Comparison & migration guide

AccessPoint vs. NextRequest

NextRequest is the most widely deployed public-records platform in US state and local government, and its public request portal is genuinely good. AccessPoint takes a different architecture: the whole access and privacy mandate, running inside your agency's own Microsoft 365 tenant.

The short answer

NextRequest earns its position. It is the largest US state-and-local public-records platform by footprint, with a public-facing request portal and published request logs that are a real transparency asset, RapidReview batch redaction, and a mature managed-SaaS operation now backed by CivicPlus. If a public front door is your single highest requirement, NextRequest is the stronger product today — AccessPoint's requestor self-service portal is on the roadmap, not shipped. The comparison is architectural and scoped: NextRequest is vendor cloud only, so responsive records are uploaded into CivicPlus's AWS environment to be processed, and its scope is public-records requests. AccessPoint keeps records inside your own Microsoft 365 and Azure tenant, collects them where they already live, and runs requests plus assessments, breach response, complaints, and risk — at flat published prices.

What is NextRequest (CivicPlus public records software)?

NextRequest is the public-records request platform used across US local government — cities, counties, school districts, special districts, state agencies, and public safety. CivicPlus cites more than 70,000 active users, roughly one million requests processed a year, and over 300,000 documents redacted annually. Those are the vendor's own figures, but by footprint NextRequest is the most widely deployed records-request product in the US state and local market, and it is well regarded by the offices that run it.

The ownership chain is worth knowing, because it shapes the roadmap you are buying into. NextRequest merged with ArchiveSocial and Monsido to form Optimere, and CivicPlus then acquired Optimere — a business reported at roughly 6,000 customers and about $30 million in annual recurring revenue at the time of the deal. Through all of it NextRequest kept its name, its own product page, and its own marketing, and it remains actively sold and developed under CivicPlus alongside the rest of that suite.

On the request itself, NextRequest is strong: the public portal and published request logs are a genuine transparency capability, RapidReview handles batch redaction across a production, and a Risk module uses pattern matching and machine learning to surface sensitive content. The differences that matter are structural rather than feature-level. NextRequest is a vendor-hosted service with no on-premises or customer-tenant option, so the personnel files, investigations, and contracts responsive to a request are exported from your systems and uploaded into the vendor's cloud to be reviewed there. And its scope is public-records requests, while the office running those requests increasingly owns privacy assessments, breach notification, and complaints as well. AccessPoint's answer to both: the records stay in your tenant, and one platform carries the whole mandate.

NextRequest and AccessPoint, side by side

NextRequest AccessPoint
Scope Public-records request management Records requests plus PIAs, AIAs, breach response with a statutory notification calculator, complaints, and an ISO 31000 privacy risk register
Where your data lives CivicPlus's AWS cloud — vendor-hosted only, no tenant-resident option Your own Microsoft 365 and Azure tenant
Records collection Responsive records exported from your systems and uploaded into the platform Pulled straight from SharePoint, OneDrive, Outlook, and Teams — plus a New-from-email flow that turns an intake-mailbox message into a fully-formed request in one step
Public request portal A genuine strength — public-facing request portal with published request and disclosure logs Not yet. Intake runs through your team today; a requestor self-service portal is on the public roadmap
Redaction RapidReview batch redaction, plus a Risk module using pattern matching and machine learning Browser-native studio with statutory exemption tagging, fall-backs, live patterns, and optional AI-proposed redactions into human review
Security & audit posture AWS-hosted; the vendor cites ISO 27001, FISMA, and SOC certifications for its cloud Runs under the certifications and controls your agency already holds — Entra ID, your own security stack, no vendor runtime access — with a hash-chained, append-only audit ledger and court-ready case audit exports
Jurisdiction coverage US state and local public-records focus, configured per implementation 106 jurisdiction packs — 33 of them US, including federal FOIA and the Privacy Act, plus Canadian, EU, and UK statutes
Pricing Quoted Flat annual, published on the site, no per-user fees

Competitor capabilities vary by product edition and configuration; this table reflects each product's public positioning as of August 2026.

Where NextRequest fits

A fair comparison cuts both ways — NextRequest is a reasonable choice when:

  • The public front door is your top requirement. NextRequest's public-facing request portal and published request logs are a real advantage AccessPoint does not match today — AccessPoint's requestor self-service portal is on the public roadmap, not shipped. If letting requesters submit and track their own requests is non-negotiable this budget cycle, that is a straightforward reason to choose NextRequest.
  • You want a fully-managed SaaS with no Azure footprint at all. AccessPoint deploys App Service, Azure SQL, and storage into your own tenant's subscription — a one-click template, but still a real infrastructure commitment. If your agency has no Azure presence and no appetite to acquire one, a vendor-hosted product is the simpler fit.
  • You are already standardized on CivicPlus. If your website, agendas, and citizen engagement already run on that suite, keeping records requests inside it carries genuine procurement, support, and training value.

Where AccessPoint differs

Your records never leave your tenant Personnel files, investigations, and contracts responsive to a request are among the most sensitive documents an agency holds. AccessPoint reviews them inside your own Microsoft 365 and Azure tenant instead of uploading them to a vendor cloud, so your existing security stack governs everything and there is no new cloud for your security team to assess.
The whole mandate, not just the request queue Privacy impact assessments, algorithmic impact assessments, breach response with a live statutory notification calculator, complaints and appeals, and an ISO 31000 privacy risk register run on the same platform and the same hash-chained audit ledger as your public-records requests.
No export-and-re-upload tax Search SharePoint, OneDrive, and Outlook and attach records straight to the request — including Teams chats, OneNote, calendars, and Copilot interaction history — instead of downloading from your systems and re-uploading into a portal on every single request.
Flat, published pricing USD $2,990, $7,990, or $14,990 a year by organization size, every feature in every tier, no per-user fees, billed through the Microsoft commercial marketplace — plus Azure hosting in your own tenant's subscription, typically around $175 a month at Microsoft's cost with no vendor markup. A 30-day free trial runs in your own tenant.

Migrating from NextRequest to AccessPoint

Moving a records program between systems is a well-worn path. The US federal FOIA community proved it when FOIAonline — EPA's shared service, not a commercial product — shut down on 30 September 2023 and the eleven agencies still on it had to stand up their own case management. That was federal and NextRequest is state and local, but the mechanics are the same, and AccessPoint imports any caseload that reaches Excel.

  1. Export your request history from your current system's reporting into Excel — request registers, requester details, statuses, and dates are enough to start.
  2. Download AccessPoint's import template from Settings → Data import & export; it is generated with your own tenant's type codes, and your existing request numbers persist as legacy references.
  3. Upload and read the per-row validation report — created, skipped, and errors — with a fix-and-reupload error workbook. Imports are create-only, so re-running a corrected file is safe.
  4. Stage documents in the pre-provisioned migration-staging container in your own tenant's Azure storage, with optional MD5 hash verification for chain of custody.
  5. Import in the background. Records arrive with their status, due dates, and documents intact, so in-progress cases continue with no cutover — no notifications fire, nothing recomputes, and every record carries an Imported audit-trail entry.

Rehearse it first. AccessPoint's Export tab produces the same workbook the importer accepts, so a dry run against a test tenant validates end to end before you touch production — and because the export is always one click away, leaving AccessPoint later would be just as clean.

Questions people ask about NextRequest and AccessPoint

Who owns NextRequest now?

CivicPlus. NextRequest merged with ArchiveSocial and Monsido to form Optimere, and CivicPlus subsequently acquired Optimere — a business reported at roughly 6,000 customers and about $30 million in annual recurring revenue at the time. NextRequest kept its own name, product page, and marketing throughout, and is still actively sold and developed as NextRequest under CivicPlus.

How is AccessPoint different from NextRequest?

Two differences, both structural. Architecture: NextRequest is vendor cloud only, so responsive records are exported from your systems and uploaded into CivicPlus's AWS environment to be reviewed there. AccessPoint is tenant-resident — the database, documents, and audit history live in your own Microsoft 365 and Azure tenant, and records are collected straight from SharePoint, OneDrive, Outlook, and Teams rather than re-uploaded. Scope: NextRequest covers public-records requests. AccessPoint covers requests plus privacy impact assessments, algorithmic impact assessments, breach response with a statutory notification calculator, complaints, and an ISO 31000 privacy risk register, all on one hash-chained audit ledger. That architecture also reframes the certification question: the ISO 27001, FISMA, and SOC certifications CivicPlus cites describe the security of the vendor's cloud, while AccessPoint runs under the Microsoft platform attestations and the agency controls you already hold, with authentication through your existing Entra ID and no publisher runtime access to your environment. Pricing is flat and published rather than quoted.

Does AccessPoint have a public request portal like NextRequest's?

No, and that is an honest current gap rather than something to spin. NextRequest's public-facing request portal with published request logs is a real strength AccessPoint does not match today. A requestor self-service portal — jurisdiction-aware public intake forms, secure status tracking, and delivery of released packages through Microsoft Entra External ID — is on AccessPoint's public roadmap, not shipped. What exists today is team-side intake, including a New-from-email flow that turns a message in your intake mailbox into a fully-formed request in one step, with the email attached as its first document. If a public portal is your highest requirement right now, check the roadmap page for current status before you decide.

We are a US agency — does AccessPoint know our state's public-records law?

If your state is among the 27 US public-records packs, yes, and the majors are covered — federal FOIA and the Privacy Act, plus California, Texas, New York, Florida, Washington, Illinois, Pennsylvania and more, among 106 packs in total. Each preloads the deadlines, exemption catalogue, fee rules, business-day calendars, and letter templates for that statute: California's 10-day determination with the 14-day unusual-circumstances extension, Texas prompt production with the 10-business-day Attorney General referral, New York FOIL's 5-business-day acknowledgement, Washington's 5-business-day response duty, Florida's reasonable-time standard. The solutions section lists every covered jurisdiction.

Can we import our NextRequest history into AccessPoint?

Yes. Export your request history to Excel, map it into AccessPoint's tenant-generated import template, and read the per-row validation report before anything commits. Old request numbers persist as legacy references, requester contacts import alongside their requests, and documents stage through the migration-staging container in your own tenant's Azure storage with optional MD5 hash verification. Imported records arrive with status, due dates, and documents intact, so in-progress cases continue with no cutover — no notifications fire, nothing recomputes, and every record carries an Imported audit-trail entry.

Competitor information on this page is drawn from public sources — vendor websites, government reports, and press coverage — and was last reviewed in August 2026. Products evolve, and a comparison is never the whole story: capabilities vary by edition and configuration. Spot something out of date? Tell us and we'll correct it.

Your Agency's Tenant. Your Whole Access & Privacy Mandate.

Try AccessPoint free for 30 days in your own Microsoft 365 tenant. Flat pricing, published on the site.

Start Free Trial