Enterprise WordPress at scale

What changes when WordPress has to work at enterprise scale.

Enterprise is not a bigger website. It is more people with different permissions, more systems that have to agree with each other, and a procurement process that asks questions a brochure cannot answer. This page is about those three things.

Multisite, security review, accessibility and integration, treated as the work rather than as extras
Estate · 14 sites one network, four teams
group.example.com Comms · 4 publishers Production
careers.example.com HR · 2 publishers Production
ir.example.com Legal approval required Locked
de.example.com Launching Q3 · 1 editor Staging

Roles, approvals and release windows per site. One login, one audit trail, and a legal hold that actually holds.

Most pages that sell enterprise WordPress describe the same site everyone else builds and add the word enterprise to it. The difference is not size. A site with two hundred thousand visitors and one editor is a normal WordPress build. A site with twelve thousand visitors, four publishing teams, a legal hold on one section and an SSO requirement is an enterprise one.

Everything below is what actually changes, and what tends to be missing from the estimate when it does.

What actually changes

Six things that are different at enterprise scale.

01

Governance, before features

Who can publish, who approves, and what happens when the person who approves is on leave. At enterprise scale the roles matrix is the architecture, and getting it wrong is what turns a CMS into a ticket queue.

Roles and approvals modelled before anything is built.

02

One network or separate installs

Multisite shares users, plugins and a release cycle across every site. Separate installs isolate risk and let teams move independently. The right answer depends on whether your teams want to move together or apart, and it is expensive to reverse.

A decision made on how your teams work, not on what is easier to build.

03

Editorial workflow that survives a launch

Drafts, review, legal sign-off, embargoes, scheduled campaigns across regions. Stock WordPress gives you draft and publish. Everything between those two is a build.

The workflow your comms team already runs, in the CMS rather than in email.

04

Uptime, incidents and who is on call

Monitoring that pages a person, a runbook they can follow at 2am, and a rollback path that has been tested rather than assumed. Procurement will ask about all three.

An answer to "what happens when it breaks" that is not "we look at it".

05

Security review and procurement

The questionnaire, the penetration test, the dependency policy, the data processing agreement. This is often the longest part of an enterprise engagement and it is almost never in the estimate.

The review handled as part of the work, not discovered halfway through it.

06

Accessibility and data residency as constraints

WCAG 2.1 AA designed in costs less than AA retrofitted after an audit. Where the data physically lives is a procurement question in the EU and a contractual one nearly everywhere.

Constraints shaping the build from week one instead of blocking the launch.

WCAG AA

the conformance level we design, build and verify to on enterprise work

Automated checks in the build, manual keyboard and screen-reader passes before launch, and a written conformance statement you can hand to a reviewer.

The part nobody else writes

When WordPress is the wrong answer.

01

The core need is an application, not content

If most of what users do is transact, calculate or manage records, you are describing an application with a marketing site attached. WordPress can host the second thing. Building the first inside it is how teams end up rewriting in year two.

We would build the application in Laravel and let WordPress do content.

02

Your content model is genuinely relational

Deeply interlinked records with real referential integrity are not what a post table is for. You can force it with custom tables and enough code, and then you own that code forever.

Honest answer: a different data layer, with WordPress in front of it.

03

You already have a DXP that people use

If Sitecore or Adobe is bought, deployed and adopted, replacing it to save licence cost rarely pays back once migration and retraining are counted. Being told this by an agency that sells WordPress is worth something.

We will say so rather than quote for the replacement.

What it costs

What an enterprise engagement costs depends on the estate, not the page count.

Two organisations with the same number of pages can differ by a factor of several, because the cost sits in governance, integration and review rather than in templates. These are the things that move it.

What moves the number

  • How many sites, and who governs them One team running fourteen sites is a different build to fourteen teams running one each. The roles matrix drives more of the estimate than the design does.
  • How many systems it has to talk to SSO, CRM, DAM, ERP, translation, analytics. Each integration is scoped by the system on the other end and how much of it you control, which is often not much.
  • The review bar, and who sets it A vendor security questionnaire is a known quantity. A penetration test with remediation, a formal accessibility audit and a data processing agreement are their own workstream.
  • Editorial workflow depth Draft and publish is standard. Multi-stage approval, legal holds, embargoes and coordinated regional releases are a build in themselves.
  • What the migration is moving Legacy estates are always larger and less consistent than the inventory says. The content that has to survive, and the URLs that must keep resolving, decide the size of this.

A single site with a heavy review process and a fourteen-site estate with a light one can land in the same place, which is why page count is the least useful number you can give us.

Rough idea to delivery

  1. You send the details What you want built, roughly, plus budget range and timing. The form asks for all of it
  2. Within 4 business hours We read it and reply. Nothing is scheduled before we know what it is about
  3. Then the call Free discovery, booked once there is enough on the table to make it worth your hour
  4. Within 48 hours of the call A written fixed-price quote you approve before anything starts
Get an estimate

Quick enquiry

Tell us about the estate.

The three things that shape the answer are how many sites there are, what they have to integrate with, and what your review process looks like. A rough version of those three is enough to get a real reply.

Prefer the full form? Start a project

No drip sequences, no marketing list. We reply and that is it.

Common questions

Frequently asked

  1. Is WordPress actually enterprise-grade?

    It runs a large share of the web including newsrooms, government departments and listed companies, so the question is not whether it can be. It is whether the build treats governance, workflow, security review and integration as first-class work rather than as things bolted on after the design is signed off. That is what separates an enterprise WordPress build from a big small one.

  2. Multisite or separate installs?

    Multisite when your sites share users, brand and a release cycle, and when one team can own the plugin set. Separate installs when teams need to move independently, when risk must be isolated, or when one site has a compliance profile the others do not. It is an expensive decision to reverse, so we make it in discovery with the people who will actually run the sites.

  3. Can you handle our security review?

    Yes, and we scope it as part of the engagement rather than treating it as an interruption. That covers the vendor questionnaire, dependency and patching policy, access control and audit trails, coordinating a third-party penetration test, and remediating what it finds. Tell us early which framework you are being assessed against, because it changes the architecture rather than just the paperwork.

  4. What about accessibility?

    We design and build to WCAG 2.1 AA, with automated checks in the build, manual keyboard and screen-reader passes before launch, and a written conformance statement you can hand to a reviewer. Retrofitting AA after a procurement review flags it costs considerably more than designing to it, which is the main reason to raise it in week one.

  5. Can you work with our existing hosting and procurement?

    Usually yes. We have shipped onto client-mandated platforms, private cloud and the managed WordPress hosts. Where hosting is already contracted we build to it. Where it is genuinely the constraint on what you are trying to do, we will say so and show you why rather than quietly working around it.

  6. What does an enterprise engagement cost?

    It is scoped after discovery, because the number is driven by how many sites there are, how many systems they integrate with, and how heavy the review process is, rather than by page count. Tell us those three things in the form below and we will come back with a written fixed-price quote. There is no rate card on this page because a figure without your scope behind it is decoration.

Running WordPress at enterprise scale?

Tell us what the estate looks like.

Discovery call is free, and it happens after we have read what you sent rather than before.