15 questions to ask a development agency before you sign in 2026

TL;DR
The questions to ask a development agency in 2026 are mostly not about technology. Ask "Who will be building this, and can I meet them?", then "What's the handoff process?", then "Who maintains it after launch?", and keep asking until somebody writes the answers down. Here is what a real answer contains.
- Names and seniority, the hours you actually get, plus every subcontractor and what happens to their access when they roll off.
- A phased contract with an acceptance standard per phase, because the mean actual-to-estimated cost ratio across 4,677 IT projects with full cost data was 1.8.
- A written copyright assignment that takes effect as the code is written, and a straight answer about which parts an AI tool generated.
- A bug warranty in days, a response window in your working hours, and a named owner for the EU reporting duty that starts this September.
What you are actually buying
You are not buying code. You are buying somebody else's estimate and a promise about next year.
Gartner forecast worldwide IT services spending at $1.570 trillion for 2026, as of July 2026, up 5.3% on 2025. The usual diligence is a portfolio review and a rate card.
The estimate is the part that breaks. Flyvbjerg and co-authors collected 5,392 IT projects and found a mean actual-to-estimated cost ratio of 1.8 across the 4,677 with complete cost data, with a power-law tail instead of a bell curve.
You will also meet the Standish Group's CHAOS report, the source of every success rate a vendor deck quotes. It sells for $450 and publishes no sampling or survey method, and Eveleens and Verhoef showed in IEEE Software that its definitions produce meaningless figures.
Three 2026 deadlines that decide who answers the phone
Three dates decide who picks up after launch. None of them moved for your project.
The European Commission confirms that the Cyber Resilience Act reporting obligations in Article 14 apply from September 11, 2026. An actively exploited vulnerability means an early warning within 24 hours, a fuller notification within 72 hours and a final report within 14 days of a fix being available. ENISA has the reporting platform scheduled to be operational by the same date.
Check the definition of manufacturer before you assume this is your vendor's problem. It covers anyone who has a product developed for them and markets it under their own name or trademark. That is you.
Two platform dates are already in force. Google has required new apps and updates submitted to Play to target Android 16, API level 36, since August 31, 2026, with an extension to November 1 on request. Apple has required uploads built with Xcode 26 since April 28, 2026.
How we built this list
Four rules, applied to every question.
- It comes from a buyer, not a marketing team. Several are quoted from public discussions about what went wrong.
- It has a wrong answer. A question any vendor passes is a warm-up, not a filter.
- The answer is checkable before money moves, in a document or on a call.
- A pattern counts when it appears in at least three statements from two independent sources. Below that it is not published.
One disclosure. Mercury Development sells outsourced development, so several of these questions are aimed at us too. Still choosing between an agency, a hire and a freelancer? The three-model comparison comes first.
The 15 questions at a glance
| # | Ask this | A real answer contains |
|---|---|---|
| 1 | Who will be building this, and can I meet them? | Names, seniority, weekly hours, a call before signing |
| 2 | Will any of this be subcontracted, and who touches our data? | Every company on the work, and a credentials offboarding rule |
| 3 | What happens if the developer assigned to us leaves mid-project? | A named backup and an unbilled overlap |
| 4 | How do you structure contracts to reduce the risk of being scammed? | Phases, acceptance criteria, your accounts, an exit clause |
| 5 | What does the estimate assume, and what happens when it is wrong? | Written assumptions and who absorbs the first overrun |
| 6 | What is the smallest piece of work you will sell me first? | A priced phase whose output outlives us |
| 7 | Who owns the copyright, and when does the transfer take effect? | A signed assignment effective on creation |
| 8 | Which AI tools are in your pipeline, and who owns what they generate? | A tool list, the licence tier, and no claim on unownable output |
| 9 | Whose name is on the App Store and Play Console accounts? | Your legal entity, your billing, your credentials |
| 10 | What's the handoff process? | A dated deliverable list and a dry run |
| 11 | How do you handle the first 30 days of bugs? | Covered defects, response times, what counts as new scope |
| 12 | Could another team pick this up without you? | A fresh machine deploying from your repository |
| 13 | What happens when something breaks at 2am after launch? | Severity classes, response times per class, an SLA |
| 14 | Who maintains it after launch? | A retainer signed with the build, forced updates included |
| 15 | Who reports it if a vulnerability in our product is exploited? | Your obligation, their evidence, a maintained SBOM |
Who actually writes the code
Every failure story starts here. Not with the stack. With the roster.
1. Who will be building this, and can I meet them?
A real answer names the engineers, states what share of their week you get and puts them on a call before you sign. Names that arrive after the contract mean you bought capacity from a pool. This is the most common question in the discussions we analyzed, and the one most often answered with a slide instead of a name.
2. Will any of this be subcontracted, and who touches our data?
Subcontracting is not automatically bad. Undisclosed subcontracting is. If your product processes EU personal data on your instructions, you are the controller, and Article 28 of the GDPR says a processor "shall not engage another processor without prior specific or general written authorisation of the controller." Ask for the list of companies, not the list of countries, then ask what happens to an engineer's production credentials the day they roll off.
3. What happens if the developer assigned to us leaves mid-project?
Agency work sits in professional services, where the Bureau of Labor Statistics puts the 2025 annual average quits rate at 2.3% a month, above the 2.0% across all industries. Your contractor's industry churns faster than the economy does. Ask who the named backup is, what overlap you get, and who pays for the ramp-up.
How the contract is built
The contract is the only part of an agency you can inspect before paying.
4. How do you structure contracts to reduce the risk of being scammed?
A defensible structure is phased, with an acceptance standard per phase, payment on accepted work, and your accounts from commit one. Fixed price against a vague scope is where that 1.8 mean overrun bites, because the argument moves from engineering to change orders. The question above is quoted from a buyer who had already been burned once.
5. What does the estimate assume, and what happens when it is wrong?
Ask for the assumptions as a list. Third-party APIs behaving as documented, content arriving on a date, a defined device matrix. Then ask who absorbs the first 10% when an assumption fails, and what the change-order lead time is. A vendor who cannot name one assumption has not estimated. They have guessed.
6. What is the smallest piece of work you will sell me first?
The good answer is a paid phase that produces something you keep: a specification, an architecture, a backlog you could hand to a different vendor. The bad answer is a free proposal and a twelve-month commitment. Discovery you paid for is leverage. Discovery you got free was sales.
What you own when it ends
Ownership is a document question, and the defaults are worse than buyers assume.
7. Who owns the copyright, and when does the transfer take effect?
Under section 101 of the US Copyright Act, work made for hire covers employees and nine listed commissioned categories. Software is not among them. The Copyright Office states that a commissioned work is not a work made for hire without a written agreement, which leaves the copyright with whoever wrote it. Ask for an assignment effective as the code is written, then check whether it is conditional on final payment.
8. Which AI tools are in your pipeline, and who owns what they generate?
Ask for the tool list and the licence tier, because free tiers can train on what your team submits. Then ask what the vendor claims to assign you. The Copyright Office states that when a work's traditional elements of authorship were produced by a machine, the work lacks human authorship and it will not register it. An assignment cannot transfer what nobody owns.
9. Whose name is on the App Store and Play Console accounts?
Apple requires an organization account to be a legal entity that can contract with Apple, and shows it as the seller of your app. If the seller is your agency, your users belong to your agency. Moving an app later is fenced: Apple blocks transfers of apps that never shipped a version, and Google requires both accounts to be registered and active.
What handoff means in practice
Handoff is cheap to negotiate before signing and expensive to negotiate after.
10. What's the handoff process?
A real answer is a dated list: repository access, setup a new engineer can follow on a clean machine, a credentials inventory, architecture notes. Then a dry run before the final invoice clears, while you still have leverage. Another question quoted from the corpus, and the one that separates a vendor from a dependency.
11. How do you handle the first 30 days of bugs?
Get the warranty in writing, because "we support what we build" means nothing. Ask which defects are covered, what the response window is, and what the vendor calls new scope instead. Fixing late is expensive: a 2002 report prepared for NIST reproduces 1995 industry figures putting repair costs at 470 to 880 times a requirements-stage baseline once a defect reaches operation.
12. Could another team pick this up without you?
The test is mechanical. A developer who has never seen the project clones the repository, follows the written setup and gets a deployable build the same day. If that takes a phone call to one specific person, the documentation is decoration. The full checklist sits in our vendor continuity plan.
Who answers after launch
Launch is where your incentives and your agency's stop agreeing, unless the contract says otherwise.
13. What happens when something breaks at 2am after launch?
Ask who is on call, how incidents are graded, what the response time is for each severity class, and whether those times sit in an SLA or in somebody's email. Response windows are stated in the vendor's working hours unless you insist on yours. Ask who holds production credentials at 2am too, because a response nobody can act on is not a response.
14. Who maintains it after launch?
Buy the retainer in the same signature as the build, because your leverage peaks before the first invoice. Then name the forced work: the Play and App Store deadlines land whether or not you shipped a feature. Google Play has required new submissions to target API level 36 since August 31, 2026, and Apple has required Xcode 26 builds since April 28, 2026.
15. Who reports it if a vulnerability in our product is exploited?
You do, if you sell in the EU under your own name. So the contractual question is narrower than it looks: who provides the technical detail, inside what window, and who pays for the emergency release. Ask the same about the software bill of materials that Annex I of the Act requires in a machine-readable format, covering top-level dependencies at minimum. Somebody has to keep it current.
Which questions matter most for your situation
Fifteen questions is a long call. Cut the list by what you are actually doing.
First build, no technical staff of your own: questions 1 and 3 on staffing, then 7 through 9 on ownership. Each is cheap to fix in a draft and expensive to fix in a migration.
Rescue after a failed vendor: questions 10 through 12, asked about your current codebase before the new one. If nobody can produce a build from your repository today, that is the first deliverable, not the roadmap.
A live product with EU users: questions 2 and 14, then 15. If you are still weighing an agency against two hires, the budget arithmetic is a different comparison and it comes first.
What public buyer discussions show
These are our own numbers, from public sources. In 2026 we analyzed 9,246 statements from buyer discussions on Hacker News, Reddit and Capterra, filtered them to 261 signals from large-ticket contexts, meaning $50,000 or more in spend or an explicit enterprise, franchise or multi-location marker, and kept 40 patterns that appeared in at least three statements from two independent sources.
Five of the fifteen questions above are quoted from that corpus word for word: numbers 1, 4, 10, 13, 14. That is the finding. The questions buyers ask after a project fails are not exotic, and they are not technical.
The patterns cluster in three situations, and only one of them is a first build. The other two are a rescue after a failed vendor and a company outgrowing the platform it started on. In both, the buyer is asking about handoff and ownership because the last contract did not cover either.
The list is a filter, not a quiz
Opinion, stated plainly. The answers matter less than what happens when you ask.
A good vendor answers all fifteen in writing inside two days, because the answers already sit in their contract template. A vendor who negotiates the questions is showing you how they will handle a change request, and that signal costs you nothing.
The other half is on you. Each of these questions has one durable form, and it is a clause: a present assignment of copyright, an accounts schedule in your name, a warranty with a stated response window, a retainer that names the forced platform updates. Asking well and then signing a template that contradicts the answers is worse than not asking, because now you hold the risk and the false comfort.
Written by Rob Devereaux, Chief Operating Officer at Mercury Development. Rob has run the firm's operations from Hudson, Ohio since 2019 and has over 20 years of operational and financial experience. The contract structures and support commitments this checklist tests are the ones he signs at Mercury.
Ready to put these to a vendor? Send them to us first
Use the list on us before you use it on anyone else. Tell us what you are building, where it will run and who you have today. We come back in writing with our answers to the questions you care about, including the awkward ones about handoff and about what happens after launch.