Need to change, #TYPO3?

(TL;DR)
Dear #TYPO3,

I spoke to a lot of people about you – and they really like you!
Even total strangers start looking your way, because you may be the new cool kid on the block.
Everyone believes you have it all: like this warm sense for community, actually quite a strong build, and brains on top too.

But yet, you seem to be so relucant. You even make a big fuzz about what’s up.

Why so shy, TYPO3? Why do you think you must change?


(long read in the comments)

To Whom It May Concern,
as a follow-up to my previous post, we shall dive into the new world.
Organizations noew are looking for a fresh alternative. They are describing, in procurement documents and agency briefs and CTO conversations, what they need from a new platform. And as they describe it — feature, requirement, reliabilty, ecosystem — what they are describing may be TYPO3. The TYPO3 that exists today, in version 14 LTS, released April 2026.

So what do they want?

Governance
The organizations leaving troubled platforms are not fleeing because of bugs (there are plenty, as we know) or missing features. They are fleeing because they painfully discovered that „Open Source“ does not automatically mean „My Own Choice“. Now, they want a system where decisions are made by many, where fail-safe is not down to one single point of failure.
TYPO3 is governed by the TYPO3 Association: a democratic, non-profit membership organization of many, who elect the board and should set strategic direction. The TYPO3 GmbH is entirely owned by the Association and explicitly prohibited from competing with the agency ecosystem it serves. Decisions are consensus-driven and long-term oriented. The roadmap is published and adhered to. Fail-safe doesn’t end at bugs: it extends to the entire ecosystem.

Security
In one year and one prominent platform alone, over 11,000 new vulnerabilities were identified. The math here is brutal: how could one ever patch along to cover all those bits and holes?
TYPO3 on the other hand is built on a different architectural philosophy. The capabilities that enterprise organizations depend on — multilingual management, multi-site permissions, workflow approvals, access control, media handling, form systems — are built into the Core. Every line of code submitted to the Core is reviewed, by rigid rules, that were agreed upon by best practice, transparency and team consensus – in other words, free from big ego. Security patches are coordinated, and the TYPO3 Association has been officially recognized by the CVE Program as a CVE Numbering Authority. That is not a minor credential. It reflects the maturity of TYPO3’s security governance.
In all of 2024, TYPO3 recorded five security vulnerabilities. Five.
That is not luck. That is architecture.

Scale
One of the most common complaints from organizations running large, complex websites on the troubled platform is that genuine content governance is bolted on rather than built in. TYPO3’s permission system and it’s content structural capacity is Core architecture: the same installation that serves a global enterprise’s 40 country sites can give each national editorial team precisely the access they need and nothing more.
For a public institution, a healthcare organization, a financial services firm, or any regulated enterprise currently searching for a replacement: this is not a feature request. It is a requirement.
And TYPO3 has been doing it, natively, for more than two decades.

Roadmap
The organizations that are most burned right now are the ones that made a strategic platform decision based on market share and community momentum rather than governance structure. They assumed that the platform’s dominance was self-sustaining.
TYPO3’s governance documents are public. The Association’s strategy is published. The GmbH’s mandate — to serve the ecosystem without competing with it — is explicit. The board is elected. The financials are reported to members. The roadmap is written down and followed.
This is not exciting. It is the organizational equivalent of TYPO3’s security architecture to avoid said single point of failure.

Of course, other feats may be to improve. The headless story is developing, as well as the AI editing experience.
And still the overall coverage of the feature lists circulating in management boards and agency briefings is impressive.

So, why do you think you need to be someone else, TYPO3?
This is the question I want to leave with the TYPO3 community.

When reading the list of what new prospects are looking for, it compares to what TYPO3 already is.
The instinct in our community — and we’ve all been there — is to respond to a strategic opportunity by asking what we need to build, what we need to change, what we need to become. That instinct is not wrong. TYPO3 should keep improving.

TYPO3 has spent the last twenty years building something that is genuinely hard to build. Democratic governance. Architectural security. Enterprise-grade Core capabilities. A community that keeps showing up.

The question is not what we need to change.

The question is: what are we afraid of?