What's the real total cost of ownership difference between self-hosted Adobe Commerce and Shopify Plus once hosting, security, and PCI compliance are included?

Shopify Plus costs $2,500 per month on a one-year term and $2,300 on a three-year term (Shopify, September 2026). Adobe publishes no equivalent figure for Adobe Commerce, so no honest total-cost difference exists as a single number. The comparable figure is a three-year total including hosting, security patching labor, PCI scope and one forced version upgrade.

Start with the refusal, because it is the finding

There is no published Adobe Commerce license price. Adobe's product pages carry no tiers and no GMV bands, and every pricing route ends at "Get started" or "Book a demo" (verified on business.adobe.com, September 2026). Any article that hands you an Adobe-versus-Shopify TCO delta as a single number built the Adobe half from somebody's leaked contract.

So this page does not give you the number. It gives you the eight lines the number is made of, and the two lines that dominate it.

The eight lines

LineShopify PlusSelf-hosted Adobe Commerce
Platform license$2,500/mo on a 1-year term, $2,300/mo on a 3-year term; main store plus 9 expansion stores, additional stores $300/mo (Shopify, Sep 2026)Unpublished. Quote-only
Hosting and infrastructureIncludedYours. On Adobe's own cloud instead, Fastly CDN and WAF are "included... at no additional cost" and the WAF is "available on Pro and Starter Production environments only" (Adobe, Sep 2026)
CDN and WAFIncludedYours, when self-hosted
APM and monitoringShopify's own reportingNew Relic APM is included on Adobe's cloud Staging and Production; self-hosted, you buy it
Security patchingShopify's responsibilityYours. Adobe's shared-responsibility model puts "Applying security and other patches to their custom Adobe Commerce... solution immediately following their release by Adobe" on the merchant (Adobe, Sep 2026)
Extension patchingApp vendors ship to the Shopify App StoreYours, for "all custom extensions and code" (Adobe, Sep 2026)
PCI"Shopify is certified Level 1 PCI DSS compliant" and compliance "extends by default to all stores powered by Shopify" (Shopify, Sep 2026)Adobe maintains "PCI certification for the infrastructure and services"; "Merchants are responsible for the compliance of their custom code, system and network processes, and organization," and for "Running PCI ASV scans" (Adobe, Sep 2026)
Version upgradesContinuous, vendor-sideA funded project on a three-year clock
Third-party payment processing0.20% per transaction on Plus when not using Shopify PaymentsGateway's own terms

The two lines that dominate

One: the upgrade clock. Adobe's software lifecycle policy gives "a three-year standard support window from the General Availability (GA) date for each version." Published end-of-support dates as of September 2026: 2.4.6 on 11 August 2026, 2.4.7 on 31 May 2027, 2.4.8 on 31 May 2028, 2.4.9 on 31 May 2029 (per Adobe, September 2026). The current version is 2.4.9, released 12 May 2026.

From 1 June 2027, Adobe "will no longer maintain Cloud environments running unsupported Commerce versions" and may suspend traffic (per Adobe, September 2026). Self-hosted, nobody suspends you, which is worse: the deadline moves from a calendar to a risk register and the upgrade slips until something forces it.

Budget an upgrade project every three years. That single line is usually larger than the hosting line and it is the one most self-built TCO models leave out entirely.

Two: who carries PCI scope. This is a compliance-scope statement, not legal advice, and both numbers below are the vendors' own words.

Shopify's position is short: "Shopify is certified Level 1 PCI DSS compliant," and "All stores powered by Shopify are PCI compliant by default" (per shopify.com/security, September 2026). Shopify's page does not enumerate residual merchant obligations, so do not read it as a statement that you have none.

Adobe's position is longer and more honest about the split. Adobe maintains "PCI certification for the infrastructure and services used for the Adobe Commerce solution." The merchant maintains "the required level of PCI compliance of the customized application," runs "PCI ASV scans," and is responsible for "the compliance of their custom code, system and network processes, and organization" (per Adobe, September 2026). Adobe also states plainly that "Storing cardholder data in Adobe Commerce is strictly prohibited."

What we will not state

We will not tell you which SAQ your business files. That depends on how your checkout is implemented and who your acquirer is, and neither Adobe nor Shopify publishes a merchant-specific SAQ mapping. Ask your acquirer and your QSA, in that order.

The method, since the number does not exist

  1. Get Adobe's license quote in writing, with the term length and the renewal escalator.
  2. Price hosting against your actual peak, not your average. Adobe Commerce production on Adobe's own cloud Pro runs "three virtual machines (VMs) behind an Elastic Load Balancer" (Adobe, September 2026); self-hosted, that shape is your bill.
  3. Put a named person and a percentage of their year against patching. Adobe's language is "immediately following their release." That is a standing obligation, not a ticket.
  4. Add one upgrade project per three years, at whatever your last replatform-scale project cost.
  5. Ask your acquirer what changes about your PCI paperwork under each option, in writing.
  6. Only then compare against $2,500 or $2,300 per month plus your app subscriptions plus 0.20% per transaction if you are not on Shopify Payments.

When NOT to run this comparison at all

  • When the trigger was a feature gap. Our enterprise-platform record scores that situation WAIT, on the basis that a Function, a checkout extension or a middleware layer closes most of them in a sprint (Deploi decision record, September 2026).
  • When nobody has priced the upgrade line. A TCO model without it flatters self-hosting by the largest single number in the comparison.
  • When the quote has not arrived. Half a comparison is worse than none.

The Deploi point of view

Our own position, from building on Shopify. Separate from the facts above.

  • Our take: the TCO difference is unknowable as published and knowable as scoped. Refuse the single number, build the eight lines, and weight the upgrade clock and the patching obligation heavily, because they are labor lines that recur and hosting is a commodity line that does not.
  • What we’ve seen: self-hosted TCO models that lose come in two shapes. The first prices infrastructure and forgets the human who patches it. The second prices year one and never prices year four, which is where the forced upgrade lands.
  • Where we disagree: the standard framing treats Shopify's fee as the expensive side because it is the visible side. The visible number is not the expensive number. An unpatched Adobe instance is cheap right up until it is the most expensive thing the company owns.
  • What this page adds: the specific published end-of-support dates and the 1 June 2027 cloud enforcement date that turn Adobe's three-year window into a recurring budget line, plus each vendor's own words on who carries PCI scope. The parent compares B2B features; this page prices the platform underneath them.

Reviewed by Martin Dejnicki, Director of SEO & AI Search. Facts verified 2026-09-14.