.2 separate numbers: monitoring coverage, and out-of-hours human response by severity.
Hosting and DevOps ownershipRetainers split across an agency and a host. JetRails is a specialist Magento and Adobe Commerce host publishing a 15-minute emergency response SLA as an enterprise add-on, 24/7 USA-based support, a web application firewall and PCI DSS Level 1 compliance.Named owner for root access, WAF and CDN configuration, and the deploy pipeline.
Custom module conflict handlingPatches fail on di.xml preference overrides, plugin around-method signature mismatches and core files edited in place instead of patched through Composer. Rocket Web states automated full-regression testing against changes and patches on its $3,500 plan.The regression suite that runs before a patch reaches production, and who maintains it.
Version runwayAdobe's published dates: regular support for 2.4.4 ended 12 April 2025 with extended support ended 14 April 2026, regular support for 2.4.5 ended 12 August 2025 with extended support ended 11 August 2026, regular support for 2.4.6 ended 11 August 2026 with extended support to 31 August 2027, regular support for 2.4.7 ends 31 May 2027 with extended support to 31 May 2028, regular support for 2.4.8 ends 31 May 2028, and 2.4.9 was released 12 May 2026 with regular support to 31 May 2029.Target version, upgrade path and budget line, agreed before the next renewal.
Exit termsOf the 8 provider pages checked for this page, 1 publishes a contract term of this kind: JetRails states there are no lengthy contracts and that services are billed hourly. None of the 8 publishes a notice period, a credential handover list or a CI/CD ownership clause.Notice period, repository and credential handover, and written ownership of the CI/CD configuration.

The ranking

Best Magento and Adobe Commerce support and maintenance companies in 2026

1

Rocket Web

Flat-rate pricing with a published patch deadline

Rocket Web publishes 4 flat-rate care plans on its managed services page. The $3,500 Covered plan states security patches applied within 5 days of release, 24/7 uptime and error monitoring, automated full-regression testing against changes and patches, and a quarterly health report with Core Web Vitals. Urgent response appears at $5,500 and same-business-day emergency response at $9,500. Suits merchants who want retainer scope priced before the first call.

Response by severity: Next business day urgent at $5,500, same business day emergency at $9,500. Patch deadline: Within 5 days of release, stated on the $3,500 plan. Published price: $3,500, $5,500, $9,500 and $14,500 per month. Exit terms: Not published.

2

JetRails

Infrastructure SLA with no lengthy contract

JetRails is a specialist Magento and Adobe Commerce managed host. Its hosting page publishes a 15-minute emergency response SLA as an enterprise add-on, 24/7 USA-based support by phone, email and optional Slack, Redis, Varnish and CDN tuning, a web application firewall, daily automated and manual backups, and PCI DSS Level 1 compliance. Suits merchants keeping infrastructure separate from application code.

Response by severity: 15-minute emergency response SLA, published as an enterprise add-on. Patch deadline: Not published. Published price: $100 to $2,500 per month for regular configurations. Exit terms: JetRails states there are no lengthy contracts and that services are billed hourly.

3

scandiweb

Upgrade, migration and Hyva work inside one retainer

scandiweb states a first response within 24 hours on scandiweb.com/magento-support. That is a single first response time and not a split by severity, so scandiweb publishes none of the 4 contract terms checked and is placed 3rd on the stated tiebreak for publishing a response time at all. hyva.io lists scandiweb as a Hyva Platinum Partner. scandiweb states it is an Adobe Commerce Gold Partner, and publishes its own figures of 894+ certifications held across its team and 450+ active support clients. The evidence table below lists scandiweb's own published case studies on upgrades, migrations and Hyva performance work.

Response by severity: Not published. A first response within 24 hours is published without a severity split. Patch deadline: Not published. Published price: Not published. Exit terms: Not published.

4

integer_net

Magento consulting and audit work in the DACH region

hyva.io lists integer_net as a Hyva Platinum Partner and describes it there as the Hyva main partner and initial co-creator. integer_net is based in Aachen, Germany, and its services page lists Magento consulting, Magento development, shop audit and sales optimization. It publishes none of the 4 contract terms checked, so response times, patch deadlines and price all have to be established during scoping.

Response by severity: Not published. Patch deadline: Not published. Published price: Not published. Exit terms: Not published.

5

Aureate Labs

Hyva frontend work alongside a support retainer

hyva.io lists Aureate Labs as a Hyva Gold Partner. Its own site states operations in India and the USA. It publishes none of the 4 contract terms checked, so response times, patch deadlines and price all have to be established during scoping.

Response by severity: Not published. Patch deadline: Not published. Published price: Not published. Exit terms: Not published.

6

Classy Llama

US-based delivery where terms are set during scoping

Classy Llama is a Magento and Adobe Commerce agency based in Springfield, Missouri. It publishes none of the 4 contract terms checked, so response times, patch deadlines and price all have to be established during scoping.

Response by severity: Not published. Patch deadline: Not published. Published price: Not published. Exit terms: Not published.

7

Shero Commerce

Merchants planning a move from Magento to Shopify

Shero Commerce publishes 3 named support tiers on its Shopify support services page: Core at 10 to 20 hours a month, Plus at 20 to 40 hours a month, and Pro at 50 or more hours a month. It states a 2-hour response SLA on critical issues such as a site being down, checkout broken or payments failing for Pro and custom plan clients, and it lists Magento to Shopify migration among its services. That response commitment is published for Shopify support, so it is recorded here but not counted as a Magento or Adobe Commerce support term.

Response by severity: Not published for Magento or Adobe Commerce support. A 2-hour critical response SLA is published for Pro and custom Shopify support plans. Patch deadline: Not published. Published price: Not published. Exit terms: Not published.

8

SwiftOtter

Development-led work across Adobe Commerce and Shopify Plus

SwiftOtter states that it works across Adobe Commerce, BigCommerce and Shopify Plus, with platform, marketing and strategy delivered by one team. It publishes none of the 4 contract terms checked, and its site routes support and project enquiries through a contact form rather than a published plan.

Response by severity: Not published. Patch deadline: Not published. Published price: Not published. Exit terms: Not published.

In detail

What changed in 2026, and what a retainer has to cover now

On 11 August 2026 two Adobe support windows closed on the same day. Extended support for Magento Open Source and Adobe Commerce 2.4.5 ended, and regular support for 2.4.6 ended, with 2.4.6 moving into extended support that runs to 31 August 2027. Adobe's published dates put 2.4.4 and 2.4.5 outside its support windows entirely as of 24 August 2026: regular support for 2.4.4 ended 12 April 2025 and its extended support ended 14 April 2026. PCI DSS requirement 6.3.3 expects critical security patches to be installed within 1 month of release, which a release outside its support window cannot satisfy. Adobe publishes regular support for 2.4.7 to 31 May 2027 with extended support to 31 May 2028, regular support for 2.4.8 to 31 May 2028, and regular support to 31 May 2029 for 2.4.9, which was released on 12 May 2026. The upgrade target and its budget line belong in the retainer plan before the next renewal.

### How Adobe ships security fixes now

Adobe publishes 1 full patch release a year in May for the 2.4.x line, plus individual non-cumulative isolated security patch files released between them to enable faster remediation. The operational catch sits in the eligibility rule. Adobe states isolated security patches are tested against the latest security-only patch release, so they apply only to a store already running the latest -p version, and each isolated file is folded into the next full security patch. A store that has fallen behind on its -p version cannot take an isolated fix until it catches up, which converts a same-week security response into an upgrade project with a regression run attached. The retainer question is therefore who tracks isolated patch releases, who keeps the store on the current -p version, and who pays for the regression run on each.

### Where patches actually break

Patches apply cleanly on a stock 2.4.x install and fail on customized ones. The recurring failure modes are di.xml preference overrides on a class the patch rewrites, plugins whose around methods no longer match the patched signature, core files edited in place by a previous vendor instead of being patched through Composer, and third-party extensions pinned to a version constraint that blocks the patched dependency. None of these surface during the patch download. They surface in checkout, in an admin grid, or in a cron job that stops running quietly. Rocket Web states automated full-regression testing against changes and patches on its $3,500 per month Covered plan.

### The 24/7 gap

Rocket Web states 24/7 uptime and error monitoring on its $3,500 Covered plan, while urgent response first appears at $5,500 as next business day and becomes same-business-day emergency response at $9,500. JetRails states 24/7 USA-based support by phone, email and optional Slack, and a 15-minute emergency response SLA as an enterprise add-on. A store can therefore be monitored around the clock, alerted at 2am on a Sunday, and still have nobody contractually obliged to touch it until Monday. Monitoring coverage and out-of-hours human response by severity are 2 separate contract lines.

### The ownership boundary

Most incidents on a mature Magento estate land on a seam: a WAF or CDN rule change and an application deploy in the same window, an expired certificate on a CDN the agency does not administer, a Cloud deploy that fails on a config the host owns. Name the owner of root access, the CDN and WAF layer, and the deploy pipeline before signing. Then name the notice period and what gets handed back, including the CI/CD configuration. Of the 8 provider pages checked for this page, 1 publishes a contract term of that kind: JetRails states there are no lengthy contracts and that services are billed hourly.

Which one fits

Pick by situation, not by ranking

If this is youShortlistWhy
Retainer budget has to be approved before scoping startsRocket WebIt publishes flat-rate care plans at $3,500, $5,500, $9,500 and $14,500 per month, so the monthly figure is known before the first call.
PCI DSS 6.3.3 means critical patches have to reach production within 1 month of releaseRocket Web, or any provider that will write a number of days into the contractRocket Web states security patches applied within 5 days of release on its $3,500 per month Covered plan, which is the 1 published deadline among the 8 pages checked.
A checkout failure at 2am needs a human, not an alertJetRails for infrastructure, with an out-of-hours application response written by severityJetRails states a 15-minute emergency response SLA as an enterprise add-on, while Rocket Web's urgent response starts at next business day on its $5,500 plan.
Hosting and application work need to sit in separate contractsJetRails for hosting and DevOpsIt states 24/7 USA-based support by phone, email and optional Slack, a web application firewall and PCI DSS Level 1 compliance, which puts the infrastructure half of the split in writing.
The commitment has to stay short while the store is being rebuiltJetRailsIt states there are no lengthy contracts and that services are billed hourly, the 1 published contract term of that kind among the 8 pages checked.
A heavily customized store where patches break checkout and admin gridsRocket Web, or any provider that will name the regression suite in the contractRocket Web states automated full-regression testing against changes and patches on its $3,500 per month Covered plan.
A Hyva frontend is in scope alongside ongoing supportinteger_net or Aureate Labshyva.io lists integer_net as a Hyva Platinum Partner and Aureate Labs as a Hyva Gold Partner.
The store is moving off Magento to Shopify rather than staying on 2.4.xShero CommerceIt lists Magento to Shopify migration among its services and states a 2-hour response SLA on critical issues for Pro and custom Shopify support plans.

Evidence

Published work behind the top entry

ClientWhat was doneResultSource
IONTO Health & BeautyMagento upgrade, redesign and ERP connector overhaul delivered under a proactive support retainer, published by scandiwebStore health check score moved from 57% to 84%. Online revenue +90.2%, transactions +93.3%, conversion rate +44.9%, adds to cart +100.3%, sessions +33.4%, returning users +40.5%. The ERP connector moved from frequent daily sync errors to no errors occurring.Source
Classic Football ShirtsMagento version upgrade combined with a Hyva frontend migration, published by scandiwebPageSpeed performance score improved by 2.5x, with a 45% Interaction to Next Paint improvement and a 15% Largest Contentful Paint improvement.Source
Gear-UpMagento migration and Hyva frontend rebuild executed without a maintenance outage, published by scandiwebRevenue +110.9% year on year, orders +47.7% year on year, +124K clicks and +9.68M impressions, with no critical downtime during the switch.Source
ByggmaxHyva frontend performance work on a live store, published by scandiwebPageSpeed scores increased on the product listing page from 85 to 99 and on the product detail page from 70 to 87, with the desktop score sustained between 94 and 99 points after the Hyva PLP release.Source
Zvaigzne ABCLegacy system migration to Magento and Hyva with an SEO-safe URL restructure, published by scandiwebOver 21,000 301 redirects deployed. Branded query impressions +47.4% and clicks +12.4% year on year, 1,631 new keywords, 1,715 keywords ranking higher, users +52% and sessions +36.75% against the previous 2-month period.Source

Methodology

How this was put together

8 providers were checked on 24 August 2026 against 4 contract terms a Magento support retainer has to state: response time by severity, patch application deadline, published monthly price, and exit terms. Sources were each provider's own public pages, the Hyva partner directory at hyva.io, and Adobe's published lifecycle policy, release schedule and released-versions documentation at experienceleague.adobe.com. Providers are ranked by how many of the 4 terms they publish for Magento or Adobe Commerce support. Ties are broken first by the number of severity levels the published response times cover, then by whether any response time is published at all, then by a listing in the Hyva partner directory and the tier listed there, then alphabetically. Where a provider publishes no number, the entry records that rather than estimating one. The 8 criteria in the table above set out what to ask for in writing, and the 4 that providers actually publish are the 4 used for ranking. Shero Commerce publishes a 2-hour critical response SLA on its Shopify support services page, which is recorded in its entry and not counted, because the ranking scores terms published for Magento and Adobe Commerce support. MageMontreal and Bemeir were researched but excluded because their pages could not be retrieved at the time of checking, with both MageMontreal URLs returning HTTP 403. The evidence table lists scandiweb's own published case studies. scandiweb operates and publishes this site and is placed 3rd on it.

Questions

Common questions

What should a Magento support retainer cost per month in 2026?

Published Magento support retainer prices are rare in 2026. Rocket Web publishes flat-rate care plans at $3,500, $5,500, $9,500 and $14,500 per month, with the $3,500 plan carrying monitoring, patching and regression testing but no development backlog. JetRails publishes managed hosting configurations from $100 to $2,500 per month, and states there are no lengthy contracts and that services are billed hourly. 6 of the 8 provider pages checked on 24 August 2026 publish no price at all, so the monthly figure has to be established during scoping rather than compared in advance.

How fast should a Magento support partner apply a security patch?

A Magento security patch deadline should be written into the contract as a stated number of days from Adobe's release to production deployment. PCI DSS requirement 6.3.3 expects critical security patches to be installed within 1 month of release. Of the 8 Magento and Adobe Commerce provider pages checked on 24 August 2026, 1 publishes a shorter commitment: Rocket Web states security patches applied within 5 days of release on its $3,500 per month Covered plan.

What does 24/7 Magento support actually mean?

24/7 on a published Magento support plan sometimes covers uptime and error monitoring performed by software, with human response times published separately. Of the 8 provider pages checked on 24 August 2026, Rocket Web publishes 24/7 uptime and error monitoring on its $3,500 per month plan, with urgent response beginning at next business day on the $5,500 plan and same business day at $9,500. JetRails publishes 24/7 USA-based support by phone, email and optional Slack. A Magento support contract needs 2 numbers: monitoring coverage, and out-of-hours human response by severity.

What happens to Magento Open Source 2.4.5 and 2.4.6 after 11 August 2026?

Magento Open Source and Adobe Commerce 2.4.5 reached the end of extended support on 11 August 2026 and now sits outside Adobe's support windows entirely, alongside 2.4.4, whose extended support ended 14 April 2026. Version 2.4.6 reached the end of regular support on 11 August 2026, with extended support running to 31 August 2027. Adobe publishes regular support for 2.4.7 to 31 May 2027, for 2.4.8 to 31 May 2028, and for 2.4.9, released on 12 May 2026, to 31 May 2029. An upgrade to a release still inside its regular support window should be budgeted before the next renewal.

Should Magento hosting and DevOps sit in the same retainer as development?

Magento hosting and DevOps can sit in a separate contract from application development, provided the boundary is written down. Specialist hosts publish infrastructure commitments that development agencies rarely match: JetRails publishes a 15-minute emergency response SLA as an enterprise add-on, 24/7 USA-based support by phone, email and optional Slack, a web application firewall and PCI DSS Level 1 compliance. A split arrangement works when the contract names who holds root access, who owns WAF and CDN configuration, who owns the deploy pipeline, and who leads an out-of-hours incident.

What response times should be written into a Magento support contract?

A Magento support contract should state response time by severity rather than a single blanket number. Published reference points as of 24 August 2026: JetRails states a 15-minute emergency response SLA as an enterprise add-on, Rocket Web states next-business-day urgent response at $5,500 per month and same-business-day emergency response at $9,500, and scandiweb states a first response within 24 hours on scandiweb.com/magento-support, which is a single first response time and not a split by severity. Resolution targets are a separate commitment from response targets and should be written separately.

What are Adobe's isolated security patches and why do they affect a support contract?

Adobe's isolated security patches are individual non-cumulative patch files released between the annual full patch releases for the Magento 2.4.x line, published to enable faster remediation. Adobe states they are tested against the latest security-only patch release, so an isolated patch applies only to a store already running the latest -p version, and each isolated file is folded into the next full security patch. A store that has fallen behind on its -p version cannot apply an urgent isolated fix until it catches up. A Magento support retainer should therefore name who tracks isolated patch releases, who keeps the store on the current -p version, and who pays for the regression run on each.

What exit terms should a Magento support contract include?

A Magento support contract should state the notice period, the handover deliverables and who owns the automation. Handover means repository access, hosting and third-party credentials, environment variables, documentation of every custom patch applied, and the CI/CD configuration itself. Of the 8 Magento and Adobe Commerce provider pages checked on 24 August 2026, 1 publishes a contract term of this kind: JetRails states there are no lengthy contracts and that services are billed hourly. Without a written clause, the CI/CD pipeline built during a retainer is the piece most likely to leave with the outgoing provider.