NASCIO State IT Tensions Highlight Governance Questions for Shared Drupal Platforms
State chief information officers face five recurring tensions as they fund and govern technology modernisation. A 16 September 2026 report from the National Association of State Chief Information Officers (NASCIO) and Forrester draws on the 2026 State CIO Survey, which received responses from 51 state and territory CIOs, and interviews with 19 CIOs. The report identifies the First Mover Penalty, Planning Trap, Funding Cliff, Local-Global Divide and Trust-Authority Balance, and argues that none has a permanent solution.
Government web estates put several of those tensions into routine decisions about shared infrastructure. A common content management system can move security, accessibility standards, design systems, platform upgrades and other technical responsibilities towards a central service while agencies retain responsibility for their own missions and content. Georgia's GovHub and Australia's GovCMS provide two Drupal-based examples of governments distributing those responsibilities across shared platforms.
The Georgia Technology Authority publicly lists GovHub as powering 86 state websites and serving more than 40 million users annually. In episode 571 of Talking Drupal, Jasmyne Epps, director of GovHub at the Georgia Technology Authority, described the platform as supporting more than 90 sites through a Drupal multisite architecture with a shared codebase and separate site databases.
That architecture turns common maintenance into platform-level work. In the Talking Drupal discussion, Epps described security patches and common platform changes as work that can be applied through the shared codebase rather than commissioned separately for each participating website. Agencies do not independently add Drupal modules or other capabilities; they can request features, while the central team evaluates additions against their wider usefulness and the maintenance responsibility they would create.
Agency input is built into that centralised product model. Georgia's GovHub Advisory Committee includes agency participants who help generate ideas and prioritise features and fixes, while individual agencies remain responsible for the accuracy and management of their own information. A Georgia case study on structured content and flexible layouts makes the same distinction, describing agency partners as the subject-matter experts for their content even when the underlying publishing technology is shared.
Georgia also leaves room for agencies outside GovHub. GTA provides website and content services beyond the shared CMS, while the state's Orchard Design System can be used to maintain greater consistency across the wider digital estate. Accessibility follows a similar division: common platform tooling and standards can provide guardrails, but agency editors remain responsible for the accessibility of content created and changed each day.
Those arrangements give NASCIO's Local-Global Divide a practical form. Georgia centralises infrastructure, common functionality, design and accessibility guardrails, and part of the product roadmap while leaving agencies responsible for their information and allowing some websites to operate outside GovHub. The advisory process also illustrates the Trust-Authority Balance: agencies can influence the shared product without independently controlling its technical architecture.
GovHub also shows how centrally maintained technical work can become common infrastructure. A security patch or platform improvement applied through the shared system can benefit many participating sites rather than being implemented repeatedly. That does not eliminate NASCIO's First Mover Penalty, but it provides a mechanism through which centrally adopted work can create value across a wider group of agencies.
Australia's GovCMS documentation provides another example of shared investment becoming reusable capability. GovCMS notes that Drupal carries no CMS licence fee, although agencies can incur costs for custom code, modules, templates and designs. It also says a newly funded module or design can subsequently become available to other GovCMS agencies and Drupal users. That model can spread the value of an initial development investment even when one organisation funds the work first.
The reuse operates across a substantial government service. GovCMS currently lists 399 live websites and 126 participating organisations, and its documentation says the cost of running and hosting websites can be spread across more than 100 departments and public-sector organisations. Australia's Department of Finance describes its wider whole-of-government ICT and digital services as mechanisms for reuse, cost avoidance, consistent user experiences and economies of scale.
Open source does not remove the recurring costs of operating that shared service. GovCMS charges organisations annually for its Software as a Service and Platform as a Service offerings, with SaaS pricing largely tied to monthly page views. When prices increased from 1 November 2025, GovCMS said rising costs for technical specialists, platform engineers and cybersecurity tools had to be reflected in agency pricing because the programme is fully cost recovered.
Georgia likewise maintains recurring platform costs. GTA says GovHub onboarding is billed according to project hours, while subscription and hosting contracts are priced according to the amount of content hosted and annual traffic. Open-source software can remove proprietary CMS licence fees, but the government services built around it still require funding for hosting, maintenance, security, development and support.
That distinction matters for NASCIO's Funding Cliff, which describes capabilities or expectations created with temporary funding that remain after the original funding source expires. GovCMS does not show that the tension disappears under a shared open-source platform. Its cost-recovery model instead demonstrates one way recurring hosting, security, maintenance and support costs can be made explicit and assigned to an ongoing service.
The Drupal examples do not map equally to all five NASCIO tensions. Neither GovHub nor GovCMS provides direct evidence that a shared CMS resolves the budget-cycle constraints behind the Planning Trap, and platform architecture alone does not settle wider questions of technology investment governance. The stronger evidence concerns how governments allocate common capabilities, preserve different levels of agency control, reuse development and fund recurring platform operations.
For government web estates, a shared-platform decision therefore reaches beyond the choice of CMS. It affects where standards are maintained, how common improvements reach participating sites, which capabilities can be reused across agencies and how ongoing costs are distributed. NASCIO's five tensions provide a useful framework for examining those decisions without treating centralisation, open source or Drupal as a permanent solution to the underlying trade-offs.
References
-
State Government IT Investment Management: 2026 State CIO Insights and Recommendations, National Association of State Chief Information Officers (16 September 2026)
-
Website Services, Georgia Technology Authority
-
Structured Content and Flexible Layouts, Georgia Technology Authority
-
What We Learned From the GovHub Listening Tour: Wins, Woes and Wishlists, Georgia Technology Authority (28 July 2026)
-
