Guide · Decision
Custom application or off-the-shelf software?
For most of a small business’s needs, off-the-shelf software sold as a subscription is the right place to start: it costs less up front, it’s quick to set up and the vendor maintains it. Custom software makes sense when the way you work is what sets you apart and off-the-shelf tools force you to change it, when your team retypes the same information across several tools, or when your rules don’t fit anywhere. Often, the best answer lies in between: keep the software that works and build only what’s missing.
In short
- Off-the-shelf software is almost always cheaper and faster to set up: start there.
- Custom software is worth the investment when your rules, workflows or integrations go beyond what the tools allow.
- Both choices carry a dependency risk: on the software vendor, or on the developer if you don’t own the code.
- In Quebec, buying or developing a system that handles personal information requires a privacy impact assessment.
- The hybrid approach is common: off-the-shelf software for the standard work, a custom application for the rest, connected to each other.
What is software as a service?
The Canadian Centre for Cyber Security defines software as a service, or SaaS, as a model where you buy a service that lets you use applications hosted by a provider and accessed over the internet. Online office suites are the best-known example. NIST’s reference definition adds a point that matters for what follows: the customer doesn’t manage the infrastructure, and controls the application only through limited settings.
It is common. According to Statistics Canada, 48.5% of Canadian private-sector businesses with 5 or more employees used cloud services in 2023: 45.1% of small businesses and 58.5% of medium-sized ones. That figure covers cloud computing in the broad sense, subscription software included, but also storage and hosting. For most small businesses, then, the question isn’t whether they will use subscription software, but for which parts of their work.
When off-the-shelf software is the right choice
- The process is the same in every business: accounting, payroll, email, simple appointment booking.
- An off-the-shelf product covers most of your needs, and you are willing to adapt the rest of the way you work.
- You need the tool right away, with a limited starting budget.
- The way you work in this area doesn’t set you apart from your competitors.
In these cases, building custom costs more for a comparable result. A good application developer should tell you so. That is our position: if off-the-shelf software does the job, we will tell you from the start.
When custom software makes sense
- The way you work is what sets you apart, and the software you’ve tried forces you to change it.
- Your rules are too specific: configurable products, pricing based on several factors, approval steps unique to your business.
- Your team retypes the same information across several subscriptions that don’t talk to each other.
- You pay for software whose features nobody really uses, and the real work still happens in Excel (see replacing Excel with a web application).
- Your customers need an experience under your own name: a portal, online approval, file tracking.
That was the case for Pavar: chairs and booths with hundreds of possible options, proposals prepared in Excel and details to pass on to production. No tool on the market followed that process from end to end; an application designed around it did.
The two options side by side
| Off-the-shelf software (SaaS) | Custom application | |
|---|---|---|
| Upfront cost | Low: a subscription | High: the build project |
| Cost over time | The subscription, per user, every year | Hosting, support and improvements |
| Timeline | A few days or weeks | A first version in a few weeks or months |
| Customization | Settings planned by the vendor | Your rules and your workflows |
| Evolution | Based on the vendor’s priorities | Based on yours |
| Data and code | With the vendor, under its contract | Yours, if the contract says so |
| Main risk | Depending on a vendor whose prices and decisions you don’t control | A poorly scoped project, or code you don’t own |
The costly mistakes on both sides
On the SaaS side, the Canadian Centre for Cyber Security names the risk plainly: being locked into a particular service, because of financial obligations or an inability to switch to another provider. It also notes that getting data out is often designed to be expensive, and recommends contracts that guarantee access to your data at a reasonable cost. Security is shared: the provider is responsible for the security of the cloud, your business for what it puts in it.
One mistake is underestimated almost everywhere: SaaS almost always forces you to change the way you work. The software sets the method, and the team has to follow it. Rollout therefore often takes longer than planned, with problems the business didn’t see coming: a step that doesn’t exist in the software, workarounds in Excel, a team that resists the change.
On the custom side, the mistakes are different: a project that tries to do everything from day one, a price that overruns, and above all code that stays with the developer for lack of a written assignment. Our guide on the cost of a custom application explains how to scope a first version, and our guide on code ownership covers what to require in the contract.
Your data and Quebec law
Whether you buy software or have it developed, Quebec’s private-sector privacy law applies the same way. Any project to acquire, develop or overhaul an information system that handles personal information requires a privacy impact assessment, and the system must be able to release that information in a structured, commonly used technological format (s. 3.3). A person can also ask for their own information in that format (s. 27).
If the software stores that information outside Quebec, an assessment is also required before it is communicated, along with a written agreement (s. 17). At the federal level, the principle is the same: an organization remains responsible for personal information transferred to a third party for processing. The Canadian Centre for Cyber Security recommends making sure sensitive data is stored in Canada.
The hybrid approach: keep what works
The choice is rarely all or nothing. Your accounting, email and payroll stay in off-the-shelf software; the custom application handles the steps they don’t cover, and connects to them through an API, imports or exports. Information is entered once and flows between the tools. That is the approach we take with our custom applications.
Before signing with a SaaS vendor, ask them these questions, based on the Canadian Centre for Cyber Security’s recommendations:
- Where are your data centres and your administrators located?
- How do we get all our data back, in what format, and at what cost?
- What happens to our data at the end of the contract, and how is it destroyed?
- How, and with how much notice, can prices and terms change?
- Does the software connect to our other tools through a documented API?
A straight answer
Off-the-shelf or custom: let’s talk about your situation.
Show us the tools you use and what slows you down. If off-the-shelf software does the job, we will tell you from the start. The first conversation with François comes with no commitment.
Book a call with FrançoisSources
- Canadian Centre for Cyber Security, models of cloud computing (ITSAP.50.111) · modified August 12, 2025
- NIST, SP 800-145, definition of software as a service · September 2011
- Statistics Canada, table 22-10-0117-01 (use of technologies by businesses, 2023) · consulted October 7, 2026
- Canadian Centre for Cyber Security, benefits and risks of adopting cloud-based services (ITSE.50.060) · modified March 5, 2020
- Canadian Centre for Cyber Security, recommended cyber security contract clauses for cloud services (ITSM.50.104) · October 2024
- Canadian Centre for Cyber Security, baseline cyber security controls for small and medium organizations · modified February 18, 2020
- Act respecting the protection of personal information in the private sector, ss. 3.3, 17 and 27 (LégisQuébec) · updated to August 12, 2026
- Personal Information Protection and Electronic Documents Act, Schedule 1, principle 4.1.3 · updated to September 21, 2026
