What to verify before adopting LocalGov Drupal
Six checks matter before a council adopts LocalGov Drupal: code custody, the governing company’s finances, contracted security patching, accessibility accountability, whether named councils actually have live sites, and the procurement route for the build contract.
Most of the answers sit in a public record or a supplier’s contract. One only comes from a digital lead at a council that has already migrated. Some of the six belong to the project itself and others to the supplier you appoint. Accessibility stays with the council whatever it buys.
Disclosure: AxisTwelve builds on the platform and appears on the project’s Certified Supplier Directory, which is one of the things this piece tells you to discount.
What LocalGov Drupal is and who runs it
LocalGov Drupal is an open-source Drupal distribution and community for council websites. The project describes its operating principle as “run by councils for councils”.
The case for adopting it is real. Content types, components and accessibility work arrive already built and tested by other councils, and the cost of that work is carried once across the group. For a council weighing a shared distribution against a bespoke build, that is the argument in favour.
Governance runs through four groups: a Product Group over the roadmap and user research, a Technical Group over technical direction and security review, the Open Digital Cooperative Board over financial sustainability, and a Core Team over day-to-day operations. This is the project’s account of itself, worth labelling as such in a business case.
The legal entity is Open Digital Cooperative Ltd, company number 14532300, incorporated on 9 December 2022 as a private company limited by guarantee and currently active. The project name and the contracting entity name are not the same, and procurement paperwork and any conflict of interest declaration need the company name.
Code custody if the cooperative fails
The code is open source, so an existing installation does not stop working if the organisation behind it does. What the licence does not protect is the roadmap and the coordinated security review, and the risk to weigh is a supplier market that drifts into private forks.
Ask where the canonical repository sits and who holds administrative rights over it. Ask what your supplier would do if upstream releases stopped, and get the answer in the contract rather than in a pitch.
An asset lock in the cooperative’s constitution is a claim repeated in secondary coverage. That has not been confirmed against a primary source. Read the articles of association filed at Companies House, which is the document that settles what happens to assets on dissolution.
What the governing company’s finances show
MHCLG’s Local Digital Fund paid for the build in stages. Discovery received £75,000 and alpha £100,000. Beta was funded in three rounds of £150,000, £275,000 and £400,000, the last of them awarded in December 2021.
That comes to roughly £1m across discovery, alpha and beta, which is arithmetic on the published grant figures rather than a number the fund itself has published. No further Local Digital Fund award to the project appears in the published grant records after December 2021.
The most recent filed accounts cover the year ending 31 December 2024, and the next are due by 30 September 2026. A council running diligence in the second half of 2026 is reading accounts that closed more than eighteen months earlier. Note the date in the risk register, and let it set how much roadmap a five-year business case assumes.
Who is contracted to apply security patches
The LocalGov Drupal Technical Group runs security reviews as a community process, and a community process carries no service level. The response window and the remedy for missing it belong on the supplier you contract with, out of hours included.
Establish in writing who applies patches, how quickly a critical advisory is acted on, whether contributed modules are in scope, and who pays when a patch breaks a customisation. A supplier that has done this before will have a patch history it can show you.
Adopting LocalGov Drupal does not discharge the accessibility duty
The duty is set by the Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, SI 2018/952. Regulation 9 names no version of WCAG. It refers to the guidelines as amended from time to time, which is how the required standard moves without anyone amending the legislation.
In practice the enforced standard is WCAG 2.2 level AA, monitored by GDS and enforced by the Equality and Human Rights Commission. The accountable body throughout is the council.
A resident renewing a garden waste subscription on a four-year-old Android phone, with text scaled up and a screen reader running, either finishes the form or rings the contact centre. The distribution supplies the components. The form logic and the tested journey decide which of those two things happens.
Ownership of the accessibility statement belongs in the contract, along with the testing cadence after launch and responsibility for legacy content. Testing built on automated scans alone will pass pages a screen reader user cannot complete.
Listed as a member, or running a live site
The homepage and the community page both refer to more than 50 councils, while the Our Councils page names 38 and states that not all of them have launched a site yet. Treat those 38 names as a list to check rather than a count of live sites.
Being listed as a member council can mean a live site, a partial migration, a paused project or an intention. Take two names off any list you are shown and ring their digital leads before the shortlist closes.
The procurement route for the build contract
The contract for a build and ongoing support is held by a supplier you appoint and procure yourself. It is procured through Digital Outcomes and Specialists 7, RM1043.9, or another compliant route.
DOS 7 is further competition only, with no direct award, so the timeline for a website replacement includes publishing a requirement and running an evaluation. Settle the route before the technology decision reaches cabinet, because it sets the dates everything else hangs off.
Questions to put to a supplier
- Continuity. What happens to our installation and our roadmap if upstream releases stop, and where is that written down?
- Patching. Who applies security patches, within what window for a critical advisory, and what is in scope?
- Accessibility. Who owns the accessibility statement, and what testing is included at launch?
- Customisation. Which requirements need bespoke work, and how does that work survive an upgrade?
- Exit. What does a handover to another supplier look like, and what do we own at the end of the term?
- Cost. What is the annual cost of hosting, support and upgrades after year one?
The Certified Supplier Directory is part-funded by the suppliers on it
The project runs a Certified Supplier Directory listing 18 suppliers. The directory page states that certified suppliers have worked with a council or Open Digital Cooperative, and that they pay to help fund the LocalGov Drupal project and contribute their time and expertise. It is a community certification combining delivery experience with financial contribution. Read it as evidence of involvement with the project and assess technical capability separately, through references, security certifications and the supplier’s record on comparable builds.
AxisTwelve appears on that directory and has delivered on the platform for the London Boroughs of Bexley, Lambeth and Merton.
Where to start
Pull the Companies House record and the articles of association before the first supplier conversation, so you ask the custody and finance questions already knowing the answers. Book the reference calls early. A digital lead at another council will tell you more in twenty minutes than a fortnight of desk research.
Frequently asked questions
How many councils use LocalGov Drupal?
The project’s own figure is more than 50 councils involved at some level. Its Our Councils page names 38 publicly and adds that not all of them have launched a site. Because involvement and a live site are counted differently, confirm whether a named authority is a member or has a site actually running.
Who owns and governs LocalGov Drupal?
The contracting entity is Open Digital Cooperative Ltd, company number 14532300, incorporated on 9 December 2022 as a company limited by guarantee. The project sets out four governance groups, covering roadmap, technical direction, financial oversight and daily operations. Contracts and conflict of interest declarations need the company name, which is not the name the project is known by.
Does adopting LocalGov Drupal make a council website legally accessible?
No. The duty rests on the council under the Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, SI 2018/952. The enforced standard is WCAG 2.2 level AA, which GDS monitors against and the Equality and Human Rights Commission enforces. No content management system discharges that duty.
References
- Companies House, Open Digital Cooperative Ltd, company number 14532300, company record and filing history, accessed 4 August 2026
- Local Digital Fund grant records for LocalGov Drupal discovery, alpha and beta, localdigital.gov.uk, accessed 4 August 2026
- LocalGov Drupal project website: governance, community, Our Councils and Certified Supplier Directory pages, accessed 4 August 2026
- Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, SI 2018/952, legislation.gov.uk, accessed 4 August 2026
Government Commercial Agency agreement page for Digital Outcomes and Specialists 7 (RM1043.9), accessed 4 August 2026