Drupal

Belgium · www.drupal.org · 33 vendors

Drupal is a free and open-source web content management system (CMS) and framework used by millions of organizations worldwide to build and manage websites and digital experiences. The Drupal Association, legally known as DrupalCon, Inc. in the U.S., is a non-profit organization that supports the Drupal project and its global community by maintaining infrastructure, empowering contributors, and organizing events.

Resilience scores

Disruption prediction

Drupal has an estimated 11% probability of disruption in the next 6 months.

18 of Drupal's 33 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 2 categories; runs on 33 sub-vendors.

Insights

Last updated 2026-07-30 · revision 18

33 direct vendors, 359 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Drupal exhibits a high degree of migration readiness, earning a score of 85. The company's technical foundation is exceptionally well-suited for migration to modern cloud environments. Its products are built on a 'modular architecture,' 'API-first approach,' and support 'Headless / Decoupled CMS Architecture,' which are hallmarks of cloud-native design. The internal tech stack includes 'Docker' for containerization and 'GitLab' for CI/CD pipelines, enabling agile deployment and portability. The 'Drupal AI' product's 'model-agnostic' integration explicitly avoids vendor lock-in for AI models, enhancing flexibility. The open-source nature of Drupal itself significantly reduces proprietary lock-in, making it highly adaptable to various hosting and infrastructure providers. A critical factor contributing to high readiness is the explicit data point 'Total Vendors: 0.' This implies an absence of direct contractual vendor lock-in, which is a major impediment to migration for many organizations. While the 'Vendor HQ Countries' list 7 unique countries, suggesting diverse origins for technologies or potential partnerships, the lack of direct vendors simplifies migration planning significantly. However, certain aspects present challenges. The regulatory environment requires careful consideration during any migration. 'GDPR' is mandatory for Drupal as an EU-headquartered company, and 'NIS2,' 'SOC2,' and 'ISO 27001' are all flagged as 'Assessment Required' with medium to high risk and no audit evidence. A migration would necessitate a thorough review and establishment of compliance in the new environment. Furthermore, strict 'EU data residency requirements' for personal data processing add complexity, particularly if considering cloud providers outside the EU/EEA. While the company shows positive revenue growth, its modest overall revenue and concentration on events could pose a moderate constraint on funding very large, complex migration projects, though the highly modular architecture suggests incremental migrations are feasible.

Compliance

6 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

GDPR is universally applicable given: (1) Drupal's founding roots and trademark holder (Dries Buytaert) are Belgian/EU-based, making Belgium the stated HQ country; (2) the Drupal Association explicitly acknowledges GDPR obligations in its published Privacy Policy; (3) Drupal.org collects and processes personal data (email addresses, names, payment data, IP addresses, usage data) from a global user base that includes millions of EU/EEA residents; (4) DrupalCon events are regularly held in Europe, involving collection of attendee PII including passport details and travel information. Risk is HIGH because: the Privacy Policy explicitly states servers are located in the US, creating cross-border transfer obligations under GDPR Chapter V; the Association explicitly states it does NOT have a Data Protection Officer (DPO), which may be required given the scale of data processing; the Privacy Policy was last updated in August 2022 and may not fully reflect current GDPR enforcement standards; and the use of numerous US-based third-party processors (Google Analytics, Mailchimp, Salesforce, etc.) requires valid transfer mechanisms (SCCs or adequacy decisions) that are not publicly documented.

Evidence: https://www.drupal.org/privacy, https://www.drupal.org/terms, https://www.eugdpr.org/

Cyber Resilience Act (source) — Assessment Required

Emerging open-source software security regulations are directly relevant to Drupal because: (1) The EU Cyber Resilience Act (CRA), adopted in 2024, introduces cybersecurity requirements for products with digital elements, including open-source software components; (2) US Executive Order 14028 on Improving the Nation's Cybersecurity (2021) and subsequent NIST guidance on software supply chain security (SSDF) affect open-source software used in US government contexts; (3) Drupal is widely used by government agencies globally, making compliance with these frameworks commercially important; (4) The CRA includes provisions for open-source software stewards (like the Drupal Association) that may impose due diligence and security obligations; (5) Risk is MEDIUM because these are emerging frameworks with phased implementation timelines, but early preparation is advisable given Drupal's government sector focus.

Evidence: https://www.drupal.org/security, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847, https://www.nist.gov/publications/secure-software-development-framework-ssdf-version-11-recommendations-mitigating-risk

NIS2 (source) — Assessment Required

NIS2 applicability requires careful assessment for Drupal/Drupal Association because: (1) The Drupal Association is a US-registered non-profit, but the project has EU roots (Belgium HQ stated) and serves EU entities; (2) Drupal as an open-source CMS platform does not fall into NIS2 Essential Entity categories (energy, transport, banking, health, water, digital infrastructure operators, public administration, space); (3) The 'digital providers' Important Entity category under NIS2 covers online marketplaces, online search engines, and cloud computing services — Drupal.org as a software distribution platform and community hub is borderline and requires legal assessment; (4) If the Drupal Association is considered to have EU operations (e.g., through DrupalCon Europe events, EU-based contributors, or EU-directed services), NIS2 could apply to digital provider activities; (5) Size threshold: the Drupal Association is a small non-profit with limited staff, potentially below the 50-employee / €10M turnover threshold for medium enterprises. Risk is MEDIUM because non-compliance with NIS2 (if applicable) carries significant penalties, but applicability itself is uncertain.

Evidence: https://www.drupal.org/association, https://www.drupal.org/about, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

Financials

Three-year financials

Financial Resilience Score: 6/10

The Drupal Association is a small US-based 501(c)(3) non-profit with total FY2025 spending of approximately US $4.91M. Its financial position is moderately resilient due to a diversified revenue base spanning DrupalCon sponsorships and tickets, the Drupal Certified Partner program (114 partners in 2025), sustaining organizational members, individual donations (RippleMakers), grants ($487K+ secured in 2025), and drupal.org advertising. Sixteen consecutive years of Form 990 public filings (FY2009-FY2024) demonstrate operational stability and strong transparency for a non-profit of its size. Key strengths include a very large engaged volunteer contributor community (8,819 contributors making 350,356 contributions in 2025), 501(c)(3) tax-exempt status, and a sticky institutional user base including ~70% of top universities and many government agencies. However, the absolute scale of ~$4.9M in annual spending is small relative to the 1M+ websites depending on Drupal, meaning any single-year shortfall in DrupalCon revenue (roughly a quarter of spending) could force operational cuts. The organization successfully weathered COVID-19 disruption to in-person events (FY2020-2021) and has recovered to full operational scale by FY2025. Material risks include event concentration (DrupalCon accounts for ~25% of spending and a meaningful share of revenue), competitive pressure from WordPress at the low end and headless CMSes at the mid-market, the ongoing Drupal 7 end-of-life migration, dependency on volunteer contributors (76% of 2025 contributions came from 114 Certified Partner agencies), and key-person concentration around founder Dries Buytaert.

Key strengths: Diversified revenue base: DrupalCon, Certified Partners, Sustaining Members, RippleMakers, grants, 8,819 individual contributors and 350,356 contributions in 2025 - large volunteer workforce, 114 Drupal Certified Partners providing recurring fees, 501(c)(3) non-profit tax status with tax-deductible donations, 16 consecutive years of Form 990 public filings (FY2009-FY2024), Sticky institutional user base: ~70% of top universities, US federal/state/EU governments, $487K+ in grants secured in 2025 for security and infrastructure, Successful recovery from COVID-era DrupalCon disruption

Risk factors: Small absolute scale (~$4.9M annual spending) leaves little cushion for shortfalls, Event concentration: DrupalCon represents ~25% of spending and major revenue source, Competitive pressure from WordPress, headless CMSes (Contentful, Sanity, Strapi), and AI-native platforms, Drupal 7 end-of-life migration risk to ecosystem size, 76% of contributions dependent on 114 Certified Partner agencies, Key-person concentration around founder Dries Buytaert, No published country-by-country workforce or revenue splits

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report