The DXP Scorecard logo
Independent Platform Evaluation
Scored on implementation experience
Not vendor briefings
← Dashboard
Drupal CMS logo

Drupal CMS

Traditional CMSTier 4
Visit Website ↗
Overall Capability
63/ 100
#12of 41overall#1of 13Traditional CMS

Drupal CMS is the Drupal Association's packaged, marketer-focused build of Drupal 11.

Head-to-Head

Capability63 : 63
Cost Efficiency68 : 73
Build Simplicity58 : 54
Operational Ease53 : 50

Drupal CMS is Drupal with the first two weeks of site building already done: Canvas, an SEO stack, consent management, an AI assistant and 22 templates install in minutes, and the Launcher runs it with zero setup. Plain Drupal remains the better base when the project centres on Drupal Commerce, an intranet distribution or a fully bespoke content model, because Drupal CMS bundles none of those and its recipes have no update path. Operations, security and hosting are identical between the two.

Full Comparison →
Capability63 : 57
Cost Efficiency68 : 76
Build Simplicity58 : 63
Operational Ease53 : 54

Drupal CMS offers a far richer content model, granular permissions, first-party multilingual support and a more modern visual builder than WordPress with Gutenberg, and its security process is more disciplined. WordPress wins on ease of adoption: a much larger talent pool, cheaper generalist developers, shallower concepts and a broader hosting market. Choose Drupal CMS for structured, multilingual or governance-heavy sites, and WordPress for speed and staffing flexibility on simpler ones.

Full Comparison →
Capability63 : 68
Cost Efficiency68 : 42
Build Simplicity58 : 48
Operational Ease53 : 50

Acquia sells the managed hosting, FedRAMP and SOC 2 attestations, uptime SLA, support desk, personalization and DAM that Drupal CMS lacks, on top of the same Drupal core. Drupal CMS delivers the editing experience, templates and AI tooling free with no contract and total hosting freedom. Buyers who need a vendor to sign for compliance and uptime should go to Acquia; those who can own operations or use another host save the license cost.

Full Comparison →
Capability63 : 51
Cost Efficiency68 : 73
Build Simplicity58 : 70
Operational Ease53 : 50

Drupal CMS is a complete website product with a visual page builder, SEO tooling, forms, consent management and multilingual support preconfigured, while Strapi is a headless API backend that expects a separate frontend. Strapi gives JavaScript teams a familiar Node stack, a typed SDK and a much smaller dependency surface to patch. Pick Drupal CMS for a marketer-run coupled site and Strapi for an API-first build owned by frontend developers.

Full Comparison →
Compare Drupal CMS against any of 41 platforms →

Use-Case Fit

Top Fit
Marketing
56#19 of 41
Commerce
48#11 of 41
Intranet
44#10 of 41
Multi-Brand
50#18 of 41
Ideal For
  • 84Government, higher education and nonprofit organisations building public marketing and information sites
  • 82Digital agencies and in-house Drupal teams standing up many content-led marketing sites
  • 78Organisations publishing structured content in many languages
  • 72Teams that want AI assistance but must control which model sees their content
Look Elsewhere If
  • 22Regulated buyers who need vendor-issued SOC 2, ISO 27001, a DPA or a HIPAA Business Associate Agreement
  • 28Marketing teams whose roadmap depends on native personalization, A/B testing or in-CMS analytics
  • 28Companies looking for an intranet or employee portal
  • 35Small teams with no developer or operations capacity who want a turnkey hosted service

Strengths & Weaknesses

Strengths
  • +
    Canvas gives marketers a real visual page builder out of the box

    Canvas is the default editor in every new Drupal CMS install. Editors drag components onto a live page, save page variants as reusable full-page templates, apply a Brand Kit of colours and fonts, and can ask Canvas AI to draft a landing page from a prompt. Autosave, Trash for recovering deleted pages and scheduled publishing are preconfigured. A marketing team can assemble, clone and schedule campaign pages without opening a ticket with developers.

    74.5
  • +
    Unmatched extensibility and module ecosystem

    Drupal CMS can use the full drupal.org catalogue of more than 50,000 contributed modules through the in-admin Project Browser, and the installer now doubles as a marketplace of agency-built site templates, including paid ones unlocked with a license key. Recipes let teams add whole feature sets declaratively, and the plugin, event and hook systems reach every layer of the platform. Swapping the default database search for Solr, Elasticsearch, Algolia or Typesense is a backend change, not a rebuild. Very few CMS products offer this much room to grow without leaving the platform.

    85
  • +
    Structured content, SEO and permissions are enterprise grade from day one

    Every site template is built on a base recipe that installs Metatag with Open Graph and Twitter Cards, Pathauto, Redirect with 404 tracking, an XML sitemap, the SEO Checklist and Yoast SEO real-time analysis. Underneath sits Drupal's Entity and Field API with unlimited custom content types, more than 20 field types and many-to-many references, plus hundreds of granular permissions and content-level access grants. Buyers get a content model and governance layer that most competitors sell as premium add-ons.

    83.25
  • +
    No license, no metering, no exit penalty

    Drupal CMS is free under the GPL for any use, including commercial, with no seat counts, API metering or feature tiers. Only one of the 22 installer templates costs money ($899), and the bundled amazee.ai provider can be avoided by bringing your own OpenAI or Anthropic key. Content lives in standard MySQL or PostgreSQL, configuration exports as YAML, and there is no vendor contract to terminate. The free Launcher desktop app runs a complete site locally with no hosting spend.

    79.2
  • +
    One of the strongest multilingual stacks available

    The Multilingual recipe added in Drupal CMS 2.2 installs content, configuration and interface translation with a setup checklist, and the installer now translates shipped configuration into the chosen language. Canvas translates page component trees field by field, previews in any language and integrates with the Translation Management Tool (TMGMT) for connectors to Phrase, Smartling, XTM and machine translation providers. Organisations publishing in many markets get field-level translation and fallback without a paid add-on.

    73
  • +
    Bring-your-own-model AI with governance built in

    The installer asks which AI provider to use (amazee.ai, OpenAI or Anthropic) and encrypts the key at rest, and the underlying AI module supports dozens of providers including self-hosted Ollama and LM Studio with failover. Global guardrails, a moderation guardrail plugin, topic restriction, per-role agent permissions and consent gating through Klaro are included. Developers get function-call plugins, agent skills, a Tool API and an AGENTS.md in the project template for coding assistants. Buyers with data-residency or model-choice requirements are not locked to a vendor's model.

    72.67
Weaknesses
  • −
    No vendor-held certifications, DPA or BAA

    The Drupal Association issues no SOC 2 report, ISO 27001 certificate, data processing agreement, sub-processor list or Business Associate Agreement for Drupal CMS. Hosts such as Acquia, Pantheon and Platform.sh hold their own attestations, but those cover the hosting boundary, not the software product, and cannot be inherited by a self-hosted deployment. Buyers in regulated industries must source every compliance artefact from their hosting provider or their own audit programme.

    31.8
  • −
    Heavy operational load and a busy 2026 security calendar

    Drupal core issued 13 security advisories in 2026, including an actively exploited highly critical PostgreSQL SQL injection and a critical PHP object injection, and bundled modules such as Canvas, Webform, Project Browser and the AI family added their own. Automatic Updates covers only core patch releases, so operators patch the wide contrib set by hand, often inside tight exploit windows. There is no built-in monitoring, alerting or APM, and 2026 guidance still budgets 15 to 25 percent of the build cost per year for maintenance.

    50.8
  • −
    Personalization, experimentation and analytics are all absent

    No Drupal CMS recipe or template enables audience segmentation, personalized variants, A/B testing, recommendations or content performance analytics. Canvas contains a first-party personalization module, but as of Canvas 1.12 it is still hidden behind a feature flag. Marketers who need targeting or experiments must add contrib modules like Smart Content or Server-side A/B Testing, or connect an external tool such as Kameleoon or a customer data platform (CDP), and read results in GA4.

    33
  • −
    No real-time collaboration, and Canvas pages sit outside editorial workflows

    There is no co-editing, presence, or inline commenting. Canvas detects when another editor changed the same page, but the side-by-side conflict resolution UI is still behind a developer feature flag, and CKEditor 5's collaboration features are a separate paid subscription. Moderation workflows are not yet available for Canvas pages, so the main marketer surface has no draft-review-approve chain. Large editorial teams will rely on locking discipline or last-write-wins.

    47.33
  • −
    Commerce and intranet use cases are not addressed by the product

    None of the 22 site templates or curated add-ons includes Drupal Commerce, an intranet, or an employee portal. Commerce 3.x and the Open Intranet distribution exist in the wider Drupal ecosystem, but they are separate installs with no product picker, checkout content layer, people directory, learning tools or workplace integrations in Drupal CMS itself. Buyers with these needs should evaluate those products directly rather than expect Drupal CMS to cover them.

    36.4
  • −
    Custom development still demands Drupal specialists

    Canvas, recipes and the AI site-building chatbot lower the entry surface, but anything beyond template assembly means the full entity, field, hook, Views and Symfony service stack, plus Composer, settings.php and Drush in production. Guides still call this the steepest learning curve of any major CMS, with one to three months to proficiency. North American Drupal specialists bill $80 to $250 per hour, roughly a 25 to 50 percent premium over general PHP developers.

    51.25

Deep Dive

Analyst Editorial

The analyst view on Drupal CMS

DXP Scorecard Analyst Team
Drupal CMS is the Drupal Association's packaged, marketer-focused build of Drupal 11. It ships the Canvas drag-and-drop page builder, a full SEO stack, consent management, a curated AI assistant and 22 installable site templates, all free under the GPL with no licensing tiers. It inherits Drupal's deep content model, granular permissions and an ecosystem of more than 50,000 modules, but it also inherits Drupal's Composer-driven operations, a heavy 2026 security patch load and a steep learning curve for custom work. Buyers get no vendor contract, so compliance certifications, uptime guarantees and support all come from the hosting provider or agency they choose.
1Core Content Management71▼
Content Modeling
1.1.1
Content type flexibility
85H

Drupal CMS inherits Drupal 11's full Entity/Field API: 20+ core field types (text, numeric, boolean, datetime, entity_reference, file, image, link, list, email, telephone), unlimited custom content types, and schema-as-code via YAML config export and recipes. Drupal CMS 2.2 (Sep 2026) keeps Field UI and Field Group in the base template, so marketers can extend types through the UI. Polymorphic/union references still need contrib (Entity Reference Revisions), which holds it below the very top.

1.1.2
Content relationships
80H

Core Entity Reference fields give many-to-many references across content types, with Views-based reverse traversal for querying from the other end. Entity Reference Revisions adds revision-aware references, and GraphQL contrib 5.0.0 (June 2026) improves relationship querying for decoupled builds. Not graph-native: reverse lookups must be configured in Views rather than being implicit.

1.1.3
Structured content support
78H

Drupal Canvas composes pages from Single Directory Components and React code components with nesting, and it now maps entity fields (including multi-valued list fields) onto component props through content templates. Paragraphs remains available for field-level component content, and Layout Builder sits in core. Rich text from CKEditor 5 is still stored as HTML rather than a portable AST, which caps the score.

1.1.4
Content validation
76H

The Typed Data / Validation API, built on Symfony Validator, supports required, unique, length, regex, allowed-value enumeration and file type/size constraints, with custom constraint plugins for cross-field rules. Drupal CMS bundles ECA, which can add condition-based checks on save without code. Custom validators beyond that still require PHP, and there is no UI rule builder of the kind some commercial platforms offer.

1.1.5
Content versioning
75H

Per-entity revision history with revert, Scheduler with content moderation integration, Canvas auto-save drafts, and (since Sep 2026) Trash for recovering deleted Canvas pages and content all ship preconfigured. The Diff module is not bundled, so side-by-side revision comparison needs an add-on, and there is no content branching. Moderated workflows also do not yet cover Canvas pages.

Authoring Experience
1.2.1
Visual/WYSIWYG editing
76H

Drupal Canvas (1.12, Sep 2026) is the default editor: marketers drag and drop components on a live page, manage page variants, apply a Brand Kit (out of feature flag Sep 2026) and generate pages with Canvas AI. Drupal CMS 2.2 closes the earlier multilingual gap by bundling Canvas Translate in its new multilingual recipe, and Canvas can now preview through a decoupled frontend. Canvas Translate is still alpha and Canvas pages lack editorial workflows, so it stays below the best visual editors.

1.2.2
Rich text capabilities
73H

CKEditor 5 is well integrated, with per-format toolbars, media embedding, Linkit link autocomplete (bundled in Drupal CMS), code blocks and solid paste handling. Its plugin architecture is extensible. Output is an HTML blob rather than a portable AST, and custom marks or annotations need CKEditor plugin development.

1.2.3
Media management
73H

Drupal CMS preconfigures the core Media Library with Focal Point, around 60 focal-point WebP image styles across nine aspect ratios wired to responsive image styles, bulk upload, SVG media, safe file deletion and AI-generated alt text. That is well beyond basic upload-and-serve. Transforms are predefined server-side derivatives rather than URL-based on-the-fly, AVIF is not configured, and there is no rights management.

1.2.4
Real-time collaboration
42M

There is no real-time co-editing or presence in Drupal CMS. Canvas auto-save does detect when an entity was changed elsewhere and reports a conflict instead of silently overwriting, and form auto-save protects drafts. The resolution flow itself is still behind a dev module, and CKEditor 5 real-time collaboration is a separate paid subscription that is not bundled.

1.2.5
Content workflows
68H

Drupal CMS ships a basic editorial workflow (Draft, Published, Unpublished) auto-applied to content types, with scheduled publishing and ECA plus the Modeler UI for automated actions. Core Workflows allows extra stages and per-transition role permissions, but no review stage is preconfigured beyond what a site template adds. Workflows are not available for Canvas pages, the main marketer surface, which keeps this below the 75+ band.

Content Delivery
1.3.1
API delivery model
78H

Core JSON:API is spec-compliant with filtering, sorting, pagination, sparse fieldsets and includes, and GraphQL 5.0.0 went stable in June 2026. Canvas adds its own routed headless content API with structured language alternates (Sep 2026). Neither JSON:API nor GraphQL is enabled by the Drupal CMS installer, and there is no separate delivery versus management API tier.

1.3.2
CDN and edge delivery
46M

Drupal CMS has no built-in CDN; delivery depends on the chosen host. Core cache tags enable granular purging through Varnish, Fastly or Cloudflare via the Purge ecosystem, and Canvas now attaches cache tags for Brand Kit and global CSS. There is no edge compute or guaranteed sub-second purge without hosting add-ons.

1.3.3
Webhooks and event system
54M

Internally, Symfony Event Dispatcher and the bundled ECA module can react to entity events without code. Outbound webhooks still come from contrib (Webhooks, Entity Webhook) and are not installed by Drupal CMS. There is no built-in retry, HMAC signing or delivery log.

1.3.4
Multi-channel output
71M

Beyond core JSON:API, Canvas now has an experimental Headless module with an official SDK and adapters for Next.js, Astro, Nuxt, TanStack Start and Angular on npm, so editors can build and preview pages rendered by a decoupled app. That narrows the old gap where visual editing only worked on coupled sites. The module is experimental, the SDK is pre-1.0, it is not in the default install, rich text is HTML, and there are no mobile SDKs.

2Platform Capabilities57▼
Personalization & Experimentation
2.1.1
Audience segmentation
38M

Drupal CMS 2.2.0 still ships no audience segmentation engine in any recipe or site template. Canvas 1.12 does include a first-party canvas_personalization submodule with Segment config entities and a UTM-parameter condition, but it is marked hidden (a feature flag) and Drupal CMS does not enable it. Real segmentation still runs through contrib (Smart IP/Context, External Personalization) or an external CDP, so the score stays in the external-tool band.

2.1.2
Content personalization
38M

No personalized variant rendering is available in a default Drupal CMS 2.2 install. Canvas's hidden canvas_personalization module defines p13n switch/case components for segment-based variants, which is a promising first-party path, but it remains an unexposed feature flag with no editor preview per audience. Production personalization still needs contrib (Personalize, External Personalization) or an external decision engine.

2.1.3
A/B and multivariate testing
35M

No native A/B testing ships with Drupal CMS 2.2. Contrib options include Server-side A/B Testing, Personalize A/B and A/B Paragraphs, and hosted testing tools (VWO, Kameleoon) integrate via tag management. None are part of Drupal CMS recipes, and statistical reporting depends on external analytics.

2.1.4
Recommendation engine
20H

No algorithmic recommendation engine exists in Drupal CMS. Editorial curation through entity reference fields and Views (such as the Recent Content blocks the base recipe ships) is the default path. ML-based recommendations require external services or custom builds.

Search & Discovery
2.2.1
Built-in search
50H

The Drupal CMS Search recipe installs Search API with the database backend, auto-indexes all content types and Canvas pages on cron, and adds per-item exclusion; Canvas 1.12 added language-aware indexing for translated pages. That beats core's legacy Search module but remains database full-text: no typo tolerance, no relevance tuning UI, and facets or autocomplete need extra modules.

2.2.2
Search extensibility
82H

Because Drupal CMS search is built on Search API, swapping the DB backend for Solr, Elasticsearch/OpenSearch, Algolia, Typesense or Meilisearch is a backend change, not a rebuild. All of these backends have maintained modules with Drupal 11 support, and faceting and autocomplete are well documented. Few CMS ecosystems offer this much backend choice.

Commerce Integration
2.3.1
Native commerce
72H

Drupal Commerce 3.x provides product catalog, cart, checkout, pricing, promotions and order management natively in the Drupal ecosystem, and recipe-based installs are available. It is not bundled in any Drupal CMS 2.2 site template or curated add-on, so it is an install-on-top capability rather than out-of-the-box.

2.3.2
Commerce platform integration
58M

The Shopify eCommerce module syncs products into fieldable Drupal entities with webhook/cron updates while Shopify handles checkout. BigCommerce and commercetools integrations exist in contrib but are less mature. There is no product picker at the level of dedicated composable commerce connectors.

2.3.3
Product content management
67M

Drupal Commerce product entities support variations, attribute-driven product types, media fields and rich text, all fieldable and revisionable. Canvas content-entity-reference props (released 1.11) let page components pull product entity data directly. It is not a PIM, but it handles editorial product content well.

Analytics & Intelligence
2.4.1
Built-in analytics
32H

Drupal CMS 2.2 has no content performance analytics. Its dashboard shows recent pages, recent content and events, plus SEO and accessibility checklists, but no page views or engagement. Contrib options such as Content Reporting and Page Performance Insight exist but are not bundled.

2.4.2
Analytics integration
67H

The curated Google Analytics add-on prompts for a Google Tag ID (GA4, GTM, Ads or Floodlight) and wires it into the Klaro consent manager so tags only fire after consent. Matomo and Segment are available as maintained contrib modules. Integration is solid for the major platforms, but event streaming from content operations still needs ECA or custom work.

Multi-Site & Localization
2.5.1
Multi-site management
63H

Drupal supports codebase-shared multisite natively, and Domain Access lets domains share content from one database. Drupal CMS adds nothing on top: there is no multi-site console or cross-site governance, although site templates and drush site:export make spinning up consistent new sites easier.

2.5.2
Localization framework
87H

Drupal CMS 2.2 adds a curated Multilingual recipe (content, config and interface translation, plus a setup checklist), and the installer now translates shipped configuration and pulls full interface translations. Canvas added symmetric field-level translation of page component trees, language-aware preview and a language switcher in the editor. On top of core's field-level translation and fallback, this makes it one of the strongest multilingual stacks available.

2.5.3
Translation integration
70M

TMGMT provides TMS and MT connectors (Phrase, Smartling and XTM via provider modules, plus DeepL, Google and Microsoft), with bulk job export and import. Canvas now integrates with TMGMT, so visual page content and content templates can go through translation jobs, which closes a real gap in Canvas-built sites. TMGMT itself is not bundled in the Multilingual recipe.

2.5.4
Multi-brand governance
52M

Canvas 1.12 moved Brand Kit (managed colors and fonts with usage tracking) out from behind its feature flag, and page variants give theme-independent full-page templates. Both work per site, though. Cross-brand policy enforcement and shared approval workflows across brands still need Domain Access plus custom development.

Digital Asset Management
2.6.1
Native DAM capabilities
54H

The Drupal CMS base recipe preconfigures document, image, local video, remote video and SVG media types with focal point cropping, bulk media upload, file cleanup on media delete, and Trash for recovery. That is a well-organized asset library, but there is still no asset versioning UI, rights or expiry management, or metadata schemas beyond fields.

2.6.2
Asset delivery & CDN optimization
45H

Drupal CMS ships responsive images with a broad set of preconfigured aspect-ratio image styles (1:1, 3:2, 4:3, 16:9, 9:16, hero) and focal-point cropping, and core converts styles to AVIF with a WebP fallback. Transforms are still predefined server-side styles, not URL-based on-the-fly transformations, and CDN delivery requires an external service or host.

2.6.3
Video & rich media management
32H

Drupal CMS includes local video upload and oEmbed remote video media types, and remote video playback is gated by Klaro consent. There is no transcoding, adaptive streaming or caption management, so real video hosting needs Mux, Vimeo or similar.

Authoring & Editorial Experience
2.7.1
Visual page builder & layout editing
74H

Canvas is the default editor in Drupal CMS 2.2, and releases 1.4 to 1.12 added editable patterns, page variants (theme-independent full-page templates), Brand Kit, multi-value props and entity-data props, on top of drag-and-drop assembly with live preview and undo. The installer now offers about 20 Canvas site templates. Visual editing of decoupled frontends exists through the Canvas Headless module but is still experimental, which keeps the score below the top enterprise editors.

2.7.2
Editorial workflow & approvals
68H

Drupal CMS installs Workflows and Content Moderation and uses ECA to enable moderation automatically on every new content type. Custom states, role-based transitions and revision-based audit trails come from core. There are no SLA timers, task assignment or parallel approval paths without contrib.

2.7.3
Publishing calendar & scheduling
63H

Scheduler handles publish and unpublish dates, integrated with moderation states, and Drupal CMS configures it automatically for new content types. There is still no calendar view or atomic release bundles in the product.

2.7.4
Real-time collaboration
32H

Canvas added an Activity Center with toast notifications, and Drupal CMS enables autosave on all content types. Canvas conflict detection with a side-by-side review UI has been built but still sits behind the canvas_dev_cd feature flag. There is no simultaneous editing, presence or inline commenting, so editors still rely on locking or last-write-wins.

Marketing & Engagement
2.8.1
Forms & data capture
77H

The curated Forms recipe installs Webform with its UI, a ready contact form, and spam protection through ALTCHA (proof-of-work, replacing Friendly Captcha), CAPTCHA and Honeypot. Webform provides conditional logic, multi-step forms, submission storage with export, and handlers for CRMs and webhooks. Native form analytics are thin.

2.8.2
Email marketing & ESP integration
58M

Drupal CMS ships Easy Email for templated transactional mail, but its curated add-on list contains no ESP recipe. Mailchimp, HubSpot and Marketo connectors are separate contrib modules installed through Project Browser. List sync and form-driven subscriptions work well once added, but there is no email composer or triggered campaign send built in.

2.8.3
Marketing automation
42M

Drupal CMS includes ECA (now 3.1 with a new modeler), which handles site-side event-condition-action automation, but not drip campaigns, lead scoring or nurture flows. Those come from Mautic or HubSpot integrations, which are well supported in contrib. This counts as tight integration with an external automation tool, not native automation.

2.8.4
CDP & customer data integration
35M

No CDP is part of Drupal CMS. Segment event streaming and the External Personalization pattern for consuming CDP decisions are contrib, and Canvas's hidden personalization module only evaluates UTM-style conditions. Unified profiles and identity resolution require external tooling.

Integration & Extensibility
2.9.1
App marketplace & ecosystem
86H

Project Browser gives in-admin access to more than 50,000 contributed modules plus a curated add-on list. The 2.2 installer offers about 21 site templates from the Drupal Association and partner agencies, including premium templates with license-key validation and a Nuxt decoupled starter. Very few CMS ecosystems are this broad.

2.9.2
Webhooks & event streaming
62M

Drupal CMS ships ECA, so content create, update, delete and state-change events can trigger HTTP calls without code, and the Webhooks contrib module adds outbound webhook configuration. There is no dedicated webhook management UI with delivery logs, signing and retry in the product; those depend on contrib configuration.

2.9.3
Headless preview & staging environments
61M

Canvas now has an experimental Headless module with a signed draft-preview model, an SDK for Next.js, Astro, Nuxt, TanStack Start and Angular, in-editor rendering of the decoupled app, multilingual preview and an OpenAPI spec. The Drupal CMS installer also offers a Nuxt decoupled starter template, and next-drupal remains mature. Branch environments and promotion still depend on the host, and Canvas Headless is not yet stable.

2.9.4
Role-based permissions & governance
78H

Drupal CMS applies core's administrator and content editor role recipes on top of one of the most granular permission systems among CMSs (per-bundle, per-operation and per-translation permissions). Field-level access, SSO (SAML, OpenID Connect, LDAP) and SCIM are available through contrib but not preconfigured. The permissions UI is complex.

3Technical Architecture70▼
API & Integration
3.1.1
API design quality
78H

Drupal CMS 2.2 (on Drupal 11.4) inherits the spec-compliant core JSON:API v1.1 module with consistent resource naming, relationships, sparse fieldsets, filtering and sorting; the contrib GraphQL module remains maintained. Canvas 1.12 adds a Canvas-owned routed content endpoint for headless apps with its own OpenAPI spec, but it sits in the experimental canvas_headless module. Core JSON:API still has no OpenAPI or interactive playground without contrib, which keeps this below purpose-built API platforms.

3.1.2
API performance
60M

No vendor SLA or documented rate limits since Drupal CMS is self-hosted by default. The core engine keeps improving: Drupal 11.4 (July 1, 2026) roughly halves database queries versus 11.3 and adds Brotli compression for aggregated CSS/JS, and Drupal CMS 2.0 sites can adopt the 11.4 core line. Dynamic Page Cache and Internal Page Cache provide layered caching and JSON:API responses can sit behind Varnish/CDN, but there is still no CDN-backed delivery or built-in rate limiting out of the box — which is why this stays below CDN-delivered API platforms.

3.1.3
SDK ecosystem
46M

The Canvas project now publishes an official JavaScript Headless SDK on npm: @drupal-canvas/headless 0.11 (first release 2026-07-22), with adapters for Next.js, Nuxt, Astro, React, Angular and TanStack Start, alongside the official Canvas CLI and Workbench packages. The SDK is pre-1.0, backs an experimental module that Drupal CMS does not enable by default, and gets about 2K monthly downloads against 88K for the community next-drupal client. There are still no official Python, Java, .NET or Go SDKs, so this stays in the community-SDK band.

3.1.4
Integration marketplace
82H

Drupal CMS can use the full Drupal.org ecosystem of 50,000+ contributed modules across payment, DAM, CRM, search, AI, email and analytics, plus a curated module set vetted for Drupal CMS. Drupal CMS 2.2.0 (2026-09-25) builds out the site template marketplace: partner templates, premium templates unlocked with license keys from third-party Composer repositories, and new bundled templates (Everbright, Mercury Demo, Forma, Lupus Decoupled Starter). Module quality varies and the maintained Drupal 11 subset is smaller, which keeps this below pure-marketplace leaders.

3.1.5
Extensibility model
90H

Extensibility is still the platform's strongest dimension. Recipes provide declarative building blocks, OOP hooks via PHP attributes modernize the hook system, and the Plugin API, Symfony DI and event subscribers extend every layer. Drupal Canvas, the default page builder in Drupal CMS, adds code components with npm imports, content entity reference props, editable page variants, external components from decoupled apps, and pluggable Canvas AI agents and tools.

Security & Compliance
3.2.1
Authentication
75H

SAML 2.0 (samlauth), OIDC (OpenID Connect), and OAuth2 (Simple OAuth) contrib modules are mature and available to any Drupal CMS install with no plan gating — an advantage over tier-gated SaaS competitors. MFA via the TFA module; API auth via OAuth2 bearer tokens. SSO requires contrib setup rather than turnkey configuration, which keeps this below platforms with built-in enterprise SSO.

3.2.2
Authorization model
85H

Inherited from Drupal 11 core: hundreds of granular permissions, fully custom roles, and the node access grants system for content-instance-level access control. Field-level permissions via the Field Permissions contrib module; Content Moderation gates access by workflow state; the Group module enables audience-based access. Meets the field-level plus instance-level bar for a top-tier score; only the reliance on contrib for field-level control keeps it from higher.

3.2.3
Compliance certifications
55M

Drupal CMS is open-source; certifications are hosting-provider dependent rather than inherent. Acquia holds FedRAMP + SOC 2 Type 2 + ISO 27001; Pantheon and Platform.sh hold SOC 2; Amazee.io offers ISO 27001-certified Drupal hosting. The GDPR contrib module provides consent management and DSAR tooling. HIPAA eligibility requires appropriate hosting configuration — the platform itself carries no certifications, capping this score.

3.2.4
Security track record
64H

Drupal core has issued 13 advisories in 2026 so far. They include the exploited highly critical PostgreSQL SQL injection (SA-CORE-2026-004), a Critical PHP object injection (SA-CORE-2026-005, June 17), and eight more moderately or less critical issues from June to September. Components that Drupal CMS bundles added their own: two Canvas improper-validation advisories (July 1) and about seven for the AI, AI Agents and AI translate modules between June and September. Coordinated disclosure, patches across all branches, the HackerOne program and Drupal CMS 2.2 encrypting AI provider keys at rest are genuine strengths, but this volume and severity push the score below the 70+ clean-history band.

Infrastructure & Reliability
3.3.1
Hosting model
80H

Drupal CMS supports self-hosted (any PHP/MySQL environment), managed platforms (Acquia, Pantheon, Platform.sh), Docker via DDEV, and private cloud. Composer-based deployment is portable across environments with no SaaS lock-in — ideal for regulated industries. Maximum flexibility at the cost of operational complexity, which is scored in other items.

3.3.2
SLA and uptime
50M

No inherent SLA — Drupal CMS is self-hosted by default and the customer owns uptime. Hosting-provider SLAs apply where used: Acquia Cloud Enterprise 99.95%, Pantheon 99.9%. No central status page because there is no central SaaS service. Scores appropriately lower than SaaS platforms per the self-hosted anti-pattern guidance.

3.3.3
Scalability architecture
80H

Drupal is proven at massive scale (government portals, global media), and the core engine keeps getting leaner — Drupal 11.4 roughly halves database queries versus 11.3, with cold-cache lookups down to about a third of 11.0/10.6. Cache tag-based invalidation enables granular CDN/reverse-proxy management, and horizontal scaling patterns (load balancers, read replicas, Redis/Memcached, Varnish, CDN) are well documented. The ceiling is high but reaching it requires operational expertise rather than vendor-managed auto-scaling.

3.3.4
Disaster recovery
72M

Configuration Management exports full site configuration as version-controlled YAML, and Drupal CMS 2.2 now keeps config outside the web root by default. Database and file backups use standard MySQL/PostgreSQL tooling or Backup and Migrate, and the Migrate API gives open-format portability without lock-in. The new drush site:export captures a site as a reusable template, not as a backup. RTO/RPO depend on the hosting environment and there is no built-in multi-region failover, so recovery targets are left to operators.

Developer Experience
3.4.1
Local development
80H

DDEV is still the officially recommended local environment: one command gives a Docker setup close to production, and new.drupal.org has dedicated Drupal CMS install docs. Drush covers config, database and cache work. Drupal CMS 2.2 ships a generic AGENTS.md in the project template for AI coding assistants. The Canvas CLI and @drupal-canvas/workbench give a local, Storybook-style component workflow, now including code components from headless codebases.

3.4.2
CI/CD integration
78H

Configuration Management is built for CI/CD: all configuration moves through version control as YAML via drush config:export/import, and Drupal 11.4 roughly doubles the speed of recipe-based installs. Drupal CMS 2.2 adds drush recipe:compare, pm:clean, canary tests for recipe config consistency and PHPStan level 7 on its own CI, and Canvas adds a canvas:doctor health check and CLI push/pull for code components. Branch-based environments come from hosts such as Pantheon Multidev and Platform.sh, not from the platform itself.

3.4.3
Documentation quality
69M

Drupal CMS documentation at new.drupal.org covers getting started, DDEV installs, recipes and site building, and Drupal Canvas has its own docs site for code components, now extended with Canvas Headless guides such as multilingual sites. The api.drupal.org reference is thorough but auto-generated and not beginner-friendly. There is no interactive API playground and contrib module docs are uneven.

3.4.4
TypeScript support
44M

The official Canvas Headless SDK ships TypeScript declarations with framework adapters for Next.js, Nuxt, Astro, React, Angular and TanStack Start, and the Canvas compiler and CLI handle TSX code components. The SDK is pre-1.0 and experimental, and it does not generate types from the Drupal content model. Content-model types still depend on community tools such as the TypeScript Definition Generator and next-drupal, so this stays below the typed-SDK band.

4Platform Velocity & Health74▼
Release Cadence
4.1.1
Release frequency
78H

Drupal CMS shipped 2.1.4 (Sept 1), 2.1.6 (Sept 23) and the 2.2.0 minor (Sept 25, 2026) with premium site templates, AI key encryption and a project-level AGENTS.md, while bundled Canvas released 1.8 through 1.12 between July and September and core shipped 11.4.0 through 11.4.8 since July 1. Held at 78 rather than 80 because the distribution itself went three months between 2.1.3 (June 2) and 2.1.4, and Drupal 12 has only reached alpha1 (Sept 2) with beta1 still untagged past its mid-September target.

4.1.2
Changelog quality
76H

drupal.org/project/cms/releases provides per-release notes, and the underlying history uses conventional-commit prefixes (feat/fix/chore/task) scoped to each sub-project with linked issue numbers, so 2.2.0 changes such as premium template licensing, config outside the web root and SA-2026-004 dependency floors are traceable. Core change records flag API changes with migration steps. Not 80+ because the distribution's published notes remain lighter than core's and do not consistently call out breaking changes separately.

4.1.3
Roadmap transparency
80H

The Drupal 12 plan is tracked in a public meta-issue that now states an early-December 2026 release, with public sub-issues for alpha1 (done), beta1 requirements, 12.0/11.5 beta targets and 12.0.0 release notes. The AI Initiative publishes a 2026 roadmap with named workstream leads, and all Drupal CMS work happens in public issue queues. Not higher because there is no community voting portal comparable to Canny.

4.1.4
Breaking change handling
77H

Core deprecates APIs for at least a minor cycle with change records, has adopted a policy deferring disruptive 11.3 deprecations until Drupal 13, and ships 11.5 as an LTS alongside 12.0 so sites are not forced onto the new major. Drupal CMS manages transitions itself: 2.x shipped a Content-create menu shim and converted the Starter template to a monolith ahead of 11.4, and added canary tests for recipe config consistency. Not higher because Drupal 12 drops update paths below 11.3 and removes six core modules, so cross-major upgrades still need manual work.

Ecosystem & Community
4.2.1
Community size
82H

Drupal remains one of the largest open-source CMS communities: 800+ Slack channels, tens of thousands of registered contributors on drupal.org, roughly 1% of all tracked websites and a strong position among top-traffic sites. Two annual DrupalCons (Chicago March 2026, Rotterdam September 2026) draw global participation. Not 90 because GitHub-star and npm-style signals are less prominent for a PHP platform than for JS ecosystems.

4.2.2
Community engagement
78H

The AI Initiative drew 31 contributing agencies by DrupalCon Chicago 2026, with 28+ organizations pledging 23+ FTE contributors, and Drupal CMS 2.2.0 incorporated templates and fixes from many outside maintainers. DrupalCon Rotterdam 2026 ran a full program including specialized summits. Not higher because commentators have questioned DrupalCon attendance counting, and developer surveys show almost no participants under 21.

4.2.3
Partner ecosystem
79H

Drupal CMS 2.2.0 turned the installer into a template marketplace: about two dozen agency-built site templates are listed with 'Created by' attribution, and premium templates can be sold with license-key validation (Dripyard's Meridian Charter School lists at $899), alongside Varbase, Convivial Gov and Provus EDU starters. This sits on the tiered Drupal Certified Partner program and the AI Initiative workstreams led by QED42 and 1xINTERNET. Not 85+ because major global SIs such as Accenture and Deloitte are not Drupal Certified Partners.

4.2.4
Third-party content
83H

Decades of tutorial content: thousands of YouTube videos, Udemy and LinkedIn Learning courses, DrupalCon session archives and extensive drupal.org documentation. Agencies (Droptica, Annertech, Stone Circle, 1xINTERNET, PreviousNext) publish steady 2026 coverage of Drupal 11.4, Drupal 12 and Drupal CMS 2.x, and trade press (TheDropTimes, CMSWire, CMSCritic) covers each release. Near the top of this metric among open-source CMSs; Drupal CMS-specific material on Canvas is still thinner than core coverage.

Market Signals
4.3.1
Talent availability
70M

Drupal Jobs remains active and Drupal developers are available in volume across North America, Europe and South Asia, backed by Acquia certification and a deep agency bench. The generational pipeline is narrowing, with developer surveys showing no respondents under 21 and few with under a year of experience. Near-term availability is strong, so not lower.

4.3.2
Customer momentum
62M

Momentum is bifurcated. Drupal CMS keeps shipping and 2.2.0 widened vertical coverage (charter schools, healthcare, government, insurance, nonprofits) through partner templates, but aggregate Drupal share has declined from about 7% of CMS sites in 2013 to roughly 1.1 to 1.2% in 2026 and Shopify has passed it overall. Enterprise position holds at 6 to 7% of the top 10,000 sites. Not higher while aggregate share erodes and there are no published Drupal CMS install-growth figures.

4.3.3
Funding and stability
80H

The AI Initiative met its $1M goal in five months and grew to $1.5M with 31 contributing agencies by DrupalCon Chicago 2026, backed by the Drupal Association's Vision Fund. Non-profit governance plus Acquia as commercial anchor insulates the project from VC pressure, and the paid template channel in 2.2.0 opens a new revenue path for contributors. Not higher because the Association has itself flagged financial sustainability challenges.

4.3.4
Competitive positioning
64M

Drupal CMS positions as the accessible, AI-ready open-source alternative to proprietary DXPs and site builders, with Canvas, bring-your-own-model AI and a growing site template catalogue giving it a clear story against WordPress and commercial DXPs. No current Gartner MQ names Drupal CMS, and aggregate market share keeps eroding. Clear differentiation keeps it above 60; lack of analyst recognition keeps it below 70.

4.3.5
Customer sentiment
54M

G2 last showed 3.9/5 from roughly 445 to 470 reviews in mid-2026; it could not be re-verified this pass, so confidence drops to MEDIUM. Under the formula, sub-4.0 with fewer than 500 reviews lands in the 45 to 60 band. Reviews praise flexibility and customization and criticize the learning curve, coding requirements and hosting cost, which Drupal CMS 2.x targets but has not yet moved in aggregate.

5Total Cost of Ownership68▼
Licensing
5.1.1
Pricing transparency
78H

Drupal CMS is free, open-source software, so there is no license cost to find out. Drupal CMS 2.2.0 added premium site templates, and their USD price is shown right in the installer's template picker ($899 for the one paid template listed), so the new paid option is transparent too. It stops short of the ceiling because total cost still means researching hosting and implementation separately, and both have wide price ranges.

5.1.2
Pricing model fit
73H

With no license there is no API metering, no seat count and no vendor bandwidth overage, and hosting is priced on its own. The optional bundled amazee.ai provider moves to flat monthly plans after its trial, and bring-your-own-key AI means model spend goes through the buyer's own provider account. The main unpredictability is implementation: 3-year TCO commonly runs 1.7 to 2.6 times the initial build.

5.1.3
Feature gating
76H

Every Drupal CMS feature, including Canvas, recipes, the AI tooling and 21 of the 22 site templates in the installer, is free with no tiers. Two paid add-ons now appear in the default path, though both are optional: the bundled amazee.ai AI provider is a 30-day trial that becomes a paid plan (bring-your-own-key avoids it), and 2.2.0 added license-key-gated premium partner templates. Neither locks a core production capability.

5.1.4
Contract flexibility
82H

There is no software contract, so a team can stop using Drupal CMS at any time without penalty. Hosting contracts are with third parties and many bill monthly (Pantheon from ~$50/mo per site). Only enterprise managed hosts such as Acquia impose annual negotiated terms, and that is a hosting choice, not a platform requirement.

5.1.5
Free / Hobby Tier
85H

Drupal CMS is free forever for any use, including commercial, with no capability limits or time limits. The free Drupal CMS Launcher desktop app runs the full platform locally with no hosting spend and no command-line setup, and budget hosting starts around $5/month.

Implementation Cost Signals
5.2.1
Time-to-first-value
66H

The free Launcher gets a working local site running in minutes, and the installer now offers 22 site templates across SaaS, nonprofit, education, government, healthcare, events, insurance and news, plus a Nuxt decoupled starter. Drupal CMS 2.2.0 added a command to export a Launcher-built site, which shortens the step from local prototype to hosted site. Production still needs hosting to be provisioned, which keeps it short of the sub-hour SaaS ceiling.

5.2.2
Typical implementation timeline
57M

Site templates and the Canvas visual builder bring simple marketing sites down to days rather than weeks, and the template library now covers most common verticals from agencies such as Kanopi, Vardot, Annertech, Promet and Zoocha. Real custom projects still run long, though: small sites 4 to 8 weeks, content-led marketing sites 6 to 14 weeks, mid-size builds 3 to 6 months and enterprise builds 5 to 9 months.

5.2.3
Specialist cost premium
52H

Drupal expertise still costs noticeably more than general web development. 2026 North American rates run $80 to $250/hour, and top-tier partners bill $150 to $250/hour against $80 to $120 for general PHP developers, roughly a 25 to 50% premium. The talent pool is smaller than WordPress's, though offshore and hybrid teams ($35 to $85/hour) bring blended costs down.

Operational Cost Signals
5.3.1
Hosting costs
56M

Hosting is never included, so every deployment adds infrastructure spend. Small sites run on budget shared hosting ($5 to $50/mo), and Drupal CMS ships a cPanel project template aimed at that market, but most production sites use managed Drupal hosting ($50 to $500/mo) or self-managed cloud servers with a CDN. Large enterprise portals can pass $50,000/year.

5.3.2
Ops team requirements
47H

Running Drupal CMS still takes steady maintenance: core and module security updates, PHP version changes and database upkeep. September 2026 alone brought three Drupal CMS patch releases and a raised core minimum for a security advisory. Automatic updates help smaller sites, but 2026 guidance still budgets 15 to 25% of build cost per year, and self-hosted sites need at least a part-time ops person.

5.3.3
Vendor lock-in and exit cost
75H

Drupal CMS is open source and stores data in standard MySQL or PostgreSQL databases, so there is little platform lock-in. Content leaves via Views Data Export, JSON:API/REST or a database dump, and configuration exports as YAML. Moving to another platform still takes ETL work, and Canvas page layouts are stored in a Drupal-specific component structure that other systems cannot read directly.

6Build Simplicity58▼
Learning Curve
6.1.1
Concept complexity
50H

Drupal CMS 2.0 (2026-01-28) makes Canvas the default no-code page builder in a new user's first five minutes, and an AI admin chatbot can now create content types, taxonomy terms, and fields conversationally — both lowering the entry surface. However, custom development still requires the full entity/field/hook/Views/services stack (nodes, blocks, Views, entities), keeping concept density well above the <5-concept ideal; 2026 guides still call Drupal's the steepest learning curve of any major CMS. Held at 50 because the underlying concept model is unchanged for developers doing real work.

6.1.2
Onboarding resources
67H

Drupal CMS has a dedicated getting-started hub (new.drupal.org/docs/drupal-cms) with a pre-configured DDEV path, plus the official Drupal CMS Launcher, a standalone Windows/macOS/Linux desktop app that installs and opens a working Drupal CMS site with no Docker, Composer or external dependencies (v1.0.9, Mar 2026). Drupal CMS 2.2 adds a generic AGENTS.md to the project template for AI-assisted development. Not higher because there is still no in-app guided tour or structured first-party learning path; docs remain spread across new.drupal.org, project.pages.drupalcode.org and Drupalize.me, and the Launcher is positioned for evaluation and site building rather than production.

6.1.3
Framework familiarity
52H

Canvas is built on Single Directory Components (Twig/JS/CSS packaged per component) and now has a first-party Canvas Headless SDK with framework adapters for Next.js, Astro, Nuxt, TanStack Start and Angular (@drupal-canvas/headless-next 0.8.0, Sept 2026), alongside JSON:API in core and next-drupal. Custom backend work still requires Drupal's Symfony/PHP entity, service and hook model, which takes a PHP developer months to reach proficiency. Up +2 for the headless adapters; capped because they are 0.x and the canvas_headless module is still flagged experimental.

Implementation Complexity
6.2.1
Boilerplate and starter quality
64H

The Drupal CMS 2.2 installer now offers 22 site templates from a canonical list, 21 of them free: Starter, Byte, the new Everbright and Mercury Demo templates, and partner templates from Kanopi, Vardot, OpenSense Labs, Annertech, Promet, QED42 and others, including decoupled options (Lupus Decoupled Starter, drunomics Nuxt Starter). A site template starter kit and `drush site:export` let teams package their own. Not higher because there is no vendor-maintained Next.js starter with CI/deployment config, and quality across partner templates is uneven.

6.2.2
Configuration complexity
51H

Drupal CMS ships pre-configured for DDEV (.ddev/config.yaml bundled), so local setup is effectively configure drupal11 project type, `ddev start`, and `composer create-project drupal/cms`. Production still requires Composer dependency management, database config, settings.php/settings.local.php environment handling, and Drush for many admin operations — a config surface far heavier than SaaS platforms — and non-DDEV setup remains poorly documented per community reports.

6.2.3
Data modeling constraints
60H

Drupal's entity/field system has no field count limits, and Configuration Management (config export/import) provides version-controlled schema deployment. Field type changes on populated content still require migration scripts via the migrate API, but tooling support makes schema evolution lower-risk than platforms without migration paths. No material changes in Drupal CMS 2.0 to this layer.

6.2.4
Preview and editing integration
65H

Canvas is the default editing experience in new Drupal CMS installs, with drag-and-drop, live preview and responsive previews and no setup for traditional deployments. For decoupled builds, the new Canvas Headless SDK lets Canvas embed the frontend app with draft-aware preview sessions and drag-and-drop on the app's own registered components, configured largely through env vars (CANVAS_SITE_URL, CANVAS_EDITOR_ORIGINS); next-drupal 2.1.0 remains the other route. Up +2; not higher because headless visual editing is 0.x/experimental and still requires frontend code changes.

Team & Talent
6.3.1
Required specialization
52H

Canvas, Site Templates, and Single Directory Components mean site builders and frontend implementers need less bespoke Drupal theming knowledge — SDC's Twig/JS/CSS packaging is familiar to frontend devs. Custom module development still demands Drupal-specific PHP (entity API, services, OO hooks — still proprietary patterns) requiring 1–3 months of ramp-up, so generalist React/TypeScript developers cannot be productive on backend work without significant investment. No certification is required.

6.3.2
Team size requirements
54M

Drupal CMS 2.0's launch messaging claims marketing teams can 'launch fully branded, professional websites in days instead of weeks' using templates and Canvas, and Byte proves a solo builder can ship a production template-based site in minutes. Production implementations with custom functionality still typically need 2–3 roles (Drupal backend, frontend, DevOps/hosting), and enterprise builds more. The floor has dropped meaningfully; the ceiling for custom work has not.

6.3.3
Cross-functional complexity
68H

Canvas gives marketers drag-and-drop page building with live preview and the Mercury component library, and the Drupal CMS 2.0 AI admin chatbot now handles structural site-building tasks — creating content types, defining taxonomy terms, adding fields, plus AI-assisted alt text — reducing developer dependency beyond just page assembly. Recipes and Site Templates further let admins add features without code. Bumped +1 as the chatbot moves structural changes (not only content) into non-developer reach; capped because custom components and third-party integrations still route through developers.

7Operational Ease53▼
Upgrade & Patching
7.1.1
Upgrade difficulty
58H

Once installed, Drupal CMS is a standard Drupal site updated the usual way, and the 2.x line has shipped as small point releases (2.1.1 through 2.1.6, then 2.2.0 on 2026-09-25) with no required migration steps. Automatic Updates handles core patch releases, and Canvas's Automatic Component Instance Updates keep prop and slot changes from breaking content. Not higher because recipes still have no update path, and the Drupal 12 upgrade (stable planned for the week of 2026-12-07, only 12.0.0-alpha1 tagged so far) is Composer-driven and drops update paths below 11.3.

7.1.2
Security patching
68H

The process is still exemplary: PSAs pre-announce critical release windows (PSA-2026-09-21 before the 2026-09-23 contrib batch), and Drupal CMS 2.1.6 shipped the same day to raise minimum Webform and Project Browser versions after critical RCE and CSRF advisories. The volume is the issue: 13 core advisories in 2026 (SA-CORE-2026-005 Critical, 2026-06-17) plus a steady stream against bundled modules, including Canvas (two in July), the AI module family, AI CKEditor, Editoria11y, Webform and Project Browser. Lowered because Automatic Updates only covers core patch releases, so operators still have to patch the wide contrib set Drupal CMS bundles by hand, often within tight exploit windows.

7.1.3
Vendor-forced migrations
52M

Drupal 11.5.0 ships alongside 12.0.0 as a long-term support release supported into mid to late 2028, so Drupal CMS operators can skip the next major rather than being forced onto it. Drupal 12 pushes disruptive API deprecations to Drupal 13, Drupal CMS 2.x already runs on 11.3+ so the Drupal 10 EOL (2026-12-09) does not touch it, and the 1.x to 2.0 move needed no action. Not higher because Drupal 12 still removes six core modules and update paths below 11.3, and recipes offer no upgrade path at each major step.

7.1.4
Dependency management
33H

Drupal CMS runs the full Composer-managed PHP/Symfony stack (PHP 8.3+, MySQL/MariaDB/PostgreSQL, Twig, Guzzle) and layers on Canvas, the Mercury component library, the AI module family with provider modules, Webform, Project Browser and a long list of recipe-installed contrib. The 2026 advisory record shows how much of that tree needs patching: the bundled AI, Canvas, Webform and Project Browser modules all had advisories between June and September. Lowered slightly because the added surface is now visibly producing security churn.

Operational Overhead
7.2.1
Monitoring requirements
42M

The status report and Automatic Updates readiness checks remain the main built-in operational signals. Drupal CMS ships no APM, alerting or observability dashboard, so production monitoring needs external tools (New Relic, Datadog, uptime checks) or a managed host's instrumentation. Unchanged.

7.2.2
Content operations burden
40M

Drupal CMS bundles the Editoria11y accessibility checker and curated SEO tooling, and Canvas component instance updates reduce breakage when components change. Automated hygiene such as orphan detection, broken reference alerts and content expiry still needs extra contrib or manual editorial discipline. Unchanged.

7.2.3
Performance management
52M

Core 11.3 and later deliver the large throughput gains drupal.org describes (26 to 33 percent more requests on the same setup), which buys headroom before tuning. Cache tags and contexts, Varnish or CDN setup and database tuning remain operator work on self-hosted installs, while managed Drupal hosts absorb much of it. Unchanged.

Support & Resolution
7.3.1
Support tier quality
45M

The Drupal Association offers no support SLA for Drupal CMS; formal support comes from Drupal hosts (Pantheon, Upsun and others) or contracted agencies. That is a notable gap for a product aimed at marketers and site builders. Good support requires a paid hosting or agency arrangement. Unchanged.

7.3.2
Community support quality
72M

Dedicated #drupal-cms-support and #drupal-cms-development Slack channels are active with Drupal Association staff taking part, and the drupal_cms and canvas issue queues move quickly. Slightly below classic Drupal because Canvas and recipe-specific answered questions are still thinner than core's two-decade archive. Unchanged.

7.3.3
Issue resolution velocity
54M

Velocity is visibly strong: Canvas went from 1.2 to 1.12 in 2026, Drupal CMS shipped 2.1.5 to fix a fatal Starter install error and 2.1.6 on the day of the September critical contrib advisories, and 2.2.0 followed two days later. Security fixes land on pre-announced dates with clear advisories. Raised from 48 on this record; not higher because there is no SLA for non-security bugs and Drupal CMS relies on a smaller maintainer team than core.

8Use-Case Fit49▼
Marketing Sites
8.1.1
Landing page tooling
78H

Drupal CMS 2.0 (launched January 28, 2026) ships Canvas 1.0 — a drag-and-drop visual page builder that is now the default editing experience, offering live preview, component-based layout design, and AI-assisted page generation ('Build me a landing page'). The Byte site template provides a preconfigured B2B SaaS marketing site out of the box, and the Mercury component library supplies common building blocks. Marketers can compose pages from hero banners, card grids, and CTA blocks without touching code. Not quite 80+ because Canvas is new and the component library is still maturing.

8.1.2
Campaign management
38M

Drupal CMS provides content scheduling (publish/unpublish dates) and content moderation workflows but has no native campaign management module — no multi-channel coordination, campaign analytics dashboard, or campaign lifecycle tooling out of the box. Contrib modules (Campaign Monitor, Mailchimp recipe) extend this but do not constitute a campaign management system. Scores above headless CMS (30–35) only because of scheduling and moderation.

8.1.3
SEO tooling
83H

Drupal CMS's base recipe, which every site template builds on, installs a full SEO stack at install time: Metatag with Open Graph and Twitter Cards, Pathauto, Redirect plus Redirect 404 tracking, Simple XML Sitemap, dedicated SEO title/description/image fields on content, the SEO Checklist, and Yoast SEO for real-time on-page analysis stored in a per-node SEO analysis field. The previous score held back because real-time SEO feedback was thought to be contrib only; Yoast SEO actually ships preconfigured. Schema.org structured data still needs an add-on, which keeps it below the high 80s.

8.1.4
Performance marketing
50M

The Forms recipe installs Webform and Webform UI with ALTCHA, CAPTCHA and Honeypot spam protection, so marketers get a real form builder and lead capture with submission views out of the box, and site templates such as Byte ship newsletter sign-up blocks. ECA (installed in the base recipe) can react to form submissions for simple follow-up automation. There is no UTM-aware content, CTA performance tracking or conversion reporting inside the CMS; conversion measurement lives in GA4 via the Google Analytics recipe.

8.1.5
Personalization and targeting
35M

Drupal CMS ships no personalization. Canvas has a canvas_personalization submodule, but as of Canvas 1.12.0 it is still marked hidden (a feature flag, not a supported feature), and no Drupal CMS recipe or site template enables it. Rule-based targeting requires adding the Smart Content contrib module through Project Browser. Acquia's commercial personalization products are out of scope for this entry. Scores at the top of the no-native-personalization band because a contrib path exists and Canvas personalization is actively in development.

8.1.6
A/B testing and experimentation
46M

The Server-side A/B Testing module provides a genuine Drupal-native experimentation framework: server-side variant execution to eliminate flicker, content-based experiments using existing Drupal entities as variants, SEO-safe canonical handling, and GA4/GTM integration (experiment data exposed via drupalSettings, analytics events triggered). A/B Paragraphs 1.0.0-beta3 (February 2026) enables paragraph-level content variant testing, and the stable Kameleoon module offers a third option. Statistical analysis and winner selection still live in GA4 or external tools — no native stat-sig reporting or auto-winner in core. Scores in the 'experimentation via tight integration' band rather than the no-capability floor.

8.1.7
Content velocity
70H

Canvas is the default editor and has kept accelerating page production: content templates render node types through Canvas, page variants (Canvas 1.12) give editable full-page templates, autosave and Trash protect drafts, Media Library bulk upload and focal point cropping speed asset handling, and Scheduler with content moderation integration handles timed publishing. The AI recipe adds a Canvas page builder agent that places components from a prompt. Reaches 70 because marketers can clone, assemble and schedule pages without a developer; not higher because approval shortcuts and bulk page operations are basic.

8.1.8
Multi-channel publishing
55M

Drupal CMS provides RESTful and GraphQL JSON:API for headless/decoupled delivery to web, mobile, and other digital channels. Content structured in Drupal can be served to multiple front-end applications, IoT devices, and digital touchpoints via APIs. However, multi-channel is API-driven requiring front-end development per channel — no native social push, email, or SMS delivery from the CMS. Scores above purely headless CMS peers because Drupal's web-first experience is mature, and API delivery to additional channels is well-documented.

8.1.9
Marketing analytics integration
52M

Drupal CMS 2.0 includes one-click Google Analytics 4 and Google Tag Manager recipe integrations — no technical setup required. Matomo and other analytics platforms have contrib modules. However, content performance metrics (engagement data, content decay, top-performing pages) remain in external analytics tools — no native analytics dashboard within the CMS. Scores above 45 because GA4 and GTM are genuinely one-click in CMS 2.0, a meaningful improvement over manual tag installation.

8.1.10
Brand and design consistency
62M

Canvas 1.11 to 1.12 added Brand Kit, a site-level store of brand colors and fonts exposed as CSS variables and colour props, with usage tracking before deletion. Combined with the Mercury component library and theme-defined component props, marketers pick from approved components and brand colours rather than free-form styling. It is still guidance more than enforcement: there is no hard lock preventing an editor from choosing an off-brand layout, and code components can bypass the kit. Moves into the lower 60s on the strength of a platform-level brand token store.

8.1.11
Social and sharing integration
48M

The SEO Tools recipe provides OG and Twitter/X card meta tag management for social preview cards. Contrib modules exist for social sharing widgets, social feed embeds (Twitter, Facebook), and basic social media integration. No native social scheduling or push-to-social workflow exists in Drupal CMS 2.0 — social distribution requires external tools (Buffer, Hootsuite). Scores at the standard 'OG plus social sharing' tier for traditional CMS platforms.

8.1.12
Marketing asset management
48M

The base recipe configures a Media Library with image, document, local video, remote video and SVG media types, bulk upload, focal point cropping, responsive image styles and media file cleanup on delete. That is a working marketing asset store with transforms, but rights management, expiry and usage reporting across pages are not included, and enterprise DAM requires an integration module. Acquia DAM is an Acquia product and does not count here.

8.1.13
Marketing localization
62H

Drupal CMS has one of the strongest multilingual frameworks in open-source CMS: core Language, Content Translation, Interface Translation, and Configuration Translation modules provide field-level translation, locale-specific content scheduling, and per-language URL structures. The Translation Management Tool (TMGMT) contrib module adds translation workflow, professional translation service integrations, and transcreation workflows. Regional cookie consent and compliance can be managed per locale via contrib. Not 65+ because transcreation UI and market-level scheduling are contrib rather than recipe-ready.

8.1.14
MarTech ecosystem connectivity
52M

Out of the box Drupal CMS 2.x offers the Google Analytics recipe (GA4 and Google Tag Manager) and ECA, a no-code event-condition-action engine that can fire on content and form events for orchestration. The curated recommended add-ons list no longer includes a Mailchimp recipe, so email/MAP, CRM (HubSpot, Salesforce) and CDP connections all come from contrib modules added through Project Browser. Mid-band: generic event triggers plus one preconfigured MarTech category.

Commerce
8.2.1
Product content depth
65M

Drupal CMS ships no commerce: none of its recipes or its 22 installer site templates include Drupal Commerce. Commerce 3.x can be added through Composer or Project Browser and brings product types, attribute-based variations, per-variation media and taxonomy, and the redesigned 3.3 order management UI, all on the same entity system Drupal CMS uses. The capability is real and mature, but it is an add-on rather than something Drupal CMS preconfigures, and Canvas has no product-specific components, so this sits below the Drupal core entry.

8.2.2
Merchandising tools
48M

Drupal Commerce provides category management, promotion and discount engines, and scheduled pricing — reasonable for an open-source commerce layer. However, there are no native search result merchandising tools, AI-driven cross-sell/upsell content blocks, or visual merchandising interfaces. Category management and promotional content scheduling exist but require custom development for advanced merchandising. Scores above 35 because Commerce's promotion engine is real.

8.2.3
Commerce platform synergy
45M

Drupal Commerce is the natural commerce layer, but it is not bundled, and there is no maintained first-party connector for Shopify, commercetools or BigCommerce in Drupal CMS. External commerce platforms connect through contrib modules or custom JSON:API work, with no product picker in Canvas. Scores in the lower mid band: an integration path exists but is not a product capability.

8.2.4
Content-driven storytelling
55M

With Drupal Commerce added, product entities can be referenced inside Canvas pages and editorial content, so buying guides and shoppable articles are possible. Canvas does not ship product card or add-to-cart components, and no site template demonstrates editorial commerce, so the pattern has to be built by a developer before marketers can compose it. Lands in the 'possible but not first-class' band.

8.2.5
Checkout and cart content
35M

Drupal Commerce provides some CMS-manageable elements in the checkout flow — trust badges, promotional messaging, and upsell blocks can be placed on cart and checkout pages via Drupal's block system. However, there is no dedicated CMS-controlled content injection layer for transactional flows — checkout templates are primarily Commerce-controlled and require developer changes to introduce CMS-managed content blocks. Scores above the floor because the underlying Drupal block architecture technically enables content in checkout, but it's not a turnkey feature.

8.2.6
Post-purchase content
42M

Drupal Commerce provides a customer dashboard where order history, address book, and payment management are accessible — and CMS content can be surfaced in this area via Drupal's block/view system. Order confirmation emails are templated and can include CMS-managed content. However, CMS-managed post-purchase sequences tied to order events (delivery tracking, review solicitation, loyalty content) require custom development or contrib modules. Scores above the floor because the Commerce customer portal exists.

8.2.7
B2B commerce content
55M

Drupal's role and access system handles gated documentation and account-based content, and Commerce plus the Commerce Pricelist and B2B contrib modules add customer-specific pricing and quote flows. None of this is preconfigured in Drupal CMS, which slightly lowers the score versus the previous round, but B2B builds on Drupal are well established.

8.2.8
Search and discovery content
50M

Drupal Search API with Solr or Elasticsearch backend enables faceted product and content search, taxonomy-driven filtering, and search result blending of editorial and product content. Commerce-specific search landing pages are achievable via Views and Search API. Synonym management and search result merchandising require contrib customization. Scores at mid-range because Search API is powerful but requires significant configuration and no native blended content-product search UI exists out of the box.

8.2.9
Promotional content management
52M

Drupal Commerce ships with a promotion engine supporting time-based activation, percentage/fixed discounts, promo codes, tiered pricing, and scheduled pricing rules. Sale banners and countdown timers can be managed via Drupal's block and scheduling system. Channel-specific targeting requires additional configuration. The promotion engine is genuinely capable for an open-source platform. Not 60+ because channel-specific content targeting and countdown timer components require contrib.

8.2.10
Multi-storefront content
50M

Multiple storefronts are achievable through Drupal Commerce's multi-store support or Drupal multisite, with shared product entities and per-store editorial content. It requires Commerce plus architectural setup, and Drupal CMS adds nothing specific for storefront separation, so it sits in the 'possible with some duplication' band.

8.2.11
Visual commerce and media
40M

Drupal's media library supports image galleries, video embedding, and basic image transforms. Product images with multiple angles are manageable. However, there is no native 360-degree product viewer, AR/3D model support, or image hotspot functionality in Drupal Commerce or Drupal CMS 2.0. These advanced visual commerce features require third-party integrations (Cloudinary, Viuer) or custom development. Scores above the floor because multi-image galleries and video on product pages are achievable without custom code.

8.2.12
Marketplace and seller content
35M

Drupal Commerce marketplace capability exists via contrib (Commerce Marketplace module, custom multi-vendor setups) but is not a first-class out-of-the-box feature. Seller profiles, seller-contributed product descriptions, and content moderation at marketplace scale are achievable but require significant developer configuration. No turnkey marketplace content management solution ships with Drupal CMS 2.0. Scores in the 30s — not at the floor because the Drupal ecosystem has documented B2B marketplace deployments.

8.2.13
Commerce content localization
60M

The Multilingual recipe adds content, config and interface translation plus Canvas translation, which applies to Commerce product and variation entities once Commerce is installed; Commerce itself handles currencies and translatable store emails. Locale-specific product copy and regional legal blocks are therefore achievable, but market-specific promo calendars and regulatory content types must be built.

8.2.14
Commerce conversion analytics
35M

Drupal Commerce integrates with GA4 via the Google Analytics module, enabling basic ecommerce tracking (product views, add-to-cart, purchases). However, there is no native content-to-revenue attribution within the CMS — connecting which editorial pages assisted conversions requires GA4 or external analytics configuration. No content performance dashboard within Drupal CMS surfaces commerce conversion data. Scores at 35 as a CMS with GA4 ecommerce tracking available but no native content-commerce analytics.

Intranet & Internal
8.3.1
Access control depth
72H

Drupal CMS inherits core's granular access control (per-bundle and per-operation permissions, content moderation states, unpublished access) and preconfigures Administrator and Content Editor roles. Department- or team-level audience visibility needs the Group or a node-access contrib module, and SSO needs a SAML or OpenID Connect module, neither of which Drupal CMS installs. Still well above simple public/private, but the audience-based piece is an add-on.

8.3.2
Knowledge management
55M

Revisions, content moderation workflows, Scheduler, Trash for recoverable deletes, taxonomy with Tagify, and the Search recipe (Search API with a database backend) give Drupal CMS a sound base for a knowledge site. There is no review-date or expiry lifecycle, and the default database search is basic. The previous score leaned on Open Intranet's RAG search, which belongs to a separate distribution and is not part of Drupal CMS.

8.3.3
Employee experience
40M

Drupal CMS is aimed at public marketing sites, and none of its 22 site templates is an intranet or employee portal. What exists natively is login, user pictures, an admin dashboard and comments. News feeds, employee directories, notifications and personalized dashboards must be built with Views and contrib. Mature Drupal intranet products (Open Intranet, Open Social) are separate distributions with their own install profiles, so they are not credited to Drupal CMS. Scores above headless peers because Drupal's authenticated-user model and Views make a portal buildable without a custom frontend.

8.3.4
Internal communications
40M

Internal news can be published as articles with scheduling and moderation, and audience targeting is possible with access-control modules, but Drupal CMS has no announcement targeting, read receipts or acknowledgment tracking. The SMS and messenger features cited previously come from Open Intranet, a separate distribution. Basic news publishing with some targeting.

8.3.5
People directory and org chart
35M

User accounts with pictures and fields plus Views allow a basic staff directory to be built, but Drupal CMS ships no directory, org chart or HR integration. The Healthcare template's provider directory shows the pattern for public listings, not employee directories.

8.3.6
Policy and document management
45M

Drupal provides revision history on all content, content moderation workflows (draft/review/publish), and scheduled content review via the Content Planner module. Document publishing with version control is achievable. However, there is no native mandatory-acknowledgment tracking, policy expiry reminders, or formal SOP management workflow in Drupal CMS 2.0 or Open Intranet. Policy management is possible via Drupal's content structures but requires custom configuration to match dedicated policy management tools.

8.3.7
Onboarding content delivery
32M

Onboarding pages can be assembled from content types, Canvas pages and role-restricted menus, but Drupal CMS has no role-specific paths, checklists or progressive disclosure. The Courses recipe credited previously belongs to Open Intranet, not Drupal CMS.

8.3.8
Enterprise search quality
48M

The Search recipe preconfigures Search API with a database backend, indexes Canvas pages and all content types, and supports per-item exclusion; Solr or Elasticsearch backends and facets are contrib additions. There is no federation to SharePoint, Confluence or Drive and no AI relevance in the default install. Adequate internal search with basic faceting once facets are added.

8.3.9
Mobile and frontline access
38M

Mercury and the site templates are responsive, and the Gin admin theme works on mobile, so staff can read and edit from phones. There is no native app, push notification or offline support, and the SMS reach credited previously came from Open Intranet rather than Drupal CMS.

8.3.10
Learning and training integration
30M

Training content can be hosted as pages and documents, but Drupal CMS has no course, completion-tracking or LMS integration features. The previous score credited Open Intranet's Courses recipe, which is not part of Drupal CMS. Basic learning content hosting only.

8.3.11
Social and collaboration features
40M

Core comments are available and the Forms recipe's Webform covers polls and surveys, but Drupal CMS has no reactions, forums, peer recognition, idea submission or community spaces. Those features (Kudos, Ideas) belong to Open Intranet. Basic commenting plus surveys.

8.3.12
Workplace tool integration
42M

Drupal CMS can reach workplace tools through ECA actions and contrib modules for Microsoft Entra ID, Google and Slack, but it installs none of them and has no Teams or Slack cards. The Microsoft 365 and Google Workspace integrations credited previously are Open Intranet features. Basic webhook-style integration only.

8.3.13
Content lifecycle and archival
50M

Drupal CMS provides content scheduling (publish/unpublish dates), revision history, content moderation workflow (draft/review/published/archived states), and the Content Planner module for editorial scheduling. The 2026 Drupal AI roadmap proposes background agents that autonomously flag outdated articles, but these are roadmap items, not shipped features. Automated review reminders for stale content and systematic archival workflows still require contrib rather than being native to CMS 2.0. Scores at 50 because the moderation states and scheduling exist, but automated freshness enforcement needs additional setup.

8.3.14
Internal analytics and engagement
35M

Drupal intranet deployments rely on GA4 or Matomo for basic page view analytics, accessible in external tools rather than within the CMS/intranet interface. There is no native intranet analytics dashboard in Open Intranet or Drupal CMS showing department-level engagement, failed search terms, or adoption metrics. Search analytics are available in Drupal Search API but require additional configuration to surface insights. Scores at 35 — above the floor because Search API logs are available, but below 45 because there is no purpose-built intranet engagement dashboard.

Multi-Brand / Multi-Tenant
8.4.1
Tenant isolation
65H

Drupal Multisite provides silo-based isolation: each site gets its own database, configuration, files, and domain while sharing a single codebase. Three architectural modes exist (multi-tenant shared DB, hybrid, multi-instance). This is genuine isolation at the application level, though not a SaaS-native multi-tenant architecture with guaranteed zero data leakage at the infrastructure layer. Adequate for enterprise multi-brand but requires ops discipline to maintain isolation.

8.4.2
Shared component library
62M

Drupal Multisite shares a single codebase, allowing themes, modules, and Canvas component libraries to be maintained centrally and consumed by all brand instances. Drupal distributions and install profiles can enforce shared design tokens and templates. Canvas 1.0 (with the Mercury component library) introduces a component system that further enables cross-brand reuse, and the Site Template Marketplace pilot (DrupalCon Chicago 2026) adds reusable site foundations. However, there is no native UI for 'global content' pushed to multiple sites — this requires custom sync or a contrib approach like Config Split. Federation is workaround-based rather than first-class.

8.4.3
Governance model
55M

Across a Drupal multisite estate, governance comes from a shared codebase, shared recipes and site templates (Drupal CMS 2.2 can export a site as a reusable template with drush site:export), config management and consistent roles. There is no console enforcing standards or approvals across brands. Acquia Site Factory and similar commercial layers are out of scope for this entry, so the score drops from the previous round.

8.4.4
Scale economics
73H

Drupal CMS is open source (GPL, no per-brand licensing fees), meaning additional brands add only infrastructure costs rather than license costs. A shared multisite codebase further reduces maintenance overhead across brands. Self-hosted or cloud-hosted via commodity providers. Compare to proprietary DXPs where each brand instance can cost six-figure license fees. The economics strongly favor Drupal for multi-brand scale, limited only by developer/hosting costs which remain relatively fixed.

8.4.5
Brand theming and style isolation
62M

Each brand site can run its own theme or Mercury sub-theme and, since Canvas 1.12, its own Brand Kit of colours and fonts applied to shared components through CSS variables. Shared components with per-site brand tokens meet the platform-level theming bar, though there is no single console managing brand kits across a portfolio.

8.4.6
Localized content governance
45M

Drupal CMS supports multilingual content per brand site in a multisite setup — each site can have its own language configuration, translation workflows, and regional legal content. Per-brand translation approval workflows are achievable via content moderation and TMGMT. However, there is no native brand-locale intersection governance — managing Brand A's French translations separately from Brand B's French translations with different approval chains requires custom workflow configuration rather than being a native platform feature.

8.4.7
Cross-brand analytics
30M

Drupal CMS has no native cross-brand analytics dashboard. Each site in a multisite setup sends analytics independently to GA4, Adobe Analytics, or other external tools. Portfolio-level aggregation requires manual setup in Google Analytics 360 (roll-up properties), custom reporting, or third-party analytics aggregation tools. The 2026 Context Control Center proof of concept shows some cross-site data awareness but is experimental. Scores at 30 — not at the absolute floor because GA4 is one-click per site and cross-property reporting is possible externally.

8.4.8
Brand-specific workflows
48M

In a Drupal multisite setup, each site can have independently configured content moderation workflows via Config Split — Brand A can have a 4-stage editorial review while Brand B has a simple draft-publish workflow. However, central auditability across brand workflows requires custom reporting or contrib — there is no native cross-brand workflow audit console. Scores at 48 because per-brand workflow configuration is genuinely possible and documented, but central oversight is a gap.

8.4.9
Content syndication and sharing
33M

Drupal CMS has no corporate-to-brand syndication. Sharing content between sites requires contrib such as Entity Share or custom JSON:API sync, with no override-point model. Acquia Content Hub is a commercial Acquia product and is no longer credited here.

8.4.10
Regional compliance controls
45M

Each site in a Drupal multisite can have independently configured cookie consent (EU Cookie Compliance module), accessibility settings, data residency preferences (via hosting), and GDPR-related modules. Per-brand compliance configuration is therefore achievable. However, there are no platform-level publishing guardrails that prevent non-compliant content from being published — compliance is enforced through configuration discipline rather than automated checks. Scores at 45 because per-brand compliance configuration is real but guardrails are manual.

8.4.11
Design system management
55M

A central Canvas component library (SDC and code components, with version hashes tracked per component instance), shared Mercury theme, per-site Brand Kits and exportable site templates give a workable federated design system, with updates propagated through Composer and Git. Versioning and override management happen in code, not in a design-system UI.

8.4.12
Cross-brand user management
48M

Multisite can share or isolate user tables, and SSO across brand sites is possible with SAML or OpenID Connect contrib modules, but Drupal CMS installs neither and has no central console for per-brand teams. Acquia Site Factory's central user management is out of scope for this entry. Basic per-site user management with limited central oversight.

8.4.13
Multi-brand content modeling
48M

Drupal's shared multisite codebase allows content types to be defined centrally and shared across brand sites. Brand-specific field extensions are achievable via contrib (Field Group, per-site Config Split) but currently require forking the base content type configuration — there is no native 'extend without fork' inheritance model for content types in Drupal. Config Split mitigates this but adds complexity. Scores at 48 because shared base models are real but per-brand extension without forking is a workaround rather than a first-class feature.

8.4.14
Portfolio-level reporting
25M

There is no portfolio reporting in Drupal CMS. Each site has its own dashboard and GA4 property, and freshness or SLA reporting across brands needs external BI. The previous score credited Acquia Site Factory's management views, which are out of scope.

9Regulatory Readiness & Trust42▼
Data Privacy & Regulatory
9.1.1
GDPR & EU data protection
48H

Drupal CMS installs the Klaro! consent manager in its base recipe for every site template, with a placeholder privacy policy page linked from the consent modal, and Klaro 3.1 (July 2026) added category-based consent and Google Consent Mode v2. However, the Drupal Association issues no DPA, sub-processor list or residency terms for the open-source product, so GDPR contracts are the deploying organization's responsibility, and Klaro still stores consent client-side only with no server-side proof of consent (issue #3549264, open as of 2026-09), which falls short of GDPR Article 7 without added logging.

9.1.2
HIPAA & healthcare compliance
28H

The Drupal Association does not issue Business Associate Agreements, and there is no HIPAA-eligible service offering for the open-source product. HIPAA compliance for Drupal is achieved only at the hosting/ecosystem level — e.g., Acquia signs a BAA and maps SOC 2 controls to HIPAA — not at the platform level. Drupal CMS itself provides no BAA and no documented HIPAA-eligible infrastructure.

9.1.3
Regional & industry regulations
40M

Drupal remains the dominant CMS for US government (NASA, USDA, VA, FDA, FCC and hundreds of federal properties) and is recognized for easing FedRAMP and Section 508 compliance paths — but FedRAMP authorization applies to the hosted system boundary (Acquia, GovDataHosting), not the open-source product, so it cannot be inherited. GDPR and CCPA are achievable via the GDPR module and Klaro. No IRAP, C5, PCI-DSS, or HITRUST certifications exist for the core software.

Security Certifications
9.2.1
SOC 2 Type II
22H

Drupal CMS is open-source software distributed by the Drupal Association; no SOC 2 Type 2 attestation exists for the platform itself, and 2026 searches confirm no Drupal Association certification. Hosting providers (Acquia, Pantheon, Platform.sh) hold their own SOC 2 Type 2 reports covering hosting infrastructure, not the Drupal CMS software product. Per scoring guidance for open-source self-hosted platforms, the customer is wholly responsible.

9.2.2
ISO 27001 / ISO 27018
22H

No ISO 27001 certification exists for Drupal CMS as open-source software or for the Drupal Association in scope of the platform. ISO 27001-certified Drupal hosting (amazee.io, Acquia) refers to the hosting provider's ISMS, not the CMS software — the anti-pattern of inheriting hosting certifications applies. Customers deploying on certified infrastructure gain that coverage, but Drupal CMS itself neither holds nor conveys the certification.

9.2.3
Additional certifications
32M

No third-party security certifications (CSA STAR, PCI DSS, Cyber Essentials, FedRAMP) apply to the Drupal CMS open-source product. The compensating factor remains strong: a dedicated 20+ member Drupal Security Team with a structured public advisory process, scheduled security release windows, a 25-point vulnerability severity scale, and coordinated disclosure — exceeding typical open-source practice. This positions Drupal CMS above minimally-maintained OSS but well below certified commercial platforms.

Data Governance
9.3.1
Data residency & sovereignty
50M

As self-hosted open-source software, Drupal CMS provides complete data residency flexibility — organizations can deploy in any region or on-premises with no vendor constraining data location, an intrinsic advantage over SaaS platforms. However, there are no vendor-issued contractual residency guarantees because there is no vendor-customer hosting relationship. CDN and sub-processor data flows are determined entirely by the deploying organization's infrastructure choices.

9.3.2
Data lifecycle & deletion
52M

Out of the box, Drupal CMS gives site owners full control of their data: the base recipe bundles the Trash module (soft delete and restore), core user cancellation can delete an account together with its content, and the 2.2 `drush site:export` command exports a whole site as a recipe. The GDPR module's export and 'forget me' workflows exist, but they are a contrib add-on that Drupal CMS does not install, so there is no ready-made self-service data subject request portal. Retention after deletion follows the deployer's own policy, not a vendor schedule.

9.3.3
Audit logging & compliance reporting
50M

The Drupal CMS base recipe enables core Database Logging (dblog), which records content operations, user actions and login events in an admin report. Core Syslog forwards logs to a SIEM through the system syslog daemon, and the stable Admin Audit Trail contrib module (1.0.13, Sept 2026) adds entity and configuration change logging, but neither is enabled by default and there is no native SIEM push connector. The tamper-evident audit_trail module is still dev-only, and dblog trims rows by count, so production deployments need a deliberate log pipeline.

Platform Accessibility
9.4.1
Authoring UI accessibility
62H

Drupal's Claro admin theme documents WCAG 2.1 AA conformance, accessibility is enforced as a core merge gate (keyboard navigation, screen reader support, focus management), and the project follows the latest WCAG recommendation (2.2 AA) with an ATAG 2.0 target for authoring interfaces. Drupal CMS 2.0 (Jan 28, 2026) made the Canvas drag-and-drop visual editor the default authoring experience and added AI-assisted alt text with human review, but Canvas's accessibility conformance is not yet formally documented, preventing a higher score.

9.4.2
Accessibility documentation
50M

Drupal.org maintains a dedicated accessibility page documenting WCAG 2.2 AA targets and ATAG 2.0 commitments, and the GSA maintains a VPAT for Drupal core (with community OpenACR/VPAT tooling under CC BY-SA), supporting government procurement. However, no single current, product-level VPAT/ACR for Drupal CMS 2.0 (including the new Canvas builder) is published on drupal.org for direct procurement use — a formal core ACR remains an open issue (#3335955), and third-party Drupal ACRs are implementation-specific.

10AI Enablement55▼
AI Content Creation
10.1.1
AI text generation & editing
66H

Drupal CMS 2.x's AI Assistant recipe preconfigures Canvas AI, which builds pages from a prompt, plus the ai_agents chatbot. The in-editor CKEditor assistant is not bundled: in AI 1.5.0 (Sept 25 2026) the ai_ckeditor submodule is deprecated in favour of a standalone project that is still at 1.5.0-beta4, and AI Automators ship in the installed ai package but come unconfigured. Scores 66 because prompt-driven page generation works out of the box, but rewriting, summarising and brand-voice controls in the editor need modules the installer does not set up.

10.1.2
AI image & media generation
54H

The AI recipe installs ai_image_alt_text, grants content editors 'generate ai alt tags' by default, and gates the feature behind a Klaro consent app, so alt-text generation works on first install. AI 1.5.0 adds rich-text image description to Automators and lets providers declare their text-to-image formats. Image generation still goes through Field Widget Actions and the provider (DALL-E and similar), which the installer does not configure. Scores 54 because only alt text is turnkey, and there is no smart crop or AI video processing.

10.1.3
AI translation assistance
55H

Neither the Drupal CMS AI recipe nor the multilingual recipe installs AI translation. The one-click ai_translate submodule is deprecated in AI 1.5.0 and has moved to a standalone ai_translate project (1.4.2 stable, Sept 2026), and the contrib ai_content_translation module handles structured content. Automators can batch-translate through Views Bulk Operations. Scores 55, which puts it in the basic-MT-hookup band: the capability is a stable add-on rather than part of the preconfigured localisation workflow, and it has no quality scoring or cross-locale brand-voice controls. The previous round credited contrib modules as native.

10.1.4
AI metadata & SEO automation
56H

Out of the box Drupal CMS generates AI alt text, and its base recipe ships Yoast SEO real-time analysis and the SEO Checklist, but those two are rule-based, not AI. AI-written meta titles, descriptions and taxonomy tags need AI Automators to be configured on fields (AI 1.5.0 adds a setup-automators agent skill) or the contrib ai_seo or contentai modules. Scores 56, the partial-automation band. The previous round's 62 treated contrib SEO modules as bundled.

AI Workflow Automation
10.2.1
AI-assisted content operations
64H

AI Automators ship in the installed ai package and support auto-tagging, summarisation, OCR, transcription and chained pipelines. They can run in bulk through Views Bulk Operations, and AI 1.5.0 adds configurable queue items per cron run and guardrails on Automators. None of it is configured by default: the Drupal CMS recipe enables only alt text, the site-building chatbot and Canvas AI. Scores 64 because the automation is broad and a site builder can enable it without code, but the installer does not build it into editorial work, and there is no smart scheduling or duplicate detection.

10.2.2
Agentic workflow automation
55H

The AI recipe installs ai_agents and puts a 'Drupal Agent' chatbot in the admin toolbar. The chatbot runs site-building functions such as creating fields and content types, and its permissions can be set per role. Canvas 1.11 and 1.12 (Aug and Sept 2026) built a Canvas Page Agent and a component agent with a Tools dropdown and chat history, but these sit in canvas_dev_ai behind an aiDevMode flag. AI 1.5.0 added agent skills and ChatMemory plugins. Scores 55 because agents are GA and preconfigured, but the shipped agent builds sites rather than running editorial pipelines, and the page-building agent is not released.

10.2.3
Content intelligence & insights
38M

Drupal CMS ships no AI content intelligence. The bundled ai_dashboard covers AI configuration, not content performance, and the base recipe's dashboard and SEO Checklist are not AI. Gap analysis and stale-content detection come from contrib modules such as ai_content_strategy and ai_seo, or from custom agents. Scores 38, the basic band, because nothing preconfigured does topic clustering, performance scoring or editorial prioritisation.

10.2.4
AI content auditing & quality
42M

AI 1.5.0 adds a configurable Moderation Guardrail plugin and a semantic topic-matching mode for the RestrictToTopic guardrail. Automators can classify or validate many entities at once through Views Bulk Operations. The older ai_validations and ai_external_moderation submodules are now deprecated, and that functionality has moved into AI core and standalone projects. Drupal CMS bundles Editoria11y, but its accessibility checks are rule-based, not AI. Scores 42 because moderation-style auditing at scale is possible, but there is no brand-voice or quality audit suite.

AI Search & Personalization
10.3.1
AI/semantic search
48H

The Drupal CMS Search recipe installs keyword-only search (search_api + search_api_db) and nothing AI. Vector search is an add-on: in AI 1.5.0 the ai_search submodule is deprecated and marked experimental, and it has moved to a standalone ai_search project still at alpha (2.0.0-alpha2, 1.3.0-alpha5 on Sept 23 2026). Backends include the stable MariaDB VDB provider (1.0.1) and Elasticsearch hybrid search. AI 1.5.0 also adds an AI reranking processor for Search API. Scores 48 because production-grade parts exist, but semantic search is an alpha add-on that nothing preconfigures.

10.3.2
AI-powered personalization
28M

Drupal CMS has no ML personalization engine. Canvas's canvas_personalization module is still hidden as of Canvas 1.12 (Sept 2026), and it is rule-based page variants, not predictive. Smart Content plus a custom engine remains partner-built work. Scores 28 because nothing ships for predictive segments, next-best-content or cold-start handling.

AI Platform & Extensibility
10.4.1
MCP server availability
42H

Drupal CMS does not bundle an MCP server. The contrib mcp_server module was rewritten on the official MCP PHP SDK and is now 2.0.0-beta5 (Sept 23 2026), with STDIO and HTTP transports and plugin-based tools, prompts and resources. OAuth2 scopes, the admin UI and the Tool API bridge are now separate companion projects, and Tool API is still 1.0.0-beta10. The older mcp module has been stable at 1.2.3 since Nov 2025. Scores 42, the beta band: the server does a lot, but the maintained line is not stable and nothing preconfigures it.

10.4.2
Bring your own AI model/key (BYOM/BYOK)
80H

The Drupal CMS installer asks which provider to use, amazee.ai, OpenAI or Anthropic, and since March 2026 it encrypts provider keys at rest with easy_encryption. The amazee.ai default is a 30-day trial that becomes a paid plan. Behind that, the ai module's provider abstraction supports dozens of providers, including self-hosted Ollama and LM Studio, and provider failover. Scores 80 for real multi-provider BYOK with local-model options; not higher because data residency depends on the chosen provider.

10.4.3
AI developer extensibility & agent APIs
68H

The ai module gives developers function-call plugins, Tool API integration and drush scaffolding. AI 1.5.0 adds agent skills, ChatMemory plugins, per-instance context overrides on function calls, multimodal embeddings in the API Explorer and token-usage metadata. The Drupal CMS project template now ships an AGENTS.md for coding agents, and JSON:API is inherited from core. Scores 68 because the extension surface is rich and well documented, but Tool API is still beta and there is no dedicated AI SDK or LLM-optimised delivery endpoint.

10.4.4
AI governance, safety & audit trails
70H

AI 1.5.0 builds on the global guardrails, streaming guardrails and input-length limits from the 1.4 line. It adds a configurable Moderation Guardrail plugin, semantic topic matching, regex validation and guardrails on Automators, and AI calls are logged through ai_observability. The Drupal CMS recipe itself routes AI features through Klaro consent, encrypts provider keys, and sets agent permissions per role. Scores 70, top of the good-governance band; not 75+ because there is no IP indemnification or hallucination confidence scoring.

10.4.5
AI observability & usage analytics
55H

AI Metering reached stable 1.0 in August 2026 (1.0.2, Aug 14). It adds pre-flight cost estimates, per-user monthly token quotas with fallback to a local model, a usage dashboard, a per-call log with CSV export and a personal usage block for editors. AI 1.5.0 adds gen_ai.* OpenTelemetry semantic conventions to ai_observability. Scores 55 because cost, quota and per-user tracking now exist inside Drupal, but AI Metering is a contrib add-on that Drupal CMS does not install, and there is no quality-trend or prompt-effectiveness analytics.

Score History

How composite scores (0–100) have changed over time. Click legend items to show/hide metrics.

+1.1 capability
analyst note

Recent Updates

September 202613 score changes▼

Drupal CMS is essentially stable this review, with Capability, Cost Efficiency and Operational Ease unchanged and only fractional movement in Platform Velocity, Build Simplicity and Compliance & Trust. The small slip in Compliance & Trust traces to data lifecycle and deletion, where the base recipe's Trash module and export controls now read as a partial answer rather than a full retention and erasure story, while the modest Platform Velocity dip reflects AI progress arriving through contrib rather than the product itself. Practitioners should note the AI-side gains beneath the flat headline: AI 1.5 brings a configurable Moderation Guardrail and semantic topic matching, AI Automators now cover tagging, summarisation, OCR and transcription, and the contrib MCP server has been rebuilt on the official PHP SDK, but semantic search and MCP support still require modules outside the Drupal CMS install and none of it moves Capability yet.

Score Changes

AI/semantic search48 → 55(+7)

The Drupal CMS Search recipe installs keyword-only search (search_api + search_api_db) and nothing AI. Vector search is an add-on: in AI 1.5.0 the ai_search submodule is deprecated and marked experimental, and it has moved to a standalone ai_search project still at alpha (2.0.0-alpha2, 1.3.0-alpha5 on Sept 23 2026). Backends include the stable MariaDB VDB provider (1.0.1) and Elasticsearch hybrid search. AI 1.5.0 also adds an AI reranking processor for Search API. Scores 48 because production-grade parts exist, but semantic search is an alpha add-on that nothing preconfigures.

AI content auditing & quality38 → 42(+4)

AI 1.5.0 adds a configurable Moderation Guardrail plugin and a semantic topic-matching mode for the RestrictToTopic guardrail. Automators can classify or validate many entities at once through Views Bulk Operations. The older ai_validations and ai_external_moderation submodules are now deprecated, and that functionality has moved into AI core and standalone projects. Drupal CMS bundles Editoria11y, but its accessibility checks are rule-based, not AI. Scores 42 because moderation-style auditing at scale is possible, but there is no brand-voice or quality audit suite.

MCP server availability38 → 42(+4)

Drupal CMS does not bundle an MCP server. The contrib mcp_server module was rewritten on the official MCP PHP SDK and is now 2.0.0-beta5 (Sept 23 2026), with STDIO and HTTP transports and plugin-based tools, prompts and resources. OAuth2 scopes, the admin UI and the Tool API bridge are now separate companion projects, and Tool API is still 1.0.0-beta10. The older mcp module has been stable at 1.2.3 since Nov 2025. Scores 42, the beta band: the server does a lot, but the maintained line is not stable and nothing preconfigures it.

Data lifecycle & deletion55 → 52(-3)

Out of the box, Drupal CMS gives site owners full control of their data: the base recipe bundles the Trash module (soft delete and restore), core user cancellation can delete an account together with its content, and the 2.2 `drush site:export` command exports a whole site as a recipe. The GDPR module's export and 'forget me' workflows exist, but they are a contrib add-on that Drupal CMS does not install, so there is no ready-made self-service data subject request portal. Retention after deletion follows the deployer's own policy, not a vendor schedule.

AI-assisted content operations67 → 70(+3)

AI Automators ship in the installed ai package and support auto-tagging, summarisation, OCR, transcription and chained pipelines. They can run in bulk through Views Bulk Operations, and AI 1.5.0 adds configurable queue items per cron run and guardrails on Automators. None of it is configured by default: the Drupal CMS recipe enables only alt text, the site-building chatbot and Canvas AI. Scores 64 because the automation is broad and a site builder can enable it without code, but the installer does not build it into editorial work, and there is no smart scheduling or duplicate detection.

AI developer extensibility & agent APIs65 → 68(+3)

The ai module gives developers function-call plugins, Tool API integration and drush scaffolding. AI 1.5.0 adds agent skills, ChatMemory plugins, per-instance context overrides on function calls, multimodal embeddings in the API Explorer and token-usage metadata. The Drupal CMS project template now ships an AGENTS.md for coding agents, and JSON:API is inherited from core. Scores 68 because the extension surface is rich and well documented, but Tool API is still beta and there is no dedicated AI SDK or LLM-optimised delivery endpoint.

AI governance, safety & audit trails65 → 68(+3)

AI 1.5.0 builds on the global guardrails, streaming guardrails and input-length limits from the 1.4 line. It adds a configurable Moderation Guardrail plugin, semantic topic matching, regex validation and guardrails on Automators, and AI calls are logged through ai_observability. The Drupal CMS recipe itself routes AI features through Klaro consent, encrypts provider keys, and sets agent permissions per role. Scores 70, top of the good-governance band; not 75+ because there is no IP indemnification or hallucination confidence scoring.

API performance58 → 60(+2)

No vendor SLA or documented rate limits since Drupal CMS is self-hosted by default. The core engine keeps improving: Drupal 11.4 (July 1, 2026) roughly halves database queries versus 11.3 and adds Brotli compression for aggregated CSS/JS, and Drupal CMS 2.0 sites can adopt the 11.4 core line. Dynamic Page Cache and Internal Page Cache provide layered caching and JSON:API responses can sit behind Varnish/CDN, but there is still no CDN-backed delivery or built-in rate limiting out of the box — which is why this stays below CDN-delivered API platforms.

Release frequency80 → 78(-2)

Drupal CMS shipped 2.1.4 (Sept 1), 2.1.6 (Sept 23) and the 2.2.0 minor (Sept 25, 2026) with premium site templates, AI key encryption and a project-level AGENTS.md, while bundled Canvas released 1.8 through 1.12 between July and September and core shipped 11.4.0 through 11.4.8 since July 1. Held at 78 rather than 80 because the distribution itself went three months between 2.1.3 (June 2) and 2.1.4, and Drupal 12 has only reached alpha1 (Sept 2) with beta1 still untagged past its mid-September target.

AI image & media generation52 → 54(+2)

The AI recipe installs ai_image_alt_text, grants content editors 'generate ai alt tags' by default, and gates the feature behind a Klaro consent app, so alt-text generation works on first install. AI 1.5.0 adds rich-text image description to Automators and lets providers declare their text-to-image formats. Image generation still goes through Field Widget Actions and the provider (DALL-E and similar), which the installer does not configure. Scores 54 because only alt text is turnkey, and there is no smart crop or AI video processing.

AI translation assistance60 → 62(+2)

Neither the Drupal CMS AI recipe nor the multilingual recipe installs AI translation. The one-click ai_translate submodule is deprecated in AI 1.5.0 and has moved to a standalone ai_translate project (1.4.2 stable, Sept 2026), and the contrib ai_content_translation module handles structured content. Automators can batch-translate through Views Bulk Operations. Scores 55, which puts it in the basic-MT-hookup band: the capability is a stable add-on rather than part of the preconfigured localisation workflow, and it has no quality scoring or cross-locale brand-voice controls. The previous round credited contrib modules as native.

AI metadata & SEO automation60 → 62(+2)

Out of the box Drupal CMS generates AI alt text, and its base recipe ships Yoast SEO real-time analysis and the SEO Checklist, but those two are rule-based, not AI. AI-written meta titles, descriptions and taxonomy tags need AI Automators to be configured on fields (AI 1.5.0 adds a setup-automators agent skill) or the contrib ai_seo or contentai modules. Scores 56, the partial-automation band. The previous round's 62 treated contrib SEO modules as bundled.

Cross-functional complexity67 → 68(+1)

Canvas gives marketers drag-and-drop page building with live preview and the Mercury component library, and the Drupal CMS 2.0 AI admin chatbot now handles structural site-building tasks — creating content types, defining taxonomy terms, adding fields, plus AI-assisted alt text — reducing developer dependency beyond just page assembly. Recipes and Site Templates further let admins add features without code. Bumped +1 as the chatbot moves structural changes (not only content) into non-developer reach; capped because custom components and third-party integrations still route through developers.

July 202638 score changes▼

Drupal CMS is on a clear improving trajectory this cycle, with gains concentrated in Build Simplicity (+2.6), Operational Ease (+1.7), and Cost Efficiency (+1.4) as Drupal CMS 2.0's desktop Launcher, improved onboarding, and core AVIF/responsive image delivery reduce setup friction and running costs. Capability and Platform Velocity ticked up modestly, led by a standout jump in AI observability (30 to 48) from native OpenTelemetry support in AI 1.3.0 and a genuine server-side A/B testing framework closing a long-standing experimentation gap. The one caution for evaluators is security: a run of 2026 core advisories including a highly critical SQL injection dropped the security track record item from 78 to 70, and Compliance & Trust remains flat at 42.1, the platform's weakest dimension.

Score Changes

AI observability & usage analytics30 → 48(+18)

AI 1.3.0 added native OpenTelemetry support exporting spans, traces, and metrics with real-time tracking of AI usage, costs, and agent decisions to Datadog, Grafana, or Sentry; this complements the AI Dashboard, AI Logging, and AI Explorer. AI 1.4.0 (June 2026) continued to route usage/cost telemetry through the observability module. Scores 48 because cost and usage tracking exist but dashboards live in external APM tools rather than in-platform, and per-user quotas, prompt effectiveness analytics, and quality trend monitoring are still missing.

A/B testing and experimentation35 → 46(+11)

The Server-side A/B Testing module provides a genuine Drupal-native experimentation framework: server-side variant execution to eliminate flicker, content-based experiments using existing Drupal entities as variants, SEO-safe canonical handling, and GA4/GTM integration (experiment data exposed via drupalSettings, analytics events triggered). A/B Paragraphs 1.0.0-beta3 (February 2026) enables paragraph-level content variant testing, and the stable Kameleoon module offers a third option. Statistical analysis and winner selection still live in GA4 or external tools — no native stat-sig reporting or auto-winner in core. Scores in the 'experimentation via tight integration' band rather than the no-capability floor.

Time-to-first-value55 → 65(+10)

Drupal CMS 2.0 materially improved onboarding: the free desktop Launcher spins up a working local site in minutes with no server setup, and site templates install a complete pre-configured professional site in under three minutes. Production deployment still requires provisioning hosting (one-click installers widely available), keeping it short of the sub-hour SaaS ceiling.

Security track record78 → 70(-8)

2026 brought four core advisories culminating in SA-CORE-2026-004 (CVE-2026-9082), a highly critical SQL injection in the database abstraction API on PostgreSQL sites rated 20/25 — the most severe core flaw in years and confirmed exploited in the wild days after the May 20 coordinated release. Handling was exemplary: an advance PSA gave operators notice, patches shipped across all supported branches, and exceptional hotfixes were issued for end-of-life 9.5/8.9 branches. The Drupal Security Team, HackerOne program, and transparent advisory database remain strengths, but an actively exploited highly critical core SQLi holds this at the threshold rather than higher.

Asset delivery & CDN optimization38 → 45(+7)

Drupal core (11.2+) now converts image styles to AVIF with WebP fallback, and Drupal CMS's Image recipe ships responsive image styles with focal-point-based cropping out of the box — a real improvement over the prior no-modern-formats posture. Transforms remain predefined server-side styles rather than on-the-fly URL-based transformation, and CDN delivery still requires external integration (Cloudflare, Fastly, CDN module).

AI governance, safety & audit trails58 → 65(+7)

The native Guardrails system (AI 1.3.0) was significantly hardened in AI 1.4.0 (June 2026): guardrails can now be configured globally to apply automatically across all incoming and outgoing requests, enforce on real-time streaming responses to block unsafe output mid-generation, and impose input-length limits to prevent denial-of-wallet cost attacks — all definable by compliance teams without code. This sits atop AI Logging, human-in-the-loop review gates, AI External Moderation, role-based tool/agent access, and configuration rollback. Scores 68 — strong audit trails plus enforceable global guardrails — but short of 75+ because IP indemnification and hallucination confidence scoring are still absent.

TypeScript support33 → 38(+5)

Drupal CMS is PHP-based, but TypeScript footing improved: Drupal Canvas's code component compiler now supports TypeScript syntax (via SWC parsing — no type checking), the Canvas CLI handles TSX components, and the contrib TypeScript Definition Generator and ts_for_core provide entity/core type definitions. Still no official auto-generated types from content models in core and no official TS SDK, keeping this in the community-tooling band.

Boilerplate and starter quality55 → 60(+5)

Drupal CMS 2.0 shipped its first official Site Template — Byte (built by Mediacurrent on the new Mercury theme), a near-feature-complete B2B SaaS marketing site with blog, newsletter, pricing and contact pages that goes from fresh install to production-ready in under three minutes — plus the Mercury component library (heroes, cards, testimonials, accordions). For headless, next-drupal and Acquia's Next.js starter kit exist but are community/vendor-adjacent rather than core-maintained, and the single first-party template lacks the breadth of headless-first platforms' starter catalogs.

Preview and editing integration58 → 63(+5)

Canvas is now the default editing experience in every new Drupal CMS 2.0 install, providing true drag-and-drop with live preview and real-time responsive desktop/mobile previews — no setup required for traditional deployments. Decoupled setups get inline preview built into the editing interface via next-drupal 2.1.0 (iframe preview with site switcher, revision/draft previews, content moderation), but these require frontend configuration. Not higher because headless preview is still multi-step and module-dependent.

Typical implementation timeline52 → 56(+4)

Drupal CMS 2.0's site templates and Canvas visual builder shift simple marketing sites toward 'days instead of weeks', a real improvement over classic Drupal. But real projects still run long: small custom sites 4–8 weeks, content-led marketing 6–14 weeks, mid-size builds 3–6 months, and enterprise 5–9 months — above the 2–4 week ideal for most work.

Cross-functional complexity63 → 67(+4)

Canvas gives marketers drag-and-drop page building with live preview and the Mercury component library, and the Drupal CMS 2.0 AI admin chatbot now handles structural site-building tasks — creating content types, defining taxonomy terms, adding fields, plus AI-assisted alt text — reducing developer dependency beyond just page assembly. Recipes and Site Templates further let admins add features without code. Bumped +1 as the chatbot moves structural changes (not only content) into non-developer reach; capped because custom components and third-party integrations still route through developers.

Vendor-forced migrations42 → 46(+4)

The feared distribution-layer migration risk did not materialize: Drupal CMS 2.0 required no action from existing 1.x sites, and because Drupal CMS ships on Drupal core 11.3, the December 9, 2026 Drupal 10 EOL does not affect it. Drupal 12 (targeted week of August 10, 2026) defers disruptive public-API deprecations to Drupal 13, so it should feel 'more like a minor update.' Below 50 because the two-year major cycle still imposes a recurring sequential-upgrade obligation and recipes lack an update path at each transition.

Mobile and frontline access38 → 42(+4)

Open Intranet 1.7.0 (2026) added a Messenger module with SMSAPI integration, allowing notifications to reach deskless/frontline workers without a Drupal account — a genuine frontline-access improvement — and the Gin admin theme layout is now optimized for mobile. However, there is still no native iOS/Android app, no native push notifications, and no offline or kiosk/shared-device support. Scores reflect the SMS reach to deskless workers but remain well below purpose-built frontline platforms.

Onboarding resources62 → 65(+3)

Drupal CMS has a dedicated getting-started hub (new.drupal.org/docs/drupal-cms) with a pre-configured DDEV path (.ddev/config.yaml bundled, drupal11 project type) that auto-opens a working site, plus Drupalize.me structured learning and the Byte template as a guided first build. Gaps remain: a Feb 2026 drupal.org forum thread documents missing instructions for installing CMS 2.0 without DDEV, and docs are still spread across new.drupal.org, project.pages.drupalcode.org, Drupalize.me, and community blogs rather than a single guided path.

Configuration complexity48 → 51(+3)

Drupal CMS ships pre-configured for DDEV (.ddev/config.yaml bundled), so local setup is effectively configure drupal11 project type, `ddev start`, and `composer create-project drupal/cms`. Production still requires Composer dependency management, database config, settings.php/settings.local.php environment handling, and Drush for many admin operations — a config surface far heavier than SaaS platforms — and non-DDEV setup remains poorly documented per community reports.

Upgrade difficulty55 → 58(+3)

The Drupal CMS 1.x → 2.0 transition (January 28, 2026) was a non-event for existing sites: official release notes confirm post-install Drupal CMS is a standard Drupal site updated like any other. Automatic Updates is stable for patch releases on Drupal 11, and Canvas 1.2 adds Automatic Component Instance Updates so prop/slot changes don't break in-use content. Not higher because recipes still have no update path and the major D11 → D12 upgrade (targeted week of August 10, 2026) remains Composer-driven.

Issue resolution velocity45 → 48(+3)

The team delivered Drupal CMS 2.0 on its published roadmap date (January 28, 2026), Canvas iterated quickly (1.0 in December 2025 to 1.2 by mid-2026), and the May 2026 highly critical advisory was handled within a pre-announced window — all signs of healthy velocity. Not higher because Drupal CMS-specific issue queues depend on a smaller maintainer team than core, and no SLA exists for non-security bugs.

Internal communications50 → 53(+3)

Open Intranet provides company news feeds, department-targeted announcements, and social interactions (comments, reactions). The 1.7.0 release (2026) added a Messenger module and SMSAPI integration, expanding multi-channel internal comms — notifications can now reach users including deskless workers without requiring a Drupal account. However, there is still no native read receipt, mandatory-read workflow, or formal acknowledgment tracking — these require custom development. Scores reflect the multi-channel notification capability offset by the lack of acknowledgment tracking.

MCP server availability35 → 38(+3)

The base Drupal MCP module is stable (updated May 2026) and the mcp_server module — back in active development — now implements the full MCP spec including Simple OAuth 2.1 with per-tool granular scopes (required/disabled modes), token auth, STDIO/HTTP transports, Tool API integration, and the official MCP PHP SDK, closing the prior OAuth gap. An mcp_client module connects Drupal to external MCP servers. Scores 42, in the announced/beta band, because mcp_server still has no stable release as of spring 2026 despite substantial, actively maintained functionality.

Webhooks and event system52 → 54(+2)

Drupal core has a robust internal event system via Symfony Event Dispatcher, but outbound webhooks remain contrib territory. The Webhooks module covers entity CRUD, user events, and system hooks (cron, cache_flush) with configurable HTTP dispatch, and the newer Entity Webhook module adds admin-UI-configured bidirectional webhooks (broadcast entity changes outward and ingest JSON payloads inward) with no custom code. Still no built-in retry logic, HMAC payload signing, or delivery logs without custom development — well behind commercial SaaS CMS webhook systems.

Audience segmentation40 → 38(-2)

Drupal CMS 2.1.x has no native audience segmentation engine. Acquia Personalization — the former flagship enterprise path — reached end-of-life Jan 31, 2026, with Acquia Convert now positioned as the successor (a paid, conversion-optimization-focused product rather than a Drupal-native segmentation UI). Contrib paths remain for rule-based conditions (Smart IP/Context), CDP-driven segments (External Personalization recipe), and geo/taxonomy targeting (Personalization module).

Visual page builder & layout editing70 → 72(+2)

Drupal Canvas is the default editing experience in Drupal CMS 2.x: drag-and-drop component assembly, in-place editing with live preview, multi-step undo, multi-page preview before publish, in-browser code components, and the Mercury component library. Canvas ships first-class in Drupal CMS 2.1.3 (June 2026) atop Drupal 11.3, and site templates (Byte, Haven) provide pre-assembled Canvas pages. Maturing rapidly but still younger than Sitecore Pages or AEM's editor.

Local development78 → 80(+2)

DDEV remains the officially recommended local environment with one-command, near-production-parity Docker setup (database, mail, Solr, Redis) and dedicated Drupal CMS install docs at new.drupal.org. Drush handles config, database, cache, and code generation, and Drupal 11.4 adds an experimental native CLI (./vendor/bin/dr) intended to grow into a Drush replacement. @drupal-canvas/workbench, a Storybook-inspired local dev server for Canvas code components, further strengthens the frontend-component workflow.

Documentation quality67 → 69(+2)

Drupal CMS documentation at new.drupal.org matured with the 2.0 release — focused getting-started guides (including DDEV install paths), Recipes documentation, and site-builder guidance — and Drupal Canvas now has a dedicated docs site covering code component concepts and guides. Underlying api.drupal.org reference remains auto-generated and thorough but not beginner-friendly, with no interactive API playground and uneven contrib module docs.

Release frequency78 → 80(+2)

Drupal CMS sustains a ~monthly stable cadence (2.0 Jan 2026, 2.0.1 Feb, 2.1.1 Apr 10, 2.1.2, 2.1.3 June 2, 2026) and core shipped 11.4.0 on July 1, 2026. Lowered from 80: the Drupal 12 major missed its August 2026 window and has now slipped to the December 7, 2026 fallback (beta1 week of Sept 14), so the 'on-track major' that justified the 80 band no longer holds. Monthly distribution releases plus a shipped 11.4 keep it firmly in the high-70s.

Concept complexity48 → 50(+2)

Drupal CMS 2.0 (2026-01-28) makes Canvas the default no-code page builder in a new user's first five minutes, and an AI admin chatbot can now create content types, taxonomy terms, and fields conversationally — both lowering the entry surface. However, custom development still requires the full entity/field/hook/Views/services stack (nodes, blocks, Views, entities), keeping concept density well above the <5-concept ideal; 2026 guides still call Drupal's the steepest learning curve of any major CMS. Held at 50 because the underlying concept model is unchanged for developers doing real work.

Framework familiarity48 → 50(+2)

Canvas is built on Single Directory Components that package Twig, JavaScript, and CSS into self-contained reusable units mirroring React, and Drupal 11.3 modernized DX (object-oriented hooks via PHP attributes, GitLab merge-request workflows) — familiar patterns for frontend developers. Headless paths are strong (JSON:API in core, next-drupal 2.1.0 with SSG/SSR/ISR + GraphQL), but custom backend work still requires learning Drupal's Symfony/PHP framework, which 2026 comparisons note takes a PHP dev 1–3 months to reach proficiency vs 1–2 weeks for WordPress. Held at 50 — SDC helps the frontend, the proprietary PHP backend still dominates.

Required specialization50 → 52(+2)

Canvas, Site Templates, and Single Directory Components mean site builders and frontend implementers need less bespoke Drupal theming knowledge — SDC's Twig/JS/CSS packaging is familiar to frontend devs. Custom module development still demands Drupal-specific PHP (entity API, services, OO hooks — still proprietary patterns) requiring 1–3 months of ramp-up, so generalist React/TypeScript developers cannot be productive on backend work without significant investment. No certification is required.

Team size requirements52 → 54(+2)

Drupal CMS 2.0's launch messaging claims marketing teams can 'launch fully branded, professional websites in days instead of weeks' using templates and Canvas, and Byte proves a solo builder can ship a production template-based site in minutes. Production implementations with custom functionality still typically need 2–3 roles (Drupal backend, frontend, DevOps/hosting), and enterprise builds more. The floor has dropped meaningfully; the ceiling for custom work has not.

Content operations burden38 → 40(+2)

Canvas 1.2's Automatic Component Instance Updates reduce content breakage when component props/slots change, and Drupal CMS 2.0 ships curated SEO tools and the Byte site template that lower editorial setup burden. However, automated content hygiene (orphan detection, broken reference alerts, content expiry) still requires contrib modules or manual editorial discipline. The governance model remains fundamentally manual.

Performance management50 → 52(+2)

Drupal core 11.3 delivers what drupal.org calls the biggest performance improvement in a decade — 26–33% more requests on the same infrastructure — giving operators more headroom before tuning is needed. The management model is otherwise unchanged: cache tag/context configuration, Varnish/CDN setup, and database tuning remain operator responsibilities on self-hosted installs, while Acquia/Pantheon/Upsun absorb much of it for hosted deployments. Not higher because active cache and scaling management is still required.

Community support quality70 → 72(+2)

Dedicated #drupal-cms-support and #drupal-cms-development Slack channels remain active with Drupal Association staff participation, and 2026 reviews describe support as 'abundant, with countless resources, forums, and knowledgeable users.' After ~18 months in market, the Drupal CMS-specific knowledge base has matured meaningfully beyond the launch period. Slightly below classic Drupal's 75 because CMS-specific (recipes, Canvas) answered-question coverage is still thinner than core Drupal's two-decade archive.

AI text generation & editing68 → 70(+2)

Drupal CMS 2.0 (GA January 2026) ships AI Automators (field-level rewriting, summarization, tone adjustment, chained pipelines), AI CKEditor integration, page generation from a single prompt via Drupal Canvas, and the Context Control Center for brand voice/audience/messaging. AI 1.3.0 added Field Widget Actions and native Guardrails, and AI 1.4.0 (June 18 2026) extended editorial reach with markdown editor extensibility. Stops at 70 because bulk generation and content-type-aware prompt template libraries remain less polished than dedicated SaaS leaders.

AI image & media generation50 → 52(+2)

AI-powered alt text generation ships GA in Drupal CMS 2.0 across image fields, AI 1.3.0 Field Widget Actions add one-click image generation from text and information extraction from images, and AI 1.4.0 (June 2026) adds Views Bulk Operations so alt-text generation can run across many entities at once. Image generation routes through the provider abstraction (DALL-E, Stable Diffusion) plus AI-assisted media categorization. Scores 54 because generation is provider-integrated rather than a native DAM product, and smart focal-point/crop and AI video processing are absent.

AI metadata & SEO automation58 → 60(+2)

The ai_seo module provides on-demand SEO analysis, contentai auto-generates SEO titles, keywords, and meta descriptions, AI Automators handle taxonomy auto-tagging, and AI 1.3.0 added metadata autofill as a Field Widget Action. AI 1.4.0 (June 2026) adds Views Bulk Operations so classification and tagging Automators run across many entities at once. Scores 62 because capabilities are still distributed across multiple contrib modules rather than a single integrated SEO workflow, and on-page scoring is on-demand rather than continuous.

AI-assisted content operations65 → 67(+2)

AI Automators provide field-level automation (auto-tagging, transcription, OCR, scraping, social post generation, chained pipelines) and autonomous content agents (GA in AI v1.2) detect outdated information and propose site-wide updates with human review gates. AI 1.4.0 (June 2026) adds native Views Bulk Operations support, letting site builders run configured AI rules — summarization, classification, tagging, translation, editorial automation — across many entities at once, closing the prior bulk-enrichment gap. Scores 70 because smart scheduling and duplicate detection remain less prominent, though automator breadth now well exceeds most open-source CMS.

Bring your own AI model/key (BYOM/BYOK)78 → 80(+2)

BYOK is the core design principle of the Drupal AI module, with 48+ providers switchable via admin UI without code (OpenAI, Anthropic, Gemini, Mistral, Hugging Face, Ollama, LM Studio, amazee.ai), including local/air-gapped deployment. AI 1.3.0 Guardrails add bidirectional filtering that prevents sensitive data leaking to external models, and AI 1.4.0 (June 2026) adds enterprise provider failover for resilience. Reaches 80 for full multi-provider BYOM with platform-level data controls; not higher because residency assurances still ultimately rest on the chosen provider.

API delivery model77 → 78(+1)

JSON:API in core since Drupal 8.7 is spec-compliant with filtering, sorting, pagination, sparse fieldsets, and relationship includes — one of the most capable core REST implementations in any CMS. GraphQL contrib reached 5.0.0 stable for Drupal 10.4/11 on June 7, 2026, with full GraphQL-spec support, PHP-attribute plugin definitions, node preview URL support, and cacheability fixes — a meaningful maturity step from beta. Both APIs support locale-aware queries. Strict JSON:API spec compliance is both a strength and a limitation for unconventional query patterns.

June 2026▼

Drupal CMS holds a stable position this review with no movement across any composite dimension. Platform Velocity remains the strongest signal at 73.5, anchored by the project's active release cadence, while Compliance & Trust continues to lag at 42.1 as the weakest area. Capability, Cost Efficiency, Build Simplicity, and Operational Ease all carry over unchanged, indicating the platform's profile has neither gained nor lost ground since the last assessment.

Trusted Implementation Experts

Reach out to these highly trusted implementation partners, agencies and specialists.

Implementation partners for Drupal CMS
Independent
We don't implement these platforms. Our trusted partner community does. Do you need help getting started?

Looking for a Drupal CMS partner?

Agencies, dev shops, and systems integrators vary wildly in how well they deliver on Drupal CMS. We don't take on implementation work ourselves.

Tell us what you're building and we'll come back with a shortlist of firms with a genuine track record on this platform.

How does Drupal CMS stack up against your shortlist?
Side-by-side scoring across all 10 categories and every criterion.
Compare head to head →