A headless build splits a decision that used to be one purchase. The commerce backend holds the catalog, the cart, and the orders, while everything a shopper loads runs somewhere else. That somewhere else decides how the storefront behaves in the first hour of a sale, how fast a price change reaches a cached page, and which compliance controls stay with your team. Choosing where a headless storefront runs is an infrastructure evaluation across ten criteria, and the four platform categories separate on all ten.
Key takeaways:
Going headless converts one vendor decision into six operational ones, and no platform category wins all six.
Point-of-presence count predicts storefront latency poorly, because the function-to-backend round trip dominates any page carrying live cart or pricing data.
Cache invalidation is the criterion that most often fails to port, since identical Next.js code revalidates differently depending on what the platform's content delivery network (CDN) can purge.
Bot-driven image transformations and challenged requests are the peak-season cost drivers that cost models usually miss.
Payment Card Industry Data Security Standard (PCI DSS) requirements 6.4.3 and 11.6.1 stay with the merchant no matter who holds the hosting attestation.
Copy link to headingWhat ecommerce hosting means for a headless storefront
Ecommerce hosting for a headless storefront is the infrastructure a team runs between the shopper and the commerce API. An all-in-one commerce platform ships that infrastructure as one product with one bill and one support contract. Going headless assembles it from six layers instead, which is why the evaluation looks nothing like picking a website builder.
Decoupling the frontend from the commerce backend is what makes headless worth the work, and it trades platform lock-in for engineering ownership. Work a software-as-a-service vendor used to absorb becomes an on-call surface for your team. The hosting choice decides how much of that surface you keep.
Copy link to headingThe six layers you take ownership of
Each layer fails differently, and a platform that covers one well can leave another bare:
Rendering compute: Serves static, incremental static regeneration (ISR), server-rendered, and partially prerendered pages from a single catalog, under load that arrives in bursts.
CDN caching: Holds product pages close to shoppers and drops them the moment inventory or price moves, which makes invalidation more important than hit rate.
Build and preview pipeline: Turns a pull request into a reviewable storefront, so merchandising and engineering can approve a campaign against real code.
Firewall and bot controls: A web application firewall (WAF) and bot detection absorb scraping, credential stuffing, and card testing before they reach checkout, which also decides what a peak-season invoice looks like.
Observability: Reports what shoppers experienced rather than what a synthetic test measured, and provides logs, traces, metrics, and user-experience data for incident diagnosis.
Backend connectivity: Carries every uncached request to the commerce API, and sets the latency floor for any page with a live cart.
Those six layers are what the categories below divide up differently.
Copy link to headingThe four categories of ecommerce hosting platform
Vendors in this market cluster into four groups, and the group usually predicts more than the individual product does. Managed frontend platforms such as Vercel, Netlify, and Cloudflare run framework-aware compute, CDN, and firewall as one product, organized around the framework's rendering model. General cloud, meaning Amazon Web Services (AWS) and Google Cloud Run, hands you primitives and leaves the assembly to you, which buys control at the cost of the layers you now operate.
Commerce-vendor runtimes like Shopify Oxygen put the storefront inside the commerce vendor's own infrastructure, which removes the integration work and fixes the backend. Self-hosting on a Kubernetes cluster or a virtual machine fleet running an OpenNext adapter leaves the team owning every layer, including the ones the other three categories hide. Named examples appear under each criterion below, scored on what they do rather than on category reputation.
Copy link to headingThe ecommerce hosting criteria that decide peak behavior
A benchmark run on a quiet Tuesday says close to nothing about the first hour of Black Friday Cyber Monday (BFCM). Three criteria decide that hour, and all three are measurable before a contract is signed.
Copy link to headingBurst and peak scaling behavior
A storefront's traffic arrives as a step function when an email lands, which puts the weight on how fast a platform adds capacity rather than on its concurrency ceiling. Fluid compute lets several invocations share one in-flight instance, which cuts cold starts. Bursts scale at 1,000 concurrent executions per 10 seconds per region, toward a ceiling of 30,000 on Hobby and Pro or 100,000 on Enterprise. Across BFCM 2025 the platform peaked at 518,027 requests per second and served 115.8 billion requests. Raw AWS Lambda scaling reaches 1,000 execution environments every 10 seconds per function per region and throttles above that.
The default account limit of 1,000 concurrent executions is the one teams forget to raise before a sale. Cloudflare Workers sidestep container cold starts entirely by running inside V8 isolates, which start far faster than a new process. Scaling headroom is not the same as availability. A Cloudflare outage on November 18, 2025 ran five hours and 46 minutes, ten days before Black Friday, after a database permissions change produced an oversized Bot Management feature file.
Copy link to headingRendering and caching model
Rendering strategy sets the cost of a page, and invalidation sets the accuracy of it. ISR ships the cached page while a background regeneration runs. Partial prerendering serves a static shell from the CDN while a function streams the cart and live pricing into it. Server-side rendering pays the full origin hit on every request, which is correct for checkout and wasteful for a category page. Cache Components in Next.js 16 make caching opt-in through the "use cache" directive and make partial prerendering the default App Router behavior.
Identical application code therefore leans harder on what the underlying CDN can purge, which is why a storefront that reprices hourly can shortlist on this criterion alone. A partially prerendered page holds a static shell and its streamed segments, and the platform has to revalidate them together or serve a shell describing prices that no longer exist. Shopify Oxygen cannot purge its full page cache for the deployed worker, so clearing it means waiting for expiry or shipping a new deployment. The Cloudflare OpenNext adapter supports partial prerendering, though its cache interception feature stays off when you use it. Self-hosted Next.js invalidates only the instance that received the call by default, and a refreshTags() implementation on a custom cache handler is what synchronizes the rest.
Copy link to headingGlobal latency and where the function runs
Point-of-presence counts are the metric most often quoted and least often predictive. Vercel Functions belong near the data source. A function sitting beside a New York visitor still owes the commerce API a full round trip. With Shopify's Storefront API or commercetools pinned to one region, that round trip dominates the page.
Coverage still matters for the static half of the page, and the numbers are public. Vercel's CDN spans 126 points of presence and 20 compute-capable regions across 51 countries. The Cloudflare network reaches 348 cities, including 36 in mainland China, where Vercel lists no point of presence. Evaluate the service available under the proposed contract, rather than total network locations. Shopify Oxygen runs on Cloudflare's network and advertises 300 or more locations. A retailer selling into mainland China has a category decision to make on this criterion alone.
Copy link to headingOperational criteria in an ecommerce hosting evaluation
Performance benchmarks need to be supplemented with operational, security, and cost evaluations. Incident reviews, invoice reconciliations, and the migration that quietly never happens surface all of them.
Copy link to headingBuild pipeline and preview environments
Preview deployments per pull request are effectively table stakes, available on Vercel, Netlify, Cloudflare, and Oxygen. The differences sit in the conditions. Netlify builds a preview when the base branch is a production branch or has branch deploys enabled. Cloudflare still documents per-pull-request previews on Pages, though its own docs now steer new projects to Workers, so a team standardizing on Pages is picking the product Cloudflare is moving away from.
Rolling deploys during a sale are the failure this criterion exists to catch. Skew Protection pins a browser to the deployment that served it through a deployment identifier. A shopper halfway through checkout then meets no version mismatch when a fix ships underneath them.
Copy link to headingObservability
Real user monitoring beats synthetic testing here, because a storefront's slowest sessions belong to shoppers on congested mobile networks that no lab test reproduces. Netlify has the stronger default on this criterion. Its real user monitoring reports Core Web Vitals from live visitors on Pro and Enterprise plans. The equivalent depth on Vercel comes from Speed Insights Plus at $10 per project per month on Pro, and it is included on Enterprise.
For a team already running an observability stack, the question is what the platform exports rather than what it displays. OpenTelemetry traces leave Vercel through the @vercel/otel package, and Drains forward logs, traces, and analytics events at $0.50 per GB on Pro. Netlify keeps log drains on Enterprise.
Copy link to headingSecurity and WAF plan tiers
WAF implementations separate on two things during an attack, rule propagation speed and which plan the rules you need sit on. Vercel propagates a firewall configuration change globally within 300 milliseconds with no redeploy, which beats shipping a hotfix while a bot hammers checkout. BotID blocked more than 415 million bot attempts across BFCM 2025. Vercel's managed rulesets are Enterprise-only, which leaves a Pro team writing its own rules.
Cloudflare is the more generous platform on rule availability. Its managed rulesets, including the Open Worldwide Application Security Project (OWASP) core ruleset, cover Pro and above, and Exposed Credentials Check screens logins against a stolen-credential database on every paid plan. Netlify's WAF needs Enterprise and the High-Performance Edge add-on.
Copy link to headingPCI DSS scope and attestations
Compliance scope is where the marketing and the standard part company. PCI DSS requirement 6.4.3 covers authorizing, integrity-checking, and inventorying every script on a payment page. Requirement 11.6.1 covers tamper detection on that content at least once every seven days, or at a frequency set by a targeted risk analysis.
Both sit with the merchant no matter who holds a service-provider Attestation of Compliance. The PCI Security Standards Council removed them from Self-Assessment Questionnaire A in January 2025, which changed the questionnaire and left the requirements of PCI DSS v4.0.1 in place. Every platform in this comparison clears the infrastructure bar. Vercel publishes SOC 2 Type 2 and ISO 27001:2022 alongside service-provider and merchant attestations. Cloudflare, AWS, and Shopify each hold PCI DSS Level 1.
Copy link to headingWhat ecommerce hosting costs, and what you give up to leave
Price lists compare badly across categories, because each one meters something different. The three criteria below surface after the contract is signed, too late to change the answer.
Copy link to headingCost model and the drivers with no ceiling
Per-unit rates are the visible half of a hosting bill and rarely the expensive half. Active CPU on Fluid compute runs $0.128 per hour at the US base rate, ISR writes cost $4.00 per million, and Fast Data Transfer starts at $0.15 per GB. CDN delivery is available through on-demand pricing or fixed monthly capacity tiers. CloudFront bills $0.085 per GB out to the internet on its pay-as-you-go rate, and Cloudflare bills no egress from Workers to origin at all. Automated traffic is what turns a predictable bill into an unpredictable one, because a crawler pulling uncached images bills like a shopper who never converts.
One podcast publisher logged 66,500 bot requests in a day against image optimization in February 2025, when per-image rates ran roughly two orders of magnitude above today's. Image optimization bills transformations on cache misses plus cache reads and writes, so bot traffic hits three meters at once. Vercel does not charge CDN Requests or Fast Data Transfer for traffic mitigated by WAF deny, challenge, or rate-limit actions. Requests that pass a challenge and reach the application incur normal usage charges; paid WAF features have separate meters. Most of that surface is addressable by tuning cache TTLs, sizes, and quality at the application layer. Vercel's spend management now pauses production deployments automatically when a team hits a set amount, which caps the driver at the cost of a hard stop.
Copy link to headingCommerce backend integration
Every uncached request crosses this boundary, so integration depth shows up as latency and as engineering hours. Next.js Commerce listens for Shopify products/update webhooks and calls revalidateTag, and the Data Cache propagates that purge to all regions within 300 milliseconds. You can reach a backend that has to stay off the public internet through AWS PrivateLink on Pro and Enterprise, or Secure Compute on Enterprise.
Oxygen removes the integration question for a Shopify catalog and forecloses it for anything else. That trade suits a single-backend retailer and fails a business running two commerce systems through a migration.
Copy link to headingLock-in and exit
Framework portability and platform portability are different questions, and Next.js answers the first cleanly. The Deployment Adapter API reached stable in Next.js 16.2 in March 2026, and it gives platforms a documented contract for framework features. OpenNext maintains adapters for AWS, Cloudflare, and Netlify. What does not travel is the platform-specific layer underneath. Durable cache storage, CDN-side streaming, and proprietary bot detection have to be rebuilt or dropped on the way out, whichever platform a team leaves.
Committing to a vendor's own runtime narrows the question further. commercetools Frontend documents Netlify as its deployment path, and Hydrogen binds closely enough to Shopify primitives that self-hosting it is documented with a caveat that the guide may lag newer Hydrogen releases. Self-hosting scores highest on this criterion by definition, since nothing is left to leave.
Copy link to headingHow the four ecommerce hosting categories compare
Scored against the criteria above, the categories separate more sharply than the individual products inside them do:
Managed platforms trade configuration surface for time to production. General cloud reverses that, and the ancillary charges are what surprise teams, since NAT Gateway and CloudWatch line items can rival the compute they support. Oxygen is included on paid Shopify plans from Starter through Plus and answers only for Hydrogen. Self-hosting gives up nothing on portability and leaves the team operating every managed layer it replaced.
Copy link to headingHow to test an ecommerce hosting shortlist on your own traffic
Vendor benchmarks settle nothing, because they run on a catalog that is not yours. Six exercises against your own numbers settle most of it:
Peak-window replay: Web Analytics and Speed Insights from last peak's busiest hour show where latency, errors, and abandonment climbed together, and that hour is the traffic shape to reproduce.
Whole-path load tests: Promo codes, cart recalculation, inventory checks, payment initiation, and order creation all belong in the test, since a homepage-only run passes while the transaction path fails.
Test type selection: k6 spike tests model the sudden jump and breakpoint tests find the ceiling, both against a preview deployment, and anything above 50,000 requests per second needs advance coordination with the platform.
Cost modeling on the uncapped drivers: ISR writes against catalog churn, image transformations against bot traffic, and CDN requests against crawler load are the three that move, and each one needs a ceiling named before launch.
Threshold setting: Core Web Vitals at the 75th percentile means Largest Contentful Paint at or under 2.5 seconds, Interaction to Next Paint at or under 200 milliseconds, and Cumulative Layout Shift at or under 0.1.
Pilot sequencing: The highest-risk conversion surface goes first, which is how Helly Hansen approached its migration, moving checkout ahead of the homepage to isolate the critical path before a peak that grew 80% year over year.
A seventh item belongs on the list and never fits in a load test. Rollback ownership is settled before code freeze, with a documented owner, a trigger metric, and an incident channel everyone already knows. Running these exercises against your own peak numbers settles the category before the first vendor call. Picking a platform is a different job from peak traffic readiness, which starts once the platform is picked.
Copy link to headingWhere Vercel fits in an ecommerce hosting decision, and where it doesn't
Vercel is one option in the managed frontend category, and the criteria above point at a specific shape of storefront it suits. They also point at the cases where another category is the better answer.
Copy link to headingWhere it fits
A Next.js App Router storefront on ISR and partial prerendering is the case Vercel is built around, since burst handling and cache invalidation both behave the way that architecture assumes. PAIGE reported a 76% increase in conversion rate and 22% in revenue running Shopify with Next.js through BFCM 2024. Developers who want the WAF, bot detection, preview deployments, and rendering from one product rather than four are buying the integration as much as the compute.
Copy link to headingWhere another category wins
Oxygen is included in a plan a Hydrogen-first team already pays for, which no managed frontend platform can match on price. Cloudflare puts managed firewall rulesets on Pro, a tier below where Vercel starts them, which settles the question for a retailer that will not be buying Enterprise. Heavy catalog churn pushes ISR write volume hard enough that the metered model can cost more than a flat cluster the team already operates. Retailers selling into mainland China need points of presence Vercel does not list.
Copy link to headingWhat you would rebuild on the way out
Application code ports through the stable adapter API, so the exit cost concentrates in the platform layer. Vercel's durable ISR storage, its CDN-side streaming for partially prerendered pages, and BotID would each need a replacement or a decision to live without one. That list is the honest measure of lock-in on any platform here.
Copy link to headingShortlist against your own peak numbers
Raw speed converges across these four categories once the catalog is cached and the images are optimized. What diverges is who gets paged, and for which layer. The candidates are rendering compute, cache invalidation, firewall rules, and the route to the commerce backend. A storefront team that knows which of those it wants to own has already narrowed the field to one category. The remaining work is checking that shortlist against its own peak traffic, and no vendor benchmark stands in for that.
For teams that land on a managed frontend platform, Vercel covers those layers through:
Fluid compute: Takes the opening hour of a sale without pre-provisioned capacity or a scaling ticket.
Tag-based invalidation: Moves a price change from a commerce webhook to every region before the next shopper sees the old one.
Vercel WAF and BotID: Let a rule ship mid-attack instead of mid-deploy, with behavioral detection sitting behind the signature rules.
Skew Protection: Keeps a rolling deploy from breaking the sessions already in checkout.
Spend management: Puts a ceiling on the cost drivers bot traffic moves, with an automatic pause as the backstop.
Start a storefront on vercel.com/new, or begin from a commerce template at vercel.com/templates.
Copy link to headingFrequently asked questions about ecommerce hosting
Copy link to headingWhat does ecommerce hosting cost at scale?
The bill tracks catalog churn and automated traffic more than shopper volume, since cache writes and image transformations meter separately from compute. Framework defaults move it too. Next.js 16 raised images.minimumCacheTTL from 60 seconds to 4 hours, cutting image revalidation.
Copy link to headingDoes the hosting platform change PCI DSS scope?
No. Requirements 6.4.3 and 11.6.1 stay with the merchant whichever platform serves the page. A merchant running an embedded payment form can satisfy them by obtaining written confirmation from its payment provider that the form's built-in protections are implemented as the provider instructs.
Copy link to headingDo you still need a CDN in front of a managed hosting platform?
Rarely, since managed frontend platforms run their own CDN and adding a second one duplicates caching and complicates invalidation. Teams add one deliberately for coverage a platform lacks, for a firewall tier on a cheaper plan, or to keep one security vendor across several properties.
Copy link to headingHow portable is a headless storefront between hosting platforms?
Cleanly at the application layer, and barely at all at the platform layer. OpenNext is rebuilding its AWS, Cloudflare, and Netlify adapters in one shared monorepo due by the end of 2026, with the current adapters still maintained.