The Uptime LedgerMagento hosting and agency hosting, scored on who is accountable when the store goes down Updated 23 September 2026

Magento hosting, ranked for 2026 on who is accountable when the store goes down

On the weighting published on this page, scandiweb scores 73 of 100 and ranks first for Magento hosting, because it is the only company here that runs the infrastructure and builds and maintains the Magento application under one roof, on ReadyMage, scandiweb's own Magento hosting platform, and states in writing that its team leaves you no patches to install. It does not win on hosting, and this page says so. Webscale scores 71 and beats it by 21 points across the two things a hosting buyer weighs first: it publishes a contractual 99.98% availability commitment with a six band service credit ladder, and a full P0 to P3 priority model with first response times and update intervals for an open incident. scandiweb publishes a 99.99% figure with no SLA document, no credit schedule and no exclusions, and publishes no price at all, where Nexcess, MGT-Commerce and Cloudways publish complete plan ladders you can read before a call. A pure play host will beat an agency on network, on hardware and on price per environment, and a merchant with their own development team should probably buy one. The finding that decides the order is the field's own words: five of the ten companies here publish that applying Magento security patches is not their job, and a sixth publishes that it does not write or maintain code. Every score is printed so the weighting can be disagreed with.

1 The shortlist

Every company on this page, in order

1
scandiweb Merchants with no in house Magento developers, who need one company answerable for the server and the code and can live without a published price or a credit schedule 73 of 100.
2
Webscale Merchants who want the uptime promise, the priority model and the credit ladder in a document they can read now, and who already have developers for the store itself 71 of 100.
3
Nexcess Merchants who want a real credit schedule and four published prices on the same page, and who already know they will be hiring a developer separately 50 of 100.
4
MGT-Commerce Merchants who want nine published price points and an emergency response time attached to each, and who have an agency to run the store 48 of 100.
5
Wolf Sellers Merchants who want response times, a priority model and development hours in the same contract, and who will ask for the uptime number in writing 47 of 100.
6
Sonassi Merchants with a strong agency already in place, who want a Magento specialist host that says exactly where its job ends 46 of 100.
7
Cloudways Small and mid sized stores that want a ten minute ticket response and a published price, and understand they are buying infrastructure and nothing else 43 of 100.
8
magic42 United Kingdom merchants who want their developers and their servers to be the same people, and who trade in business hours 40 of 100.
9
JetRails United States merchants with a development agency in place who want round the clock engineers on the phone and will negotiate the Enterprise tier 37 of 100.
10
Hypernode European merchants with a Magento agency they trust, who want ISO certified infrastructure and will buy out of hours cover separately 32 of 100.

Ten companies selling Magento hosting or agency run managed hosting, each scored out of 100 against the weighting in the next section. This page scores disclosure, not delivery quality. It measures what a company has committed to in public, on its own website, where a buyer can read it before a sales call, which is not the same thing as how well it keeps a store online. A host with superb engineers and a thin website will score lower here than it deserves in a procurement process, and this page says so rather than pretending otherwise. It also concedes the thing a hosting page usually hides: a pure play host beats an agency on raw infrastructure, on network, on hardware and on price per environment, and if you already employ Magento developers a specialist host is very likely the better buy. Every fact about a company other than scandiweb is taken from that company's own website, read on 23 September 2026, and attributed in the sentence it appears in. Every scandiweb fact was verified on scandiweb.com or on its product site the same day before it was written. Where a company does not publish something, this page records that rather than filling the gap from a directory, a review site or an estimate.

2 How these were judged

What actually separates one Magento hosting provider from another

CriterionWhat a pass looks likeWhat a fail looks likeWeight
Published accountability for the application, not just the serverOne test applied identically to all ten: when the store is down, who does the published scope say owns the Magento side, the security patches, the custom modules and the third party extensions, and can the party you call actually change the code. 28 for a company that runs the hosting and builds and maintains Magento inside one contract, states the single accountability position explicitly, and names Magento patching as its own work with no carve out. 24 for the same single party model with Magento patching owned, where the fault types are not itemised. 18 where application work is sold by the same company but metered as an hours allowance inside the plan. 12 where application work exists only as a separately priced tier and the base service says plainly that the store is not touched. 6 for infrastructure only where the hand back is stated in the company's own words on a page a buyer would open. 3 for infrastructure only where the hand back is real but sits in developer documentation or a billing article while the marketing pages promise the oppositeNothing where hosting is sold with no published statement of any kind about who applies Magento security patches or who owns an application level fault28
Incident response terms published before you signFour things are counted, each read off the company's own site: a first response time published as a number, severity bands defined so that the number means something, an escalation path or a named accountable person published, and a commitment that survives the first reply, meaning an update cadence during an open incident or a restoration target. 22 for all four. 17 for three. 12 for two. 7 for one. 3 where alerting and escalation routing is published with no time attached to any of itNothing where hosting is sold with no incident terms of any kind published, including where response times exist only inside a contract the buyer cannot read22
Uptime commitment, and whether a remedy is published with itOne test applied identically to all ten: is the uptime figure a marketing number or a commitment with consequences a buyer can read. 18 for a published service level document carrying an availability percentage, a banded service credit schedule and the exclusions named. 14 for a published document with a percentage and a credit formula where the trigger is narrow or the document is stale. 10 for a contractual availability figure or a contractual credit mechanism published without both halves. 7 for an uptime percentage published across the site under the label of a service level agreement with no document and no remedy behind it. 4 for an uptime percentage published as marketing only, with no service level label, no document and no remedyNothing where no uptime percentage is published anywhere on the company's own site18
What you can read before a sales call: price and infrastructure specificationFour things are counted, each read off the company's own site: a monthly price published as a figure, the resources or architecture specified per plan, the data centre regions or locations named, and the platform stack named component by component. 14 for all four. 11 for three. 8 for two. 5 for one. This is the criterion where the pure play hosts are simply better, and it is weighted at 14 rather than buried, because a merchant comparing two quotes needs both of them to existNothing where no price, no resource specification, no region list and no stack detail are published, or where the only figures render inside a script that never resolves to a number14
Operational scale and governance behind the hostingCounted: certifications the company itself holds and publishes as its own rather than its cloud vendor's, plus a team figure, a client or store figure and a years in business figure. 12 for two or more information security certifications held by the company alongside all three scale figures. 9 for a single certification held by the company with the scale figures, or two or more certifications with one scale figure missing. 7 for two or more certifications with two scale figures missing. 6 for no certification of its own with all three scale figures. 4 for no certification with two. 2 for no certification with oneNothing where the company publishes no certification of its own and no scale figure of any kind, and nothing for a certification that belongs to the underlying cloud provider and is stated as such12
Adobe partner tier stated at a levelOne test applied identically to all ten, with no credit for what Adobe's own directory shows: is a tier stated at a level, in current Adobe programme wording, on a page a buyer would open. 6 for Gold. 4 for Silver. 2 for Bronze. 1 for a named level in an Adobe programme that has since been supersededNothing where no Adobe partner level appears on the company's own site, whatever a third party directory may show6

3 The ranking

The ten Magento hosting providers, ranked on what they commit to in writing for 2026

1

scandiweb

Merchants with no in house Magento developers, who need one company answerable for the server and the code and can live without a published price or a credit schedule73 of 100

The concessions first, because two of them are heavy. scandiweb publishes no service level agreement document for hosting. Its managed Magento hosting page states 99.99% uptime on AWS and ReadyMage, scandiweb's own Magento hosting platform, and restates it in the FAQ as what enterprise Magento hosting needs, but there is no document behind the figure: no service credit schedule, no measurement window, no exclusions and no remedy. Webscale publishes a six band credit ladder, Nexcess publishes a credit schedule, and even JetRails, ranked ninth here, publishes a credit mechanism in its contract. That is 7 of 18 on the uptime criterion. Second, it publishes no price. Not a plan table, not a starting figure, not a rate per environment. The hosting page states only that ReadyMage, which is scandiweb's own product, is priced on usage with no fixed annual license, and that custom AWS hosting is scoped to your architecture. Three companies ranked below it publish complete plan ladders, which is 8 of 14 and a real disadvantage for a merchant who wants two comparable quotes.

What it takes full marks on is the criterion this page weighs heaviest, and it takes them on a sentence it published itself rather than on anything argued here. The hosting page states that most stores have one vendor running the servers and another that knows the code, and that incidents bounce between them, and then states that scandiweb is both: the team hosting PUMA, Cook Medical and Beauty Works also builds on Adobe Commerce every day, and the same engineers handle ongoing Magento support after go live. On patching it is unambiguous, stating that it sets up and runs every layer of the stack on AWS, which leaves your team no servers to maintain and no patches to install, with security patching, managed firewall and DDoS protection handled for you. Its Magento hosting on AWS page adds that patching and health checks are handled for you on a schedule, and its managed cloud hosting page that patching is scheduled with evidence kept for auditors. Five companies on this page state the opposite about themselves. That gap is 28 of 28, and it is the whole reason the order comes out as it does.

On incident terms it takes 12 of 22, which is a loss to four companies below it. It publishes the numbers: what it covers after launch states that when something does break it responds inside eight minutes for platform incidents, with an eight minute response SLA and a 24/7 operations center printed beside it, and ReadyMage, the platform scandiweb owns, publishes that urgent issues are addressed within five minutes, not lost in finger pointing between application and infrastructure. It publishes a named accountable person, stating a named account team that answers at any hour with always one person accountable for your store staying up, and an on call engineer reached by a paging alert at any hour. Those are two of the four things this criterion counts. What is missing is the other two: no severity band definitions for hosting anywhere on the site, and no update cadence or restoration target for an open incident. Webscale publishes both, which is why it takes the full 22 and finishes two points behind overall rather than ahead. Separately, its Magento support retainer publishes a first response within 24 hours with issues triaged by severity and showstoppers taken first, across 450+ active support clients and 9,000+ tickets handled, which is the support contract rather than the hosting one, and the two numbers should not be confused.

On governance it is the only company here taking full marks. It states ISO 9001, ISO 27001 and ISO 27017 certification with PCI DSS compliant practices in body text on its Adobe Commerce page rather than only as a badge image, and ISO 27001 and ISO 27017 certified infrastructure on the hosting page. Behind it sit 894+ Adobe certifications, 600+ specialists, 700+ brands, 2,100+ projects, a 95 NPS and 23+ years. Its Adobe tier is published as Adobe Gold Solutions Partner on the hosting page and Adobe Gold Partner on the Adobe Commerce page, which is 6 of 6 on a test the other nine were put through identically. It appears five times in the full Hyvä agency register and is Platinum on every listing, recorded here as context because Hyvä is not scored on this page. The published stack is Varnish and Redis, Elasticsearch or OpenSearch, PHP 8.1 and above with OPcache, NVMe SSD storage with HTTP/2 and HTTP/3 and a built in CDN, with auto scaling on AWS, and ReadyMage, scandiweb's own platform, publishes data centre regions across Australia, Dubai, Canada, the United States and Europe.

Two things belong on the first call. The two response numbers sit on two different properties and are worded differently: eight minutes for platform incidents on scandiweb.com, five minutes for urgent issues on ReadyMage's own site, which is scandiweb's product. Ask which one governs your contract and what counts as urgent, because neither page defines it. And ask for the uptime figure in writing with a remedy attached, because the 99.99% is published as a number and not as a term. What it does publish in place of a schedule is a record: its own write up of ReadyMage, published on 22 January 2026, states plainly that ReadyMage is a product of scandiweb, and the platform's site publishes a full migration off Azure in under six hours with PCI and ISO compliance maintained, and a store that auto scaled from two servers to nine through an eight times traffic spike. Its engineering write up on server auto scaling in Magento 2 shows the mechanism behind that. Related work sits on its Magento performance optimization and Magento technical audit pages.

2

Webscale

Merchants who want the uptime promise, the priority model and the credit ladder in a document they can read now, and who already have developers for the store itself71 of 100

On its own site, Webscale publishes the only complete contractual uptime remedy in this lane, and it is the reason the gap at the top of this page is two points rather than twenty. Its service level agreement states that should the company fail to achieve 99.98% service availability over a calendar month, the customer has the right to a service level credit, and then publishes the ladder in full: 99.98% down to 99.97%, which is nine to thirteen minutes of downtime, earns one thirtieth of the monthly list fees; below 99.97% to 99.90%, thirteen to forty four minutes, two thirtieths; 99.90% to 99.85%, three thirtieths; 99.85% to 99.8%, five thirtieths; 99.8% to 99.5%, fifteen thirtieths; and below 99.5%, meaning more than 216 minutes down in a month, the full 100% of the monthly fees. Credits are capped at the month's fees, applied against the next invoice, and named as the customer's exclusive remedy. It also publishes the maintenance window, weekend nights on Mountain Time, and the availability formula itself. That is 18 of 18, and nobody else here comes close.

Its incident terms are the only full marks on the second heaviest criterion, and they are full marks because of one thing nobody else publishes. Its documentation defines four priorities, P0 urgent for a site that is down, P1 high for degraded performance, P2 normal and P3 low, and then gives a first response time for each at each of three support tiers: Essentials P0 thirty minutes, Proactive P0 thirty minutes, Strategic P0 fifteen minutes, with P1 running four hours, two hours and thirty minutes. The service level agreement separately states a fifteen minute guaranteed response for critical errors, defined as errors which prevent the customer's website from taking or processing transactions. Note that the two documents disagree, because the agreement promises fifteen minutes to everyone and the matrix gives it only at the top tier. The thing that earns the fourth point is the update interval, a published cadence for how often you hear from them while the incident is still open, two hours at Essentials, sixty minutes at Proactive, fifteen minutes at Strategic. Included P0 volume is capped at ten and twenty five tickets a month on the lower tiers and unlimited at the top. A named subject matter expert, a direct phone line and a private Slack channel exist only at the top tier, and the documentation is careful to say that the named expert comes with guardrails and schedules and is not an on demand round the clock resource.

Where it loses is the application. The only place Webscale answers who actually applies a Magento patch is its Magento 1 end of life documentation, and the answer is a flat no: it states that Webscale provides the patches to customers, and that customers or their developer team will download and verify the patch in a staging or testing environment before applying it to production. For Magento 2 and Adobe Commerce there is no equivalent statement published at all. What it offers instead is virtual patching, configuring the platform to limit exposure without making any changes to the application code, plus a thirty day patch availability commitment for Magento 1 Open Source and sixty days for Magento 1 Commerce. Application work exists but is metered: developer enablement hours covering code review, troubleshooting and platform level engineering run to zero at Essentials, four hours a month at Proactive and ten to twenty at Strategic, pooled monthly and not rolled over. Its marketing promises more than that, offering application aware troubleshooting that diagnoses slow checkouts, caching issues and third party API failures, but its own positioning statement is that Webscale operates at the infrastructure and delivery layer, beneath your existing stack, all without touching your commerce platform. That is 12 of 28.

Three things belong on the call, and the third is the one that would worry us most. First, the exclusion. The agreement classifies as planned downtime, and therefore excludes from the availability calculation entirely, any downtime due to the customer's application errors, database errors, application server failures or database server failures. For a Magento store those are the most common failure modes, so the credit ladder covers a narrower band of outages than it first appears to. A second clause excludes downtime taken for purposes of maintaining the integrity or operation of the services regardless of the notice provided, which is maintenance with no notice requirement at all. Second, pricing is published as Essentials from $499 a month on a single server environment, Scale from $1,199 a month multi server, and Enterprise custom, but the support tiers that carry the response commitments are sold separately from the hosting tiers and no support tier price is published anywhere. Third, MageMojo. Webscale acquired the Magento host MageMojo, and every page on webscale.com was searched for the name, case insensitive, with zero occurrences. There is no acquisition announcement, no date and no statement about what happened to MageMojo customers anywhere on the site. The domain magemojo.com now redirects to Webscale's positioning page at an anchor that does not exist on it, and MageMojo survives only as a support address and a set of URL slugs inside the documentation. On certifications it states that the Webscale platform holds PCI DSS, SOC 2 Type 2 and HIPAA certifications, with softer built in PCI compliance wording on the product pages; it never claims PCI DSS Level 1 Service Provider status and publishes no ISO certification. Its only Adobe level is from a press release dated 14 February 2023, stating that it joined the Adobe Exchange Partner Program at the Accelerate level, which is a named level in a programme since superseded and scores one point. It publishes no headcount, no founding year and no case study with a URL of its own.

3

Nexcess

Merchants who want a real credit schedule and four published prices on the same page, and who already know they will be hiring a developer separately50 of 100

Nexcess and Liquid Web are one company and are ranked here once. Every nexcess.net address now redirects to liquidweb.com, checked on 23 September 2026, the footer reads copyright Liquid Web LLC by Nexcess Corp, the service level page carries two separate documents headed Liquid Web SLA and Nexcess SLA, and the Magento hosting page states that its PCI status belongs to Nexcess infrastructure, which powers our Magento hosting. Ranking them separately would have been double counting the same stack.

It publishes the clearest hand back sentence a buyer will find anywhere in this lane, and it publishes it on the Magento hosting page itself, in answer to its own FAQ question about whether you still need a developer. The answer states that while they manage the server infrastructure, you will likely still need a developer for Magento application level tasks: theme customization, extension installation and updates, custom coding, and Magento core upgrades. Managed hosting is defined on the same page as the server level aspects only, including operating system and stack updates and patching. Its support documentation goes further, listing as out of scope the installation and configuration of third party software, developer related tasks, adding removing or modifying web pages, code, plugins or themes, and code, database or website performance optimization. And its support page answers the question directly: it does not currently offer in house development services, and partners with development agencies instead. Adobe's security patches and Magento core upgrades are therefore the merchant's job, stated plainly by the company rather than inferred. That is 6 of 28, and it is above the floor only because the statement is printed where a buyer will actually read it.

Its service level agreement is a real one and it is the reason it finishes third. Nexcess commits to a minimum 100% uninterrupted transit to the internet and 100% uninterrupted electricity, measured monthly, with a credit of 5% of recurring monthly fees for every additional fifteen minutes beyond that, capped at the month's fees, claimed within seven days, and named as the sole and exclusive remedy. Read the definitions before relying on it. Loss of services means the customer is unable to connect to the Nexcess datacenter, which is reachability rather than store availability, so a Magento store that is up but broken triggers nothing. Outages may not be combined to reach the fifteen minute minimum, so three separate ten minute outages in a month earn no credit at all. The company's determination of credits is final, invoices must be paid in full while a claim is reviewed, and a claim judged false or duplicative carries a fifty dollar charge and possible suspension. The page's own timestamp reads 26 August 2013. Response times are explicitly carved out of the agreement: it states a goal of under one minute on chat and one hour on tickets, and then says in the same paragraph that these initial response times are not part of an SLA and are not guaranteed. There are no severity bands and no escalation process, which is 7 of 22.

On what you can read before a call it takes the full 14, one of only three companies that do. Four Magento plans are published with regular prices, not only promotional ones: XS at $74 a month, S at $145, M at $247 and L at $409, each with its storage, bandwidth and PHP worker counts, on dedicated environments with OpenSearch and a Cloudflare CDN. On governance its own certification claim is specific and unusually strong for a host, that Nexcess infrastructure is a PCI DSS Level 1 Service Provider, which is a materially different statement from the PCI compliant hosting wording most of this field uses; it publishes no ISO 27001, no ISO 27017 and no SOC 2 report of its own. Its scale figures fight each other on its own site, with ten global data centers and 500K+ websites under management on one page against twenty two data centers and over 180,000 customers on another, and no headcount anywhere. It publishes no Adobe partner level of any kind, and instead runs a page positioned against Adobe Commerce Cloud under headings including hidden fees and your code is their code. Its client evidence is genuine: an index of eighteen case studies each with its own URL, including Netalico, where it states the agency sped up a client site by 295%, increased conversions by 350% and saved the client $15,000 a year. One tension is worth naming: its homepage advertises round the clock hosting and application support while its own scope document rules out code, plugins, themes and performance optimisation.

4

MGT-Commerce

Merchants who want nine published price points and an emergency response time attached to each, and who have an agency to run the store48 of 100

MGT-Commerce publishes the single most explicit refusal in this lane, and it publishes it as an answer to its own question. Under the heading asking whether it applies Magento security patches, its security page states that it does not offer Magento security patches and updates, that its expert team carries out server side security updates, and that it ensures the server is in optimal health. Everything else on the site is consistent with that: its service level table lists MGT tested operating system patches and never Magento patches, and its hosting page lists operating system security patches and updates under what is included while stating that it manages all server related changes so you can focus on your Magento store. Its own terms put third party code risk back on the merchant twice, requiring routine backups before installing applications or extensions from other manufacturers, and disclaiming liability for errors and incompatibility of third party software. There is no statement anywhere about who handles a broken custom module. That is 6 of 28, and the score is that high only because the refusal is unusually clear.

It publishes an actual service level page, which most of this field does not, and the numbers on it are specific. A 99.95% network uptime guarantee applies to all three product families, alongside a two hour instance replacement, round the clock support, a managed AWS port firewall, its own web application firewall, managed backups with full hourly instance snapshots, DDoS mitigation through Amazon Shield, an encrypted file system and a New Relic installation. Response is split two ways: under 24 hours for general guidance on every plan, and guaranteed response for emergencies running from under eight hours on Single Server Premium through four hours and two hours, under two hours across the Multi Server tiers, and down to under one hour on Auto Scaling Premium and under thirty minutes on Auto Scaling Enterprise. An emergency is defined only as your system being down and not operating. There are no severity bands beyond that split, no escalation process, no named engineer and no account manager published anywhere, which is 12 of 22.

Three gaps between what it markets and what it contracts belong on the first call. First, the homepage advertises a fifteen minute response time and calls it the fastest in the industry, while its own service level page gives eight hours for a Single Server Premium emergency and twenty four hours for anything not classed as an emergency; the security page words the same claim honestly, as an average response time under fifteen minutes. Second, the service level page and the Single Server plan page publish different emergency response times for the same tiers, eight, four and two hours on one and four, two and one on the other. Third and most important, the binding contract says something different again. Clause 3.2 of its terms states that a guarantee of service availability free of interruption is not technically possible, and that the customer can expect an average monthly availability amounting to 98% over the year. Ninety eight percent monthly permits roughly fourteen and a half hours of downtime a month against the twenty two minutes implied by 99.95%. Clause 3.3 removes the obvious remedy: in the case of defects, the customer cannot reduce the ongoing payments. No service credit schedule of any kind is published, and a search of the service level page for credit and refund returns nothing. That is 10 of 18, for a contractual figure with no remedy attached.

Where it is genuinely strong is everything a buyer can read before picking up the phone, and it takes the full 14 there. Nine tiers are published with prices: Single Server Premium at 149 euro a month, Ultimate 199, Enterprise 249; Multi Server Basic 299, Premium 499, Ultimate 999; Auto Scaling Basic 1,499, Premium 1,999, Enterprise 4,999, all plus AWS cost pass through, with the architecture spelled out per tier down to load balancers, slave databases, Varnish, NFS, ElastiCache and Elasticsearch. Note that the pricing page publishes Multi Server at 249 euro where the homepage says 299, and that the 149 euro headline is the tier capped at three support requests a month with the slowest emergency response in the table. Its footprint is published as 96 AWS availability zones and more than 250 CloudFront points of presence, with a dated benchmark stating time to first byte measured from an EU datacenter on a cached homepage in February 2026. On governance it publishes 40+ engineers, 5,000+ stores hosted and a 2011 founding, and it holds no certification of its own: every certification named on the site belongs to AWS and is attributed to AWS in the same sentence, which is the honest way to put it and scores nothing here. It publishes no Adobe partner level in any wording, and its Adobe Commerce page is positioned against Adobe's own hosting under the line same Adobe, different bill. It has no case studies at all; its sitemap of fifty one pages contains none, and the eight brand logos under trusted by leading brands carry no caption identifying them as customers and no page behind any of them.

5

Wolf Sellers

Merchants who want response times, a priority model and development hours in the same contract, and who will ask for the uptime number in writing47 of 100

Wolf Sellers is an Adobe Gold Partner that runs managed cloud infrastructure for the stores it builds, and it publishes the hardest response numbers of any agency on this page. Its support and maintenance plans run Starter at eight by five cover with a twenty hour development allowance and a four hour response commitment, Business at round the clock cover for critical issues with forty hours and a one hour commitment, Enterprise at full round the clock cover with eighty hours and a thirty minute commitment, and a custom tier above that. Severity is defined by business symptom rather than by system layer, which is the smartest thing on the page: P1 alerts are named as store down, broken checkout and data loss, handled around the clock every day of the year including holidays, while P2 and P3 can wait for the next business day depending on plan. Defining the top priority by what the merchant loses rather than by which component failed sidesteps the infrastructure versus application argument at triage time, which is exactly the argument this page exists to examine. It states that every plan includes a contractual service level agreement for response time, resolution time and hours of coverage, with monthly activity reports.

On the application it scores 18 of 28, the second highest here and well above every pure play host, because the party answering the ticket is the party that can change the code. Every plan bundles development hours with the response commitment rather than selling them separately, and it publishes a patch commitment of its own: security patches applied within 72 hours, with staging testing before production and automatic rollback on failure. It sells implementation, custom software development, cloud infrastructure on AWS and Azure, and continuous integration and deployment work, so nothing about a Magento fault has to leave the building. What holds it below the top of this criterion is that it never itemises the boundary. There is no published statement anywhere about who is responsible when a third party extension or a bespoke integration breaks the store, and no in or out of scope list for application level debugging. The development hours are an allowance, not a liability position, and a merchant should ask what happens in month two when the eighty hours are gone and the checkout is still broken.

It publishes no uptime percentage at all, which is the single largest hole in an otherwise numerate page and scores zero on that criterion. The nearest thing is a monitoring frequency, uptime monitoring every thirty seconds, which tells you how often they look rather than what they owe you. There is no service credit, no remedy and no availability figure on the hosting page, the support page or the FAQ. Resolution time is named as a dimension of the contractual service level agreement without ever being given a number. There is no escalation ladder, no on call rotation and no named engineer published. Its detection stack is unusually well specified for an agency, naming application performance monitoring through New Relic or Datadog, real time checkout error alerts, queue monitoring across RabbitMQ and Redis, synthetic monitoring of the checkout flow and real user monitoring, which makes the absence of an availability commitment stranger rather than less noticeable.

On price it publishes support plans starting at 35,000 Mexican pesos a month, available annually or month to month, and a hosting cost illustration rather than a rate card, putting a store at fifty thousand sessions a month at roughly $300 to $600 a month on AWS. It publishes no per plan hosting price and no named cloud regions, which is 5 of 14. On scale it publishes a team of 135 people, mostly developers, more than fifty brands and a 2014 founding, and holds no certification of its own: what it publishes is compatibility wording, PCI DSS Level 1 compatible and PCI DSS Level 1 ready, alongside a web application firewall against the OWASP top ten and annual penetration testing. Compatible is not certified, and this page scores it as the former. Its Adobe tier is the strongest credential it holds, published on its own about page as Adobe Gold Partner and described there as the second highest tier Adobe grants to its partners, restated on the service page as a certified Gold Partner. That is the full 6, the same as scandiweb takes. Three clients have case studies with their own URLs, Casa Cravioto, Juguetron and Enlace; the fifty plus brand logos on the portfolio page have no page behind them and are not counted here. One caveat belongs on the page rather than in a footnote: its hosting offer is agency run managed AWS and managed Adobe Commerce Cloud rather than an own brand hosting product, so a merchant comparing it with a host is comparing two different shapes of thing.

6

Sonassi

Merchants with a strong agency already in place, who want a Magento specialist host that says exactly where its job ends46 of 100

Sonassi publishes the cleanest scope boundary in this entire field, in five words: we don't touch your store. The full sentence reads that it provides platform support for everyone, covering platform incident response, autoscaling optimisation, network stability and speed, backup management and platform security, and then draws the line. Its PCI responsibility matrix says the same thing in contractual language, against requirement 6.3: Sonassi is responsible for patching the operating system and services, and you are responsible for patching any software you install, such as Magento or Node. Its billing article states that the day to day running and operation of a client's Magento store is wholly their responsibility, that Sonassi only provides hosting for the application, and that any assistance beyond that is chargeable support. Its statement of work lists Magento upgrades, Magento extension installation, Magento code profiling and deep auditing, and general day to day administration as explicitly not included. It is the only company here that arrived at that position deliberately and says so: its site wide footer records that it formed in 2008 building and hosting Magento stores, and that in 2015 it committed to stop building Magento stores and dedicate itself to hosting, and no longer offers proactive development services.

The clause a merchant should read twice is the burden of proof. If you suspect a server side fault, Sonassi states, you must first conduct the necessary due diligence to rule out your application, configuration or code being at fault; and if it investigates following a support request and identifies the issue as being caused by your application, configuration or code rather than the server, the time spent is chargeable. That is the hand back written as a billing rule. It is honest, it is unusual to publish, and it means that on the night your checkout fails you are paying someone to prove it is not your fault before anyone starts fixing it. It scores 12 of 28 rather than 6 only because paid store tiers genuinely exist: it states that store support is available from its accredited developers, ranging from routine patch management through to full store support, sold as Store Lite and Store Full at tailored pricing, with Store Full adding a dedicated Slack channel and direct access to the development team.

Its response bands are published and they are properly graded, which is more than most of this field manages: emergency one hour, high four business hours, normal seven business hours and low fourteen business hours, identical across the Standard, Enhanced and Intensive plans, with out of hours defined precisely as after 18:00 and before 10:00 GMT on weekdays and all day at weekends. The contact method for every plan is a ticket. Its marketing figures are presented as achieved averages rather than commitments, which is the correct way round: a three minute average emergency response, a one hundred percent support ticket resolution rate and a fourteen hour average resolution on normal priority tickets. No escalation ladder, no on call rotation and no named engineer is published, which holds it to 12 of 22. On uptime it publishes a 99.95% service level agreement on five separate pages, and then publishes nothing behind it. There is no terms page on the site at all, the statement of work contains no uptime clause and no credit schedule, a full search for service credit, refund, compensation and rebate returns nothing, and the download support SLA button on the plans page has no link attached to it. That is 7 of 18, the same rung scandiweb sits on.

Support plan prices are published at Standard included, Enhanced at £80 a month per server and Intensive at £150 a month per server, with additional support at £1.50 a minute and out of hours work at £45 per fifteen minutes; base server pricing renders only inside a JavaScript configurator and is not readable. Hardware is specified more carefully than anywhere else here, enterprise Supermicro servers with hand picked components stress tested for a minimum of two weeks before production, with four hour hardware replacement and a fully owned UK datacentre estate, although no named location. On governance it claims a long list of ISO accreditations as its own, including ISO 9001, ISO 27001, ISO 14001, ISO 22301, ISO 27018 and ISO 27017, which is the strongest certification set after scandiweb's, with one caveat a careful reader should note: the page does not distinguish between standards it is certified against and standards it aligns to, and several numbers in its second badge row are guidance documents rather than certifiable schemes. Its PCI wording is compliant rather than certified, with no Level 1 Service Provider claim and no attestation published. It publishes no headcount and no client or store count, and no case study with a URL, substituting around twenty attributed testimonials from retailers and agencies. It publishes no Adobe partner level for itself in any wording, current or legacy. Two internal contradictions are worth flagging because both are live: one page states it can find and fix any problems, whether server related or your store itself, against we don't touch your store on another; and one page calls it a profitable, privately owned company while another states it is the specialist eCommerce division of iomart Plc and a public limited company.

7

Cloudways

Small and mid sized stores that want a ten minute ticket response and a published price, and understand they are buying infrastructure and nothing else43 of 100

Cloudways publishes the most precise response commitments in the lane after Webscale, and it publishes them for every plan including the free support tier. High priority tickets carry a three hour target on Standard, thirty minutes on Advanced and ten minutes on Premium; normal priority runs twelve hours, six hours and two hours. High priority is properly defined rather than left to the buyer: it must relate to events that render the customer's infrastructure or services unusable or inaccessible, and it states openly that events rated high priority by customers which do not match that description will be demoted to normal priority by its own personnel. Escalation is published as a rule: a live chat session that runs past the tier's time limit becomes a ticket carried forward by senior engineers, fifteen minutes on Standard and thirty on Advanced, with Premium buying a private Slack channel and phone access around the clock. What it does not promise is a fix. Its own words: the response time goal is the time it takes to acknowledge and have the work started status only, not the time it takes to resolve the issue in question. Three of the four things this page counts, which is 17 of 22, and higher than scandiweb takes.

On the application it is the weakest entry here, and the evidence is its own out of scope list, published on the support page under a preface that leaves no room for tiers: no matter which support plan you are on. The list rules out changes to website content or appearance, changes to the functionality of plugins, themes or modules, debugging custom code, application level security issues, auditing your code, upgrades of plugins, themes or modules, and, in its own summary, in general anything that implies code editing. That applies on the $500 a month Premium tier as much as on the free one. Its Magento hosting page says nothing at all about who applies Adobe security patches; a search of that page for patch and security update returns nothing. What it does publish is server side only, regular operating system patches on your server, and its help centre puts keeping applications, plugins and themes up to date under what the customer is responsible for. The tension is that the same support page's comparison table ticks application support and customization support for the paid tiers, immediately above the list that excludes code editing entirely. That is 3 of 28.

Its service level agreement is worth understanding before anyone quotes its uptime at you, because it is a support agreement rather than a hosting one. In its own words, service availability refers to the Cloudways services support platform console only and in no case applies to the service availability of its third party cloud providers, and the document ends by pointing at the DigitalOcean, Amazon EC2 and Google Compute Engine agreements for the servers themselves. Credits are real but they buy back missed support responses, five percent of the monthly fee for each hour the standard is missed, capped at the month's fees, never aggregated and never paid in cash. Two clauses matter for a customised Magento store. Credits are void where the failure is based on a non standard environment, customer authored code or changes made by anyone other than the provider, which for a Magento build is a wide carve out. And the agreement states that it may be changed at the company's sole discretion and without prior notice. The uptime figures it markets, 99.99% on one product page and 99.9% on another, appear nowhere in the agreement. That is 7 of 18. Note also that the legal counterparty throughout is DigitalOcean, whose legal pages the terms of service, privacy policy and acceptable use policy all link to.

On what a buyer can read before a call it takes the full 14, and it is the reason it outranks three companies with better scope statements. Flexible plans run from $11 a month to $342 a month, Autonomous plans at Growth $99, Scale $199 and Plus $399 with baseline server counts, bandwidth and disk published per tier and overage rates named per gigabyte and per server hour. Its footprint is published as three cloud providers, 43 locations and 58 data centers, with the DigitalOcean regions listed by city. One pricing structure deserves attention: the support add ons that carry the ten and thirty minute response times cost $500 or $100 a month respectively, or ten percent of your invoice, whichever is higher, so the support you need to make the response commitment real scales with your spend. On governance it holds nothing of its own. Its trust page lists only the certifications its infrastructure partners maintain, at the infrastructure level, and its own help centre says the quiet part plainly: a web hosting platform alone cannot be fully PCI compliant, and Cloudways helps with the server and infrastructure security while application level security is managed by you. It publishes over 102,000 customers, a figure that sits on the same page as an unexplained 840K plus, and no headcount and no founding year. It publishes no Adobe partner level in any wording. Its client evidence is strong for a self serve platform, with Magento case studies each carrying their own URL, including Ciyapa at a 22% boost in conversion rates, 40% increase in page visits and 30% faster load times.

8

magic42

United Kingdom merchants who want their developers and their servers to be the same people, and who trade in business hours40 of 100

magic42 publishes the sentence this entire page was built around, and it publishes it about itself without being asked. When a performance issue appears on your site, it writes, a standalone hosting company will tell you it is a code problem, and a standalone development agency will tell you it is a server problem; with magic42 the same team is responsible for both, so problems get diagnosed and fixed rather than passed back and forth. The page it sits on is headed with the question of why you would host your Magento site with your development agency, and describes the offer as managed Magento hosting on dedicated bare metal and cloud infrastructure from a UK agency that builds and maintains the sites it hosts. On patching it is unambiguous and it is the only company besides scandiweb to name Adobe explicitly: when Adobe releases Magento security patches, its development team reviews and applies them to your site, with testing on staging before deployment to production, and operating system patches go out through a standardised, centrally managed configuration. Its monitoring scope includes application errors alongside server resource usage, response times and security events, which is precisely the thing Hypernode publishes that it does not watch. That is 24 of 28, second only to scandiweb, and it is earned.

Then the numbers stop. It publishes no response time in minutes or hours, no severity bands, no resolution target and no escalation ladder. What it publishes instead is routing, that automated alerts escalate to its development team, and a proactive flagging promise, that if it spots a growing database, memory pressure during peak hours or a pattern of bot traffic it will flag it and recommend a course of action. Its cover model is business hours and it says so rather than claiming otherwise: having your hosting managed by a UK based team means we are in your timezone and available during your working hours. No round the clock claim appears anywhere, no out of hours arrangement is published and no stated office hours are given. That is 3 of 22, the lowest on this page, and it is the whole reason a company with the second best scope statement in the field finishes eighth. A merchant whose Black Friday indexer stalls at two in the morning has nothing published to hold them to.

Its uptime claim is a section heading, 99.9% uptime guaranteed, backed on the page by redundant infrastructure, proactive monitoring and automated alerting, with no service level document, no credit schedule and no remedy behind it: 4 of 18. It publishes no price of any kind, no plan names and no monthly figures, which with a fully specified stack and no named data centre is 5 of 14. The stack itself is specified carefully, with PHP at the correct version, memory limits and OPcache settings for your Magento version, MySQL, Redis, Varnish, Elasticsearch or OpenSearch and a CDN, plus daily automated backups of database, media and configuration stored off server so they survive a hardware failure. On governance it publishes no certification at all, not ISO 27001, not ISO 27017, not SOC 2, not PCI DSS, and not even a PCI compliant hosting marketing claim, on the hosting, about or contact pages. It publishes twenty plus years managing eCommerce infrastructure and forty eight named case studies each with its own URL, and no current headcount, the only team figure on the site being a historical fifteen at incorporation. Its Adobe tier is published as Adobe Solution Partner at Bronze level, dated on its own about page to January 2021, which is 2 of 6 on a test applied identically to all ten.

Read it as the clearest statement of the argument this page makes, from a company that has not yet built the terms to back it. The scope promise is the strongest in the field after scandiweb's, and there is nothing published that a merchant could hold it to if the promise failed. That combination is worth naming rather than smoothing over, because it is exactly the trade a buyer has to make: a smaller agency that genuinely owns both layers, against a host that owes you a credit if the network drops and owes you nothing at all if your checkout breaks.

9

JetRails

United States merchants with a development agency in place who want round the clock engineers on the phone and will negotiate the Enterprise tier37 of 100

JetRails puts its scope boundary under a heading rather than in the small print, and the heading is the argument: why JetRails is not a development firm, and why that is a good thing. The text is worth quoting because it is the most self aware version of this position anywhere in the set. We do not write or maintain code, it states; we build and manage the infrastructure that makes that code perform, and that separation keeps us focused on performance optimization, uptime, scaling and managed security. It goes on to say that it is not competing with agencies or developers, so it can recommend partners objectively and collaborate freely. Its security page frames the split the same way: security is a shared system, infrastructure lives with JetRails, application behavior lives with your team, and compliance depends on both. That is a real, published, defensible position.

What it never does is name the patch. The only patching scope stated anywhere is the operating system, rapid operating system patch updates on one page and operating system vulnerability patching and hardening on another, and a search of its Magento hosting page for patch wording returns no matching sentences at all. So while the inference is obvious, JetRails never publishes an answer to the question of who applies an Adobe security patch to your store, which is the single most important thing a Magento merchant needs to know about a host. It muddies it slightly in the other direction too, claiming on the Magento hosting page that it has helped clients resolve stuck carts, failing reindexes, slow admin panels and caching conflicts with third party extensions, which are application symptoms. It scores 6 of 28: the hand back is published where a buyer will find it, but the patch question itself is unanswered.

Its numbers live in marketing and its contract lives somewhere else. It publishes 99.99% uptime on two pages. Section 23 of its terms of service, which is the section headed service level agreements, reads in full that it will use commercially reasonable efforts to maximize availability of the service. There is no percentage in the contract at all. A credit mechanism does exist and is more than several companies here publish: claims must be made within five business days or forfeited, credits cannot exceed two weeks of credit in any calendar month, the exclusions name scheduled maintenance and necessary network upgrades, and credits are the sole and exclusive remedy. But the schedule that would say how much a credit is worth sits in supplements the site does not publish, so a prospect cannot read the actual agreement before signing. That combination, a contractual mechanism with no number and a marketing number with no contract, is 10 of 18, and it is one rung above where scandiweb sits. On response it publishes a fifteen minute emergency response commitment, and publishes it honestly as an enterprise grade service add on rather than as part of the base package, available at the Enterprise tier alongside a dedicated technical account manager. Emergency is never defined, no severity bands exist and no resolution target is published: 12 of 22.

Support is its strongest marketing claim and it is specific about it: round the clock United States based support by phone, email and optional Slack, with no AI bots, no call trees and experienced engineers managing the environment every day of the year. Pricing is published only as a range, with regular configurations between $100 and $2,500 a month and tier names carrying no figures, and its data centres are described only as secure United States facilities with no named locations, which is 5 of 14. On certifications it is unusually straight, stating on its compliance page that while it does not issue certifications it does align your hosting environment with the controls your auditors expect, and listing the audit artefacts it supplies: architecture diagrams, access records, detailed logs, patch histories and configuration notes. Two product pages sit awkwardly beside that, one stating that its environments are PCI DSS Level 1 certified and listing SOC 2 Type II compliance, where the grammatical subject is the environments rather than the company. It publishes no ISO certification and no headcount, a founding in 2000 and thousands of online storefronts. It publishes no Adobe partner level of any kind; its partners page names Shopware, Amasty, Amazon Web Services, Cloudflare, Hyvä and Sansec and no Adobe tier. Its client evidence is the best of the pure play hosts: sixteen case studies each with its own URL, including Galco, which it states moved from Adobe Commerce Cloud to open source Magento on AWS with zero site down incidents since migration across more than three million SKUs, carrying a named quote from the chief information officer, and RuffleButts at a 90% reduction in CDN costs worth more than $20,000 a year and a 500% increase in transactions at high peak.

10

Hypernode

European merchants with a Magento agency they trust, who want ISO certified infrastructure and will buy out of hours cover separately32 of 100

Hypernode publishes the most useful sentence in this entire research set, and it publishes it inside its own monitoring documentation rather than on a sales page. The big thing missing from the list of things we monitor, it writes, is your application, or does Magento work. What it does monitor is named precisely: the hosting software services that come preinstalled, Nginx, MySQL and Redis, the optional extras Varnish and RabbitMQ, and the root filesystem. Nothing above that line. Its security documentation says the rest in eight words: although we are very skilled in hosting Magento shops, we are no Magento developers. Its scope of support states that it can, as a courtesy, attempt best effort support on issues related to the application, with its primary focus on providing a fast and stable platform and not the inner workings of the web application, and that it cannot assist with the installation of, or issues relating to, third party software such as plugins, modules, add ons, themes or other components or scripts. Magento patching is framed as the merchant's task, with its security page telling you that regular Magento patches are released to secure your shop and offering a free tool so you can check your own patch status.

The clearest illustration of what that means in practice is its own advice when one of your extensions turns out to be vulnerable. Upgrade if an update exists. Contact the developer if it does not. And if there is still nothing, disable the extension, even if you lose some fundamental functionality in your webshop. The host's remedy for a broken extension is to switch the feature off. The same document notes that in the case it describes, the vulnerability was actively abused within less than eight hours of discovery. That is a company being honest about where its job ends, and it scores 3 of 28 rather than 6 for one reason: the scope document lives in developer documentation that renders as a JavaScript application, while its agency facing marketing page calls Hypernode the absolute extension of your development team and invites you to tackle all issues, whether Magento or infrastructure issues. Those two sentences cannot both be the offer.

Its response bands are published and graded, urgent requests at fifteen to thirty minutes, priority requests at zero to one hours and standard requests at two to four hours, with no definition of what makes a request urgent and no resolution target. Its escalation is the most specific published by anyone here: an alert pages an on call operative who is on standby around the clock, and if the alert goes unacknowledged for thirty minutes it automatically escalates to the entire team. That is 12 of 22. But read the hours before relying on any of it. Free support runs Monday to Friday from nine in the morning to six in the evening Central European time. Out of hours is a separately paid emergency service at 200 or 100 euro per incident depending on contract, free only where the issue is caused by a Hypernode outage, and its own page states that its goal is to guarantee the short term continuity of the webshop rather than to resolve anything, with no rights derivable from the solutions offered. The plans page meanwhile advertises that all hosting plans come with round the clock premium support. Ask which applies at two in the morning.

It publishes no uptime percentage anywhere, on any page opened, which is zero on that criterion, and no service credit or remedy. Its terms are published only as a binary document that could not be read, so its contractual availability position is recorded here as unverified rather than claimed in either direction, which is the honest treatment. Plan families are named, Falcon on one cloud and Eagle on AWS, but every price on every plan page renders as an unresolved script placeholder rather than a number, so its pricing is not readable: 8 of 14, earned on the stack detail and the published emergency fees. Where it is genuinely strong is governance, and it is the only pure play host here to score 9. It states that it holds ISO/IEC 27001:2022, NEN 7510:2024 and ISO 9001:2015, and adds the clause that matters, that the certification applies not only to its internal organisation but also to its data centres, which is the difference between holding a certificate and pointing at your cloud provider's. It publishes no PCI claim in any wording and no SOC 2. It publishes 25 plus years, more than 200 agencies and 2,500 plus customers, and no headcount and no named data centre locations. It publishes no Adobe partner level in any wording, including on its own Adobe Commerce hosting page, and one line on that page is worth repeating because it tells you how it sees the market: it states that Hypernode consistently provides demonstrably faster support and is considerably more flexible than Adobe. Its own partner tiering for agencies runs bronze through platinum with progressive recurring commission, which is the shape of this whole lane in one sentence: the host pays agencies to bring merchants, then hands the application faults back to those same agencies.

4 Which one fits

Pick by situation, not by ranking

If this is youShortlistWhy
You have no in house Magento developers and nobody to hand a code fault toscandiweb, then magic42This is the one situation where the ranking and the recommendation agree. scandiweb's managed Magento hosting page states that it runs every layer of the stack, leaving your team no servers to maintain and no patches to install, and that the same engineers who run the infrastructure also build on Adobe Commerce and handle ongoing Magento support after go live. magic42 publishes the same model at a smaller scale, stating that its development team reviews and applies Adobe's Magento security patches with staging testing first. Every pure play host on this page publishes, in one form or another, that the application is your problem.
You already employ Magento developers and want the best infrastructure for the moneyNexcess, MGT-Commerce or CloudwaysBuy the host. This page concedes the point rather than arguing it: a pure play host beats an agency on network, on hardware and on price per environment, and all three of these publish complete plan ladders with resources specified, which no agency here does. Nexcess publishes four Magento plans at $74, $145, $247 and $409 a month with a real service credit schedule behind them. MGT-Commerce publishes nine tiers from 149 to 4,999 euro a month plus AWS pass through. Cloudways publishes plans from $11 a month and a ten minute high priority response on its top support tier. If you have the developers, the thing an agency host adds is the thing you already have.
Procurement will not sign without an uptime figure that has a consequence attachedWebscale, then NexcessOnly two companies here publish an availability commitment with a credit schedule a buyer can read. Webscale publishes 99.98% with six credit bands running from one thirtieth of the monthly fee up to the full 100% below 99.5%, plus the maintenance window and the exclusions. Nexcess publishes 100% network and power with 5% of the monthly fee for every fifteen minutes beyond that. Read both exclusion lists first: Webscale classifies application, database and application server failures as planned downtime and excludes them from the calculation entirely, and Nexcess defines the trigger as being unable to connect to its datacenter, which is not the same as your store being up. Seven companies here publish an uptime percentage with nothing at all behind it, scandiweb included.
Your store is down at two in the morning and you need to know who picks upWebscale or Cloudways for the published number, scandiweb for the single throat to chokeWebscale publishes a fifteen minute guaranteed response for critical errors defined as errors preventing the site taking or processing transactions, plus an update interval so you keep hearing from them while it is open. Cloudways publishes a ten minute high priority response on its Premium tier. scandiweb publishes an eight minute response for platform incidents on what it covers after launch with a 24/7 operations center, and ReadyMage, scandiweb's own Magento hosting platform, publishes that urgent issues are addressed within five minutes rather than lost in finger pointing between application and infrastructure. Check the hours as carefully as the minutes: Hypernode's free support stops at six in the evening and magic42 publishes working hours only.
A custom module or a third party extension is what actually broke the storescandiweb, magic42 or Wolf SellersEvery pure play host on this page excludes this in writing. Cloudways lists debugging custom code and application level security issues as out of scope on every plan including its $500 a month tier. Hypernode states it cannot assist with issues relating to plugins, modules, add ons or themes, and advises disabling the extension if no fix exists. Sonassi states that if it investigates and finds the fault is in your application or code, the time is chargeable. Nexcess lists modifying code, plugins or themes as out of scope. Of the three agencies here, only scandiweb publishes both the scope position and the incident terms; Wolf Sellers bundles development hours into every plan without publishing a scope statement, and magic42 publishes the scope statement without publishing any response time.
You are weighing Adobe Commerce on Cloud against a managed host or an agencyRead the section below before you shortlist anyoneAdobe's own documentation describes Adobe Commerce on Cloud as pre provisioned infrastructure with PHP, a database, Redis or Valkey, a message queue and a search engine on AWS, with a git based build and deploy workflow. What that does not settle is who fixes your code when the store is down, which is the same question every entry on this page is scored on. Two companies here sell explicitly against it, MGT-Commerce under the line same Adobe, different bill, and Nexcess under headings including hidden fees. Take the accountability questions in the methodology to all three shapes of supplier rather than assuming the platform answers them.
You are a United Kingdom or European merchant with compliance requirementsSonassi or Hypernode for certified infrastructure, scandiweb if you want the code covered tooHypernode is the only pure play host here that states its certifications cover not only its own organisation but also its data centres, holding ISO/IEC 27001:2022, NEN 7510:2024 and ISO 9001:2015, and publishes no PCI claim at all. Sonassi claims the longest ISO list of any host here alongside a fully owned UK datacentre estate, with PCI worded as compliant rather than certified. scandiweb publishes ISO 9001, ISO 27001 and ISO 27017 with PCI DSS compliant practices as body text on its Adobe Commerce page, and its managed cloud hosting page states patching is scheduled with evidence kept for auditors. Nexcess is the only company here claiming PCI DSS Level 1 Service Provider status for its infrastructure.

5 Evidence

Published work and published numbers behind the entries

ClientWhat was doneResultSource
Beauty WorksPeak traffic event reported by scandiweb on its own sitescandiweb states that 25,000 concurrent shoppers were held through the Molly-Mae launch with no rise in support contacts, alongside 80% conversion uplift, 32% year on year revenue growth and $1.3M new revenue, with round the clock security operations monitoring through every launchSource
Cook MedicalCloud migration reported on the site of ReadyMage, scandiweb's own Magento hosting platformThe platform states the store was migrated 100% off Azure in under six hours with PCI and ISO compliance maintained and predictable cost planning, described on the page as the smoothest migration the client had experiencedSource
Beauty Works auto scaling eventAuto scaling behaviour reported on the site of ReadyMage, which is scandiweb's own productThe platform states traffic spiked up to eight times after influencer campaigns and the infrastructure auto scaled from two servers to nine instantly with zero slowdown. scandiweb's own engineering write up of the mechanism dates an earlier instance of it to 21 June 2021Source
Webscale customers generallyService credit ladder published by Webscale in its own service level agreementWebscale publishes six credit bands against a 99.98% availability commitment, from one thirtieth of the monthly list fees at nine to thirteen minutes of downtime, up to 100% of the monthly fees below 99.5% availability, capped at the month's fees and named as the exclusive remedySource
Webscale Magento 1 customersPatch responsibility published by Webscale in its own documentationAsked in its own FAQ whether the patches are applied by Webscale support, it answers no, stating that Webscale provides the patches to customers and that customers or their developer team will download and verify the patch in a staging or testing environment before applying it to productionSource
NetalicoAgency migration reported by Nexcess on its own siteIt states that Netalico sped up their client's site by 295%, increased conversions by 350% and saved their client $15,000 a year by moving to Nexcess, now part of Liquid WebSource
GalcoMigration off Adobe Commerce Cloud reported by JetRails on its own siteJetRails states the store moved from Adobe Commerce Cloud to open source Magento on AWS with zero site down incidents since migration, across more than three million SKUs, with a named quote from Joe Garzia, chief information officerSource
RuffleButtsEdge caching and performance work reported by JetRails on its own siteJetRails states a 90% reduction in content delivery costs worth more than $20,000 a year, a 20% faster time to first byte, a 50% reduction in application servers at peak and a 500% increase in transactions at high peak with zero critical errorsSource
Sonassi hosting customersPatch responsibility published by Sonassi in its own PCI responsibility matrixAgainst PCI requirement 6.3 it states that Sonassi is responsible for patching the operating system and services, and that you are responsible for patching any software you install, such as Magento or NodeSource
MGT-Commerce hosting customersPatch responsibility published by MGT-Commerce on its own security pageAsked in its own FAQ whether it applies Magento security patches, it states that it does not offer Magento security patches and updates, and that its expert team carries out server side security updates insteadSource
CiyapaMagento store performance reported by Cloudways on its own siteCloudways states a 22% boost in conversion rates, a 40% increase in page visits, 30% faster load times, uptime averaging 99.9 percent and a 50% reduction in security threatsSource
Hypernode hosting customersMonitoring scope published by Hypernode in its own documentationIt states that the big thing missing from the list of things it monitors is your application, or does Magento work, and names what it does watch: Nginx, MySQL and Redis, the optional Varnish and RabbitMQ, and the root filesystemSource

6 In detail

The hand back, in the field's own words

Ask the ten companies on this page a single question, who applies the Adobe security patch to my store, and the field splits cleanly in two. Five answer that it is not them, and they answer in writing on their own sites. MGT-Commerce states that it does not offer Magento security patches and updates, and that its team carries out server side security updates instead. Sonassi states in its PCI responsibility matrix that it is responsible for patching the operating system and services and that you are responsible for patching any software you install, such as Magento. Nexcess states on its Magento hosting page that you will likely still need a developer for theme customization, extension installation and updates, custom coding and Magento core upgrades. Hypernode frames Magento patches as something released to secure your shop, with a free tool so you can check your own patch status. Webscale, asked in its own documentation whether the patches are applied by its support team, answers no. A sixth, JetRails, publishes under its own heading that it does not write or maintain code, and never names Magento patching at all, which leaves the most important question a Magento merchant can ask a host unanswered on its site. That is six of the ten. Three publish that they apply Adobe's patches themselves, scandiweb, magic42 and Wolf Sellers, and all three are agencies that also run hosting. This page did not have to argue that infrastructure accountability and application accountability come apart. The field said it first.

The same split runs through the exclusions, which is where the accountability in a hosting contract actually lives. Webscale publishes the best credit ladder in the lane and then classifies downtime due to the customer's application errors, database errors, application server failures and database server failures as planned downtime, excluded from the availability calculation entirely. For a Magento store, those are the most common failure modes there are. Cloudways voids its service credits where the failure is based on a non standard environment or customer authored code, which for any customised Magento build is a wide carve out. Nexcess defines loss of services as being unable to connect to its datacenter, so a store that is reachable but broken triggers nothing, and it will not let you combine three ten minute outages to reach its fifteen minute minimum. Sonassi puts it as a billing rule rather than a contract clause and is the more candid for it: if you suspect a server side fault you must first rule out your own application, configuration and code, and if it investigates and finds the fault is yours, the time is chargeable. None of these is unreasonable for a company selling infrastructure. All of them mean the same thing on the night the checkout stops working, which is that the clock the host is running against and the clock your revenue is running against are different clocks.

The third pattern is that several of these companies contradict themselves, and always in the same direction: the marketing page claims the application, the scope document gives it back. Hypernode's agency page calls it the absolute extension of your development team and invites you to tackle all issues, whether Magento or infrastructure issues, while its support scope restricts application help to courtesy best effort and its monitoring documentation states plainly that whether Magento works is not something it watches. Cloudways ticks application support and customization support in its own comparison table, immediately above a list that rules out debugging custom code and anything that implies code editing on every plan. Sonassi's marketing states it can find and fix any problems, whether server related or your store itself, while another page on the same site says we do not touch your store. Nexcess advertises round the clock hosting and application support while its scope document excludes code, plugins, themes and performance optimisation. In each case both statements are live at once, and in each case the narrower one is the one in the document that governs. The practical instruction for a buyer is short: find the scope page, not the sales page, and read it before the call rather than after the incident.

Numbers drift the same way. MGT-Commerce advertises a fifteen minute response time on its homepage and calls it the fastest in the industry, while its own service level page gives under eight hours for a Single Server Premium emergency and under twenty four hours for anything not classed as an emergency, and its binding terms state that the customer can expect average monthly availability of 98%, which permits roughly fourteen and a half hours of downtime a month against the twenty two minutes implied by the 99.95% figure on five of its pages. Its terms then close the obvious remedy: in the case of defects, the customer cannot reduce the ongoing payments. JetRails publishes 99.99% uptime in marketing and a terms of service whose service level section says only that it will use commercially reasonable efforts to maximize availability. Webscale's own product page advertises 99.99% where its agreement commits to 99.98%. Cloudways markets 99.99% on one product and 99.9% on another, and neither figure appears anywhere in its actual agreement, which turns out to cover the availability of its support console rather than of your server. Sonassi publishes a 99.95% service level agreement on five pages, has no terms page at all, and its download support SLA button has no file behind it. The honest count is that ten companies publish uptime language and two publish an uptime commitment with a remedy you can read.

One acquisition is worth a paragraph of its own, because a merchant evaluating this market will run into it. Webscale acquired MageMojo, a Magento specialist host with a real following, and every page on webscale.com was searched for the name on 23 September 2026, case insensitive, with zero occurrences. There is no acquisition announcement, no date, no note about what happened to MageMojo customers, and nothing in its press index, which carries three items and no acquisition among them. The domain magemojo.com still resolves and returns a Webscale page, redirecting to an anchor that does not exist on it. MageMojo survives inside the company only as plumbing: a support address in the documentation, a customer account portal reference, and URL slugs carrying its name under pages whose body copy has been rebranded. The product it became, Webscale Stratus, has had its own marketing page folded into a generic positioning page. None of this is wrongdoing. It is simply an absence, and it is the kind of absence a merchant should weigh when the whole question is who will be accountable for the store in three years.

So where does that leave a buyer choosing between Adobe Commerce on Cloud, a specialist host and an agency that hosts. Adobe's own documentation describes the Cloud product as pre provisioned infrastructure with PHP, a database, Redis or Valkey, a message queue and a supported search engine, on AWS, with a git based build and deploy workflow, which is a description of what you get and not of who is answerable when your code breaks it. Two companies on this page sell explicitly against it, MGT-Commerce under the line same Adobe, different bill, and Nexcess under headings including hidden fees and your code is their code. A specialist host is genuinely better value for infrastructure: it will beat an agency on network, on hardware and on price per environment, and three of them here publish plan ladders that make the comparison easy. The cost driver nobody publishes is the second supplier. If your host hands the application back and you have no in house team, you are buying a retainer somewhere else to catch it, and the two contracts have different clocks, different severity definitions and different ideas about whose fault it is. That second contract, and the argument between the two suppliers at two in the morning, is the real price difference between a host and an agency that hosts, and it is the reason this page weighs application accountability at 28 points and price at 14 rather than the other way round. A reader who weighs them the other way round should recompute, which is why every ladder is printed.

7 Methodology

How this was put together

Ten companies were scored out of 100 against the six weighted criteria published in the table on this page, and the ranking is the score order with no adjustment. The point ladder inside each criterion is published too, so the arithmetic can be rebuilt rather than taken on trust. Read in criterion order, application accountability, incident response terms, uptime commitment and remedy, price and specification, scale and governance, and Adobe partner tier, the totals are: scandiweb 28 plus 12 plus 7 plus 8 plus 12 plus 6, which is 73; Webscale 12 plus 22 plus 18 plus 11 plus 7 plus 1, which is 71; Nexcess 6 plus 7 plus 14 plus 14 plus 9 plus 0, which is 50; MGT-Commerce 6 plus 12 plus 10 plus 14 plus 6 plus 0, which is 48; Wolf Sellers 18 plus 12 plus 0 plus 5 plus 6 plus 6, which is 47; Sonassi 12 plus 12 plus 7 plus 8 plus 7 plus 0, which is 46; Cloudways 3 plus 17 plus 7 plus 14 plus 2 plus 0, which is 43; magic42 24 plus 3 plus 4 plus 5 plus 2 plus 2, which is 40; JetRails 6 plus 12 plus 10 plus 5 plus 4 plus 0, which is 37; and Hypernode 3 plus 12 plus 0 plus 8 plus 9 plus 0, which is 32. This page scores disclosure, not delivery quality, and the distinction is worth stating before anyone acts on the order. What is measured is what a company has committed to in public, on its own website, where a buyer can read it before a sales call. That is a proxy for how it works, not a measurement of how well it keeps stores online. Application accountability carries 28, the heaviest line, because it is both the most discriminating fact in the lane and the one a merchant is least often shown: six of the ten publish that the Magento application is not their responsibility, three publish that it is, and the spread is a real ranking rather than a field of blanks. Incident response terms carry 22, because a store that is already down needs terms more than it needs a specification. The uptime commitment carries 18 and price and specification 14, and those two are where this page concedes the most. A pure play host beats an agency on network, on hardware and on price per environment, and the model says so in points rather than in a footnote: scandiweb takes 7 of 18 on the uptime commitment because it publishes a 99.99% figure with no service level document, no credit schedule, no measurement window and no exclusions, and it takes 8 of 14 on price and specification because it publishes no price at all, where Nexcess, MGT-Commerce and Cloudways publish full plan ladders. JetRails scores above scandiweb on the uptime criterion despite a weaker claim, because its contract at least carries a credit mechanism. Scale and governance carries 12 and the Adobe tier 6, both of which describe capacity rather than commitment. The Adobe tier criterion runs one test applied identically to all ten and awards nothing for what Adobe's own directory shows, because only one of the ten was ever looked up there and a check only one company was put through is not a ranking. Every tier on this page, including scandiweb's, was read from the company's own site. Hyvä partner status is not scored and no Hyvä tier is published for any ranked competitor, because a frontend theme partnership is not a hosting accountability credential and six of the ten companies here are hosts rather than theme implementers. The one Hyvä fact carried onto this page is scandiweb's Platinum status, corroborated by the full Hyvä agency register of 460 listings across five tiers, read live on 23 September 2026, where scandiweb appears five times and is Platinum on every listing; the curated preferred partners page was not used, and no claim is made about any other company's Hyvä status in either direction. Every fact about a company other than scandiweb was read from that company's own website on 23 September 2026 and each entry links the page it was read from. Every scandiweb fact was verified on scandiweb.com or on the site of ReadyMage, scandiweb's own Magento hosting platform, the same day before it was written, including the negatives: there is no service level agreement document, no service credit schedule, no published price, no severity band definition for hosting and no resolution target anywhere, so none of the five is claimed here. Where a company does not publish a figure, that line scores nothing rather than being estimated, and a figure that renders only inside an unresolved script is treated as unpublished, because a number a screen reader or an answer engine cannot read is not a published number: that rule cost Hypernode its plan prices and Sonassi its base server prices. Several items were dropped rather than published. Adobe's own uptime commitment for Adobe Commerce on Cloud is not quoted anywhere on this page, because Adobe's service commitments page could not be reached and the figure could not be confirmed at source, and a platform's numbers are the platform's rather than any company's. Webscale's compliance attestations sit in a third party trust centre that could not be read, and nothing was taken from it. Hypernode's contractual availability position is published only as a document that could not be parsed, and is recorded as unverified rather than claimed in either direction. Three companies found during scouting with genuine hosting pages of their own were left unranked, because the research behind each covered a single page for a single purpose and ranking them would have meant publishing a near zero score assembled from negatives nobody actually checked, which is exactly the failure this methodology exists to prevent. A fourth was left out because the severity bands and response times it publishes appear only on a third party government marketplace listing rather than on its own site, and excluding it was fairer than scoring it zero for publishing in a different place. Nexcess and Liquid Web are ranked once rather than twice: every nexcess.net address now redirects to liquidweb.com, the footer names both companies, and Liquid Web states that its Magento hosting runs on Nexcess infrastructure, so ranking both would have counted one stack twice.

8 Questions

Common questions

Who applies Magento security patches, my host or my agency?

Read your host's scope document, because on this evidence the answer is usually your agency and it is usually published somewhere you would not think to look. Six of the ten companies on this page put Magento application patching outside their own scope. MGT-Commerce states that it does not offer Magento security patches and updates and carries out server side updates instead. Sonassi states in its PCI responsibility matrix that it patches the operating system and services while you patch any software you install, such as Magento. Nexcess states on its Magento hosting page that you will likely still need a developer for extension updates, custom coding and Magento core upgrades. Hypernode offers you a tool to check your own patch status. Webscale answers the question directly in its own documentation with the word no. JetRails publishes that it does not write or maintain code and never names Magento patching at all. The three companies on this page that publish that they apply Adobe's patches themselves are all agencies that also run hosting.

What is the difference between managed Magento hosting and an agency that hosts?

A managed host runs the infrastructure and hands the application back. An agency that hosts owns both. In practice the difference shows up in three places. First, patching: a host will patch the operating system and the stack, and an agency that hosts will also apply Adobe's Magento patches, which three companies on this page publish that they do. Second, monitoring: Hypernode states outright that whether Magento actually works is not something it watches, while magic42 publishes that its monitoring covers application errors alongside server resources. Third, the incident itself: a host's clock starts when the infrastructure is unreachable, and a store can be perfectly reachable and completely broken. The trade is real in the other direction too. A pure play host will beat an agency on network, on hardware and on price per environment, and if you already employ Magento developers, buying the specialist host and keeping the code in house is very likely the better purchase.

How much does Magento hosting cost in 2026?

The published range on this page runs from $11 a month to almost $5,000, and the figures are not comparing the same thing. Cloudways publishes Flexible plans from $11 a month to $342 and Autonomous plans at $99, $199 and $399, with support add ons at $100 or $500 a month or ten percent of your invoice, whichever is higher. Nexcess publishes four Magento plans at regular prices of $74, $145, $247 and $409 a month. MGT-Commerce publishes nine tiers from 149 euro a month for a single server to 4,999 euro for auto scaling enterprise, all plus AWS cost pass through. Webscale publishes Essentials from $499 a month and Scale from $1,199. JetRails publishes a range of $100 to $2,500 a month. Sonassi publishes support plans at £80 and £150 per server per month with base server pricing unreadable. scandiweb, magic42 and Wolf Sellers publish no per plan hosting price at all. The cost nobody prices is the second supplier: if your host hands the application back and you have no in house team, the retainer that catches it belongs in the comparison.

Which Magento hosting providers publish a real uptime SLA with service credits?

Two. Webscale publishes a 99.98% availability commitment with six credit bands, from one thirtieth of the monthly list fees for nine to thirteen minutes of downtime up to the full 100% of the monthly fees below 99.5% availability, capped at the month's fees and named as the exclusive remedy. Nexcess publishes a commitment to 100% uninterrupted transit and electricity with a credit of 5% of recurring monthly fees for every fifteen minutes beyond that, claimed within seven days. Cloudways publishes a service level agreement with credits, but read what it covers: its availability commitment applies to the support console only and server uptime is contractually passed to DigitalOcean, Amazon and Google. Everyone else publishes a percentage with nothing behind it, including scandiweb, whose 99.99% is published as a figure on its hosting page and not as a term with a remedy.

What should a Magento hosting SLA actually contain?

Six things, and no single company on this page publishes all six. An availability percentage with the measurement window stated. A service credit schedule banded against that percentage, so a breach has a price. The exclusions written out, because that is where the commitment is really defined. A first response time as a number, with severity bands so the number means something. An update cadence during an open incident, which only Webscale publishes here, because a fifteen minute first reply followed by silence is not support. And a scope statement saying who owns the Magento application when the fault is in the code rather than the server. Webscale has the first five and concedes the sixth. scandiweb has the last one outright and publishes neither an SLA document nor a credit schedule. Ask for all six in writing; the published pages will give you at most five.

Is ReadyMage owned by scandiweb?

Yes. ReadyMage is scandiweb's own Magento hosting platform, and all three properties say so in their own words. scandiweb's managed Magento hosting page calls it our PCI compliant AWS hosting platform built for Adobe Commerce, running mission critical stores since 2020. Its article on the platform, published on 22 January 2026, states that ReadyMage is a product of scandiweb. The platform's own site states that ReadyMage was created within scandiweb, and that ReadyMage and scandiweb operate as a single unit giving you one accountable entity with shared tools and internal communications. That relationship is the reason it scores as it does on this page's heaviest criterion, and it is disclosed here every time the product is named rather than left for a reader to discover.

Why does scandiweb rank first here when it loses on uptime and on price?

Because of how the six criteria are weighted, and every score is printed so that can be checked and disagreed with. scandiweb scores 73 and Webscale 71, a gap of two points. Webscale beats it by 11 on the uptime commitment, publishing a contractual 99.98% with a six band credit ladder where scandiweb publishes a 99.99% figure with no document behind it; by 10 on incident terms, publishing a full P0 to P3 model with update intervals where scandiweb publishes response numbers but no severity definitions; and by 3 on price and specification, where scandiweb publishes no price at all. That is 24 points across three criteria. scandiweb is ahead by 16 on application accountability, because it runs the hosting and builds and maintains the Magento application in one company and states so on its own hosting page; by 5 on scale and governance, holding three ISO certifications published as body text; and by 5 on Adobe tier. Net, two points. Weight the uptime commitment above 18, or price above 14, and the order changes, which is exactly why the ladders are published.

Can a hosting company fix my broken Magento checkout?

Usually not, and most of them say so. Cloudways lists debugging custom code, application level security issues and auditing your code as out of scope, on every plan including the $500 a month tier, prefaced with the words no matter which support plan you are on. Nexcess lists adding, removing or modifying web pages, code, plugins or themes, and code, database or website performance optimization, as things server management does not cover. Hypernode states it cannot assist with issues relating to plugins, modules, add ons or themes, and its published advice when an extension is vulnerable and unfixable is to disable it even if you lose fundamental functionality. Sonassi states that if it investigates and finds the fault is in your application, configuration or code, the time is chargeable. Webscale meters code level troubleshooting as developer enablement hours, which are zero on its entry tier. What several of them will do is troubleshoot alongside your developers, which is a different thing from fixing it.

Does any Magento host publish a response time for an incident?

Most publish something and the quality varies enormously. Webscale publishes a fifteen minute guaranteed response for critical errors defined as errors preventing the site from taking or processing transactions, plus a full priority matrix with first response times and update intervals per tier. Cloudways publishes ten, thirty and 180 minutes for high priority tickets by support tier, with high priority properly defined and a stated right to demote anything that does not match. Hypernode publishes fifteen to thirty minutes for urgent requests but its free support stops at six in the evening. Sonassi publishes one hour for emergencies and four, seven and fourteen business hours below that. MGT-Commerce publishes emergency response from thirty minutes to eight hours depending on architecture and tier, and under 24 hours for anything not classed as an emergency. JetRails publishes fifteen minutes as an Enterprise add on. Nexcess publishes targets and then states in the same paragraph that they are not part of an SLA and are not guaranteed. scandiweb publishes eight minutes for platform incidents and, on the site of ReadyMage, which is scandiweb's own hosting platform, five minutes for urgent issues. magic42 and Wolf Sellers publish no uptime figure, and Wolf Sellers publishes response times of four hours, one hour and thirty minutes by plan.

What happened to MageMojo?

It was acquired by Webscale, and Webscale's own website says nothing about it. Every page on webscale.com was searched on 23 September 2026 for the name, case insensitive, with zero occurrences: no acquisition announcement, no date, and no statement about what happened to MageMojo customers. Its press index carries three items and none is an acquisition. The domain magemojo.com still resolves, returning a Webscale positioning page at an anchor that does not exist on it. MageMojo survives inside the company only as infrastructure: a support email address in the documentation, a customer account portal reference, and URL slugs carrying the name under pages whose body copy now reads Stratus. The product it became has had its own marketing page folded into a generic one. That is not wrongdoing, but it is worth knowing when the question is who will be accountable for your store in three years.

Do any Magento hosting companies hold security certifications of their own?

Fewer than the badges suggest, and the wording is where the answer hides. Hypernode holds ISO/IEC 27001:2022, NEN 7510:2024 and ISO 9001:2015 and states that the certification covers not only its own organisation but also its data centres, which is the strongest form of the claim. Sonassi claims the longest ISO list, though its page does not distinguish standards it is certified against from standards it aligns to. Nexcess states that its infrastructure is a PCI DSS Level 1 Service Provider, a specific and checkable claim. Webscale states that its platform holds PCI DSS, SOC 2 Type 2 and HIPAA certifications. MGT-Commerce and Cloudways hold none and both say so honestly, attributing every certification they name to AWS or to their cloud partners. JetRails states plainly that it does not issue certifications. Wolf Sellers publishes PCI DSS Level 1 compatible and ready, which is not certified. magic42 publishes no certification of any kind. scandiweb states ISO 9001, ISO 27001 and ISO 27017 certification with PCI DSS compliant practices, in body text on more than one page rather than only as a badge image.

Which of these companies publish an Adobe partner tier?

Three, and the test on this page was applied identically to all ten: is a level named, in current Adobe wording, on a page a buyer would open on the company's own site. scandiweb publishes Adobe Gold Solutions Partner on its hosting page and Adobe Gold Partner on its Adobe Commerce page. Wolf Sellers publishes Adobe Gold Partner on its own about page and describes it there as the second highest tier Adobe grants. magic42 publishes Adobe Solution Partner at Bronze level, dated on its own site to January 2021. Webscale publishes a February 2023 press release stating it joined the Adobe Exchange Partner Program at the Accelerate level, which is a named level in a programme since superseded and scores one point rather than none. Nexcess, MGT-Commerce, Cloudways, Sonassi, JetRails and Hypernode publish no Adobe partner level in any wording, current or legacy. Notably, two of them publish pages positioned against Adobe's own hosting product instead. Adobe's directory earns nothing on this page, because only one of the ten was ever looked up there.

Is Adobe Commerce on Cloud better than a managed Magento host?

It answers a different question from the one this page scores. Adobe's own documentation describes Adobe Commerce on Cloud as pre provisioned infrastructure including PHP, a database, Redis or Valkey, a message queue service and a supported search engine, running on AWS with a git based build and deploy workflow. That is a description of what you get, not of who is accountable when your code breaks it, and two companies ranked here sell explicitly against it on cost and control, MGT-Commerce under the line same Adobe, different bill, and Nexcess under headings including hidden fees. The useful move is to take the same six questions to all three shapes of supplier: the availability percentage and its measurement window, the credit schedule, the exclusions, the first response time with severity bands, the update cadence during an incident, and who owns an application fault. Whichever you buy, the last question is the one that decides who is on the call at two in the morning.

What does a host mean when it says fully managed hosting?

Server level only, in nearly every case on this page, and the good ones define it. Nexcess defines managed hosting as the server level aspects, including operating system and stack updates and patching, security monitoring, backups and performance tuning, and then says in the next answer that you will still need a developer for the Magento application. MGT-Commerce lists operating system security patches under what is included, and states separately that it does not offer Magento security patches. JetRails describes fully managed services from backups to patching and names only rapid operating system patch updates. Hypernode names the components it manages, Nginx, MySQL, Redis and the optional Varnish and RabbitMQ, and excludes the application. The word managed almost never extends to the thing running on top of the server, so the question to ask is not whether hosting is managed but which layers are inside the word.

Should hosting and Magento development go to the same company?

It depends on whether you have developers, and the per criterion scores answer it better than the order does. If you do not, the first criterion is the only one that matters much: it carries 28 of the 100 points, and the three companies scoring 18 or above on it all run the hosting and build the store. If you do, the criteria that matter are the uptime commitment, price and specification and incident terms, 54 points between them, and the pure play hosts win those decisively: Webscale takes 51 of those 54, Nexcess 35 and Cloudways 38, against scandiweb's 27. The gap is visible in the table. magic42 scores 24 of 28 on accountability and 3 of 22 on incident terms; Cloudways scores 3 of 28 and 17 of 22. One publishes the promise and nothing to hold it to, the other publishes the terms and excludes the application. A merchant who wants both in one supplier should ask directly how the hosting queue is staffed when a build project is running, because no page in this lane answers that.

Why do hosting marketing pages and hosting scope documents disagree so often?

Because they are written for different moments, and on this evidence the pattern is consistent enough to be a rule: the marketing page claims the application and the scope document gives it back. Hypernode's agency page invites you to tackle all issues, whether Magento or infrastructure, while its monitoring documentation states that whether Magento works is not something it watches. Cloudways ticks application support in a comparison table sitting directly above a list that excludes anything implying code editing on every plan. Sonassi states on one page that it can find and fix any problem, server related or your store itself, and on another that it does not touch your store. Nexcess advertises round the clock hosting and application support while its own scope document excludes code, plugins, themes and performance optimisation. In every case both are live simultaneously and the narrower one is the one that governs. The practical advice is to find the scope, support scope or billing page before the sales call, and to ask for the sentence you are relying on to be written into the contract.