The DXP Scorecard — Independent Platform Evaluation
Independent Platform Evaluation
Scored on implementation experience
Not vendor briefings
← Dashboard

Umbraco

Traditional CMSTier 3
Visit Website ↗
Overall Capability
56/ 100
#29of 40overall#9of 13Traditional CMS

Umbraco is a mature, MIT-licensed .NET CMS that pairs exceptional cost transparency and zero vendor lock-in with a disciplined release machine — v18 GA shipped on schedule in June 2026 with Elements/Library, typed OpenAPI schemas, and a rapidly maturing first-party AI stack (Umbraco.AI, Copilot GA, official MCP servers).

Head-to-Head

Capability56 : 59
Cost Efficiency72 : 41
Build Simplicity67 : 53
Operational Ease61 : 43

Both are .NET-based mid-market platforms, but Umbraco's open-source model, faster and more predictable release cadence, and first-party AI/MCP stack give it stronger momentum and developer goodwill. Sitefinity offers more integrated marketing capabilities and enterprise support packages under Progress, while Umbraco's editorial UX and community are consistently rated higher.

Full Comparison →
Capability56 : 63
Cost Efficiency72 : 73
Build Simplicity67 : 54
Operational Ease61 : 50

Drupal's module ecosystem, granular access control, and free-in-core capabilities (workflows, faceted search) exceed Umbraco's, and its community dwarfs Umbraco's in scale. Umbraco wins decisively on editorial usability, onboarding simplicity for .NET teams, and a more disciplined vendor-led release cadence — a Drupal build typically demands more specialist depth than an equivalent Umbraco build.

Full Comparison →
Capability56 : 70
Cost Efficiency72 : 64
Build Simplicity67 : 64
Operational Ease61 : 61

Contentful offers polished official SDKs in many languages, GraphQL, CDN-native global delivery, and SOC 2 compliance — the headless fundamentals where Umbraco's REST-only Delivery API and absent official SDKs lag despite v18's typed OpenAPI schemas. Umbraco provides a full editorial backoffice, free self-hosting, and hybrid rendering that Contentful cannot match, at a fraction of the cost for content-heavy sites.

Full Comparison →
Capability56 : 48
Cost Efficiency72 : 76
Build Simplicity67 : 69
Operational Ease61 : 49

Both are open-source with self-host freedom, but Strapi's JavaScript/TypeScript stack draws from a far larger developer pool and its headless DX (REST + GraphQL, official SDKs) is more complete. Umbraco offers a substantially more mature editorial experience, stronger multilingual and multi-site support in core, a richer first-party commercial add-on ecosystem, and a far more advanced AI/MCP story.

Full Comparison →
Compare Umbraco against any of 40 platforms →

Use-Case Fit

Top Fit
Marketing
52#24 of 40
Commerce
39#22 of 40
Intranet
38#17 of 40
Multi-Brand
45#23 of 40
Ideal For
  • 85.NET development teams building mid-market marketing and corporate sites
  • 84Budget-conscious organizations that need zero licensing cost and no vendor lock-in
  • 80European multi-site, multilingual organizations with GDPR-first requirements
  • 74Teams adopting AI-assisted content workflows with model choice and governance requirements
  • 76Agencies standardizing on one platform across many client builds
Look Elsewhere If
  • 30US-regulated enterprises requiring SOC 2, HIPAA, or FedRAMP attestation
  • 28Marketing-led organizations expecting native personalization, testing, and analytics out of the box
  • 22Organizations building employee intranets or digital workplace portals
  • 20Teams with large concurrent editorial staffs needing real-time co-authoring

Strengths & Weaknesses

Strengths
  • +
    Best-in-class cost transparency and zero lock-in

    The MIT-licensed core has no usage metering, seat limits, or expiry, and Umbraco Cloud pricing (€45–€730/mo) is publicly listed with 2026 increases disclosed transparently. Content lives in standard SQL Server/SQLite with a documented schema and configurable media storage, so exit costs are limited to developer migration time. Monthly Cloud billing and a permanent self-host option mean no contractual lock-in at any level.

    85.6
  • +
    Disciplined release cadence with exemplary security response

    The twice-yearly major cadence held exactly on schedule (v18.0.0 GA June 25, 2026), with three maintained branches (18.x, 17.x LTS, 13.x LTS) all patched in parallel. The July 7, 2026 high-severity Delivery API flaw was patched same-day across all three supported majors, and the public roadmap is backed by shipped follow-through (Compose, Elements, AI stack). This is one of the most predictable release machines in the .NET CMS space.

    72.5
  • +
    Strong extensibility and modern, well-designed REST API

    The dual-layered extensibility model — IComposer/INotificationHandler server-side plus the TypeScript/Lit Bellissima backoffice extension framework — is a genuine app framework, not just API hooks. Umbraco 18's opt-in typed OpenAPI schemas (discriminated unions per content type) make the Delivery API self-documenting and enable strongly-typed client generation, with maximum hosting flexibility from self-hosted Docker to managed Umbraco Cloud.

    75.3
  • +
    First-class multi-site and localization in core

    Field-level language variants with per-property translation, fallback configuration, and culture-to-domain assignment ship free in core — no add-on required. Multiple content trees with hostname routing support many sites from one installation, and Umbraco 18's Elements/Library adds governed reusable content shareable across sites with reference tracking and permissions.

    72
  • +
    Rapidly maturing first-party AI stack with unmatched provider flexibility

    Umbraco.AI supports roughly ten official BYOK provider packages (OpenAI, Anthropic, Bedrock, Gemini, Mistral, and more) on a Microsoft.Extensions.AI abstraction — best-in-class model flexibility with central governance. The open-source Developer MCP Server exposes 315+ permission-aware Management API endpoints, and the conversational Copilot reached GA in July 2026 with field-level generation, block-aware editing, and a human approval gate.

    68.5
  • +
    Editor-friendly backoffice buildable by lean teams

    The Bellissima backoffice is consistently praised for editorial usability — G2 awarded Umbraco Best Usability in both Headless and DXP indices in Spring 2026, and overall sentiment sits at 4.5/5 across ~973 reviews. Editors need only 1–4 hours of training, solo .NET developers can ship complete sites, and typical production projects need just 1–3 people.

    73.3
Weaknesses
  • No real-time collaboration whatsoever

    As of Umbraco 18 (June 2026), simultaneous editors still overwrite each other in a last-writer-wins model with no presence indicators, conflict detection, or inline commenting. Roadmap-targeted collaboration features have repeatedly failed to ship, leaving teams with concurrent editorial workflows exposed to silent content loss.

    21
  • Marketing capabilities almost entirely gated behind paid add-ons

    Open-source core has no segmentation, personalization, A/B testing, recommendations, or analytics — all require the commercial Umbraco Engage license, and there is no recommendation engine even with it. Organizations evaluating the free core against marketing-suite competitors will find the out-of-box marketing surface nearly empty.

    19
  • Weak intranet and employee-experience tooling

    No people directory, org chart, LMS integration, onboarding journeys, workplace tool integration (Teams/Slack), or intranet adoption analytics exist in core or official add-ons. The third-party Uintra framework covers basics like activity feeds, but building a competitive employee experience requires extensive ground-up custom development.

    25.2
  • No portfolio-level governance for multi-brand estates

    Cross-brand analytics, executive portfolio reporting, corporate-to-brand content syndication with override control, and regional compliance guardrails are all absent from core, Engage, and the marketplace. Multi-brand operators get solid logical tenant isolation and shared Elements, but managing a brand portfolio at scale requires external BI tooling and custom development.

    28
  • Compliance certification gaps: no SOC 2, no HIPAA

    Umbraco explicitly states it has no active focus on SOC 2, relying instead on Azure's certifications — which cannot be inherited by the platform. No HIPAA BAA is offered and no FedRAMP, PCI-DSS, or IRAP attestations exist, leaving the January 2026 ISO 27001 certification as the sole platform-scope credential. This blocks procurement in US-regulated industries.

    38.3
  • Thin media, DAM, and visual commerce capabilities

    There is no native video hosting or transcoding (YouTube/Vimeo embeds required), no asset rights management or usage tracking, and no 360°/AR/3D product media tooling. The media library covers focal-point cropping and ImageSharp transforms well, but anything beyond basic image workflows requires external DAM or visual commerce services.

    32

Deep Dive

Full Analyst Assessment

Umbraco is a mature, MIT-licensed .NET CMS that pairs exceptional cost transparency and zero vendor lock-in with a disciplined release machine — v18 GA shipped on schedule in June 2026 with Elements/Library, typed OpenAPI schemas, and a rapidly maturing first-party AI stack (Umbraco.AI, Copilot GA, official MCP servers). Its core content management, extensibility, and multilingual multi-site capabilities are solid, but nearly all marketing capabilities (personalization, A/B testing, analytics, workflow) are gated behind paid add-ons, real-time collaboration is absent, and it lacks SOC 2 certification. It fits .NET-centric mid-market teams and multi-site European organizations far better than marketing-led enterprises or intranet/portfolio-governance use cases.

1Core Content Management65
Content Modeling
1.1.1
Content type flexibility
78H

Umbraco's Document Type system offers 30+ built-in property editors with Content Composition for reusable property groups, plus Document Type inheritance and Element Types. Umbraco 18 (June 2026) added Elements in a new Library section — reusable content that lives outside the document tree (site settings, footers, promo blocks). Limitations remain: no native union/polymorphic field types and no schema-as-code; complex nested schemas still rely on Block Editor or Element Types rather than being first-class.

1.1.2
Content relationships
65M

Content Picker, Multi-Node Tree Picker, and Media Picker provide cross-document relationships. These remain unidirectional — Umbraco does not natively track back-references. For bidirectional lookups, developers must build custom code or query indexes. No changes to the relationship model in v18.0.x.

1.1.3
Structured content support
73H

Block List and Block Grid provide component-based composition with nested blocks and Element Types for reusable schemas; Block Grid adds column/row/area layout control. Umbraco 18's Elements extend this with reusable content pieces referenced across a site, though mixing Elements alongside standalone blocks in the Block Editor and converting blocks into library elements is deferred to v19 (later 2026). RTE (TipTap) still outputs HTML rather than portable AST — not as deep as Sanity's Portable Text but strong for a traditional CMS.

1.1.4
Content validation
70M

Property-level validation is built into every property editor — required fields, regex patterns, min/max for numeric types, character limits. Custom validators via C# validation attributes and INotificationHandler for cross-field validation. Umbraco Workflow now adds validation-before-submit, but core validation for complex business logic still requires backend development.

1.1.5
Content versioning
77H

Full revision history per document with rollback, draft/published dual state, and scheduled publishing. The commercial Umbraco Workflow add-on adds Alternate Versions (concurrent parallel versions without blocking the published one) and Release Sets (schedule grouped version batches to drive campaigns); in the 2026 release these are gated by license state. Core versioning is strong; branching-style capability still requires the paid add-on.

Authoring Experience
1.2.1
Visual/WYSIWYG editing
65H

The Bellissima backoffice is mature through Umbraco 17 LTS and 18 with WCAG accessibility work, and Block Grid provides drag-and-drop content composition, but there is still no true in-context page editing — editing happens in the backoffice panel, not on the live page. Third-party visual builders (ByteEditor, uSkinned) exist but are not core platform features.

1.2.2
Rich text capabilities
70H

TipTap replaced TinyMCE as the default RTE in Umbraco 16 due to TinyMCE's license change. TipTap is a more modern editor with improved table editing (add/remove columns, resize, merge/split cells), better extensibility, and MIT licensing; internal link management and media embeds remain well-integrated. No major RTE change in v18. Output is still HTML rather than portable AST, limiting structured content portability.

1.2.3
Media management
72H

The Media section provides a structured media library with type-based organization, built-in focal point and Image Cropper, and a Media Delivery API for headless access with metadata (dimensions, focal point, crops). Umbraco 18 adds Media Recycle Bin Protection (default on). Still no built-in DAM with rights management, AI tagging, or metadata workflows; external DAM via community packages.

1.2.4
Real-time collaboration
20M

Umbraco still has no real-time co-editing capability as of Umbraco 18 (June 2026). Presence indicators and conflict resolution repeatedly targeted on the roadmap have not shipped in the 18.0.x line. Editing the same content item simultaneously results in last-writer-wins overwrite with no conflict detection or prevention.

1.2.5
Content workflows
62M

Umbraco Workflow (commercial add-on) provides configurable approval workflows, Alternate Versions for parallel document versions, and Release Sets for grouping and scheduling multiple content changes as campaign batches with task tracking. The 2026 release added auto-save and validation before submit and cleaner license gating. These require the paid add-on and feature flags; core Umbraco remains draft/published only.

Content Delivery
1.3.1
API delivery model
73H

The Delivery API (REST) offers filtering, sorting, expansion, preview mode, and a dedicated Media Delivery API. Umbraco 18 adds opt-in typed OpenAPI schemas per Document/Element/Media Type (discriminated unions keyed on contentType) and replaces Swashbuckle with native Microsoft.AspNetCore.OpenApi (OpenAPI 3.1), improving generated-client typing — though API responses themselves are unchanged. Core CMS remains REST-only; GraphQL lives only in Heartcore/Compose, not core.

1.3.2
CDN and edge delivery
50M

No built-in CDN in Umbraco CMS itself. Umbraco 18 adds configurable output caching, improving delivery performance server-side. Umbraco Cloud leverages Azure CDN for static assets and Umbraco Compose includes a Global CDN, but both are separate products. Self-hosted deployments require external CDN configuration; no cache-tag-based granular invalidation or edge computing in the core CMS.

1.3.3
Webhooks and event system
63M

Native webhook system (since v13) with configurable outbound webhooks on content events (published, unpublished, deleted, saved); Umbraco 18 extends webhook support to Elements and changes the default payload type to minimal (configurable). The internal .NET INotificationHandler system remains comprehensive for server-side integrations, and Umbraco Forms supports submission webhooks. Delivery reliability (retries, failure logging) is still basic, and there is no HMAC payload signing in core.

1.3.4
Multi-channel output
66M

The Delivery API plus Media Delivery API enable fully headless delivery for any frontend, and Umbraco 18's typed OpenAPI schemas let teams generate strongly-typed clients (TypeScript, Swift, C# DTOs) shaped to their content model. ASP.NET Core supports coupled/hybrid rendering and Elements add reusable cross-channel content. However, official frontend SDKs remain limited and RTE output is still HTML (not format-agnostic), so the headless DX is less polished than purpose-built headless CMSs.

2Platform Capabilities46
Personalization & Experimentation
2.1.1
Audience segmentation
25M

No native audience segmentation in open-source core. Umbraco Engage (first-party commercial add-on) provides rule-based segmentation with Deploy support, Forms/Commerce integration, and a headless Engage API; Q1 2026 added explicit scoring so defined actions can directly move visitors into a persona/journey stage alongside implicit behavioral scoring. Still a paid license — not in MIT core.

2.1.2
Content personalization
25M

No native personalization in open-source Umbraco. Umbraco Engage personalizes content on specific pages, across multiple pages, or by Document Type using segments/personas, with a visual workflow builder, Deploy support, and a headless API; Q1 2026 explicit scoring sharpens persona classification. Remains a paid commercial add-on, not core functionality.

2.1.3
A/B and multivariate testing
18M

No built-in A/B testing in core. Umbraco Engage includes A/B testing of headlines, layouts, CTAs, and full variants with real-time result monitoring and Deploy support for test-config portability, integrated with Commerce and Forms surfaces. Requires commercial Engage license — external tool needed without it.

2.1.4
Recommendation engine
10I

No native recommendation engine in core or established first-party add-on. Basic related content via IPublishedContentQuery by tags or document type is manual curation only. Engage does behavioral/journey scoring but not content recommendation; no ML-powered or collaborative-filtering recommendations without external service integration.

Search & Discovery
2.2.1
Built-in search
62H

Examine (Lucene.NET-based) is Umbraco's built-in search, providing full-text indexing, fuzzy matching, field boosting, and custom indexers. RFC 0027's new search abstraction with built-in filtering and faceted search remains roadmap — expected as a separate package after Umbraco 17, and not shipped in Umbraco 18 (GA June 2026). Current Examine provides adequate search for small-to-medium sites without advanced relevance tuning or ML ranking.

2.2.2
Search extensibility
70M

Examine's abstraction layer supports alternative backends via Examine.ElasticSearch and ExamineX (Azure AI Search, Elasticsearch). The planned RFC 0027 search abstraction, shipping as a separate package in 2026, will let developers bring their own search engine far more cleanly. Current extensibility is solid through C# interfaces but requires developer implementation for non-Examine backends.

Commerce Integration
2.3.1
Native commerce
47M

Umbraco Commerce (first-party paid add-on) provides product catalog, cart, checkout, order management, pluggable payment (Stripe, PayPal) and shipping providers, multi-currency and multi-store/multi-market support, discounting, and a Drop-in Cart feature for simplified storefront setup. Smaller extension ecosystem than purpose-built commerce platforms; requires paid license.

2.3.2
Commerce platform integration
55M

A first-party Shopify integration (Umbraco.Cms.Integrations.Commerce.Shopify, v5.0.0) provides a backoffice product picker and strongly-typed value converter that pull real-time product data — SKUs, variants, availability, pricing — from the Shopify Admin API directly into content, giving genuine API federation with live product data for Shopify. No pre-built commercetools, BigCommerce, or Salesforce Commerce connectors; those require custom API integration.

2.3.3
Product content management
48M

With Umbraco Commerce, product content is managed via Document Types with variant support for attributes, pricing, and stock. Commerce nodes integrate with the standard content tree and benefit from Umbraco's flexible content modeling. Bulk product management and PIM-level features remain limited. Requires Commerce add-on license.

Analytics & Intelligence
2.4.1
Built-in analytics
17M

No built-in analytics in open-source core. Umbraco Engage provides content performance analytics with visitor profiling and behavioral tracking (with a Q1 2026 bot-detection enhancement improving data quality) integrated across Forms and Commerce surfaces. Umbraco Commerce includes an order/revenue analytics dashboard. Both require commercial licenses — analytics depth is limited without them.

2.4.2
Analytics integration
55M

GA4, GTM, and Matomo integration via template-based script injection. Community packages exist for common analytics platforms. No middleware-level analytics hooks or event streaming built in. Sufficient for most sites but not deeply integrated compared to platforms with native analytics event APIs.

Multi-Site & Localization
2.5.1
Multi-site management
73H

First-class multi-site support within a single installation: multiple content trees with domain-based routing, independent navigation, and per-site templates. Culture and hostname assignments allow multiple sites from one CMS instance with a shared media library, and Umbraco 18's Elements add first-class reusable content pieces (with reference tracking and permissions) shareable across sites. Well-established and stable.

2.5.2
Localization framework
78H

Strong multilingual support built into core: field-level language variants with per-property translation, configurable mandatory and fallback behavior, culture-to-domain assignment, and locale-specific publishing. Umbraco 17 added consistent UTC date handling with timezone support, improving i18n accuracy. Variant UI is intuitive and well-integrated.

2.5.3
Translation integration
50M

Umbraco.Community.TranslationManager package provides TMS integration for workflow-based translation. Community connectors for Smartling and Memsource exist at varying maturity. No official first-party TMS marketplace integrations; translation workflow relies on community packages rather than supported first-party connectors.

2.5.4
Multi-brand governance
57M

Multiple sites within one installation represent multiple brands with separate templates, stylesheets, and content trees. Umbraco 18 Elements provide a first-class shared reusable-content library (reference tracking, workflow, permissions, audit logs) that strengthens cross-brand component sharing, and section/content-tree permissions isolate per-brand editorial teams. Still no native 'brand' tenant concept — brand separation is built from site structure and permission layers.

Digital Asset Management
2.6.1
Native DAM capabilities
38M

Umbraco's media library provides folder-based organization, auto-populated image metadata (width, height, file path), and an Image Cropper property editor with focal point support. No asset versioning, usage tracking across content, rights/expiry management, or metadata schema customization. Falls into the basic file storage + some organization tier; external DAM (QBank, IntelligenceBank) required for advanced DAM needs.

2.6.2
Asset delivery & CDN optimization
45M

Umbraco bundles ImageSharp.Web for on-the-fly cropping and resizing (GetCropUrl) with focal point preservation and WebP/AVIF output. Only a 'pull'-style CDN is supported — requests route through the site so ImageSharp can process and the CDN caches the result; there is no built-in global CDN. External Cloudinary or Imgix required for advanced transformation pipelines or global edge delivery.

2.6.3
Video & rich media management
18M

No native video hosting, transcoding, or adaptive streaming. Video files can be uploaded to the media library but only as raw files — no thumbnail generation, caption management, or streaming delivery. YouTube/Vimeo/Mux embedding required for video playback. Scores in the 'requires external embedding' tier.

Authoring & Editorial Experience
2.7.1
Visual page builder & layout editing
42M

Block Grid Editor (Umbraco 11+) provides grid-based block composition with a structured editor panel and backoffice preview, but is code-first — developers must configure all block types. Block List Editor is simpler and less visual. No drag-and-drop WYSIWYG out of the box; ByteEditor 4.0 (third-party commercial) adds a true visual layer. No built-in visual editor for headless frontends.

2.7.2
Editorial workflow & approvals
57M

Umbraco Workflow (first-party paid add-on, v18) provides multi-stage approval workflows with configurable approval groups, thresholds, a granular permissions model, audit trail, and per-document-type configuration, plus Teams/Slack/Jira integration. The v18 release extends approvals to Umbraco 18 Elements (with folder-inheritance) and adds an extensible pre/post-approval action system per Document Type. Requires paid license and still lacks the deep custom-state flexibility of enterprise DXP workflow engines.

2.7.3
Publishing calendar & scheduling
52H

Scheduled publish and scheduled unpublish (embargo/expiry) are built into Umbraco core for all document types with timezone support, and Umbraco Workflow adds release planning on top. No native visual calendar view for all scheduled items across the site (community Scheduled Content Dashboard package exists), and no release bundles for atomic multi-item publishing.

2.7.4
Real-time collaboration
22M

No native real-time collaborative editing or presence indicators. Umbraco uses last-publish-wins versioning — simultaneous editors overwrite each other, with prior versions in history for rollback. A V10-era community package provides informational notifications only. Umbraco Workflow enforces sequential control via approval state but is not real-time collaboration.

Marketing & Engagement
2.8.1
Forms & data capture
60M

Umbraco Forms (first-party paid add-on) provides a drag-and-drop form builder with conditional logic on fields, submission storage, GDPR compliance, custom workflows, spam protection (reCAPTCHA), and webhook/integration hooks on submission. No progressive profiling or multi-step form wizard patterns documented. Forms integrates with Umbraco Engage for behavioral tracking.

2.8.2
Email marketing & ESP integration
35M

No native email sending capability. Marketplace includes pre-built Mailchimp and HubSpot connectors, plus ActiveCampaign community packages, and Forms submissions can trigger webhooks (or Zapier/Make/n8n) to ESP platforms. The upcoming Umbraco Automate can orchestrate triggered email flows, but GA is July 9, 2026 (beta today). Integration depth is connector/webhook-based rather than subscriber list sync with content push or triggered campaign sends from CMS events.

2.8.3
Marketing automation
43M

Umbraco Engage (commercial) already provides behavioral triggers, a visual automation workflow builder, first-party visitor profiling, and segmentation. Umbraco Automate — a native, open-source, drag-and-drop journey-orchestration engine for 'if this, then that' flows (onboarding emails, sales alerts, discount codes) with C# triggers, webhooks, and AI connectors — is in beta with GA July 9, 2026, moving Umbraco toward genuine built-in automation. Still short of full drip/lead-scoring campaign management, and Automate is not yet GA.

2.8.4
CDP & customer data integration
20L

No native CDP. Umbraco Engage provides first-party behavioral profiling stored on the customer's own server (GDPR-aligned), but is not a true customer data platform — no unified customer profiles across channels, no identity resolution, no Segment or mParticle integration. External CDP requires custom integration (webhooks/Automate can connect but not resolve identities).

Integration & Extensibility
2.9.1
App marketplace & ecosystem
62M

Umbraco has a long-established package ecosystem (20+ years) across marketplace.umbraco.com and our.umbraco.com/packages, spanning CRM, analytics, DAM, search, commerce, marketing, and AI categories. Active HQ investment with first-party add-ons (Commerce, Workflow, Forms, Engage, and the new open-source Automate). Smaller than WordPress but healthier governance than many traditional CMS ecosystems.

2.9.2
Webhooks & event streaming
55M

Native webhooks in core covering content published, unpublished, deleted, and media events, configurable per content type, with extensible custom events via WebhookEventBase<TNotification>. Umbraco Commerce adds its own webhook events, and Umbraco Automate adds webhook triggers/connectors for external systems. No explicit documentation of signed payloads, retry logic, or webhook filtering. Solid coverage of key events with extensibility, but no true event streaming (Kafka/EventBridge).

2.9.3
Headless preview & staging environments
55M

Content Delivery API supports draft preview mode, and Umbraco 18 (GA June 2026) refined the backoffice UI for configuring multiple preview environments (available since v12.3) plus opt-in typed OpenAPI schemas per content type. Branch-based preview deployments supported via CI/CD. No shareable preview links with temporary access tokens. Solid draft preview for headless frontends but limited branch-environment automation.

2.9.4
Role-based permissions & governance
58M

Umbraco has custom user roles with section-level and content-tree ACL. SAML and OIDC SSO are supported with role mapping from identity providers and auto-linking. No native SCIM support (SSOJet third-party required). No documented field-level permissions. Good role model with SSO but missing SCIM and field-level granularity compared to enterprise DXPs.

3Technical Architecture65
API & Integration
3.1.1
API design quality
75H

The Delivery API follows REST conventions cleanly with predictable endpoints, consistent JSON, content expansion, filtering/sorting/pagination, and batch read endpoints (17.3+). Umbraco 18 (GA Jun 2026) adds opt-in typed OpenAPI schemas for each Document/Element/Media Type, expressed as discriminated unions keyed on contentType — a meaningful upgrade from the previously loosely-typed spec — and moves to the built-in Microsoft.AspNetCore.OpenApi (endpoint now /umbraco/openapi/). No GraphQL keeps it below schema-driven headless CMSs, but it is now a very well-designed, self-documenting REST API.

3.1.2
API performance
57M

No published SLAs for self-hosted deployments; performance depends on hosting, output caching, and CDN setup. Umbraco Cloud (Azure + Cloudflare) provides a better baseline. Umbraco 18 adds configurable output caching plus further performance work atop 17.x hybrid/key-based caching, and batch reads (17.3+) mitigate N+1 patterns. Rate limiting remains self-managed, and there is no CDN-native delivery edge tier comparable to headless SaaS competitors.

3.1.3
SDK ecosystem
45M

No official multi-language SDKs for external consumption. The .NET backend has a rich internal API via IPublishedContent and services, but there are no official JavaScript, Python, or Go client SDKs. Umbraco 18's typed OpenAPI schemas improve client codegen but do not constitute shipped SDKs. Community-maintained TypeScript clients and Next.js starters exist but are not official. This remains a meaningful gap versus headless CMSs with polished official SDKs in 6+ languages.

3.1.4
Integration marketplace
62M

marketplace.umbraco.com hosts curated packages covering common integration needs: SEO, Forms, analytics, media providers, search, CRM integrations, and content delivery helpers. The marketplace is significantly smaller than Drupal's module ecosystem but has solid coverage for mid-market use cases. NuGet packages extend this further. Quality varies across packages and some are single-maintainer projects. The curated marketplace has improved discoverability over the legacy our.umbraco.com packages site.

3.1.5
Extensibility model
78H

Umbraco's extensibility is strong and dual-layered. Server-side: IComposer, IComponent, INotificationHandler patterns, custom health checks, background jobs via ASP.NET Core DI. Client-side: the Bellissima backoffice (v14+, matured through v18) uses Lit/Web Components/TypeScript with a declarative manifest system (umbraco-package.json) for custom property editors, dashboards, sections, and entity actions. Entity actions on collection cards (17.3+) extend the model further. This is a genuine App Framework, not just API extensibility.

Security & Compliance
3.2.1
Authentication
70M

Umbraco supports OAuth2/OIDC for backoffice SSO via ASP.NET Core Identity (compatible with Entra ID, Okta, Auth0, Google Workspace), and MFA for backoffice users. Member authentication uses ASP.NET Core Identity; API auth uses keys for the Delivery API. Umbraco 18 adds a lightweight external-only members option (minimal identity record when authenticating members via Entra ID, Auth0, Google, or any external IdP), improving federated member scenarios. Configuration still leans on .NET code rather than UI-based setup, a barrier for non-technical administrators.

3.2.2
Authorization model
65M

The backoffice permission system covers user group access to content sections, document types, and media. Document-level permissions for user groups on specific content nodes are supported. Member groups provide frontend access control. 17.2 added user group descriptions and tree navigation visual indicators for restricted access, improving permission visibility. The system is functional but lacks field-level permissions and programmatic per-document access hooks equivalent to Drupal's node access grants.

3.2.3
Compliance certifications
61H

Umbraco achieved ISO 27001:2022 certification (Jan 27, 2026) covering both the product organization and Umbraco Cloud, following an independent audit of people, processes, and technology. GDPR posture is strong as a Danish (EU) company, with active NIS2 Directive and EU Cyber Resilience Act compliance work. However, Umbraco explicitly does not pursue its own SOC 2, relying on Azure's SOC certification instead, and no HIPAA BAA is documented. ISO 27001 + GDPR without SOC 2 places it above GDPR-only platforms but below full SOC 2 + ISO 27001 leaders.

3.2.4
Security track record
71H

Umbraco maintains a responsible disclosure program with CVE-tracked patches delivered via NuGet. The March 2026 security releases (17.2.2, 16.5.1) addressed privilege escalation in user groups, XSS in property descriptions, and authorization bypass on domain access — patched promptly across supported LTS branches. Continued regular servicing through Q2/Q3 2026 (18.0.x, 17.5.x, 13.15.x) shows no major advisories in the feed. No incidents of Drupalgeddon severity. Rapid cross-version patching demonstrates mature response processes.

Infrastructure & Reliability
3.3.1
Hosting model
75H

Maximum flexibility: self-host on any server running .NET 10+ (Linux, Windows, Docker, Azure App Service, AWS, GCP, on-premise), or use Umbraco Cloud (managed SaaS on Azure with Cloudflare). Modular running of backoffice, website, and delivery API independently (17.3+) supports microservice-style deployments, and Umbraco 18 continues the modular-deployment direction. Umbraco Cloud provides dev/staging/production environments with CI/CD integration and official Docker images.

3.3.2
SLA and uptime
55M

Umbraco Cloud offers 99.9% uptime SLA on paid plans with a public status page at status.umbraco.io. Incidents remain fairly frequent — degraded provisioning performance (Apr 29, 2026) and further acknowledged outages through June 2026 — and self-hosted deployments have no inherent SLA. The Cloud SLA is reasonable for mid-market but below the 99.95% of enterprise-grade platforms.

3.3.3
Scalability architecture
65M

Umbraco scales horizontally via standard ASP.NET Core load balancing. NuCache handles read-heavy content delivery efficiently, and Redis is supported for distributed caching in multi-server setups. 17.x/18 performance improvements include hybrid cache optimizations, key-based caching, N+1 elimination in the Management API, and redirect tracking optimization for large sites. Standard .NET web scaling — proven for medium-scale workloads but not tested at the extreme scale of CDN-native CMSs.

3.3.4
Disaster recovery
68M

Content stored in SQL Server or SQLite with portable schema. Media in configurable file systems (local, Azure Blob, S3). Umbraco Cloud provides automatic data backups with point-in-time restore on Azure. Umbraco Deploy (commercial) handles content/schema migration between environments. The data format is open with no proprietary binary formats. RTO/RPO depend on hosting and backup strategy for self-hosted; Cloud users benefit from Azure's DR capabilities.

Developer Experience
3.4.1
Local development
68H

The dotnet new umbraco template creates a ready-to-run local project, and SQLite as a local database option removes the SQL Server requirement. Visual Studio 2022, VS Code with IISExpress, and the .NET CLI are all supported. Umbraco 18 requires .NET 10 and Node.js for the full development stack. The local experience is clean for .NET developers but requires the .NET toolchain — no cloud-based sandbox or playground available.

3.4.2
CI/CD integration
70M

Umbraco Deploy (commercial, included in Umbraco Cloud) provides environment-to-environment deployment of schema and optionally content. Git-based deployment via Umbraco Cloud with dev/staging/production environments. Self-hosted CI/CD uses standard .NET build pipelines (GitHub Actions, Azure DevOps, GitLab CI). Unattended background upgrades with health probes (17.3+) improve automated deployment scenarios, continued through 18. No branch-per-PR content environments like Platform.sh.

3.4.3
Documentation quality
68H

docs.umbraco.com is well-organized, consistently maintained by Umbraco HQ, and covers getting started, content management, development, extending, cloud, and troubleshooting. Versioned docs now cover through Umbraco 18, including the custom-generated-client guide for the Delivery API. The property editor tutorial demonstrates the Lit/TypeScript extension API clearly. Some areas (advanced deployment, headless patterns) are less comprehensive, and there is no interactive playground.

3.4.4
TypeScript support
55H

Umbraco 18 (GA Jun 2026) closes the biggest gap: opt-in typed OpenAPI schemas for each Document/Element/Media Type, so generated TypeScript types can be shaped to the actual content model (discriminated union on contentType) rather than a loosely-typed property bag. This is first-party, content-model-aware type generation, plus the backoffice extension system is TypeScript/Lit-native. It stops short of 80+ because it is opt-in config requiring an external client generator, and the OpenAPI 3.1 oneOf/discriminator patterns aren't uniformly supported by generators — not the seamless dedicated codegen of Sanity or Contentful.

4Platform Velocity & Health68
Release Cadence
4.1.1
Release frequency
76H

The twice-yearly major cadence held exactly on schedule: v18.0.0 GA shipped Jun 25, 2026 (after beta/rc1-3), followed immediately by 18.0.1 (Jul 1) and 18.0.2 (Jul 7). In parallel, 17.5.0-17.5.3 and 13.15.0/13.15.1 all shipped across late Jun-early Jul 2026, showing rapid patching across three maintained branches. This is one of the more disciplined release machines in the .NET CMS space.

4.1.2
Changelog quality
70M

GitHub release notes are detailed per version and the docs site (docs.umbraco.com) provides comprehensive version-specific upgrade guides with breaking changes clearly called out. releases.umbraco.com offers structured release history across all maintained branches, and v18 release notes even quantify contributions (176 fixes, 4 community-contributed). Quality is above average for open-source CMS projects but lacks the polished side-by-side migration diffs of best-in-class platforms.

4.1.3
Roadmap transparency
73H

Umbraco maintains a public roadmap at umbraco.com/products/knowledge-center/roadmap/ with a roadmap-history page and quarterly product updates that continue on cadence (Q1 2026 update published). Communication is backed by shipped direction — the Winter Keynote 2026 AI/Compose strategy translated into the Feb 2026 Compose launch and Elements landing in v18 — plus Codegarden 2026 and a community roadmap portal. More structured and better-followed-through than most mid-market open-source CMSes.

4.1.4
Breaking change handling
65H

Post the disruptive v14 Bellissima rewrite, the v15->16->17->18 upgrades have followed a predictable, incremental playbook with multi-week public beta/rc windows (v18 ran beta then rc1-3 before Jun 25 GA). Semver is followed with breaking changes confined to the two major versions per year, version-specific upgrade guides are thorough, and older branches (17.x, 13.x LTS) still receive patches, giving real choice on upgrade timing. Not best-in-class on automated codemods/migration tooling.

Ecosystem & Community
4.2.1
Community size
65H

GitHub: ~5.1K stars, ~2.9K forks, 470+ contributors on the main CMS repo. Community moved from Slack to Discord and forums migrated to Discourse (community.umbraco.com) in Feb 2025, and CodeGarden remains the flagship conference. Smaller than WordPress/Drupal but substantial for the .NET CMS space, with a predominantly European base and growing global presence.

4.2.2
Community engagement
68M

The Umbraco community remains genuinely engaged with its 'friendly unicorn' culture: Discourse handles searchable technical Q&A while Discord covers social/events, and the core team participates directly in GitHub and community channels. The active MVP program and 60+ Contributing Partners sustain code and content contributions. A tempering signal: only 4 of 176 v18 fixes came from the community (3 contributors), so engagement skews toward forum activity over core-code PRs.

4.2.3
Partner ecosystem
65H

Umbraco runs a formal Silver/Gold/Platinum partner program plus a Contributing Partner track, with the network expanding notably in 2025 (93 new partners, 64 Contributing Partners recognized) and increased Marketplace activity into 2026. Strong UK/EU agency ecosystem with growing North American coverage, Partner Summit events, and a structured certification program. Lacks the top-tier global SIs (Accenture/Deloitte) that anchor tier-1 DXP ecosystems.

4.2.4
Third-party content
60M

Growing content ecosystem: UmbracoTV YouTube, the searchable Discourse forum, and steady agency coverage of v18, Compose, and Codegarden 2026 (Mentor Digital, Pixelbuilders, Bluegrass, Vajra Global, etc.), plus the umb.fyi newsletter. Pluralsight/Udemy courses exist but are limited. Content volume is substantially smaller than Drupal/WordPress but steadily improving with the new community platform structure.

Market Signals
4.3.1
Talent availability
57M

LinkedIn shows Umbraco developer jobs across US and EU, with freelance platforms (Toptal, Upwork, Arc) listing Umbraco talent. The pool remains concentrated in Europe (UK, Netherlands, Nordics) with limited senior-level supply. The broad .NET developer base provides an on-ramp and the certification program is well-defined, but talent is still niche compared to WordPress/Drupal ecosystems.

4.3.2
Customer momentum
67M

Momentum is broadening beyond core CMS: the Umbraco Compose platform launched Feb 2026, Agent Skills and Umbraco MCP shipped, and the company reported rising Marketplace activity plus raised Compose ingestion limits (Pro 100K/mo, Enterprise 1M/mo) driven by AI hackathons worldwide. Cloud adoption grew ~50% in 2025 with G2 Momentum Leader recognition and case studies (Renault, Thames Water, Dansani). Still mid-market-centric rather than landing marquee enterprise logos quarterly.

4.3.3
Funding and stability
70M

Umbraco HQ remains independently owned with Monterro as investor since 2021 ($8.85M round, $9.13M total). Continued strategic investment shows in the 2024 uMarketingSolutions acquisition (Umbraco Engage) and the 2026 Compose/AI product buildout. Revenue is diversified across Cloud, Forms, Deploy, Engage, Commerce, and Compose, the company has been profitable, and there are no acquisition or layoff signals. Founded 2004, MIT-licensed core.

4.3.4
Competitive positioning
66H

Umbraco holds G2 Leader positions across CMS, Headless, DXP, and WebOps, taking Best Usability in both the Headless and DXP Usability Indices in Spring 2026 (79 badges), with strong regional CMS leadership. The Compose orchestration layer plus agentic-AI tooling (MCP, Agent Skills) sharpen its differentiation as the open-source .NET CMS moving up into integration/DXP territory. Still absent from a formal Gartner MQ for DXP, which caps the ceiling.

4.3.5
Customer sentiment
78H

G2 rating of 4.5/5 with ~973 reviews (2026), approaching the 1,000 milestone — well into the 75-85 band per the rubric's '4.5+ with 200+ reviews' anchor. Gartner Peer Insights: 4.2-4.3/5. Positive themes: editorial UX, developer flexibility, open-source freedom, .NET Core support, welcoming community. Common criticism: learning curve, custom coding requirements, limited built-in marketing features.

5Total Cost of Ownership72
Licensing
5.1.1
Pricing transparency
88H

Umbraco CMS is MIT licensed — the core platform is completely free with zero licensing ambiguity. Umbraco Cloud pricing (Starter €45/mo, Standard €280/mo, Professional €730/mo) is publicly listed and the 2026 increases were disclosed transparently on the blog. Not higher because several commercial add-on prices still show as variable on the main pricing page, requiring navigation to individual product pages to get exact figures.

5.1.2
Pricing model fit
85H

The MIT license means core Umbraco has zero licensing cost regardless of content volume, API calls, user seats, or site traffic. Cloud plans are flat monthly fees with no usage-based metering or overage charges. Costs scale with infrastructure choice and optional add-ons, not vendor pricing traps. The commercial add-ons (Forms, Deploy, Commerce, Engage, Workflow) add predictable line-item costs on per-domain or annual subscription bases.

5.1.3
Feature gating
72H

The open-source core covers content management, Delivery API, multi-site, multilingual, media management, Examine search, and the full backoffice. Forms is now included in all Cloud plans, removing a previous gating pain point. However, several meaningful capabilities still require paid add-ons for self-hosted: Deploy On-Premises, Commerce, Engage (analytics/personalization), and Workflow. The gating is transparent but notable.

5.1.4
Contract flexibility
85H

No vendor contract for the core open-source software. Self-hosted deployments have zero vendor contractual lock-in. Umbraco Cloud offers monthly billing on all tiers (Starter through Professional), avoiding annual-only lock-in. Commercial add-on licenses are per-domain with annual renewals. You can self-host to avoid all vendor contracts entirely. Maximum flexibility at the core level.

5.1.5
Free / Hobby Tier
88H

Umbraco CMS is MIT licensed with no usage limits, no user caps, and no expiry. Developers can self-host on any .NET hosting environment (Azure App Service, local IIS, Docker, Linux) for minimal cost. SQLite support eliminates the SQL Server requirement for development and simple deployments. The full feature set of the open-source core is available with no restrictions. Umbraco Cloud offers a free trial but not a permanent free tier.

Implementation Cost Signals
5.2.1
Time-to-first-value
55M

Getting Umbraco to first published content requires .NET SDK installation, project creation via `dotnet new umbraco`, and database setup (SQLite for quick start). An experienced .NET developer can reach first content in under an hour via the web installer. Non-.NET developers face additional ramp for SDK setup. Compared to SaaS headless CMSs where first content is minutes away, the local toolchain requirement adds friction, but the SQLite quick-start path has reduced this significantly.

5.2.2
Typical implementation timeline
55M

A typical Umbraco marketing/brochure site: 4-10 weeks (£10-15K). Corporate sites: 6-12 weeks (£15-50K). Complex enterprise with multiple sites, custom integrations, and e-commerce: 3-6 months (£50-250K+). These timelines are comparable to other mid-market CMS platforms. The .NET toolchain and Umbraco's relative simplicity mean implementation times are shorter than enterprise DXPs but longer than headless CMS-native implementations.

5.2.3
Specialist cost premium
58M

Umbraco developers command ~$42/hr average onsite (ZipRecruiter May 2026, $33-47 range) and ~$58/hr for remote roles ($49-69), a moderate premium over .NET generalists. The ramp time for a .NET developer new to Umbraco is days-to-weeks — significantly shorter than for proprietary CMS platforms. Freelancer availability is strong via Toptal, Upwork, and Arc.dev. The premium is substantially lower than for Sitecore or AEM specialists, and .NET skills are mainstream.

Operational Cost Signals
5.3.1
Hosting costs
58M

Umbraco Cloud starts at €45/month (Starter) scaling to €730/month (Professional) — hosting, database, CDN, and Forms included. Self-hosted requires .NET hosting with SQL Server or SQLite, costing $10-$500/month depending on scale. Azure App Service can host Umbraco cost-effectively from ~$10-50/month for basic workloads. The hosting cost profile is moderate — lower than enterprise SaaS platforms but more than static hosting or PHP-based CMSs on shared hosting.

5.3.2
Ops team requirements
54M

Self-hosted Umbraco requires standard .NET web application operations: Kestrel/IIS management, database maintenance, security patching, backup management, and performance monitoring. Umbraco Cloud reduces ops burden with automatic security updates, managed infrastructure, and automated upgrades. Part-time DevOps is typically sufficient for self-hosted mid-market deployments. Umbraco 13 LTS reaches end-of-life 14 Dec 2026 (~5 months out), so self-hosted teams face near-term migration to v17 LTS (.NET 10) or v18, though a one-year v13/v17 support overlap and continued v13 patching ease the pressure.

5.3.3
Vendor lock-in and exit cost
82H

MIT license means zero software vendor lock-in. Content is stored in standard SQL Server/SQLite with a documented schema. Media files use configurable storage providers (local, Azure Blob, S3). The Delivery API enables CMS-agnostic frontend delivery, making frontend code portable. Migration away from Umbraco requires standard database export and content transformation — no proprietary binary formats or vendor exit fees. Exit costs are developer time for content migration only.

6Build Simplicity67
Learning Curve
6.1.1
Concept complexity
65H

Umbraco's core concepts remain manageable for .NET developers: Document Types, Data Types, content tree, Templates, and ASP.NET Core MVC/Razor rendering, with the Delivery API using standard REST for headless. Umbraco 18 GA (18.0.2, released 25 June 2026) adds an Elements/Library concept for reusable content managed outside the page tree, but it is intuitive and layers on top of the existing Block model rather than introducing a new paradigm. Complexity sits below Drupal but above pure headless CMSs because surface controllers, value converters, and the published content cache remain Umbraco-specific patterns.

6.1.2
Onboarding resources
67M

docs.umbraco.com provides structured getting-started guides, tutorials, and API references that the Community Docs Team has refreshed through the v17.5 LTS cycle and updated for the v18 GA feature set. Umbraco Academy offers official training (free online and paid instructor-led), and UmbracoTV plus our.umbraco.com supplement with community tutorials. The getting-started experience requires .NET SDK setup but is well-guided; the main gap remains the absence of an interactive cloud sandbox — local install is still required to evaluate.

6.1.3
Framework familiarity
64H

Built on ASP.NET Core (.NET 10 LTS in v17.5 and v18) — direct skill transfer for .NET developers using C#, MVC/Razor, DI, and standard middleware. For headless, the Delivery API is consumed by any HTTP client, and Umbraco 18 now emits opt-in typed OpenAPI schemas per Document Type, Element Type, and Media Type, so standard codegen tools (e.g. Orval) generate typed TypeScript clients — a meaningful step toward mainstream tooling. Cross-platform familiarity is still capped by the mandatory .NET server-side runtime.

Implementation Complexity
6.2.1
Boilerplate and starter quality
72M

The dotnet new umbraco template provides a clean scaffold, and the Clean Starter Kit (Paul Seal, targeting Umbraco 17 and above) bundles Content Delivery API integration, Next.js revalidation, dictionary/search/contact endpoints, and OpenAPI/Swagger docs. With Umbraco 18's built-in typed OpenAPI schemas, the documented Orval workflow now auto-generates typed clients and models for a Next.js frontend, closing much of the earlier codegen gap. The vendor still does not ship a first-party opinionated Next.js/Nuxt starter, which is what keeps this from scoring higher.

6.2.2
Configuration complexity
68H

Configuration uses standard .NET appsettings.json patterns — familiar to any .NET developer — with environment-specific overrides through the standard configuration provider chain and far fewer config files than Drupal. Umbraco's migration runner manages database schema changes, and v18 additions like typed OpenAPI output are simple opt-in config flags. The configuration surface area is manageable for a stock install, though load balancing, CDN, and custom search integrations still add layers.

6.2.3
Data modeling constraints
62M

Adding new Document Types and Data Types is straightforward, and Umbraco 18's Elements/Library gives a cleaner home for reusable content, but changing property types on published content can still cause data loss because property data is typed at storage level with no automatic migration, and removing properties orphans existing data. Umbraco Deploy helps synchronize schema across environments, yet content migration after schema changes remains a manual effort. The constraints are well-known and avoidable with planning, but they keep the score in the low 60s.

6.2.4
Preview and editing integration
68H

The Bellissima backoffice includes an inline preview panel that renders the published template alongside the editing form, and the Delivery API supports preview mode via an API key for draft content. The community DeliveryApiExtensions package adds the ability to preview Delivery API responses directly from backoffice content nodes, which closes most of the headless preview gap. Umbraco still does not ship true in-page click-to-edit for decoupled frontends, which is what caps this in the high 60s.

Team & Talent
6.3.1
Required specialization
65H

Server-side customization requires .NET/C# knowledge — generalist JavaScript developers cannot work on the backend without cross-training. However, a .NET developer ramps significantly faster than in Drupal or Sitecore, and the v17.5/v18 backoffice extension model is standard TypeScript with framework choice, which makes UI customization accessible to mainstream web developers. For pure headless frontend delivery, no .NET knowledge is required.

6.3.2
Team size requirements
72H

Solo .NET developers can ship and maintain Umbraco sites across the full stack, and typical production projects need only 1–3 people: a .NET developer for backend and content modeling, optionally a frontend developer, and a content editor. Complex implementations layering commerce, personalization, and external integrations may extend to 3–5 people, but that is closer to the project ceiling than the floor. Solo-developer feasibility is realistic for standard builds and well-supported by the Clean Starter Kit ecosystem.

6.3.3
Cross-functional complexity
71H

The Bellissima backoffice, mature across v17.5 LTS and v18 GA, is consistently praised for its clean, intuitive editorial UI — a genuine competitive strength vs. Drupal, Sitecore, or AEM. Umbraco 18's new Library section lets editors create and manage reusable content (Elements) independently of pages, further reducing developer involvement for ongoing content operations. Editors typically need only 1–4 hours of training, and marketers can manage content, settings, and templates without developer involvement once data types and templates are configured.

7Operational Ease61
Upgrade & Patching
7.1.1
Upgrade difficulty
58H

Minor upgrades stay smooth via NuGet with an automatic migration runner, and v18.0.0 GA (2026-06-25) shipped as a Standard-Term Support release with clean 18.0.1/18.0.2 point releases. But v17→v18 carries real breaking changes: the single-mode Block List migration now runs automatically and silently skips nested data unless custom property editors register an ITypedSingleBlockListProcessor first, plus EnableMediaRecycleBinProtection now defaults on. G2 reviewers still consistently flag upgrades as 'complicated and time-consuming,' and the v13→v17 AngularJS→Web Components rebuild remains the real barrier — moderate difficulty overall.

7.1.2
Security patching
70H

Umbraco HQ demonstrated exemplary coordinated patching on 2026-07-07, shipping same-day fixes across all supported majors (18.0.2, 17.5.3, 13.15.1) for a high-severity Delivery API authorization flaw, following March 2026 (CVE-2026-31832/33/34) and a June 2026 Umbraco.AI advisory. Advisories carry clear severity ratings and affected version ranges; patches ship via NuGet for self-hosted and apply automatically on Umbraco Cloud. Transparent, predictable, and fast — near best-practice for a self-hostable .NET CMS.

7.1.3
Vendor-forced migrations
55H

The v18 GA softened forcing pressure: HQ shipped it as Standard-Term Support and explicitly framed staying on v17 LTS as 'just as valid a choice,' so customers on the LTS (support to Nov 2027, security to Nov 2028) are not pushed onto the next major. Still, v13 EOL (Dec 2026) is a hard deadline and v17+ requires subscription licensing rather than one-off licenses, creating a commercial forcing function. Calendar-driven EOLs plus the licensing shift keep migration obligations predictable but unavoidable.

7.1.4
Dependency management
58M

v17/v18 target .NET 10 (v17 LTS) with all dependencies managed via NuGet with lockfile support, and v18 refreshed transitive libraries (e.g. Markdig 0.45→1.1.x) to current versions. Smidge was removed from the default install, trimming the dependency surface, and standard .NET tooling (dotnet list package --vulnerable, Dependabot) handles scanning. The tree is standard ASP.NET Core plus Umbraco packages — smaller and more predictable than Drupal's Composer ecosystem.

Operational Overhead
7.2.1
Monitoring requirements
55M

Umbraco Cloud includes an Availability & Performance dashboard leveraging Azure metrics, hostname monitoring with automated pinging, usage tracking for bandwidth/storage, and project audit logs — a meaningful reduction in setup burden for managed customers. Self-hosted still requires external APM (Application Insights, New Relic) for real observability, with the backoffice Health Check dashboard and Serilog covering only basic checks. Solid for Cloud, still hands-on for self-hosted.

7.2.2
Content operations burden
65M

v18 adds a dedicated Library section for managing reusable elements with reference tracking, workspace validation, scheduled publishing, rollback, permissions, audit logs, and recycle bin — reference tracking in particular surfaces content dependencies and reduces manual governance work. This builds on v17's Release Sets for batch publish/scheduling and the backoffice's bulk operations and media library. There is still no native broken-link checker (handled via community packages like Skybrud Redirects), which caps the score.

7.2.3
Performance management
57M

v17 added load-balanced backoffice support, removing the single-machine editing bottleneck and improving high-concurrency resilience, while ASP.NET Core Output Caching and NuCache remain the core published-content caching layer with automatic invalidation. Umbraco Cloud is progressing toward managed load balancing, but CDN configuration is still manual for self-hosted. Less effort than before thanks to load balancing, but not yet SaaS-level hands-off.

Support & Resolution
7.3.1
Support tier quality
55M

Umbraco Cloud offers tiered SLA-backed support, and 2026 G2 reviews describe technical support as 'fantastic' and responsive — e.g. staying engaged through a Forms license issue until resolved (Support & Training rated ~4.0/5). Self-hosted relies on community or contracted certified-partner support, and there is no global 24/7 enterprise NOC comparable to Sitecore or AEM. Good mid-tier support, but enterprise-grade coverage is limited.

7.3.2
Community support quality
70H

The Umbraco community remains one of the strongest in the CMS space: an active forum.umbraco.com, real-time Discord/Slack, and G2 Leader recognition across CMS, Headless, DXP, and WebOps in both Winter and Spring 2026 reports. G2 reviewers consistently cite community and documentation breadth as differentiators, with healthy contributor engagement across the v17/v18 releases. Some feedback still notes documentation gaps for newer versions.

7.3.3
Issue resolution velocity
62H

Three supported major lines are all receiving timely fixes in parallel — v18 (18.0.0 GA 2026-06-25, 18.0.1, 18.0.2), v17 (17.5.0–17.5.3), and legacy v13 (13.15.0/13.15.1) — and the 2026-07-07 high-severity advisory was patched across all three the same day. The paid core team prioritizes commercially impactful and security issues with transparent changelogs, though non-critical bugs can still linger and community package maintenance varies by maintainer.

8Use-Case Fit44
Marketing Sites
8.1.1
Landing page tooling
58M

Block Grid editor enables component-based landing page composition with live editing mode, but marketers cannot create new layouts without developer involvement — they compose from pre-defined block types. Third-party ByteEditor adds visual page building but is not native. Umbraco 18.0 GA (25 June 2026) introduced a new Library section with reusable Elements, but Elements are reusable content pieces without their own URL — a content-reuse primitive, not a marketer-facing layout builder. MCP-assisted layout creation is AI-CLI tooling, not marketer self-service. Score remains in the 'can edit but not create layouts' band.

8.1.2
Campaign management
38M

Umbraco Engage (commercial add-on) provides UTM campaign tracking, campaign analytics, marketing automation, email/SMS marketing, and a dedicated Campaigns section in the backoffice. This covers basic campaign lifecycle but lacks content calendaring and multi-channel coordination dashboards found in full DXPs. Engage MCP extensions for campaigns remain on the 2026 roadmap and have not materially expanded campaign management since the prior review.

8.1.3
SEO tooling
65M

SEO tooling relies on well-established community packages: SEO Checker for on-page analysis, meta tag management, and redirect management; Skybrud packages for sitemaps, Open Graph, and structured data. Custom Document Type properties handle meta fields. The redirect handling performance improvements introduced in 17.3 carry forward into the 17.5 LTS line and 18.0. The ecosystem is solid but nothing is built-in — packages must be installed and maintained.

8.1.4
Performance marketing
55M

Umbraco Forms (commercial) provides form building with conditional logic for lead capture. Umbraco Engage adds A/B testing, conversion goal tracking, personalization, 360° profiling, and in-CMS analytics — covering most performance marketing needs. Engage's new explicit scoring (based on intentions/actions, alongside implicit content-consumption scoring) sharpens conversion-oriented visitor classification. Together, Forms + Engage deliver a functional performance marketing stack. Both are paid add-ons but first-party and well-integrated.

8.1.5
Personalization and targeting
62M

Umbraco Engage provides genuine behavioral personalization: audience segments built from referral source, visit history, geolocation, campaign tags, and persona scores. The 360° profiling engine creates rich profiles for identified and anonymous visitors. Explicit scoring (intentions/actions) now supplements implicit content-consumption scoring, moving visitors into journey stages/personas faster and more precisely. Content can be personalized per segment at the node level. Block-level and property-level segment variations are under investigation but not yet shipped. Requires a paid Engage license and is an add-on, but deep and first-party.

8.1.6
A/B testing and experimentation
58M

Umbraco Engage includes built-in A/B testing — headline variants, layout tests, CTA optimization, full page variants — with real-time result monitoring and multiple simultaneous tests. Statistical reporting is present. The capability is first-party and tightly integrated into the backoffice, reducing the need for an external experimentation tool. However, Engage is a paid add-on and A/B testing is not available without it. Auto-winner selection is not explicitly documented.

8.1.7
Content velocity
57M

Block Grid with inline editing reduces editing cycle time for existing page types. Umbraco 18.0's new Library/Elements feature lets editors create reusable, URL-less content pieces once and insert them across pages via the Element Picker (with rollback, scheduled publishing, and permissions) — a modest velocity gain for repeated content. The full 'update once, change everywhere' block mixing is targeted for Umbraco 19 (later 2026). New page layouts still require developer time to define block types. Adequate speed for teams with established page templates; slower for net-new layouts.

8.1.8
Multi-channel publishing
50M

Umbraco's Content Delivery API enables headless delivery to web, mobile apps, and third-party channels. Umbraco 18.0 added opt-in typed OpenAPI schemas per Document/Element/Media Type, improving generated clients and headless integration robustness. The platform is web-first, but structured content models can be consumed via API for other frontends. No native multi-channel orchestration, email template management, or push notification delivery. API delivery to other channels requires frontend development. The headless/hybrid capability exists but multi-channel is not a first-class authoring concern.

8.1.9
Marketing analytics integration
52M

Umbraco Engage provides in-CMS analytics dashboards — page views, visitor behavior, campaign performance, goal completions — visible in the backoffice. Standard GA4 and Google Tag Manager integration works via script injection. Content performance metrics are available within Engage for Engage-instrumented pages. Improved bot detection (2026) yields cleaner analytics data. External analytics tools needed for full depth. Better than basic tag integration but short of full in-CMS analytics suites.

8.1.10
Brand and design consistency
45M

Block Grid's predefined block palette creates some consistency guardrail — editors can only use approved block types. Umbraco 18.0's Library/Elements adds centrally managed reusable content pieces with permissions, providing a further consistency lever for shared content. However, there is still no design token system, no enforced style constraints at the platform level, and no brand consistency dashboard. Brand customization is enforced via template design and developer-defined block configurations, not platform-level tooling.

8.1.11
Social and sharing integration
38M

Open Graph and Twitter/X card meta tags are handled via SEO Checker and Skybrud packages, not built into core. No native social scheduling, push-to-social workflows, or social proof widgets. SEO Checker previews social card appearance. Package-based OG management is the ceiling — no first-party social publishing or scheduling capability.

8.1.12
Marketing asset management
42M

Native media library supports image uploads with built-in focal point and crop definitions via Image Cropper property editor. Basic asset search and folder organization. No rights management, usage tracking, or brand portal capabilities. Third-party DAM integrations (Cloudinary, Azure Blob, Bynder) are available via marketplace packages but require installation and configuration. Below the threshold of a true DAM.

8.1.13
Marketing localization
48M

Umbraco has solid built-in multi-language support — content variants per language, Dictionary items for UI strings, language-specific domains. However, there are no transcreation workflows, locale-specific campaign scheduling, or market-level compliance guardrails. Regional cookie consent requires third-party packages. Generic localization infrastructure applied to marketing content, not purpose-built marketing localization tooling.

8.1.14
MarTech ecosystem connectivity
48M

CRM integrations documented on umbraco.com with webhook/API-based connectors to Salesforce and HubSpot. Umbraco Compose acts as a composable integration hub connecting CMS, CRM, PIM, DAM, and ERP into unified API outputs. Marketplace has various CRM and MAP package integrations at varying maturity levels. No pre-built native connectors to ad platforms or CDP. Better than minimal but not deep pre-built MarTech stack.

Commerce
8.2.1
Product content depth
52M

Umbraco Commerce supports product content modeling via Document Types and property editors — product variants, attributes, per-variant pricing, and custom metadata. Complex data structures including tiered pricing and cross-sell relationships are possible via editor-friendly schemas. Customer Management with order history and analytics widgets (added in early 2026) augments commercial content insight. Product modeling is flexible but not purpose-built — less structured than dedicated PIMs and requires developer setup to model correctly.

8.2.2
Merchandising tools
42M

Umbraco Commerce provides category navigation, promotions engine, discount codes, and basic cross-sell via content relationships. Analytics widgets for Top Selling Products, Applied Discounts, Most Popular Discounts, and Stock Forecast (shipped early 2026) give merchandisers better visibility into performance. Still no algorithmic merchandising, search merchandising, or content-driven discovery. Analytics improvements add insight but not merchandising action.

8.2.3
Commerce platform synergy
48M

Umbraco Compose is a SaaS composable integration layer designed to connect CMS, PIM, ERP, and external commerce platforms into unified API outputs. Pre-built connectors to Shopify/commercetools remain community-maintained. Extended MCP for Commerce data is on the 2026 roadmap but not yet shipped. The Storefront API enables headless commerce integration. Custom API integration is feasible via .NET but most external commerce platforms require developer effort.

8.2.4
Content-driven storytelling
38M

Umbraco CMS + Commerce together can support buying guides and product-adjacent editorial content — editors can create editorial pages that reference Commerce product nodes. However, shoppable content with inline product references and purchase CTAs is not a first-class authoring pattern. Blending rich editorial with commerce data requires developer implementation rather than being an out-of-the-box editorial workflow.

8.2.5
Checkout and cart content
35M

Umbraco Commerce Checkout is a drop-in add-on package providing a themeable checkout flow. CMS-managed content in the checkout (trust badges, upsell banners, shipping callouts) is technically possible — the checkout flow renders via Umbraco templates — but is not a zero-dev capability. Template modification required to inject CMS-controlled content into the transactional flow. Score reflects the gap between capability and marketer self-service.

8.2.6
Post-purchase content
32M

Post-purchase experience (order confirmation, delivery tracking pages, onboarding sequences) lives largely within Commerce templates. Umbraco Commerce docs now include a how-to for building a Members Portal (my account) enabling member registration and order history, but this is a documented build pattern rather than a drop-in feature. Abandoned cart overview in CMS remains a roadmap item. Currently, post-purchase content lives in developer-controlled templates rather than being CMS-managed.

8.2.7
B2B commerce content
45M

Umbraco Commerce supports B2B scenarios with customizable customer-specific pricing (price lists by customer group), member-gated catalogs, approval workflows, and ERP integrations. Personalized logins via Members enable per-customer product/pricing visibility, quick order, reorder, and saved shopping lists. Features require implementation but Commerce provides the primitives. Less out-of-the-box than dedicated B2B platforms but genuinely capable with development.

8.2.8
Search and discovery content
35M

Examine search (Lucene-based) provides full-text search across CMS content including Commerce products. No native faceted search for commerce discovery, no synonym management, no search merchandising, and no blended content-product search results without custom development. Search landing pages and faceted filtering require developer implementation. The search foundation is solid but commerce-specific search enrichment is not addressed out-of-the-box.

8.2.9
Promotional content management
42M

Umbraco Commerce's promotions engine handles discounts with time-based activation (start/end dates). Scheduled publish/unpublish in the CMS enables time-based promotional content (banners, sale pages). Multiple discount types (fixed, percentage, free shipping, buy-X-get-Y) are supported. No native countdown timer widgets, promo code messaging components, or channel-specific targeting of promotional content. Basic scheduled banners with Commerce discount rules.

8.2.10
Multi-storefront content
45M

Umbraco Commerce's Storefront API (introduced 12.1) enables a true headless multi-storefront architecture with separate frontends per region/brand consuming a shared Umbraco CMS backend. Multi-currency, multi-tax, and multi-language are built-in. However, storefront-specific editorial content (legal pages, regional landing pages) requires some content duplication within the CMS tree rather than a governed shared/override model. Capable with some duplication.

8.2.11
Visual commerce and media
30M

Umbraco's media library handles standard product images with focal point cropping. Video embeds are possible via property editors (YouTube/Vimeo embed or video file uploads). No native 360-degree product views, AR/3D model support, or image hotspot tooling. Advanced visual commerce capabilities (zoom, hotspot, 3D) require custom frontend implementation or third-party integration — not addressed by Commerce or core CMS out-of-the-box.

8.2.12
Marketplace and seller content
20L

Umbraco Commerce and CMS have no marketplace-specific features — no seller profiles, seller-contributed product descriptions, content moderation at scale, or review aggregation. Multi-author backoffice access could technically support some seller content submission workflows, but this is generic CMS multi-author capability, not marketplace tooling. Building a marketplace on Umbraco would require extensive custom development.

8.2.13
Commerce content localization
45M

Umbraco CMS has built-in multi-language support (content variants per language, Dictionary items) and Commerce supports multi-currency and multi-tax out-of-the-box. Locale-specific product descriptions via language variants are possible. Currency-aware content blocks require custom implementation. No native regulatory content management (EU labels, Prop 65) or market-specific promo calendar tooling. Generic multi-language + Commerce multi-currency applied to product content.

8.2.14
Commerce conversion analytics
38M

Umbraco Engage tracks content engagement (page views, goals, conversions) and Commerce shipped analytics widgets (Top Selling Products, Applied Discounts, Stock Forecast) in early 2026. However, direct content-to-revenue attribution — connecting a specific editorial page to downstream purchase — requires custom implementation connecting Engage events to Commerce orders. Analytics split between Engage (content) and Commerce (transactions), with no native revenue attribution bridge.

Intranet & Internal
8.3.1
Access control depth
68H

Content-node-level permissions for backoffice users (deny/allow on specific nodes and subtrees by user group). Member groups control frontend content gating for intranet/portal scenarios. User group permissions cover document type, media, and section access. Umbraco 18.0's Library adds permission and start-node scoping for reusable Elements, extending granular access control to shared content. Functional for most intranet and B2B portal implementations. Less granular than Drupal's node access grant system but sufficient for department-level content isolation with SSO-backed member authentication.

8.3.2
Knowledge management
65M

Hierarchical content tree maps well to knowledge base structures. Tags and categories via property editors enable classification. Examine search provides full-text search for knowledge bases. Umbraco 18.0's Library gives reusable knowledge snippets a managed home with rollback, scheduled publishing, audit logs, and recycle bin. Umbraco Workflow (commercial) adds approval workflows for content updates. No native content lifecycle management (review dates, expiry, archival). Adequate for organizational knowledge bases but requires architectural design work to assemble from primitives.

8.3.3
Employee experience
52M

Umbraco can serve as an intranet CMS with member groups for authenticated access, content tree for navigation, and Forms for employee interactions. Uintra (open-source framework) provides a news/events feed, groups, and activity streams on top of Umbraco — reducing custom dev burden significantly. No native news feed, employee directory, notifications, or social features in core. Substantial custom development still needed beyond Uintra to match SharePoint or dedicated intranet platforms.

8.3.4
Internal communications
35M

Umbraco supports publishing news and announcements to authenticated member groups — providing basic audience-segmented internal comms. Scheduled publish/unpublish for timed announcements. No read receipts, acknowledgment tracking, mandatory-read workflows, or targeted comms dashboards. Uintra extends this with a collective activity feed, but still lacks acknowledgment and mandatory-read capabilities critical for compliance-driven internal comms.

8.3.5
People directory and org chart
22L

No native people directory or org chart tooling in Umbraco core or official add-ons. An employee directory can be built using Member types (custom Document Types for people profiles) with Examine search, but this is a ground-up custom build rather than a platform feature. Org chart visualization requires additional frontend development. HR system integration (Workday, BambooHR) requires custom API connectors. Score reflects the absence of platform-provided tooling.

8.3.6
Policy and document management
38M

Umbraco has built-in content versioning and rollback. Umbraco Workflow (commercial) adds multi-stage approval workflows suitable for policy update reviews. Scheduled publish/unpublish handles planned policy activations. No native mandatory acknowledgment tracking, automated review date reminders, or SOP expiry workflows. Basic document publishing with version control and optional commercial approval tooling — functional but short of a compliance-grade policy management system.

8.3.7
Onboarding content delivery
28L

No native onboarding journey tooling in Umbraco. Structured onboarding pages can be built as content types with member-gated access and role-based content trees. Progressive disclosure (30/60/90 day content release) would require custom scheduled content logic. Umbraco Engage segments could be used for role-specific content personalization in an onboarding context. This is an assembly-from-primitives scenario, not a platform feature.

8.3.8
Enterprise search quality
38M

Examine search (Lucene-based) provides full-text internal search across CMS content with custom index definitions for faceting. Umbraco 18.0's Library content is integrated into global search. Uintra adds Elastic Search for intranet scenarios. No federated search across SharePoint, Confluence, or Google Drive. No AI-powered relevance ranking. Search quality for internal content volumes is adequate for CMS-scoped content but cannot index connected external systems without custom integration work.

8.3.9
Mobile and frontline access
30M

No native Umbraco mobile app. Intranet frontends built on Umbraco can be made responsive and PWA-enabled, providing web-based mobile access. The Umbraco backoffice itself has responsive improvements in recent versions. No native push notifications, offline support, or kiosk/shared-device modes. Deskless/frontline worker access relies on a developer-built responsive web frontend — adequate for basic access but not a native mobile experience.

8.3.10
Learning and training integration
20L

No native LMS integration or learning management features in Umbraco. Training content (courses, modules, quizzes) can be hosted as CMS content, but completion tracking, certification, and course assignment require a dedicated LMS. No documented Cornerstone, Workday Learning, or SCORM integration in the marketplace. Learning content hosting is the only realistic use case — external LMS required for everything else.

8.3.11
Social and collaboration features
30M

No native social or collaboration layer in Umbraco core. Uintra provides an activity feed, news feed, events, and group spaces on top of Umbraco — giving a modest social layer for intranet deployments. Comments, reactions, polls, and peer recognition all require Uintra or custom development. Uintra covers the basics but is an open-source third-party framework requiring separate adoption and maintenance.

8.3.12
Workplace tool integration
28L

No native Microsoft 365/Teams, Google Workspace, or Slack integration in Umbraco core or official add-ons. Webhook-based integrations are technically feasible and some community packages exist for notification pushing. Embedded content cards, bot-driven notifications, and single-pane experiences would require custom development. The platform is not positioned for workplace tool integration and the marketplace reflects this.

8.3.13
Content lifecycle and archival
32M

Scheduled publish/unpublish in core handles basic content expiry. Umbraco 18.0's Library adds a recycle bin and rollback for reusable Elements, but not automated review dates or stale-content flagging. No automated review date reminders, stale content flagging, ownership assignment, or archival workflows for pages. Umbraco Workflow (commercial) adds approval steps but not lifecycle management for existing content. Content freshness for intranet trust requires manual editor discipline or custom automation. A notable gap for intranet use cases.

8.3.14
Internal analytics and engagement
28L

No native internal content analytics or engagement dashboards in core. Umbraco Engage provides visitor analytics but is primarily a marketing personalization tool rather than an intranet adoption measurement tool. Department-level analytics, failed search terms, and adoption dashboards are not addressed by any first-party tooling. External analytics (GA4) can provide basic page views. Score reflects the absence of purpose-built intranet analytics.

Multi-Brand / Multi-Tenant
8.4.1
Tenant isolation
65M

Multi-site via domain and hostname configuration provides logical tenant isolation within a single installation — separate content trees, templates, and user group permissions per site. True database-level isolation requires separate Umbraco installations. No native multi-tenant admin dashboard. Community confirms multi-tenancy works in Umbraco 15/17/18 but many plugins don't support it. Logical isolation is solid; physical isolation requires separate instances.

8.4.2
Shared component library
62M

Shared partial views, Element Types, and the shared media library enable component sharing across brand sites within a single installation. Umbraco 18.0's new Library section provides a dedicated, centrally governed home for reusable Elements — with reference tracking, permissions, rollback, and scheduled publishing — consumed across content via the Element Picker. This strengthens central maintenance of shared content within one installation, though it remains intra-installation (not cross-tenant) and lacks a governed design-token override mechanism. The 'update once, change everywhere' block reuse is targeted for Umbraco 19.

8.4.3
Governance model
58M

User group permissions provide central admin with per-site editorial access control. Umbraco Workflow (commercial) enables multi-stage approval workflows per Document Type. Umbraco 18.0's Library adds permission- and start-node-scoped governance over reusable Elements. MCP Server (Umbraco 17+) keeps permissions and governance at center for AI-assisted workflows. No out-of-box governance dashboard for multi-brand management. Cross-site approval hierarchies require custom development.

8.4.4
Scale economics
65M

Core CMS remains MIT-licensed — zero per-brand software cost increment for a single installation hosting multiple brand sites. Commercial add-ons (Commerce, Engage, Forms, Workflow) are priced per installation, not per site, maintaining economics as brand count grows within a single instance. The model becomes less favorable if separate installations are needed for true tenant isolation, as add-on costs multiply. Still competitive vs. per-brand licensed CMS platforms.

8.4.5
Brand theming and style isolation
45M

In a multi-site Umbraco installation, each brand site has its own templates, stylesheets, and asset folders. This provides CSS-level brand isolation but not platform-level design token management or theme inheritance. Brand customization requires developer-maintained CSS and template sets per brand. No token override system, no design system versioning, and no central-to-brand theme propagation mechanism.

8.4.6
Localized content governance
38M

Umbraco multi-language support provides per-brand locale configuration. Translation workflows are not natively governed per brand — a shared translation workflow applies across the installation. There are no brand-specific translation approval chains, no regional legal content governance guardrails, and no system for managing market-specific compliance content per brand. Generic localization infrastructure without brand-locale governance distinction.

8.4.7
Cross-brand analytics
25L

No portfolio analytics dashboard across brand sites in Umbraco or any first-party add-on. Umbraco Engage provides per-site analytics within the backoffice for each site, but there is no aggregate view across multiple brand sites. Cross-brand performance comparison requires manual aggregation from per-site analytics or external tools (GA4 with multi-property reporting). Executive-level portfolio reporting is not addressed.

8.4.8
Brand-specific workflows
45M

Umbraco Workflow (commercial) supports per-Document-Type approval chains that can be configured independently per content area and thus per brand site. Approval stages, reviewers, and notification recipients can be set per content type/group. However, workflows are configured per Document Type rather than natively per brand, and there is no central audit view across all brand workflows. With careful configuration, brand-specific workflows are achievable but not natively first-class.

8.4.9
Content syndication and sharing
35M

No native corporate-to-brand content syndication with controlled override points. Umbraco 18.0's Library enables reusable Elements with reference tracking within a single installation — a step toward shared content — but cross-brand syndication with local adaptation and override control is not delivered (mix-and-match/customize-per-page is targeted for Umbraco 19). The 17.x+ Content Delivery API enables API-level content consumption across brands. Press-release push with local adaptation still requires custom development.

8.4.10
Regional compliance controls
32L

No per-brand/region compliance guardrails in Umbraco. Cookie consent is handled via third-party packages (Cookiebot marketplace integration). Accessibility compliance is the developer's responsibility. GDPR data handling is addressed at infrastructure/hosting level, not CMS publishing guardrails. Data residency is an Umbraco Cloud hosting consideration, not per-brand CMS enforcement. There are no CMS-level guardrails preventing non-compliant publishing per brand.

8.4.11
Design system management
37M

Shared partial views and Element Types enable centrally maintained component sharing across brand sites. Umbraco 18.0's Library adds a dedicated management home for reusable Elements with permissions, rollback, reference tracking, and audit logs — a genuine step toward centralized component management, though it manages reusable content instances rather than a versioned design system with tokens. No design-token management, version propagation, or brand-level extension governance. Design system management remains largely a developer-practice discipline.

8.4.12
Cross-brand user management
55M

A single Umbraco installation provides a central backoffice where a super-admin can manage all brand sites. User groups can be scoped to specific sites/content sections, enabling autonomous brand editorial teams with their own permissions. SSO integration for single sign-on across brand teams is supported. No dedicated cross-brand user management dashboard or cross-brand contributor role with controlled access across multiple brands. Functional centralization without dedicated tooling.

8.4.13
Multi-brand content modeling
40M

Shared Document Types across multi-site provide a common base model that all brand sites use. Brand-specific extensions (adding fields per brand) can be achieved via composition and Element Types, but this typically results in separate Document Type variants per brand rather than a truly shared base with clean per-brand extension. Forking the base model per brand is the common pattern, which limits maintainability at scale.

8.4.14
Portfolio-level reporting
20L

No executive portfolio reporting across the brand portfolio in Umbraco or any first-party add-on. No content freshness tracking by brand, publishing SLA reporting, cost allocation per tenant, or capacity planning dashboards. Umbraco Engage provides per-site analytics but no portfolio aggregation. Portfolio reporting requires external business intelligence tooling (GA4, Power BI, Looker) connected to per-brand data exports. This is a notable gap for multi-brand platform management.

9Regulatory Readiness & Trust60
Data Privacy & Regulatory
9.1.1
GDPR & EU data protection
75H

Umbraco is headquartered in Odense, Denmark (EU jurisdiction), with a downloadable 2024 DPA (18-page PDF) including SCCs available to all customers. Sub-processor Microsoft Azure published, EU (Netherlands) data residency default on Umbraco Cloud, and twice-yearly (May/Nov) GDPR data revisions. Not higher because the sub-processor list is minimal (Azure) and right-to-erasure is not self-service tooling.

9.1.2
HIPAA & healthcare compliance
35H

No HIPAA BAA offered by Umbraco and no healthcare-specific compliance documentation published. European-market focus means HIPAA is not a priority. Self-hosted Umbraco on HIPAA-compliant infrastructure is technically feasible but the platform provides no BAA or guidance.

9.1.3
Regional & industry regulations
51M

Strong GDPR via Danish EU HQ, now backed by ISO 27001 certification (Jan 2026). Multi-region Umbraco Cloud hosting (UK, Canada, Australia) supports UK GDPR/IDTA, PIPEDA, and Australian Privacy Act data residency needs. CCPA implied via DPA. No FedRAMP, IRAP, C5, or PCI-DSS attestation; NIS2 compliance work is underway but aligned to ISO 27001 rather than a separate certification.

Security Certifications
9.2.1
SOC 2 Type II
35H

Umbraco does NOT hold SOC 2 certification. The compliance FAQ explicitly states Umbraco A/S has no active focus on obtaining SOC certification and instead relies on Microsoft Azure's SOC reports. Per anti-pattern rules, cloud provider certifications cannot be inherited by the platform, so no SOC 2 Type 1 or Type 2 attestation exists for Umbraco itself.

9.2.2
ISO 27001 / ISO 27018
74H

Umbraco achieved ISO/IEC 27001:2022 certification announced 27 January 2026, scoped to its product organisation (the teams developing, maintaining, and operating Umbraco's products) — platform scope, not just infrastructure. No ISO 27018 (cloud PII processing) certification documented. Score reflects platform-scope 27001 without 27018.

9.2.3
Additional certifications
45M

No additional certifications beyond ISO 27001 (scored under 9.2.2). No CSA STAR Level 2, PCI-DSS, Cyber Essentials Plus, FedRAMP, or IRAP. NIS2 compliance work is in progress but not a certification. Base score for no additional certifications per rubric.

Data Governance
9.3.1
Data residency & sovereignty
80H

Umbraco Cloud now offers five data center regions — West Europe (Netherlands), East US (Virginia), South UK, East Australia, and Central Canada (soft-launched April 2025) — with the customer selecting region at project creation and residency contractually backed via the DPA. This spans EU, US, UK, APAC, and Canada. Self-hosted deployments provide complete residency control; not higher because Cloudflare CDN caching can move content outside the chosen region.

9.3.2
Data lifecycle & deletion
58M

Content version cleanup with configurable retention (default 90 days for daily snapshots, 4 days for all versions) and per-form Forms data retention with automated deletion. Content Delivery API provides JSON export. Not higher because there is no documented post-termination retention period and right-to-erasure requires manual handling rather than a self-service portal.

9.3.3
Audit logging & compliance reporting
57M

Umbraco has a native Audit Trail tracking content changes and user actions, persistent for content operations. Infrastructure logs default to 24-hour retention. Not higher because there is no native SIEM integration — SIEM forwarding requires a self-hosted Azure deployment with custom log export.

Platform Accessibility
9.4.1
Authoring UI accessibility
72H

Umbraco states the backoffice meets WCAG 2.2 Level AA and ATAG 2.0 criteria, with an external accessibility consultant and community Accessibility Team auditing editor-facing workflows and shipping fixes in v17/17.1. Not higher because some system-level improvements (keyboard movement, text spacing) remain in progress for 2026.

9.4.2
Accessibility documentation
62M

Umbraco maintains a continuously updated Accessibility Conformance Report (ACR) tracking backoffice accessibility status, serving a role comparable to a VPAT for procurement, with the community accessibility team resolving issues publicly. Not higher because there is no formal Section 508 conformance statement and some system-level accessibility work remains in progress.

10AI Enablement48
AI Content Creation
10.1.1
AI text generation & editing
64H

Umbraco.AI.Prompt (GA) delivers field-level, content-type-scoped generation, rewriting, summarization and expansion with central brand-voice/tone governance, and the conversational Copilot (Umbraco.AI.Agent.Copilot) reached final GA release July 2026 — it understands editorial context, works with blocks and complex structures, supports speech-to-text dictation and file uploads, and can save/publish behind a manual approval gate. This is native first-party AI, not a plugin. Not higher because bulk multi-item generation and long-form authoring workflows remain lighter than dedicated content-generation leaders.

10.1.2
AI image & media generation
40M

Alt-text generation is GA via Umbraco.AI.Prompt, and AI focal-point selection plus alt text ship in the third-party AI Essentials Toolkit; Copilot adds drag-and-drop media upload into the chat context. Native AI image generation (DALL-E/Firefly/Stable Diffusion) is still not shipped in GA, and no AI video or DAM processing is documented. Scored mid-band for solid auto alt text without native image generation.

10.1.3
AI translation assistance
34M

Umbraco.AI.Prompt can generate per-field draft translations and translation hints natively, and the third-party AI Essentials Toolkit adds an intelligent translation function with dashboard and glossary; the ecosystem also offers Translation Manager by Jumoo with an official OpenAI connector. There is still no native MT engine or bulk cross-locale quality scoring with brand-voice preservation built into core. Slightly above the no-AI-translation floor for the Prompt-based and marketplace options.

10.1.4
AI metadata & SEO automation
52H

Umbraco.AI.Prompt (GA) natively generates SEO titles, meta descriptions, alt text, content summaries and taxonomy tags as one-click, full-context field actions, and Copilot can apply these conversationally. Still missing is a built-in on-page SEO scoring/optimization dashboard woven into the editorial workflow — that requires third-party packages like SeoToolkit.Umbraco. Solid partial automation, capped below the on-page-scoring threshold.

AI Workflow Automation
10.2.1
AI-assisted content operations
48M

With Copilot now GA, editors can clean up content, restructure blocks, compare and analyse content, and save/publish behind approval, while Umbraco.AI.Prompt handles auto-tagging, alt text and metadata enrichment across items — several AI assists now woven into editorial. Smart scheduling, duplicate detection and AI-driven bulk lifecycle automation are still not shipped, and content-workflow automation remains on the roadmap. Above the light-assist band but short of comprehensive automation.

10.2.2
Agentic workflow automation
52M

Umbraco.AI.Agent is built on Microsoft Agent Framework with AG-UI streaming, ships 66+ Agent Skills covering every backoffice extension type plus routing and quickstart skills, and the Copilot reached GA (July 2026) executing multi-step tasks with context awareness, semantic search and an approval gate before save/publish. This is real agentic capability in GA, but it is a human-in-the-loop copilot rather than a fully autonomous named content-pipeline agent (à la Contentstack Agent OS / Sanity Content Agent). Solid GA agentic features, mid-band.

10.2.3
Content intelligence & insights
30M

The first phase of Agent Copilot for Engage lets marketers explore Engage analytics (personas, journeys, scoring, goals, segments, A/B tests) through conversation rather than static reports — an emerging AI insights layer. There is still no AI-driven content gap analysis, topic clustering, stale-content detection or editorial-priority recommendation dashboard in core. Early and Engage-scoped, so low-mid band.

10.2.4
AI content auditing & quality
28M

AI Tests and Evaluations (Umbraco.AI) targets prompt/model quality comparison across providers before go-live rather than content auditing, and Copilot can compare/analyse and clean up individual content items. No brand-voice compliance scanning, accessibility AI auditing, or at-scale duplicate/thin-content detection across hundreds of pages is available in GA. Minor bump for Copilot's per-item analysis, still well below dimension-level auditing.

AI Search & Personalization
10.3.1
AI/semantic search
46H

Umbraco.AI.Search is now a first-party semantic vector-search add-on (beta) that indexes content as embeddings and exposes similarity search through the CMS Search API and an AI agent tool, built on the new Umbraco.Cms.Search abstraction; Copilot already consumes it for semantic retrieval. This is a major shift from the prior third-party-only state (ExamineX/Azure AI Search). Held at mid-band because both Umbraco.AI.Search and the underlying search framework are still in beta, not the default provider yet.

10.3.2
AI-powered personalization
24H

Umbraco Engage provides rules-based personalization with explicit scoring, personas, journeys and A/B testing, and the forthcoming Engage MCP / Agent Copilot for Engage lets AI explore and configure this via conversation — but runtime personalization uses manually defined rules and explicit signals, not ML predictions. No predictive segment assignment, next-best-content recommendations or cold-start handling exists. Rule-based with an AI configuration/insights layer, so low band.

AI Platform & Extensibility
10.4.1
MCP server availability
68H

The official Developer MCP Server (open-source, 315+ Management API endpoints as composable, permission-aware read/write/publish tools) is now version-aligned with Umbraco 17/18 and effectively production-grade, and a hosted CMS Editor MCP plus the existing Developer MCP are launching as remote MCPs on Umbraco Cloud — beta July 2026, GA later summer — all on a shared Base MCP SDK. Compatible with Claude, Cursor and VS Code Copilot. Just short of the top band because the editorial Editor MCP and Engage MCP are still in beta/announced.

10.4.2
Bring your own AI model/key (BYOM/BYOK)
82H

Umbraco.AI is built on Microsoft.Extensions.AI as a provider abstraction with roughly ten official first-party provider packages — OpenAI, Anthropic, Amazon Bedrock, Google Gemini, Microsoft AI Foundry, Mistral, DeepSeek, Hugging Face, Fireworks AI and Together AI. Users supply their own keys and pay providers directly (Umbraco has no billing role), support multiple connections per provider, define governance once centrally, and switch providers with a config change; community M.E.AI providers can also be added. Best-in-class provider flexibility.

10.4.3
AI developer extensibility & agent APIs
60H

The Management API (315+ endpoints) is fully exposed as MCP tools on a shared Base MCP SDK that all Umbraco MCP servers now build on, Agent Skills (SKILL.md with YAML frontmatter) are a published integration pattern, semantic search is exposed as an AI agent tool, and M.E.AI allows custom provider packages. No dedicated LangChain/LlamaIndex/CrewAI integration guides exist and a RAG-ready Content Delivery MCP is still on the roadmap, keeping this in the strong-but-not-top band.

10.4.4
AI governance, safety & audit trails
54M

Governance is Umbraco.AI's headline theme ('adopt AI without losing control'): a central framework defines permitted actions, tone and which data is sent to providers, applied consistently across every AI package; full request/response audit logging with version history covers all AI entities; the MCP servers respect Umbraco's existing permission model; and Copilot's GA save/publish requires human approval. Missing: hallucination detection/confidence scoring, IP indemnification, and dedicated brand-safety enforcement scanning. Good governance with audit trails and human-in-the-loop, below comprehensive.

10.4.5
AI observability & usage analytics
44M

The backoffice AI area now surfaces analytics and logs capturing when AI is used, which task it supports and how often, alongside per-request token tracking with hourly/daily rollups and full audit logging, and AI Tests & Evaluations enable prompt/model comparison. Missing are per-user/team consumption breakdowns, prompt-effectiveness analytics, latency dashboards and quality-trend monitoring; external integrations (e.g. Langfuse) would need custom middleware. Basic usage tracking and cost visibility, mid-band.

Score History

How composite scores (0–100) have changed over time. Click legend items to show/hide metrics.

+16.8 capability
analyst note

Recent Updates

July 20267 score changes

Umbraco's momentum is modestly improving, with the movement concentrated almost entirely in Compliance & Trust (+1.6) while Capability, Cost Efficiency, and Build Simplicity hold steady and Platform Velocity and Operational Ease tick up only fractionally. The compliance gain reflects two concrete developments: Umbraco Cloud's expansion to five data center regions, which drove a 12-point jump in data residency and sovereignty, and the January 2026 ISO 27001 certification reinforcing its GDPR posture. For practitioners with regional hosting or regulatory requirements, the data residency improvement is the standout shift and meaningfully broadens where Umbraco Cloud can now be considered; elsewhere, the platform's on-schedule v18 release and parallel support of three major lines signal reliable but unchanged execution.

Score Changes

Data residency & sovereignty6880(+12)

Umbraco Cloud now offers five data center regions — West Europe (Netherlands), East US (Virginia), South UK, East Australia, and Central Canada (soft-launched April 2025) — with the customer selecting region at project creation and residency contractually backed via the DPA. This spans EU, US, UK, APAC, and Canada. Self-hosted deployments provide complete residency control; not higher because Cloudflare CDN caching can move content outside the chosen region.

Regional & industry regulations4851(+3)

Strong GDPR via Danish EU HQ, now backed by ISO 27001 certification (Jan 2026). Multi-region Umbraco Cloud hosting (UK, Canada, Australia) supports UK GDPR/IDTA, PIPEDA, and Australian Privacy Act data residency needs. CCPA implied via DPA. No FedRAMP, IRAP, C5, or PCI-DSS attestation; NIS2 compliance work is underway but aligned to ISO 27001 rather than a separate certification.

Issue resolution velocity6062(+2)

Three supported major lines are all receiving timely fixes in parallel — v18 (18.0.0 GA 2026-06-25, 18.0.1, 18.0.2), v17 (17.5.0–17.5.3), and legacy v13 (13.15.0/13.15.1) — and the 2026-07-07 high-severity advisory was patched across all three the same day. The paid core team prioritizes commercially impactful and security issues with transparent changelogs, though non-critical bugs can still linger and community package maintenance varies by maintainer.

Security track record7071(+1)

Umbraco maintains a responsible disclosure program with CVE-tracked patches delivered via NuGet. The March 2026 security releases (17.2.2, 16.5.1) addressed privilege escalation in user groups, XSS in property descriptions, and authorization bypass on domain access — patched promptly across supported LTS branches. Continued regular servicing through Q2/Q3 2026 (18.0.x, 17.5.x, 13.15.x) shows no major advisories in the feed. No incidents of Drupalgeddon severity. Rapid cross-version patching demonstrates mature response processes.

Release frequency7576(+1)

The twice-yearly major cadence held exactly on schedule: v18.0.0 GA shipped Jun 25, 2026 (after beta/rc1-3), followed immediately by 18.0.1 (Jul 1) and 18.0.2 (Jul 7). In parallel, 17.5.0-17.5.3 and 13.15.0/13.15.1 all shipped across late Jun-early Jul 2026, showing rapid patching across three maintained branches. This is one of the more disciplined release machines in the .NET CMS space.

Ops team requirements5554(-1)

Self-hosted Umbraco requires standard .NET web application operations: Kestrel/IIS management, database maintenance, security patching, backup management, and performance monitoring. Umbraco Cloud reduces ops burden with automatic security updates, managed infrastructure, and automated upgrades. Part-time DevOps is typically sufficient for self-hosted mid-market deployments. Umbraco 13 LTS reaches end-of-life 14 Dec 2026 (~5 months out), so self-hosted teams face near-term migration to v17 LTS (.NET 10) or v18, though a one-year v13/v17 support overlap and continued v13 patching ease the pressure.

Onboarding resources6667(+1)

docs.umbraco.com provides structured getting-started guides, tutorials, and API references that the Community Docs Team has refreshed through the v17.5 LTS cycle and updated for the v18 GA feature set. Umbraco Academy offers official training (free online and paid instructor-led), and UmbracoTV plus our.umbraco.com supplement with community tutorials. The getting-started experience requires .NET SDK setup but is well-guided; the main gap remains the absence of an interactive cloud sandbox — local install is still required to evaluate.

June 2026

Umbraco's momentum is flat this cycle, with every composite dimension—Capability, Platform Velocity, Cost Efficiency, Build Simplicity, Operational Ease, and Compliance & Trust—holding precisely at prior levels. The absence of movement reflects a quiet review period without meaningful product, ecosystem, or governance shifts to reweight any dimension. Scores remain stable since the last review, leaving Umbraco's positioning unchanged across the board.

March 20267 score changes

Umbraco is broadly stable this cycle with one notable exception: Compliance & Trust dropped 4.7 points, driven primarily by a sharp correction to SOC 2 Type II scoring after confirmation that Umbraco holds no such certification and has no active pursuit of one, alongside softer declines in audit logging and data residency coverage. Partially offsetting this, accessibility scores improved as Umbraco now publishes a maintained Accessibility Conformance Report and claims WCAG 2.2 AA conformance for its backoffice, though these gains were not enough to prevent the overall compliance dimension from slipping. Practitioners in regulated industries should take note of the SOC 2 gap, while those prioritizing content editor accessibility will find Umbraco's recent investments encouraging.

Score Changes

SOC 2 Type II6835(-33)

Umbraco does NOT hold SOC 2 certification. Their compliance FAQ explicitly states they have no active focus on obtaining SOC certification and instead rely on Microsoft Azure's SOC reports. Per anti-pattern rules, cloud provider certifications cannot be inherited by the platform. No SOC 2 Type 1 or Type 2 attestation exists for Umbraco itself.

Accessibility documentation4562(+17)

Umbraco maintains a continuously updated Accessibility Conformance Report (ACR) tracking backoffice accessibility status. This functions similarly to a VPAT for procurement purposes. No formal VPAT document specifically found, but the ACR serves a comparable role. Not higher because no Section 508 formal conformance statement and some system-level accessibility work remains in progress.

Audit logging & compliance reporting6557(-8)

Umbraco has a native Audit Trail tracking content changes and user actions. Infrastructure logs have a default 24-hour retention. No native SIEM integration — achieving SIEM requires self-hosted Azure deployment with custom log forwarding. Audit trail history is persistent for content operations. Log export requires custom implementation.

Data residency & sovereignty7568(-7)

Umbraco Cloud offers two data center regions: EU (NW Europe / Netherlands) and US East (Virginia). Customers choose at provisioning. EU residency is contractually backed via DPA. No APAC region option for Umbraco Cloud. Self-hosted deployments provide complete residency control. Score reflects EU/US binary choice with contractual guarantee.

Authoring UI accessibility6572(+7)

Umbraco now claims WCAG 2.2 Level AA and ATAG 2.0 conformance for the backoffice. External accessibility consultant reviewed editor-facing workflows throughout 2025. Most audited issues resolved and shipped in v17/17.1. UI components built with accessibility tests. Some system-level improvements (keyboard movement, text spacing) still in progress for 2026.

Additional certifications4845(-3)

No additional certifications beyond ISO 27001. No CSA STAR Level 2 audit, no PCI-DSS, no Cyber Essentials Plus, no FedRAMP, no IRAP. NIS2 compliance work is in progress but not a certification. Base score for no additional certifications per rubric.

ISO 27001 / ISO 270187274(+2)

Umbraco achieved ISO/IEC 27001:2022 certification in January 2026 for its product organization — platform scope, not just infrastructure. Third-party audit by independent security specialist. This is a significant recent milestone. No ISO 27018 (cloud PII processing) certification documented. Score reflects platform-scope 27001 without 27018.

June 2025

Umbraco 15 and early work on V16 continue the rapid release cadence. The new backoffice ecosystem is rebuilding momentum with packages migrating to the Lit-based extension system. Regulatory readiness improves with better GDPR tooling and security hardening, but the platform still lacks native compliance certifications that enterprise DXPs offer.

Platform News

  • Umbraco 15 STS release

    Short-term support release tracking .NET 9, with continued backoffice improvements and API enhancements.

  • Bellissima extension ecosystem growing

    Community adoption of new Web Components-based extension model accelerating, reducing V14 migration friction.

  • Umbraco Cloud security enhancements

    Improved security headers, CSP support, and audit logging capabilities in Umbraco Cloud.

August 2024

Umbraco 14 ships with the completely rewritten Bellissima backoffice built on Lit/Web Components, replacing the decade-old AngularJS UI. This is a massive frontend modernization that improves extensibility but temporarily disrupts the package ecosystem as all backoffice extensions need rewriting. Platform velocity remains solid but the breaking changes create short-term friction.

Platform News

  • Umbraco 14 with new Bellissima backoffice

    Complete backoffice rewrite using Lit/Web Components, replacing AngularJS. Major extensibility improvement but breaks existing backoffice packages.

  • Management API introduced

    New Management API for programmatic content and media operations, complementing the Content Delivery API.

  • Umbraco Commerce maturation

    Umbraco Commerce (formerly Vendr) continues to evolve as the official e-commerce solution for Umbraco.

December 2023

Umbraco 13 LTS launches on .NET 8, the second enterprise-grade LTS release on modern .NET. The Content Delivery API is now mature and well-documented, making hybrid headless architectures practical. The platform is finding its niche as a developer-friendly .NET CMS with good TCO, though it still trails headless-native platforms on API capabilities.

Platform News

  • Umbraco 13 LTS on .NET 8

    Second LTS on modern .NET stack, with mature Content Delivery API and improved media handling.

  • Umbraco Marketplace growth

    Official package marketplace expanding with V10+ compatible packages, ecosystem stabilizing after migration period.

  • Umbraco Cloud CI/CD improvements

    Enhanced deployment pipelines and environment management in Umbraco Cloud.

February 2023

Umbraco 11 and 12 ship in quick succession as Umbraco adopts a rapid release cadence aligned with .NET versions. The new backoffice rewrite using Lit/Web Components (codenamed Bellissima) is announced, promising a modern extensible UI. However, the pace of major version bumps creates upgrade fatigue in the community.

Platform News

  • Umbraco 11 on .NET 7

    STS release tracking .NET 7, introducing Block Grid editor and improved property editors.

  • New backoffice (Bellissima) announced

    Ground-up rewrite of the Umbraco backoffice using Lit/Web Components, replacing the aging AngularJS UI.

  • Umbraco acquires Plumber workflow tool

    Workflow approval capabilities brought in-house, strengthening enterprise content governance.

June 2022

Umbraco 10 LTS arrives on .NET 6, marking the first long-term supported version on the modern .NET stack. The Content Delivery API is introduced, giving Umbraco native headless capabilities without requiring Heartcore. The rapid V9→V10 cadence signals strong platform velocity and commitment to staying current with .NET releases.

Platform News

  • Umbraco 10 LTS on .NET 6

    First LTS release on modern .NET, providing enterprises a stable migration target from V8.

  • Content Delivery API introduced

    Built-in REST API for headless content delivery, reducing dependency on Heartcore for simple headless use cases.

  • Codegarden 2022 in-person return

    Return to in-person Codegarden conference in Odense, reinvigorating community engagement.

September 2021

Umbraco 9 launches as the landmark .NET 5 rewrite, modernizing the entire stack. This is the biggest architectural shift in Umbraco's history, moving from .NET Framework to cross-platform .NET 5. Early adoption is cautious as the ecosystem of packages needs to be ported, but developer excitement is high.

Platform News

  • Umbraco 9 released on .NET 5

    Complete rewrite to .NET 5 with dependency injection, cross-platform support, and modern C# patterns.

  • Package ecosystem migration begins

    Community packages begin migration from V8 to V9, causing temporary ecosystem fragmentation.

  • Umbraco Cloud support for V9

    Umbraco Cloud updated to support .NET 5 deployments alongside legacy V8 projects.

March 2021

Umbraco 8 is the stable workhorse of the .NET CMS world, running on .NET Framework 4.7.2. The platform enjoys a loyal community especially in Europe, but lacks modern headless capabilities and cloud-native features. Platform velocity is moderate as the team focuses on planning the major .NET Core migration.

Platform News

  • Umbraco 8.x LTS maintenance releases

    Steady stream of bugfix releases for V8 while the team prepares the .NET Core rewrite.

  • Umbraco Heartcore headless product

    Heartcore SaaS headless offering available but limited adoption compared to dedicated headless CMS platforms.

  • COVID-era community growth

    Virtual Codegarden and expanded online community engagement during pandemic.

How does Umbraco stack up against your shortlist?
Side-by-side scoring across all 10 categories and every criterion.
Compare Platforms →