A large share of software gets built by someone other than the firm on the invoice. Agencies subcontract to cover overflow, to reach skills they do not employ, and to serve clients they could not serve profitably at their own cost base. Almost nobody writes about the arithmetic, which is a shame, because the arrangement works well when the numbers are understood on both sides and badly when they are not.
We sit on the supplier side of this, so treat what follows as informed and partisan.
How the markup actually works
Two different structures get called the same thing.
In branded reselling, the prime presents the work as its own. Markups over provider cost run from about 50% to over 100%, producing gross margins in the 25% to 50% range.
In subcontracting, the sub is disclosed or at least visible, and the prime is doing substantive work alongside the delivery: discovery, design, client management, quality. Markups sit lower, roughly 25% to 50%, with gross margins around 15% to 40%.
Neither is exploitation. The prime is not just adding a percentage, it is carrying the client relationship, the commercial risk, the scope negotiation and the collection risk. Those are real jobs with real cost, and a sub who resents the markup usually has not tried doing them.
Why the prime does it anyway
The uncomfortable truth is that subcontracting often produces a better margin than in-house delivery, not a worse one, because the alternative is not "do it cheaper ourselves." It is one of these:
- turn the work down, earning nothing
- hire for it, which costs a senior recruitment cycle and creates fixed cost against variable demand
- take it and deliver it late with the team you have, which costs the relationship
Against those three, a marked-up subcontract that ships on time is frequently the best available outcome. That framing matters when you negotiate, because a sub arguing on rate alone is answering a question the prime is not asking. What the prime is buying is capacity that appears when needed and disappears when it does not.
Where these arrangements go wrong
Four failure modes, in rough order of how often I see them.
Inadequate vetting. This is the single largest cause of partnership failure. The fix is unglamorous and well known: review the portfolio, take two or three references, then run a small paid pilot, typically in the $3,000 to $5,000 range, before committing anything that matters.
Missing IP assignment. If the prime's agreement with the sub lacks assignment language reaching the individual engineers, the prime cannot cleanly assign to the client. Nobody notices until the client's own acquisition diligence asks who owns the repository.
Undisclosed disclosure requirements. Many client contracts require consent before work is subcontracted, and some require naming the subcontractor. Breaching that quietly is a much larger problem than asking would have been. The detail worth knowing on the security side: a partner's certification does not extend to its subcontractors, so each layer needs its own.
Single-source dependency. A prime with one sub has outsourced its capacity to a company it does not control. The standard mitigation is two, even when the second is smaller.
What a fair arrangement looks like
The good ones I have been part of share five features:
- 1.A pilot before the real thing. Both sides learn more from one small paid project than from three calls.
- 2.Named accountability on both sides. One person at the prime, one at the sub. Not account managers relaying.
- 3.Overlap hours written down as a number. Not "we are flexible," which means nobody decided.
- 4.Direct access to the engineers doing the work, even if the client never sees them. Relaying technical questions through a manager doubles the cost of every clarification.
- 5.A stated position on client contact. Whether the sub ever appears, under what name, and what happens if the client asks directly. Ambiguity here poisons otherwise good relationships.
The case for disclosure
The instinct is to hide the arrangement. I think that is usually wrong, and not only for ethical reasons.
Buyers increasingly ask where the people touching their data sit, because their own vendor-risk process requires it, and the question arrives during diligence when the deal is nearly closed. A prime that has already said "our engineering bench is global, here is how the controls travel" is answering from strength. A prime discovered mid-deal is negotiating from the floor. The same logic applies one level down, which is why our own posture is stated in how to vet a development partner with a global team rather than left to be found out.
What this means for your firm
- If you are a prime: run the pilot, check the assignment chain reaches individuals, read your client contracts for consent clauses, and get a second supplier before you need one.
- If you are a sub: stop negotiating on rate alone. Reliability, overlap and written communication are what get you the second project, and the second project is where the margin is.
- Either way: agree the client-contact rule in writing at the start, while it is a hypothetical.
If you are quoting work you cannot staff at a margin right now, that is a solvable problem and a short conversation. Tell us what the overflow looks like and we will tell you whether we are the right bench for it. Sometimes the honest answer is that the work wants a specialist we are not, and saying so early costs us nothing.
Sources
- AgencyPro: white label versus subcontracting, margins and vetting
- Black Kite Technologies: the white-label agency guide for 2026
- Nearshore Business Solutions: SOC 2 and ISO 27001 requirements for partners