[ Drupal · Full playbook ]
// 05 / 20The buyer's playbook.
The working reference behind Drupal Development Cost & Agency Buyer Guide 2026: what to ask, what to watch and how to run the first 90 days.
← Back to the guide[ RFP questions ]// 01
Questions that reveal real capability.
Ask for a relevant example, the decision made, the result or learning, and the person who would own the work.
- 01Why is Drupal the right fit for these requirements?
- 02List contributed and custom modules with maintenance status.
- 03Describe configuration management and environment promotion.
- 04How are security advisories triaged and patches deployed?
- 05What automated tests protect critical workflows?
- 06How will migration be rehearsed and reconciled?
- 07Define caching, CDN, performance and observability.
- 08What knowledge transfer prevents vendor dependence?
[ Risk ]// 02
Make failure visible before signature.
| Risk | Early warning | Control |
|---|---|---|
| Custom code debt | Core behaviour overridden | Prefer supported patterns |
| Upgrade friction | Modules lag | Track lifecycle compatibility |
| Configuration drift | Environments differ | Configuration management and CI |
| Security response gap | Patch owner unclear | Define emergency SLA |
| Poor editor experience | Workflow is slow | Prototype with editors |
[ Value case ]// 03
Measure outcomes—not activity.
01Editorial throughputBaseline ________
90-day target ________
90-day target ________
02Accessibility defectsBaseline ________
90-day target ________
90-day target ________
03Page performanceBaseline ________
90-day target ________
90-day target ________
04Security patch currencyBaseline ________
90-day target ________
90-day target ________
05Migration reconciliationBaseline ________
90-day target ________
90-day target ________
06Lifecycle lead timeBaseline ________
90-day target ________
90-day target ________
[ First 90 days ]// 04
Move from evidence to operating rhythm.
01
Days 1–30
Discovery, architecture and migration decisions
Exit evidenceApproved baseline, owners, scope and risk log
02
Days 31–60
Design system, environments, core build and integrations
Exit evidenceWorking outputs, QA evidence and decision record
03
Days 61–90
Migration waves, security QA, training and rollout
Exit evidenceMeasured result, learning backlog and operating owner
[ Reference desk ]// 05
Speak the same language.
| Term | Plain-language meaning |
|---|---|
| Core | The maintained Drupal platform. |
| Contributed module | A community-maintained extension. |
| Configuration management | Versioned settings across environments. |
| Composer | PHP dependency manager. |
| Drush | Drupal command-line tooling. |
| Caching layer | Mechanisms reducing repeated processing. |
[ Playbook in hand? ]