Menu
IndustriesPortfolioBlogAbout
For Founders

Fixed Price vs Time and Materials vs Retainer: Which Software Contract Should You Sign?

Fixed price, time and materials, or retainer: who carries the risk in each software contract, the clauses that decide your outcome, and how to compare quotes.

Solyio Engineering9 min read

The short answer

  • check_circleChoose fixed price when scope can be written down precisely, time and materials with a not-to-exceed cap for genuinely exploratory work, and a retainer only after launch for ongoing maintenance and improvements.
  • check_circleA fixed price includes a contingency for the vendor's risk, commonly somewhere around 15-35% of the estimate, so you pay a premium in exchange for cost certainty.
  • check_circleTime and materials is only safe with three controls: a not-to-exceed ceiling, a weekly burn report, and a written scope ledger recording every change.
  • check_circleIP ownership should transfer to you on full payment of the fees for custom work, and the contract should list deliverables as repository, infrastructure, credentials and documentation — not just "the app".
  • check_circleContracts written in 2026 should also cover who owns prompts and evaluation sets, how AI model costs are billed, and whether your data may be used to improve the vendor's own products.

The straight answer

Use fixed price when the scope can be written down precisely — which, with a proper discovery phase, covers most projects if they are broken into phases. Use time and materials (T&M) with a cap for work you cannot yet define. Use a retainer after launch, for maintenance and a steady flow of improvements.

The model matters because it decides who pays when reality differs from the plan. Everything else in the contract is about making that allocation fair and visible.

The three models on one table

Each model moves risk to a different party and fails in a predictable way. Knowing the failure mode is more useful than knowing the definition.

Fixed priceTime and materialsRetainer
Who carries overrun riskVendor, within agreed scopeClientShared, capped per month
Cost of changing scopeChange order requiredJust more hoursAbsorbed if within the monthly allowance
Price premiumContingency built into the priceNone, but no ceiling by defaultOften a small discount for commitment
Typical failureArguments over what was in scopeBudget drift with no clear endpointPaying monthly for little delivered
Cash flow for clientPredictable, milestone-basedVariable, usually monthlyFlat monthly
Best forDefined builds and phasesDiscovery, research, unclear problemsPost-launch maintenance and iteration
How the three common contract models compare.

The hidden premium inside a fixed price

Every fixed price contains a contingency: the amount the vendor adds to cover estimate uncertainty. You are buying insurance against overruns, and like all insurance it costs something even in the years nothing goes wrong.

How agencies price uncertainty

Contingency commonly lands somewhere around 15-35% of the base estimate, depending on how well the scope is defined and how many unknown integrations there are. The math is simple once written out.

Scope clarityContingencyFixed priceWhat drives it
Detailed spec, known APIs~15%~$23,000Few unknowns remain
Clear goals, some open questions~25%~$25,000One or two integrations untested
Short brief, legacy systems~35%~$27,000Data quality and integrations unverified
Illustrative contingency math on a $20,000 base estimate.

When the premium is worth paying

Pay the premium when budget certainty matters more than the lowest possible cost — a board-approved budget, a grant, or a founder spending personal money. The cheapest way to reduce it is a short, paid discovery phase that turns unknowns into knowns before the main price is set.

Where time and materials goes wrong, and how to cap it

T&M fails when nobody can say how much has been spent against what was delivered. It is safe with three controls in the contract.

Not-to-exceed ceilings that still allow change

A not-to-exceed (NTE) ceiling caps spend for a defined scope. The vendor must stop and ask before crossing it. You keep T&M's flexibility, but the budget cannot drift silently.

Sprint budgets and the weekly burn report

Require a weekly report with hours used, hours remaining against the NTE, what shipped, and what is at risk. If a vendor cannot produce this in fifteen minutes, they are not tracking it.

The scope ledger

Keep one shared document listing every scope change: date, who requested it, estimated impact and approval. It ends most billing disputes before they start because the history is not a matter of memory.

What a retainer should and should not include

A good retainer buys a defined capacity or set of outcomes each month, with response times you can hold the vendor to. A bad one buys vague availability.

Hours versus outcomes

Hour-based retainers are simple to measure but reward slowness. Outcome-based retainers — for example, "security patches applied within a week, up to N small changes a month" — are harder to define but align better. Many teams combine a small base of guaranteed hours with named recurring outcomes.

Rollover, expiry and the unused-hours trap

Unused hours that expire each month quietly raise your effective rate. Negotiate a limited rollover, such as one month, or a quarterly true-up.

Response-time SLAs with consequences

Define severity levels and response times — for example, production down versus minor bug — and what happens when the vendor misses them, such as a service credit. An SLA without a consequence is a hope.

Is your retainer a subscription to nothing?

Test it quarterly: list what the retainer delivered, estimate what it would have cost as separate small projects, and compare. If the retainer costs much more for months running, resize it or end it.

The hybrid model we use

Our default is phased: scope and quote the first phase at a fixed price, then fix-price later phases or move to a retainer after launch. It gives you cost certainty on the part you can define and avoids pricing guesswork into the parts you cannot.

Solyio projects are quoted at a fixed price before work begins, with a deposit and milestone payments tied to defined stages. Public starting points are Launch from $1,900 and Build from $6,900, with Scale quoted to scope — see pricing. Our Terms of Service and refund policy describe how deposits, milestones and cancellations work.

The nine clauses that decide your outcome

Pitch decks do not decide how a project ends; these nine clauses do. Read them before you read anything else in the agreement.

ClauseWhat good looks likeRed flag
IP assignmentOwnership of custom deliverables transfers on full payment; any pre-existing vendor components are licensed to youVendor keeps ownership, or rights are unclear
Third-party and open-source licensesVendor warrants licenses are compatible with your use and lists major dependenciesNo mention of licenses at all
Deliverables definitionRepository, deployed infrastructure, credentials and documentation"The website" or "the app"
Acceptance criteriaWritten criteria and a fixed test window, e.g. 5-10 business daysAcceptance at the vendor's discretion
Change ordersWritten process with price and timeline impact before work startsChanges billed after the fact
Termination for convenienceEither side can exit; you pay for work done plus a fair notice feeNo exit, or you forfeit everything paid
Credential custodyAccounts in your name from day one; vendor has delegated accessVendor-owned cloud, domain or app store accounts
WarrantyDefined period to fix defects against the agreed spec at no chargeNo warranty, or one that excludes most bugs
Liability and AI-generated codeReasonable mutual cap; clear statements on AI-assisted code and licensingUnlimited liability on one side, or silence on AI
What to look for in each clause. Wording varies; the intent is what matters.

IP assignment: on payment, not on signature

Transfer on full payment is standard and fair: the vendor is protected against non-payment, and you own the custom work once you have paid for it. What you should reject is ambiguity. The clause should name what transfers, and separately state how any vendor-owned frameworks or components are licensed to you.

Credential custody and when escrow is real

Source code escrow is often theater on small projects: if the repository, cloud account and domain are in your name from day one, you already have what escrow promises. Escrow earns its cost when you depend on software the vendor hosts and controls.

Termination and a fair kill fee

A fair termination clause lets you stop, pay for work completed, and receive everything produced so far. A kill fee equal to a short notice period, commonly a few weeks of planned work, compensates the vendor for reserved capacity without trapping you.

Payment schedules compared

Milestone-based schedules protect both sides best, because payment follows visible progress.

ScheduleHow it worksRisk to clientRisk to vendor
50 / 50Half up front, half on completionHigh — half paid before seeing anythingHigh — final half withheld over small issues
30 / 40 / 30Deposit, mid-point, completionModerateModerate
Deposit + milestonesDeposit, then payment per delivered milestoneLow — pay as value appearsLow — steady cash flow
Monthly in arrears (T&M)Invoice hours worked each monthBudget drift without an NTEDelayed payment
Common payment structures for a fixed-price project.

Why 50/50 is a red flag in both directions

A 50/50 split puts too much at stake at two single moments. Clients pay heavily before any evidence of progress; vendors then carry the whole second half against a subjective "done". Smaller, more frequent milestones remove both problems.

AI-era clauses most older templates miss

Contract templates written before AI-heavy development usually say nothing about prompts, models or AI-generated code. Add four clauses.

  1. 1Prompts, evaluation sets and fine-tunes. State that prompts, evaluation data and any fine-tuned models built for your project are deliverables you own on payment.
  2. 2Model vendor costs. Say whether API costs are passed through at cost, marked up, or capped, and whose account the keys live in. Your own account is best.
  3. 3AI-assisted code. Ask the vendor to confirm that all code, including AI-assisted code, is reviewed by their engineers and meets the license warranties in the contract.
  4. 4Use of your data. Prohibit the vendor from using your data or outputs to train or improve their own products or models without written consent.

How to compare two quotes that are not comparable

Normalize both quotes to the same scope and the same worst case before comparing prices. Here is a worked example.

ItemQuote A (fixed)Quote B (T&M)
Headline price$18,000Estimated $15,400-$20,900 (140-190 hours at $110)
Data migrationExcluded — add ~$3,000Included
Revision rounds2 includedBilled as hours
Warranty30 daysNone stated — negotiate
Worst case$21,000 plus approved change orders$22,000 not-to-exceed ceiling
Normalized comparison~$21,000$15,400-$22,000
Illustrative example. Quote A is fixed price; Quote B is T&M with a ceiling.

After normalizing, the quotes are close. The decision now turns on how confident you are in the scope: confident, take A for certainty; unsure, take B for flexibility — but only with the ceiling in writing.

Red flags in the contract, not the pitch

  • Deliverables described only as "the website" or "the platform".
  • Cloud, domain or app store accounts registered to the vendor.
  • No acceptance window, or acceptance at the vendor's sole discretion.
  • No termination for convenience, or forfeiture of all fees paid.
  • Silence on third-party licenses and AI-generated code.
  • T&M with no ceiling and no reporting obligation.

Frequently asked questions

Who owns the code — the agency or us?add

Normally you own the custom work once the project fees are paid in full. Agencies often keep ownership of pre-existing frameworks or components they reuse and license them to you. Make sure the contract names what transfers and how any retained components are licensed.

Is a 50% upfront deposit normal?add

It happens, but a smaller deposit followed by milestone payments is safer for both sides. Large upfront payments put your money at risk before any progress is visible, and a large final payment puts the vendor at risk over subjective sign-off.

Can I get a fixed price without a discovery phase?add

For small, well-understood projects, yes. For anything with unknown integrations or unclear requirements, a fixed price without discovery will either carry a large contingency or lead to change-order disputes. A short paid discovery phase usually saves money overall.

What is a fair kill fee?add

Payment for all work completed plus a modest notice fee, commonly equal to a few weeks of planned work, to cover capacity the vendor reserved. You should receive everything produced up to the termination date.

Do I need source code escrow on a $20,000 project?add

Usually not. If the repository, hosting account, domain and credentials are in your name from the start, you already hold what escrow would protect. Escrow matters more when you depend on software the vendor hosts and controls.

What happens to my project if the agency goes out of business?add

If you own the accounts and have repository access, another team can take over with limited disruption. If the vendor controls the accounts, recovery can be slow and costly — which is why credential custody belongs in the contract, not in trust.

contractspricing modelshiring an agencystatement of workip ownership
S
Solyio Engineering
Product & Platform Team

The engineers and architects who build Solyio's client platforms — web, mobile, cloud, and AI automation. Everything here comes out of shipped client work.

Keep reading

rocket_launchFor Founders25 min read

How to Write an MVP Scope Document a Development Agency Can Actually Quote

Agencies do not quote a vision, they quote decisions. Here are the nine sections that turn an idea into a fixed number, the four cut rules that shrink the feature list, and a fill-in template you can send to three firms the same day.

Readarrow_forward