Application packaging in 2026 is no longer a question of whether MSIX is ready. It is a question of evidence: how many of your applications will package, install and run, what that costs in-house against outsourcing, and which controls keep the packaging pipeline safe. Our new white paper, The State of Application Packaging in 2026, answers those questions with measured results, first-party Microsoft sources and a cost model whose every assumption is stated. It is 45 pages, free to download, and updates our 2025 edition.
Most packaging budgets are still set from last year's supplier quote and a vendor's promise of effort savings. Neither tells an IT leader at a 50 to 600 user organisation, or an MSP packaging for several customers, what will actually happen to their own application list. This year's edition was written to close that gap.
What changed in twelve months
A lot moved underneath packaging teams between September 2025 and September 2026:
- Windows 10 reached end of support on 14 October 2025. Commercial Extended Security Updates cost $61 per device in year one, doubling each year for up to three years, and are included at no additional cost on Windows 365 and Azure Virtual Desktop.
- Windows 11 servicing is breaking old scripts. Windows 11, version 25H2 no longer includes PowerShell 2.0 and uninstalls the WMIC utility, so legacy install, detection and uninstall scripts that depend on them will fail.
- App-V server support ended in April 2026. The App-V client and sequencer moved to fixed extended support and are no longer deprecated, so App-V exits can follow your own schedule rather than a hard deadline.
- Microsoft's MSIX investment shifted to the platform. The report documents servicing while applications are in use, package integrity enforcement, the general availability of Artifact Signing and a weekly MSIX engineering blog. It also records where the gaps remain: the MSIX Packaging Tool has had no public release since 2024.
- Catalogues roughly doubled. The Intune Enterprise App Catalog listed about 933 applications in June 2026, against around 450 in mid-2024, so more mainstream software needs no custom packaging at all.
The measured results
The centre of the report is the 2026 EfficientEther research programme: three open-access preprints, each with a stated method and disclosed limitations.
The first is MSIX at scale across 3,261 application cases. An automated workflow produced an MSIX package in 90.68% of cases and a complete smoke-test pass in 80.04%, across eight installer and distribution types. The second is the native MSIX or App Attach decision for Azure Virtual Desktop, which found similar steady-state launch times for the two models and concluded that App Attach is justified by its assignment model, not by speed. The third is a defensive security analysis of the Package Support Framework, which found that the decisive risk sits before signing, not after deployment.
The report ties these together with a six-rung evidence ladder, because "it worked" always needs qualifying.
The research measured builds, installation, launch of a selected entry point and smoke-test cleanup at scale. Confirming it is the intended application, and rungs 5 and 6, remain your decision gates.
What packaging costs in 2026
The UK Government's G-Cloud framework remains the most transparent public benchmark, because suppliers publish their prices. The report analyses the 12 G-Cloud 15 services whose titles name application packaging, as listed on 21 September 2026, with suppliers identified by letter rather than by name. Across those published price lists:
- Per-application packaging prices cluster between £320 and £575 at typical volumes, broadly stable against 2025.
- A full discover, package, test and deploy lifecycle is priced at up to £1,145 per application.
- Day rates for an end-user computing engineer run from £392 to £900, with a median of £600.
The more useful finding is how quotes are structured. Discovery, packaging, acceptance testing and deployment are increasingly priced separately, so a £350 packaging price and a £1,000 lifecycle price can describe the same outcome. The report lists what to compare beyond the headline: stages included, formats included, warranty after a Windows feature update, and whether validation evidence ships with each package.
It also looks at how packaging services describe MSIX to the organisations that hire them. MSIX appears in two-thirds of the services analysed, usually as one format in a list. None of the twelve explicitly links MSIX to a security benefit. If MSIX matters to your estate, ask your packaging team or supplier to evaluate it first for each application and record why any application ships in another format.
Download the full report for the price tables, the day-rate analysis and the questions to ask before you sign a packaging contract.
Does in-house automation pay back?
The cost model compares ways of operating, not suppliers, and states every input so you can replace it with your own:
- If engineering capacity already exists, automation pays back after a handful of packages, because each package mostly costs review time.
- If a dedicated engineer must be hired, the illustrative model breaks even at about 113 packages a year against a £450 outsourced price.
- Volume includes updates. An estate with 150 applications that each release two or three updates a year needs 300 to 450 packages a year before any Windows feature-update regression work.
These are modelled results, not measured savings. The report says so plainly and shows the sensitivity to pass rate and outsourced price, which is what a finance lead needs before approving either route.
AI in packaging: govern where the data goes
AI is already part of how endpoint teams work. One 2026 survey of Intune users cited in the report found that 89% use at least one AI tool for Intune management, although it measured adoption rather than packaging specifically. The report's position is practical: the key decision is where installers, scripts and configuration go, more than which assistant you pick. Use local or enterprise AI for sensitive material, never consumer accounts, and put AI-generated scripts, package suggestions and fix-up configuration through the same evidence gates as anything a person produces. The report sets out seven controls for doing that.
The security case, stated precisely
The report corrects a common misconception: most converted desktop applications run as full-trust MSIX packages. They get package identity and some virtualisation, not a sandbox. The case for MSIX is still strong when it is stated accurately. There is no arbitrary install-time code of the kind MSI custom actions allow, packages are signed and can be integrity-enforced, machine-wide registry writes are redirected, and removal is clean.
The risk moves to the pipeline. A package signed with your enterprise certificate inherits your trust, so the report's controls table covers signing keys, package integrity, Package Support Framework governance, feed and manifest control, and the same approval gates for AI assistants that change packages as for human engineers.
Six actions for the next 90 days
The report closes with a seven-step decision framework and six practical actions:
- Inventory and classify your portfolio: catalogue-available, MSIX candidate, needs fix-ups, not suitable for MSIX, retire.
- Run an automated MSIX pilot on a representative sample, measuring the pass rate at each rung of the evidence ladder.
- Scan install and detection scripts for PowerShell 2.0 and WMIC dependencies.
- Review your signing pipeline: where keys live, who can sign, and whether package integrity is enabled.
- Ask your packaging team or supplier to evaluate MSIX first and document every exception.
- For Azure Virtual Desktop, decide per application group between native MSIX and App Attach, and test on your real storage and session hosts.
Where EtherApps Forge fits
EtherApps Forge is the packaging tool behind the research, and the report is careful about what that does and does not show. The research demonstrated automated capture, build and signing from eight installer types, automated first-line validation with a saved report for every pass, support for applying the Package Support Framework only where it is needed, and App Attach image creation for Azure Virtual Desktop. It did not measure staff time or cost, and it does not replace business-task testing on your own platform. EfficientEther develops EtherApps Forge and has a commercial interest in these results, which the report discloses.
EtherApps Forge is a Windows desktop application that runs in your own environment, so installers and signing material stay with you. The MSIX packaging and deployment route covers the packaging pipeline, and legacy application modernisation covers the applications that need the most care. The quickest way to find out how your own portfolio behaves is a pilot: EtherApps Forge includes a free 7-day trial of the full workflow.
Get The State of Application Packaging in 2026 and take the evidence, the price benchmarks and the cost model into your next packaging decision.
