The initial effort of building PunchOut in-house is deceptive. The first build — optimistically €40–60k — is only the tip of the iceberg. The real cost accrues over years: in maintenance, ongoing development, and reacting to the special cases of every single procurement system.
5-year TCO in the model scenario · 15 enterprise customers
excl. order processing
excl. order processing
excl. order processing
incl. order processing
All values are model assumptions (methodology below). The model is deliberately conservative in favor of building in-house — and its best case is the floor, not the expected value: the variance points exclusively upward.
Methodology
Transparency note
All cost figures on this page are model assumptions based on publicly available market data and established software engineering literature. They illustrate orders of magnitude and are not a binding quote. The model is deliberately conservative in favor of building in-house — if the comparison still favors buying, the result is all the more robust.
The average gross annual salary of a software developer in Germany is €65,000 (jobvector salary analysis 2026, as of July 29, 2026, 2,272 data points; €52,663–€76,290 at the 25th/75th percentile)1. Including employer social security contributions, equipment, and overhead, we assume fully loaded costs of approx. €100,000–€120,000/year (assumption).
The comparison covers 5 years. Model scenario: a manufacturer/wholesaler serves 15 enterprise customers via e-procurement systems such as SAP Ariba, Coupa, Jaggaer, and Onventis.
The list price of PunchCommerce Business is €49 per license per month (plus VAT), protocol-independent — OCI, cXML, and IDS Connect included. PunchCommerce Enterprise is priced individually. The comparison uses a model assumption for a typical enterprise configuration: a €1,495/month base fee (incl. procurement gateway, order processing for cXML orders, dedicated infrastructure, custom domain & SSL, OAuth 2.0, support via phone/ticket/email) plus €44.10 per customer per month (assumed volume-tier value below the Business list price)21. All prices plus VAT.
TCO comparison
Why does maintenance dominate? The empirical software engineering research is unambiguous: Robert L. Glass puts maintenance at 40 to 80 percent of software lifecycle costs (60 percent on average) — and roughly 60 percent of maintenance is enhancement work, not bug fixing2. Barry Boehm formalized the relationship between development and annual maintenance cost in the COCOMO model back in 19813.
Meir M. Lehman's laws of software evolution explain the mechanism: a system in use must be adapted continuously or it becomes progressively less useful (Continuing Change) — and its complexity increases as it evolves unless actively counteracted (Increasing Complexity)4. Applied to PunchOut: cXML is continuously developed (currently version 1.2.071, as of August 14, 2026)12, and every new procurement system brings its own logic. An in-house build has to follow this change permanently.
All values are assumptions; scenario of 15 enterprise customers over 5 years.
| Cost block | Best case | Mid case | Realistic |
|---|---|---|---|
| Initial development | €40k | €50k | €60k |
| Maintenance (platform updates, security, bug fixing), €15–25k/year × 5 | €75k | €100k | €125k |
| New integrations/special cases (€15–30k each) | €15k | €30k | €50k |
| Subtotal for building in-house | €130k | €180k | €235k |
Important methodology note
This make calculation does not yet include order processing (handling inbound cXML orders including the order management pipeline). The real make total is therefore even higher — with PunchCommerce it is included in the base fee.
Partly included in maintenance, partly on top; orders of magnitude are assumptions.
| Additional block | Character | Order of magnitude (assumption) |
|---|---|---|
| Ongoing adaptation to new cXML versions | recurring | part of maintenance; grows with release frequency |
| Adapting to each procurement system's logic (Ariba, Coupa, Jaggaer, Onventis) | per platform/customer | €15–30k per new platform logic |
| ISO 9001 (initial certification + surveillance) | one-off + annual | initial ~€5–15k, annually ~€5.5–11k |
| ISO 27001 (initial certification + audits + pen tests) | one-off + annual | first year SME ~€35–50k, annually ~€7.5–15k |
| Opportunity cost of developers | ongoing | deducted from the core product |
| Bus factor / concentrated know-how risk | risk | hard to quantify, high |
| Security / pen tests | annual | ~€3–20k/year |
| SLA / 24-7 operational readiness | ongoing | staffing and on-call costs |
Model calculation (assumption, plus VAT)
Included in the base fee
Even in the best case, building in-house merely matches buying (€130k vs. ~€129k) — and that best case is the floor, not the expected value. Flyvbjerg and Budzier analyzed 1,471 IT projects: the average cost overrun was 27 percent — but one in six projects was a "black swan" with an average 200 percent cost overrun and a schedule overrun of almost 70 percent5. The risk sits exclusively in the upward outliers — never downward.
Older Standish CHAOS figures (1994: only 16.2 percent of projects on time and on budget; 52.7 percent exceeding budget by 189 percent on average)6 point in the same direction but are methodologically contested7; we therefore rely primarily on the peer-reviewed Flyvbjerg/Budzier data.
On top of that: the €130k make floor does not even include order processing, which is included with PunchCommerce. The buy side, by contrast, has no variance — it is contractual from day 1.
Marginal costs
The TCO table describes a fixed scenario. What matters, though, is the dynamic: what happens when the next enterprise customer demands an integration — via a platform you don't support yet?
+ €2.6k over 5 years
In the model assumption, every additional connected customer costs €44.10/month ≈ €529/year — protocol-independent, whether OCI, cXML, or IDS Connect.
The economic reason: the SaaS vendor amortizes its maintenance costs across many customers (fixed-cost degression). Average maintenance cost per customer falls as the customer base grows — the marginal price stays stable.
+ €15–30k per new platform logic
Every new platform, every new protocol, every special request from a won tender creates its own development block (assumption: €15–30k and more) — plus a permanently growing maintenance surface.
A single company carries 100 percent of the maintenance burden alone — no economies of scale — and additionally fights Lehman's second law: complexity that grows with every special integration4.
Interactive model calculation
Move the customer count — the model scales both sides over 5 years. All values are assumptions (model details below), not a quote.
In-house · 5-year TCO (model range)
–
excl. order processing; variance points upward only
PunchCommerce · 5-year TCO (model assumption)
/month · fixed & predictable · incl. order processing
Marginal cost per additional customer (5 years)
€2,646 vs. €15–30k
Buy: linear · Make: per new platform logic
Note: for small scenarios without SLA requirements, PunchCommerce Business starts at €49 per customer per month with no base fee — the buy side would then be significantly lower still.
Core competence
Four questions as a self-test. If your answer is mostly "no", core competence theory clearly favors buying.
Does PunchOut middleware differentiate us in the market — or do customers simply expect it as a hygiene factor?
Would a customer choose us because of our self-built PunchOut middleware? Or because of product, price, availability, and service?
Does building in-house tie up developer capacity that is missing from the actual core product or the digitalization of the core business?
Do we have the specialist knowledge for all protocols and platform quirks — permanently, even through staff turnover?
Transaction cost economics
Following Coase, firms exist where internal organization is cheaper than the market8. Williamson refined this: high asset specificity favors make, standardized services favor buy9. PunchOut is built on open standards (cXML, OCI, IDS Connect) — low specificity, economically a clear buy case.
Core competence theory
Prahalad and Hamel: companies should concentrate resources where they differentiate10. A manufacturer or wholesaler differentiates through products, assortment, availability, price, and service — not through protocol middleware.
Analyst rule of thumb
Gartner's buy-build-blend model: "Buy what you can. Build what you must."11 Non-differentiating systems (systems of record — which includes PunchOut middleware) should be bought.
Scope
"Connecting PunchOut" sounds like one interface. In reality it is a product made of twelve capabilities — each of them its own cost driver of an in-house build.
PunchOutSetupRequest, OrderMessage, BrowserFormPost — plus ongoing version maintenance of the standard.
Two protocol variants: HTTP POST/GET and JSON — both maintained permanently in parallel.
German wholesale standard (plumbing/HVAC, electrical) with seven actions — from cart to product search.
Integration layer for Shopware, Magento, JTL, Spryker, or your custom platform.
For customers without shop access or with customer-specific catalogs.
Custom attributes per customer, assortment, and classification (ECLASS, UNSPSC).
OCI supports up to 40 data nodes — which ones are required varies per buyer.
Documentation per platform and buyer — for onboarding and audits.
Receive OrderRequests, validate them, forward to ERP/shop — not included in the make TCO above.
SAML and OIDC for enterprise requirements on user and permission management.
Uptime commitments, incident response, and escalation paths in the enterprise environment.
Certifications that enterprise procurement increasingly demands from suppliers.
The main reason every new customer creates its own engineering block in an in-house build: session handling, authentication, mapping, and certification differ per system — four examples.
The platform details come from vendor and practitioner documentation and are practical observations, not platform guarantees. They demonstrate: "connecting PunchOut" is never done once — it is done per platform and, in part, per buyer.
Hidden costs
Enterprise procurement increasingly demands proof of quality and information security management from suppliers. With an in-house build, this effort lands entirely on you — when buying, the vendor carries it. The following orders of magnitude come from consulting and certification providers and depend on scope20.
24/7 on-call, monitoring, and continuous security updates — in the enterprise environment not optional, but part of the contract (SLA).
When buying, the vendor carries this burden
netzdirektion is certified to ISO 9001:2015 (DEKRA). PunchCommerce is hosted in ISO 27001-certified data centers in Germany, GDPR-compliant — including monitoring, security updates, and SLA-backed operations in the Enterprise plan.
Verdict
Following Williamson and Prahalad/Hamel, two axes decide make or buy: how much does PunchOut differentiate you in the market — and how specific are your requirements beyond the open standards?
Differentiation low · specificity high
Blend
Buy the standard, add special logic where needed.
Differentiation high · specificity high
Make
The exception — integration is your product.
Differentiation low · specificity low
Buy
The standard case for manufacturers and wholesalers.
Differentiation high · specificity low
Blend
Buy the standard, build differentiation elsewhere.
This analysis would be incomplete without the opposite direction. Make is the right decision if at least one of these applies:
If none of these apply, TCO, marginal costs, and core competence theory all point the same way: buy — or blend: buy the standard and build only genuinely special logic yourself.
FAQ
Short and specific answers — on costs, protocols, maintenance, and the edge cases where building in-house is the right call.
Sources
Selection of the literature, standards, and market data used. Cost figures from consulting and certification providers are market-based orders of magnitude, not official statistics.
Persönlicher Kontakt
We run the numbers for your scenario — customer count, platforms, protocols, order volume. Factual and traceable, with all assumptions disclosed.