Q4 2026: The Most Expensive Time to Migrate Drupal
Drupal 7 support ended on 5 January 2025. Drupal 10 end of life on 9 December 2026 lands in the same release window as Drupal 12 and Drupal 11.5. Drupal 10 sites cannot upgrade straight to Drupal 12. Drupal 11 is the next supported step. For teams on either legacy version, 2026 is a deadline year, not a planning year.
Key Takeaways
- Enterprises spend 60% to 80% of IT budget maintaining existing systems, so every month on a legacy version deepens the imbalance.
- Senior Drupal architects are scarce, and agencies book Q3 and Q4 migration work months ahead.
- Waiting into Q4 means paying a premium for an expedited timeline rather than a planned one.
- Holiday code freezes remove weeks of delivery capacity from exactly the quarter the deadline falls in.
- Organizations that start in Q1 and execute in Q2 spend less and enter 2027 with the work behind them.
For most CTOs, Q4 is a rush to the finish line: closing budgets, freezing code for the holidays, and planning next year's roadmap.
In 2026, that quarter is carrying more than it can hold. Drupal 10's end of life, the Drupal 12 release, and the Drupal 11.5 release all land inside the same week in December. Add the annual holiday code freeze at most enterprises and the predictable Q4 spike in agency demand, and the last quarter of the year is the worst available window for a migration that has to complete before the deadline rather than after it. If you need to migrate Drupal before then, start now.
What Does Waiting to Migrate Drupal Cost?
Waiting costs budget, staff time, and leverage. All three grow each month instead of showing up as one bill in December. Three of the four items below build whether or not anything breaks; the fourth is the payoff you forfeit by waiting.
The Innovation Tax
Industry research shows that enterprises spend between 60% and 80% of their IT budgets maintaining old systems. That leaves as little as 20 cents of every dollar for new work, new features, or a stronger market edge. Every month on a legacy Drupal version deepens that gap.
The Talent Gap
Senior Drupal architects are in short supply. Agencies that build Drupal migration projects book Q3 and Q4 work months in advance, and teams that wait usually pay more for rush timelines. That premium is the clearest cost of waiting, because it shows up in quotes during the quarter.
The Productivity Drain
Research from CodeScene estimates that developers spend up to 42% of their time on technical debt. That is about two full workdays each week lost to code that should have been updated. An earlier update gives that time back to your engineering team in the same fiscal year.
The Update Payoff
Updating to Drupal 11 is not only about avoiding risk. Current Drupal versions offer better caching, a cleaner deployment path, and access to the Drupal AI module ecosystem, which is not available on unsupported branches. Teams that move before the deadline get those gains in a planned release, not in an emergency.
What Are the Compliance Risks of Running Unsupported Drupal?
Unsupported software is a control gap that auditors flag, and it grows more serious the longer a known flaw goes unpatched. Teams still running Drupal 7 have had no security patches since January 2025.
Drupal 10 faces a sooner deadline than many teams think. Individual Drupal 10 minor releases lose security coverage before the branch itself does, and Drupal 10.6.0 is the final minor in the series. Check which 10.x minor your site runs, because a site two minors behind is exposed now, not in December.
Compliance exposure: For teams subject to GDPR, HIPAA, or PCI-DSS, unsupported software is not always a violation. But it is a documented control gap. It shows up in audit findings, weakens your case after an incident, and can block procurement and vendor security reviews.
What Changes After 9 December 2026?
Your site keeps running. That is the part most stakeholders get wrong in both directions: nothing switches off, and nothing is fine either. What stops is the flow of fixes.
- No more Drupal 10 core releases. The branch is closed, so security advisories affecting it are not patched.
- Contributed modules follow. Maintainers move their Drupal 10-compatible branches to supported versions, and coverage fades over time instead of ending on one date.
- Procurement and audit consequences arrive on their own schedule. A rule that requires supported software does not care that the site is still serving pages.
The practical effect is that risk starts on 10 December and does not announce itself. There is no outage to escalate, which is why these migrations slip.
Why Do Small Updates Beat One Large Upgrade?
The organizations facing the hardest version of this deadline are usually not the ones that skipped a major version. They are the ones that stopped applying minor updates.
Every deferred minor release adds deprecated API calls, lets contributed modules drift further from their maintained branches, and widens the gap between what the site needs and what its runtime supports. That accumulated distance is what turns a two-month upgrade into a four-month one, and it is measured in deferred maintenance rather than in major versions.
Our Enterprise Migration Playbook makes the same point about launch approach: phased migration outperforms a single cutover in almost every enterprise context, because errors stay contained and timelines stay recoverable. The exception is a site whose content architecture is so degraded that phasing preserves the wrong foundation.
The same logic applies to updates. Applying minors as they ship keeps each step small enough to test properly, and it means the major version jump is the only large thing you are doing at once.
After 9 December, that discipline stops being available on Drupal 10 in any case, because the minor releases stop.
Should You Migrate to Drupal 11 or Wait for Drupal 12?
Migrate to Drupal 11. Drupal does not support skipping major versions, so a Drupal 10 to 11 migration is required before Drupal 12 regardless of timing. Drupal 11 is the next supported step either way.
The next step depends on where you are now: Drupal 7 and Drupal 9 sites need a migration project to Drupal 11, Drupal 10 sites upgrade to Drupal 11 and then 11.5, and Drupal 11 sites should land on 11.5 before considering Drupal 12.
| Your current version | Status | Next supported step |
|---|---|---|
| Drupal 7 | End of life since January 2025. Unpatched. | A migration project to Drupal 11, not an upgrade |
| Drupal 9 | Already past end of life | Drupal 11, starting now |
| Drupal 10 | Supported until 9 December 2026 | Drupal 11.3 or higher, then 11.5. Drupal 12 will not upgrade from anything below 11.3 |
| Drupal 11 | Current and supported | Drupal 11.5, which ships the same week as Drupal 12 |
For teams already on Drupal 11, landing on 11.5 is the lower-risk move before considering the major version jump. For teams on Drupal 10, waiting for Drupal 12 does not reduce the work. It only shortens the runway, and it adds a version-target trap: "move to Drupal 11" is not precise enough in 2026, because only 11.3 and above lead anywhere.
When Do You Need to Start?
Now, if the site must be live on a supported version before 9 December 2026. As of late August, that is fifteen weeks, and a meaningful share of it is holiday freeze and agency capacity that is already booked.
A realistic sequence for an enterprise Drupal 10 site is: a readiness audit to count custom modules and check contributed dependencies, a scoped upgrade, testing against real traffic, then cutover outside the freeze.
The audit matters because deprecation debt is often the variable that doubles the timeline, and it is what makes a Drupal migration estimate meaningful. Sites moving from Drupal 7 or 9 are rebuilds, not upgrades, and should be scoped separately.
Organizations that finish before Q4 reclaim budget, avoid the demand spike, and enter 2027 ready for Drupal 12. Organizations that start in Q4 will be competing for capacity in the same quarter as everyone else who waited.
Why Should You Count Backward From Your Freeze, Not 9 December?
The deadline most organizations actually work to is not 9 December. It is whenever their change freeze begins, and that is usually weeks earlier.
For nonprofits, the binding date is fundraising rather than holidays. Giving Tuesday falls on 1 December 2026, eight days before Drupal 10 goes end of life, and year-end giving runs through 31 December.
Most fundraising organizations will not accept a platform change inside that window, which moves the real go-live target into late October or early November.
Run the same calculation against 1 November instead of 9 December, and the fifteen weeks above becomes about ten. A Drupal 10 to 11 upgrade generally takes two to four months. A four-month project needed to start in early July.
A two-month project needs to start now. Add partner selection and contracting on top, and for any organization whose procurement requires a formal RFP, the decision point has already passed.
That is not a reason to stop. It is a reason to change what you are scoping. A team that cannot finish before its freeze should be planning a January cutover deliberately, with a documented risk acceptance covering the weeks in between, rather than discovering the same outcome in November with no plan attached.
Find your own freeze date before you scope anything. For most teams, it is the single number that determines whether this is a 2026 project or a 2027 one.
Vardot builds and migrates enterprise Drupal platforms as a Drupal Diamond Certified Partner, with 200+ platforms launched, a 4.9/5 Clutch rating across verified reviews, and standing among the top 20 Drupal contributors worldwide.
Find out what your migration actually involves before scoping the budget.
FAQs
Drupal 10 security support ends on December 9, 2026. After that date, any newly discovered vulnerabilities will not receive patches, leaving sites exposed. For enterprises subject to GDPR, HIPAA, or PCI-DSS, operating on unsupported software crosses from a technical gap into an active compliance risk.
Generally two to four months. The variable that moves the number most is deprecation debt: how many minor releases the site has skipped and how far its contributed modules have drifted from their maintained branches. Drupal 7 and Drupal 9 sites are a different exercise entirely. Those are rebuilds rather than upgrades and typically run seven to twelve months.
An upgrade moves an existing site forward in place, keeping its content, configuration, and custom code. A migration rebuilds the site on a new version and moves content across. Drupal 10 to Drupal 11 is an upgrade. Drupal 7 or Drupal 9 to Drupal 11 is a migration, which is why the timelines and budgets differ by a factor of three or more.
Start with a migration readiness audit, which produces the module and dependency inventory that makes every later estimate meaningful. Run partner selection in parallel rather than after it, because procurement is usually the longest fixed step and the one least under your control. A Drupal 10 to 11 upgrade generally takes two to four months, so a project starting in September can still land before the December freeze windows. One starting in November cannot.
Earlier than December 9 for most organizations. The binding date is the start of your change freeze, not the end-of-life date. Nonprofits running year-end giving are typically frozen from early November, since Giving Tuesday falls on December 1, 2026. Enterprises with holiday code freezes are usually locked from mid-December. Working backward from your freeze rather than from December 9 removes four to six weeks from the available runway.
Industry research shows enterprises spend 60 to 80 percent of IT budgets maintaining legacy systems. Separately, estimates suggest developers lose up to 42 percent of their time, roughly two full workdays per week, managing technical debt.