The DXP Scorecard — Independent Platform Evaluation
Independent Platform Evaluation
Scored on implementation experience
Not vendor briefings
← Dashboard

Concrete CMS

Traditional CMSTier 4
Visit Website ↗
Overall Capability
44/ 100
#37of 40overall#11of 13Traditional CMS

Concrete CMS is a niche but mature open-source PHP CMS whose enduring differentiator is best-in-class in-context drag-and-drop editing paired with granular permissions and a credible compliance posture (ISO 27001, SOC 2 Type 2, FedRAMP Moderate / DoD IL2 controls) for its managed hosting.

Head-to-Head

Capability44 : 54
Cost Efficiency66 : 65
Build Simplicity48 : 64
Operational Ease48 : 53

Craft CMS wins decisively on developer experience, content modeling depth (Matrix fields, schema-as-code via Project Config), GraphQL delivery, and modern integrations. Concrete CMS counters with stronger in-context visual editing, broader compliance certifications (FedRAMP IL2, HIPAA, SOC 2 Type 2), and zero license cost for self-hosted use. Craft is the better choice for headless and developer-led builds; Concrete fits regulated and editor-led use cases better.

Full Comparison →
Capability44 : 63
Cost Efficiency66 : 73
Build Simplicity48 : 54
Operational Ease48 : 50

Drupal offers a vastly larger contributor community, deeper content modeling (Views, taxonomy, Layout Builder), and a mature headless story via JSON:API and GraphQL. Concrete CMS is materially easier for non-technical editors out of the box and ships a more polished in-context editing experience, with a comparable or better compliance posture for managed hosting. Pick Drupal for scale, ecosystem, and complex data models; pick Concrete for editor self-service on smaller programs.

Full Comparison →
Capability44 : 36
Cost Efficiency66 : 70
Build Simplicity48 : 53
Operational Ease48 : 51

Both are mid-tier open-source PHP CMSes targeting similar SMB and agency audiences. Concrete CMS has materially better in-context editing, more sophisticated permissions/workflows, and a stronger compliance posture for managed hosting; Joomla has a larger community, more extensions, and broader translation/multilingual maturity. Concrete is the safer pick for compliance-sensitive and intranet builds.

Full Comparison →
Capability44 : 56
Cost Efficiency66 : 72
Build Simplicity48 : 67
Operational Ease48 : 61

Umbraco's .NET stack, Cloud offering, larger partner network, and Heartcore headless option position it more strongly for mid-market and enterprise programs. Concrete CMS counters with a more accessible PHP runtime, a stronger inline-editing experience for non-technical users, lower TCO via fully MIT self-hosting, and a better-documented compliance posture. Umbraco is the safer enterprise choice; Concrete fits SMB and government editor-driven use cases.

Full Comparison →
Compare Concrete CMS against any of 40 platforms →

Use-Case Fit

Marketing
46#27 of 40
Commerce
32#32 of 40
Intranet
39#14 of 40
Top Fit
Multi-Brand
47#19 of 40
Ideal For
  • 80Government and military intranets with strict compliance needs
  • 78SMB and mid-market brochure/marketing sites with non-technical editors
  • 70Multi-site / multi-brand portfolios on a constrained budget
  • 70Agencies and freelancers building bespoke PHP-stack sites
  • 65HR portals and internal communications sites
Look Elsewhere If
  • 22Headless / composable / omnichannel programs
  • 18AI-native content operations
  • 25Enterprise marketing teams requiring deep MarTech
  • 30Commerce-led organizations with sophisticated product content needs

Strengths & Weaknesses

Strengths
  • +
    In-context visual editing and editor productivity

    Concrete CMS pioneered front-end drag-and-drop editing and it remains the platform's strongest single feature: editors click any area on the live page to add or reorder blocks with full version history, approval workflows, and rollback. The block/page-type model plus dashboard bulk editing and Bulk SEO Updater accelerate content velocity, and reviews consistently note editors are productive within minutes rather than days.

    68
  • +
    Granular permissions and access governance

    The permission system supports page-, area-, and page-type-level ACLs with group, user, and time-based scoping plus exclusion rules — used in production at IMCOM (hundreds of sites) and BASF. Combined with OAuth2/OIDC on the REST API, native multi-level approval workflows, and marketplace SAML/MFA add-ons, it is a notably strong governance story for a tier-4 CMS, falling short only of field-level permissions and SCIM.

    64.3
  • +
    Predictable TCO and zero-lock-in open source path

    MIT-licensed self-hosted core means zero license cost and full portability of MySQL data and filesystem assets, while managed hosting is transparently priced at $4.99/$19 per month with no metered API or bandwidth overages. Hosting on commodity LAMP infrastructure starts around $3/month, and exit cost is low because there is no proprietary storage or closed delivery API.

    69.3
  • +
    Compliance and trust for a tier-4 platform

    PortlandLabs publishes SOC 2 Type 2 (Security & Availability, scope explicitly includes open-source Concrete CMS development), ISO 27001 certification, HIPAA/HITECH and PCI-DSS external audit validation, and meets FedRAMP Moderate controls at DoD IL2 — an unusually strong portfolio versus comparably-priced traditional CMS peers. The HackerOne program, monthly patch cadence, and CVE-numbering-authority status reinforce a credible security operations posture, though gaps remain around GDPR documentation, data residency, and a public trust portal.

    62.5
  • +
    Multi-site and multi-brand architecture at scale

    A single installation can host many language/brand sites with shared codebase, themes, and blocks while preserving per-site content trees, themes, workflows, and admin autonomy — proven by the IMCOM deployment running hundreds of garrison sites with centralized compliance. Scale economics are favorable since adding sites does not add license fees, only infrastructure.

    60
  • +
    Active release cadence and transparent project health

    Twelve releases shipped in the trailing 12 months culminating in 9.5.0 (Twig templating, PHP 8.5) and rapid security follow-ups in 9.5.1 and 9.5.2 demonstrate sustained delivery velocity. A public roadmap, monthly town halls, named community contributors on every release, and a dedicated 'Squash Week' bug sprint provide unusual transparency for a small-vendor open-source CMS.

    59
Weaknesses
  • AI enablement is largely absent from core

    The May 2026 town hall explicitly confirmed no AI features in core and none on the near-term roadmap. The only options are third-party marketplace add-ons (GPT-4 Turbo integration, DAM auto-tagging, a community MCP server requiring BYOK) — there is no agentic workflow capability, no semantic search, no AI personalization, no content intelligence, and no AI observability. This is a meaningful gap as competitors ship native AI assistants and agentic features.

    12.6
  • Headless and developer ecosystem are thin

    REST exists but GraphQL was proposed in 2022 and remains unshipped, no official SDKs are published for any language, TypeScript support is effectively zero, and webhooks require custom PHP rather than a native HTTP delivery layer. There is no Next.js/Nuxt/Astro starter, no draft preview API, and no schema-as-code workflow — headless usage is possible but second-class to coupled PHP rendering.

    32.5
  • Marketing technology stack is shallow

    Native A/B testing does not exist, marketing automation is absent, no CDP connectors are available, recommendation engines are not provided, and ESP integration is limited to a community Mailchimp add-on. Personalization is restricted to user-group visibility rules with no behavioral targeting or variant content engine — well below mid-market DXP expectations.

    23.1
  • Real-time collaboration and rich media are dated

    There is no simultaneous co-editing, presence, or inline commenting — collaboration is sequential and workflow-based. Media handling lacks native focal point, WebP/AVIF transforms, video hosting, and adaptive bitrate streaming; the rich text editor still ships CKEditor 4 (EOL June 2023, pinned at 4.22.1) with no announced successor.

    38.7
  • Talent pool, partner network, and community size are small

    GitHub has 841 stars and ~7 LinkedIn US job postings reference Concrete CMS — substantially below WordPress, Drupal, or modern headless peers. The certified-partner directory is limited to small regional agencies (no Tier-1 SIs), and third-party content (Udemy/Pluralsight courses, conference talks) is sparse, raising staffing risk for enterprise programs.

    41
  • Self-hosted operational burden and modest SLA posture

    The Standard Hosting SLA explicitly disclaims uptime guarantees and places backup responsibility on the subscriber, with no published RTO/RPO, no native APM or observability, and no built-in CDN. Self-hosted teams own all patching, monitoring, and DR — manageable for SMBs but unattractive for enterprises expecting SaaS-grade operations.

    40.7

Deep Dive

Full Analyst Assessment

Concrete CMS is a niche but mature open-source PHP CMS whose enduring differentiator is best-in-class in-context drag-and-drop editing paired with granular permissions and a credible compliance posture (ISO 27001, SOC 2 Type 2, FedRAMP Moderate / DoD IL2 controls) for its managed hosting. The platform is most compelling for SMB, government, and intranet builds that value editor self-service, predictable TCO, and self-hosted control. It lags badly in headless delivery, AI enablement, real-time collaboration, and modern marketing tooling (A/B testing, CDP, marketing automation), and the developer ecosystem — talent pool, SDKs, GraphQL — remains small versus mainstream CMS peers.

1Core Content Management58
Content Modeling
1.1.1
Content type flexibility
58H

Concrete CMS models content through page attributes (text, textarea, boolean, image/file, address, date, number, URL, email, rating, select, topics, etc.) plus the Express system for custom relational data objects. ~12–15 built-in attribute types with custom attribute types available via PHP, but there is no repeater/matrix field for page attributes and no schema-as-code option. Nothing in 9.5.x (through 9.5.2, June 2026) adds new modeling primitives; not higher because deep nested/repeatable field composition is absent.

1.1.2
Content relationships
60M

Express supports associations (one-to-many and many-to-many) between Express objects, with traversal available through the PHP API. Page-to-page relationships exist via the Page Selector attribute and page alias system. Relationships are functional but not graph-native; there is no bidirectional query API or reverse-lookup shorthand comparable to Craft or Hygraph.

1.1.3
Structured content support
60M

Block-based page composition is Concrete CMS's core paradigm — content areas hold multiple reorderable block types, and the Express block embeds structured data objects inside pages. 9.5.x continued refining block behavior (granular block caching controls, copy-on-drag from stacks/clipboard). However, there is no matrix/nested-block field for deeply composing structured components within a single entry; nesting is limited to the page-level block stack.

1.1.4
Content validation
62M

Each attribute type includes standard validation rules: required, text min/max length, file type and size restrictions for image/file attributes, date range constraints. Unique constraint support for Express attributes was added in 9.1.0. Custom validation is achievable via PHP event hooks pre-save. No cross-field validation GUI or rule-engine builder.

1.1.5
Content versioning
70H

Page versioning is a core Concrete CMS feature: every edit creates a new version, full version history is viewable, rollback is one click, and 9.1.0 added HTML diff comparison between arbitrary page versions. Scheduled publishing is natively supported. Not higher because there is no content branching and no diff/version UI for non-page content (Express objects, files).

Authoring Experience
1.2.1
Visual/WYSIWYG editing
82H

In-page visual editing is Concrete CMS's founding differentiator. Editors click any content area on the live page, add blocks, and drag-and-drop to rearrange — no form-based panel required — and can reorganize page layouts entirely from the front-end. 9.5.x maintenance releases continued refining the editing experience. Genuine in-page visual editing, comparable to best-in-class among traditional CMSes; not higher because complex column/grid layout still depends on theme/block support (not a full Webflow-style page builder).

1.2.2
Rich text capabilities
58H

Concrete CMS still ships CKEditor 4 (pinned at 4.22.1), a library that reached end-of-life in June 2023; the roadmap lists Concrete 10 as a future focus with the editor still undecided ('CKEditor or something new?') and no CKEditor 5 upgrade planned due to license incompatibility. Formatting, embedded images/files, and paste handling are solid, but output is an HTML blob and the underlying editor remains EOL with no announced successor as of mid-2026 (9.5.2).

1.2.3
Media management
52M

Concrete CMS includes a file manager with folder organization, search, custom attributes on files, automatic responsive thumbnail generation, and an in-browser image editor (crop, rotate, resize, filters). 9.4.0 improved external storage (S3) performance. WebP output still requires the 'WebP for Thumbnails' marketplace add-on (not core through 9.5.2) — no native focal point or WebP/AVIF URL transforms. Below average for modern media handling.

1.2.4
Real-time collaboration
40M

No evidence of real-time co-editing in Concrete CMS through 9.5.2. The version/approval workflow model is sequential — editors create a draft that routes through approvers. Last-write-wins behavior applies when multiple users edit concurrently without locking. No presence indicators or conflict resolution documented in any 9.4.x or 9.5.x release notes.

1.2.5
Content workflows
68H

Workflow is a native Concrete CMS feature. Editors attach multi-stage approval workflows to any page or page type via permissions, with role-based stage transitions, notification emails, and an audit trail via version history. Scheduled publishing integrates with workflows. More capable than a basic draft/published toggle without a plugin; not higher because stages are sequential rather than conditional-routing and there is no visual workflow builder.

Content Delivery
1.3.1
API delivery model
58H

A built-in REST API with OAuth2 and OpenID Connect authentication has been available since Concrete 9.2+, with documented endpoints covering pages, files, Express objects, and more. There is still no GraphQL API — the 2022 proposal noted GraphQL work had 'not yet been started' and nothing through 9.5.2 (mid-2026) has shipped one. REST API is functional for headless use but lacks the filtering/sorting depth of headless-first platforms.

1.3.2
CDN and edge delivery
38H

Concrete CMS is primarily self-hosted open source with no built-in CDN. CDN integration requires external configuration (CloudFront, Azure CDN) via community tutorials; the misc.img_src_absolute config option eases serving assets from external origins but is not a CDN layer. Official enterprise hosting includes managed infrastructure but is not a globally distributed CDN with sub-second cache purge. Score reflects the majority self-hosted deployment pattern.

1.3.3
Webhooks and event system
40M

Concrete CMS has an internal PHP application events system (on_page_version_approve, etc.) but no native HTTP webhook delivery layer, and nothing in the 9.4.x/9.5.x release notes (through 9.5.2) adds one. Outbound webhooks require custom development or third-party marketplace add-ons. No HMAC payload signing, retry logic, delivery logs, or per-event filtering documented in core.

1.3.4
Multi-channel output
48H

Concrete CMS is a traditional coupled CMS with a REST API added as a secondary capability. Rendering is PHP-template based; Twig templating support added in 9.5.0 (April 2026) is a developer-experience improvement, not a channel-agnostic delivery change. Rich text output is raw HTML, not an AST, and there are no official SDKs for JavaScript, Swift, Kotlin, or other non-PHP runtimes. Headless use via REST is possible but secondary to coupled web rendering.

2Platform Capabilities41
Personalization & Experimentation
2.1.1
Audience segmentation
35M

Concrete CMS has a native user group and user attribute system that drives block-level content visibility rules — basic rule-based segmentation for logged-in users. No CDP integration or real-time behavioral segmentation engine exists. Functional for gated/role-based content but well short of modern marketing segmentation.

2.1.2
Content personalization
38M

Block-level show/hide based on user group membership is the extent of native personalization — no content variant system, no in-editor audience preview, and no external decision engine bridge. Adequate for access-controlled content but not for marketing personalization scenarios.

2.1.3
A/B and multivariate testing
20H

No native A/B testing exists in Concrete CMS core or the current marketplace. A legacy 'Experimenter' block-level A/B add-on exists only for end-of-life concrete5 5.6 and is no longer sold. Any experimentation on v9 (now 9.5.2) requires fully external tooling.

2.1.4
Recommendation engine
15H

No built-in algorithmic recommendation engine exists in Concrete CMS. Content discovery relies entirely on manual editorial curation (related pages blocks, manual linking). No ML-based or collaborative filtering capability found in core or marketplace.

Search & Discovery
2.2.1
Built-in search
45H

Concrete CMS ships with full-text search backed by MySQL FULLTEXT indexing, covering page name, description, and text content fields. Faceting, typo tolerance, and advanced relevance tuning are absent. Adequate for small-to-mid sites but lacking enterprise search features.

2.2.2
Search extensibility
40M

No official Algolia or Elasticsearch marketplace add-on exists for Concrete CMS. Community Packagist packages for Algolia are minimal and unsupported. Custom webhook-based indexing is possible but requires full custom development with no supported patterns.

Commerce Integration
2.3.1
Native commerce
52H

The Community Store is a widely adopted, actively maintained free add-on providing a full e-commerce stack (product catalog, cart, checkout, shipping modules, payment integrations) within Concrete CMS, with active 2025–2026 development confirming its role as the de facto e-commerce solution. Not as high as true core commerce because it is add-on dependent, but it is the de facto standard.

2.3.2
Commerce platform integration
45M

Two Shopify integration add-ons exist on the marketplace (eCommerce with Shopify, Hutman Shopify Integration), providing product embed and checkout bridging at the product picker / embed level, plus a Snipcart integration. No deep bidirectional sync or live product federation. No commercetools, BigCommerce, or SFCC connectors found.

2.3.3
Product content management
42M

Community Store provides product-specific field patterns (name, description, attributes, images, SKUs) within Concrete CMS's content model. Editorial product management is functional but relies on generic content types repurposed with product structure — not as sophisticated as purpose-built PIM tools.

Analytics & Intelligence
2.4.1
Built-in analytics
48H

Concrete CMS provides built-in page-view statistics, download statistics, form results tracking, and featured Matomo integration. 9.4.0 added a Total File Downloads column in the File Manager for asset engagement tracking. Goes beyond operational metrics but lacks deep engagement analytics.

2.4.2
Analytics integration
55H

Google Analytics tracking code injection is natively supported via Dashboard → System & Settings → Tracking Codes. Matomo is a featured first-party integration. Extended GA add-on provides OAuth2-based GA data in-CMS. No documented Segment or Amplitude connectors, keeping this below the 65+ tier.

Multi-Site & Localization
2.5.1
Multi-site management
65H

Concrete CMS has a well-established native multi-site architecture where a single installation hosts multiple language/locale site trees with shared components and block types. Dashboard-level management is centralized. Governance tools are basic but multi-site capability is a known platform strength.

2.5.2
Localization framework
62H

Document-level localization via separate page trees per locale with built-in copy-locale functionality and locale associations. RTL language support is native. Field-level localization is not available — content changes require page-level duplication. Solid for mid-market multilingual use cases.

2.5.3
Translation integration
35M

A Translations Manager add-on and translate.concretecms.org exist for UI/interface string translation. No official integrations with enterprise TMS platforms (Phrase, Smartling, Lokalise, Crowdin) were found. Page content translation is primarily manual, placing this at the webhook-only / manual tier.

2.5.4
Multi-brand governance
30M

User group permissions and multi-site trees can approximate brand separation but no dedicated cross-brand governance tools, shared component libraries with policy enforcement, or global style/approval workflow controls exist. Multi-site is present but governance is basic permissions only.

Digital Asset Management
2.6.1
Native DAM capabilities
52H

Concrete CMS's core file manager has custom metadata attributes (the docs explicitly describe building a DAM via attributes), folder structure, asset versioning with rollback, usage tracking across pages, per-file permissions, and download statistics (a File Manager column since 9.4.0); a free open-source 'Brand Central' DAM add-on extends this with collections/categories and asset pages. Missing at the core tier: rights/expiry management, built-in CDN on self-hosted, and AI tagging. Solid for a traditional CMS but not a purpose-built DAM.

2.6.2
Asset delivery & CDN optimization
35M

CDN delivery on self-hosted requires third-party add-ons (Use CDN, Amazon S3, Azure Blob + CDN); built-in CDN only on SaaS tiers. Thumbnail generation with configurable dimensions is native but WebP requires a marketplace add-on and AVIF is unsupported. Basic image crop/resize via built-in editor. Not qualifying for 40+ without native CDN and WebP.

2.6.3
Video & rich media management
22H

No native video hosting, transcoding, or adaptive bitrate delivery in Concrete CMS. Video files can be stored in the file manager as static assets but there is no thumbnail generation, caption management, or streaming capability. Video presentation relies on embedding external services (YouTube, Vimeo); 9.4.7 only improved YouTube embed iframe rendering.

Authoring & Editorial Experience
2.7.1
Visual page builder & layout editing
72H

In-context drag-and-drop editing is the defining identity of Concrete CMS since its concrete5 era. Editors toggle Edit Mode to drag blocks into areas on the live page, seeing exactly what visitors see. Layout blocks support multi-column structures; 9.5.0 refined block copy behavior (blocks from stacks/clipboard now copy rather than reference). One of the strongest traditional CMS visual editing experiences.

2.7.2
Editorial workflow & approvals
60H

Two built-in workflow types: Basic (single-step) and Enterprise (multi-step, role-based routing). Enterprise Workflow assigns different decision-makers at each stage, includes email notifications, a full audit trail of approvals/rejections, and a 'Waiting for Me' approval inbox. Approval batches allow bulk section launches. No visual workflow state machine builder — routing follows a sequential model only.

2.7.3
Publishing calendar & scheduling
55H

Scheduled publishing with FROM and TO date/time fields is natively supported on pages — content goes live at FROM and auto-unpublishes at TO. Workflows and scheduling can be combined. A Production Mode feature (since 9.2.0) distinguishes dev/staging/live environments. No full editorial content calendar UI; release bundles are not a documented feature.

2.7.4
Real-time collaboration
25H

No real-time simultaneous editing, presence indicators, or inline commenting found in Concrete CMS. Collaboration is entirely workflow-based and asynchronous — editors submit, reviewers approve/comment via the workflow system. Version history with author attribution exists but there is no conflict-free collaborative editing implementation.

Marketing & Engagement
2.8.1
Forms & data capture
50H

Native drag-and-drop form builder supports CAPTCHA (SecurImage + reCAPTCHA), submission storage in DB with CSV export, email notifications, and multiple field types. Conditional field logic is absent in the core Form block — it requires the Formidable or Form Reform marketplace add-ons, which also add multi-step forms. Solid basic form builder without native progressive profiling.

2.8.2
Email marketing & ESP integration
30M

No native email campaign capability (9.5.0's Symfony Mailer migration is transactional email plumbing only, not marketing email). Only a community Mailchimp add-on (JeRo's) exists, providing a subscribe form block with API v3 integration — subscriber list sync only, no content push or triggered sends. No HubSpot, Salesforce Marketing Cloud, Brevo, or other ESP connectors found.

2.8.3
Marketing automation
20H

No native marketing automation capability exists in Concrete CMS — no behavioral triggers from CMS events, no drip campaign orchestration, no lead scoring. No tight integration with an automation platform found in the marketplace. Concrete CMS is not positioned as a marketing automation platform.

2.8.4
CDP & customer data integration
18H

No native CDP capability and no Segment, mParticle, Tealium, or other CDP connectors found in the marketplace. Google Tag Manager can be injected via tracking codes to route events to a CDP indirectly, but this is not a supported integration. CDP integration is fully DIY.

Integration & Extensibility
2.9.1
App marketplace & ecosystem
40M

The relaunched market.concretecms.com keeps growing with monthly 2026 additions (HTMX package, AI editor tools, UI blocks) announced in town hall roundups, plus a 'Try Before You Buy' trial on SaaS hosting. Notable integrations include Shopify, Snipcart, Mailchimp, Stripe, Amazon S3, SAML SSO, and Azure CDN. The catalog remains in the low hundreds — substantially smaller than WordPress or Drupal ecosystems.

2.9.2
Webhooks & event streaming
25H

No native outgoing webhook system exists in Concrete CMS — no UI to configure endpoints, event triggers, retry logic, or signed payloads. The PHP application event system fires internal events (on_user_add, page events, file events) that developers can hook into with custom code. Outgoing HTTP webhooks require custom development with no supported patterns.

2.9.3
Headless preview & staging environments
28H

Concrete CMS is fundamentally a coupled CMS — headless delivery is not a positioning. The REST API (OAuth2, covering Pages, Files, Users, etc.) was designed for management operations, not content delivery. Draft versions are viewable by logged-in users with permissions but there are no shareable external preview links. Production Mode (since 9.2.0) distinguishes dev/staging/live environments at the server level.

2.9.4
Role-based permissions & governance
55M

Concrete CMS has a notably granular permission architecture: custom role creation, group-based assignments, content-level ACL per page/section, time-based permissions, and permission exclusions for individual users. SAML 2.0 SSO is available via the Macareux SAML Authentication marketplace add-on (multiple IdPs, attribute and group mapping, documented Entra ID setup) — a material improvement over the prior LDAP-only situation. Still no field-level permissions and no SCIM, keeping this below the 65+ tier.

3Technical Architecture55
API & Integration
3.1.1
API design quality
50H

Concrete CMS ships a built-in REST API since 9.2+ with OAuth2 and OpenID Connect authentication and endpoints for pages, files, and Express objects, documented via Swagger UI. No GraphQL API exists — the 2022 proposal explicitly stated GraphQL work 'has not yet been started' and as of the 9.5.2 release (June 2026) no GraphQL delivery is documented; only a community graphql-websocket package exists. Filtering and sorting depth remains limited compared to headless-first platforms.

3.1.2
API performance
44M

Concrete CMS is a self-hosted PHP platform with no built-in CDN or documented API rate limits. CDN integration requires external configuration via CloudFront or Azure CDN tutorials. No published throughput benchmarks or pagination ceiling documentation for the REST API. The official enterprise hosting does not publish CDN-backed API delivery specs.

3.1.3
SDK ecosystem
32H

No official SDKs are published for JavaScript, TypeScript, Python, Ruby, Java, .NET, or mobile. The platform is PHP-native and the PHP application framework is the primary developer surface. Community packages exist on Packagist and the Concrete Marketplace for PHP, but no multi-language official SDK ecosystem has been established and no SDK announcements appeared through the 9.5.x releases.

3.1.4
Integration marketplace
62H

The Concrete CMS Marketplace (market.concretecms.com) lists thousands of add-ons and themes spanning SEO, forms, e-commerce, analytics, translation, and authentication, with continued 2025–2026 additions (Macareux SAML Authentication, Two-Step Authentication Advanced in March 2026). Breadth is solid for a traditional CMS, though the marketplace skews PHP-commercial and many integrations are narrow single-purpose add-ons rather than platform-grade integrations.

3.1.5
Extensibility model
68H

Concrete CMS provides a mature PHP extensibility model: custom block types (UI and rendering), custom packages, custom attribute types, custom single pages, custom themes, and a PHP event/hook system throughout the core. Version 9.5.0 (April 2026) added Twig templating support in block views, page templates, and single pages, modernizing the templating layer. No headless App Framework for cloud-hosted JavaScript extensions exists, but for a self-hosted PHP CMS the extensibility depth is strong.

Security & Compliance
3.2.1
Authentication
63H

OAuth2 and OpenID Connect are built into the Concrete CMS REST API core for API token management. SAML 2.0 SSO remains a marketplace add-on (Macareux SAML Authentication) rather than core, and MFA likewise depends on marketplace add-ons (Two-Step Authentication Advanced, March 2026; Two-Factor Login Security). SSO and MFA requiring third-party add-ons rather than core functionality keeps this below the 78+ threshold for mid-tier SSO inclusion.

3.2.2
Authorization model
68H

Concrete CMS has a sophisticated RBAC system: group-based user management, granular page/page-type-level permissions, time-based access control, permission exclusions for rule exceptions, and custom single-page permissions. The 9.5 releases also shipped permission fixes, indicating active maintenance. This exceeds predefined-roles-only, but no field-level permissions are documented and content-instance access control is not a core GUI feature.

3.2.3
Compliance certifications
70M

PortlandLabs now publishes a dedicated hosting compliance page detailing SOC 2 Type 2 and ISO 27001 certification plus HIPAA compliance and FedRAMP Moderate / DoD IL2 controls with continuous monitoring for the managed hosting tier, backed by specifics (AWS CIS benchmarks, FIPS 140-2 MFA, encryption at rest/in transit, annual independent penetration and DR testing) — a substantial, well-documented improvement over the prior thin posture. It stays below the 80+ band because the certifications cover only the managed hosting offering (Concrete is predominantly self-hosted, where compliance is operator-owned), there is no explicit GDPR/EU data residency claim, and no public trust portal or audit reports are accessible.

3.2.4
Security track record
54H

Concrete CMS operates a HackerOne responsible disclosure program and is a CVE Numbering Authority with high-quality advisories and prompt patching, and has no known major data breach. However, 2026 was a heavy vulnerability year: CVE-2026-7888 (unauthenticated PHP object injection RCE via unsafe unserialize() in Workflow/Form/File components, CVSS v4.0 8.4 High, fixed 9.5.2), CVE-2026-3452 (authenticated RCE via Express Entry List, fixed 9.4.8), CVE-2026-8350 (privilege escalation to admin group), CVE-2026-8203 (stored XSS), plus earlier CSRF-to-RCE issues. The shift into unauthenticated-RCE-class findings, despite transparent disclosure and fast fixes, holds this in the mid-50s.

Infrastructure & Reliability
3.3.1
Hosting model
73H

Concrete CMS is available as self-hosted open source (PHP/MySQL on any LAMP/LEMP stack) and via official enterprise hosting from PortlandLabs with GitLab deployment, managed PHP/MySQL, and direct core-team support — now backed by SOC 2 Type 2 / ISO 27001 / HIPAA certification plus FedRAMP Moderate / DoD IL2 controls on AWS for the hosted tier, strengthening its fit for regulated industries. The dual model provides flexibility for self-hosted control and managed convenience. No VPC or dedicated private-cloud tier is documented for the managed offering, keeping it below the top band.

3.3.2
SLA and uptime
36H

The Standard Hosting SLA page still states that PortlandLabs 'makes no guarantees on uptime availability under this agreement,' caps damages at fees collected, and places backup responsibility on the subscriber. No published uptime percentage or public status page was found for the official hosted offering as of mid-2026. Self-hosted installations carry no vendor SLA by definition. This remains firmly in the no-formal-SLA tier.

3.3.3
Scalability architecture
50M

Concrete CMS uses a standard PHP/MySQL architecture with no built-in horizontal scaling, auto-scaling, or CDN delivery. Scalability is entirely dependent on the operator's infrastructure choices (load balancers, Redis caching, CDN). PHP 8.5 readiness in 9.5 keeps the runtime current, but no documented enterprise-scale references or published API throughput benchmarks were found. Adequate for mid-market self-hosted deployments but not enterprise-proven at scale.

3.3.4
Disaster recovery
43M

The managed hosting compliance page references annual disaster recovery testing, but the Standard Hosting SLA explicitly states backups are provided 'for the courtesy of the subscriber' and that maintaining backups is 'the sole responsibility of the subscriber,' with no published RTO/RPO commitments, retention policies, or multi-region failover specs. For self-hosted deployments, backup and DR responsibility falls entirely to the operator. Content export via database dump is possible but no built-in export tooling comparable to headless platforms is documented.

Developer Experience
3.4.1
Local development
70H

Concrete CMS is a PHP application that runs fully on a local LAMP/LEMP/MAMP stack, DDEV, Docker Compose, or any PHP 8.x environment, with 9.5 adding PHP 8.5 readiness. The GitHub repository is Composer-managed, enabling standard PHP local setup, and the `concrete/bin/concrete5` CLI handles cache clearing, migrations, and other tasks. No official DDEV quickstart comparable to Craft's, but local development is well-supported.

3.4.2
CI/CD integration
52M

The official enterprise hosting uses GitLab deployment pipelines. Concrete CMS does not have a schema-as-code system comparable to Craft's Project Config — content model configuration is stored in the database, not version-controlled YAML. Environment management (dev/staging/prod) exists in the hosted offering but no branch-per-PR content environment support was documented. Standard PHP deployment patterns (Deployer, Capistrano) apply for self-hosted.

3.4.3
Documentation quality
62H

Official developer documentation at documentation.concretecms.org covers the 9.x REST API, block/package/attribute development, permissions, versioning guides, and per-release notes (9.5.2 release notes published June 2026). User guides cover the full editorial experience. Documentation is functional and actively maintained but reflects a PHP-era development style with fewer framework-specific integration guides or interactive playgrounds compared to modern headless CMS documentation.

3.4.4
TypeScript support
28H

Concrete CMS is a PHP-native platform with no official TypeScript SDK, no type generation from the content model, and no published npm packages. The REST API returns JSON that consumers can type manually, but there is no official @concretecms npm package, no codegen tooling, and no IDE type integration documented. The 9.5 modernization focused on Twig and PHP 8.5, not JavaScript/TypeScript tooling.

4Platform Velocity & Health53
Release Cadence
4.1.1
Release frequency
68H

Concrete CMS shipped 12 releases over the past 12 months on a near-monthly cadence, including the 9.5.0 feature release (2026-04-28) adding Twig templating and PHP 8.5 support, followed by 9.5.1 (2026-05-19) and 9.5.2 (2026-06-03). Cadence is consistent with meaningful feature minors rather than patches only, but the platform is not shipping major features monthly and v10 remains unreleased, keeping it below the 75+ band.

4.1.2
Changelog quality
60M

GitHub release notes are well-structured with New Features / Behavioral Improvements / Bug Fixes sections and per-change contributor attribution (verified on 9.5.0). However, breaking changes are not called out in a dedicated section and migration guides are not linked per-release, keeping it below the 75+ band for enterprise-grade changelogs.

4.1.3
Roadmap transparency
60H

The public roadmap at concretecms.org/roadmap lists Current Focus (bug fixing, marketplace rebuild, CMS-marketplace integration) and Future Focus (Concrete v10 with a CKEditor 4 replacement and AI site-building integration), and monthly town halls continue. There is still no community voting or prioritization portal (no Canny/GitHub Discussions upvotes), which caps the score at the moderate band.

4.1.4
Breaking change handling
55M

The 9.x line uses semver-compatible versioning and v8 completed a structured LTS wind-down, ceasing security patches in March 2026 after a final 8.5.21 release; v10 is signposted on the public roadmap ahead of release. No automated codemods or formal published deprecation-window policy was found, so transition handling remains present but not enterprise-grade.

Ecosystem & Community
4.2.1
Community size
42H

The main GitHub repository has 847 stars and 479 forks (verified 2026-07-09), still below the 1K-star threshold that maps to sub-45 scoring for an open-source platform. The forum is active but small-scale and Stack Overflow volume is sparse. The community is real but well below mainstream open-source CMS peers like Drupal or Strapi.

4.2.2
Community engagement
57H

Engagement is genuine and verifiable: 122 PRs opened since 2026-01-01 (78 merged), daily forum activity, monthly town halls, named community contributors credited in every release note (mlocati, hissy, ounziw, ccmEnlil), and a 'Squash Week' core-team bug/security sprint held in May 2026 with open community participation. Constrained by small absolute community size, so it stays below the 65+ band.

4.2.3
Partner ecosystem
48M

Concrete CMS maintains a formal certified services partner program with a certification test, a partner directory, and a Regional Partner Forum linked from the project site. However, the certified partner list remains small regional agencies with no Tier-1 SIs (Accenture, Deloitte, Valtech), limiting enterprise delivery capacity.

4.2.4
Third-party content
45M

Third-party content exists — agency blog posts, forum tutorials, some YouTube content, and an April 2026 TechRadar editorial review — but there are no notable Udemy or Pluralsight courses and minimal conference talk presence. The content ecosystem supports getting started but does not validate broad market adoption.

Market Signals
4.3.1
Talent availability
38H

Talent supply remains a thin niche pool: only a handful of LinkedIn job postings mention Concrete CMS, there is no certification program tied to major learning platforms, and the platform is absent from Stack Overflow Developer Survey recognition. Freelancers exist on Upwork and the project's own jobs forum, but enterprise hiring at scale would be difficult.

4.3.2
Customer momentum
50M

Concrete CMS won a third consecutive SourceForge Leader Award (Spring 2026, following Fall 2025 and Winter 2026), indicating a sustained, actively reviewing user base, and earned a TechRadar top-CMS editorial pick in April 2026. However, no major enterprise logo announcements or fresh case studies were found, so the trajectory reads as stable-with-positive-press rather than growing.

4.3.3
Funding and stability
50M

PortlandLabs remains a small, privately held company with no disclosed funding rounds, operating the platform continuously since 2008. Ongoing monthly releases, an active 2026 marketplace-rebuild initiative, and no layoff or distress signals support credible bootstrapped stability, but the absence of growth capital caps long-term velocity.

4.3.4
Competitive positioning
47M

Concrete CMS holds a clear niche — SMB and government/military sites emphasizing inline editing and granular permissions — and gained an April 2026 TechRadar editorial endorsement as an 'impressive, open-source solution.' It remains absent from Gartner MQ and Forrester Wave and is not strongly differentiated against Drupal or WordPress in broad market perception, so positioning stays defensible but narrow.

4.3.5
Customer sentiment
58H

Sentiment is positive but low-volume: G2 stands at 4.5/5 across ~66 reviews and Capterra at 4.5/5 across ~54 reviews (both re-verified this cycle), keeping combined volume well below the 100+ threshold and mapping to the 45-60 band, trending toward the top given rating quality. The Spring 2026 SourceForge Leader Award (top 5% of favorably reviewed software) corroborates the positive rating.

5Total Cost of Ownership66
Licensing
5.1.1
Pricing transparency
65H

Concrete CMS publishes its managed hosting tiers openly: Starter at $4.99/mo and Business at $19/mo (both billed annually), with limits clearly listed, while Enterprise/Custom SLA pricing remains sales-gated. The core software is free and open source (MIT), so the most common deployment path carries zero licensing cost. Deducted for annual-billing-only managed plans and the sales-gated Enterprise tier — the industry-norm pattern rather than full public pricing.

5.1.2
Pricing model fit
72H

Self-hosted (the primary deployment path) has zero license cost — completely flat and predictable. Managed hosting uses simple flat-fee tiers with clear page-view, storage, and editor-seat limits, with no API metering or bandwidth overage charges. The only friction is the lack of a monthly billing option on managed plans.

5.1.3
Feature gating
66H

All core CMS features are fully available in the free MIT-licensed self-hosted version — no functional capability is paywalled. However, both Starter and Business managed plans explicitly state 'NO ACCESS to source code,' reserving custom code deployment for the sales-gated Custom SLA tier, and marketplace add-ons are sometimes reported as limited in selection and arbitrarily priced. Self-hosting remains a full-featured escape hatch, which limits the impact.

5.1.4
Contract flexibility
60M

Managed hosting is annual-only with no published monthly option. However, the self-hosted path has no contract or lock-in whatsoever. No evidence of startup discounts, nonprofit pricing, or education programs was found on the pricing page. The annual-only managed billing is a mild friction point offset by the zero-commitment open-source route.

5.1.5
Free / Hobby Tier
72H

The full CMS software is free forever under the MIT license and can be self-hosted on any PHP host — a genuine, permanent, commercially permissive free path rather than a trial. Users still need to provision their own PHP hosting (from ~$3/mo via partners), so it is not a zero-cost managed free tier. No managed free plan exists.

Implementation Cost Signals
5.2.1
Time-to-first-value
68M

Concrete CMS runs on standard PHP and installs on shared hosting in minutes with standard tooling; 2026 reviews describe it as working 'out of the box' and 'easy to setup' with rich built-in features reducing plugin hunting. The inline page-editing model lets editors become productive quickly — reviews cite training 'in minutes instead of hours or days.' Slightly more setup than pure SaaS, comparable to Craft CMS or Joomla.

5.2.2
Typical implementation timeline
66M

Community reviews consistently describe fast deployments for typical marketing sites — basic setups of 10–20 developer hours and a recurring claim that 'development time and cost is nearly cut in half.' Info-Tech notes 'low cost of deployment.' Complex enterprise builds with custom themes/add-ons can run 100+ hours, but there is no community signal of consistently overrunning timelines.

5.2.3
Specialist cost premium
62M

Concrete CMS is PHP/MySQL-based using mainstream web skills, keeping the specialist premium lower than proprietary Java or .NET DXPs — freelance rates of $50–150/hr align with standard PHP work. However, its talent pool is significantly smaller than WordPress or Drupal, so hiring developers with specific Concrete CMS experience carries a moderate premium. PHP generalists ramp up reasonably quickly.

Operational Cost Signals
5.3.1
Hosting costs
67H

Self-hosted deployments run on commodity PHP/MySQL hosting from ~$3–15/month, among the cheapest operational options in this dataset. Official managed hosting starts at $4.99/month (Starter) or $19/month (Business) including SSL, backups, and managed upgrades. Enterprise managed deployments add cost for staging, CI/CD, and high availability but the base infrastructure overhead remains low.

5.3.2
Ops team requirements
57M

Self-hosted deployments require routine PHP server maintenance, CMS core updates, and add-on patching — typical of any traditional CMS. Official managed hosting includes managed upgrades, nightly backups, and security monitoring, substantially reducing ops burden on that path. Since most production deployments are self-hosted, moderate sysadmin overhead is the realistic norm; no platform-engineering team is needed.

5.3.3
Vendor lock-in and exit cost
72H

As MIT-licensed open source with a standard MySQL database and filesystem assets, Concrete CMS has low exit cost — content and data are exportable with standard tooling, and moving between managed hosting, self-hosting, or other providers is straightforward. Proprietary marketplace add-ons and the lack of source-code access on cheap managed tiers add only minor migration friction since the underlying platform is fully portable.

6Build Simplicity48
Learning Curve
6.1.1
Concept complexity
45M

Concrete CMS retains a substantial proprietary vocabulary: Pages, Areas, Blocks, Stacks, Themes, Express (a bespoke no-code relational data system), Attributes, Single Pages, and Packages. The Page/Area/Block hierarchy and Express data model have no equivalents in mainstream PHP or JS frameworks; the 9.5.0 Twig option cleans up template syntax but adds nothing to (and removes nothing from) the domain-model concept count. User reviews describe the learning curve as manageable for PHP developers, but the concept count is well above the <5 threshold for higher scores.

6.1.2
Onboarding resources
42M

Official docs at documentation.concretecms.org include a developer guide, user guide, and API reference, plus a certification program at training.concretecms.com. There is still no interactive sandbox, no structured framework-specific learning path, no headless quick-start, and the REST API docs remain thin. The standalone 'How to Learn Concrete CMS' page signals the onboarding journey is not self-evident.

6.1.3
Framework familiarity
42M

Concrete CMS 9.5.0 (June 2026) added optional Twig templating in core for block views, page templates, and single pages — a mainstream, transferable syntax familiar from Symfony, Drupal, and Craft — which meaningfully improves the templating layer over raw PHP views. The underlying stack is still a custom PHP MVC framework (not Symfony/Laravel), with no GraphQL API, no official JS/TS SDKs, and a REST API (OAuth2/OpenID Connect since 9.2) that is functional but not headless-first; 2026 Next.js/React headless roundups do not mention Concrete. Higher scores require standard REST/GraphQL with first-class React support, which is absent.

Implementation Complexity
6.2.1
Boilerplate and starter quality
35H

No official Next.js, Nuxt, Astro, or React starter template exists, and no CLI scaffolding tool. The only package boilerplate remains a community-maintained third-party repo (MacareuxDigital/v9_package_boilerplate). Marketplace themes are paid commercial products, not development starting points — a meaningful gap relative to modern headless platforms and even Joomla.

6.2.2
Configuration complexity
52M

Installation via Composer + interactive CLI or zip upload is straightforward for PHP developers with standard PHP/MySQL requirements, and 9.4.x improved CLI task feedback and added JSON config support in import XML, modestly improving automation. There is still no official Docker dev environment, no environment variable management pattern, and the REST API must be explicitly enabled via the Dashboard UI; production hardening requires a separate best-practices doc.

6.2.3
Data modeling constraints
48M

Content modeling uses Attributes (typed metadata) and Express (a proprietary relational object builder). There is no migration tooling for schema evolution, no TypeScript type generation, and no schema-as-code workflow; Express relationships do not map naturally to REST API output without additional wiring. User reviews also note there is no syncing process between local and remote environments, compounding schema-change risk on live content.

6.2.4
Preview and editing integration
62H

In-context WYSIWYG editing remains a core Concrete CMS strength — editors click directly on page elements in Edit Mode with full draft/version management and built-in workflow approvals, so coupled-architecture preview fidelity is excellent. The penalty: for headless/decoupled setups there is no draft preview API, no native webhook delivery layer, and no Next.js draft mode integration — preview is entirely server-side.

Team & Talent
6.3.1
Required specialization
44M

Theme and template work is now partly a transferable skill: 9.5.0 lets developers author page templates, single pages, and block views in Twig, which generalist PHP/Symfony/Drupal developers already know. But building custom Blocks still requires Concrete's proprietary controller/view/form structure, extending the REST API requires platform-specific service-provider and routing patterns, the certification is Concrete-specific and non-portable, and the talent pool is small (GitHub ~2.6k stars). Standard React or Laravel knowledge still does not transfer.

6.3.2
Team size requirements
52M

A solo PHP developer can build and deploy a traditional Concrete CMS site; a 2-person team is viable for moderate complexity. Self-hosted deployments require ops capability unless using managed hosting, and reviewers report friction with 3+ developers on one project due to the lack of environment syncing. For headless usage the team expands to include a separate frontend developer since the REST API is not headless-first.

6.3.3
Cross-functional complexity
58M

The in-context editing model lets content editors work directly on pages without developer involvement for routine updates; reviews consistently praise editor self-service ('editors catch on quickly with very little need for support'). 30+ built-in block types and built-in approval workflow reduce governance overhead. Penalties: new content types (custom blocks, Express objects) require PHP development, and permissions/ACL configuration needs developer involvement.

7Operational Ease48
Upgrade & Patching
7.1.1
Upgrade difficulty
42H

Concrete CMS upgrades remain self-hosted with database migrations applied on first page visit after file replacement, and no downgrade path exists — only backup restore. The 9.4→9.5 jump (April 2026) added Twig templating and PHP 8.5 support without major breaking changes per the minor-version policy, but themes, custom code, and third-party packages must all be verified compatible before upgrading. Frequent releases mean regular upgrade events for self-hosters.

7.1.2
Security patching
48H

Active HackerOne program and monthly patch releases continue, with fast turnaround demonstrated in 2026: 9.5.1 (May 2026) fixed five CVEs — including RCE via insecure deserialization (CVE-2026-8135) and path traversal RCE (CVE-2026-8134) — about three weeks after 9.5.0 shipped. However, patching always means upgrading the full self-hosted installation, and the steady stream of serious CVEs (RCE, CSRF-to-RCE in CVE-2026-8426) puts real urgency on self-hosted admins.

7.1.3
Vendor-forced migrations
62M

As an open-source platform, Concrete CMS imposes no vendor-controlled forced migrations; teams upgrade on their own schedule. The ESM model provides at least 3 years of critical security updates on the last minor of each major version. The 9.5 Twig templating addition is additive — legacy PHP templates were not deprecated on a forced timeline.

7.1.4
Dependency management
52H

Concrete CMS runs on a standard LAMP stack (PHP 8.x, MySQL/MariaDB, Apache or Nginx) with no mandatory external services — a relatively contained dependency graph, and PHP 8.5 support landed in 9.5. However, transitive dependency risk is real: 9.5.2 (June 2026) specifically patched vulnerabilities in third-party dependencies and PHP object injection issues, so self-hosters must track core releases for dependency fixes.

Operational Overhead
7.2.1
Monitoring requirements
35M

Concrete CMS provides no native APM, usage dashboards, or built-in status observability. Self-hosted teams must set up all web server, PHP-FPM, database, and application-layer monitoring independently. Documentation covers cron jobs and CLI operations but no monitoring tooling.

7.2.2
Content operations burden
42M

Concrete CMS offers a traditional page/block editing model with no documented automated content hygiene tooling — no orphan detection, broken link alerts, or content expiry workflows built into core. Content governance relies on manual editorial discipline, with some marketplace add-ons but no native automation.

7.2.3
Performance management
42M

Performance is entirely customer-managed for self-hosted deployments: cache configuration, database query tuning, CDN selection, and PHP settings all require explicit setup. The 9.5 release notes cite performance improvements, but there is still no native CDN or managed caching layer. The hosted offering reduces some burden but is not the default mode.

Support & Resolution
7.3.1
Support tier quality
45M

Formal paid support is available primarily through the managed hosting offering; the open-source community edition relies on forums and community channels. 2025–2026 reviews continue to flag that 'development support is limited, making receiving assistance for rare or undocumented difficulties difficult' and that developer documentation lags. Reasonable for an open-source CMS but not SLA-backed for self-hosters.

7.3.2
Community support quality
52M

Concrete CMS maintains an active, passionate community — 2025 reviews note 'there is always someone on the forums to help' and the team publishes regular community round-ups. It remains much smaller than WordPress/Joomla communities, and documentation gaps mean edge-case questions can go without good answers.

7.3.3
Issue resolution velocity
52M

2026 demonstrated strong security response velocity: 9.5.1 shipped roughly three weeks after 9.5.0 to fix five CVEs including RCE-class issues, followed by 9.5.2 a few weeks later for dependency vulnerabilities, with transparent advisories via HackerOne and the security page. General non-security bug resolution still follows community contribution cadence, which is slower than a fully staffed vendor — keeping this below the 60+ band.

8Use-Case Fit41
Marketing Sites
8.1.1
Landing page tooling
66H

Concrete CMS has a native drag-and-drop block editor where marketers can add layout columns and drop content blocks without writing code. Page types for ad landing pages can be excluded from navigation. Scores 66 rather than higher because the block-area model is less WYSIWYG than modern page builders like Elementor and requires some setup for custom layouts.

8.1.2
Campaign management
35M

Concrete CMS has scheduled publishing and integrations with Mailchimp, Constant Contact, and Mautic via add-ons, but no native campaign management, content calendar, or multi-channel campaign coordination. Marketers must rely entirely on external tools for campaign lifecycle. Score reflects the typical range for traditional CMS platforms without dedicated campaign tooling.

8.1.3
SEO tooling
69H

Concrete CMS includes built-in SEO controls: meta title/description/keywords per page, a Bulk SEO Updater for site-wide meta management, custom URL slugs, automatic XML sitemap generation, and redirect management. The official SEO feature page details these capabilities. Missing Schema.org structured data automation keeps it below 75.

8.1.4
Performance marketing
52M

A native form builder (drag-and-drop, no code) is included for lead capture. Integration with external marketing automation (Mailchimp, Mautic) is available but no built-in conversion tracking, UTM parameter management, or CTA analytics. Score reflects solid form handling with minimal native conversion tooling.

8.1.5
Personalization and targeting
30M

Concrete CMS supports user-group-based content visibility — pages and blocks can be shown or hidden based on authenticated user groups — providing basic rule-based targeting. However, there is no native behavioral targeting, geo-targeting, or AI-driven personalization engine. The marketplace does not list a dedicated personalization add-on. This places it in the 15–35 range for limited native personalization with third-party dependency.

8.1.6
A/B testing and experimentation
20M

No native A/B testing or experimentation capability is present in Concrete CMS core or the current marketplace. A legacy 'Experimenter' add-on (block-level A/B/multivariate testing) exists only on the archived concrete5-era marketplace and is not maintained for v9. Teams would need to integrate VWO or Optimizely via external script injection, with no tight CMS-level integration. Scores at the floor of the scale for this item.

8.1.7
Content velocity
64H

Inline editing directly on the front-end is a core differentiator for Concrete CMS — editors click any block to edit in place without navigating to a dashboard. Page types serve as templates for fast new-page creation. Block library enables drag-and-drop reuse without developer involvement. The 9.4.0 release (May 2025) added dashboard bulk page editing — page type, template, theme, and caching settings can now be changed across many pages at once — strengthening bulk operations alongside the existing Bulk SEO Updater. Scores 64 rather than 70+ because complex multi-region layouts still benefit from developer setup, and there is no AI-assisted content drafting.

8.1.8
Multi-channel publishing
35M

Concrete CMS is primarily a web-delivery CMS, but the built-in REST API (shipped in 9.2+, with OAuth2 and OpenID Connect authentication and documented endpoints) now enables genuine API-based content delivery to other channels. However, the API is not headless-first — limited filtering/sorting depth, no GraphQL (the 2022 proposal's GraphQL work never started), and no official SDKs for any language. Content models remain page-tree-based rather than structured for channel renditions, and no email, push, social, or in-app delivery is built in. Score reflects functional API delivery without multi-channel tooling.

8.1.9
Marketing analytics integration
42M

Concrete CMS supports Google Analytics and similar tag-based integrations through the dashboard's tracking code injection and via add-ons in the marketplace. There are no native content performance dashboards or engagement metrics within the CMS itself. The official features page mentions 'consolidated reporting' but this refers to form/data reporting rather than marketing analytics. Score reflects standard tag integration with external analytics tools.

8.1.10
Brand and design consistency
55M

Concrete CMS has a Style Editor that allows administrators to define brand-level typography, colors, and layout tokens applied across the site. Page types and block templates enforce structural consistency. However, there is no hard lock-down mechanism preventing editors from overriding brand tokens on individual blocks, and there is no design token system comparable to modern component libraries. Score reflects component-based consistency without enforcement.

8.1.11
Social and sharing integration
42M

Concrete CMS 9.4.0 added native Open Graph support for social media sharing control, complementing the SEO block's Twitter Card meta management. Social sharing widgets are available as marketplace add-ons. There is no native push-to-social scheduling or UGC embed tooling. Scores in the 30–50 range for OG/card meta tag management plus marketplace-available sharing widgets.

8.1.12
Marketing asset management
42M

Concrete CMS has a built-in File Manager that handles image uploads, auto-generates thumbnails at configurable sizes, supports file tagging and folder organization, and provides a usage tracker to see where assets are used. This is functional for moderate marketing volumes but lacks rights management, video hosting, advanced image transforms (beyond thumbnail presets), and DAM-grade search. Scores in the 35–55 range for basic media library with some transforms.

8.1.13
Marketing localization
50M

Concrete CMS has built-in multilingual support with separate page trees per language, synchronized content relationships, and a dashboard translation interface. This supports generic localization of marketing content including locale-specific page variants. However, there are no marketing-specific transcreation workflows, locale-level campaign scheduling, or regional compliance tools (cookie consent, legal disclaimers) beyond what can be manually built. Score reflects generic localization applied to marketing content.

8.1.14
MarTech ecosystem connectivity
42M

Concrete CMS has documented integrations with Mailchimp, Constant Contact, and Mautic (email/MAP category) via marketplace add-ons. The marketplace also lists HubSpot and Salesforce integrations. However, these represent shallow embed or form-sync integrations rather than deep API-level event triggers or CDP connectivity. No pre-built ad platform or bidirectional CRM connectors were found. Score reflects some integrations plus generic webhook/API capability.

Commerce
8.2.1
Product content depth
46M

The Community Store add-on enables basic product content: images, variants (size/color) with distinct pricing, stock tracking, and product grids. However, it is a community-maintained add-on, not a core feature, and is not purpose-built for rich editorial product content at scale. Community Store remains actively maintained (2026, compatible with v8 and v9) but reviews note limited ecommerce maturity versus dedicated platforms.

8.2.2
Merchandising tools
24M

Community Store includes basic discount codes and automatic discounts but has no cross-sell/upsell content management, category search merchandising, or promotional content scheduling tools. This is typical for CMS-based community add-ons; Concrete CMS is not a commerce-first platform.

8.2.3
Commerce platform synergy
40M

Two Shopify integration add-ons are on the Concrete CMS Marketplace — 'eCommerce with Shopify' (configurable Shopify storefront embedding) and 'Hutman Shopify Integration' (imports Shopify products into Concrete pages) — and Ecwid also offers a shopping cart add-on. These remain embed/product-import integrations rather than deep API federation or real-time content+product co-authoring. No documented integration with commercetools, SFCC, or BigCommerce.

8.2.4
Content-driven storytelling
32M

Concrete CMS pages can embed Community Store product blocks alongside editorial content blocks, enabling basic product-in-context layouts. However, shoppable content, buying guide templates, or lookbook authoring patterns are not first-class features — they require manual assembly from generic blocks. No native inline product reference with purchase CTA tooling. Score reflects product embeds possible but not a purpose-built editorial commerce pattern.

8.2.5
Checkout and cart content
22M

Community Store has a single-page checkout flow (billing, shipping, payment) but this is rendered by the add-on, not the CMS content editor. There is no mechanism to inject CMS-managed trust badges, upsell banners, or post-add modals into the checkout flow without template modification. Scores near the floor as checkout content is fully in the Community Store template.

8.2.6
Post-purchase content
22M

Community Store supports automatic digital product downloads after purchase, providing a minimal post-purchase CMS content experience. Order confirmation emails are template-based within Community Store, not CMS-managed pages. No delivery tracking pages, loyalty program content, or review solicitation content sequences managed from the CMS. Scores near the floor.

8.2.7
B2B commerce content
30M

Concrete CMS's granular user-group permissions can gate product documentation or catalog pages to authenticated B2B users, providing basic access-controlled content. However, there are no B2B-specific features: no customer-specific pricing display, no quote-request workflow, no account-based catalog segmentation. Score reflects basic access control applicable to B2B without purpose-built B2B commerce content features.

8.2.8
Search and discovery content
32M

Concrete CMS has a built-in site search (using PHP/MySQL full-text or Solr integration for larger deployments). Community Store products appear in site search. However, there is no faceted search enrichment, no search landing page tooling, and no blended content-product search result management. Score reflects basic search with minimal content-side enrichment for commerce.

8.2.9
Promotional content management
35M

Scheduled publishing in Concrete CMS core allows time-limited promotional banners to be activated and deactivated without developer involvement. Community Store supports discount codes with time limits. However, there are no countdown timers, promo code messaging blocks, or channel-specific promotional targeting natively. Score reflects basic scheduled banners slightly above the floor.

8.2.10
Multi-storefront content
40M

The multi-site architecture can serve multiple storefronts from one installation, each with its own content tree, theme, and user base. Shared block/template components reduce duplication. However, product content between storefronts is not natively federated — each site manages its own product pages via Community Store instances, creating some duplication. Score reflects multi-storefront possible with partial content sharing.

8.2.11
Visual commerce and media
35M

Community Store supports multiple product images with lightbox display. The file manager auto-generates thumbnails. Video embeds via YouTube/Vimeo blocks are possible on product pages. However, there are no 360-degree view capabilities, AR/3D model references, or image hotspot tooling natively. Score reflects basic image galleries and video embeds without advanced visual commerce features.

8.2.12
Marketplace and seller content
20M

Community Store is a single-vendor storefront add-on with no multi-vendor marketplace capability. There are no seller profile pages, seller-contributed product descriptions, or content quality moderation at multi-vendor scale in either core Concrete CMS or Community Store. This is beyond the platform's intended scope.

8.2.13
Commerce content localization
40M

The built-in multilingual system with separate page trees can be applied to product pages managed via Community Store, enabling locale-specific product descriptions. However, there is no currency-aware content block system, no regional regulatory content automation (EU labels, Prop 65), and no market-specific promo calendar. Score reflects generic localization applied to product content without commerce-specific locale tooling.

8.2.14
Commerce conversion analytics
25M

Google Analytics and GA4 can be integrated via script injection to track commerce events from Community Store checkouts, but this requires manual configuration and analysis happens entirely in GA4. There is no native content-to-revenue attribution within the CMS, no content-assisted conversion tracking dashboard. Score reflects basic analytics integration with conversion data in fully external tools.

Intranet & Internal
8.3.1
Access control depth
68H

Concrete CMS has a well-documented granular permissions system: permissions can be set at page, page type, or area level, inherited by child pages, and scoped to user groups, individual users, or custom roles. SSO integration is supported and used in production (BASF enterprise intranet case study). ISO 27001/SOC 2/HIPAA certification confirms enterprise-grade security posture. Score stops short of 75 because field-level sensitivity is not a native feature.

8.3.2
Knowledge management
52M

Concrete CMS supports version history, approval workflows, and content moderation which covers basic knowledge article lifecycle. There is no native knowledge taxonomy, content expiry/review scheduling, or internal search tuning beyond site search defaults. Functional for moderate intranet needs but lacks dedicated knowledge management tooling.

8.3.3
Employee experience
50M

Concrete CMS actively markets HR portal and internal communications solutions with configurable news feeds, team pages, and SSO-backed access — a step above most generic CMS platforms for intranet use. The Army Senior Executive Portal case study reports usage growth (cited at ~150%) after a UX-focused rebuild, adding to the government portal case study roster. However, it lacks native employee directory integration, social features (likes/comments), or a mobile app, keeping it in the low-50s rather than 60+.

8.3.4
Internal communications
45M

Concrete CMS supports targeted news publishing by user group, enabling department-specific announcements. The HR portal and internal communications solution page highlights news feeds and workflow-backed approvals. However, there are no read receipts, acknowledgment tracking, or mandatory-read workflows in core or the marketplace. Score is in the 30–50 range for basic news publishing with audience targeting.

8.3.5
People directory and org chart
28M

Concrete CMS has no native employee directory or org chart visualization. User profiles exist in the system but are minimal (name, email, groups). A directory could be custom-built using page types and the member list block, but this requires developer effort and is not a configurable out-of-the-box feature. No HR system integration (Workday, BambooHR) is documented. Score reflects basic directory buildable with custom development.

8.3.6
Policy and document management
42M

Concrete CMS provides version history (full page version control), multi-level approval workflows, and content expiration — covering the basics of policy document lifecycle. There is no mandatory acknowledgment tracking, no automated review expiry reminders for policy authors, and no audit trail viewer beyond version history. Score reflects basic document publishing with version control above the floor.

8.3.7
Onboarding content delivery
32M

The HR portal application page references onboarding workflows and structured content for new hires, enabled by Concrete CMS's page-type system and access control. However, there are no structured onboarding journeys with progressive disclosure over 30/60/90 days, role-specific content paths, or task checklists that activate automatically from an HR event. What exists is the ability to build onboarding pages rather than a purpose-built onboarding delivery system.

8.3.8
Enterprise search quality
38M

Concrete CMS has built-in site search based on MySQL full-text indexing for smaller deployments, with a Solr/Elasticsearch add-on available for larger installations. Search covers pages, files, and user-submitted content. There is no federated search across external systems (SharePoint, Confluence), no AI-powered relevance ranking, and limited faceted filtering. Score reflects adequate internal search with basic faceting capability.

8.3.9
Mobile and frontline access
30M

Concrete CMS front-end themes are responsive and render on mobile browsers. The inline editing interface is available on mobile browsers but is not optimized for touchscreen use. There is no native mobile app, no offline support, no push notifications, and no low-bandwidth mode or kiosk/shared-device configuration. Score reflects responsive web access without native mobile app support.

8.3.10
Learning and training integration
25M

Concrete CMS can host training content as standard web pages or documents accessible to specific user groups. The HR portal page mentions training materials. However, there is no LMS integration (Cornerstone, Workday Learning), no course assignment, completion tracking, or certification management in core or the marketplace. Score reflects basic learning content hosting without any tracking or LMS connectivity.

8.3.11
Social and collaboration features
32M

Concrete CMS HR portal and intranet marketing reference employee recognition tools and engagement surveys, but evidence for native social features is thin. The Conversation block provides threaded discussion on pages. There are no reactions, polls, community spaces by department/interest, or peer recognition workflows in core. The Conversation block and community forum usage suggest limited social capability rather than a full social layer.

8.3.12
Workplace tool integration
25L

No documented integration with Microsoft 365/Teams, Google Workspace, or Slack was found in the Concrete CMS marketplace or official documentation. SSO can authenticate against Azure AD (Microsoft) or Google via third-party add-ons, but that does not constitute embedded content cards or bot-driven notifications in workplace tools. Score reflects no meaningful workplace tool integration.

8.3.13
Content lifecycle and archival
44M

Concrete CMS has content expiration dates in core — pages can be set to expire automatically on a future date. Version history enables rollback. Approval workflows provide a structured review cycle. However, there is no automated stale content flagging based on age, no ownership assignment for review reminders, and no formal archival workflow. Score reflects basic content expiry and manual review above the floor.

8.3.14
Internal analytics and engagement
30M

Concrete CMS HR portal marketing references analytics and reporting for employee engagement. However, no native department-level page view analytics, failed search term dashboards, or intranet adoption dashboards exist in the platform. Analytics relies on GA4 or similar external tools injected via script. Score reflects basic page view analytics available externally without intranet-specific engagement measurement.

Multi-Brand / Multi-Tenant
8.4.1
Tenant isolation
58M

Concrete CMS supports multi-site architecture from a single installation with separate content trees, separate user bases, and configurable permission isolation per site. The IMCOM case study (hundreds of garrison websites on one install with compliance controls) validates silo-based isolation at scale. This is not a true multi-tenant SaaS architecture with independent environments, but provides meaningful silo-based separation.

8.4.2
Shared component library
58M

Multi-site installs in Concrete CMS share a single codebase, theme, and block library, allowing centrally maintained templates and blocks to be reused across all sites while permitting local overrides. Branding consistency is a stated feature of the multi-site product. Not a federated content API model but provides shared component infrastructure through the install architecture.

8.4.3
Governance model
62M

The IMCOM deployment demonstrates centralized compliance and security controls across hundreds of sites, with thousands of individual content managers operating within enforced governance. Concrete CMS provides multi-level approval workflows, page-level and block-level access controls, content expiration, and centralized user management across the multi-site network. Cross-brand approval workflows are limited to within-site workflows rather than a true cross-brand governance console.

8.4.4
Scale economics
65M

Concrete CMS is open source (free community edition), so adding sites does not incur per-brand licensing fees — only infrastructure and managed hosting costs scale. The multi-site architecture runs many sites on one install, reducing server overhead versus separate deployments. Commercial support packages exist but are not required per-site.

8.4.5
Brand theming and style isolation
52M

Each site in a Concrete CMS multi-site installation can have its own theme, color palette, typography, and style settings via the Style Editor. Per-site theme assignment and style customization are straightforward. However, this is CSS/configuration-level theming rather than a design token system with inheritance from a central brand library. Score reflects basic CSS/config theming per brand with shared component structures.

8.4.6
Localized content governance
40M

The multilingual system combined with multi-site architecture allows per-brand, per-locale content trees. Each brand/site can have its own translation workflow via the dashboard. However, there is no governance layer for brand-aware translation approvals, no differentiation between shared vs. isolated translation workflows at the brand level, and no regional legal content governance per brand. Score reflects basic per-brand localization with shared workflows.

8.4.7
Cross-brand analytics
25L

No cross-brand analytics dashboard exists in Concrete CMS. Each site's analytics relies on separately configured external tools (GA4, etc.), and there is no aggregated portfolio view of content performance across sites. A multi-site admin can navigate between sites but sees no unified metrics. Score reflects no cross-brand analytics with manual aggregation required.

8.4.8
Brand-specific workflows
48M

Approval workflows in Concrete CMS can be configured per page type and per site, giving individual brand sites some control over their publishing workflow stages and approvers. The multi-site admin can see and manage all sites but workflow configuration is per-site. There is no central workflow audit console spanning all brands. Score reflects some workflow variants per brand without central audit trail across brands.

8.4.9
Content syndication and sharing
40M

In a multi-site Concrete CMS installation, globally shared blocks, templates, and page types cascade to all sites from the central codebase. However, there is no CMS-level mechanism to push a specific piece of content (e.g., a press release or legal disclaimer) from a corporate parent site to child brand sites with controlled override points. Content syndication requires developer-built solutions. Score reflects basic content sharing through architecture with no native push-syndication workflow.

8.4.10
Regional compliance controls
44M

Concrete CMS has ISO 27001/SOC 2/HIPAA certifications and per-site configuration options allowing compliance settings (cookie consent, legal page content) to be managed per brand. Cookie consent add-ons are available in the marketplace. However, there are no automated publishing guardrails preventing non-compliant content, no per-brand accessibility enforcement, and no data residency configuration per tenant. Score reflects basic compliance settings available per brand without automated guardrails.

8.4.11
Design system management
44M

The shared codebase in a Concrete CMS multi-site installation provides a centrally maintained block and template library that all sites inherit. Individual sites can override theme styles. However, there is no formal design system versioning, no component versioning with update propagation, and no brand-level extension model beyond CSS overrides. Score reflects shared components with some brand override but no formal design system management.

8.4.12
Cross-brand user management
55M

In a Concrete CMS multi-site installation, a super-admin can manage users, groups, and permissions across all sites from the main dashboard. SSO via SAML is supported and can span all sites. Individual brand teams can be granted autonomous admin rights within their site. This provides meaningful central oversight with brand team autonomy, though there is no SCIM provisioning or true cross-brand contributor role that spans sites without super-admin privileges.

8.4.13
Multi-brand content modeling
40M

All sites in a Concrete CMS multi-site installation share the same block types and page type templates from the central codebase. Per-brand content type extensions require code changes rather than configuration, meaning adding brand-specific fields involves developer work and risks diverging the codebase. There is no interface for per-brand content model extension without forking. Score reflects basic shared types with limited no-code customization per brand.

8.4.14
Portfolio-level reporting
25L

There is no executive portfolio reporting dashboard across the Concrete CMS multi-site network. A super-admin navigates to individual sites and views their own content/form reports. Content freshness, publishing SLA adherence, and capacity metrics across the portfolio are not aggregated anywhere in the platform. Manual aggregation from external analytics tools would be required. Score reflects no portfolio reporting capability.

9Regulatory Readiness & Trust51
Data Privacy & Regulatory
9.1.1
GDPR & EU data protection
44M

PortlandLabs now offers a standard Data Privacy Addendum (DPA) to hosting clients on request, and the platform is stated to be aligned with GDPR controls — a real improvement over the prior no-DPA posture. However, the public privacy policy still references the invalidated EU-US Privacy Shield framework (struck down 2020) rather than SCCs or the EU-US Data Privacy Framework, no public sub-processor list is published, and no EU data residency option exists (hosting is US-only). The stale transfer mechanism and residency gap hold this below the 60+ DPA band.

9.1.2
HIPAA & healthcare compliance
74H

A Business Associate Agreement (BAA) is now explicitly available: hosting customers collecting PHI are directed to contact their account rep or [email protected] to enter into a BAA, and healthcare use is documented on a dedicated page (health-care form fields, uploads, encryption at rest and in transit). PortlandLabs hosting is externally audited for HIPAA Security Rule and HITECH controls. Not higher because HIPAA coverage is limited to managed hosting (not self-hosted open source) and there is no HITRUST or deep healthcare implementation guidance.

9.1.3
Regional & industry regulations
68M

PortlandLabs hosting meets FedRAMP Moderate controls at DoD Impact Level 2 with continuous monitoring, and states compliance with the controls for HIPAA, HITECH, PCI-DSS, COPPA, GDPR, CCPA and PIPEDA — broader regional coverage (now including CCPA, PIPEDA, COPPA) than previously documented. Not higher because several frameworks are self-attested 'controls' alignment rather than independent certifications, and UK GDPR/IDTA, LGPD, IRAP, and C5 remain unaddressed.

Security Certifications
9.2.1
SOC 2 Type II
65M

SOC 2 Type 2 is confirmed covering Security and Availability Trust Service Criteria, with the report available on request, and the scope explicitly includes development of the open-source Concrete CMS as well as hosting. Supply-chain SOC 2 reports (AWS, Atlassian, Google Cloud, New Relic carve-outs) are reviewed. Confidentiality, Processing Integrity, and Privacy TSCs are not covered, keeping this below the 85+ band.

9.2.2
ISO 27001 / ISO 27018
62M

PortlandLabs holds ISO 27001 certification — 'This certification proves that Portlandlabs has a robust security and risk management program' — with the certificate available on request. No ISO 27018 (cloud PII processing) is mentioned anywhere. The certification covers PortlandLabs' hosting and development operations, not the open-source software package independently, so it falls in the infrastructure/operations band.

9.2.3
Additional certifications
68M

Beyond SOC 2 and ISO 27001, PortlandLabs meets FedRAMP Moderate (DoD IL2) controls with continuous monitoring and has PCI-DSS and HIPAA/HITECH external audit validation, plus US Army PIV authentication licensing. The open-source core runs a HackerOne vulnerability disclosure program with monthly patches and CVE tracking on NIST, and infrastructure access uses FIPS 140-2 MFA. This is an unusually strong portfolio for a tier-4 traditional CMS; no CSA STAR, Cyber Essentials Plus, IRAP, or C5.

Data Governance
9.3.1
Data residency & sovereignty
35M

Hosting infrastructure remains AWS US-based and the FedRAMP environment is inherently US-only. No EU or APAC data residency options or contractual residency guarantees are documented on any hosting page. Self-hosted deployments can choose any region, but without vendor contractual guarantees that does not earn residency credit — a significant gap for EU-based customers.

9.3.2
Data lifecycle & deletion
45L

The Hosting Privacy Policy page now resolves (previously 404) and the DPA covers data-handling obligations for hosting clients, so documentation has improved. A 'Personal Information Deletion' process is listed in the legal index, and for the open-source platform full database export is inherently available. Still no documented self-service export portal for hosted customers, no published post-termination retention period, and deletion tooling specifics remain thin.

9.3.3
Audit logging & compliance reporting
45M

Concrete CMS provides an audit trail that tracks all content changes (who changed what and when) alongside login history, email logging, and error logging. However, no SIEM integration, configurable log retention, or log export APIs are documented. Present but basic — not enterprise compliance-reporting grade.

Platform Accessibility
9.4.1
Authoring UI accessibility
35L

No formal WCAG 2.1 AA conformance documentation exists for the Concrete CMS authoring interface, and no ATAG 2.0 commitment is documented. The accessibility offerings found (e.g. the All-in-One Accessibility marketplace widget) target the delivered public website, not the CMS editor, and so do not count toward authoring-UI conformance. Federal usage (US Army portal licensing) implies some Section 508 attention in practice, but no formal editor conformance statement is published.

9.4.2
Accessibility documentation
28L

No official VPAT or ACR for Concrete CMS was found on concretecms.com, concretecms.org, or in the legal index, and no Section 508 formal conformance statement is published. VPAT results that surface are third-party marketplace audit services for customer sites, not a product accessibility conformance report. Given federal usage a VPAT may exist on request, but it is not publicly accessible for procurement — which is what this item measures.

10AI Enablement20
AI Content Creation
10.1.1
AI text generation & editing
30M

The 'AI Integration - GPT 4 Turbo' marketplace add-on (De Webmakers, updated Jan 2026, requires v9.3.0+) delivers GPT-4 Turbo content generation with WYSIWYG editor integration. Core remains AI-free through 9.5.0 (which shipped Twig templating + PHP 8.5, no AI); AI integration for site building and content optimization now appears on the official roadmap but has not shipped. No brand voice controls, prompt templates, or native assistance — capped at the third-party-plugin band.

10.1.2
AI image & media generation
20M

The Brand Central DAM add-on uses AI to auto-tag uploaded media files with relevant metadata, improving searchability. No smart focal crop, no native auto alt-text generation, and no AI image generation are documented in core or marketplace through the 9.4.x/9.5.0 releases. Auto-tagging remains the only confirmed AI media feature.

10.1.3
AI translation assistance
15M

No native machine translation in Concrete CMS core through 9.5.0. Linguise (third-party SaaS) can integrate via script injection and API key, using Google Cloud Neural MT and a proprietary LLM model, but this is a fully external cloud service. No core changelog or marketplace entries reference MT features.

10.1.4
AI metadata & SEO automation
28M

The 'AI Integration - GPT 4 Turbo' add-on generates SEO meta titles/descriptions and confirms bulk SEO updates across pages (marketplace listing, Jan 2026). The 'Large Language Models Generator' add-on generates an /llms.txt AI-discoverable site inventory. Both are third-party marketplace add-ons, not core — no on-page SEO scoring or native automation.

AI Workflow Automation
10.2.1
AI-assisted content operations
22M

AI-powered metadata auto-tagging on media upload (Brand Central DAM) plus bulk SEO updates via the AI Integration add-on are the only confirmed AI ops assists, both outside core. Official blog posts describe AI scheduling and content lifecycle automation aspirationally; no AI content-ops features have shipped in core through 9.5.0.

10.2.2
Agentic workflow automation
5H

No agentic products exist in the Concrete CMS ecosystem as of mid-2026 — no named agent suite, multi-step content pipeline, or autonomous automation. The org roadmap now lists generic 'AI integration for site building and content optimization' as planned, but this is neither agentic-specific nor shipped; the project's concrete AI activity remains a contributor AI-use policy and community 'skills files' for external coding assistants.

10.2.3
Content intelligence & insights
10H

No content intelligence features exist. The blog post mentions AI could 'identify stale, duplicated, or outdated pages' but frames this as general guidance for external tools, not as a Concrete CMS feature. No marketplace add-on delivers content gap analysis, topic clustering, or AI editorial recommendations as of mid-2026.

10.2.4
AI content auditing & quality
10H

No AI auditing tool exists in core or marketplace through 9.5.0. The 'Smart Ways to Integrate AI' blog post lists editorial QA and tone checking as recommended external AI use cases, but no Concrete CMS add-on implements these. A third-party accessibility widget (Skynet Technologies) is rule-based, not AI-driven.

AI Search & Personalization
10.3.1
AI/semantic search
15H

Concrete CMS uses standard full-text search with no vector or semantic search capability through 9.5.0. No marketplace add-on or core feature provides AI-enhanced relevance ranking, embedding generation, or RAG-ready content indexing. Custom external integration would require substantial developer work from scratch.

10.3.2
AI-powered personalization
12M

No native ML personalization engine. The 'Poper Widgets Popups Embeds Powered by AI' marketplace add-on is an external SaaS JavaScript embed that adapts CTAs based on visitor context, but it operates outside the CMS layer. No predictive audience segmentation, no behavioral ML, no native A/B testing with AI as of mid-2026.

AI Platform & Extensibility
10.4.1
MCP server availability
42M

The community-built TypeScript concretecms-mcp-server (MacareuxDigital) remains the only MCP option: it wraps the REST API with OAuth2 auth (loading openapi.yml to discover endpoints) and supports system info, content read/write, file upload, and user access. As of mid-2026 it has minimal adoption and no formal releases published, is not officially endorsed by Concrete CMS, and lists a remote Streamable-HTTP server as a future goal — keeping it below the well-supported-community band.

10.4.2
Bring your own AI model/key (BYOM/BYOK)
32M

BYOK is confirmed: the 'AI Integration - GPT 4 Turbo' add-on (free, Jan 2026) requires users to supply their own OpenAI API key, configured via the dashboard's AI Integration settings page. However, it is a third-party marketplace add-on limited to a single provider (OpenAI) — no official Concrete CMS BYOM framework, no Anthropic/Azure/Gemini support, no model switcher.

10.4.3
AI developer extensibility & agent APIs
28M

Concrete CMS is open-source (MIT, PHP) with a REST API usable for AI consumption, as demonstrated by the community MCP server that reads its openapi.yml. No official AI SDK, no LangChain/LlamaIndex connectors, and no LLM-friendly content API. The community 'skills files' initiative (structured Markdown docs to help coding LLMs work with Concrete) remains a proposal — AI tooling is still developer-DIY.

10.4.4
AI governance, safety & audit trails
20M

Concrete CMS has mature general-purpose governance — approval workflows requiring human review before publish, comprehensive audit trail, ISO 27001, SOC 2, HIPAA compliance, and role-based permissions — serving as de facto AI safety layers. The official AI policy governs contributor AI use in the open-source project, not AI output in the product. No AI-specific output logging, decision audit trail, or prompt governance exists.

10.4.5
AI observability & usage analytics
8H

No AI usage dashboards, token consumption tracking, model performance monitoring, or AI observability tooling exists in Concrete CMS core or marketplace. AI usage through the BYOK AI Integration add-on is entirely opaque to CMS administrators — cost and usage monitoring relies on the user's own OpenAI dashboard.

Score History

How composite scores (0–100) have changed over time. Click legend items to show/hide metrics.

+8.7 capability
analyst note

Recent Updates

July 202620 score changes

Concrete CMS is on a modestly improving trajectory, with the movement almost entirely concentrated in Compliance & Trust, which jumped from 46.3 to 50.9 while Capability, Platform Velocity, Cost Efficiency, Build Simplicity, and Operational Ease held essentially flat. The compliance gain reflects PortlandLabs formalizing its hosting posture: an explicitly available BAA for HIPAA workloads, published SOC 2 Type 2 and ISO 27001 certifications, and a standard GDPR Data Privacy Addendum, which together make the platform newly viable for regulated-industry evaluations where it was previously a non-starter. Practitioners should note the one countervailing signal — the security track record score slipped slightly — so the strengthened certifications should be weighed alongside the platform's ongoing vulnerability disclosure activity rather than taken as a blanket security upgrade.

Score Changes

HIPAA & healthcare compliance5074(+24)

A Business Associate Agreement (BAA) is now explicitly available: hosting customers collecting PHI are directed to contact their account rep or [email protected] to enter into a BAA, and healthcare use is documented on a dedicated page (health-care form fields, uploads, encryption at rest and in transit). PortlandLabs hosting is externally audited for HIPAA Security Rule and HITECH controls. Not higher because HIPAA coverage is limited to managed hosting (not self-hosted open source) and there is no HITRUST or deep healthcare implementation guidance.

Compliance certifications3858(+20)

PortlandLabs now publishes a dedicated hosting compliance page detailing SOC 2 Type 2 and ISO 27001 certification plus HIPAA compliance and FedRAMP Moderate / DoD IL2 controls with continuous monitoring for the managed hosting tier, backed by specifics (AWS CIS benchmarks, FIPS 140-2 MFA, encryption at rest/in transit, annual independent penetration and DR testing) — a substantial, well-documented improvement over the prior thin posture. It stays below the 80+ band because the certifications cover only the managed hosting offering (Concrete is predominantly self-hosted, where compliance is operator-owned), there is no explicit GDPR/EU data residency claim, and no public trust portal or audit reports are accessible.

GDPR & EU data protection2844(+16)

PortlandLabs now offers a standard Data Privacy Addendum (DPA) to hosting clients on request, and the platform is stated to be aligned with GDPR controls — a real improvement over the prior no-DPA posture. However, the public privacy policy still references the invalidated EU-US Privacy Shield framework (struck down 2020) rather than SCCs or the EU-US Data Privacy Framework, no public sub-processor list is published, and no EU data residency option exists (hosting is US-only). The stale transfer mechanism and residency gap hold this below the 60+ DPA band.

Security track record6356(-7)

Concrete CMS operates a HackerOne responsible disclosure program and is a CVE Numbering Authority with high-quality advisories and prompt patching, and has no known major data breach. However, 2026 was a heavy vulnerability year: CVE-2026-7888 (unauthenticated PHP object injection RCE via unsafe unserialize() in Workflow/Form/File components, CVSS v4.0 8.4 High, fixed 9.5.2), CVE-2026-3452 (authenticated RCE via Express Entry List, fixed 9.4.8), CVE-2026-8350 (privilege escalation to admin group), CVE-2026-8203 (stored XSS), plus earlier CSRF-to-RCE issues. The shift into unauthenticated-RCE-class findings, despite transparent disclosure and fast fixes, holds this in the mid-50s.

Bring your own AI model/key (BYOM/BYOK)2532(+7)

BYOK is confirmed: the 'AI Integration - GPT 4 Turbo' add-on (free, Jan 2026) requires users to supply their own OpenAI API key, configured via the dashboard's AI Integration settings page. However, it is a third-party marketplace add-on limited to a single provider (OpenAI) — no official Concrete CMS BYOM framework, no Anthropic/Azure/Gemini support, no model switcher.

Regional & industry regulations6268(+6)

PortlandLabs hosting meets FedRAMP Moderate controls at DoD Impact Level 2 with continuous monitoring, and states compliance with the controls for HIPAA, HITECH, PCI-DSS, COPPA, GDPR, CCPA and PIPEDA — broader regional coverage (now including CCPA, PIPEDA, COPPA) than previously documented. Not higher because several frameworks are self-attested 'controls' alignment rather than independent certifications, and UK GDPR/IDTA, LGPD, IRAP, and C5 remain unaddressed.

Role-based permissions & governance5055(+5)

Concrete CMS has a notably granular permission architecture: custom role creation, group-based assignments, content-level ACL per page/section, time-based permissions, and permission exclusions for individual users. SAML 2.0 SSO is available via the Macareux SAML Authentication marketplace add-on (multiple IdPs, attribute and group mapping, documented Entra ID setup) — a material improvement over the prior LDAP-only situation. Still no field-level permissions and no SCIM, keeping this below the 65+ tier.

Multi-channel publishing3035(+5)

Concrete CMS is primarily a web-delivery CMS, but the built-in REST API (shipped in 9.2+, with OAuth2 and OpenID Connect authentication and documented endpoints) now enables genuine API-based content delivery to other channels. However, the API is not headless-first — limited filtering/sorting depth, no GraphQL (the 2022 proposal's GraphQL work never started), and no official SDKs for any language. Content models remain page-tree-based rather than structured for channel renditions, and no email, push, social, or in-app delivery is built in. Score reflects functional API delivery without multi-channel tooling.

Rich text capabilities6258(-4)

Concrete CMS still ships CKEditor 4 (pinned at 4.22.1), a library that reached end-of-life in June 2023; the roadmap lists Concrete 10 as a future focus with the editor still undecided ('CKEditor or something new?') and no CKEditor 5 upgrade planned due to license incompatibility. Formatting, embedded images/files, and paste handling are solid, but output is an HTML blob and the underlying editor remains EOL with no announced successor as of mid-2026 (9.5.2).

Release frequency6568(+3)

Concrete CMS shipped 12 releases over the past 12 months on a near-monthly cadence, including the 9.5.0 feature release (2026-04-28) adding Twig templating and PHP 8.5 support, followed by 9.5.1 (2026-05-19) and 9.5.2 (2026-06-03). Cadence is consistent with meaningful feature minors rather than patches only, but the platform is not shipping major features monthly and v10 remains unreleased, keeping it below the 75+ band.

Customer momentum4750(+3)

Concrete CMS won a third consecutive SourceForge Leader Award (Spring 2026, following Fall 2025 and Winter 2026), indicating a sustained, actively reviewing user base, and earned a TechRadar top-CMS editorial pick in April 2026. However, no major enterprise logo announcements or fresh case studies were found, so the trajectory reads as stable-with-positive-press rather than growing.

Data lifecycle & deletion4245(+3)

The Hosting Privacy Policy page now resolves (previously 404) and the DPA covers data-handling obligations for hosting clients, so documentation has improved. A 'Personal Information Deletion' process is listed in the legal index, and for the open-source platform full database export is inherently available. Still no documented self-service export portal for hosted customers, no published post-termination retention period, and deletion tooling specifics remain thin.

AI metadata & SEO automation2528(+3)

The 'AI Integration - GPT 4 Turbo' add-on generates SEO meta titles/descriptions and confirms bulk SEO updates across pages (marketplace listing, Jan 2026). The 'Large Language Models Generator' add-on generates an /llms.txt AI-discoverable site inventory. Both are third-party marketplace add-ons, not core — no on-page SEO scoring or native automation.

App marketplace & ecosystem3840(+2)

The relaunched market.concretecms.com keeps growing with monthly 2026 additions (HTMX package, AI editor tools, UI blocks) announced in town hall roundups, plus a 'Try Before You Buy' trial on SaaS hosting. Notable integrations include Shopify, Snipcart, Mailchimp, Stripe, Amazon S3, SAML SSO, and Azure CDN. The catalog remains in the low hundreds — substantially smaller than WordPress or Drupal ecosystems.

Community engagement5557(+2)

Engagement is genuine and verifiable: 122 PRs opened since 2026-01-01 (78 merged), daily forum activity, monthly town halls, named community contributors credited in every release note (mlocati, hissy, ounziw, ccmEnlil), and a 'Squash Week' core-team bug/security sprint held in May 2026 with open community participation. Constrained by small absolute community size, so it stays below the 65+ band.

Competitive positioning4547(+2)

Concrete CMS holds a clear niche — SMB and government/military sites emphasizing inline editing and granular permissions — and gained an April 2026 TechRadar editorial endorsement as an 'impressive, open-source solution.' It remains absent from Gartner MQ and Forrester Wave and is not strongly differentiated against Drupal or WordPress in broad market perception, so positioning stays defensible but narrow.

Feature gating6866(-2)

All core CMS features are fully available in the free MIT-licensed self-hosted version — no functional capability is paywalled. However, both Starter and Business managed plans explicitly state 'NO ACCESS to source code,' reserving custom code deployment for the sales-gated Custom SLA tier, and marketplace add-ons are sometimes reported as limited in selection and arbitrarily priced. Self-hosting remains a full-featured escape hatch, which limits the impact.

Configuration complexity5052(+2)

Installation via Composer + interactive CLI or zip upload is straightforward for PHP developers with standard PHP/MySQL requirements, and 9.4.x improved CLI task feedback and added JSON config support in import XML, modestly improving automation. There is still no official Docker dev environment, no environment variable management pattern, and the REST API must be explicitly enabled via the Dashboard UI; production hardening requires a separate best-practices doc.

Issue resolution velocity5052(+2)

2026 demonstrated strong security response velocity: 9.5.1 shipped roughly three weeks after 9.5.0 to fix five CVEs including RCE-class issues, followed by 9.5.2 a few weeks later for dependency vulnerabilities, with transparent advisories via HackerOne and the security page. General non-security bug resolution still follows community contribution cadence, which is slower than a fully staffed vendor — keeping this below the 60+ band.

Content velocity6264(+2)

Inline editing directly on the front-end is a core differentiator for Concrete CMS — editors click any block to edit in place without navigating to a dashboard. Page types serve as templates for fast new-page creation. Block library enables drag-and-drop reuse without developer involvement. The 9.4.0 release (May 2025) added dashboard bulk page editing — page type, template, theme, and caching settings can now be changed across many pages at once — strengthening bulk operations alongside the existing Bulk SEO Updater. Scores 64 rather than 70+ because complex multi-region layouts still benefit from developer setup, and there is no AI-assisted content drafting.

June 20261 score change

Concrete CMS is essentially stable this cycle, with every composite dimension holding flat except for a marginal 0.2-point dip in Operational Ease. The movement is driven entirely by a small downtick in issue resolution velocity, where the 9.5.1 security patch shipping three weeks after 9.5.0 to address five CVEs nudged the underlying signal lower. Practitioners should read this as a non-event for capability, cost, and compliance posture, but worth noting that maintenance cadence remains the platform's most sensitive lever.

Score Changes

Issue resolution velocity5250(-2)

2026 demonstrated strong security response velocity: 9.5.1 shipped roughly three weeks after 9.5.0 to fix five CVEs including RCE-class issues, followed by 9.5.2 a few weeks later for dependency vulnerabilities, with transparent advisories via HackerOne and the security page. General non-security bug resolution still follows community contribution cadence, which is slower than a fully staffed vendor — keeping this below the 60+ band.

March 2026

Concrete CMS remains a niche traditional CMS with solid in-context editing and favorable cost of ownership, but limited developer ecosystem growth and slow release cadence constrain its competitiveness. The platform serves existing installations well but struggles to attract new projects in a market dominated by WordPress, headless CMSes, and composable DXPs.

Platform News

  • Concrete CMS community status quo

    Platform continues in maintenance mode with a small but dedicated community supporting existing deployments.

June 2025

Concrete CMS enters a steady-state maintenance phase with infrequent releases. The platform retains its strengths in in-context editing and low total cost of ownership but shows little innovation. Regulatory readiness improves slightly as the team adds basic compliance documentation, though it still lacks enterprise-grade certifications.

Platform News

  • Security hardening and GDPR documentation updates

    Improved privacy tooling and compliance documentation for European deployments.

August 2024

Release cadence slows as the small core team focuses on maintenance rather than major feature development. The platform remains functional and cost-effective but falls further behind competitors in API capabilities, headless delivery, and modern developer experience. Community contributions have declined noticeably.

Platform News

  • Concrete CMS v9.3.x maintenance releases

    Focus on PHP 8.2/8.3 compatibility, security patches, and minor UX improvements.

  • Marketplace activity decline

    Fewer new addons being published as developer community shrinks relative to larger CMS ecosystems.

November 2023

Concrete CMS v9.2.x continues incremental improvements with better content versioning and workflow capabilities. The platform maintains a loyal niche user base, particularly in government and education sectors, but growth is limited as the broader market shifts toward headless and composable architectures.

Platform News

  • Concrete CMS v9.2 release

    Improved content workflows, versioning enhancements, and better multilingual support.

  • Government and education case studies published

    Platform highlights adoption in public sector organizations valuing its in-context editing and accessibility features.

February 2023

Version 9.1.x releases stabilize the new architecture and restore developer confidence after the v9 migration disruption. The addon ecosystem is slowly recovering, and build simplicity improves as documentation catches up. Platform velocity remains healthy with regular point releases addressing community feedback.

Platform News

  • Concrete CMS v9.1.x point releases

    Series of stabilization releases improving performance, fixing migration edge cases, and enhancing the editing experience.

  • Updated developer documentation for v9

    Comprehensive rewrite of developer docs covering Symfony patterns, Doctrine entities, and new routing.

May 2022

Concrete CMS v9 reaches stable release, delivering the most significant architectural overhaul in the platform's history. The Symfony/Doctrine migration modernizes the technical foundation but introduces breaking changes that slow addon ecosystem recovery. Build simplicity temporarily dips as developers navigate migration from v8.

Platform News

  • Concrete CMS v9.0 stable release

    Major release featuring Symfony components, Doctrine ORM, PHP 8.0+ support, and rewritten asset pipeline.

  • v8 to v9 migration guide published

    Breaking changes in block types, packages, and routing require significant addon rewrites.

  • Marketplace addon compatibility push

    Community effort to port popular addons to v9, though many remain v8-only.

September 2021

The platform officially rebrands from concrete5 to Concrete CMS, signaling a strategic push for broader market recognition. Early previews of version 9 show significant architectural modernization with Symfony and Doctrine ORM, generating renewed community interest and a spike in contributor activity.

Platform News

  • Rebrand from concrete5 to Concrete CMS

    Major rebrand to shed the versioned name and position the platform as an enterprise-ready CMS.

  • Version 9 development preview

    Preview releases introduce Symfony HttpFoundation, Doctrine ORM, and modernized PHP 8 support.

  • New concretecms.com community hub

    Revamped website and marketplace to accompany the rebrand and attract new developers.

March 2021

concrete5 v8.5.x is a mature but aging traditional CMS with strong in-context editing but limited modern developer tooling. Community activity is steady but the platform struggles to compete with WordPress and emerging headless alternatives, and the codebase shows its age with legacy PHP patterns.

Platform News

  • concrete5 v8.5.7 maintenance release

    Bug fixes and PHP 7.4 compatibility improvements for the legacy 8.x branch.

  • PortlandLabs community roadmap discussion

    Team signals intent to modernize the platform with a major version rewrite using Symfony components.

How does Concrete CMS stack up against your shortlist?
Side-by-side scoring across all 10 categories and every criterion.
Compare Platforms →