THE SHORT ANSWER
A website mainly presents information, while a web application supports interactive tasks in a browser. A mobile app is installed and can use device capabilities. SaaS is software delivered as an ongoing service and may be web or mobile. A marketplace connects multiple participant groups. These categories can overlap.
Compare purpose before technology
| Format | Best suited to | Common added responsibility |
|---|---|---|
| Content website | Information and discovery | Publishing, accessibility and maintenance |
| Web application | Interactive browser workflows | State, accounts, data and security |
| Mobile application | Frequent or device-specific use | App distribution, permissions and version support |
| SaaS | Ongoing software service | Billing, tenancy, support and reliability |
| Marketplace/platform | Interactions between participant groups | Trust, liquidity, disputes and governance |
Choose from the use case
- Does the task require login or saved progress?
- Must it use camera, location, notifications or offline capability?
- How frequently will people return?
- Does the product coordinate multiple participant groups?
- What sensitive data or payments are involved?
- Who will maintain the service after launch?
A responsive web experience can often test a workflow before native mobile distribution is justified.
Every additional layer creates operating work
Accounts require identity and recovery. Persistent records require data design, access rules and backups. Payments require server-side verification and reconciliation. Mobile releases add store policies and version management. SaaS adds service reliability and customer administration.
Complexity can be necessary, but it should trace to a real user or business requirement.
Evidence & context: NIST
Write a format decision
State the user task, context, essential data, integrations, device needs and maintenance capacity. Then record why the chosen format is the smallest credible way to deliver the outcome.
Use the technology stack overview only after the product form and requirements are clear.
Sources & further reading
- How the web works
MDN Web Docs. Standards-oriented learning material on clients, servers, DNS, HTTP and browser rendering. It is a simplified conceptual introduction rather than a complete architecture guide.
- Learning about users and their needs
GOV.UK Service Manual. Public-service design guidance linking user needs to stories, acceptance criteria and continued research. Its process should be adapted to the product and risk context.
- Secure Software Development Framework
NIST. Outcome-based secure-development guidance covering preparation, protection, secure production and vulnerability response. It is a framework, not a product-specific checklist.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗