An Adobe Commerce audit is an independent, evidence-based review of a store running the paid edition of Magento (formerly Magento Commerce or Enterprise). It covers what a generic Magento audit skips: the B2B module, staging-aware data, Commerce-only features, licence value and the upgrade path within Adobe's support lifecycle. You get a severity-rated report and a prioritised roadmap - packages from $1,650, with the report in about 5-10 business days.
Adobe Commerce audit: B2B, content staging and the licence you pay for
An independent review of the parts of your store that only exist on Adobe Commerce - the B2B module, content staging and the Commerce-only features - plus an honest answer to whether you use enough of the licence to justify it. Run by an Adobe Commerce Certified Expert, on a copy of your code and data.
What an Adobe Commerce audit covers that a Magento audit does not
Adobe Commerce shares its core with Magento Open Source, so the usual checks on code, performance and security still apply. What changes the risk profile is everything Adobe adds on top: a versioned data model for content staging, a B2B suite, and Commerce-only features tied to the licence. These are the areas where Adobe Commerce stores most often carry hidden cost, and where an audit written for Open Source has nothing to say.
B2B module
Company accounts, shared catalogs, negotiable quotes, requisition lists and purchase orders - and what they cost in indexing and caching.
Content staging
The row_id data model behind scheduled updates, and the custom code, imports and queries that silently break against it.
Commerce-only features
Customer segments, related product rules, reward points, store credit, gift cards and returns (RMA) - used, bypassed or duplicated.
Licence value
A neutral keep, reconfigure or reconsider view: are you using enough of what the Adobe Commerce licence includes to justify it.
Upgrade path
Where your version sits in Adobe's support lifecycle, what the Upgrade Compatibility Tool flags, and what it cannot see.
Security & permissions
Patch level, admin hardening, and company-role checks in custom REST and GraphQL endpoints, so a B2B buyer cannot reach data their role should not.
How the Adobe Commerce B2B module affects performance and risk
The B2B module is one of the strongest reasons to pay for Adobe Commerce, and one of the most common sources of slow pages and fragile custom code. Each B2B feature adds data, permissions and indexing work, and the cost grows with the number of companies, shared catalogs and websites rather than with traffic. I audit B2B as a system: how it is configured, what it does to caching and indexers, and whether your custom code respects its rules.
- Shared catalogs and customer groups - every custom shared catalog comes with its own customer group, and price and permission indexes scale with customer groups multiplied by websites. I measure what your catalogue structure costs at reindex time.
- Category permissions - shared catalogs rely on them, adding permission indexers and checks on every category and product page. Misconfigured permissions are also a data-exposure risk.
- Full-page cache variation - the customer group is part of the cache context, so logged-in B2B buyers spread across many groups lower the cache hit rate. I quantify it with real numbers, not assumptions.
- Negotiable quotes and purchase orders - custom pricing, checkout and ERP code is checked against quote negotiation and approval flows, which extensions built for B2C often ignore.
- Company roles in custom endpoints - custom controllers, REST and GraphQL endpoints must enforce company role permissions, or a buyer can see or act on data their role should not reach.
- Unused B2B features - features switched on but never used still add configuration, queue consumers and upgrade surface. Turning them off is often the cheapest win.
Content staging and row_id: where custom code breaks on Adobe Commerce
Adobe Commerce lets you schedule changes to products, categories, CMS pages and blocks, and catalogue and cart price rules. To make that possible, those entities are versioned: the main table is keyed by row_id, the same entity_id can appear on several rows, and created_in and updated_in decide which version is live. Attribute values join on row_id, not entity_id. Code written for Open Source that hardcodes entity_id works in testing and then returns duplicate or wrong data the day marketing schedules its first campaign. It is one of the most frequent defects I find in Adobe Commerce codebases.
- Link field - custom code should resolve the join column through MetadataPool (getLinkField() returns row_id on Adobe Commerce and entity_id on Open Source) rather than hardcoding entity_id.
- Raw SQL, imports and ERP syncs - direct inserts and updates that bypass the staging-aware layer, leaving orphaned versions or overwriting scheduled changes.
- Reporting and data exports - queries that count every version row as a separate product or category.
- Scheduled update hygiene - overlapping or stale updates, and campaigns that go live at peak traffic, triggering cache invalidation and reindex work when you can least afford it.
Are you using what you pay for in the Adobe Commerce licence?
An Adobe Commerce licence includes features that Open Source does not have. Many stores pay for them and then buy third-party extensions that do the same job - a gift card module on top of native gift cards, a returns extension next to native RMA, a loyalty plugin next to reward points. The audit includes an inventory of what you use, bypass or duplicate, and a neutral recommendation. I don't resell licences, hosting or extensions, so I have no stake in the answer.
- Keep - you rely on B2B, staging, segments or other Commerce-only features, and replacing them would cost more than the licence.
- Reconfigure - you pay for native features you have bypassed with extensions; removing the duplicates cuts cost and upgrade risk.
- Reconsider - you use little that is Commerce-only. Magento Open Source or Mage-OS may fit better, and I outline what a move would really involve, staging data and B2B included.
- Inventory - customer segments, related product rules, reward points, store credit, gift cards, returns (RMA), content staging and B2B.
Adobe Commerce upgrade path and the support lifecycle
Adobe gives each 2.4.x release three years of standard support from its general availability date. As of October 2026, Adobe's lifecycle policy lists these dates: Adobe Commerce 2.4.9 (released May 12, 2026) is supported until May 31, 2029, and 2.4.8 until May 31, 2028. Standard support for 2.4.7 ends on May 31, 2027, with a free extension to May 31, 2028; 2.4.6 is in extended support until August 31, 2027; 2.4.4 and 2.4.5 receive only isolated security fixes in a one-time transitional period ending May 31, 2027. The audit places your store on this timeline and sizes the upgrade.
- Upgrade Compatibility Tool - Adobe's tool, available for Adobe Commerce only, flags custom code that relies on core code changed or removed in the target version. I run it and then review what it cannot see.
- Beyond the tool - third-party module support, B2B and staging customisations, data migrations and infrastructure changes that a static check does not cover.
- Dependencies - Adobe does not patch PHP, MariaDB or search engines for you, so their end-of-life dates go into the same plan.
- Effort and order - a realistic estimate and sequence: clean up first, or upgrade first.
How an Adobe Commerce audit runs
The audit is non-invasive: it runs on a copy of your code and an anonymised copy of the database, so nothing touches your live store. B2B stores add a pass over company and catalogue structure, agreed during discovery.
Discovery and access
We agree which edition features you actually run - B2B, content staging, segments, gift cards and the rest. You share the repository or a code archive and an anonymised database copy. This is where any extra scope is confirmed, so the quote is fixed before work starts.
Edition-specific analysis
I review custom code against the staging data model and B2B flows, and measure indexing and cache behaviour with your real catalogue structure. The standard code, performance and security checks run alongside, on a copy, with zero production impact.
Report with a licence view
Every finding is rated by severity and placed in a prioritised roadmap with effort estimates in work-hours. You also get a lifecycle timeline for your version and the feature inventory behind the keep, reconfigure or reconsider recommendation.
Live review
We walk the report through with your team or agency in a 60-120 minute session and agree the order of work. You can act on it in-house, with your current partner or with me - there is no obligation to buy implementation.
How much does an Adobe Commerce audit cost?
The same three fixed packages as every SimpleMage audit, with the Adobe Commerce areas built into each. Active B2B setups can add scope, so the final quote is confirmed after discovery - before any work starts.
Code & Architecture Audit
- Custom code checked against the staging (row_id) model and B2B flows
- Module inventory, including extensions that duplicate Commerce-only features
- Security - patches, admin hardening, company-role checks in custom endpoints
- Report + prioritised roadmap
- 60-min review session
Performance Audit
- Everything in the Code & Architecture audit, plus:
- Core Web Vitals, TTFB and throughput measured
- Full-page cache (Varnish) hit ratio, including customer-group cache variation
- Indexer and query analysis, including shared catalogs and category permissions
- 90-min review session
Comprehensive Audit
- Everything in the Performance audit, plus:
- Upgrade path within Adobe's support lifecycle (Upgrade Compatibility Tool + manual review)
- DevOps & CI/CD audit (current infrastructure and processes)
- Licence value review - keep, reconfigure or reconsider
- Independent code & delivery assessment
- 120-min review session + 2 weeks of support
Indicative prices - B2B and the number of integrations can add scope, so the quote is confirmed after discovery.
Running Magento Open Source or Mage-OS instead?
Adobe Commerce audit - frequently asked questions
Get an independent read on your Adobe Commerce store
Start with a free 30-minute call. Tell me which Commerce features you use and what worries you, and I'll tell you which package fits and how the scope looks - before you commit to anything.