Hiring · Guide

Web development agency: the technical vetting checklist for 2026

Most guides to hiring a web development agency ask you to check a portfolio, read some reviews and call two references. That still matters, but it misses the part of the job a client cannot see: the code itself, who owns it, how securely it was written, and what happens to your site the day the agency stops answering emails. This is a technical due diligence checklist built for 2026, when a growing share of what an agency ships was written or assisted by AI and the standard vetting questions have not caught up.

The short answer

Vet a web development agency on code ownership, AI code review practices, security scanning, QA process, hosting and credential handover, performance targets and a written support SLA, not just design samples. Get IP assignment, admin access and a defined post-launch response time in the contract before you sign.

Why technical vetting matters more in 2026

The tooling changed faster than the vetting questions did. Veracode's 2026 GenAI Code Security Report tested output from more than 100 AI models and found the average security pass rate has stalled at 56 percent, with 44 percent of AI coding tasks producing a detectable OWASP Top 10 vulnerability. Java code fared worst at a 30 percent pass rate against 63 percent for Python, which matters if your agency is quoting a stack you have not asked about. At the same time, Verizon's 2026 Data Breach Investigations Report found vulnerability exploitation overtook stolen credentials as the leading cause of breaches for the first time in the report's 19-year history, appearing in 31 percent of breaches, up 55 percent year over year, while only 26 percent of critical known vulnerabilities were fully patched in 2025, down from 38 percent the year before.

None of that means avoid AI assisted development. It means ask how the agency reviews it, because most have not updated their QA to match how they now write code.

What a web development agency actually does, versus a design agency

A design agency owns layout, visual identity and user experience. A web development agency owns the engineering underneath it: the codebase, database, third party integrations, hosting architecture and the security posture of all of it. Plenty of firms, including HyberX, do both under one roof, but the two disciplines get evaluated on different criteria. If you are hiring primarily for the technical build, see our full breakdown of what to hire a web development company versus a web design agency for before you go further with this checklist.

The AI code question you need to ask

Ask directly: what share of this build is AI generated or AI assisted, and what human review gate catches vulnerabilities before it ships. Stack Overflow's 2026 developer trust research found that 84 percent of developers now use AI coding tools daily, yet only 29 percent actually trust the code it produces, down from 40 percent in 2024. As their analysis put it, using a tool constantly and trusting its output unconditionally turned out to be two separate things. An agency with a real answer to this question, ideally a documented code review step specific to AI generated code, is a genuinely different vendor than one that has not thought about it.

Vetting areaWhat to askRed flag answer
AI code reviewWhat percentage of the build is AI assisted, and who reviews it"We don't really track that" or no human review step
Security scanningDo you run dependency or SCA scans and how fast do you patch known vulnerabilitiesNo scanning tool named, vague "we keep things updated"
QA processWhat is your test coverage expectation and device matrix before launchManual click-through only, no staging environment
Code ownershipDoes the contract assign IP to us on final payment, not just license itAgency retains rights or reuses your code in a template
Hosting and accessWho holds admin credentials, DNS and the hosting account after launchAgency insists on keeping sole access post-launch
Performance targetsWill you commit to Core Web Vitals thresholds in writing"It'll be fast" with no measurable target
AccessibilityWhat is your WCAG 2.2 AA conformance target and how is it testedNo accessibility testing mentioned at all
Post-launch SLAWhat are your response times for critical bugs after invoicingVerbal promise only, nothing in the contract
What we'd do about it

Put the AI code review question in writing as part of the proposal request, not a verbal follow-up. An agency's answer tells you more about their actual QA discipline than any portfolio piece, because it forces them to describe a process rather than show you a finished result with the process hidden.

Security and dependency practices to check

Ask what the agency scans for and how often. Dependency and software composition analysis tooling catches outdated packages with known vulnerabilities before they ship, and the gap between finding a critical flaw and patching it is where most breaches now happen according to Verizon's data above. You do not need to understand the tooling. You need a specific named process instead of a general assurance that "security is a priority."

Code ownership, credentials and the lock-in trap

The most expensive mistake in this checklist is not technical, it is contractual. If the agency's contract does not explicitly transfer intellectual property to you on final payment, or if they keep the only copy of admin credentials, domain registrar access and the hosting account, you do not fully own your own website. This is a common structure precisely because it locks a client into paying the same agency for every future change. Your business name should be on the domain registrar and hosting account from day one, not the agency's.

Performance and accessibility benchmarks to put in the contract

"Fast" and "accessible" are not contract terms. Numbers are. As of the May 2026 Chrome UX Report snapshot, only about 56 percent of tracked website origins pass all three Core Web Vitals thresholds (LCP under 2.5 seconds, INP under 200 milliseconds, CLS under 0.1), which gives you a real baseline to hold a bid against rather than a vague promise. Accessibility carries legal weight too. WebAIM's 2026 audit of the top one million home pages found 95.9 percent have detectable WCAG failures, averaging over 56 errors per page, and researchers linked part of that regression to AI assisted, unreviewed development. Separately, more than 5,000 ADA website accessibility lawsuits were filed in the US in 2025 with no small business exemption, and nearly 70 percent targeted e-commerce sites specifically, where defending even a baseless claim commonly runs $5,000 to $125,000. Ask for a specific WCAG 2.2 AA target and how it gets tested before launch, not after a complaint arrives.

What we'd do about it

Write Core Web Vitals thresholds and a WCAG 2.2 AA target directly into the statement of work, tied to final sign-off. On our own builds we test both before a project is marked complete, because "we'll fix it after launch" is where most performance and accessibility debt actually gets created.

What should a post-launch SLA actually cover?

Three things: an uptime commitment if the agency also hosts the site, a defined response time split by severity (critical bug versus minor cosmetic issue), and a stated consequence if they go unresponsive after final invoicing. Small businesses currently plan to spend more here, not less: Clutch's 2026 small business research found 45 percent plan to increase technology and web spending this year with web development as the top single investment priority at 39 percent, and 45 percent of small businesses now outsource development to an agency rather than build in-house. That is exactly the population this checklist protects, because rising demand also raises the number of agencies willing to sell a build without a real support structure behind it.

How much technical vetting is enough for a small project?

  1. For a five to ten page marketing site, confirm IP ownership, credential handover and a written support window. Full security audits are usually overkill at this scope.
  2. For anything handling payments, accounts or customer data, add the security scanning and AI code review questions in full, since the exposure is real.
  3. For a rebuild of an existing site, ask specifically how the migration preserves current rankings and redirects, which is a technical step vendors sometimes skip to save time.
  4. For any e-commerce build, treat the accessibility question as non-negotiable given the 2025 lawsuit volume above.
  5. Always get the answers in writing. A verbal "yes, of course" during a sales call is not a contract term.

This is the same standard we hold our own website design and development work to, and it is worth applying even to a smaller build like our fixed-scope five page website, where clients still deserve clear answers on ownership and access despite the lighter price point.

Frequently asked questions

What is the difference between a web development agency and a web design agency?

A web design agency focuses on layout, visual identity and user experience. A web development agency builds the engineering underneath it: the codebase, integrations, database, hosting architecture and security. Many firms do both, but the technical vetting in this checklist applies specifically to the development side of the work.

Should I ask a web development agency how much of their code is AI generated?

Yes. Veracode's 2026 GenAI Code Security Report found that AI generated code passes security checks only 56 percent of the time, and 44 percent of AI coding tasks contain a detectable OWASP Top 10 flaw. Ask what share of a build is AI assisted and what human review gate catches vulnerabilities before launch.

Who should own the code, hosting and domain after a website is built?

You should. The contract should assign IP ownership to you on final payment, not merely license it, and your business should hold the hosting account, domain registrar and admin credentials directly rather than through the agency's account. Agencies that insist on keeping sole access are creating a lock-in point, not a convenience.

What performance standard should a web development agency commit to?

Put Core Web Vitals targets in the contract rather than accepting a vague promise of a fast site. As of the May 2026 Chrome UX Report data, only about 56 percent of tracked website origins pass all three Core Web Vitals thresholds, so a documented target separates a genuine commitment from marketing language.

Does website accessibility actually matter for a small business build?

Yes. Over 5,000 ADA website accessibility lawsuits were filed in the US in 2025 with no small business exemption, and nearly 70 percent targeted e-commerce sites. Ask any web development agency for their WCAG 2.2 AA conformance target and how they test for it before launch.

What should be in a web development agency's post launch SLA?

A written uptime commitment, defined response times for critical bugs versus minor ones, and a clear consequence if the agency goes unresponsive after invoicing. Verbal promises about support are not enforceable. If it is not in the contract, assume it does not exist.

The takeaway

A portfolio tells you what an agency can design. It tells you almost nothing about how they write, review, secure and hand off code, and that gap is where 2026's real risk sits: AI assisted development that has outpaced most agencies' QA process. Ask the eight questions in the table above, get the answers in writing, and hold ownership of your own domain, hosting and credentials from day one. That single habit prevents more expensive problems than any amount of portfolio browsing.

Rahul Gupta

Founder of HyberX, a digital growth agency working with brands across the US, Europe, the Middle East and India. Writes on web design, paid media and conversion optimisation.

More about Rahul · LinkedIn

Related reading

Want a second set of eyes on a proposal?

Send us the scope and we will tell you what's missing before you sign, no obligation.

Book a Growth Call