SaaS EngineeringPublished

SaaS Development Benchmarks 2026

Engineering velocity, cost structures, and quality benchmarks from 521 SaaS companies spanning seed stage to enterprise scale.

Published March 26, 202619 min read4,800 wordsHalkwinds Research
About This Research521 SaaS companies surveyedSaaS Engineering researchPublished March 26, 2026Halkwinds Research · Annual Report 2026

Key Findings

Median SaaS product team at $10M ARR: 12 engineers, 2 product managers, 1 designer

AI-assisted development teams ship 2.4x more features per engineer per quarter

Infrastructure costs average 18% of revenue at scale (15–20% is the healthy benchmark range)

Median time from concept to first paying customer: 9.4 months for B2B SaaS in 2026

API-first architecture is now standard at 89% of SaaS companies above $5M ARR

SaaS security incidents cost average $3.2M in 2025 — up 34% from 2024

Navin Sharma — Chief Technology Officer

Written by

Navin Sharma

Chief Technology Officer

Garima Walia — Chief Executive Officer

Reviewed by

Garima Walia

Chief Executive Officer

Published March 26, 2026Updated August 8, 2026

Executive Summary

SaaS engineering in 2026 is defined by a bar-belled cost structure: teams are leaner per dollar of ARR than at any point in the last decade, even as infrastructure and security spend consume a growing, non-negotiable share of revenue.

The median SaaS product organization at $10M ARR now runs on 12 engineers, 2 product managers, and 1 designer — a ratio that has held steady even as AI-assisted development lets that same team ship 2.4x more features per engineer per quarter than in 2023.

Infrastructure spend has settled into a 15-20% of revenue benchmark band (18% average at scale), and API-first architecture — now standard at 89% of companies above $5M ARR — has become the default assumption for new SaaS builds rather than a differentiator.

Time-to-first-paying-customer (9.4 months median for B2B SaaS) and the rising cost of security incidents ($3.2M average in 2025, up 34% year over year) are now the two variables enterprise buyers and investors scrutinize most closely when evaluating SaaS engineering maturity.

This report benchmarks these dynamics across 521 SaaS companies spanning seed stage to $100M+ ARR, giving engineering leaders, CFOs, and investors an evidence-based reference point for team sizing, budget allocation, and technology strategy decisions in 2026.

01

State of the SaaS Development Market

12:2:1Median engineer:PM:designer ratio at $10M ARR
2.4xFeature throughput gain from AI-assisted development
18%Average infrastructure cost as % of revenue at scale
9.4 moMedian concept-to-first-customer timeline (B2B SaaS)

SaaS engineering entered 2026 in a genuinely different posture than it held even three years earlier. The capital-abundant era of 2019-2021 — when growth at any cost of engineering headcount was rewarded — has given way to a discipline in which every additional engineer, every infrastructure dollar, and every month to first revenue is scrutinized by boards, investors, and CFOs with the same rigor once reserved for sales efficiency metrics. At the same time, AI-assisted development has changed what a lean team can actually produce, decoupling headcount from output in a way that did not exist in prior cycles.

This report benchmarks that new reality across 521 SaaS companies spanning seed-stage startups near $1M ARR through enterprise SaaS leaders above $100M ARR. The headline pattern is not that teams have gotten dramatically smaller — the median product team at $10M ARR still runs 12 engineers, 2 product managers, and 1 designer — but that the same team now ships materially more. AI-assisted development teams in this sample shipped 2.4x more features per engineer per quarter than teams without structured AI tooling adoption, and companies appear to be reinvesting that productivity gain into roadmap scope and competitive speed rather than headcount reduction.

Cost structure has stabilized around a set of benchmarks that now function as an industry consensus: infrastructure spend in the 15-20% of revenue range (18% average at scale), API-first architecture as the default rather than the exception (89% of companies above $5M ARR), and a median 9.4-month path from concept to first paying customer for B2B SaaS. The one benchmark moving in the wrong direction is security: the average cost of a SaaS security incident reached $3.2M in 2025, up 34% from 2024 — a trend line that this report treats as inseparable from the velocity gains AI-assisted development has unlocked.

Taken together, these figures describe a market in which the primary competitive axis is no longer 'can you build it' but 'how efficiently, how securely, and how fast can you get it in front of a paying customer.' The sections that follow break each of these dimensions down by stage, region, and vertical.

The competitive question in SaaS engineering is no longer whether you can build it — it's how efficiently, how securely, and how fast you can get it to a paying customer.

Halkwinds Research
  • 521 SaaS companies benchmarked, from $1M ARR seed stage to $100M+ ARR enterprise leaders
  • Engineering headcount ratios have held steady even as AI tooling substantially increased per-engineer output
  • Security incident cost is the one benchmark trending unfavorably, up 34% year over year
02

Research Methodology

Research Documentation

This report is based on primary research conducted by Halkwinds Research between August 2025 and February 2026. The core dataset comprises structured survey responses and, where available, publicly verifiable engineering metrics from 521 SaaS companies. Respondents included CTOs, VPs of Engineering, heads of product, and finance leaders at companies ranging from pre-Series A seed-stage startups (under $1M ARR) to enterprise SaaS providers exceeding $100M in annual recurring revenue. The sample skews toward North America (47%) and Europe (29%), with Asia-Pacific (18%) and the rest of world (6%) making up the remainder — a distribution disclosed transparently because it shapes how representative regional conclusions in this report should be read.

Point estimates in this report carry a ±4 percentage point margin of error at a 95% confidence level across the full sample. Vertical and stage-specific subsamples — for example, healthtech SaaS or sub-$1M-ARR companies — carry wider margins of error, typically ±6 to ±9 percentage points, reflecting smaller cell sizes. No survey respondent was a Halkwinds client, and no compensation was provided for participation, consistent with the independent research standard Halkwinds applies across its Research Hub.

This report applies three explicit attribution tiers, and every statistic in the sections that follow is labeled according to one of them. First, Halkwinds Research data: figures derived directly from the 521-company survey sample, presented as Halkwinds Research estimates. Second, verified third-party data: figures attributed by name to an external research organization (Gartner, IDC, McKinsey, Forrester, Deloitte, DORA/Google Cloud's State of DevOps research, OWASP, or government/regulatory sources) — these are never restated as Halkwinds' own findings. Third, expert analysis: interpretive commentary, causal reasoning, or forward-looking recommendations, which is explicitly framed as analysis rather than as measured data. Readers should treat any unattributed specific number in this report as a data-entry error and are encouraged to consult research@halkwinds.com for the underlying source.

Survey design followed established B2B primary research protocols, including double-blind company identification during data collection and independent cross-referencing of self-reported figures — team size, deployment frequency, ARR band — against publicly available data such as job postings, funding disclosures, and public engineering blogs where available, to reduce reliance on unverified self-report alone.

  • Sample: 521 SaaS companies, seed stage ($1M ARR) through enterprise ($100M+ ARR)
  • Field window: August 2025 - February 2026
  • Margin of error: ±4 points full sample; ±6 to ±9 points for subsamples
  • Three-tier attribution: Halkwinds Research data, verified third-party data (named), and expert analysis (labeled as interpretation)
03

Current Market Landscape

$5M-$25MARR band with highest API-first adoption growth (74%→89%)
76%Sample concentration in North America + Europe

The global SaaS market has moved past its hypergrowth-at-any-cost phase into what industry analysts broadly describe as a consolidation and efficiency phase. Gartner has forecast continued double-digit growth in worldwide SaaS end-user spending through the medium term, even as growth rates in the broader public cloud market moderate from the peaks of the early 2020s. IDC's public commentary on the software market points to a similar pattern: overall SaaS spending continues to expand, but the mix is shifting decisively toward AI-native product categories and vertical, industry-specific SaaS rather than generic horizontal tooling.

Structurally, three forces are driving this market today. First, buyer procurement has matured — enterprise buyers increasingly demand security certifications, uptime guarantees, and integration depth before signing, which raises the bar (and cost) of reaching enterprise-ready product maturity, a dynamic reflected in this report's 9.4-month median time-to-first-customer figure. Second, the compute and tooling layer has commoditized: managed Kubernetes, serverless platforms, and AI coding assistants have lowered the marginal cost of building well-architected software, which is a major contributor to the 2.4x feature-throughput gain documented in this report. Third, capital discipline imposed by the 2022-2023 funding contraction has persisted structurally even as funding markets have partially recovered — investors continue to underwrite SaaS growth against efficiency benchmarks like the infrastructure-cost-to-revenue ratios detailed later in this report, not growth alone.

Within this landscape, the 521 companies in this benchmark sample cluster into recognizable cohorts: early-stage companies still finding product-market fit and running lean, capital-efficient engineering organizations; growth-stage companies ($10M-$50M ARR) investing heavily in platform engineering and API surface area to support partner ecosystems; and enterprise-scale SaaS providers ($50M+ ARR) whose engineering organizations increasingly resemble those of the enterprise software vendors they compete against, with dedicated security, compliance, and platform teams.

One structural driver deserves particular emphasis: AI-assisted development is not just a productivity tool inside these companies — it is reshaping the competitive landscape itself, compressing the time advantage that well-funded incumbents once held over smaller, faster-moving challengers. A well-architected two-person engineering team in 2026 can credibly compete on shipping velocity with teams several times its size from five years ago, which is reshaping how investors and enterprise buyers evaluate SaaS vendors of every size.

04

Historical Timeline: How SaaS Engineering Evolved

The engineering practices benchmarked in this report did not emerge overnight; they are the product of roughly fifteen years of iterative architectural and organizational evolution. Understanding that arc helps explain why today's benchmarks look the way they do, and which of today's practices are likely to prove durable versus transitional.

2010-2015 marked the emergence of modern multi-tenant SaaS architecture as the default assumption for new B2B software, replacing on-premise and single-tenant hosted deployment models. This period established core patterns — shared infrastructure with tenant isolation, subscription billing, and continuous deployment — that remain foundational today. 2016-2020 was the API economy and product-led growth (PLG) era: companies like Stripe, Twilio, and Slack popularized API-first design as a growth lever rather than purely a technical decision, and self-serve, usage-based adoption models began challenging traditional enterprise sales motions.

2021-2023 was defined by a capital reckoning. The venture funding contraction that began in late 2021 forced a wholesale reassessment of SaaS unit economics — infrastructure cost as a percentage of revenue, engineer productivity, and burn multiples became board-level metrics almost overnight, and many companies that had scaled engineering headcount aggressively during the 2019-2021 period undertook painful restructuring. This period is the direct precursor to the cost-discipline benchmarks (15-20% infrastructure-to-revenue range, lean team ratios) documented throughout this report.

2024-2026 has been the AI-assisted engineering inflection point. The maturation of AI coding assistants from autocomplete tools into genuine collaborators capable of scaffolding features, writing tests, and reviewing code has produced the productivity step-change reflected in the 2.4x feature-throughput figure — a shift comparable in magnitude, though different in kind, to the cloud infrastructure transition of the early 2010s. Where that transition changed how software was deployed, this one is changing how it is written.

  • 2010-2015: Multi-tenant SaaS architecture becomes the default deployment model
  • 2016-2020: API economy and product-led growth reshape go-to-market and architecture together
  • 2021-2023: Capital contraction forces cost-efficiency discipline into engineering organizations
  • 2024-2026: AI-assisted development produces a step-change in per-engineer feature throughput
06

Regional Analysis

47%North America share of sample
29%Europe share of sample
18%Asia-Pacific share of sample
6%Rest of world share of sample

North America, representing 47% of this report's sample, remains the largest and most mature SaaS engineering market, characterized by the highest concentration of companies above $50M ARR and the deepest adoption of platform engineering practices. North American companies in this sample also reported the highest average infrastructure spend in absolute terms, though not necessarily as a percentage of revenue, reflecting both scale and a greater propensity to run multi-region infrastructure for enterprise customers with data residency requirements.

Europe, at 29% of the sample, shows a distinct regulatory-driven engineering profile. GDPR and the broader European data protection framework have made data residency, consent management, and audit-trail infrastructure default architectural requirements rather than add-ons, and this report's data suggests European SaaS companies build these capabilities earlier in their lifecycle than their North American counterparts, sometimes at the cost of slightly slower time-to-first-customer figures in regulated verticals. The EU AI Act's phased implementation is beginning to add a comparable governance layer for companies building AI-powered SaaS features.

Asia-Pacific, at 18% of the sample, reported the fastest year-over-year growth in engineering headcount and AI tooling adoption of any region in this study, driven by strong domestic SaaS markets in India, Southeast Asia, and Australia. APAC companies in this sample also showed the highest rate of API-first adoption relative to their revenue stage, suggesting that later-market entrants are able to adopt current best practices from day one rather than migrating toward them, an advantage of being a relatively later entrant into a now-mature architectural consensus.

The remaining 6% of the sample — Latin America, the Middle East, and Africa — is too small in this dataset to support high-confidence regional conclusions, and Halkwinds treats findings from this subsample as directional rather than statistically robust. Anecdotally, companies in these markets reported the highest reliance on distributed, cross-border engineering talent models, a pattern consistent with broader industry commentary on the globalization of software engineering talent pools.

07

Industry Analysis: SaaS Sub-Verticals

SaaS is not a single market with uniform engineering economics — it is a collection of sub-verticals with meaningfully different cost structures, compliance burdens, and time-to-market profiles. This report's sample spans horizontal product-led SaaS, vertical B2B SaaS (fintech, healthtech, legal tech, and similar industry-specific categories), and infrastructure/developer-tooling SaaS, and the differences between them are large enough that a single overall benchmark can be misleading if applied uncritically to a specific vertical.

Horizontal, product-led SaaS — tools built for a broad market and sold through self-serve or low-touch motions — shows the fastest time-to-first-customer in this sample (6.8 months median) and the leanest infrastructure cost ratios, reflecting simpler compliance requirements and more standardized architecture patterns. These companies tend to over-index on API-first design early, since integration into a buyer's existing tool stack is itself part of the value proposition.

Vertical B2B SaaS built for regulated or high-compliance industries — fintech and healthtech chief among them — shows materially longer time-to-first-customer (11.2 and 13.5 months respectively) and higher relative infrastructure and compliance costs, but also commands premium pricing and typically lower customer churn once acquired. Halkwinds' work building platforms like AtlasIQ (enterprise revenue and financial intelligence) and CareAxis (healthcare AI) reflects this pattern directly: the engineering investment required to reach production-grade compliance in these verticals is front-loaded, but the resulting product tends to be far stickier.

Infrastructure and developer-tooling SaaS — companies building for other engineering teams rather than end business users — occupies a distinct middle ground: these companies typically show the highest internal engineering sophistication (unsurprising, given their customer base is other engineers) and the earliest adoption of practices like platform engineering and daily deployment cadence, effectively acting as leading indicators for practices that later diffuse into horizontal and vertical SaaS more broadly.

Fintech and Healthtech SaaS: The Compliance Premium

Fintech and healthtech SaaS companies in this sample report the longest sales and implementation cycles but also the highest gross margins once contracts are signed, reflecting a compliance investment that acts as both a cost center and a competitive moat against less-regulated entrants.

Case work from Halkwinds' AtlasIQ platform deployments illustrates this pattern in financial services specifically: engineering investment in auditability and regulatory reporting infrastructure, while expensive up front, becomes a durable differentiator against competitors unwilling to make the same investment.

Vertical vs. Horizontal SaaS Growth Dynamics

This report's data is consistent with a broader industry narrative — echoed in commentary from firms like McKinsey — that vertical, industry-specific SaaS is capturing a growing share of new SaaS investment relative to horizontal tooling, as AI-native features become easier to price and justify when scoped to a specific, high-value professional workflow rather than a generic productivity use case.

08

Technology Analysis: Architecture and Stack

89%API-first adoption above $5M ARR
62%Companies deploying at least daily

The dominant architectural pattern in this report's sample is not a single technology stack but a maturity curve: early-stage companies (under $5M ARR) predominantly run a modular monolith — a single deployable codebase organized into clearly bounded internal modules — which minimizes operational overhead while team size and product surface area are still small. The transition toward microservices or a broader service-oriented architecture typically begins once a company needs independent team scaling, isolated failure domains, or materially different scaling profiles across product areas, most commonly somewhere between $10M and $50M ARR in this sample.

API-first design, standard at 89% of companies above $5M ARR, has become the connective tissue of this architecture regardless of where a company sits on the monolith-to-microservices spectrum: internal modules and external partner integrations alike are increasingly built against the same well-documented, versioned API surface, reducing the cost of eventually decomposing a monolith and simplifying partner and customer integrations in the meantime.

Cloud-native infrastructure — containerized workloads on managed Kubernetes, serverless functions for event-driven workloads, and managed database and streaming services — is now the default assumption across the sample regardless of company stage, though the sophistication of usage (multi-region deployment, blue-green releases, infrastructure-as-code discipline) increases materially with scale. Observability tooling — structured logging, distributed tracing, and real-time alerting — has similarly become table stakes rather than a mature-company luxury, driven in part by the need to maintain reliability at the accelerated deployment cadence documented in the Global Trends section.

AI coding assistants and agentic development tools are now embedded directly into the engineering workflow of the large majority of companies in this sample, not run as a side experiment. The most sophisticated organizations in this study have moved beyond individual developer productivity tools toward AI-assisted code review, automated test generation, and — in a smaller but growing subset — agentic handling of well-scoped maintenance tickets, a pattern consistent with Halkwinds' broader research on enterprise AI adoption and agentic system deployment.

AI Coding Assistants: From Autocomplete to Collaborator

The productivity gains documented in this report are concentrated in specific task categories: code generation for well-specified features, test writing, and code review assistance show the largest measured gains, consistent with McKinsey's public research on generative AI in software engineering, which similarly finds the largest gains concentrated in well-scoped, pattern-based coding tasks rather than novel architectural or product-design work.

Companies in this sample that report the highest feature-throughput gains are not simply the heaviest users of AI coding tools — they are the ones that paired AI tool adoption with updated code review and testing practices designed specifically to catch the failure modes unique to AI-generated code, a pattern this report treats as central to translating raw AI productivity potential into safely shippable output.

09

Cost Analysis: Budgets, TCO, and Benchmarks

18%Average infrastructure cost as % of revenue at scale
$3.2MAverage cost of a SaaS security incident, 2025
32%Engineering payroll as % of revenue at $10M ARR

Infrastructure cost as a percentage of revenue is the single most closely watched efficiency metric in this report's sample, and it follows a clear pattern across company stage: roughly 27% of revenue for companies under $5M ARR, declining to the 15-20% healthy benchmark range (18% average) by the time companies reach $25M-$100M+ ARR. The decline reflects a combination of committed-use cloud discounting becoming available at higher spend tiers, architectural maturity reducing waste, and fixed platform costs being amortized across a larger revenue base — not simply a mechanical function of scale.

Total cost of ownership for a SaaS engineering organization at the $10M ARR stage, per this report's revenue-allocation model, breaks down roughly as follows: engineering payroll represents approximately 32% of revenue, infrastructure approximately 18%, sales and marketing approximately 28%, and general and administrative costs approximately 10%, leaving a typical low-double-digit operating margin at this stage. This allocation shifts meaningfully with scale: infrastructure's share tends to compress modestly while security, compliance, and platform-engineering-specific line items — often invisible in earlier-stage cost models — become explicit budget categories.

Security is increasingly a first-class cost category rather than a rounding error inside the broader infrastructure or engineering budget. The average cost of a SaaS security incident reached $3.2M in 2025, a figure that includes breach response, customer notification, regulatory penalties where applicable, and the harder-to-quantify cost of customer churn following disclosure. This 34% year-over-year increase means that proactive security investment — penetration testing, security tooling, and dedicated security engineering headcount — increasingly pencils out favorably against expected incident cost even before accounting for the reputational and customer-trust dimensions of a breach.

Cost benchmarking also varies meaningfully by go-to-market motion: usage-based and hybrid pricing models require metering, real-time billing, and granular entitlement infrastructure that adds a distinct and growing cost line relative to simpler seat-based subscription billing — a cost that this report's data suggests is frequently underestimated in early-stage financial models.

Security has stopped being a line item inside the infrastructure budget and become a budget category of its own — and the companies treating it that way are the ones avoiding the $3.2M average incident cost.

Halkwinds Research

Cost Structure by ARR Stage

Seed-stage companies (under $1M ARR) in this sample typically run the leanest absolute engineering budgets but the highest infrastructure cost ratios relative to revenue, since fixed platform costs are spread across a very small revenue base. Growth-stage companies ($10M-$50M ARR) show the most balanced cost structure across categories and the fastest-improving infrastructure efficiency. Enterprise-scale companies ($50M+ ARR) show infrastructure costs stabilizing around the 17-18% mark but see new cost categories — dedicated security teams, compliance certification maintenance, and platform engineering headcount — become explicit and material budget lines.

10

Benefits: Quantified Gains from Modern SaaS Engineering Practice

The clearest quantified benefit in this report is engineering productivity: AI-assisted development teams shipped 2.4x more features per engineer per quarter than teams without structured AI tooling adoption. Applied at the median team size of 12 engineers, this translates into roadmap capacity that would previously have required a substantially larger team — capacity companies in this sample are using primarily to compete on speed and product scope rather than to reduce headcount.

API-first architecture delivers a compounding benefit that is harder to quantify in a single number but shows up throughout this report's data: companies with mature API-first practices report faster partner integration timelines, lower cost to build and maintain mobile and third-party clients, and — because 89% of companies above $5M ARR have already adopted this pattern — a lower relative cost of interoperating with the broader SaaS ecosystem their customers already use.

Infrastructure cost discipline, once achieved, compounds favorably: companies that reach the 15-20% of revenue benchmark range free up capital for engineering headcount, go-to-market investment, or margin expansion, whichever the business prioritizes. This report's Halkwinds Research analysis suggests companies that hit this benchmark range earlier in their growth trajectory — rather than only after a forced cost-cutting exercise — retain more optionality in how they deploy the resulting capital.

Finally, security investment shows a clear, if harder to isolate, benefit: while this report cannot claim a precise ROI figure for security spend without over-stating causality, the scale of the $3.2M average incident cost relative to typical security program budgets in this sample strongly suggests that proactive investment is the economically rational choice for the large majority of companies represented here, independent of the reputational and customer-trust benefits that are harder to price directly.

  • 2.4x feature throughput gain reinvested into roadmap scope, not primarily headcount reduction
  • API-first architecture reduces partner integration and multi-client development cost
  • Reaching the 15-20% infrastructure cost benchmark earlier preserves capital optionality
  • Proactive security investment appears economically favorable against average incident cost
11

Challenges: Implementation Barriers

The most commonly cited challenge in this report's sample is not a technology gap but an organizational one: integrating AI-assisted development into existing code review, testing, and quality-assurance processes without either slowing teams down with excessive caution or exposing the organization to the failure modes unique to AI-generated code — subtly incorrect logic, security anti-patterns, or plausible-but-wrong implementations that pass a superficial review. Companies in this sample that struggled most with AI tooling adoption were disproportionately those that treated it as a drop-in productivity tool rather than a practice requiring updated engineering process.

Technical debt management is a related and growing challenge: the same velocity that lets teams ship 2.4x more features can, without disciplined architectural oversight, produce a proportional increase in accumulated complexity and inconsistent patterns across a codebase, particularly when multiple engineers are using AI assistance with different prompting habits and review standards. Several companies in this sample explicitly cited a need for stronger internal architectural review processes specifically because of, not despite, AI-assisted development.

Talent and organizational design present a second category of challenge. As infrastructure cost ratios stabilize and teams stay lean relative to output, companies report growing difficulty attracting and retaining senior engineers who can operate effectively at this pace — the skill set required (strong architectural judgment, comfort directing and reviewing AI-assisted work, and platform engineering fluency) is scarcer than the skill set required for traditional feature-team engineering roles.

Integration complexity is the third recurring challenge, particularly for companies adopting API-first and platform engineering practices later than their peers: retrofitting a well-documented, versioned API surface onto a codebase originally built without one is materially more expensive than building API-first from the start, and several companies in this sample cited this retrofit cost as a multi-quarter engineering distraction from new feature work.

  • Integrating AI-assisted development into review and QA processes without introducing new risk categories
  • Managing technical debt and architectural consistency at higher shipping velocity
  • Attracting and retaining senior engineers with the judgment to direct and review AI-assisted work
  • Retrofitting API-first architecture onto codebases not originally built with it
12

Risks: Security, Compliance, and Vendor Exposure

Security risk is the most quantified risk category in this report: the average cost of a SaaS security incident reached $3.2M in 2025, up 34% from 2024. This report's analysis attributes the increase to a combination of factors — a broader attack surface created by proliferating third-party API integrations, compressed development timelines that in some cases outpaced security review capacity, and rising regulatory penalties tied to frameworks like GDPR and an expanding set of US state-level privacy laws. OWASP's API Security Top 10 remains a widely referenced external framework for the specific vulnerability classes most relevant to API-first SaaS architectures.

Compliance risk compounds this picture, particularly for vertical B2B SaaS companies serving regulated industries. Healthtech SaaS companies face HIPAA and, increasingly, state-level health data privacy requirements; fintech SaaS companies face a patchwork of financial services regulation that varies significantly by jurisdiction and product type; and companies building AI-powered features across any vertical face the EU AI Act's phased compliance requirements as they come into full effect. Compliance failures in this sample were disproportionately associated with companies that treated certification (SOC 2, ISO 27001) as a one-time sales-enablement project rather than an ongoing operational discipline.

Vendor and infrastructure concentration risk is a less visible but structurally important risk category: the large majority of companies in this sample run on a small number of hyperscale cloud providers, and an outage, pricing change, or policy shift at any one of these providers represents a systemic risk shared across a large share of the SaaS industry simultaneously. Multi-cloud and cloud-agnostic architecture strategies remain the exception rather than the rule in this sample, largely because the operational complexity cost is judged by most companies to outweigh the concentration-risk benefit below a certain scale.

A newer risk category specific to this report's period is AI-generated code and model risk: as a growing share of production code is AI-assisted or AI-generated, companies face emerging questions around intellectual property provenance, subtle correctness failures that evade traditional testing patterns, and — for companies embedding third-party AI models directly into their product — dependency on the security and reliability posture of model providers outside their direct control. This report treats AI-governance maturity as a leading indicator worth monitoring closely over the next several benchmark cycles.

  • Security incident cost up 34% year over year to $3.2M average in 2025 (Halkwinds Research estimate)
  • Compliance risk concentrated in vertical B2B SaaS serving regulated industries (healthtech, fintech)
  • Vendor/cloud-provider concentration risk remains structurally under-addressed across the sample
  • AI-generated code introduces new categories of correctness, IP, and model-dependency risk
13

Future Outlook: 2026-2030

Over the next four years, this report's analysis expects the productivity gains from AI-assisted development to broaden from individual developer tooling toward more autonomous, agentic handling of well-defined engineering work — bug triage, dependency updates, test maintenance, and eventually well-scoped feature implementation with human oversight at the review and architecture-decision stage rather than the line-of-code stage. Halkwinds' related research on enterprise AI adoption projects AI agents becoming a primary interface for routine workflows across enterprise software more broadly by 2028, a trend this report expects to be at least as pronounced inside SaaS engineering organizations themselves as in the products they build.

Infrastructure cost ratios are likely to remain roughly stable in the 15-20% band rather than continuing to decline meaningfully, as savings from architectural maturity and committed-use discounting are increasingly offset by new cost categories: AI inference costs for AI-native product features, expanded observability and security tooling, and compliance infrastructure for an expanding set of regulatory frameworks. Companies that assume infrastructure costs will continue trending toward zero as a share of revenue are, in this report's analysis, likely to be surprised by these offsetting cost pressures.

Security and compliance investment will very likely continue rising as a proportion of engineering budgets, both because incident costs are rising (this report's $3.2M average, up 34% year over year, shows no clear sign of plateauing) and because regulatory frameworks — the EU AI Act, an expanding set of US state privacy laws, and sector-specific frameworks in healthcare and financial services — are adding compliance surface area rather than reducing it. This report's analysis expects dedicated security and compliance engineering roles to become standard even at earlier-stage companies than is currently typical.

Finally, the boundary between vertical and horizontal SaaS is likely to blur further as AI-native features make it commercially viable to build deeply specialized functionality for narrower and narrower customer segments, a trend consistent with the industry-wide shift toward vertical SaaS investment noted in the Industry Analysis section. Halkwinds expects this report's benchmark figures — team composition ratios, infrastructure cost bands, and time-to-market timelines — to remain directionally stable through 2030 even as the underlying technology stack continues to evolve, because they are ultimately governed more by organizational and go-to-market dynamics than by any single technology choice.

  • Agentic AI handling of well-scoped engineering work expected to broaden significantly by 2028
  • Infrastructure cost ratios likely to stabilize near current levels rather than continue declining
  • Security and compliance investment set to keep rising as a share of engineering budgets
  • Vertical and horizontal SaaS boundaries expected to blur further as AI-native features narrow addressable segments profitably
14

Enterprise Recommendations

Enterprise SaaS providers (above $50M ARR) should treat this report's infrastructure cost benchmark (15-20% of revenue, 18% average) as a governance metric reviewed at the same board cadence as customer acquisition cost or net revenue retention, not solely as an engineering-team KPI. Material deviation from this range in either direction — overspend that signals architectural inefficiency, or underspend that may signal deferred reliability or security investment — warrants explicit board-level discussion.

Given the $3.2M average cost of a security incident and its 34% year-over-year increase, enterprise organizations should formalize security and compliance as a dedicated engineering discipline with its own headcount, budget line, and executive sponsor, rather than a responsibility distributed across product engineering teams as a secondary concern. This includes treating AI-generated code review and governance as an explicit extension of existing security practice, not a separate initiative.

Enterprises should audit their AI-assisted development adoption against the 2.4x feature-throughput benchmark documented in this report: organizations significantly below this figure despite meaningful AI tool licensing spend likely have a process or governance gap — insufficient integration of AI tooling into code review and testing workflows — rather than a tooling gap, and should prioritize process investment over additional tool procurement.

Finally, enterprise SaaS providers should use this report's regional analysis to inform where they invest in localized compliance and data-residency infrastructure, particularly given the EU AI Act's phased implementation and the continued expansion of US state-level privacy law — treating this as a proactive architectural investment rather than a reactive response to individual enterprise customer requirements as they arise.

  • Treat the 15-20% infrastructure cost benchmark as a board-level governance metric
  • Formalize security and compliance as a dedicated discipline with executive sponsorship
  • Audit AI-assisted development ROI against the 2.4x benchmark to find process, not tooling, gaps
  • Invest proactively in regional compliance and data-residency infrastructure ahead of enterprise deal requirements
15

SME Recommendations

Growth-stage SaaS companies ($10M-$50M ARR) sit at the inflection point where this report's data shows the most rapid change in cost structure and architecture maturity, making this the highest-leverage stage to make deliberate rather than reactive decisions. Companies at this stage should benchmark their team composition against the 12:2:1 engineer-to-PM-to-designer ratio documented in this report, using material deviations as a prompt to investigate roadmap throughput or design-quality issues rather than treating headcount planning as purely a budget exercise.

Given that API-first adoption climbs from 74% to 89% precisely across this ARR band, growth-stage companies still running without a well-documented, versioned API surface should prioritize this investment now rather than later — this report's data suggests the cost of retrofitting API-first architecture rises, not falls, the longer it is deferred, as more of the codebase and more external integrations accumulate around the absence of a clean API boundary.

This is also the stage at which companies should make a deliberate, not accidental, decision about microservices decomposition. This report's data shows the shift away from a modular monolith typically happening somewhere in this ARR band, but the decision should be driven by a specific, identified need — independent team scaling, isolated failure domains, differentiated scaling profiles across product areas — rather than by architectural fashion, given the meaningful operational overhead microservices introduce.

Finally, growth-stage companies should treat this report's infrastructure cost decline curve (from roughly 22% down toward 18-19% across this band) as an efficiency target to actively pursue through committed-use discounting and architectural cleanup, rather than an outcome that occurs automatically with scale — several companies in this sample that failed to capture this efficiency gain cited a lack of dedicated ownership over infrastructure cost as the root cause.

  • Benchmark team composition against the 12:2:1 ratio at the $10M ARR milestone
  • Prioritize API-first architecture investment now — retrofit cost rises the longer it is deferred
  • Make microservices decomposition a deliberate decision tied to a specific scaling need, not architectural fashion
  • Actively pursue infrastructure cost efficiency rather than assuming it follows automatically from scale
16

Startup Recommendations

Seed-stage SaaS startups (under $1M ARR) should expect and budget for infrastructure costs materially above the 18% average benchmark — roughly 27% of revenue in this report's sample — since fixed platform costs are spread across a very small revenue base at this stage; this is a normal, temporary pattern rather than a red flag, and founders should avoid over-correcting toward premature infrastructure cost optimization at the expense of shipping speed.

Given the 6.8-month median time-to-first-customer for horizontal, product-led SaaS versus 11-14 months for regulated verticals in this report's sample, founders building in fintech or healthtech should set realistic fundraising and runway expectations around the longer compliance-driven timeline from day one, rather than benchmarking against horizontal SaaS peers whose path to first revenue is structurally faster.

Early-stage companies should adopt AI-assisted development practices deliberately and early — this report's data suggests the 2.4x productivity benchmark is achievable at small team sizes, potentially the single highest-leverage lever available to a resource-constrained founding engineering team — but should pair this adoption with disciplined code review practice from the outset, rather than retrofitting review rigor after the codebase has grown large enough for AI-generated inconsistencies to become costly.

Finally, startups should resist the temptation to over-architect early: this report's data confirms that the modular monolith remains the dominant, and appropriate, pattern below $5M ARR, and that API-first design — which can and should be adopted from day one regardless of company size — delivers most of the integration and partnership benefits of a more complex microservices architecture without its operational overhead.

  • Expect infrastructure costs materially above the 18% benchmark at seed stage — this is normal, not a red flag
  • Set fundraising and runway expectations around vertical-specific time-to-first-customer, not horizontal SaaS benchmarks
  • Adopt AI-assisted development early, paired with disciplined code review from day one
  • Favor a modular monolith with API-first design over premature microservices decomposition
17

References and External Sources

The figures and analysis in this report draw on two categories of sources: Halkwinds Research's own 521-company primary research (detailed in the Methodology section) and publicly available research and commentary from independent third-party organizations, cited by name wherever referenced. The sources below are external, verified third-party research organizations and are not Halkwinds data — they are listed here for transparency and so readers can consult the original source material directly.

This report also draws on Halkwinds' own related primary research, listed separately, which readers can use to cross-reference adjacent findings on enterprise AI adoption and software engineering productivity more broadly.

  • Gartner — public market research and forecasts on worldwide SaaS and public cloud end-user spending
  • IDC — software and SaaS market sizing and growth-rate commentary
  • McKinsey & Company / McKinsey Global Institute — published research on generative AI's impact on software engineering productivity
  • Forrester — industry commentary on platform engineering and internal developer platform adoption
  • Deloitte — enterprise technology budget and digital transformation research
  • DORA (DevOps Research and Assessment) / Google Cloud — State of DevOps research on deployment frequency and engineering performance tiers
  • OWASP — API Security Top 10 framework, referenced for SaaS API vulnerability classes
  • EU AI Act and GDPR — referenced as regulatory sources for AI governance and data protection compliance requirements
  • Halkwinds Research — Enterprise AI Adoption Trends 2026 (related primary research, /research/enterprise-ai-adoption-trends-2026)
  • Halkwinds Research — Software Engineering Productivity Benchmark Report 2026 (related primary research, /research/software-engineering-productivity-benchmark-report-2026)
18

About Halkwinds

Halkwinds is an AI-first software engineering company that designs, builds, and scales SaaS products and enterprise technology platforms for organizations ranging from early-stage startups to Fortune 500 enterprises. Our engineering teams work across application development, cloud architecture, AI/ML engineering, and data platforms — the same disciplines benchmarked throughout this report. Our own product portfolio, including AtlasIQ (enterprise revenue and financial intelligence), CareAxis (healthcare AI), and AstraFi (institutional DeFi infrastructure), reflects the same team-composition, infrastructure-efficiency, and API-first architecture principles this report identifies as industry benchmarks.

This research reflects Halkwinds' commitment to building a public knowledge commons for SaaS engineering leaders, investors, and operators — data and analysis practitioners can rely on, cite, and use to make better team-structure, budget, and technology investment decisions. For partnership inquiries, research access, or SaaS engineering consulting, contact us at research@halkwinds.com.

Downloadable Resources

SaaS Development Benchmarks 2026 — Full Report (PDF)

pdf

The complete 521-company benchmark dataset with methodology appendix, in a downloadable format for board and investor presentations.

SaaS development cost breakdown Custom software vs SaaS decision guide

SaaS Engineering Team Scaling Checklist

checklist

A stage-by-stage checklist for structuring engineering, product, and design headcount from seed stage through $100M+ ARR, aligned to this report's team-composition benchmarks.

Application development services Dedicated team vs staff augmentation

SaaS Infrastructure Cost Health Scorecard

scorecard

A self-assessment scorecard to benchmark your infrastructure spend against the 15-20% of revenue healthy range identified in this report, with remediation guidance for outliers.

SaaS development cost breakdown Microservices architecture cost guide

AI-Assisted Engineering Adoption Roadmap

roadmap

A 12-month roadmap template for introducing AI-assisted development practices into an existing SaaS engineering organization without disrupting delivery velocity.

AI and machine learning for SaaS Nexora AI workflow operating system

Related Halkwinds Content

Frequently Asked Questions

Halkwinds Research benchmarking across 521 SaaS companies finds a median product team of 12 engineers, 2 product managers, and 1 designer at the $10M ARR milestone. This ratio has remained stable even as AI-assisted development has increased per-engineer output, suggesting companies are reinvesting productivity gains into faster roadmaps rather than smaller teams.

Where does your organisation stand?

The Halkwinds AI Ascent Model™ helps enterprise technology leaders benchmark their AI maturity across five levels — from first production deployment to compounding competitive advantage.

Research Library

Related Research Reports

Developer Productivity27 min

Software Engineering Productivity Benchmark Report 2026

Every engineering organization now tracks some form of productivity metric, and nearly all of them are experimenting with AI-assisted development — yet the relationship between AI adoption, developer experience, and actual delivery performance is far messier than headline productivity claims suggest. This report benchmarks DORA and SPACE metrics, AI coding assistant ROI, developer experience investment, and enterprise delivery performance across 758 engineering organizations, and maps what separates teams that convert AI tooling into measurable throughput from teams that convert it into more code review debt.

Read report
Enterprise AI24 min

Enterprise AI Adoption Trends 2026

Enterprise AI has crossed the operational threshold. Seventy-two percent of Fortune 500 organizations now run at least one AI system in production — and the average enterprise manages 3.4 concurrent AI initiatives. This report maps the state of enterprise AI across healthcare, manufacturing, financial services, retail, and beyond.

Read report
AI Agents21 min

AI Agent Adoption Report 2026

AI agents are the most transformative enterprise technology category of the 2025–2026 cycle. This dedicated report examines architecture patterns, deployment economics, governance approaches, and the emerging multi-agent production landscape across 634 organizations — the most comprehensive agent-specific enterprise research available.

Read report
Cloud18 min

Enterprise Cloud Cost Benchmark Report 2026

Enterprise cloud spend reached $780 billion globally in 2025 — yet 32% remains unoptimised waste according to our benchmark data. This report quantifies cloud cost maturity across AWS, Azure, and GCP, mapping FinOps practice adoption, reserved capacity utilisation, and savings plan optimisation against peer benchmarks.

Read report
Halkwinds Authority Graph — relationships are tag-driven and automatically updated

Take Action on These Insights

AI Automation Discovery Call

Startup workflow automation scoping

AI Automation Discovery Call