You have probably sat through the pitch, or a version of it. A vendor stands up, says they build for government and only government, that they understand civic web in a way no generalist ever could, and then the price reflects exactly how special that understanding is. It sounds obviously right. The people who do one thing all day ought to be the best at that thing.
So here is a result I genuinely did not expect when we started fingerprinting government websites. In American local government, the platforms sold specifically to government, by companies whose whole reason for existing is civic web, are being quietly and comprehensively out-built by a general-purpose open-source CMS that no salesperson ever walked into a town hall to recommend.
Nobody demoed Drupal to anyone. It is still winning.
The numbers, before anyone accuses me of cheerleading
We fingerprinted the platform behind 18,682 US government and higher-education domains, then measured what each one actually emits. Among government sites where we could identify the vendor, the specialist platforms cluster at a median readiness of 63.6. Drupal sites sit at 72.7.
The individual signals are where it stops being close. Canonical tags, which decide whether your URLs survive contact with a redesign, appear on 91.1% of government Drupal sites. The largest government specialist vendor, running roughly 2,500 municipal sites, manages 11.3%. That is not a gap, that is a different answer to the question. Strict transport security runs 78.3% on Drupal against 14.1% on that same vendor.
One in nine, versus nine in ten, on a setting that determines whether a town's website keeps its search visibility after the next redesign. The vendor was hired to know that.
The part I actually find remarkable
Government is the worst-performing sector we have measured. Not close to the worst, the worst: an average readiness of 62.6 against 69.4 across the most-visited 50,000 domains. Underfunded, procured through processes designed in a different era, maintained by teams who are usually doing four other jobs.
Government Drupal sites score 71.6.
Read that next to the web average again. A municipal website in the least-resourced corner of the internet, running a CMS chosen by a civil servant rather than recommended by a sales team, is better prepared for a migration than the average commercial site in that group. The sector it lives in is seven points below that bar. Its Drupal sites are two points above it.
Higher education tells the same story more quietly, with university Drupal at 73.8 against a sector average of 70.0, and strict transport security at 72.8% versus 43.8% for WordPress.
| Group | Median readiness |
|---|---|
| Government sites on specialist civic vendors | 63.6 |
| Average site, most-visited 50k | 69.4 |
| Government sites on Drupal | 71.6 |
| University sites on Drupal | 73.8 |
Why this happens, which is the useful bit
None of this is because municipal Drupal teams are better funded. They are manifestly not. It happens because a platform's defaults are doing work that nobody has to remember to do.
A specialist vendor optimises for what wins the procurement: the demo, the workflow, the accessibility statement, the training. Those matter. But canonical discipline and transport security are invisible during a sales cycle. Nobody has ever lost a government contract because their canonical implementation was weak, because nobody in the room knew to ask.
Drupal got there by a different route. Its defaults were argued over in public by people who would have to live with them, and the correct behaviour ended up being the path of least resistance. You have to work to break it. That is the whole advantage, and it compounds every single time somebody rebuilds a site.
Now the thing the community should fix
I am not going to pretend the picture is clean. Structured data, the markup that tells a machine what a page actually is, appears on 15.3% of government Drupal sites and 58.6% of government WordPress sites. In higher education it is 25.9% against 80.1%. That is the signal answer engines lean on hardest when they decide whom to quote, and Drupal is losing it badly.
Here is why I still think this is the strongest position of any CMS we have measured. Canonical discipline and security posture are architectural. A platform that lacks them cannot bolt them on later without tearing things up. Structured data is a template concern. It is a module, a theme decision, a few hours inside a distribution, and it lands on every page at once.
So here is where I actually land, and I am not hedging it. Drupal is winning the two things that are almost impossible to fix after the fact, canonical discipline and transport security, and losing the one thing that is genuinely easy to fix. Structured data is a template concern. It is a module, a theme decision, a few hours inside a distribution, and then it lands on every page at once. Every other platform we measured has that ratio backwards, carrying the easy wins and quietly rotting on the architecture.
So if you maintain a distribution, a base theme, or a government profile, this is the single highest-leverage patch available to the whole ecosystem right now: ship sane schema output by default. Not buried in an options screen. The thing that happens when someone installs it and changes nothing, because changing nothing is what most people do.
The vendors won the demo. They always will, because canonical tags and transport headers never come up in the room. But the sites people actually rely on are decided long after everyone has gone home, and Drupal is already winning that part. Somebody just needs to hand it the one line it keeps forgetting to say.
Figures come from our open datasets, published under CC BY 4.0: 9,324 live .gov and .mil sites, 1,796 live .edu sites, and a vendor-fingerprint pass over 18,682 domains. Vendor names in the concentration study are anonymised by design. Platform figures cover only sites exposing a detectable fingerprint, so read every share as a floor rather than a ceiling.
