Government
How do you procure open-source-based infrastructure in the public sector?
The code is free. The obligations are the procurement.
The answer
Procure the accountability, not the software. The licence costs nothing and answers to no one, so what the agency is actually buying is a named party responsible for security patching, upgrade choreography, incident response, and the operating discipline around a codebase nobody vendor-owns — which should be specified, priced and contracted exactly as explicitly as a proprietary licence would be.
The four obligations to name in the contract
Who monitors upstream for security advisories, and within what window patches are applied.
Who performs upgrades, and how a breaking change upstream is handled and paid for.
Who is on call when the system fails at three in the morning, with the rota named rather than implied.
What happens to all of the above if the supplier relationship ends — the exit plan applies here exactly as it does to proprietary software.
The advantage worth protecting
Open-source infrastructure gives a public body something proprietary licensing rarely does: the ability to change supplier without changing system. That advantage survives only if the procurement keeps the code, the data and the operational knowledge transferable — which makes knowledge transfer a contract deliverable rather than a courtesy.
Talk to the practice
Tell us what you are trying to build and what has to be true for it to work.
Contact