How fast should a Magento agency apply an Adobe security patch?
There is no single industry answer, so read what the published range actually looks like. On this page it runs from under 2 hours for a critical vulnerability, which is Interjar's published SLA, through Bemeir's 7 days for critical or 72 hours where a flaw is actively exploited, ParadoxLabs' 3, 2 or 1 days depending on which retainer you buy, and 1Digital's usually within 72 hours for high severity advisories, down to two companies that publish no number at all and explain why. The useful reference point is that automated exploitation of a Magento flaw often begins within 24 to 72 hours of disclosure, and in the September 2026 case the first confirmed attack on a live store took roughly 50 minutes from first contact to full takeover. Anything measured in weeks for a critical unauthenticated flaw is measured against an attacker working in hours.
Which Magento agencies publish a patch turnaround at all?
Five of the eight companies researched publish something. Four publish a forward commitment: Interjar at under 2 hours from Adobe release for critical and pre authenticated remote code execution flaws, ParadoxLabs at 3, 2 or 1 days by retainer tier against published monthly prices, Bemeir at 7 days for critical or 72 hours where actively exploited with 14, 30 and 90 days behind it by severity, and 1Digital at usually within 72 hours for high severity advisories. One publishes a dated retrospective rather than a commitment: On Tap states that APSB26-92 was applied across every client store the same week it was released in August 2026. scandiweb publishes a dated day by day record of its own response to the September 2026 zero day but no forward number. Towering Media publishes an estimate with conditions rather than a promise, and Macopedia publishes an argued policy of stating no number at all.
Does Adobe still release Magento security patches quarterly?
No. Adobe moved to monthly isolated security fixes in January 2026, and its own documentation commits to monthly isolated security fixes for faster and predictable protection against critical vulnerabilities, alongside annual patch releases with long term support and out of cycle hotfixes where necessary. The bulletin record shows it in practice: six Magento and Adobe Commerce bulletins in the first nine months of 2026, four of them since July and two in September alone, against six across the whole of 2025. Three of the seven agencies ranked on this page still describe the cadence as quarterly on the page where they sell security work, and one of them names the old months on a page stamped as reviewed in May 2026, four months after the change. Only On Tap states it correctly.
What is the 30 October 2026 Adobe Commerce deadline?
It is the date by which Adobe Commerce on Cloud environments running 2.4.4 through 2.4.9 must upgrade three third party dependencies: MariaDB 10.5 and below to 10.6 or higher, Elasticsearch to OpenSearch, and RabbitMQ 3.9 and below to 3.13 or higher. A second wave follows on 31 May 2027 for PHP 8.1 and below to reach 8.2 or higher and Redis 5 and below to reach Valkey 8 or higher. It applies to the Cloud product only, not to on premises installations and not to the software as a service product. Not one of the eight companies researched for this page publishes it anywhere, which is why this page does.
What happens if I miss the Adobe Commerce Cloud dependency deadline?
Adobe states it in two stages and neither is ambiguous. First, environments that do not meet the security requirements by the deadlines will have inbound traffic suspended, taking the storefront offline. Second, if an environment continues to remain non compliant following traffic suspension, Adobe may terminate the cloud services, initiating the decommissioning process, as a result of which all data and assets within the hosted commerce environment, including all instances, environments and branches, will be permanently deleted and cannot be restored. That is not a warning about patches going unavailable. It is the store going dark and then the data going away. If you run Adobe Commerce on Cloud on 2.4.4 through 2.4.7, check your MariaDB, search engine and message queue versions this week.
Does my Magento Open Source store still get security patches?
It depends on your version, and the distinction catches people out. Adobe states that extended support security patches are available to Adobe Commerce customers only and are not available for the Magento Open Source code base. So a store on Adobe Commerce 2.4.6 continues to receive security patches after regular support for that line ended on 11 August 2026, while a store on Magento Open Source 2.4.6 has received none since that date. The September 2026 fix showed the same split in a different form: it covered Adobe Commerce from 2.4.4 up but Magento Open Source only from 2.4.6 up, leaving Open Source 2.4.5 and earlier with no official fix for an actively exploited unauthenticated remote code execution flaw. Of the seven agencies ranked here, only Macopedia publishes the general rule correctly and calls it the most repeated error in writing about the Magento lifecycle.
What should a Magento security patching SLA actually state?
Five things, and no single company on this page publishes all five. A turnaround time from Adobe's release, not from when your agency notices. That time differentiated by severity, so a critical unauthenticated flaw is not queued behind a cosmetic fix. A separate, faster window for a vulnerability already being exploited, which only Bemeir names in this set at 72 hours. A statement of cover hours, since a commitment measured in hours is not deliverable business hours only against bulletins shipped on United States Pacific time. And what happens when a patch cannot be applied safely, which Bemeir publishes as escalation to senior engineering, alternative mitigation and compensating controls until the patch can be applied. Ask for all five in writing, because the published pages will give you at most three.
Can an under 2 hour patch SLA be delivered in business hours only?
Not reliably, and this page prints both halves of the one live example rather than picking a side. Interjar's security page states that critical and pre authenticated remote code execution patching has out of hours response covered. Its emergency support FAQ states that emergency support operates during business hours, and that for retainer clients with critical issues outside those hours it will do its best to respond as quickly as possible but cannot guarantee out of hours availability. Both sentences are published on the same site. Adobe ships its bulletins on United States Pacific time, which for a team working United Kingdom hours can land in the middle of the night, so an under 2 hour commitment from release and a business hours only cover statement cannot both govern. Ask which one is in the contract.
What does Magento support and maintenance cost?
Two companies on this page publish a full rate card. ParadoxLabs publishes four tiers: hourly only at $195 an hour, then $2,700 a month for 15 engineering hours with a 3 day patch SLA, $4,950 a month for 30 hours with a 2 day patch SLA, and from $9,000 a month for 60 or more hours with a 1 day patch SLA and a named engineer, all month to month with a 15 hour minimum, 30 days notice and a $899 site audit credited against the first month. Towering Media publishes $500, $900 and $1,800 a month, also month to month, with security patches applied and tested before production on every tier. Interjar publishes £100 an hour billed to the minute. 1Digital and Macopedia withhold prices by stated policy, and On Tap prices its patching and upgrade programme at zero. For context, ParadoxLabs anchors its own pricing against hiring a senior Magento engineer at $120,000 or more a year fully loaded.
Do any of these agencies hold a security certification?
One of the eight companies researched does, and it is the one ranked first. scandiweb states it is ISO 27001 and ISO 27017 certified for information and cloud security, runs PCI compliant hosting infrastructure and delivers under ISO 9001 with PCI DSS compliant practices, published as body text on more than one page rather than only as a badge image. The other seven publish no ISO 27001, no ISO 27017, no SOC 2 and no PCI DSS certification of their own on any page read. Nobody on this page publishes SOC 2, including scandiweb. The closest anyone else comes is Interjar, which publishes a PCI Requirement 12.10 incident response workflow and preserves incident logs, command history and deploy artefacts for a minimum of 12 months to support a forensic review, which is a named standard it works to rather than a certification it holds. For a lane whose subject is security, that is the most striking absence on the page.
Who do I call if my Magento store is already hacked?
Three of the seven ranked agencies publish something usable for a live compromise. Interjar publishes the most: a response in under 15 minutes for retainer clients, a minute by minute containment runbook, six named incident types including a hacked store and a security breach, a PCI Requirement 12.10 workflow with artefacts preserved for 12 months, a written incident report within 1 business day, and a stated 1 to 3 days for recovery from a confirmed compromise. 1Digital publishes a priority one response target under 1 hour with mitigation under 4 hours, after hours coverage and a pager rotation on its top tier. Towering Media sells emergency work for card skimming scripts, unauthorised admin access and suspicious file changes, but states that response times for new clients depend on current availability. scandiweb publishes a compromise check alongside the patch, with an indicators of compromise table and credential rotation as part of the same job. ParadoxLabs, Bemeir, On Tap and Macopedia publish no hack recovery offer at all on the pages read.
Is a virtual patch a substitute for applying Adobe's patch?
No, and the vendor selling one says so explicitly. A Magento aware firewall installed as a module inside the store blocks a known attack path while the official patch is still pending, which buys a merchant the time to test and deploy properly instead of running an emergency weekend release. It does not fix the underlying flaw, it does not remove a backdoor already installed, and the vendor states plainly that it does not replace an existing content delivery firewall and that its own scanner is still needed alongside it. What makes it worth knowing about is the published timing: on the September 2026 flaw that protection was deployed two days before Adobe's emergency hotfix, and on an earlier flaw four months before Adobe's backported fix reached supported release lines. Treat it as a way to control when you patch, not as a reason not to.
Why is Sansec not ranked on this page?
Because it is not an agency and ranking it as one would be a category error. Sansec is a Netherlands eCommerce security vendor and forensics firm. It sells server side malware and vulnerability scanning, a Magento aware firewall, continuous threat research and paid incident investigation and cleanup, and it does not build Magento stores or apply Adobe patches for merchants. Scoring it on patch turnaround against companies whose job is to apply patches would compare two different things and flatter neither. It appears on this page in the topic section and in the evidence table, labelled as what it is, because it is the source several ranked agencies cite themselves and because its published timelines are the best available evidence for how long the gap between disclosure and a vendor patch actually runs.
Which agencies publish incident performance data rather than promises?
One. Interjar publishes rolling 90 day statistics across its retainer base, refreshed quarterly: a median time to acknowledge of 2 to 4 minutes, a median time to restore of 15 to 45 minutes, 100% of priority one incidents resolved the same business day and zero data loss events, with the definitions printed on the page and the full methodology available on request. The figures are self reported and unaudited and the page says so. Nobody else ranked here publishes a single operational metric. The nearest anything else comes is a volume figure rather than a performance one, such as scandiweb's 9,000 or more tickets handled across 450 or more active support clients, which tells you about scale and nothing about speed. If an operational number matters to your board, this is the one field where the whole lane except one company has nothing to show you.
Which of these companies are Hyvä partners?
Read from the full Hyvä agency register rather than from anybody's own claim, five of the eight are listed. scandiweb appears five times and is Platinum on every listing. ParadoxLabs is Gold and makes no Hyvä claim itself. Bemeir is Gold, which settles a claim its own site leaves open by saying it is the only United States partner without naming a level. On Tap and Macopedia are Silver. Towering Media is Bronze, which matters because it markets Hyvä harder than any other non Platinum name here and a reading of the curated preferred partners page alone would have said it holds nothing. Interjar and 1Digital are not in the register at all, and 1Digital markets Hyvä storefront support as a capability rather than as a partnership, which is the honest way to put it. The register holds 460 listings across five tiers, of which 264 are Bronze, so Bronze is the baseline rather than a distinction. Hyvä status is not scored on this page, because a front end theme partnership is not a security credential.
How do I check an agency's Adobe partner tier myself?
Look it up in Adobe's own Solution Partner Directory rather than taking it from the agency's website, because a tier shown there was issued by Adobe rather than written by the agency. This page does not score that check and says so plainly: scandiweb is the one entry that was looked up, where it is listed as a Gold Partner, and the other seven were not, so whether they appear there is simply unknown. Absence from a directory is not proof that no tier is held. What the tier criterion scores instead is what each company states on its own site: scandiweb states Gold, Interjar states Adobe Silver Solution Partner, Bemeir states an Adobe Commerce partnership with no level, On Tap publishes Magento era partner wording from 2007 with no current Adobe level, Towering Media claims Adobe Commerce certified engineers rather than a partnership, and ParadoxLabs, 1Digital and Macopedia publish no Adobe partner wording of any kind. Ask for the tier and the region, then check it yourself.
What is CVE-2026-75650 and does it affect my store?
It is an unauthenticated remote code execution flaw in Adobe Commerce and Magento Open Source, disclosed on 5 September 2026 and patched by Adobe on 7 September as bulletin APSB26-146. Unauthenticated means an attacker needs no account and no credentials. Adobe's own knowledge base announcement is headed Urgent Action Required and states that Adobe is aware the flaw has been exploited in the wild targeting Adobe Commerce merchants. Adobe lists Adobe Commerce 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3 and Magento Open Source 2.4.4 through 2.4.9 among the affected versions, but affected and patched are not the same list: the fix reaches Adobe Commerce from 2.4.4 up and Magento Open Source only from 2.4.6 up. A second bulletin, APSB26-138, followed on 8 September. If your store was online after 4 September 2026, patching alone is not enough, because the fix closes the entry point without removing a backdoor that may already be installed.
Why does an isolated security patch require me to be on the latest version?
Because Adobe tests it that way. Adobe states that isolated security patch files are non cumulative standalone files containing security fixes only, released independently to enable faster remediation, and that to apply one a customer must be on the latest security only patch release for their supported release line, because isolated patches are tested exclusively against that version. The practical consequence is the part most agency pages skip: patch speed is downstream of version hygiene. A store several minor versions behind cannot take the fast path at all, so the fastest patch turnaround in the world will not help until the upgrade backlog is cleared. If a prospective agency quotes you a patch SLA without asking what version you are on, that is a question worth asking back.
Should patching and development go to the same agency?
They can, but the criteria that decide each one sit on different lines of this weighting, so read the per criterion scores rather than the order if only one matters to you. Patching and incident handling turn on the first two criteria, 52 of the 100 points. Capacity to do larger work turns on delivery scale and partner tier, 24 points between them. The gap shows up clearly: ParadoxLabs scores 21 of 30 on patch turnaround and 3 of 13 on delivery scale, while On Tap scores 10 of 30 on turnaround and 10 of 13 on scale. One publishes a patch SLA next to a price and no client work at all; the other has 400 or more people and no response time. A merchant who wants both in one supplier should ask directly how the patch queue is staffed when a build project is running, because no page in this lane answers that.
Why does scandiweb rank first here when it loses the heaviest criterion?
Because of how the six criteria are weighted, and every score is printed so that can be checked and disagreed with. scandiweb scores 74 and Interjar 68, a gap of six points. Interjar beats it by 17 on patch turnaround and by 5 on incident terms, 22 points ahead across the two heaviest criteria on the page, on the strength of an under 2 hour published SLA and the only operational performance data anyone here publishes. scandiweb is ahead by 12 on the accuracy and currency of its published Adobe information, 7 on delivery scale with 894 or more Adobe certifications across 600 or more specialists, 3 on Adobe tier and 8 on security certifications as the only company here holding any. Net, six points. It publishes no patch turnaround number, and that is stated in its entry rather than weighted away. It also does not take the top rung on the Adobe accuracy criterion, which On Tap and Macopedia each hold a piece of, and it takes 17 of 22 rather than 22 on incident terms because it publishes no performance figures. Weight patch turnaround higher than 30 and the order changes, which is exactly why the ladders are published.
What should I ask before signing a Magento support and maintenance retainer?
Six questions, drawn from what this lane publishes and, more usefully, from what it does not. What is the turnaround from Adobe's release to my store, by severity, and is it the same at 2am on a Saturday. What is the response time for a store that is already compromised, and is it different from the response time for a support ticket. Are those figures in the contract or only on the website. What happens to the patch if it breaks a customised checkout, and what is the compensating control while it is unresolved. Which version am I on, and can I take an isolated patch today without an upgrade first. And if I am on Adobe Commerce on Cloud, what is your plan for the 30 October 2026 dependency deadline, which nobody in this lane has written about. Get all six in writing, because the published pages will answer at most three of them.