Country guide
Outsourcing software development to Mexico
A U.S. buyer's evidence-led guide to Mexican software outsourcing, including REPSE triage, time zones, data controls, IP, pricing, and pilots.

Mexico outsourcing decision in 90 seconds
A credible proposal lets the buyer answer all six questions below with evidence. If one remains ambiguous, pause commercial negotiation and resolve the operating model first.
| Decision | Evidence to obtain before approval | Why it changes the result |
|---|---|---|
| What are we buying? | Statement of work, authority map, acceptance method, named delivery owner | A managed outcome and buyer-directed personnel allocate responsibility differently |
| Who is the supplier? | Exact legal name, tax and invoice details, signer authority, employer and subcontractor chain | The sales brand may not be the entity employing contributors or promising rights |
| Does specialized-services analysis apply? | Counsel’s fact-specific conclusion; REPSE result when relevant; registered activity and validity | Mexican labor rules focus on the real personnel arrangement, not the proposal label |
| Where and when will work happen? | Named city, IANA time zone, schedule, holidays, seasonal test dates | Mexico has multiple time zones and special seasonal rules in specified border locations |
| What data and IP cross the boundary? | Data map, role allocation, security schedule, contributor rights chain, dependency register | Contract ownership is incomplete without lawful data handling and operational custody |
| Can we exit safely? | Repository and account ownership, transition duties, data return/deletion, knowledge test | A low starting rate does not compensate for trapped code, records, or expertise |
Mexico should remain on the shortlist only when its named team and arrangement beat the alternatives on the buyer’s actual constraints. This guide does not rank Mexican developers as a group, quote a universal hourly rate, or decide legal applicability from a webpage.
Decide the engagement model before comparing rates
Start by writing one sentence that describes the real delivery relationship. “The provider owns planning and delivers an accepted product increment” is different from “our engineering manager assigns tickets to three named provider employees every day.” Calling both arrangements “outsourcing” hides the control, continuity, and compliance questions that matter.
For a managed project or managed service, the supplier should have meaningful authority over staffing, sequencing, internal supervision, quality, and recovery while the buyer controls business priorities, constraints, access, and acceptance. Evidence should include a provider delivery lead, an integrated plan, quality controls, risk ownership, service levels where appropriate, and remedies tied to outcomes.
For staff augmentation, the buyer usually owns the backlog, architecture, daily direction, review, integration, and final quality. The proposal should make that buyer management burden visible. Confirm named people, allocation, replacement terms, rate changes, access controls, work location, and the entity responsible for the employment relationship.
For an independent contractor, the contract label does not replace review of how the relationship will actually operate. Map supervision, exclusivity, tools, schedule, workplace, integration, economic terms, substitution, and termination with qualified advisers for the relevant facts.
For local employment or an employment-service route, identify the legal employer, payroll and benefits responsibilities, intellectual-property chain, management authority, support process, termination path, and what happens if the intermediary changes. A platform interface does not remove the need to understand the underlying entity and agreement.
Use the staff augmentation versus project outsourcing guide to assign delivery responsibility before asking a Mexican provider to price the work.
Treat REPSE as a fact-driven gate, not a checkbox
The current Mexican Federal Labor Law prohibits subcontracting of personnel, described in Article 12 as one person or entity providing or making its own workers available for another’s benefit. Article 13 permits subcontracting of specialized services or works under stated conditions, including that they are outside the beneficiary’s corporate purpose and predominant economic activity and that the contractor is registered in the public registry referenced by Article 15. Article 14 addresses a written contract and approximate participating headcount for those specialized arrangements.
That text does not support a blanket statement that every cross-border software contract needs REPSE, nor does a remote-delivery label prove that it does not. Applicability depends on the real relationship, the parties, the work, where and how it is performed, and current interpretation. The safe buyer workflow is to create a factual record and obtain Mexican legal and tax advice for the arrangement.
Ask counsel and the supplier to work from the same fact sheet:
- Which Mexican entity employs or contracts every contributor?
- Is any supplier employee being put at the buyer’s disposal, and what operational facts support that answer?
- Who assigns work, supervises the person, approves time or leave, evaluates performance, selects replacements, and directs methods?
- Will anyone work in a space or center under the buyer’s ownership, administration, or responsibility, whether permanently, indefinitely, or periodically?
- What are the buyer entity’s corporate purpose and predominant economic activity, and how does the proposed service relate to them?
- Is the supplier promising a defined result with its own management, or primarily providing named capacity under buyer direction?
- Are subcontractors, related entities, or another employer involved?
- Which agreement, location, and entity does the conclusion cover, and what changes would trigger a new review?
The official REPSE FAQ says the registration obligation concerns providers that put their own workers at a third party’s disposal and explains its view of work performed at another company’s facilities. It also describes three-year renewal. Because the page is an administrative resource rather than engagement-specific advice, preserve counsel’s conclusion and the facts behind it instead of copying one sentence into every contract file.
Verify REPSE evidence when the arrangement requires it
When qualified review concludes that REPSE is relevant, do not accept a badge, screenshot, or registration number by itself. Search the official public registry using the provider’s exact legal name, RFC, or filing folio. The platform says a current result can show the legal name, location, notice details, validity, and authorized specialized services or works.
Build a dated evidence packet containing:
- The searched legal name and identifier and the date of the lookup.
- The current registry result, validity period, and status.
- The exact authorized service matched to the proposed statement of work.
- The contracting entity, invoicing entity, employer, and any subcontractor.
- The written agreement and the approximate worker count where the applicable rule requires it.
- A covenant to maintain required registrations and notify the buyer of denial, cancellation, expiry, scope change, or material factual change.
- The owner and cadence for re-verification, including before renewal or scope expansion.
- Counsel’s conclusion and assumptions, stored with the procurement decision rather than in a sales email.
Registration is not a quality certification. It does not prove that the proposed engineers are available, that the supplier can deliver the system, or that the buyer’s data and intellectual property are protected. Keep labor-model review separate from technical, security, financial, and delivery evaluation.
If counsel concludes REPSE is not engaged, retain that conclusion and the supporting facts. Revisit it when authority, worksite, corporate entity, subcontracting, scope, or delivery method changes. An evidence-backed “not applicable to this arrangement” record is more useful than silence.
Specify the Mexican legal and delivery chain
Request the supplier’s exact legal name, entity type, registered and operating addresses, tax identifier used for the transaction, bank-account beneficiary, signer authority, and invoice currency. Independently validate material records through the appropriate official, banking, legal, or professional channel. Do not send funds because a salesperson changed payment instructions in email; verify changes through a separately established contact path.
Draw the chain from the U.S. buyer to every person who can access confidential information, code, tickets, customer data, production, or credentials. For each entity and individual, record:
- the employing or contracting entity;
- the agreement that binds them;
- approved country and city of work;
- confidentiality and intellectual-property obligations;
- access scope and security requirements;
- authority to subcontract or relocate work;
- insurance or financial responsibility where relevant;
- offboarding owner and deadline; and
- notification duties when the chain changes.
Ask whether the commercial brand, Mexican contract entity, parent company, U.S. sales affiliate, and contributor employer are the same. If not, allocate every promise to the entity capable of performing it. A parent-company logo on a proposal does not automatically make the parent responsible.
Use exact cities and time zones
“Mexico time” is not an operating specification. Mexico’s time-zone law defines Central, Pacific, Northwest, and Southeast zones. It also limits seasonal time to specified northern-border locations, with a statutory seasonal interval from the second Sunday in March to the first Sunday in November. That means the working-hour relationship with a U.S. office can depend on the Mexican city, the U.S. city, and the date.
For each critical participant, store the actual city and an IANA time-zone identifier such as America/Mexico_City, America/Tijuana, or the correct identifier for that person’s location. Do not store a fixed “UTC minus” assumption or infer the zone from the country. Time-zone databases and organizational schedules also need maintenance.
Test the proposed collaboration window on four dates: a normal week, the U.S. spring clock change, the U.S. autumn clock change, and any Mexican seasonal boundary relevant to the team’s location. Include the buyer product owner, reviewers, supplier delivery lead, and escalation contact—not only developers.
The working agreement should state:
- normal local hours for each role;
- the sustainable live decision window;
- response expectations by issue severity;
- who can make product and technical decisions during that window;
- holidays and planned absence recording;
- how daylight-saving changes are communicated; and
- an asynchronous handoff format for decisions, risks, tests, and work in progress.
Nearshore value comes from faster decisions and lower handoff latency, not from maximizing meetings. A Mexico-based team with two deliberate live windows and strong written records may collaborate better than a nominally closer team kept in calls all day.
Map personal data before providing access
Mexico’s current Federal Law on Protection of Personal Data Held by Private Parties defines a persona encargada as a person or legal entity processing personal data on behalf of the responsible party. It also defines transfers separately from communications involving the responsible party or processor. Those definitions are a starting point, not a substitute for mapping the buyer, Mexican provider, subprocessors, systems, people, purposes, and jurisdictions.
Before onboarding, create a data schedule with one row per category:
| Field | Required buyer record |
|---|---|
| Data | Category, source, sensitivity, and whether realistic development data is necessary |
| Purpose | Approved use and prohibited secondary use |
| Roles | Responsible party, processor, recipient, subprocessor, and operational owner |
| Location | Systems, backups, support locations, and approved work countries |
| Access | Named roles, privilege, authentication, logging, and approval |
| Lifecycle | Retention, blocking where applicable, return, deletion, and evidence |
| Rights and incidents | Request-assistance workflow, contacts, timing, preservation, and notification |
The law addresses purpose limitation, data minimization relative to the stated purpose, security measures, continuing confidentiality, data-subject ARCO rights, and national or international transfers. Translate those duties and the buyer’s own U.S. obligations into operational controls. Determine with counsel which party is responsible for notices, consent or another legal basis, rights handling, transfer conditions, incident communications, and regulator interaction.
Prefer synthetic or minimized development data. Keep production credentials individual, scoped, and time-bounded. Require approved subprocessors and work locations, administrative logging, investigation cooperation, vulnerability handling, and deletion or return evidence. If the supplier says “compliant,” ask for the system, owner, artifact, date, and exception process that make the claim testable.
Build a complete software-rights chain
The current Mexican Federal Copyright Law protects computer programs and addresses the default treatment of patrimonial rights for software and documentation created by employees in their duties, subject to agreement. A U.S. buyer should not extrapolate that rule to every founder, freelancer, subcontractor, pre-existing component, open-source dependency, dataset, model, or generated asset.
Have qualified counsel define ownership and licenses for:
- source and object code;
- tests, documentation, designs, schemas, infrastructure, and configuration;
- prompts, evaluation sets, model adapters, embeddings, and synthetic data where relevant;
- pre-existing supplier tools and reusable frameworks;
- third-party commercial and open-source software;
- data transformations, databases, and content;
- inventions, know-how, feedback, and improvements; and
- rights needed to build, modify, host, operate, sublicense, sell, and transition the system.
Then verify the contributor chain. The supplier should be able to explain how employees and subcontractors are bound, what agreement covers each person, and how pre-existing or third-party material is approved. Do not collect unnecessary personal documents; obtain appropriate representations, samples, attestations, or counsel review while respecting privacy.
Operational custody is the second half of IP protection. Keep repositories, cloud accounts, domains, package registries, signing keys, analytics, app-store accounts, and production services in buyer-governed organizations. Require dependency and license records, code review, secret scanning, reproducible builds, current documentation, and continuous handover. The strongest assignment clause cannot restore a repository the buyer never controlled.
Evaluate the named team and delivery system
Interview the people proposed for delivery-critical roles, including the manager who will own scope and recovery. Ask each person to walk through a relevant system, their personal contribution, a difficult constraint, a decision that changed, the quality evidence used, an incident or failure, and how someone else took over the work.
Verify role, seniority, working language, city, normal schedule, allocation, expected start date, tenure with the supplier, and competing commitments. Titles are not comparable evidence. A “senior” profile without a named person or artifact walkthrough should not receive the same score as verified experience.
For managed delivery, evaluate the provider’s planning, product reasoning, architecture, testing, security, operations, dependency management, forecasting, and stakeholder communication as one system. For augmentation, evaluate whether the buyer has enough product, engineering-management, architecture, review, environment, and security capacity to absorb the proposed people without creating a queue.
Use one provider scorecard across Mexico and other eligible locations. Score verified evidence, record missing items as missing, and name the person accepting each exception.
Compare complete, dated cost—not a country average
Request a dated range by named role, seniority, allocation, currency, billing unit, taxes, vendor fees, tools, equipment, travel, unusual-hour assumptions, leave treatment, onboarding, replacement, rate review, termination, and transition. Clarify whether the supplier absorbs rework caused by its own quality defects and how scope changes are priced.
Add buyer-side costs: product ownership, management, review, security, legal and tax advice, vendor administration, payment and currency operations, travel, environment setup, integration, and transition. Model a likely case and a disruption case, not only the quoted monthly total.
Do not convert a salary survey into a supplier rate. Salary, contractor compensation, staff-augmentation price, and managed-service price represent different responsibilities and inclusions. Preserve the quote date, currency assumptions, named team, and scope so the comparison can be reproduced later.
The lowest bid is often the least informative when it omits delivery leadership, testing, security, paid leave assumptions, transition, or the supplier’s management layer. Normalize proposals before ranking them.
Run a representative paid pilot
Choose a milestone that resembles the intended relationship. It should include one ambiguous product decision, integration with an existing system, code or artifact review, automated testing, security-relevant access, documentation, and handover. Avoid trivia tests and disposable prototypes that bypass the hard collaboration path.
Before the pilot, record:
- outcome, non-goals, constraints, and acceptance evidence;
- engagement model and authority boundaries;
- named team, locations, schedules, and allocation;
- approved repositories, environments, data, and accounts;
- security and incident contacts;
- intellectual-property and dependency rules;
- cost cap and change process;
- daily or milestone evidence expected; and
- continue, revise, or stop criteria.
During the pilot, measure accepted output, decision latency, buyer review burden, forecast changes, escaped defects, blocked time, documentation quality, and recovery when an assumption fails. Do not reward visible activity that does not improve an accepted outcome.
End with a buyer-controlled build, current setup instructions, decisions and risks, test evidence, dependency record, access review, cost reconciliation, and a short handover exercise by someone who did not produce the work. Scale only if the real delivery system supports the promised benefit.
Contract for evidence and change
The outsourcing contract checklist covers the broader agreement. For a Mexico delivery arrangement, attach an evidence schedule that names the artifact, owner, frequency, recipient, and consequence when evidence is missing.
Useful rows include legal-entity verification, engagement-model assumptions, REPSE evidence when applicable, named-team allocation, work-location approval, subprocessor list, access review, security tests, incident exercises, dependency inventory, rights-chain attestation, service reporting, continuity test, data-return or deletion record, and transition package.
Define change triggers. New buyer direction over individuals, a new worksite, another Mexican entity, subcontracting, a material scope expansion, a different data category, a location change, or an expired registration may require review before work continues. A contract signed once is not a control for a relationship that changes every quarter.
Mexico outsourcing red flags
- The proposal calls itself a managed project, but the buyer is expected to direct individuals and own every delivery decision.
- The seller will not identify the Mexican contract entity, employer, subcontractors, or bank beneficiary.
- A REPSE logo or screenshot is offered without an exact legal-name lookup, validity, authorized activity, or applicability analysis.
- The provider makes a universal claim that REPSE always applies—or never applies—to software outsourcing.
- “Mexico time” appears in the plan without cities, time-zone identifiers, seasonal test dates, or named decision makers.
- Team members cannot be interviewed, their assignment happens after signature, or allocation is not documented.
- Personal data can be copied into development systems without a purpose, role, location, retention, and rights-assistance map.
- An “all IP belongs to the client” sentence is not supported by contributor agreements, dependency records, or buyer-controlled repositories.
- Production requires shared accounts, unmanaged devices, or supplier-owned cloud and source-control organizations.
- The rate excludes delivery leadership, testing, security, transition, or foreseeable buyer management effort.
- Exit terms omit work in progress, documentation, credential revocation, data return or deletion, and transition assistance.
- The supplier guarantees legal, employment, tax, privacy, or classification outcomes without examining the actual facts.
Frequently asked questions
Is Mexico a good country for software outsourcing from the United States?
It can be a strong candidate when a named team provides useful working-hour overlap and the commercial arrangement survives delivery, legal, security, IP, cost, and continuity review. Country proximity is a shortlist factor, not provider evidence.
Does every Mexican software outsourcing company need REPSE?
This guide does not make that claim. Mexican rules and the official REPSE FAQ focus on specified personnel and specialized-services arrangements. Obtain Mexican advice based on the actual entities, corporate activities, authority, worksite, personnel relationship, and scope. If registration is relevant, verify the official registry result and authorized activity directly.
Is Mexico in the same time zone as the U.S. buyer?
Not necessarily. Mexico has multiple statutory zones, and specified northern-border locations use seasonal time. Record the actual Mexican and U.S. cities, use current IANA time-zone data, and test the dates when either side’s clock relationship can change.
How should a U.S. buyer protect source code and IP?
Use counsel to create a complete rights and license chain across the supplier, employees, subcontractors, pre-existing materials, dependencies, data, and AI-related assets. Pair it with buyer-governed repositories and accounts, reproducible builds, dependency records, individual access, and tested handover.
Can a Mexican team access U.S. customer or employee data?
That depends on the data, purposes, buyer obligations, Mexican roles, systems, transfer path, contracts, and controls. Map the flow first, minimize access, determine the applicable requirements with counsel, and make rights assistance, security, incident response, retention, and deletion operationally testable.
Should we choose staff augmentation or a managed Mexican team?
Choose based on who should own planning, supervision, architecture, integration, quality, and recovery. Staff augmentation can work when the buyer has management capacity. A managed team can work when the provider has real authority and evidence to deliver an outcome. Do not buy one while contracting and operating the other.
What is the best first project for a Mexico-based team?
Use a bounded paid milestone that tests the hardest uncertainty in the intended relationship: product decisions, integration, security, quality, collaboration, or handover. It should produce a useful accepted artifact even if the buyer decides not to scale.
Are Mexican developers cheaper than U.S. developers?
A country average cannot answer the procurement question. Compare dated proposals for named people and responsibilities, then include supplier management, taxes and fees, currency, buyer oversight, tools, security, travel, transition, quality, and risk.
Evidence ledger
Sources used on this page
- Federal Labor Law — Chamber of Deputies of the Mexican Congress. Supports: The current official labor-law text, including Articles 12 through 15 on personnel subcontracting, specialized services, written contracts, and the public registration requirement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Registry of Specialized Service Providers or Specialized Works (REPSE) — Mexico Secretariat of Labor and Social Welfare. Supports: The official registry, current applicability FAQ, three-year renewal statement, public lookup fields, and authorized-specialized-service verification workflow. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Federal Law on Protection of Personal Data Held by Private Parties — Chamber of Deputies of the Mexican Congress. Supports: The current private-sector personal-data law, including controller and processor roles, purpose limitation, security measures, confidentiality, ARCO rights, and transfers. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Law of Time Zones in the United Mexican States — Chamber of Deputies of the Mexican Congress. Supports: The official Mexican time-zone map and the seasonal-time rules that apply only to specified northern-border locations. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Federal Copyright Law — Chamber of Deputies of the Mexican Congress. Supports: The current official copyright text, including the treatment of computer programs and the default rule for software created by employees in their duties, subject to contract. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: November 15, 2026. Corrections: hello@outsourcing.ai.
