How to Choose a CMS When You've Outgrown a Website Builder
At 100 to 200 people the question stops being which CMS is best. It becomes who edits, who deploys, who signs off on security, and where the thing is hosted.
Once several people are publishing, a developer or agency is in the loop, and somebody has to sign off on security, a top five list of content management systems stops being useful. Every platform on it can build a website. The question is which one survives your organisation.
Four questions decide it. Answer them before you look at a feature comparison, including this one.
1. How many people edit, and how much can they break
Count the people who will publish without asking anyone. If it is two, almost anything works. If it is fifteen across three teams, you need permissions that actually restrict, templates that constrain layout, and a review step before publish.
This is the question that most often overrules everything else, because the cost of a marketing team that cannot publish without a developer is paid every week, forever.
2. Who deploys a change, and how long does it take
There is a real difference between a platform where a content editor changes a page in the browser and it is live, and one where a change goes through a build and a deploy. Neither is wrong. One suits a team that ships copy daily, the other suits a team that wants review gates and version control.
Ask how long a one line copy fix takes, end to finish, in the setup you are being sold. If the answer involves a developer and a release window, make sure everyone who publishes knows that before you sign.
3. Who reviews the security of it
On a hosted platform, most patching is the vendor's problem. On a self hosted open source platform, it is yours, and it is a standing job rather than a launch task. Every plugin you install is code you are trusting and code someone has to keep updated.
Two things to have ready when your IT or risk person asks. The Essential Eight from the Australian Signals Directorate is the framework they will most likely reference, and patching is a large part of it. And every form on your site collects personal information, which puts the CMS squarely inside APP 11 of the Australian Privacy Principles: take reasonable steps to protect personal information from misuse and unauthorised access. A CMS with an unpatched form plugin is that obligation going unmet, and nobody thinks of the website when they audit for it.
4. Where is it hosted
Almost no CMS comparison mentions hosting region, and it is one of the few questions with a concrete answer.
Ask which region your content and your form submissions sit in. For an Australian business, hosting in the AWS Sydney region, ap-southeast-2, gives you shorter round trips for Australian visitors and a simpler answer on data residency. If the platform hosts your data overseas, that is not automatically a problem, but APP 8 covers cross-border disclosure of personal information and you should know the answer before you are asked it rather than after.
The shortlist
HubSpot Content Hub
HubSpot's CMS, previously called CMS Hub. It fits when the site's main job is marketing and you already run HubSpot, because the pages, the forms, the contact records and the reporting are the same system rather than four connected ones.
What you get: thousands of free and paid templates in the marketplace, drag and drop modules for editors, smart or dynamic content for showing different content to different visitors, a globally hosted CDN, a built in web application firewall and 24/7 threat monitoring. The security posture is largely HubSpot's problem rather than yours, which is the main argument for it at this size.
What to watch: HubSpot uses its own templating language, HubL, so your developers are learning something that is not transferable. It is not built for e-commerce. And it is an all in one platform, so on any single dimension you can find something more specialised.

There is a direct comparison in HubSpot CMS versus WordPress, a fuller breakdown of what Content Hub includes and who it fits, and if you are weighing it against assembling your own set of tools, Content Hub against a standalone CMS and tool stack.
WordPress
The most widely used CMS in the world, running around 43 per cent of all websites. Over 57,000 plugins in the official directory and roughly 31,000 themes, which is both the reason to pick it and the reason it goes wrong.
It fits when you want maximum flexibility, you have or can hire people who know it, and you are willing to own the maintenance. Editors find it familiar, which is worth more than it sounds.
Wondering if your current CMS is the problem?
Most people inherited their CMS from whoever built the last site.
What to watch: you own the patching, for core, themes and every plugin. Page performance is a function of what you install, and a site with thirty plugins is slow for reasons nobody wants to investigate. Free to download is not free to run, since you pay for hosting, the domain, and any premium theme or plugin you depend on.
A headless setup
Content lives in an API-driven CMS, the front end is built and deployed separately. It fits when you have a development team, more than one place the content has to appear, and a real reason to control the front end.
What to watch: the editing experience is not included. In a traditional CMS the preview and the page builder come with it. In a headless build, somebody has to design and pay for the way your marketing team sees a page before it goes live, and teams that skip that step end up with editors who will not touch it.
Drupal
Built by developers for developers. Highly configurable modules and themes, and it handles large amounts of content and traffic well. To use it properly you need PHP, HTML and CSS, so a developer or an agency is not optional.
Security is a strength relative to other open source options, with the project releasing security and bug fix updates monthly, but somebody still has to install them. If nobody in your organisation can code, this is the wrong answer.
Joomla
Sits between Drupal and WordPress. More built in features than most open source options, including multilingual pages and heavier user management, plus over 6,000 extensions.
What to watch: the learning curve is steep for a non technical editor, extensions can be awkward to install and manage, and while there is a 13 member security team releasing patches, there is no built in automatic updating. That means known vulnerabilities stay open on your site until someone remembers, which is the pattern attackers rely on.
Shopify
Different category. If the site's actual job is selling products, this is a commerce platform with content attached rather than a CMS with a shop bolted on. It handles its own backups, updates and PCI compliance, and there are themes and apps for the rest, including connecting to HubSpot.
What to watch: much less control over code and layout than the others, and the content side is thinner. Plenty of businesses run Shopify for the store and something else for the marketing site, which is a perfectly reasonable answer.
What it will cost
Published list prices move constantly, so get a current quote rather than trusting a comparison article. What is stable is the shape of the cost, and it has five parts:
- Licence or subscription, which is zero on the open source options and the headline number on the hosted ones
- Hosting, which is the reverse
- Build, meaning developer or agency time, and the largest single line on Drupal and on anything headless
- Plugins, themes and extensions, individually small and collectively not
- Ongoing maintenance, meaning patching, updates and the person who does them
A platform that looks free usually moves the cost into the last two, where it does not appear in the business case and does appear in someone's week.
The cost nobody budgets for
Migration. Moving a site of any size means content, URLs and redirects, templates rebuilt, forms and their integrations reconnected, and analytics history that will never quite line up again.
That is the real argument for taking these four questions seriously now. You are not choosing the best CMS. You are choosing the one you will not have to leave in three years.
Where to start
Write down the answers to the four questions above, in your own words, before you take a single demo. Then make every vendor answer them. The platform that gives you clean answers to who edits, who deploys, who patches and where it is hosted is usually the right one, whatever the feature grid says.
Torn between HubSpot and WordPress?
Whichever way you go, you live with it for about five years.
Making that call, and then running the build, is what our Operating Systems and Websites work is. If you are stuck between two options, tell us who edits and who deploys and that will narrow it fast.