The roadmap contained herein consists of good-faith release estimates on a month-by-month basis. However, none of the dates should be considered hard commitments.
Q3 is closing, and we are excited to finish up 2026 with a strong set of features to close out the year! The first half of the year was about proving the direction; this quarter was about landing it — a modernized authoring stack in customers' hands, AI that enterprise security teams will actually approve, and the first working agent inside dotCMS. The five themes from June still hold:
Content Management for Humans — getting content to market faster
AI Accelerated Governance — AI the enterprise can actually trust
Agentic Readiness — preparing for an agent-driven web
Content Optimization — proving content works with data
Scalable, Flexible Cloud Infrastructure — resilient and evergreen
Here's where each stands heading into Q4.
Content Management for Humans
The goal hasn't changed: get the right content to market faster, without a developer ticket for every change. What changed in Q3 is that these pieces stopped being previews and started being the default experience.
Live today:
Block Editor v3 — The editor rebuild shipped: a sticky top toolbar that behaves like Google Docs or Word, focus mode, a redesigned asset selector with folder filtering, and better search. This was the round content teams asked for most directly.
Content Drive — Search and Add Content — Search forms are now generated from each content type's own fields, so you filter on the attributes that actually matter, and authors can create content and drop assets without leaving the file-browser view.
A modernized admin — ES Search, Query Tool, Velocity Playground, and the Publishing Queue are rebuilt in Angular, with the new Users portlet in beta. Less legacy UI, more consistency.
Landing as Q3 closes:
Content Drive — Workflow Actions — Trigger workflow actions on one asset or hundreds, with only valid actions surfaced when a selection spans content types or workflow steps, and a preview before anything runs. This is what turns Content Drive from a better file browser into a content operations surface.
Content Drive — Search and Performance at Scale — Find any asset in repositories holding millions of files, with pagination that keeps up. Enterprise DAM scale, not demo scale.
Edit Content — The new Angular editing screen consolidates workflow actions, locking, locale management, version history, and comments into a single side panel, across traditional and headless environments.
Asset Picker — One reusable picker for every place you select an asset — relationship fields, image fields, binary files, the Block Editor, folder selectors — instead of five slightly different ones.
The New Content Drive
Coming in Q4:
Permissions UI — A redesign that makes permission effects visible and predictable before you save: clear inheritance indicators, impact previews, and conflict detection. Permissions is one of the loudest items in our feedback inbox.
Configuration and Maintenance portlets — The last major Dojo screens — system settings, licensing, cluster monitoring, cache and index management, logs, and system jobs — rebuilt in Angular, closing out the modernization program.
AI Accelerated Governance
AI in the CMS only matters if it runs on infrastructure your security team already approved. dotAI now runs on the provider and model you choose — proven end to end this quarter by an enterprise insurance customer who completed a full proof of concept on their own deployment, covering chat, semantic search, and image generation. Q3 puts real configuration and security controls around that foundation, and Q4 extends the governance layer further: full admin visibility into AI activity, editor-facing transparency into what AI does inside workflows, and an agent that catches quality and compliance issues before publish.
Live today:
dotAI Multi-Provider Support — Azure OpenAI, AWS Bedrock, and Google Vertex AI are shipped alongside OpenAI, and embeddings now run on OpenRouter as well — multi-provider now covers semantic search, not just generation. If your AI governance policy blocked dotAI before, it very likely doesn't anymore.
Automated WCAG Accessibility Checker — WCAG 2.1 AA scanning on the Axe engine, catching issues before content goes live.
The WCAG Accessibility Checker
Landing as Q3 closes:
dotAI Provider Configuration UI — A real settings screen: pick a provider per capability, fill in the fields it needs, and test the connection before you save. Multi-provider support stops being a properties-file exercise.
dotAI Security Hardening — RAG permission enforcement, output safety, and abuse controls. Semantic search should never surface content a user isn't allowed to see; this makes that a guarantee rather than an assumption.
The new dotAI Configuration Screen for Multi-provider support
Coming in Q4:
dotAI Admin Observability and Governance — Usage dashboards, real-time activity feeds, error tracking, and audit trails for compliance reporting.
dotAI Workflow Visibility and Feedback — Show editors what an AI action will do before a workflow runs and what it did afterward, with the ability to review and correct the output. No more black box.
Content Quality Agent — An agent that watches content during editing and surfaces quality issues — missing metadata, SEO gaps, compliance problems — before publish rather than after.
Agentic Readiness
This is where the roadmap moved most. In June we were just getting started, now we have the platform and capabilities are exploding!
Live today:
The @dotcms/ai agentic runtime — dotCMS as a runtime your AI operates, not just an API it calls. It carries out multi-step content tasks while staying inside the rules you set: it touches only what you allow, saves changes as drafts for a person to review and publish, and never holds your credentials. Run it against your own model or gateway.
Landing as Q3 closes:
dotCMS MCP Server v2 — The agent-operable CMS. Connect Claude, Cursor, or any MCP client and use natural language to create content types, build pages, manage workflows, and publish — across the full hybrid-CMS surface, governed by the same role-based permissions you already trust. v1 was a read-oriented beta; v2 is the whole platform.
The Accessibility Fix Agent — Our first agent. It scans a page for accessibility problems, fixes them in the template and stylesheet code, and saves the result as a working version for a human to review and publish. It's merged and running end-to-end inside dotCMS. To be precise: the architecture is proven, and packaging, cost controls, and data-residency work are what's left before it's something you turn on.
Coming in Q4: the agentic work becomes a product question rather than a platform one — what the offering is, who it's for, how it's packaged. Every agent that follows the accessibility one — GEO, SEO, migration, site building — sits on the same foundation, which is exactly why we built the foundation first.
Content Optimization
Getting content live is half the job; knowing whether it works is the other half.
Live today:
Native Content Analytics — Page views, conversion events, and GA4-style engagement and bounce metrics from one native event stream, with no third-party tag. The global infrastructure layer underneath it was completed in Q2, which is what makes the rest of this section possible. This is in Early Adopter phase now and is targeted for GA late this year.
Page Health — GEO Scanner — Runs against any page's rendered HTML and returns a 0–100 readiness score across four categories — Citability, Structured Knowledge, Content Authority, Discoverability — with prioritized fixes. Built for a web where AI answer engines are a distribution channel, not an afterthought.
Content Analytics: Site Engagement Dashboard
Landing as Q3 closes:
Analytics Query API — Query your analytics data by metric and dimension through one consistent REST API: the same data behind the dashboard, available to your own tools and BI stack. The in-product dashboard now runs on this API too.
Experiments: A/B Testing v2 — A new experiment management UI, first-party conversion data from dotCMS Analytics rather than a bolted-on tool, and consistent behavior across traditional and headless front ends. Headless A/B testing has been a real gap; this closes it.
Scalable, Flexible Cloud Infrastructure
Enterprises run mission-critical sites on dotCMS. This track is about resilience, transparency, and staying evergreen without surprises.
Live today:
Evergreen Release Tracks — Customers now choose their own upgrade window instead of absorbing whatever cadence we set, with automated daily promotions and per-environment track selection behind it. This was the loudest single piece of feedback we received all year, and it's live for cloud customers.
Multi-Region Resiliency and DR — Multi-region dotCMS Cloud with US-East/US-West failover is generally available, and existing multi-region customers have been migrated onto the new infrastructure — geographic redundancy, business continuity, and US data sovereignty for compliance-led enterprises.
In-App Usage Dashboard — Evergreen cloud customers can see the site and content-type usage that drives their pricing, directly in-app.
In-App Usage Dashboard
Landing as Q3 closes:
OAuth Support — OAuth 2.0 and OpenID Connect for enterprise SSO with Okta, Azure AD, and Google Workspace, consolidating our separate SSO and MFA work onto modern identity standards.
OpenSearch 3.x — Rollout 1 — A zero-downtime phased migration off OpenSearch 1.0 using dual writes, shadow reads, and gradual traffic migration — the kind of work nobody notices when it goes right.
New dotAuth Configuration Screen
Coming in Q4:
Rollback and Database Versioning — Roll content and configuration back to a previous state, giving teams a real safety net for accidental changes.
Looking Ahead
What stands out about 2026 in hindsight is how much the AI story changed underneath us mid-year. In January, "AI in the CMS" meant generation features. By Q3 it meant an agent that operates the platform on your behalf, governed by the permissions you already configured. We spent much of the quarter building that foundation.
The constant is direction, not dates: a modern editing experience that gets content to market faster, AI that enterprises can actually govern and trust, readiness for an agentic web, analytics that prove content works, and cloud infrastructure that stays resilient and evergreen.
We'll keep this updated as the year closes out. As always, feedback is welcome and appreciated!