Loader logo

White-label Drupal development, on terms that serve you.

Drupal is an enterprise-grade, open-source CMS. Agencies reach for it when security, complex permissions, editorial governance, and multi-site scale matter more than a big plugin ecosystem, which is exactly the work we take on.

Here is what that means when you bring it to us:

  • You win the project and own the client. We stay out of that relationship entirely.
  • We build under your brand: the migration, the module and theme work, and the ongoing updates.
  • It becomes yours on delivery. The site and the IP transfer to you, and your client never learns we were involved.

An unsupported Drupal site is a liability. We turn it back into an asset.

Drupal’s release cycle is forcing a decision for a lot of sites, and the dates are fixed rather than approximate.

  • Drupal 7 is end of life, and has been since 5 January 2025. No security updates. Sites still on it are exposed.
  • Drupal 8 and 9 are long past support. Drupal 8 ended in November 2021 and Drupal 9 in November 2023.
  • Drupal 10 reaches end of life on 9 December 2026. Drupal 10.6 is its final minor release, and no further releases follow that date.
  • Drupal 12 ships the week of 7 December 2026, two days before Drupal 10’s support ends.

If a client is on an unsupported version, staying put stops being a maintenance question and becomes a security and compliance one.

Drupal’s release cycle is forcing a decision for a lot of sites, and the dates are fixed rather than approximate.

  • Drupal 7 is end of life, and has been since 5 January 2025. No security updates. Sites still on it are exposed.
  • Drupal 8 and 9 are long past support. Drupal 8 ended in November 2021 and Drupal 9 in November 2023.
  • Drupal 10 reaches end of life on 9 December 2026. Drupal 10.6 is its final minor release, and no further releases follow that date.
  • Drupal 12 ships the week of 7 December 2026, two days before Drupal 10’s support ends.

If a client is on an unsupported version, staying put stops being a maintenance question and becomes a security and compliance one.

Which Drupal version to move to? We’ll tell you.

Worth being direct about, because the timing catches people out. For a client on Drupal 10 today, the target is Drupal 11, not Drupal 12.

Drupal 12 arrives the same week Drupal 10 loses support, which means moving straight to it puts a client’s production site on a brand-new major release in its first week. Drupal 11 has been stable since 2024, and the eventual step from 11 to 12 behaves more like a minor upgrade than a migration. Getting current on 11 first is the lower-risk route, and it is what we will recommend unless there is a specific reason not to.

Working backwards from 9 December 2026: a client who wants to be safely off Drupal 10 should be starting the upgrade well before the autumn, not in the weeks before the deadline.

When Drupal is the right call. (And when it’s not!)

Because Drupal is more involved than WordPress, recommending it correctly protects your margin and your client relationship. The honest guide:

Drupal is the right call when the project has:

1

Strict security or compliance needs,

covering government, healthcare, finance, and education. Drupal has enterprise-grade access control and a dedicated security team.

2

Complex permissions and editorial workflows,

where many people touch content and role-based access and approval chains are needed out of the box.

3

Scale or multi-site requirements,

meaning large, high-traffic sites, or many related sites run from one platform.

4

An existing Drupal investment,

where the client is already on Drupal and migrating to a supported version is cheaper and lower-risk than re-platforming entirely.

Drupal is usually the wrong call when:

  • It is a standard marketing site, blog, or small business site. WordPress is faster and cheaper.
  • The client wants to self-manage cheaply with a big plugin ecosystem. Again, WordPress.
  • There is no security, scale, or governance requirement to justify the higher build cost.

Tell us the project and we will tell you honestly which way to go, including “this should be WordPress” when it should. We work inside your process either way, whether that is Slack, ClickUp, Asana, or Basecamp.

What we handle on Drupal

1

Legacy-to-supported migrations

Drupal 7, 8, 9, or 10 to a supported version: content, modules, theme, redirects, and SEO. This is most of our Drupal work.

2

Version upgrades and ongoing updates

Keeping sites on a supported release as the cycle moves.

3

Custom module development

To Drupal coding standards, built to survive future core updates, when contributed modules do not fit.

4

Multi-site and permissions architecture

Role-based access and content governance.

5

API integration

Connecting Drupal to the client’s other systems.

6

New builds

From-scratch Drupal when a project genuinely calls for it. A smaller part of what we do.

7

Performance and security hardening

Caching, optimization, and current security practices.

FAQ

Do I need to migrate my client off an old Drupal version?

If they are on Drupal 7, yes. It reached end of life on 5 January 2025 and no longer receives security updates. Drupal 8 and 9 are also long past support. And if they are on Drupal 10, the deadline is 9 December 2026, after which no further releases are made. Staying on an unsupported version is a security and compliance risk rather than just a maintenance one.

Yes, and it is most of our Drupal work. There is no direct upgrade path from Drupal 7, so it is a full rebuild: we handle content migration, module replacements, theme rebuild, and SEO preservation so search visibility survives the move.

Upgrade to 11. Drupal 12 ships the week of 7 December 2026, the same week Drupal 10 loses support, so moving straight to it means running a brand-new major release on a production site in its first week. Drupal 11 has been stable since 2024, and the later step from 11 to 12 is closer to a minor upgrade than a migration.

Currently supported Drupal releases, plus migrations from legacy Drupal 7, 8, 9, and 10. We follow Drupal’s official upgrade paths and release cycle.

For enterprise-grade security, complex permissions, advanced content workflows, or large multi-site architectures, which typically means government, universities, and large organizations. For standard marketing sites, WordPress is usually the better and cheaper choice, and we will say so.

Yes, to Drupal coding standards when contributed modules do not fit, built for performance, security, and compatibility with future core updates.

Granular role-based access control, content moderation, and editorial approval processes are built in, which is ideal when many people touch content and governance matters.

Yes. It has strong built-in multilingual support through dedicated core modules, including right-to-left languages, content translation, and interface translation.

Regular core and module updates, security-advisory monitoring, input validation, access-control configuration, and database hardening. Drupal has a dedicated security team that patches vulnerabilities actively, and we apply those patches promptly.

Stop Doing It All

Have a build you think needs Craft?

Send us the scope. If it is really a WordPress job, we will say so. If it is Craft, we will come back with a fixed quote and a timeline.