Conference Description
Key Takeaways
- Four-day conference for the Drupal open-source community, held in Rotterdam
- Security content addresses secure coding, vulnerability disclosure, patch management and supply-chain risks in contributed modules
- Compliance sessions cover GDPR, NIS2 and accessibility requirements
- Relevant for developers, site builders, designers, marketers and decision-makers working with Drupal in government, education and enterprise environments
About the Event
DrupalCon Rotterdam 2026 is the flagship annual gathering for the Drupal open-source community. The four-day programme includes keynotes, technical sessions, hands-on workshops, contribution sprints and networking opportunities. Drupal powers high-profile websites across government, education and enterprise sectors, making security a persistent concern for organisations that rely on the platform.
Security and Development Topics
Security content runs throughout the conference programme. Sessions and workshops are expected to address secure coding practices, the processes of the Drupal Security Team, coordinated vulnerability disclosure and rapid patch management. Supply-chain security will feature prominently, with discussions on risks associated with contributed modules and dependency management using Composer.
Technical sessions will also examine protecting APIs and headless architectures, reflecting the growing adoption of decoupled Drupal implementations. Infrastructure topics include zero-trust hosting models, web application firewalls and automated security update workflows. Incident response planning is another area of focus for teams responsible for maintaining Drupal deployments.
Compliance and Regulatory Context
The conference connects technical security practices to legal and operational requirements. Sessions will address GDPR obligations, the NIS2 Directive and accessibility standards. These compliance topics are particularly relevant for organisations in regulated industries or those operating across European jurisdictions, where security controls must align with broader governance frameworks.
Contribution Sprints
Contribution sprints provide opportunities for attendees to work directly on the Drupal codebase. Security-focused sprints may concentrate on fixing vulnerabilities, improving test coverage and strengthening the security posture of contributed modules.
Who Should Attend
DrupalCon Rotterdam 2026 is designed for developers, site builders, designers, marketers and decision-makers involved with Drupal projects. Security and compliance content will be valuable for teams responsible for government, education and enterprise websites where data protection, regulatory compliance and operational resilience are priorities.

