Self-hosted vs SaaS CMS
The choice between running a CMS on infrastructure you control and using one delivered as a managed service by a vendor. It decides who patches, who scales, who owns uptime, and where your data lives.
Self-hosted and SaaS describe two ways of running a CMS. A self-hosted CMS runs on infrastructure you control, whether your own servers or a cloud account in your name, and your team is responsible for operating it. A SaaS CMS, software as a service, is delivered by a vendor as a managed online service: you use it over the internet and the vendor runs the machinery behind it. The choice is less about the software’s features than about who does the work of keeping it running.
Who patches, who scales, who owns uptime
In the self-hosted model those responsibilities sit with you. When a security patch is released, your team applies it. When traffic grows, your team provisions capacity. When something breaks at two in the morning, it is your team that owns getting it back. The gain is control: you decide the hosting, the upgrade timing, the configuration, and no third party can change the service underneath you.
In the SaaS model the vendor carries those duties. Patching, scaling, and uptime are theirs to manage, and updates arrive without your involvement. The gain is that you are not operating infrastructure; the cost is that you accept the vendor’s choices about when things change and how the service runs, with less ability to alter them.
Where the data lives
The models also differ in where content is stored. Self-hosting keeps the data in infrastructure you control, which lets you decide its location, relevant when rules such as the GDPR constrain where personal data may be held. With SaaS the data sits in the vendor’s systems, so those questions become a matter of the vendor’s terms and regions rather than your own configuration.
The honest capacity question
The deciding factor is often not preference but capacity. Self-hosting gives control over the hosting, the upgrade timing and the configuration, and it only works if you have the people and the discipline to operate infrastructure reliably; without them, control becomes a liability. Self-hosting decides who operates the software, and the licence terms come from the software you choose: proprietary products can be run on your own infrastructure and still carry a fee. SaaS removes that operational burden and, in return, hands the vendor authority over the service and the terms. Open-source software can be self-hosted with no licence fee, and it still needs a competent team to run it securely, keep it maintained, and avoid the lock-in that comes from neglecting either. Which model fits depends on how much you need to control against how much you are equipped to operate.
Where it connects
The forms of dependence each model creates are covered under vendor lock-in, and the way the choice shifts costs between lines is part of CMS TCO. This choice is separate from where the presentation layer lives, which is the subject of headless vs traditional CMS. The commerce version of the same choice is an engine like Medusa.js, self-hosted with the order data in infrastructure you control, and how WAYF builds on it sets out the shape of that work.
Common questions
-
What’s the difference between a self-hosted CMS and a SaaS CMS?
A self-hosted CMS runs on infrastructure you control, whether your own servers or a cloud account in your name, and your team operates it. A SaaS CMS is delivered by a vendor as a managed online service, and the vendor runs the machinery behind it. What separates them is who does the work of keeping it running.
-
Who applies security patches on each model?
On a self-hosted CMS your team does, along with provisioning capacity when traffic grows and getting the service back when something breaks overnight. On SaaS the vendor carries patching, scaling and uptime, and updates arrive without your involvement. You gain the freed capacity and accept the vendor's timing on when things change.
-
Where is the content stored in each model?
Self-hosting keeps content in infrastructure you control, so you decide its location. That matters where rules such as the GDPR constrain where personal data may be held. With SaaS the content sits in the vendor's systems, so location becomes a question of the vendor's terms and regions rather than your own configuration.
-
Is self-hosting cheaper because open-source software has no licence fee?
The licence line can go to zero. The operating work does not: open-source software self-hosted without a licence fee still needs a competent team to run it securely and keep it maintained. The saving is real where that team already exists, and it turns into a liability where it does not.
-
How do we choose between them?
By capacity more often than by preference. Self-hosting gives control over the hosting, the upgrade timing and the configuration, and works only where you have the people and the discipline to run it reliably and securely. SaaS removes that operational burden and hands the vendor authority over the service and its terms. Licence cost is a separate question.
We're booking content platform
engagements for 2026.
Twenty-five minutes to walk through the work and decide if we're the right team for it. Scoping and a fixed price come after.