What they cost, how to evaluate one, and whether you need to hire at all.
Building a listed AppExchange app takes Apex, Lightning Web Components, managed-package experience, and a security review most first-time teams fail. Here is what hiring for that actually costs in 2026, and the alternative worth pricing against it.
Built by ex-Salesforce AppExchange engineers
Founded by a former member of Salesforce's AppExchange team
An AppExchange developer builds commercial Salesforce apps that are distributed as managed packages and listed on Salesforce's marketplace. The work is different from ordinary Salesforce development: it requires second-generation packaging, namespace management, upgrade paths, and passing Salesforce's mandatory security review, which roughly half of first submissions fail.
In 2026, hiring one costs about $90 to $125 an hour onshore through a consultancy, or $35 to $70 an hour offshore depending on region. A complete commercial AppExchange app typically lands between $50,000 and $150,000.
Rates vary more by location than by skill, and more by security review experience than by either. These are published 2026 ranges, linked to source.
| Where you hire | Hourly rate | What you get | Source |
|---|---|---|---|
| Onshore US or UK, via consultancy | $90 to $125 | Developer. Architects run $135 to $170 | Source pending |
| Onshore US, broad market range | $120 to $250+ | Wide spread by seniority and firm | Source pending |
| Eastern Europe | $45 to $70 | Strong overlap with EU hours | Source pending |
| Latin America | $40 to $65 | Nearshore, US timezone overlap | Source pending |
| India | $35 to $55 | Widest quality spread, verify packaging experience | Source pending |
| Complete commercial app | $50,000 to $150,000+ | Architecture, build, security review, listing | Source pending |
The hourly number is the misleading one. Roughly half of first security review submissions fail, and a remediation cycle adds six to nine weeks of billable time that no rate card shows you. Price the review risk, not just the rate.
Two quotes for the same brief can differ by 3x. These are the variables that explain it.
Where the work happens
Offshore roughly halves the rate, from $90 to $125 onshore down to $35 to $70. It also widens the quality spread, so the saving is real only if you can verify managed-package experience specifically.
Seniority, not headcount
A developer runs $90 to $125 through a consultancy; an architect runs $135 to $170. An AppExchange build needs architect judgement early and developer hours later, and quotes that price it all at one rate are usually hiding which.
How standard your data model is
A sync onto standard objects is a different job from one that needs custom objects, unusual sharing rules, and governor limit planning. This is decided before any code exists and it sets everything after it.
Security review cycles
The multiplier nobody quotes. About half of first submissions fail, and remediation adds six to nine weeks of billable time. A cheaper rate that needs two cycles is not cheaper.
Who does the listing work
Partner Console setup, listing metadata, screenshots, and a demo org are real hours. Contracts that stop at code leave them with you, and they still have to happen before anything is listed.
What happens after launch
Three Salesforce releases a year can break a package. Agency maintenance retainers run $22K to $45K per year, and the alternative is your own team owning regression testing forever.
Bars rank how far each variable tends to move a quote. They order the list; they are not a measurement.
- 01
Ask for a listed app, not a portfolio
Anyone can show custom org work. Ask for a live AppExchange listing they packaged, and check it on the marketplace yourself.
A good answer names the listing and the namespace. A vague one talks about orgs they have worked in.
- 02
Ask their first-attempt security review rate
About half of submissions fail first time. Someone who has shipped several will know their own number and explain what they failed on.
A good answer is a number and a story. Anyone claiming they have never failed one has probably submitted once.
- 03
Confirm 2GP, not 1GP
Second-generation packaging is the current standard. A developer still defaulting to 1GP has not shipped recently.
A good answer explains why they would pick one over the other for your case, not just which one they know.
- 04
Separate org development from packaging
Custom Salesforce skills do not transfer automatically. Namespaces, upgrade paths, and version management are a distinct discipline.
Ask what breaks for an existing customer when you rename a field. If the answer is nothing, they are thinking in orgs.
- 05
Get IP ownership in writing
Who owns the package, the namespace, and the source when the engagement ends. Ambiguity here is expensive later.
Get it in the contract, not the call. The namespace is the part people forget until they try to leave.