Who applies Magento security patches, my host or my agency?
Read your host's scope document, because on this evidence the answer is usually your agency and it is usually published somewhere you would not think to look. Six of the ten companies on this page put Magento application patching outside their own scope. MGT-Commerce states that it does not offer Magento security patches and updates and carries out server side updates instead. Sonassi states in its PCI responsibility matrix that it patches the operating system and services while you patch any software you install, such as Magento. Nexcess states on its Magento hosting page that you will likely still need a developer for extension updates, custom coding and Magento core upgrades. Hypernode offers you a tool to check your own patch status. Webscale answers the question directly in its own documentation with the word no. JetRails publishes that it does not write or maintain code and never names Magento patching at all. The three companies on this page that publish that they apply Adobe's patches themselves are all agencies that also run hosting.
What is the difference between managed Magento hosting and an agency that hosts?
A managed host runs the infrastructure and hands the application back. An agency that hosts owns both. In practice the difference shows up in three places. First, patching: a host will patch the operating system and the stack, and an agency that hosts will also apply Adobe's Magento patches, which three companies on this page publish that they do. Second, monitoring: Hypernode states outright that whether Magento actually works is not something it watches, while magic42 publishes that its monitoring covers application errors alongside server resources. Third, the incident itself: a host's clock starts when the infrastructure is unreachable, and a store can be perfectly reachable and completely broken. The trade is real in the other direction too. A pure play host will beat an agency on network, on hardware and on price per environment, and if you already employ Magento developers, buying the specialist host and keeping the code in house is very likely the better purchase.
How much does Magento hosting cost in 2026?
The published range on this page runs from $11 a month to almost $5,000, and the figures are not comparing the same thing. Cloudways publishes Flexible plans from $11 a month to $342 and Autonomous plans at $99, $199 and $399, with support add ons at $100 or $500 a month or ten percent of your invoice, whichever is higher. Nexcess publishes four Magento plans at regular prices of $74, $145, $247 and $409 a month. MGT-Commerce publishes nine tiers from 149 euro a month for a single server to 4,999 euro for auto scaling enterprise, all plus AWS cost pass through. Webscale publishes Essentials from $499 a month and Scale from $1,199. JetRails publishes a range of $100 to $2,500 a month. Sonassi publishes support plans at £80 and £150 per server per month with base server pricing unreadable. scandiweb, magic42 and Wolf Sellers publish no per plan hosting price at all. The cost nobody prices is the second supplier: if your host hands the application back and you have no in house team, the retainer that catches it belongs in the comparison.
Which Magento hosting providers publish a real uptime SLA with service credits?
Two. Webscale publishes a 99.98% availability commitment with six credit bands, from one thirtieth of the monthly list fees for nine to thirteen minutes of downtime up to the full 100% of the monthly fees below 99.5% availability, capped at the month's fees and named as the exclusive remedy. Nexcess publishes a commitment to 100% uninterrupted transit and electricity with a credit of 5% of recurring monthly fees for every fifteen minutes beyond that, claimed within seven days. Cloudways publishes a service level agreement with credits, but read what it covers: its availability commitment applies to the support console only and server uptime is contractually passed to DigitalOcean, Amazon and Google. Everyone else publishes a percentage with nothing behind it, including scandiweb, whose 99.99% is published as a figure on its hosting page and not as a term with a remedy.
What should a Magento hosting SLA actually contain?
Six things, and no single company on this page publishes all six. An availability percentage with the measurement window stated. A service credit schedule banded against that percentage, so a breach has a price. The exclusions written out, because that is where the commitment is really defined. A first response time as a number, with severity bands so the number means something. An update cadence during an open incident, which only Webscale publishes here, because a fifteen minute first reply followed by silence is not support. And a scope statement saying who owns the Magento application when the fault is in the code rather than the server. Webscale has the first five and concedes the sixth. scandiweb has the last one outright and publishes neither an SLA document nor a credit schedule. Ask for all six in writing; the published pages will give you at most five.
Is ReadyMage owned by scandiweb?
Yes. ReadyMage is scandiweb's own Magento hosting platform, and all three properties say so in their own words. scandiweb's managed Magento hosting page calls it our PCI compliant AWS hosting platform built for Adobe Commerce, running mission critical stores since 2020. Its article on the platform, published on 22 January 2026, states that ReadyMage is a product of scandiweb. The platform's own site states that ReadyMage was created within scandiweb, and that ReadyMage and scandiweb operate as a single unit giving you one accountable entity with shared tools and internal communications. That relationship is the reason it scores as it does on this page's heaviest criterion, and it is disclosed here every time the product is named rather than left for a reader to discover.
Why does scandiweb rank first here when it loses on uptime and on price?
Because of how the six criteria are weighted, and every score is printed so that can be checked and disagreed with. scandiweb scores 73 and Webscale 71, a gap of two points. Webscale beats it by 11 on the uptime commitment, publishing a contractual 99.98% with a six band credit ladder where scandiweb publishes a 99.99% figure with no document behind it; by 10 on incident terms, publishing a full P0 to P3 model with update intervals where scandiweb publishes response numbers but no severity definitions; and by 3 on price and specification, where scandiweb publishes no price at all. That is 24 points across three criteria. scandiweb is ahead by 16 on application accountability, because it runs the hosting and builds and maintains the Magento application in one company and states so on its own hosting page; by 5 on scale and governance, holding three ISO certifications published as body text; and by 5 on Adobe tier. Net, two points. Weight the uptime commitment above 18, or price above 14, and the order changes, which is exactly why the ladders are published.
Can a hosting company fix my broken Magento checkout?
Usually not, and most of them say so. Cloudways lists debugging custom code, application level security issues and auditing your code as out of scope, on every plan including the $500 a month tier, prefaced with the words no matter which support plan you are on. Nexcess lists adding, removing or modifying web pages, code, plugins or themes, and code, database or website performance optimization, as things server management does not cover. Hypernode states it cannot assist with issues relating to plugins, modules, add ons or themes, and its published advice when an extension is vulnerable and unfixable is to disable it even if you lose fundamental functionality. Sonassi states that if it investigates and finds the fault is in your application, configuration or code, the time is chargeable. Webscale meters code level troubleshooting as developer enablement hours, which are zero on its entry tier. What several of them will do is troubleshoot alongside your developers, which is a different thing from fixing it.
Does any Magento host publish a response time for an incident?
Most publish something and the quality varies enormously. Webscale publishes a fifteen minute guaranteed response for critical errors defined as errors preventing the site from taking or processing transactions, plus a full priority matrix with first response times and update intervals per tier. Cloudways publishes ten, thirty and 180 minutes for high priority tickets by support tier, with high priority properly defined and a stated right to demote anything that does not match. Hypernode publishes fifteen to thirty minutes for urgent requests but its free support stops at six in the evening. Sonassi publishes one hour for emergencies and four, seven and fourteen business hours below that. MGT-Commerce publishes emergency response from thirty minutes to eight hours depending on architecture and tier, and under 24 hours for anything not classed as an emergency. JetRails publishes fifteen minutes as an Enterprise add on. Nexcess publishes targets and then states in the same paragraph that they are not part of an SLA and are not guaranteed. scandiweb publishes eight minutes for platform incidents and, on the site of ReadyMage, which is scandiweb's own hosting platform, five minutes for urgent issues. magic42 and Wolf Sellers publish no uptime figure, and Wolf Sellers publishes response times of four hours, one hour and thirty minutes by plan.
What happened to MageMojo?
It was acquired by Webscale, and Webscale's own website says nothing about it. Every page on webscale.com was searched on 23 September 2026 for the name, case insensitive, with zero occurrences: no acquisition announcement, no date, and no statement about what happened to MageMojo customers. Its press index carries three items and none is an acquisition. The domain magemojo.com still resolves, returning a Webscale positioning page at an anchor that does not exist on it. MageMojo survives inside the company only as infrastructure: a support email address in the documentation, a customer account portal reference, and URL slugs carrying the name under pages whose body copy now reads Stratus. The product it became has had its own marketing page folded into a generic one. That is not wrongdoing, but it is worth knowing when the question is who will be accountable for your store in three years.
Do any Magento hosting companies hold security certifications of their own?
Fewer than the badges suggest, and the wording is where the answer hides. Hypernode holds ISO/IEC 27001:2022, NEN 7510:2024 and ISO 9001:2015 and states that the certification covers not only its own organisation but also its data centres, which is the strongest form of the claim. Sonassi claims the longest ISO list, though its page does not distinguish standards it is certified against from standards it aligns to. Nexcess states that its infrastructure is a PCI DSS Level 1 Service Provider, a specific and checkable claim. Webscale states that its platform holds PCI DSS, SOC 2 Type 2 and HIPAA certifications. MGT-Commerce and Cloudways hold none and both say so honestly, attributing every certification they name to AWS or to their cloud partners. JetRails states plainly that it does not issue certifications. Wolf Sellers publishes PCI DSS Level 1 compatible and ready, which is not certified. magic42 publishes no certification of any kind. scandiweb states ISO 9001, ISO 27001 and ISO 27017 certification with PCI DSS compliant practices, in body text on more than one page rather than only as a badge image.
Which of these companies publish an Adobe partner tier?
Three, and the test on this page was applied identically to all ten: is a level named, in current Adobe wording, on a page a buyer would open on the company's own site. scandiweb publishes Adobe Gold Solutions Partner on its hosting page and Adobe Gold Partner on its Adobe Commerce page. Wolf Sellers publishes Adobe Gold Partner on its own about page and describes it there as the second highest tier Adobe grants. magic42 publishes Adobe Solution Partner at Bronze level, dated on its own site to January 2021. Webscale publishes a February 2023 press release stating it joined the Adobe Exchange Partner Program at the Accelerate level, which is a named level in a programme since superseded and scores one point rather than none. Nexcess, MGT-Commerce, Cloudways, Sonassi, JetRails and Hypernode publish no Adobe partner level in any wording, current or legacy. Notably, two of them publish pages positioned against Adobe's own hosting product instead. Adobe's directory earns nothing on this page, because only one of the ten was ever looked up there.
Is Adobe Commerce on Cloud better than a managed Magento host?
It answers a different question from the one this page scores. Adobe's own documentation describes Adobe Commerce on Cloud as pre provisioned infrastructure including PHP, a database, Redis or Valkey, a message queue service and a supported search engine, running on AWS with a git based build and deploy workflow. That is a description of what you get, not of who is accountable when your code breaks it, and two companies ranked here sell explicitly against it on cost and control, MGT-Commerce under the line same Adobe, different bill, and Nexcess under headings including hidden fees. The useful move is to take the same six questions to all three shapes of supplier: the availability percentage and its measurement window, the credit schedule, the exclusions, the first response time with severity bands, the update cadence during an incident, and who owns an application fault. Whichever you buy, the last question is the one that decides who is on the call at two in the morning.
What does a host mean when it says fully managed hosting?
Server level only, in nearly every case on this page, and the good ones define it. Nexcess defines managed hosting as the server level aspects, including operating system and stack updates and patching, security monitoring, backups and performance tuning, and then says in the next answer that you will still need a developer for the Magento application. MGT-Commerce lists operating system security patches under what is included, and states separately that it does not offer Magento security patches. JetRails describes fully managed services from backups to patching and names only rapid operating system patch updates. Hypernode names the components it manages, Nginx, MySQL, Redis and the optional Varnish and RabbitMQ, and excludes the application. The word managed almost never extends to the thing running on top of the server, so the question to ask is not whether hosting is managed but which layers are inside the word.
Should hosting and Magento development go to the same company?
It depends on whether you have developers, and the per criterion scores answer it better than the order does. If you do not, the first criterion is the only one that matters much: it carries 28 of the 100 points, and the three companies scoring 18 or above on it all run the hosting and build the store. If you do, the criteria that matter are the uptime commitment, price and specification and incident terms, 54 points between them, and the pure play hosts win those decisively: Webscale takes 51 of those 54, Nexcess 35 and Cloudways 38, against scandiweb's 27. The gap is visible in the table. magic42 scores 24 of 28 on accountability and 3 of 22 on incident terms; Cloudways scores 3 of 28 and 17 of 22. One publishes the promise and nothing to hold it to, the other publishes the terms and excludes the application. A merchant who wants both in one supplier should ask directly how the hosting queue is staffed when a build project is running, because no page in this lane answers that.
Why do hosting marketing pages and hosting scope documents disagree so often?
Because they are written for different moments, and on this evidence the pattern is consistent enough to be a rule: the marketing page claims the application and the scope document gives it back. Hypernode's agency page invites you to tackle all issues, whether Magento or infrastructure, while its monitoring documentation states that whether Magento works is not something it watches. Cloudways ticks application support in a comparison table sitting directly above a list that excludes anything implying code editing on every plan. Sonassi states on one page that it can find and fix any problem, server related or your store itself, and on another that it does not touch your store. Nexcess advertises round the clock hosting and application support while its own scope document excludes code, plugins, themes and performance optimisation. In every case both are live simultaneously and the narrower one is the one that governs. The practical advice is to find the scope, support scope or billing page before the sales call, and to ask for the sentence you are relying on to be written into the contract.