Modernization and software Guide
Platform Engineering in 2026: When an Internal Developer Platform Pays and How to Build One
Nine in ten organizations now say they run an internal developer platform, yet the research behind the movement is thinner than its marketing, and three cloud and tooling vendors are retiring their own platform products. This guide sets out what platforms measurably change, when one pays, what it costs and how AI coding agents and supply-chain attacks have changed the case.
For CTOs, VPs of engineering and heads of infrastructure deciding whether to build, buy or shrink an internal developer platform.
The short answer
An internal developer platform pays when many teams repeat the same pipeline, infrastructure, security and cost work, a small team can turn that work into self-service defaults, and you measure the friction it removes from the start. Keep the platform thin, run it as a product with a product manager, and keep its definitions in portable code so a retired tool does not strand you.
Key takeaways
- Platforms are now near universal: 90% of organizations in Google's 2025 DORA research use one, and 76% have dedicated platform teams.1
- The measured gains are modest. In DORA's 2024 research, platform users reported 8% higher individual productivity and 10% higher team performance, while throughput fell 8% and change stability fell 14%.2
- The evidence base is thin: only 2 of 88 sources in a 2026 literature review were top-tier research mainly about platform engineering, and scorecards have no peer-reviewed evidence of working.3
- Vendors are retiring platform products. AWS Proton support ends on October 7, 2026, Azure Deployment Environments retires on February 22, 2027 and Atlassian plans to end Compass support on December 31, 2027.456
- The strongest 2026 case is control. Supply-chain attacks run through build pipelines, only 4% of organizations pin all their GitHub Actions to commit hashes, and the EU Cyber Resilience Act made vulnerability reporting mandatory on September 11, 2026.78
- AI coding agents raise the stakes: DORA found AI's effect on organizational performance is strong where platform quality is high and negligible where it is low.1
Platform engineering means building an internal product, usually called an internal developer platform, that gives engineering teams self-service paths to build, test, deploy and run software on approved defaults. A developer portal such as Backstage is often its front door, with a catalog of services, owners and documentation. Behind it sit templates, pipelines, infrastructure code and policies. Google's DORA research program, the longest-running study of software delivery, reports that by 2025 "adoption had become nearly universal, with 90% of organizations reporting the use of an internal developer platform and 76% establishing dedicated platform teams."1 Having a platform is no longer a distinction. What matters in 2026 is whether yours is any good, what it costs and what it controls.
- 90%of organizations report using an internal developer platform, and 76% have dedicated platform teams1
- 14%drop in change stability among platform users in DORA's 2024 research, alongside an 8% drop in throughput2
- 29.6%of platform teams do not measure success at all, in a 2025 survey of 518 engineers9
What the research measured
The most cited evidence is DORA's 2024 report. Platform users had "8% higher levels of individual productivity and 10% higher levels of team performance," and an organization's software delivery and operations performance rose 6% with a platform. The same report found that "throughput and change stability saw decreases of 8% and 14%, respectively, which was a surprising result."2 DORA offered two explanations. A platform adds handoffs between systems, and each one adds time. And respondents required to "exclusively use the platform to perform tasks for the entire app lifecycle" saw a 6% fall in throughput, which DORA linked to being forced onto a platform "when it might not be fit for purpose."2 Its advice was to be user-centered and to aim for developer independence, the ability to do a task without waiting on an enabling team, which DORA associates with a 5% productivity improvement.1
| Measure in DORA's 2024 research | Platform users compared with non-users |
|---|---|
| Individual productivity | 8% higher |
| Team performance | 10% higher |
| Software delivery and operations performance | 6% higher |
| Throughput | 8% lower; 6% lower again where platform use was exclusive |
| Change stability | 14% lower |
DORA's 2025 report, based on nearly 5,000 technology professionals, moved the question from whether to have a platform to how good it is.10 It found that "when platform quality is high, the effect of AI adoption on organizational performance becomes strong and positive," while with a low-quality platform the effect "is negligible."1 The platform capability most correlated with a good user experience was "clear feedback on the outcome of my tasks."1
Beyond DORA, most surveys come from companies that sell platform tools, and they measure pain and adoption more than results. The State of Platform Engineering Vol 4, from 518 engineers, found that 29.6% of platform teams "do not measure success at all," 55.9% of companies run more than one platform and 47.4% of platform initiatives work on an annual budget between $0 and $1 million.9 Port, a portal vendor, reports that 78% of engineering teams wait a day or more for SRE or DevOps help.11 Atlassian's 2025 survey of 3,500 developers and managers found 50% lose 10 or more hours a week, "largely due to organizational inefficiencies."12 Academic work trails all of this. A 2026 literature review in Frontiers in Computer Science found that only 2 of its 88 sources came from top-tier venues with platform engineering as the main topic, and that for scorecards, the main governance tool in portals, "no peer-reviewed empirical evidence of effectiveness exists despite widespread commercial adoption."3
What companies report
Companies publish the scale of their platforms far more often than their payback. The table separates figures a company published itself from those published by a vendor that sold it something.
| Company and platform | What was published | Source and year |
|---|---|---|
| Uber, SubmitQueue for CI | CI resource usage cut by 53%; Go P95 wait fell from 33.69 to 18.64 minutes; more than 4,500 engineers rely on it daily13 | Uber, 2025 |
| Uber, Up for deployment | 4,500 services deployed more than 100,000 times a week by 4,000 engineers; about 2,000,000 compute cores migrated over two years, returning "tens of millions of dollars of extra capacity"14 | Uber, 2023 |
| Spotify, Backstage | Time for a new engineer to merge a tenth pull request fell from "over 60 days" to "only 20"15 | Spotify, 2021 |
| Mercado Libre, Fury | More than 30,000 microservices and NoOps tooling for 16,000 developers16 | QCon talk, 2024 |
| Zalando | A team of 9 ran more than 140 Kubernetes clusters; 3,000+ production deployments a week17 | CNCF case study, 2018 |
| Skyscanner | 456 services deployed 3,733 times in a month; an idea to monitored production in 30 minutes18 | InfoQ talk report, 2018 |
| Toyota North America, on Backstage | Cost reduction of more than $10 million in 2022, including about $5 million a year in cloud infrastructure19 | Published by Spotify, a Backstage seller |
The pattern is consistent. The strongest numbers come from a company's own telemetry on one narrow job, such as Uber's CI queue. Portal-wide savings figures arrive through vendors. And the figures age: Spotify, which created Backstage, last published an onboarding number in 2021.15
Where platforms fail
The documented failure is adoption. In 2023 Spotify officials estimated publicly that "the average Backstage adoption rate is 10%" inside the companies that had installed it.20 Backstage now has 3,400 known adopters, by Spotify's count.21 Thoughtworks has placed "miscellaneous platform teams" on Hold in its Technology Radar since 2022, describing teams that carry the platform label without "clear outcomes or a well-defined set of customers."22 A portal that nobody opens is a cost with no return, and nearly a third of platform teams would not know, because they do not measure.9
The second failure is concentration. A shared platform turns one mistake into everyone's outage. Roblox was down for 73 hours in October 2021, and its postmortem says "a single Consul cluster supporting multiple workloads exacerbated the impact" of two unrelated faults.23 In January 2023 CircleCI disclosed that an attacker had taken "customer environment variables, tokens, and keys" from its systems, and its customers had to rotate their secrets.24 A platform team has to design for its own failure, with separate control planes for critical services and secrets that expire.
When a platform pays
No research-grade threshold says when to start. The team-size cutoffs in circulation, such as 20 or 50 engineers, come from vendors and marketing sites without a method. The useful guidance is about scope. Team Topologies, the book most platform teams cite, calls for a "thinnest viable platform" and says it "could be just a wiki page" that records which cloud services you use and how.25 For sizing, the best benchmark we found comes from DX, a vendor now owned by Atlassian: across 39 companies, most dedicate 2 to 6% of engineering headcount to central developer productivity, with an average of 4.7%, and the share falls as companies pass 1,000 engineers.26
| What you see | Start with | Build a platform when |
|---|---|---|
| Every team writes its own pipelines and infrastructure code | Shared pipeline templates and a module repository | Several teams copy and drift, and fixes do not reach them |
| Engineers wait days for environments or access | Documented requests with an owner and a target time | The same requests repeat and can be safely automated |
| Nobody knows who owns a service | A service catalog in a spreadsheet or Git file | The catalog needs to stay current without anyone editing it |
| Audits ask for change records, SBOMs and review logs | Evidence collected by hand for each audit | Evidence should come out of every build automatically |
| Cloud bills cannot be split by team | Required tags and a monthly review | Untagged or oversized resources should be blocked before they deploy |
| AI coding agents are opening pull requests | Agent use on a sandboxed pilot | Agents need scoped credentials, network limits and audit logs at scale |
Four conditions separate platforms that pay from those that drift. There is a named friction with a number on it, such as days to a first deploy or hours waiting for access. Enough teams repeat the same work that a shared default beats each doing it alone. The team stays small and is run as a product: 52% of respondents in Puppet's 2024 survey called a product manager crucial to a platform team's success.27 And the platform is measured from its first week, against the friction it was built to remove and against DORA's delivery measures, so a fall in throughput or stability shows up early.1
Vendors are retiring platform products
Between 2025 and 2026, AWS, Microsoft and Atlassian each announced the end of a first-party platform or portal product, while open-source foundations strengthened the layer underneath.
| Product or project | Status, October 2026 |
|---|---|
| AWS Proton | Support ends October 7, 2026; after that date "all data will be deleted." AWS lists Harmonix, a Backstage-based option "not maintained by an AWS service team," among the alternatives4 |
| Amazon CodeCatalyst | "No longer open to new customers"; AWS points customers to GitLab Duo with Amazon Q28 |
| Azure Deployment Environments | Retires February 22, 2027, when create, deploy and other write operations are expected to be blocked5 |
| Microsoft Dev Box | Closing-down period began September 14, 2026; retires September 18, 2028, with Windows 365 recommended29 |
| Atlassian Compass | Moving into DX; support planned to end December 31, 20276 |
| Backstage | Open source; a CNCF Incubating project since March 15, 2022, not yet graduated30 |
| Crossplane and Kyverno | Graduated in the CNCF on November 6, 2025 and March 24, 20263132 |
| Terraform and OpenTofu | IBM completed its $6.4 billion HashiCorp acquisition on February 27, 2025; OpenTofu is the open-source fork in the CNCF Sandbox3334 |
The lesson for a build-or-buy decision is to keep the definitions portable. Service catalogs, templates, infrastructure code and policies should live in your Git repositories in open formats, with the portal as a replaceable layer on top. Atlassian's migration guide shows why: Compass scorecards do not carry over to the replacement product and have to be recreated.6
What it costs
| Option | Published price | What else you pay for |
|---|---|---|
| Backstage, self-hosted | Free open-source license | A dedicated team; Roadie, which sells hosted Backstage, says teams happy with self-hosting had at least three engineers, about $450,000 a year35 |
| Port | Free up to 15 seats; Basic from $30 and Standard from $40 per seat per month36 | Entity and run limits per tier |
| Roadie, hosted Backstage | Teams plan $24 per developer per month, open to "existing subscribers only"37 | New customers get custom plans |
| Spotify Portal for Backstage | AWS Marketplace lists a license key at $35,000 per 12 months, billed by units38 | The number of units needed is set under contract |
| HCP Terraform | Free up to 500 managed resources with unlimited users; paid tiers from $0.10, $0.47 and $0.99 per resource per month3940 | Cost grows with the estate, not with seats |
The largest cost is people. Using DX's average of 4.7% of engineering headcount, a 200-engineer organization would staff about nine people across developer productivity, which covers the platform and the tooling around it.26 Zalando's team of 9 running more than 140 clusters for its engineering teams is the same order of size.17 A platform that needs far more people than that, relative to the engineers it serves, is usually doing too much.
AI coding agents make the platform the control plane
AI coding agents follow whatever defaults they are given, at volume. That is why DORA calls AI an amplifier and finds it pays off only on a high-quality platform.1 In the same research, 90% of respondents used AI at work and 30% reported little or no trust in the code it generates.10 The platform is where an agent's permissions, network access and audit trail are set, so it is where agent risk is managed.
Portals are adding Model Context Protocol (MCP) servers so agents can query the catalog and trigger actions, but maturity varies. Backstage's MCP integration arrived in version 1.40 and is "highly experimental and could be subject to breaking changes."41 Port launched its MCP server in June 2025 noting that agents using it "cannot yet execute actions."42 GitHub's remote MCP server became generally available in September 2025 with OAuth-based authentication.43 The controls need checking too. GitHub's documentation says its Copilot coding agent firewall "only applies to processes started by the agent via its Bash tool" and that "sophisticated attacks may bypass the firewall."44 A platform for agents needs scoped, short-lived credentials, an allowlist of MCP servers and network destinations, and logs a security team can read.
Supply-chain attacks run through the pipeline
The strongest case for a platform in 2026 is control of the build-and-publish path, because that is where the major supply-chain attacks of the past three years ran.
| Date | Incident | Default a platform template would set |
|---|---|---|
| March 2024 | Malicious code in XZ Utils 5.6.0 and 5.6.1, CVE-2024-309445 | Pinned base images and dependencies, updated centrally |
| March 14 to 15, 2025 | tj-actions/changed-files tags repointed to a malicious commit, exposing CI secrets in more than 23,000 repositories46 | Third-party actions pinned to commit hashes from an allowlist |
| September 2025 | Shai-Hulud, a self-replicating worm, compromised more than 500 npm packages47 | Short-lived publishing credentials and lockfile-only installs |
| May 11, 2026 | 84 malicious versions across 42 TanStack packages, via a pull_request_target workflow, cache poisoning and an OIDC token taken from runner memory48 | Risky workflow triggers banned, caches isolated, each publish approved |
Guidance alone does not change these defaults. Datadog's State of DevSecOps 2026 found that only 4% of organizations pin all public GitHub Actions to commit hashes, the median dependency is 278 days out of date and 50% of organizations adopt new library versions within 24 hours of release, the window in which worms spread.7 Verizon's 2026 Data Breach Investigations Report found that exploiting software flaws, at 31% of breaches, has passed stolen credentials as the top entry point for the first time, and that third parties are now involved in 48% of breaches.49 A template that pins, scans and signs by default changes these numbers for every team at once, and policy as code enforces them at deployment.32
Rules that ask for evidence from every build
| Rule or standard | What it requires | What the platform supplies |
|---|---|---|
| EU Cyber Resilience Act | Since September 11, 2026, manufacturers must send an early warning of an actively exploited vulnerability within 24 hours and a full notification within 72 hours8; from December 11, 2027, a machine-readable SBOM covering at least top-level dependencies50 | An SBOM and dependency inventory per build, and a fast path to find affected products |
| EU Digital Operational Resilience Act, Article 9 | Financial entities must keep documented, risk-based controls for ICT change management, including software changes51 | Change records, approvals and deployment logs from the pipeline |
| SLSA v1.2 | Build and source tracks for provenance and source control integrity52 | Signed provenance from a hardened build service |
| US federal software attestation | OMB M-26-05 rescinded M-22-18 and M-23-16 on January 23, 2026; agencies may still use the attestation form and may require SBOMs by contract53 | Evidence buyers can request even where it is no longer mandated |
| NIST SSDF 1.2 | SP 800-218r1 published as a draft for public comment on December 17, 202554 | A control map to keep current as the final version lands |
Cost control follows the same route. The State of FinOps 2026, with 1,192 respondents representing more than $83 billion in annual cloud spend, names shift left, giving engineers cost information before they deploy, as a top priority and reports growing partnership with platform engineering teams. It also found 98% of respondents now manage AI spend.55 The waste is structural: CAST AI, a vendor, measured average CPU utilization across Kubernetes clusters at just 10% and memory at 23% across more than 2,100 organizations.56 Platform defaults address this directly, with resource requests and autoscaling set in templates, required ownership tags, preview environments that expire and policies that reject oversized resources.
Shared templates and a wiki
The thinnest viable platform
- Pipeline and infrastructure templates in Git
- A catalog file per service
- No new product to run
- Relies on teams adopting updates
Buy a hosted portal
Port, Roadie, Spotify Portal and others
- Quick catalog and scorecards
- Per-seat or license pricing
- Data and scorecards need an exit plan
- Still needs templates and policies behind it
Build on open source
How we advise, once friction is measured
- Backstage or a lighter catalog over Git
- Templates, policy as code and infrastructure code you own
- A small team run as a product
- Portable when any tool retires
How to build a platform that pays
- Measure the friction Record time to first deploy, waiting time for environments and access, change failure rate and the hours teams spend on pipelines and audits.
- Pick one path Choose the most repeated job, usually a new service from repository to production, and make it self-service end to end.
- Set the defaults Build pinned dependencies, signed builds, SBOMs, ownership tags, resource limits and short-lived credentials into that path.
- Keep it in Git Hold templates, infrastructure code, catalog entries and policies in open formats so the portal stays replaceable.
- Run it as a product Give the platform a product manager, publish a roadmap, and let teams leave the path when it does not fit, with a clear cost to doing so.
- Add agents with limits Give AI coding agents the same paths with scoped credentials, network allowlists, approved MCP servers and audit logs.
- Review every quarter Compare the friction numbers and DORA's delivery measures with the baseline, and retire features nobody uses.
Questions before funding a platform team
- Which friction will the platform remove, and what does it measure today?
- How many teams repeat that work, and what share of engineering headcount will the platform team take?
- Which security, compliance and cost defaults will every build get?
- Where do our templates, catalog and policies live if we replace the portal?
- How will we spot a fall in throughput or change stability after rollout?
- What will AI coding agents be allowed to do through the platform, and who reviews it?
The case for platform engineering has shifted. The productivity argument rests on self-reported gains and a measured delivery dip that good design has to remove. The argument that holds up in 2026 is control: a shared path is where pinned dependencies, short-lived credentials, SBOMs, change records, cost tags and agent permissions become defaults instead of requests. The question to ask is which defaults you would enforce and what they would prevent, with the portal chosen afterward as a replaceable layer.
This is how we approach platform work in our cloud and DevOps engagements: measure the friction first, build the thinnest path that removes it, put security, cost and agent controls into that path as code in your repositories, and grow the platform only where the numbers show teams using it.
Questions leaders ask
What is platform engineering?
Platform engineering is the practice of building an internal product that gives software teams self-service paths to build, test, deploy and run their services on approved defaults. The product is usually called an internal developer platform, and a developer portal such as Backstage often serves as its front door.
What is the difference between an internal developer platform and a developer portal?
The platform is the set of paths and defaults: pipeline templates, infrastructure code, policies, environments and credentials. The portal is the interface on top, typically a service catalog with owners, documentation and buttons that start platform workflows. A portal without paths behind it is a directory, and paths without a portal still work through Git and the command line.
When should a company invest in platform engineering?
When several teams repeat the same pipeline, infrastructure, security and cost work, and you can measure the friction it causes. No research sets a team-size threshold. Start with the thinnest viable platform, which can be shared templates and a wiki page, and grow it as measured demand appears.
How big should a platform team be?
DX's 2026 benchmark of 39 companies found most dedicate 2 to 6% of engineering headcount to central developer productivity, with an average of 4.7%, and the share falls above 1,000 engineers. Popular ratios such as one platform engineer per eight to twelve developers imply roughly double that and have no research behind them.
Does platform engineering improve developer productivity?
Modestly, by self-report. In Google's DORA 2024 research, platform users reported 8% higher individual productivity and 10% higher team performance, but throughput fell 8% and change stability fell 14%. DORA's 2025 research found platform quality decides whether AI adoption improves organizational performance.
Should we use Backstage?
Backstage is the most widely used open-source portal framework, with 3,400 known adopters, and a CNCF Incubating project. Self-hosting it needs a small dedicated team. Hosted versions and commercial portals trade that team for license fees. Whichever you choose, keep your catalog, templates and policies in Git so the portal can be replaced.
What replaces AWS Proton?
AWS ends support for Proton on October 7, 2026 and deletes its data after that date. AWS lists CloudFormation Git sync, Harmonix (a Backstage-based partner solution), CodePipeline with CodeBuild, and GitHub Actions as alternatives. AWS says deployed infrastructure remains intact, but templates and pipelines need a new home.
Sources
- Capabilities: platform engineeringDORA, Google Cloud
- Accelerate State of DevOps 2024 (full report)DORA, Google Cloud, 2024
- Platform engineering: a multivocal literature reviewAnjum, Frontiers in Computer Science, 2026
- AWS Proton end of supportAWS documentation
- Azure Deployment Environments retirement guideMicrosoft Learn
- Migrate from Compass to DXAtlassian Support
- State of DevSecOps 2026Datadog, 2026
- Cyber Resilience Act: reporting obligationsEuropean Commission
- Announcing the State of Platform Engineering Vol 4platformengineering.org, December 2025
- Announcing the 2025 DORA reportGoogle Cloud, September 2025
- State of internal developer portals 2025Port
- State of developer experience report 2025Atlassian, 2025
- Slashing CI costs at UberUber Engineering, 2025
- Up: portable microservices ready for the cloudUber Engineering, 2023
- How Backstage made our developers more effectiveSpotify Engineering, September 2021
- Scaling innovation with NoOps: how Mercado Libre manages 30,000 microservicesQCon San Francisco, November 2024
- Zalando case studyCNCF, 2018
- Skyscanner scaled continuous deliveryInfoQ, March 2018
- Adopter spotlight: ToyotaSpotify for Backstage, 2023
- Behind the scenes, Spotify Backstage a work in progressTechTarget, November 2023
- Getting Backstage in front of a shifting dev experienceStack Overflow blog, September 2025
- Miscellaneous platform teamsThoughtworks Technology Radar
- Roblox return to service, 10/28 to 10/31 2021Roblox, January 2022
- CircleCI incident report for January 4, 2023 security incidentCircleCI, January 2023
- What are the core team types in Team Topologies?Team Topologies
- Developer productivity headcount benchmarks, Q1 2026DX, January 2026
- Puppet's 2024 State of DevOps reportPerforce, 2024
- Migrating from Amazon CodeCatalystAWS documentation
- Microsoft Dev Box retirement guideMicrosoft Learn
- Backstage project pageCNCF
- CNCF announces graduation of CrossplaneCNCF, November 2025
- CNCF announces Kyverno's graduationCNCF, March 2026
- IBM completes acquisition of HashiCorpIBM, February 2025
- OpenTofu project pageCNCF
- The true cost of self-hosting BackstageRoadie
- PricingPort
- PricingRoadie
- Spotify Portal for BackstageAWS Marketplace
- Continuing HCP Terraform's enhanced free tier experienceHashiCorp
- HashiCorp pricingHashiCorp
- Backstage release v1.40.0Backstage
- Port MCP serverPort, June 2025
- Remote GitHub MCP server is now generally availableGitHub changelog, September 2025
- Customizing or disabling the firewall for Copilot coding agentGitHub Docs
- Reported supply chain compromise affecting XZ Utils, CVE-2024-3094CISA, March 2024
- tj-actions/changed-files security advisory, CVE-2025-30066GitHub Advisory Database
- Widespread supply chain compromise impacting npm ecosystemCISA, September 2025
- npm supply chain compromise postmortemTanStack, May 2026
- 2026 Data Breach Investigations ReportVerizon, May 2026
- Regulation (EU) 2024/2847, the Cyber Resilience ActEUR-Lex
- Regulation (EU) 2022/2554, the Digital Operational Resilience ActEUR-Lex
- What's new in SLSA v1.2SLSA, OpenSSF
- OMB rescinds Biden-era software security memorandaMayer Brown, February 2026
- SSDF version 1.2 available for public commentNIST, December 2025
- State of FinOps 2026FinOps Foundation, Linux Foundation, 2026
- Kubernetes cost benchmark report 2025CAST AI, 2025
Written by DigyAi Engineering from the systems we build and run. Every figure links to its public source, and every link and figure was checked on October 6, 2026. No client data appears in our insights.