Agency selection
Website Developer Agency: What to Buy and Verify
An agency's job is to turn what your business needs into a website you can actually run, with someone clearly on the hook for the design, the code, the content, the testing, the launch and the support afterwards. Judge them on who they are putting on your project and what they will put in writing, not on the word “agency”.
Reviewed August 3, 2026 against current W3C, OWASP and U.S. Copyright Office guidance, all linked at the foot of this page.
Hassan Jamal·May 12, 2026·9 min read
The short answer
- ✓Hire an agency when the job needs several different skills and one person answerable for delivering it.
- ✓Define outcomes, scope, acceptance, ownership and support before comparing price.
- ✓Ask for evidence, both tested by hand and by tool, that it is accessible, secure, working, still ranking and fast.
- ✓Use a freelancer or your own team when you already have someone doing the coordinating and the quality checking.
Build
Architecture, frontend, backend, CMS and integrations.
Access
WCAG target, keyboard, semantics and human testing.
Protect
Threats, data, credentials, dependencies and incidents.
Discover
Crawlability, content, metadata, schema and measurement.
What a full-service website developer agency does
Seven phases, and what you buy from an agency rather than a contractor is one party answerable across all of them. Any of the seven can be bought separately, and often is. The reason to buy them together is that the seams between them are where projects fail, and a single accountable party owns those seams.
- ✓Discovery: goals, audiences, journeys, constraints, data and current evidence.
- ✓Strategy: information architecture, measurement, content and technical decisions.
- ✓Design: research, flows, wireframes, responsive UI and design system.
- ✓Engineering: frontend, backend, CMS, integrations, data and infrastructure.
- ✓Quality: content, function, accessibility, security, SEO, analytics and performance.
- ✓Release: migration, rollback, monitoring, Search Console and account handoff.
- ✓Operation: defect support, maintenance, incidents, upgrades and change requests.
The engagements you are actually buying
Those phases get packaged into a handful of distinct engagements. Naming which one you need before you brief anybody removes most of the ambiguity from the quotes that come back.
- ✓New build. A site designed and developed for this business rather than adapted from a template, including the content model and the editing workflow the team will use afterwards.
- ✓Platform migration. Moving an existing site to a different stack while keeping its content, its URLs and its search visibility intact. The technical core is a mapped redirect for every indexed URL, tested before cutover rather than after.
- ✓Commerce and headless storefronts. A custom storefront in front of an existing commerce backend, so checkout, inventory and orders stay where they are while the customer-facing layer is rebuilt.
- ✓Custom application engineering. Work no platform covers: calculators, portals, dashboards, internal tools and integrations between systems that do not speak to each other.
- ✓Operation. Hosting, monitoring, security updates, content changes and incident response after launch. Decide whether you are buying this before you sign, not after the support window lapses.
Core services and their acceptance evidence
Every service in this table has an artefact that proves it was delivered, and the second column is the one to read. A service with no named acceptance evidence is a line on an invoice rather than a deliverable. Ask for that column to appear in your own proposal, because it is what turns sign-off into a check rather than an opinion.
| Service | Deliverable | Evidence |
|---|---|---|
| UX and design | Accepted flows, components and responsive states | Prototype review and agreed device coverage |
| Content and CMS | Content model, migration and editor workflow | Counts, exceptions, preview and publishing tests |
| Accessibility | Agreed WCAG 2.2 conformance target | Automated checks plus keyboard and human evaluation |
| Security | Controls appropriate to the data and threat model | ASVS-informed tests, dependency review and runbooks |
| SEO | Rendered signals, URL plan and monitoring | Crawl, index, metadata, schema and redirect tests |
| Performance | Accepted pages, profiles and targets | Recorded runs plus field monitoring where available |
How much does a website developer agency cost in 2026?
Nobody can publish an honest agency rate table without a dated sample where every quote covers the same scope. What you pay depends on how much thinking the project needs, how many templates sit behind the pages, who writes the content, how much data has to move, what it connects to, whether it has to meet accessibility or compliance rules, how much testing there is, and what support you get afterwards. The only fair comparison is several proposals answering one brief. Our website cost guide works through the same inputs, and custom build timelines covers the schedule side of the same scope.
PandaCodeGen's public planning tiers start at $1,500 Starter, $3,500 Growth and $5,000 to $10,000 Scale, with larger work scoped separately. Standard payment is 30 percent at onboarding and 70 percent on delivery under the signed agreement. These are PandaCodeGen terms, not a market average.
Platforms a modern agency may support
A platform is not automatically modern or legacy. An agency may deliver WordPress, Shopify, Webflow, headless CMS, Next.js or other application stacks. What decides it is how your team wants to edit, what the site has to do, what data is involved, what your people can actually run, security, speed, whether you can take it elsewhere, and operating model. Ask why the proposed platform fits and what would disqualify it.
Our platform pages set out what a move to or from each stack involves: WordPress migration, Shopify and WooCommerce storefront engineering, Webflow migration, and custom application engineering for work that no platform covers. If the proposal separates the storefront from the backend, read what headless commerce means before you accept the architecture.
A four-stage delivery process
Four stages, each producing something you can inspect before the next begins. Define ends with an agreed scope. Design ends with approved templates. Build and verify ends with test evidence. Launch and operate ends with a handover you hold. A proposal that cannot say what each gate produces has not been planned to that level yet.
- Define. What you have, what you need, what could go wrong, how you will measure it, what is in scope, what you are assuming, and how you sign it off. The deliverable is written, and it includes what the current site actually does today, measured rather than described.
- Design. How the site is organized, what the content is, how people move through it, what it looks like, prototypes, and the technical calls. Architecture is the planning that happens before code: URL structure, content model, integrations, environments. Deciding it upfront costs hours. Discovering it halfway through the build costs weeks.
- Build and verify. Writing it, moving the data, wiring up the integrations, reviewing the work, and recording evidence that it is right. Ask for working progress at a regular interval rather than a single reveal at the end, so a wrong direction surfaces in the second week instead of the third month.
- Launch and operate. The switchover, the ability to undo it, monitoring, handing it over, support and maintenance. A low-risk cutover keeps the current site serving until the replacement has been tested on a staging URL, exports every indexed URL and maps it to its new path before anything moves, validates the map, then makes the switch at DNS with the TTL lowered in advance so propagation is quick and reversible.
Four contract lines the standard checklist always misses
Search for what belongs in an agency contract and you get the same list everywhere: scope, deliverables, revision rounds, payment milestones, late fees, intellectual property. That list is correct and it is written for agency work in general, not for a website. Four things specific to websites are missing from it, and each one is expensive to discover after signing rather than before.
- ✓Account ownership, named individually. Domain registrar, DNS, hosting, repository, CMS, analytics, tag manager, payment gateway. Intellectual property clauses cover code and rarely mention accounts, and accounts are where lock-in actually happens. Ask whose email address each one is registered under, today.
- ✓The redirect map, if any URL changes. This is the single most commonly assumed line in a rebuild. It is real work, it protects existing search traffic, and if it is not itemized then nobody has priced it and nobody has been made responsible for it.
- ✓Acceptance criteria with test conditions attached. Not “a fast site” but which pages, which device profiles, how many passing runs, measured how, and what happens if it fails. A performance number with no conditions is not a term, it is a slogan.
- ✓What you receive if the project stops mid-way. Most contracts describe completion and cancellation and skip the state in between, which is the one you are most likely to be in if something goes wrong. Agree now whether partial work, designs and access transfer at that point.
None of these is adversarial and a competent vendor will have answers ready. The reason to raise them before signing rather than after is simply that all four are cheap to write down now and expensive to negotiate once the relationship is under strain. Our guide to what you actually own works through the ownership side in detail, including why a “work made for hire” clause often does not do what people assume.
Performance terms to put in writing
PandaCodeGen's 90-plus target is conditional on agreed representative pages, mobile and desktop profiles, recorded environment and three recorded runs per page and profile. It is not a promise that every URL, on every device, forever, scores 90. The contract should state the target, test, evidence, exclusions, cure and remedy. For what the underlying page metrics actually measure, see Core Web Vitals explained.
If you are reading this from the other side of the table — an agency deciding whether to offer custom development rather than a business buying it — the partner-side version of this guide covers the same ground from the delivery end.
In-house developer vs agency vs freelancer
The reason coordination is worth paying for is that website problems rarely sit in one discipline. A page that loads slowly is often a hosting decision, a code decision and a content decision at the same time, and the search consequences belong to none of those three people individually. Someone who only writes frontend code will correctly report that the frontend is fine. They will be right, and the page will still be slow.
So the question is not really agency versus freelancer. It is who is going to notice when a problem crosses a boundary, and who is answerable when it does. If you already have someone doing that job, a specialist is often the better and cheaper hire. If you do not, you are buying that role whether it appears on the invoice or not, and it is worth knowing which person it is.
| Model | Strength | Buyer must cover |
|---|---|---|
| Internal team | Context, continuity and direct control | Capacity, specialist gaps and opportunity cost |
| Freelancer | Focused skill and flexible engagement | Direction, design, QA, continuity and release ownership |
| Agency | Coordinated disciplines and delivery accountability | Vendor governance, assigned-team verification and handoff |
How to choose the right agency
Comparable work and a written scope tell you more than positioning does. Our project case studies show the scope behind each build, and our review of US custom development agencies sets out the criteria we use to compare shops.
- ✓Ask for current, comparable work and directly contactable references.
- ✓Take the live URLs from their portfolio and measure them yourself. A claim about performance that you can check in a browser is worth more than one you cannot.
- ✓Meet the delivery lead and senior technical owner, not only sales.
- ✓Review the actual statement of work, assumptions and exclusions.
- ✓Require accessibility, security, SEO, functional and performance acceptance.
- ✓Define change control, payment, refund, support, termination and dispute process.
- ✓Define content, custom deliverables, reusable tools, third-party licenses, repository and accounts.
- ✓Confirm ongoing maintenance, incident responsibility and exit.
How to verify what an agency tells you
Shortlisting three to five agencies and checking reviews is the standard advice and it is fine as far as it goes. The part usually left out is what to actually check, because most of what an agency publishes about itself cannot be falsified by reading it more carefully.
Portfolios show sites at launch, not today.Open every portfolio link and check three things: that it still resolves rather than 404s, that it still looks like the case study, and that the agency's own footer credit or the underlying stack is still there. A portfolio piece that has since been rebuilt by somebody else is not evidence of a lasting result, and it is a fair question to ask about. Run the live URLs through PageSpeed Insights yourself rather than accepting a screenshot of a score, which is a lab result from an unknown date and device.
Third-party reviews are worth checking and worth reading properly. Clutch, Trustpilot and the relevant subreddits are where feedback sits that the agency does not control. Read the three-star reviews before the five-star ones, because they are where scope disputes, delays and communication problems actually get described. Check whether the reviews mention the people you have been meeting: a strong record earned by a team that has since left tells you about the past, not about your project. Treat review volume in this industry with some perspective too, since most small studios have very few reviews and an absence of them is weak evidence either way.
Ask what happens after launch, in writing. Who holds the domain, the repository, the hosting account and the analytics property. Whether you receive documentation and a walkthrough for your own team, or whether every future change routes back through the agency. Whether the stack is portable or the site only runs on their proprietary hosting. Those answers decide what your options look like in year two, and they are cheap to get before signing and expensive to discover afterwards. What that looks like in a contract is set out under ownership and licensing below.
Seven questions before signing
Seven questions, and the answers matter more than the asking. A usable answer names something specific enough to write into the scope and check later; a vague one tells you the work has not been thought through yet. Ask all seven of every finalist, including us, and compare the answers side by side.
- Who exactly will deliver the work, and what relevant project did they complete?
- Which requirements, pages, data and integrations are excluded?
- How will each acceptance target be reproduced?
- What triggers a change order, and who approves it?
- Who controls the domain, repository, hosting, CMS, analytics and business accounts?
- What will this cost to run every month once it is live, itemized by provider?
- What happens after launch, at termination and when another team takes over?
A usable answer names something specific enough to write into the scope and check later. An evasive one does not.
| You asked | A usable answer | An answer to press on |
|---|---|---|
| Who writes the code? | Named people, with work you can look at | "Our team handles that" |
| What performance do you commit to? | A stated target on named pages, a stated measurement method, and a stated remedy | "We prioritize performance" or an unconditional promise with no method attached |
| Do I receive the source code? | The repository transfers to an account you control, and you can deploy it elsewhere | Access to a copy they host, contingent on staying a customer |
| What will it cost monthly? | A line per provider, with which ones are optional | "We can work that out after launch" |
| How do you protect search visibility? | Every indexed URL exported and mapped before cutover, with the map validated first | SEO quoted as a separate service to be bought later |
Founder-led, senior-led and outsourced teams
Team structure alone does not prove quality, so do not treat founder-built as a shortcut for good or outsourced as a shortcut for bad. A founder-led boutique can offer direct accountability but limited capacity. A larger or distributed team can offer specialist depth but more handoffs. Require disclosure of assigned roles, subcontractors, locations, access, confidentiality, review and accountability. Ours are named on the PandaCodeGen team page.
Ownership and licensing
U.S. copyright ownership does not automatically follow payment in every contractor relationship. Put transfer or licensing in a signed writing and separate custom deliverables from client content, pre-existing materials and third-party components. PandaCodeGen's current policy is custom-deliverable transfer after full payment under the contract, retention of reusable tools and pre-existing code, and continuation of third-party licenses. The practical checks are set out in do you own your website.
This page gives you questions to ask rather than headline numbers, because hosting bills, traffic capacity, store revenue and security outcomes all depend on the specific build, stack and operating conditions behind them. Where we do commit, we commit in the scope document: our performance commitment is a 90+ Lighthouse handover target on mobile and desktop for the representative pages named in that scope, verified across three recorded runs. Ask any agency to write its equivalent commitment the same way, with the pages, the devices and the verification method stated.
Related reading
If budget is the constraint, read what a low-cost developer leaves you to cover. If the site already exists, our redesign cost breakdown explains which parts of a rebuild carry the scope.
Frequently asked questions
Frequently Asked Questions
Is web development dead because of AI?
No. AI can assist research, coding and testing, but the buyer still needs accountable requirements, architecture, security, accessibility, privacy, integration, validation and ownership decisions. Evaluate the named team and its evidence rather than assuming tool use guarantees speed or quality.
What is the 3 second rule in website design?
It is a planning heuristic, not a universal abandonment point or Google requirement. Use your own real-user and funnel evidence. Google publishes Core Web Vitals thresholds for field experience, but passing them does not guarantee rankings, conversion or revenue.
Can a website developer agency preserve existing SEO rankings during migration?
Ask the agency to show you the URL map before work starts, not after launch. That single document is where migration SEO is won or lost, and an agency that cannot produce one has not scoped the job. Rankings and recovery timing stay with the search engines; what a vendor can be held to is that every old address resolves and every template renders its content in HTML.
How is a website developer agency different from a web design company?
Labels overlap. Compare the actual scope and assigned team across research, UX, visual design, content, frontend, backend, integrations, accessibility, security, SEO, analytics, QA, launch and operations. Platform choice alone does not establish quality, performance or ownership.
What should I ask a website developer agency before signing?
Ask who performs the work, what routes and features are included, how acceptance is evidenced, which costs and dependencies are excluded, who owns code and accounts, and how changes, launch, rollback, support, termination and remedies work. Put the answers in the signed scope.
Primary sources
Get a migration plan and comparable scope
We will turn the current site, risks and required outcomes into a written scope you can use to evaluate PandaCodeGen or another qualified agency.
Related Articles
Next.js Development Agencies in 2026: A Disclosed Shortlist
Compare eight Next.js and software-engineering partners using current official service evidence, transparent inclusion rules and a buyer verification framework.
Pagepro Alternatives in 2026: Compare Scope and Fit
A commercially disclosed way to compare Pagepro, Naturaily, Blazity, PandaCodeGen and other Next.js partners using current services and equivalent written requirements.
Cheap Web Developer: How to Hire Without Getting Burned (2026)
Compare affordable web proposals by scope, live evidence, security, accessibility, SEO migration controls, ownership, support, and full operating cost.