Open Source Software offers many advantages. In order to use it successfully, securely and long-term, it is important to consider certain sustainability criteria when choosing a provider. In the position paper at hand the Open Source Business Alliance maps out the four most important selection criteria and offers crucial advice especially for entities in a tender offer on how they can choose providers that can reliably ensure the successful use of the software, because they contribute to the further development and maintenance of the corresponding open-source solution.
When sustainable providers compete with dumping providers
Due to the freedoms granted by the open-source software licenses, development and distribution models of open-source software differ from proprietary business models. With proprietary software, the manufacturer participates in every license sold, even if the license was granted by a third-party provider. With open-source software, this is not always the case: Additional services are usually offered commercially instead of the software license. These services can be offered by any third-party provider.
It happens time and again that third-party providers win a bidding process by making unrealistically low offers because a public tender is usually decided by the cheapest price. These third-party providers often submit a calculation that does not account for sufficient support, sufficient funds for the continuous development and maintenance of the software or the upstream publication of software modifications. When problems occur, these service providers are not able to adequately supply support. This can lead to the failure of the respective projects, which damages the reputation of the open source software community as a whole. In addition, no money goes to the open-source manufacturer, who is therefore unable to invest sufficiently in the further development and maintenance of the open-source solution.
IT Security and Potential for Reuse are at Risk
One argument for using open-source software in administrative digitization is the potential for reuse, i.e. that an authority can continue to use the software that has already been developed and paid for by another authority if the corresponding source code is published on a publicly accessible platform such as openCode. However, this potential for reuse is not possible if insufficient funds are invested in the continuous development and maintenance of the software, and it is therefore not economical for the manufacturer to continue development at all. This is then bad for customers, as less high-quality and up-to-date open-source solutions are available on the market. This also jeopardises the IT security of the deployed open-source solutions in public administration or may lead to the failure of IT projects.
Selection Criteria for the Sustainable Procurement of Open Source Software
The challenge for public administration is therefore to develop the right requirements and award criteria so that they can reliably select from service providers those who are able to offer sustainably secure and high-quality software and services.
The Open Source Business Alliance proposes four selection criteria in their new paper:
- Relationship with the Software Manufacturer / Community: Is there a business relationship between the service provider and the software manufacturer or the community and to what extent is there going to be support available from them in the course of a project?
- Ensuring Upstream Publication of Modifications and Patches: How is the service provider ensuring that modifications of the software and patches are going to be made available upstream to the general public?
- Ensuring High-Quality Level 3 Support: To what extent is the service provider able to ensure high-quality level 3 support? Do they have the necessary expertise with regard to the source code of the specific open-source product themselves or are they able to ensure the support of the manufacturer?
- Securing the Supply Chain Through Support for Core Components: Open-source software usually consists of various core components. Does the provider support developers and projects that supply the software components that the provider is integrating in their product? This is also going to become relevant with regard to „supply chain security“ in the Cyber Resilience Act.
Birgit Becker and Claus Wickinghoff, Spokespersons of the Procurement Working Group at the Open Source Business Alliance:
„If public authorities want the open-source software that they are using to still be available and well-tended a couple of years from now, they have to make sure that the manufacturer who maintains the software has a share in the respective business deal. With proprietary software, this is always the case: The manufacturer has a share in every license sold.
In public tenders the most cost-effective offer has to get the award of contract. This is generally equated with the cheapest offer and it opens the floodgates to providers offering dumping prices. When these service providers only calculate their own services and take the software for granted because they can freely download it somewhere on the internet, it‘s in the long term not profitable anymore for manufacturers to invest in the security and maintenance of the open-source software. This is going to be to the detriment of the contracting authority that wants to use high-quality software. In the end, the cheapest offer is most of the time not the most cost-effective.
We want our selection criteria to help contracting authorities with the question how they can choose a provider with whom they can realise sustainable projects, so that everyone in the open-source ecosystem profits and the open-source software is securely available long-term.“
You can download the full paper here (PDF) and you can read the full paper here
About the Open Source Business Alliance – Federal Association for Digital Sovereignty e.V.
The Open Source Business Alliance (OSBA) is the federal trade association of the German open-source industry. The OSBA represents more than 230 companies which together generate more than 126 billion euros in annual revenues. The OSBA is cooperating with scientific institutions and software user groups in order to further public awareness for the importance of open-source software and open standards for a successful digital transformation. It is also their goal to drive open-source innovations and to establish open-source software as the standard in public procurement, in research funding and in the promotion of trade and industry. The OSBA is convinced that open-source software and open standards are the crucial prerequisite for digital sovereignty, for the capacity for innovation and for security in the age of digitalisation. As such, open-source software is the answer to one of the most pressing challenges of our time.
Contact Information:
Open Source Business Alliance – Bundesverband für digitale Souveränität e.V.
Pariser Platz 6a
10117 Berlin
Lisa Reisch
Head of Press Relations at the Open Source Business Alliance
Phone: +49 (30) 300 149 3377
Email: presse@osb-alliance.com

