Skip to content
Web Development22 min read

Custom Software Development in Australia: Costs, Process and Choosing a Partner

Custom software development in Australia: when it pays off, the delivery process, Xero, MYOB and Peppol integrations, IP ownership, TCO and partner checks.

01

What does custom software development in Australia actually involve?

Custom software development means designing, building and maintaining software around your own workflows instead of adapting your business to a packaged product. For Australian businesses it pays off when a workflow is distinctive and valuable, when off-the-shelf tools cannot integrate cleanly with systems such as Xero or MYOB, or when owning the data model matters. Otherwise, configured SaaS is usually cheaper.

This guide is written for owners, operations leads and product managers deciding whether to commission bespoke software, and how to run the project if they do. It covers the choice between SaaS, configurable SaaS, custom and hybrid; the cases where custom work is not justified; the delivery process; integrations that matter in Australia, including accounting platforms and Peppol eInvoicing; security and privacy; ownership of the code; costs and a total cost of ownership worksheet; the R&D Tax Incentive; and how to choose a partner.

For generic depth on build-versus-buy economics, see our guides to WordPress versus custom development cost of ownership and building or buying AI agents. Facts are sourced, our recommendations are labelled as ours, and examples are hypothetical. Nothing here is legal, tax or financial advice.

02

Key takeaways

  • Treat custom software as a long-term product, not a one-off purchase. Over several years, running costs can outweigh the build.
  • Most good outcomes are hybrids: SaaS for commodity functions such as accounting and payroll, custom code for the workflow that sets you apart.
  • Run a paid, time-boxed discovery before committing to a build price. It should produce user journeys, a data model, an integration map and a risk list.
  • Agree the source of truth for every shared record before integrating with Xero, MYOB or other systems. Most integration defects are data-ownership defects.
  • Paying a contractor does not transfer copyright. Under s196(3) of the Copyright Act 1968 an assignment must be in writing and signed.
  • Keep repositories, cloud accounts, domains and credentials in accounts your business owns from day one.
  • The Essential Eight is guidance, not law, for most private businesses. Privacy Act obligations, where they apply, are law.
  • Current R&D Tax Incentive rules and the changes proposed from 1 July 2028 are different things. Take advice from a registered tax agent before counting on either.
03

SaaS, configurable SaaS, custom or hybrid?

Before talking to developers, be clear which of four options you are actually comparing. The labels below are ours, but the distinctions are practical: they decide who changes the software, who patches it and who owns the data model.

OptionWhat it meansBest whenWatch for
SaaS as isA subscription product used with its standard settingsThe process is common across your industry and you are happy to follow the product's way of workingPer-user pricing growth, limited export, roadmap you do not control
Configurable SaaSA platform you shape with fields, workflows, low-code rules and marketplace appsMost needs are standard, and the rest fit inside the platform's configuration limitsConfiguration sprawl that only one person understands; app add-on costs
CustomSoftware built for your workflows, data model and integrationsThe workflow is distinctive, valuable and stable enough to specifyBuild and run costs, key-person risk, security and maintenance duties
HybridSaaS for commodity functions plus a custom layer: a portal, integration or workflow engineAccounting, payroll and email are standard but one core process is notIntegration upkeep when either side changes its API

Pro tip

Our recommendation: list your top ten workflows and mark each as ‘same as competitors’ or ‘how we win’. Buy or configure the first group. Consider custom work only for the second, and only where the volume or value justifies running software for years.

04

When custom development is not justified

Suppliers rarely lead with this section, so we will. Custom software is a commitment to fund a product indefinitely: hosting, security patches, dependency upgrades, integration changes and new features. If the benefit does not outlast those costs, do not build.

Signs you should not commission custom software yet:

  • A SaaS product covers most of the workflow, and the gap can be closed with configuration, an integration or a small change to how people work.
  • The function is commodity: general ledger, payroll, rostering, email marketing or a standard CRM. These products absorb regulatory change for you; Single Touch Payroll reporting to the ATO each pay day is one example of change you would otherwise have to track yourself.
  • The process is still changing month to month. Software freezes a process; prove it on spreadsheets, forms or a configured tool first.
  • Nobody in the business will own the product after launch: no one to prioritise changes, accept releases or answer users.
  • The case rests on avoiding subscription fees alone. Over several years, custom maintenance can cost more than the licence it replaced.
  • The real problem is data quality or training, which new software will not fix.
  • You need it live in weeks for a fixed event, and a configured product could do the job.
05

The delivery process, from discovery to support

Well-run custom projects follow a similar sequence even when teams work in short iterations. Each stage has an output you can inspect. The diagram shows our recommended flow; the gates are decisions, not paperwork.

Custom software delivery flow with decision gates
[1 Discovery] journeys, data model, integration map, risks
      |
   GATE A: build, configure SaaS, or stop?
      |
[2 Architecture] hosting region, auth, data flows, NFRs
      |
[3 Design] flows and prototypes tested with real users
      |
[4 Build in slices] one end-to-end workflow per release
      |      \
      |   [Integrations] Xero/MYOB, Peppol access point,
      |                  payments, identity
      |
[5 Test] automated tests, UAT, security checks, data trial
      |
   GATE B: go-live criteria met?
      |
[6 Launch] staged rollout, data migration, hypercare
      |
[7 Run] patching, monitoring, backups, roadmap
      |
   GATE C (every 6-12 months): extend, keep, or retire?

Worth noting

The design stage deserves its own budget line. Our guide to the product design process covers research, prototyping and usability testing in generic depth.

06

Discovery: what it should produce

Discovery is a short, paid phase that turns an idea into something a team can estimate. A fixed build price without discovery is either padded for risk or likely to be renegotiated. Ask for discovery as a separate engagement with its own deliverables, so you can take the outputs to another supplier if you choose.

What a useful discovery delivers: the users and roles; the end-to-end journeys for each role; a first data model, naming the records the system owns and the ones it only reads; an integration map with the direction and frequency of each data flow; non-functional requirements such as availability, response times, data retention and audit needs; a privacy assessment of personal information collected; a risk list; a release plan sliced by workflow; and an estimate with stated assumptions.

Questions discovery must answer for Australian businesses: is the business an APP entity under the Privacy Act; will any personal information leave Australia, including through support tools; which accounting platform is the source of truth for invoices and contacts; will you send or receive eInvoices through Peppol; and who in the business will own the product after launch.

If you are still testing whether the idea is worth building at all, the earlier step is validation, covered in our guide to product idea validation and, for new ventures, in MVP development for Australian startups.

07

Architecture decisions that set your future costs

Architecture choices made in the first weeks decide how expensive the software is to change in year three. Our recommendation for most business applications is a well-structured single application (a modular monolith) on managed cloud services, with clear module boundaries, rather than microservices from the start.

Hosting region. AWS runs Asia Pacific (Sydney), ap-southeast-2, with three Availability Zones enabled by default, and Asia Pacific (Melbourne), ap-southeast-4, which requires opt-in. Microsoft Azure runs Australia East in New South Wales with availability zones, paired with Australia Southeast in Victoria, and Google Cloud runs australia-southeast1 (Sydney) and australia-southeast2 (Melbourne). Choosing a local region is straightforward; the harder part is checking where logs, backups, email, analytics and AI services send data.

Cross-border data. For businesses covered by the Privacy Act, APP 8 requires an entity, before disclosing personal information to an overseas recipient, to take reasonable steps to ensure the recipient does not breach the APPs, and the entity can remain accountable for the recipient's acts. The OAIC's guidelines note that some overseas cloud storage can be a ‘use’ rather than a ‘disclosure’ where a binding contract limits the provider's handling and the entity keeps effective control. Get advice on your own arrangements.

Shared responsibility. Cloud providers secure the infrastructure; you secure what you build and configure on it. Microsoft states that for all cloud deployment types ‘you own your data and identities’. AWS describes its role as security ‘of’ the cloud and the customer's as security ‘in’ the cloud. Your contract with a developer should say who carries the customer side after launch.

Multi-tenancy. If the software will later be sold to other businesses, the tenancy model matters early. AWS's SaaS Lens describes silo (dedicated resources per tenant), pool (shared resources) and bridge (a mix) models. Our guide to SaaS development in Australia covers this in depth.

08

Integrations: Xero, MYOB, Peppol and the systems around them

For many Australian businesses the value of custom software is mostly in its integrations: quotes that become invoices without re-keying, jobs that update stock, payments that reconcile themselves. Integrations are also where budgets overrun, because each external system has its own data rules, limits and change schedule.

Accounting platforms. Xero's developer platform offers an accounting API and an Australian payroll API using OAuth 2.0. MYOB's developer portal introduces the MYOB Business API alongside APIs for EXO, Acumatica and its Transactions product. Before building, confirm which product and edition the business actually runs, because API coverage differs between them.

Peppol eInvoicing. The ATO is the Australian Peppol Authority. Businesses are generally identified on the network by their ABN, and they send and receive eInvoices through an accredited access point provider rather than connecting directly; only providers need ATO accreditation. B2B eInvoicing is voluntary. It matters most if you invoice Commonwealth entities: the Department of Finance's supplier pay-on-time policy (RMG 417) has been reported as requiring payment of eInvoices within 5 calendar days where both parties use Peppol, against 20 days for other invoices. Check the current policy before relying on it.

Other common connections. Australia Post offers shipping and tracking APIs, which need an eParcel or StarTrack contract (reported from its developer centre). Payment providers, identity providers, CRMs and industry platforms each add their own work. Treat every integration as a small product with an owner.

Integration questionWhy it mattersDecide before build
Which system owns each record?Two systems editing the same contact or invoice produces conflictsOne source of truth per record type
What triggers a sync?Polling, webhooks and batch jobs fail differentlyEvent, schedule and retry rules
How are tax codes mapped?GST treatment must match between systemsA reviewed mapping table, signed off by finance
What happens when the other side is down?Lost or duplicated invoices are expensive to unwindQueues, idempotent writes and a reconciliation report
Who renews tokens and API access?Expired OAuth connections fail silentlyMonitoring and a named owner

Worth noting

Our guide to API integration in Australia covers integration patterns, retries and monitoring in more detail.

09

Security and privacy: a baseline for custom software

Security is shared between the code, the hosting environment and the people who run it. A sensible baseline uses recognised references rather than a supplier's own checklist.

Application security. The current edition of the OWASP Top 10 is the OWASP Top 10:2025. It keeps broken access control as the top risk and adds software supply chain failures and mishandling of exceptional conditions. Ask your developer how each category is addressed in design, code review and testing.

Environment security. ASD's Australian Cyber Security Centre publishes the Essential Eight: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. It is guidance, not a legal obligation for most private businesses, and ASD defines maturity levels one to three. For software projects, the patching, MFA, admin privilege and backup strategies translate directly into hosting and deployment requirements.

Privacy. The OAIC says most small businesses (annual turnover of $3 million or less) are not covered by the Privacy Act, but some are regardless of turnover, including health service providers and businesses that trade in personal information. If you are covered, the Australian Privacy Principles shape what your software collects, how it secures it and how people can access or correct it. Covered entities also fall under the Notifiable Data Breaches scheme; the OAIC reported 1,205 notifications in calendar 2025, the highest since the scheme began, with malicious or criminal attacks the largest cause.

Incident obligations. Since 30 May 2025, businesses with annual turnover over AUD 3 million (per Home Affairs), and certain critical infrastructure entities, must report ransomware or cyber extortion payments within 72 hours of paying. Your runbook should name who makes that call.

Our website security guide for Australian businesses covers hosting, patching and incident response in more depth. Nothing here is legal advice; check the OAIC and ASD's guidance for your situation.

  • Role-based access checks on every request, tested automatically
  • MFA for all admin, hosting, repository and accounting-platform accounts
  • Secrets in a managed vault, never in code or shared documents
  • Dependency scanning and a patching schedule in the support agreement
  • Audit logs for sign-ins, permission changes and data exports
  • Encrypted, tested backups with a documented restore
  • A data map showing where personal information is stored and sent
10

Testing and acceptance

Testing should be planned in discovery and paid for in the estimate, not squeezed in before launch. Agree what ‘done’ means for each release in writing.

Layers to expect: unit tests for business rules such as pricing and GST calculations; integration tests against sandbox accounts for Xero, MYOB or payment providers; end-to-end tests for the main journeys; accessibility checks for any customer-facing screens; security testing proportionate to the data held; and a trial data migration using a copy of real records.

User acceptance testing (UAT) is where your staff run their real tasks with realistic data and sign off. Give UAT named testers, scripted scenarios and time out of their normal work. UAT done only by the developer, or skipped under deadline pressure, removes the one check that uses the business's own knowledge of edge cases.

If an early version was put together quickly with AI coding tools, read our guide to taking a vibe-coded app to production before going live; it covers the testing and hardening gaps those builds typically have.

11

Maintenance and support after launch

Launch is the start of the software's working life. Runtimes reach end of support, APIs change, browsers and phone operating systems update, and users find better ways to work. Budget for that from the start.

What a support agreement should define: response and resolution targets by severity; hours of cover; who monitors uptime and errors; the patching schedule for dependencies and runtimes; how integration changes from Xero, MYOB or other vendors are handled; backup and restore testing; a monthly allowance for small improvements; and how larger changes are estimated.

Time zones. If your supplier is offshore, check the overlap honestly. India Standard Time is UTC+5:30. Sydney and Melbourne are 4.5 hours ahead on AEST (UTC+10) and 5.5 hours ahead during daylight saving (AEDT, UTC+11); Brisbane stays 4.5 hours ahead all year. That leaves a workable shared morning in Australia, but out-of-hours incident cover needs to be written into the agreement.

12

Owning what you pay for: IP, repositories and escrow

Ownership is the clause most businesses read last and regret first. Software code is protected as a literary work under the Copyright Act 1968, and law-firm and Business Victoria guidance notes that a business paying a non-employee developer does not automatically own the code.

Section 196(3) of the Act states: ‘An assignment of copyright (whether total or partial) does not have effect unless it is in writing signed by or on behalf of the assignor.’ Section 197 allows future copyright to be assigned, so a contract can assign code before it is written. In practice: get a written IP assignment, signed, covering all deliverables, with a clear carve-out list for the supplier's pre-existing tools and open-source components, and a licence for anything not assigned. Ask a lawyer to review the wording.

Source code escrow is a three-party contract between the software vendor, the customer and an independent escrow agent, with code released on defined triggers such as supplier insolvency or failure to support. It is most useful when the supplier keeps the code, for example when you license a platform rather than own a bespoke build. If you own the repositories, escrow matters less.

  • Code repositories in your organisation's account, with the supplier added as members
  • Cloud hosting, domains, DNS and email sending accounts in your name and billing
  • Accounting, payment and API credentials issued to your business, not a developer
  • Architecture notes, environment set-up and deployment steps documented in the repository
  • A signed IP assignment and a licence for any retained supplier components
  • A list of third-party and open-source licences used
  • An exit clause covering handover, knowledge transfer and access removal
13

What drives the cost of custom software

We do not publish AUD price ranges. There is no neutral Australian survey of custom software costs, and the figures that circulate are mostly vendor marketing. What we can do is name the drivers, so you can compare quotes on the same basis and see where a lower price has removed something. Our website development cost guide for Australia applies the same approach to websites.

Cost driverPushes cost upKeeps cost down
Roles and permissionsMany roles with fine-grained rulesTwo or three roles with clear boundaries
WorkflowsMany branching approval paths and exceptionsOne main path, exceptions handled manually at first
IntegrationsTwo-way sync with several systems, legacy systems without APIsOne-way sync with well-documented APIs
Data migrationYears of inconsistent records from several sourcesA clean cut-over with limited history
Compliance and securityHealth or financial data, audit trails, external testingLow-sensitivity data, standard controls
InterfacesWeb, iOS and Android apps, offline useOne responsive web application
ReportingCustom dashboards and exports for each teamA small set of agreed reports plus export
Support levelExtended hours, fast response targetsBusiness hours, standard targets

Key takeaway

Quotes for custom work in Australia should state whether they include GST. GST is 10% on most taxable supplies, per the ATO. If one quote is GST-inclusive and another is not, the cheaper-looking one may not be cheaper.

14

Total cost of ownership worksheet

Compare options over the period you expect to use them, not just the build. The worksheet below uses formulas only. Fill in your own quotes; we have deliberately left out prices. Run it for each option (SaaS, configurable SaaS, custom, hybrid) over the same period, and decide consistently whether to work in GST-exclusive amounts.

TCO worksheet (enter your own figures; N = years)
ONE-OFF COSTS
  D  = discovery
  B  = design and build
  M  = data migration and cleansing
  T  = training and change management
  One-off = D + B + M + T

RECURRING COSTS (per year)
  H  = hosting and managed services
  L  = SaaS licences x users (SaaS and hybrid)
  S  = support and maintenance agreement
  I  = integration upkeep (API changes, tokens)
  E  = enhancements budget
  K  = internal product owner time x hourly cost
  Recurring = H + L + S + I + E + K

TCO over N years = One-off + (Recurring x N)

BENEFIT (per year, be conservative)
  Hours saved x loaded hourly cost
  + errors avoided x cost per error
  + revenue enabled (only if evidenced)

GST: add 10% to taxable items if comparing
inclusive prices; keep all options on one basis.

Pro tip

Our recommendation: count internal product owner time (K) honestly. Custom software without someone in the business prioritising and accepting changes tends to drift, and that cost does not appear on any supplier's quote.

15

The R&D Tax Incentive: current rules and proposed changes

Founders and finance teams often ask whether a custom software project can be claimed under the Research and Development Tax Incentive. It is possible, but software is an area where eligibility needs particular care.

Current rules (as published). business.gov.au states that the incentive is for companies: Australian-incorporated companies, or foreign companies that are Australian tax residents or have a permanent establishment. R&D expenditure for the income year must generally be at least $20,000. Core R&D activities are experimental activities whose outcome cannot be known in advance; supporting activities must be directly related to core activities; and activities must be registered. Accounting firms report that companies with turnover under $20 million can receive a refundable offset at their company tax rate plus 18.5 percentage points, with a non-refundable offset for larger companies.

Proposed changes (not law). business.gov.au says changes announced in the 2026–27 Budget ‘will start from 1 July 2028’. Coverage by accounting and law firms reports that the proposal would exclude supporting activities, raise the core R&D premiums, lift the refundable turnover threshold from $20 million to $50 million, raise the minimum spend from $20,000 to $50,000, and limit refundability to a company's first ten years. Treasury released exposure drafts in September 2026, according to PwC. These are announced proposals and may change before, or if, they are legislated.

What this means for a software project. Building a portal, integrating Xero or configuring workflows using known techniques is unlikely to be core R&D on its own. A genuinely uncertain technical question, tested through a planned experiment, may be. Keep contemporaneous records of hypotheses, experiments and results either way, and take advice from a registered tax agent or R&D adviser before you build the incentive into a business case.

16

Choosing a development partner

A partner's portfolio tells you what they have built; their process tells you what yours will be like. Our full checklist is in choosing a web development company in Australia. For custom software, five questions separate suppliers quickly.

  • Will you run a paid discovery with deliverables we own, before quoting the build?
  • Who exactly will work on our project, and what happens if they leave?
  • How do you test, review code and manage security, with reference to the OWASP Top 10?
  • Will repositories, cloud accounts and credentials sit in our accounts, with a written IP assignment?
  • What does support cost after launch, and how do you handle changes from Xero, MYOB or other vendors?

Pro tip

If the supplier will also manage your hosting, the ACSC's ‘questions to ask managed service providers’ are a useful addition: whether they implement better-practice security such as the Essential Eight, administer systems securely, monitor activity, assess systems regularly, and can respond to incidents.

17

Hypothetical examples

Hypothetical: a trades business with job management. A building services company with a few dozen field staff uses a job management SaaS, Xero and spreadsheets for quoting. The quoting rules are distinctive and drive margin, but scheduling and invoicing are standard. A sensible outcome is hybrid: keep the job management product and Xero, and build a small custom quoting tool that pushes approved quotes into both. The full replacement a supplier proposed would have rebuilt commodity functions at a higher running cost.

Hypothetical: an allied health network. A group of clinics wants a referral portal for GPs. Because health service providers are covered by the Privacy Act regardless of turnover, discovery prioritises a data map, hosting in an Australian region, audit logs and a check on every overseas tool in the support stack under APP 8. The build is modest; most of the effort sits in privacy design and testing.

Hypothetical: a distributor selling to government. A wholesale supplier invoices several Commonwealth agencies from MYOB. Rather than custom software, the first step is enabling Peppol eInvoicing through an accredited access point that works with its accounting product. Custom work is limited to a reconciliation report. Sometimes the right amount of custom software is very little.

18

Common mistakes

  • Asking for a fixed build price before discovery, then paying for the uncertainty in change requests.
  • Rebuilding commodity functions such as accounting or payroll instead of integrating with products that already handle Australian requirements.
  • Leaving repositories and cloud accounts in the developer's name, with no written IP assignment.
  • Choosing an Australian hosting region and assuming that settles privacy, while logs, support tools and AI services send data overseas.
  • Budgeting for the build but not for support, patching and integration changes.
  • Treating proposed R&D Tax Incentive changes as if they were law, or assuming routine development qualifies.
  • Skipping user acceptance testing with real staff and real data.
  • Adding AI features without a clear use case or cost model; our guides to AI implementation and AI automation costs in Australia cover how to scope them.
19

How this fits into your wider plan

Custom software is one part of a broader product decision. Our pillar guide to digital product development in Australia shows how websites, apps, SaaS and internal tools fit together. If the custom software is customer-facing and replaces a marketing site, compare the trade-offs in custom websites versus website builders. If you are a startup, website development for startups covers what to build first.

21

Conclusion

Custom software development in Australia earns its cost when it supports a workflow that is distinctive, valuable and stable, and when it is planned as a product with an owner, a support budget and clear ownership of the code. Start with a paid discovery, keep commodity functions on SaaS, design integrations around a single source of truth, build to recognised security and privacy baselines, and make sure every repository and account is yours.

Equally, be willing to conclude that you should not build. A configured product, a small integration or a process change is often the better investment, and a good partner will tell you so.

Weighing up a custom build?

ZSpace Labs is an India-based, remote-first technology studio working with Australian and international businesses on web applications and custom software and mobile apps. If a second opinion on scope, architecture or whether to build at all would help, we are happy to talk it through.

Start a Project
FAQ

Common questions.

Custom software development is designing, building and running software for one organisation's specific workflows, rather than buying a product built for many customers. It can be a whole application, such as a job management portal, or a custom layer around off-the-shelf tools, such as an integration between a quoting system and Xero. The business funds the build and the upkeep, and in return controls the features, the data model and the roadmap.

Get in touch

Have a project in mind?

Whether you're building a new digital product, improving an existing website, or looking to automate part of your business — let's talk.