A growing SaaS stack can leave UK companies paying for overlapping subscriptions while business data becomes scattered across multiple platforms. Software as a service can make things simpler in terms of access and infrastructure, yet it can lead to redundancies if it isn’t monitored on a consistent basis.
Answering “What is software as a service?” makes it easier to distinguish convenient subscription-based software from a stack that eventually becomes costly to maintain. This approach can cut infrastructure and deployment costs, but its effectiveness depends on how the software is priced and integrated.
This guide covers how SaaS operates, its difference from PaaS and IaaS, which models fit various business requirements, how much UK organisations are charged for it, and what things need to be considered in relation to UK GDPR, data residency, and vendor termination.
In many cases for businesses in the UK, SaaS operates side-by-side with a solution developed for that particular business by software development companies in the UK. It is not about whether the tool provided through a particular approach is better or worse overall, but what the business needs.
Below is the table which summarises the key SaaS facts to consider in evaluation: ownership, cost, deployment time, appropriate usage, risk of compliance in the UK, and the point where licence and integration costs make sense for a bespoke solution.
|
Aspect |
Key details |
|
What it is |
Software delivered over the internet, usually by subscription, with hosting, maintenance and updates handled by the vendor. |
|
Who owns the software |
The vendor owns the platform. Customers pay for access rather than owning the software itself. |
|
Typical pricing |
Common models include per-user monthly fees, tiered plans, usage-based pricing, and freemium access. |
|
Set-up time |
Often days to weeks for standard deployment, compared with longer implementation for on-premises or custom-built systems. |
|
Best fit |
Standard business processes such as email, CRM, accounting, HR, collaboration and project management. |
|
Worst fit |
Highly specific workflows, extensive integration requirements or cases where strict data-residency control is essential. |
|
Main UK risk |
Data residency, international transfers and UK GDPR responsibilities between controllers and processors. |
|
Cost tipping point |
When recurring licence, integration and support costs approach or exceed the long-term cost of building and maintaining a custom system. |
Software as a Service (SaaS) is software accessed over the Internet while the provider hosts, maintains and updates the application on its own or third-party infrastructure. Customers access the software as a managed service and may pay through subscriptions, usage-based charges, freemium plans, or other pricing models.
Practical considerations relate to where the software operates and who controls its operation. The vendor takes care of application and infrastructure operations in SaaS solutions, while the client pays for access to such systems.
This matters when deciding whether to buy SaaS or choose a software development company to build around your workflows.
The main point of difference here is that the former type is managed by the software provider, whereas the latter type of software is installed by the user. All other differences in terms of SaaS vs. on-premise are related to cost, support, customisation, infrastructure management, and exit strategy, and largely stem from this operational model.
|
Factor |
SaaS |
On-premise |
|
Ownership |
Vendor owns and controls the software platform; the customer pays for access. |
Customer typically purchases or licences software for deployment within its own environment. |
|
Where it runs |
On infrastructure managed by the SaaS provider or its hosting partners. |
On infrastructure controlled by the customer or a contracted hosting provider. |
|
Who updates it |
Vendor releases patches, security updates, and new versions centrally. |
Customer or its IT partner plans, tests, and installs updates. |
|
Upfront cost |
Usually lower because infrastructure and deployment costs are spread through recurring fees. |
Often higher due to licences, infrastructure, deployment and configuration. |
|
Payment type |
Subscription, usage-based billing or a combination of recurring charges. |
Licence fees, infrastructure costs and ongoing maintenance or support contracts. |
|
Customisation depth |
Usually limited to configuration, integrations and vendor-supported extensions. |
Greater scope for big changes when the customer controls the application and infrastructure. |
|
Exit difficulty |
Depends on export formats, APIs, contract terms and how deeply the platform is integrated. |
Migration can still be complex, but the customer generally retains greater control over the deployed environment and stored data. |
When comparing SaaS versus bespoke products from MVP development companies, companies should not consider cost alone at the outset. The more unique the process, integration needs or ownership expectations, the greater the importance of distinguishing software operated by the vendor from software operated directly by the customer.
There are certain operational characteristics of SaaS platforms that make them different from locally hosted software applications. These characteristics impact the way customers gain access to the software, how updates are delivered by the vendors, and the manner in which costs accrue.
Before the advent of SaaS, firms used to purchase software licences, install software on their own and do the upgrading. In the latter half of the 1990s, the concept of application service provider emerged, wherein business applications were hosted remotely. This was a precursor to the concept of SaaS.
Browser CRM technology was made popular by Salesforce in the early 2000s through their approach to providing business applications without any need for local installation. This was due to advancements in internet technology and cloud computing, which made it easier to use hosted applications and thus subscription delivery.
The contemporary SaaS model was a result of this change: software vendors provide the service constantly, and customers pay to use the product without having to buy each release separately.
SaaS solutions do not exist in a vacuum, as the data from CRM may have to be transferred into accounting software, the HR system may have to interface with payroll systems, and the support system may have to transfer data to analysis tools. This can be accomplished through API integrations.
In some cases, integration effort, middleware, and maintenance can end up being more expensive than the actual subscription fees themselves. The underlying software framework, API design, and authentication model can affect how much custom integration work is required.
The differences between SaaS, PaaS, and IaaS lie in the amount of the technological stack managed by the provider. The choice will be determined based on whether your company requires pre-made software, an environment for creating apps, or complete control of computing resources.
|
Model |
What you get |
What you manage |
Typical example |
|
SaaS |
Ready-to-use software delivered through the internet. |
Users, permissions, configuration, data, and integrations. |
|
|
PaaS |
Managed environment for building, deploying and running applications. |
Application code, business logic, data and configuration. |
|
|
IaaS |
Virtual servers, storage, networking and other computing resources. |
Operating systems, applications, runtime, security configuration and data. |
|
These models are not conflicting with each other. A firm that is using custom software development services can deliver an application on PaaS or IaaS while using SaaS for CRM, accounting, communication, and other general purposes of business.
Using software as a service for business is most appropriate when the procedure is common among businesses, and there is no commercial benefit in having that particular software built from scratch. These circumstances are mostly applicable to SaaS:
Both PaaS and IaaS can be considered as appropriate approaches when the SaaS solution fails to offer sufficient flexibility to the organisation. This occurs when an agency develops its own product, requires customised infrastructure, or has some other technical requirements that cannot be met by the SaaS solution.
SaaS choice influences implementation level, pricing model, integration requirements, and how well the software aligns with current operations. Horizontal SaaS solutions are typically evaluated by cost, usability, and integration, while vertical SaaS solutions require evaluation of industry processes and compliance reporting.
Horizontal SaaS involves those functions which are common to different industries. The software as a service examples clearly depict how the same category can support a retailer, law firm, or agency without being designed around one sector:
Vertical SaaS products cater to the terminology and workflow of the specific industry. The organisation will begin with a solution that already fits into the industry workflow, meaning there will be less configuration necessary for the platform.
Examples include:
It is essential for financial services, law, and healthcare firms to evaluate the capabilities of the SaaS solution to store regulated data before using the software. Evaluation should consider factors like access controls, auditing, encryption, data retention policies, and data-exporting capabilities instead of relying on the vendor’s feature list.
Key areas to review include:
The advantages and disadvantages of SaaS become more apparent once you consider the aspect of purchasing software through a subscription service. SaaS might be faster and more efficient in terms of set-up and scalability, but the cost is that you will have some of your control handed over to the software vendor.
The main benefits of software as a service come from reducing the amount of infrastructure and maintenance a business has to manage itself. There are more details on how it impacts your product:
There are savings on operations but also dependencies that are harder than expected to assess at procurement time.
Before signing up for the service, ask the SaaS provider these questions and get written answers. These will indicate whether you can recover all necessary information, how long it will take to transfer it elsewhere, and any technical or contractual expenses that might arise upon termination of the subscription. Here is what you need to ask your provider:
Are core records, custom fields, configurations, metadata, permissions, and activities also included?
Verify whether data is exportable to CSV, JSON, XML, and database formats, and whether relationships between records are maintained.
Some companies export only essential information; attachments, comments, and logs need a special request.
Find out if regular limitations still exist during a massive export or if higher ones are possible for extra payment.
Confirm when our access to the account ends, when production data is deleted, and how long backups are retained after termination.
Inquire if the provider assists with the data export, technical support, or other migration services, and whether there are any separate fees for that.
The SaaS cost in the UK may be anywhere from just a few pounds per person monthly up to several hundred for business-specific software. The initial headline subscription fee is just the tip of the iceberg, as factors such as the number of users, plan type, billing schedule, etc. may affect the total cost.
Not all SaaS companies have the same pricing model. There are many that price their products on a per-user or per-month basis, but there are others that charge based on other models like organisation-level or usage models.
|
Pricing model |
How it works |
Best for |
Watch out for |
|
Per user/per month |
The bill increases with the number of paid seats. |
Teams where each employee needs their own account. |
Inactive users can continue generating charges unless licences are regularly removed. |
|
Tiered plans |
Features, limits and support increase across packages such as Starter, Professional and Enterprise. |
Businesses that expect their requirements to grow. |
A single required feature may force an upgrade of the whole account. |
|
Usage-based |
Charges depend on consumption, such as API calls, storage, messages, or AI credits. |
Workloads that vary significantly from month to month. |
Spend becomes harder to forecast when usage spikes. |
|
Freemium |
Basic functionality is free, with paid tiers unlocking additional limits or features. |
Small teams testing a product before committing. |
Business-critical controls, integrations, or reporting may sit behind paid plans. |
|
Flat rate |
One recurring fee covers the account rather than individual seats. |
Teams that want predictable billing as headcount changes. |
The plan may impose limits on transactions, storage, or other usage. |
|
Per-feature add-ons |
Core software has one price, while specific modules or capabilities cost extra. |
Businesses that need only selected advanced functions. |
Several small add-ons can materially increase the final subscription cost. |
Software as a service pricing has huge variation between categories, and thus the numbers provided below should be seen as up-to-date sources of information rather than averages. They were compiled from vendor-provided costs and were valid in the UK in September 2026.
|
Category |
Typical pricing structure |
Example source |
|
Collaboration suite |
£5.40–£10.80 per user/month |
Microsoft 365 Business Basic to Business Standard, paid yearly. |
|
CRM |
£20–£80 per user/month |
Salesforce Starter Suite to Pro Suite. |
|
Accounting |
£18–£70 per organisation/month |
Xero Ignite to Ultimate. Xero explicitly states that it does not charge per-user licence fees. |
|
HR |
From £5 per employee/month |
Ciphr’s published starting price; the vendor notes that the figure is based on 125 employees and a three-year minimum term. |
|
Project management |
£7.70–£23.10 per user/month |
Microsoft Planner Plan 1 to Planner and Project Plan 3, paid yearly. |
Here is an example for further clarification: let’s take a business from the UK with 10 employees that uses Microsoft 365 Business Standard for all employees, Salesforce Starter for 3 salespeople, Xero Grow, CharlieHR, and Planner Plan 1 for all employees.
The stack comes to approximately £329 per month before VAT, based on current published prices. For a 50-person team, the resulting subscription can be around £1,510 per month before VAT.
The price displayed on a SaaS pricing page does not reflect all the costs involved in implementing the product. Before comparing vendors, one must include the costs incurred outside the basic license fee:
It is not the case that the purchase of a seemingly compliant SaaS solution removes your liability for data protection. According to the UK GDPR, and as evidenced in the ICO guidance, if a company acts as a controller, it has an obligation to ensure that processors have appropriate guarantees with regard to the processing of personal data.
This means that in a UK company’s case, the vendor due diligence process should not end with simply spotting a GDPR icon or a privacy policy page link. You need to understand which types of personal data are collected by the software and how they are processed and used.
In a typical SaaS arrangement, the customer becomes the controller because it determines why personal data is processed and for what purpose the service is used. The SaaS provider is normally the processor when it processes personal data under the customer’s instructions.
Even when employing a processor, the duties of the controller do not get discharged. As the ICO states, controllers should be able to appoint processors that can provide appropriate guarantees regarding technical and organisational measures. In addition, processors are liable for any breach of their duties.
When a controller contracts out processing activities, Article 28 states that the processing must be based on a contract or other legal act. This is usually set out in a Data Processing Agreement (DPA) and includes, but is not limited to, the nature, period, purpose, and type of data being processed.
A .co.uk domain or a London office that sells the product does not necessarily indicate where the consumer’s data is processed. The production servers may be located in one place, the backup servers somewhere else, and the support engineers somewhere else.
Inquire of the vendor in writing about the location of primary data, backups, and logging, from where the support staff is able to access it, and which sub-processors will receive any personal information. Do this prior to signing the agreement so that it can be checked along with the DPA and transfer documentation.
When you are about to sign a SaaS agreement, consider the following issues with regard to the vendor’s documentation and written answers. You need to make sure that the location where your data is stored and who has access to it, the transfer process, data retention period, and termination are considered.
|
Area to check |
Why it matters |
|
Data Processing Agreement (DPA) |
Confirms the processing scope, instructions, security duties, sub-processor arrangements, and what happens to personal data when the service ends. |
|
Hosting and backup regions |
Primary storage and backups may be located in different countries, so checking only the advertised hosting region can give an incomplete picture. |
|
International transfers |
Transfers outside the UK may require adequacy coverage, an IDTA, a UK Addendum or another valid mechanism, depending on the circumstances. |
|
Support access |
Engineers or support teams based overseas may be able to access personal data even when the main database is hosted in the UK. |
|
Retention and deletion |
Establish how long deleted accounts, records and backups remain available and whether deletion occurs automatically after termination. |
|
Breach notification SLA |
The contract should specify how quickly the vendor will inform you of a personal data breach and what information it will provide. |
|
Sub-processor list |
Shows which third parties may handle your data and helps you identify additional jurisdictions, services and dependencies in the processing chain. |
When determining how to choose a SaaS provider, benchmark the potential vendors not on the basis of how many features they have, but rather based on how they function compared to how your company currently operates. Here are some factors that can help differentiate between the two.
Step 1. Start with your actual workflow. See if the software will cater to the approvals, handovers, roles, and exceptions that your team works with on a daily basis. If the regular processes are still done through spreadsheets or manual data entry, then it won’t be very effective for operational use.
Step 2. Test the integration you will actually use. Ask the vendor to demonstrate how the platform integrates with your CRM, ERP, accounting software, identity provider, and analytical tools. Check which integrations are native, which need middleware, and whether API access or webhooks sit behind a higher-priced plan.
Step 3. Get specific about data location. Request the names of countries where production data, backups, and logging take place, as well as the current list of subprocessors of the vendor. The Data Processing Agreement (DPA) must reflect these conditions and describe data retention, deletion, and international transfers.
Step 4. Check what security certificates actually cover. It should not be taken as an ISO 27001 certificate alone being sufficient. Request the scope of certification, confirm whether the software as a service offering falls within that scope, and ask whether the provider is also certified under Cyber Essentials.
Step 5. Read the SLA as a contract, not a marketing claim. Look into how uptime is measured, the maintenance periods that are excluded, and what happens after a major outage. Also, the SLA should mention the response time for critical issues, the escalation process, and any service credits.
Step 6. Ask the vendor to explain the exit process. Identify the type of record, file, and configuration data that you can extract and their formats, how long you have access to export them following termination, and whether migration support services cost additional money. This will help you determine how challenging it is to switch service providers.
Step 7. Build a 3-year cost before signing. Consider renewal increase rates, expected user numbers, storage requirements, premium functionality, and implementation considerations. Compare the total cost to the initial quotation so the introductory price doesn’t obscure the fact that the final cost will be significantly higher.
Step 8. Test support before you become a customer. Raise an issue that requires technical assistance during UK business hours and time how quickly staff respond. Also check if the response is helpful and how easy it is for the issue to reach an expert. This will give you a better indication than sales response time.
The SaaS model is very successful when the company uses standardised and repeatable processes that do not need to be heavily customised. However, the model is not effective when the company relies heavily on custom and specific business processes, unique logic, or system control.
Considering Software as a Service as a business strategy often results in too many subscriptions and duplication of tools. It is essential for businesses to audit their entire software stack annually, eliminate duplicates, and get rid of any tools not offering sufficient operational value.
Exit strategy planning must happen before signing the contract. Review data export capabilities, data retention policies, termination provisions, migration assistance, and dependencies before signing. An efficiently managed SaaS stack gives the organisation flexibility, but only when procurement and governance processes are managed intentionally.
Not quite. SaaS is just one example of how cloud computing can be used; that is, to access software on the internet. Cloud computing encompasses PaaS to develop applications as well as IaaS to host the infrastructure.
Some software-as-a-service applications allow certain features to work without Internet access, then synchronise with their servers upon reconnecting. The difference is huge among different vendors. For companies that have engineers, sales personnel, or field teams working off-site, it’s essential to check offline capability before subscribing.
Generally, customers retain the rights to the information that they upload, while the provider holds the right to the application and technology itself. The crucial issue is your ability to download, transfer, and delete the information, and thus, the terms of exporting and retention must be carefully considered.
Recovery of VAT on SaaS will depend on whether the UK rules on recovery for input taxes are met. However, it can vary based on the supplier location and invoice method used. Seek professional advice to clarify whether recovery is possible in your case. This is not tax advice.
Share this article: