The case for tying public procurement to open-source maintenance is no longer just a technical argument; it is a question of law, budget and public value. The Welsh Government’s own guidance on the Procurement Act 2023, which took effect on 24 February 2025, makes clear that buyers are now operating under a wider framework than the old regulations allowed. The shift is designed to create a more flexible and transparent commercial system, while still protecting value for money and op...
Continue Reading This Article
Enjoy this article as well as all of our content, including reports, news, tips and more.
By registering or signing into your SRM Today account, you agree to SRM Today's Terms of Use and consent to the processing of your personal information as described in our Privacy Policy.
That matters because the old procurement regime made it harder to justify scoring suppliers for benefits that did not accrue directly to the contracting authority. Under the new Act, that obstacle has been removed. The Welsh guidance says award criteria may now take account of advantages that flow to service users or other stakeholders, rather than only to the authority making the purchase. In practice, that opens the door to evaluating suppliers on whether they contribute back to the open-source components on which a contract depends.
The point is not abstract. Public digital infrastructure across Europe already relies heavily on open-source software. Germany has committed large sums to moving federal websites on to TYPO3. The European Commission runs hundreds of Drupal sites that serve hundreds of millions of visits a year. Australia’s GovCMS supports a large shared platform across dozens of agencies. Nextcloud has also become part of the German federal cloud environment at scale. Against that backdrop, the PHP Foundation has warned that the maintenance burden for the language itself is carried by a relatively small number of contracted engineers, funded by contributions that are tiny compared with the size of the public and commercial ecosystems that depend on their work.
That imbalance is exactly what open-source advocates want procurement to address. One proposal, borrowed from Drupal4Gov EU and associated with Tiffany Farriss, would award points for verified contribution to upstream projects, reserve a small share of contract value for maintaining the components a service depends on, and require non-sensitive code to be returned to the community within a set period. The principle is simple: if a public body is buying software built on shared code, the contract should help sustain the shared code.
The legal basis for doing so is stronger now than it was under the Public Contracts Regulations 2015. The Procurement Act 2023 no longer insists that award criteria be assessed only from the standpoint of the contracting authority. That is an important distinction. A patch contributed back to PHP may not help a council’s own website in the narrowest sense, but it can strengthen the wider ecosystem that keeps that website running, along with many others. The new framework allows buyers to recognise that wider benefit.
Even so, the law is not a free pass. Section 23 of the Act still requires award criteria to be connected to the subject matter of the contract, clear enough to be measured, sufficiently specific, and proportionate to the contract’s scale and complexity. A vague promise to “support open source” is unlikely to survive scrutiny. A more defensible approach would be to score tenderers on committed upstream maintenance of the exact packages on which the service depends, backed by merged code contributions or formal funding agreements with the maintainers, and reported against a dependency list.
That dependency list is the crucial mechanism. It turns a broad policy ambition into something concrete and auditable. In effect, the composer.lock file, or an equivalent software bill of materials, becomes part of the contract’s technical reality. That makes the criterion measurable package by package, specific to the service being delivered, and easier to defend as proportionate.
The politics of funding open-source infrastructure remain awkward. LocalGov Drupal offers a useful comparison. More than 50 councils across the UK and Ireland now use the shared platform, and the project says a new council website can cost up to 80 per cent less than a bespoke build. It also encourages councils to fix bugs upstream rather than patching them privately. Yet the contribution model is voluntary, sliding by population and budget, with annual payments ranging from £1,000 to a £10,000 cap for the largest councils. That leaves plenty of public savings on the table and only a limited, optional route to reinvest in the software itself.
The government already expects the same culture in principle. The Government Digital Service Service Standard asks teams to make new source code open and to use and contribute to open standards, common components and patterns. In other words, the idea that public teams should give something back is already embedded in policy. What has been missing is a procurement mechanism that turns that expectation into a funded obligation.
For suppliers, the implication is straightforward. If public bodies start asking for upstream maintenance as part of the tender, vendors will need to price it properly and identify the packages, projects and maintainer relationships involved. For buyers, the next step is equally clear: build a line into the tender, assign it a sensible weight and stop treating contribution as an optional extra. Under the new Act, that can be done without waiting for another policy rewrite.
The wider lesson is that digital sovereignty does not begin with rhetoric about independence. It begins with contracts that acknowledge who maintains the software stack and who pays for that maintenance. The law now gives public authorities more room to make that choice. The challenge is whether they will use it.
Source: Noah Wire Services



