Build or License PunchOut? A Make-or-Buy Analysis | Create OCI and cXML PunchOut Catalogues | PunchCommerce                            ![](//analytics.punchcommerce.de/matomo.php?idsite=1&rec=1)

   Make-or-buy analysis · For enterprise decision-makers  Build PunchOut in-house or license it? A TCO and core competence analysis.
============================================================================

 The initial effort of building PunchOut in-house is deceptive. The first build — optimistically €40–60k — is only the tip of the iceberg. The real cost accrues over years: in maintenance, ongoing development, and reacting to the special cases of every single procurement system.

 [ Request TCO comparison 30 min · remote · with the founder ](https://account.netzdirektion.de/appointments/punchcommerce) [ Read methodology &amp; assumptions ](#methodik)

      €40–60k initial build Maintenance &amp; updates Platform special cases Certifications Operations &amp; SLA

5-year TCO in the model scenario · 15 enterprise customers

  €130k In-house · best caseexcl. order processing

 €180k In-house · mid caseexcl. order processing

 €235k In-house · realisticexcl. order processing

 fixed &amp; predictable ~€129k PunchCommerceincl. order processing

  All values are model assumptions (methodology below). The model is deliberately conservative in favor of building in-house — and its best case is the floor, not the expected value: the variance points exclusively upward.

 Methodology

 Methodology &amp; assumptions — before you read on
----------------------------------------------------

Transparency note

 All cost figures on this page are **model assumptions** based on publicly available market data and established software engineering literature. They illustrate orders of magnitude and are not a binding quote. The model is deliberately **conservative in favor of building in-house** — if the comparison still favors buying, the result is all the more robust.

### Fully loaded developer cost (Germany)

 The average gross annual salary of a software developer in Germany is €65,000 (jobvector salary analysis 2026, as of July 29, 2026, 2,272 data points; €52,663–€76,290 at the 25th/75th percentile)[1](#ref-1). Including employer social security contributions, equipment, and overhead, we assume fully loaded costs of **approx. €100,000–€120,000/year** (assumption).

### Time horizon &amp; scenario

 The comparison covers **5 years**. Model scenario: a manufacturer/wholesaler serves **15 enterprise customers** via e-procurement systems such as SAP Ariba, Coupa, Jaggaer, and Onventis.

### Price basis of the buy side

 The list price of PunchCommerce Business is €49 per license per month (plus VAT), protocol-independent — OCI, cXML, and IDS Connect included. PunchCommerce Enterprise is priced individually. The comparison uses a model assumption for a typical enterprise configuration: a **€1,495/month base fee** (incl. procurement gateway, order processing for cXML orders, dedicated infrastructure, custom domain &amp; SSL, OAuth 2.0, support via phone/ticket/email) plus **€44.10 per customer per month** (assumed volume-tier value below the Business list price)[21](#ref-21). All prices plus VAT.

 TCO comparison

 The 5-year TCO: building in-house vs. PunchCommerce
-----------------------------------------------------

 Why does maintenance dominate? The empirical software engineering research is unambiguous: Robert L. Glass puts maintenance at **40 to 80 percent of software lifecycle costs** (60 percent on average) — and roughly 60 percent of maintenance is enhancement work, not bug fixing[2](#ref-2). Barry Boehm formalized the relationship between development and annual maintenance cost in the COCOMO model back in 1981[3](#ref-3).

 Meir M. Lehman's laws of software evolution explain the mechanism: a system in use must be adapted continuously or it becomes progressively less useful (*Continuing Change*) — and its complexity increases as it evolves unless actively counteracted (*Increasing Complexity*)[4](#ref-4). Applied to PunchOut: cXML is continuously developed (currently version 1.2.071, as of August 14, 2026)[12](#ref-12), and every new procurement system brings its own logic. An in-house build has to follow this change permanently.

### Building in-house: base model calculation

All values are assumptions; scenario of 15 enterprise customers over 5 years.

    Cost block Best case Mid case Realistic     Initial development €40k €50k €60k   Maintenance (platform updates, security, bug fixing), €15–25k/year × 5 €75k €100k €125k   New integrations/special cases (€15–30k each) €15k €30k €50k   Subtotal for building in-house €130k €180k €235k

Important methodology note

 This make calculation does **not** yet include **order processing** (handling inbound cXML orders including the order management pipeline). The real make total is therefore even higher — with PunchCommerce it is included in the base fee.

### Additional cost blocks of building in-house

Partly included in maintenance, partly on top; orders of magnitude are assumptions.

    Additional block Character Order of magnitude (assumption)     Ongoing adaptation to new cXML versions recurring part of maintenance; grows with release frequency   Adapting to each procurement system's logic (Ariba, Coupa, Jaggaer, Onventis) per platform/customer €15–30k per new platform logic   ISO 9001 (initial certification + surveillance) one-off + annual initial ~€5–15k, annually ~€5.5–11k   ISO 27001 (initial certification + audits + pen tests) one-off + annual first year SME ~€35–50k, annually ~€7.5–15k   Opportunity cost of developers ongoing deducted from the core product   Bus factor / concentrated know-how risk risk hard to quantify, high   Security / pen tests annual ~€3–20k/year   SLA / 24-7 operational readiness ongoing staffing and on-call costs

### The buy side: PunchCommerce in the same scenario

Model calculation (assumption, plus VAT)

  Base fee, enterprise configuration €1,495.00/month

 15 customers × €44.10 (assumed volume-tier value) €661.50/month

 Total per month €2,156.50

 Per year ≈ €25.9k

 Over 5 years ≈ €129k — fixed and predictable from day 1

Included in the base fee

- Procurement gateway for OCI, cXML &amp; IDS Connect
- Order processing for cXML orders
- Dedicated infrastructure
- Custom domain &amp; SSL
- OAuth 2.0
- Support via phone, ticket &amp; email
- Ongoing protocol and platform maintenance by the vendor

### The asymmetry: buy is deterministic, make has a fat tail

 Even in the best case, building in-house merely *matches* buying (€130k vs. ~€129k) — and that best case is the **floor, not the expected value**. Flyvbjerg and Budzier analyzed 1,471 IT projects: the average cost overrun was 27 percent — but **one in six projects was a "black swan" with an average 200 percent cost overrun and a schedule overrun of almost 70 percent**[5](#ref-5). The risk sits exclusively in the upward outliers — never downward.

 Older Standish CHAOS figures (1994: only 16.2 percent of projects on time and on budget; 52.7 percent exceeding budget by 189 percent on average)[6](#ref-6) point in the same direction but are methodologically contested[7](#ref-7); we therefore rely primarily on the peer-reviewed Flyvbjerg/Budzier data.

 On top of that: the €130k make floor does not even include order processing, which is included with PunchCommerce. The buy side, by contrast, has no variance — it is contractual from day 1.

 Marginal costs

 What does the next customer cost?
-----------------------------------

 The TCO table describes a fixed scenario. What matters, though, is the dynamic: what happens when the next enterprise customer demands an integration — via a platform you don't support yet?

 Buy · linear and predictable\+ €2.6k over 5 years

 In the model assumption, every additional connected customer costs €44.10/month ≈ €529/year — protocol-independent, whether OCI, cXML, or IDS Connect.

 The economic reason: the SaaS vendor amortizes its maintenance costs across many customers (fixed-cost degression). Average maintenance cost per customer falls as the customer base grows — the marginal price stays stable.

 Make · erratic and unpredictable\+ €15–30k per new platform logic

 Every new platform, every new protocol, every special request from a won tender creates its own development block (assumption: €15–30k and more) — plus a permanently growing maintenance surface.

 A single company carries 100 percent of the maintenance burden alone — no economies of scale — and additionally fights Lehman's second law: complexity that grows with every special integration[4](#ref-4).

Interactive model calculation

###  How does the comparison change with your customer count?

 Move the customer count — the model scales both sides over 5 years. All values are assumptions (model details below), not a quote.

  Number of enterprise customers to connect:   12550

In-house · 5-year TCO (model range)

  –

excl. order processing; variance points upward only

PunchCommerce · 5-year TCO (model assumption)

 /month · fixed &amp; predictable · incl. order processing

Marginal cost per additional customer (5 years)

€2,646 vs. €15–30k

Buy: linear · Make: per new platform logic

 Note: for small scenarios without SLA requirements, PunchCommerce Business starts at €49 per customer per month with no base fee — the buy side would then be significantly lower still.

  Model assumptions of this calculator- Buy: (€1,495 + customer count × €44.10) × 60 months. Price basis: see methodology; real enterprise pricing is quoted individually.
- Make best case: €40k initial build + €45k maintenance base (5 years) + €3k per customer (pro-rated maintenance and integrations).
- Make realistic: €60k initial build + €75k maintenance base (5 years) + €6.67k per customer.
- Both make values are linear simplifications of the TCO table above (at 15 customers: €130k and €235k) and exclude order processing, certifications, and 24/7 operations.
- At very small customer counts the curves converge — what remains decisive is the risk profile (fat tail) and the developer capacity tied up.

  [ Request a TCO comparison for your scenario 30 min · remote · with the founder ](https://account.netzdirektion.de/appointments/punchcommerce)

  Core competence

 Is PunchOut part of your core business?
-----------------------------------------

 Four questions as a self-test. If your answer is mostly "no", core competence theory clearly favors buying.

 1Does PunchOut middleware differentiate us in the market — or do customers simply expect it as a hygiene factor?

 2Would a customer choose us because of our self-built PunchOut middleware? Or because of product, price, availability, and service?

 3Does building in-house tie up developer capacity that is missing from the actual core product or the digitalization of the core business?

 4Do we have the specialist knowledge for all protocols and platform quirks — permanently, even through staff turnover?

### The theoretical framing

Transaction cost economics

 Following Coase, firms exist where internal organization is cheaper than the market[8](#ref-8). Williamson refined this: high *asset specificity* favors make, standardized services favor buy[9](#ref-9). PunchOut is built on open standards (cXML, OCI, IDS Connect) — low specificity, economically a clear buy case.

Core competence theory

 Prahalad and Hamel: companies should concentrate resources where they differentiate[10](#ref-10). A manufacturer or wholesaler differentiates through products, assortment, availability, price, and service — not through protocol middleware.

Analyst rule of thumb

 Gartner's buy-build-blend model: *"Buy what you can. Build what you must."*[11](#ref-11) Non-differentiating systems (*systems of record* — which includes PunchOut middleware) should be bought.

 Scope

 What you would actually rebuild — the scope checklist
-------------------------------------------------------

 "Connecting PunchOut" sounds like one interface. In reality it is a product made of twelve capabilities — each of them its own cost driver of an in-house build.

 1

### cXML PunchOut

PunchOutSetupRequest, OrderMessage, BrowserFormPost — plus ongoing version maintenance of the standard.

 2

### OCI 4.0 and OCI 5.0

Two protocol variants: HTTP POST/GET and JSON — both maintained permanently in parallel.

 3

### IDS Connect 2.5

German wholesale standard (plumbing/HVAC, electrical) with seven actions — from cart to product search.

 4

### Integration with every shop system

Integration layer for Shopware, Magento, JTL, Spryker, or your custom platform.

 5

### Own storefront with catalog management

For customers without shop access or with customer-specific catalogs.

 6

### Flexible data model

Custom attributes per customer, assortment, and classification (ECLASS, UNSPSC).

 7

### Field mappings

OCI supports up to 40 data nodes — which ones are required varies per buyer.

 8

### Customer-specific documentation

Documentation per platform and buyer — for onboarding and audits.

 9

### Order processing for cXML orders

Receive OrderRequests, validate them, forward to ERP/shop — not included in the make TCO above.

 10

### Single sign-on

SAML and OIDC for enterprise requirements on user and permission management.

 11

### Guaranteed SLAs

Uptime commitments, incident response, and escalation paths in the enterprise environment.

 12

### ISO 9001 and ISO 27001

Certifications that enterprise procurement increasingly demands from suppliers.

### And every platform has its own logic

 The main reason every new customer creates its own engineering block in an in-house build: session handling, authentication, mapping, and certification differ per system — four examples.

#### SAP Ariba

 [15](#ref-15)

- cXML-native; authentication via From/Sender/SharedSecret or digital certificate
- Formal Ariba Network certification; test and production accounts required (test ANID with "-T" suffix)
- UNSPSC/ECLASS classification required
- No self-certify: the buyer's enablement team tests the full loop incl. test PO

#### Coupa

 [16](#ref-16)

- cXML questionnaire with separate test/production records
- BuyerCookieID is persistent per user/supplier — contrary to the generic cXML recommendation of rotating it per session
- Two to four sandbox test rounds are common in practice

#### Jaggaer

 [17](#ref-17)

- Mandatory compliance with the cxml.org standard; cXML documents must not contain a byte order mark (BOM)
- DUNS/NetworkID vary per customer; every buyer can define its own field requirements and workflows
- Certificate valid for at least 3 years; sandbox onboarding before go-live

#### Onventis

 [18](#ref-18)

- Supports OCI 4.0, OCI 5.0, cXML, and openTRANS
- Uses its own OCI 5.0 JSON variant with custom field naming (e.g. VENDOR\_MAT)
- Paid setup per connection

 The platform details come from vendor and practitioner documentation and are practical observations, not platform guarantees. They demonstrate: "connecting PunchOut" is never done once — it is done per platform and, in part, per buyer.

 Hidden costs

 The hidden cost block: certifications &amp; operations
--------------------------------------------------------

 Enterprise procurement increasingly demands proof of quality and information security management from suppliers. With an in-house build, this effort lands entirely on you — when buying, the vendor carries it. The following orders of magnitude come from consulting and certification providers and depend on scope[20](#ref-20).

### ISO 27001 (information security)

  Total first-year cost, SME (10–50 employees) ~€35–50k

 Total first-year cost, mid-market (50–250 employees) €50–80k

 Initial audit fee alone, DAkkS-accredited bodies €9–25k

 Ongoing/year: surveillance audit, internal audit, ISMS tooling ~€7.5–15k

 Annual pen tests €3–8k

### ISO 9001 (quality management)

  Initial certification, SME, audit fee alone ~€2.5–4k

 Realistically incl. consulting/documentation, first year €25–45k

 Annual surveillance audits €3–6k

 Plus internal audit ongoing

 #### Then there are operations

 24/7 on-call, monitoring, and continuous security updates — in the enterprise environment not optional, but part of the contract (SLA).

When buying, the vendor carries this burden

 netzdirektion is certified to ISO 9001:2015 (DEKRA). PunchCommerce is hosted in ISO 27001-certified data centers in Germany, GDPR-compliant — including monitoring, security updates, and SLA-backed operations in the Enterprise plan.

 Verdict

 The decision matrix
---------------------

 Following Williamson and Prahalad/Hamel, two axes decide make or buy: how much does PunchOut differentiate you in the market — and how specific are your requirements beyond the open standards?

Differentiation low · specificity high

Blend

Buy the standard, add special logic where needed.

Differentiation high · specificity high

Make

The exception — integration is your product.

Differentiation low · specificity low

Buy

The standard case for manufacturers and wholesalers.

Differentiation high · specificity low

Blend

Buy the standard, build differentiation elsewhere.

 ↑ vertical: asset specificity of the requirement horizontal: degree of PunchOut differentiation →

### When building in-house makes sense

 This analysis would be incomplete without the opposite direction. Make is the right decision if at least one of these applies:

- PunchOut/procurement integration is itself your product — you are an e-procurement or middleware vendor.
- No standard product covers your requirements — high asset specificity in Williamson's sense.
- A permanently funded integration team with protocol expertise already exists.
- Compelling reasons that rule out buying demand full data sovereignty and architectural control.

 If none of these apply, TCO, marginal costs, and core competence theory all point the same way: buy — or blend: buy the standard and build only genuinely special logic yourself.

 FAQ

### Frequently asked questions on the make-or-buy decision

Short and specific answers — on costs, protocols, maintenance, and the edge cases where building in-house is the right call.

  What does it cost to build a PunchOut solution in-house?   In our model calculation (15 enterprise customers, 5 years, deliberately conservative in favor of building), the 5-year TCO comes to €130,000–€235,000 and more. The largest block is not the initial build (€40–60k) but maintenance and ongoing development. Processing inbound cXML orders is not even included in that figure. All values are model assumptions, not quotes.

  Why is maintenance the largest cost block?   The empirical software engineering research is unambiguous: Robert L. Glass puts maintenance at 40 to 80 percent of software lifecycle costs (60 percent on average), and roughly 60 percent of maintenance is enhancement work, not bug fixing. Lehman's laws of software evolution explain the mechanism: a system in use must change continuously and inevitably grows more complex — protocol releases and new procurement systems create exactly this adaptation pressure.

  Which protocols does a PunchOut solution need to support?   At minimum cXML (SAP Ariba, Coupa, Jaggaer, and others), OCI 4.0 and OCI 5.0 (SAP SRM, S/4HANA, Onventis, and others), plus IDS Connect 2.5 in the German technical wholesale trade. On top of that come buyer-specific field mappings, session handling, and authentication per platform.

  How often does cXML change?   cXML is a living standard under continuous development. The cXML Reference Guide is currently at version 1.2.071 (as of August 14, 2026, © 2026 SAP SE). Every new version can force changes to an in-house build — with PunchCommerce, the vendor carries that version maintenance.

  Is PunchOut a competitive advantage?   For manufacturers and wholesalers, generally not — your customers simply expect PunchOut as a hygiene factor. Differentiation comes from product, assortment, availability, price, and service. Following Prahalad/Hamel, development resources should be concentrated where they differentiate the core business — not in protocol middleware.

  What does PunchCommerce cost?   PunchCommerce Business costs €49 per customer per month (plus VAT), protocol-independent — OCI, cXML, and IDS Connect included. PunchCommerce Enterprise (with SLA, dedicated infrastructure, and order processing) is priced individually; the comparison on this page uses a model assumption of a €1,495/month base fee plus €44.10 per customer per month.

  Why do SAP Ariba, Coupa, Jaggaer, and Onventis differ?   Each platform has its own session, authentication, and mapping logic as well as its own testing and certification processes: Ariba requires formal network certification with test and production accounts, Coupa uses persistent BuyerCookieIDs contrary to the generic cXML recommendation, Jaggaer forbids byte order marks in cXML documents, and Onventis uses its own OCI 5.0 JSON variant with custom field naming. An in-house build has to implement and permanently maintain every one of these quirks.

  When does building in-house make sense?   When procurement integration is itself your product (you are an e-procurement or middleware vendor), when requirements are so specific that no standard product covers them, or when a permanently funded integration team with protocol expertise already exists. For the typical manufacturer or wholesaler, none of these apply.

  Sources

 Sources
---------

 Selection of the literature, standards, and market data used. Cost figures from consulting and certification providers are market-based orders of magnitude, not official statistics.

1. jobvector: *Software developer salary analysis 2026* (as of July 29, 2026, 2,272 data points) – [jobvector.de](https://www.jobvector.de); additionally Indeed, StepStone.
2. Glass, R. L. (2003): *Facts and Fallacies of Software Engineering*, Addison-Wesley – Fact 41 (maintenance: 40–80% of software costs, avg. 60%) and Fact 42 (enhancements: ~60% of maintenance costs).
3. Boehm, B. (1981): *Software Engineering Economics*, Prentice Hall (COCOMO; annual change traffic).
4. Lehman, M. M. (1974/1996): *Laws of Software Evolution* – 1st law (continuing change), 2nd law (increasing complexity).
5. Flyvbjerg, B.; Budzier, A. (2011): *Why Your IT Project May Be Riskier Than You Think*, Harvard Business Review – [hbr.org](https://hbr.org/2011/09/why-your-it-project-may-be-riskier-than-you-think); dataset: [arXiv:1304.0265](https://arxiv.org/abs/1304.0265).
6. Standish Group (1994 ff.): *CHAOS Report*.
7. Molokken, K.; Jørgensen, M. (2003): *A Review of Surveys on Software Effort Estimation* (methodological critique of the Standish figures).
8. Coase, R. (1937): *The Nature of the Firm*, Economica.
9. Williamson, O. E. (1985): *The Economic Institutions of Capitalism*, Free Press.
10. Prahalad, C. K.; Hamel, G. (1990): *The Core Competence of the Corporation*, Harvard Business Review, May–June 1990 – [hbr.org](https://hbr.org/1990/05/the-core-competence-of-the-corporation).
11. Gartner: *Buy vs. Build Strategy / Buy-Build-Blend* – [gartner.com](https://www.gartner.com).
12. cXML.org: *cXML Reference Guide*, version 1.2.071 (August 14, 2026, © 2026 SAP SE) – [xml.cxml.org](https://xml.cxml.org/current/cXMLReferenceGuide.pdf).
13. SAP: *Open Catalog Interface (OCI) 4.0/5.0 – specification*; SAP Community – [community.sap.com](https://community.sap.com).
14. TradeCentric: *SAP SRM OCI PunchOut* (up to 40 data nodes, buyer-specific) – [tradecentric.com](https://tradecentric.com).
15. SAP/Ariba: *Ariba Network PunchOut Catalog Guide* – [support.ariba.com](https://support.ariba.com).
16. Coupa: *PunchOut Catalogs*, Coupa Compass – [compass.coupa.com](https://compass.coupa.com).
17. JAGGAER: *Supplier Enablement Terms / cXML Integration Specification* – [jaggaer.com](https://www.jaggaer.com).
18. Onventis: *Punchout Interface / OCI / openTRANS* – [onventis.com](https://www.onventis.com); PunchCommerce Onventis OCI documentation.
19. BVBS / DG Haustechnik / ZVSHK: *IDS Connect 2.5* – [itek.de](https://www.itek.de); PunchCommerce IDS Connect gateway documentation.
20. ISO cost figures: secjur (*ISO 27001/9001 costs 2026*), heydata (*ISO 27001 costs 2026*), Drata (*ISO 27001 Certification Cost*), acato (*ISO 9001 costs*) – market-based provider figures, scope-dependent.
21. PunchCommerce: feature and pricing information (2026) – [punchcommerce.de/features-and-pricing](https://www.punchcommerce.de/en/features-and-pricing).

 Persönlicher Kontakt

Request your individual TCO comparison
--------------------------------------

We run the numbers for your scenario — customer count, platforms, protocols, order volume. Factual and traceable, with all assumptions disclosed.

 [Request TCO comparison](https://account.netzdirektion.de/appointments/punchcommerce) [Book a demo with the founder](https://account.netzdirektion.de/appointments/punchcommerce)

  Antwort i. d. R. **innerhalb von 24h** • Gründer‑Geführt • Technischer Deep‑Dive möglich

 [ PunchCommerce® ist ein Produkt der ![Netzdirektion GmbH](https://www.punchcommerce.de/static/netzdirektion-logo.png "PunchCommerce® ist ein Produkt der netzdirektion | Gesellschaft für digitale Wertarbeit mbH") ](https://netzdirektion.de)

 [Give feedback now - your opinion helps us to become even better!](https://easy-feedback.de/umfrage/1883200/5FuM95 "Your opinion helps us to become even better!")
