Open source, communs numériques et souveraineté : les leviers du secteur public

par OUTSCALE

At OUTSCALE EXPERIENCES 2026, Julie Ripa, Co-Director of La Suite numérique at the Interministerial Digital Directorate (DINUM), Florian Caringi, Deputy Head of Data & Open Source, President of OW2 and Vice President of Tosit within the BPCE Group, and Léo Unbekandt, Co-Founder and Chief Technology Officer of Scalingo, discussed the role of open source and digital commons in digital sovereignty, particularly in the public sector.

Open source and digital commons are playing an increasingly important role in public-sector digital sovereignty strategies. In particular, they enable public administrations to better control their technological dependencies, facilitate reversibility and pool their digital investments. Their effectiveness nevertheless depends on specific conditions: open governance, an active community, available skills and sustainable funding.

Understanding open source and digital commons

Open source as a collaboration model

Open source refers to code distributed under a license that authorizes its use and, subject to the applicable conditions, its modification and redistribution. This approach is based on several core principles: transparency, collaboration and the ability to develop and innovate collectively.

In an open-source environment, value therefore lies not only in the code. It also depends on the communities that maintain it, the organizations that develop it and the stakeholders capable of integrating it into operational environments.

Open source thus provides a shared technological foundation. It enables several companies, public administrations and contributors to work on common building blocks sometimes through cooperation, and sometimes through competition between service providers.

Digital commons rely on governance

A digital common is a digital resource collectively managed by a group that defines its own rules. This resource may take different forms, including data, code, specifications or content.

Wikipedia and Linux illustrate this approach. However, publishing software under an open-source license is not enough to create a digital common. The decisive factor is the community and governance organized around the resource.

A project becomes a common when several stakeholders can contribute to its maintenance, participate in decision-making and ensure its continuity. Governance must therefore define how contributions are made, how changes are approved and how the project is funded.

Digital sovereignty as strategic autonomy

Controlling technological dependencies

Digital sovereignty does not mean that an organization must produce all the hardware and software components it uses on its own. Such an approach would be difficult to achieve in practice, since no organization controls the entire digital value chain, from hardware to software.

Rather, digital sovereignty is about having the ability to control and make informed choices. A sovereign organization must be able to:

  • identify its technological and organizational dependencies;
  • control its data and choose its tools;
  • change providers when necessary;
  • limit its dependence on a single supplier;
  • maintain the ability to respond to risks associated with its suppliers and technologies.

This approach can be described as strategic autonomy. It involves choosing one’s dependencies, measuring their impact and building resilience solutions suited to the organization’s activities.

Open source as a resilience lever

Open source contributes to this autonomy by reducing the risk of dependence on a single stakeholder. An open technology can be maintained, integrated or adapted by multiple actors, provided that a sufficiently robust ecosystem exists around the project.

This plurality facilitates reversibility. An organization can rely on different integrators, service providers or internal teams to operate the same technology. It therefore has greater room for maneuver in the event of price changes, license modifications, product discontinuation or strategic disagreement with its provider.

Reversibility also depends on architectural choices. Open APIs, open software and widely adopted technologies make it easier to move a solution to another environment.

Public-sector strategies

The “public money, public code” principle

In the public sector, opening up code reflects a desire to reuse collective investments. The “public money, public code” principle holds that code funded by taxpayers should be reusable by other public administrations, companies or citizens.

This approach pursues several objectives. It improves the transparency of public action, facilitates code review and creates opportunities for cooperation between public administrations. It also promotes innovation by enabling different stakeholders to reuse and adapt existing developments.

La Suite numérique illustrates this approach. This suite of collaborative tools for public-sector employees is developed as open source and operated by DINUM. It can be hosted on sovereign clouds, including OUTSCALE’s SecNumCloud environment or ministerial infrastructures.

Pooling development at European level

Opening up code facilitates collaboration between public administrations in different countries. Tools developed to meet a public-sector need can be reused in other national contexts and then enhanced through new contributions.

This cooperation makes it possible to bring together resources around shared challenges, pool development efforts and reduce the costs associated with creating similar solutions. It also contributes to the emergence of European alternatives to major technology platforms.

However, publishing the code is only a first step. For a public-sector solution to become a sustainable digital common, it must attract private companies, other public administrations and contributors from several countries.

Building a sustainable community

Open and inclusive governance

The long-term viability of a digital common depends on the diversity and commitment of its ecosystem. A solution that remains entirely dependent on a single public administration or company retains a structural weakness, even when its code is open.

Governance must therefore organize the participation of different stakeholders. It should establish rules for reviewing contributions, prioritizing developments, resolving disagreements and maintaining essential components.

Foundations and associations can play an important role in this organization. A foundation with open governance can bring together software publishers, integrators, users and public-sector stakeholders around common rules. An association can also facilitate the sharing of best practices, co-development and joint funding.

Cooperation and competition within the same ecosystem

A digital common can bring together competing companies that contribute to the same technological building block. This logic of coopetition enables each stakeholder to develop its own services while improving a shared software infrastructure.

PostgreSQL is an example of a technology around which several companies can offer services, integrations or support. Competition between these stakeholders helps strengthen the underlying technology and increases the range of options available to users.

The community then extends beyond the project’s initial offering. It transforms open-source software into a widely adopted, maintained and usable resource for multiple organizations.

Assessing open-source risks

Distinguishing open source, source-available and open core

The term “open source” can cover different realities. Some software publishers offer an open version of their software while reserving essential features for proprietary modules. This model, often called open core, can limit the user’s actual freedom.

A thorough assessment should therefore examine:

  • the license applicable to the code;
  • the features available in the open version;
  • the terms governing commercial use;
  • the project’s governance;
  • the diversity of its contributors;
  • its maintenance and support arrangements;
  • the community’s ability to continue the project.

Software may be publicly accessible while remaining highly dependent on a single company. The project’s long-term viability must therefore be assessed alongside its license and technical characteristics.

Monitoring project vitality

Opening up the code does not guarantee software continuity. A project may be technically promising while depending on a very small team or a limited number of contributors. If the company maintaining it changes its strategy, abandons the product or changes its license, users may face significant operational risk.

Organizations must therefore assess the vitality of communities, the frequency of contributions, the diversity of maintainers and the existence of stakeholders capable of ensuring the project’s continuity. This approach is part of the broader management of software supply-chain risks.

Understanding licenses and forks

A license applies to code at a given point in time. If the project owner subsequently changes the license, code already released under the previous license remains subject to the rights defined at that time, subject to the specific terms of the license concerned.

A fork consists of creating a new branch of a project from an existing version and continuing its development along a separate path. This possibility enables a community to keep developing software when its governance, license or strategic direction no longer meets its needs.

A fork does not eliminate legal constraints. The new project inherits the obligations of the license governing the reused code. Some licenses are compatible with one another, while others impose specific restrictions on redistribution, commercial use or research.

Companies can rely on an Open Source Program Office to manage these issues over time. This function helps structure license analysis, contribution management and compliance with open-source usage requirements.

Security and maintenance of critical components

Automated analysis is changing the scale of cybersecurity

Artificial-intelligence tools capable of analyzing code can help detect vulnerabilities in open-source projects. They also lower the barrier to entry for developers who want to contribute to existing projects.

However, this development increases the volume of potential issues that must be addressed. Projects may receive more reports, fixes and contributions, with varying levels of quality. Teams must therefore strengthen their review, assessment and prioritization processes.

For operators of large infrastructures, the growing number of vulnerabilities requires shorter response times. Security becomes an organizational capability based on monitoring, coordination and the availability of teams able to intervene quickly.

Funding essential components

A large share of proprietary software and digital services relies on open-source building blocks. The robustness of these components is therefore a collective concern for public administrations, companies and users.

Organizations that use these projects must contribute to their long-term sustainability. This contribution can take several forms:

European funding mechanisms dedicated to maintaining digital commons can reinforce this dynamic. They help support sovereign and open-source projects that provide collective value but have limited resources.

Creating value with open source

Value also lies in operation

Open source can support viable business models. Commercial value often comes from the services surrounding the software: integration, hosting, operations, support, maintenance, security and scaling.

A company can therefore use open-source technology while providing specialized operational expertise. It helps customers deploy the software, keep it running in production and adapt it to their specific requirements.

This approach is particularly relevant for managed services. Customers benefit from open technology and professional support to operate it over the long term.

Developing European alternatives

Open source can also support the creation of European technology companies. Platforms such as Scalingo rely on open-source components and provide environments that enable customers to test, deploy and operate these technologies.

The use of open software and open APIs strengthens the reversibility of the services offered. Customers can retain the ability to change providers and reduce their exposure to proprietary interfaces.

This proposition addresses the growing expectations of public- and private-sector organizations seeking to limit their dependence on major technology platforms. It combines open technology with operational, support and security expertise.

Three priorities for organizations

To turn open source into a lever for digital sovereignty, organizations can focus their efforts on three priorities:

  • map technological dependencies, licenses and critical stakeholders;
  • contribute to the projects used by the organization through code, funding or expertise;
  • participate in governance structures capable of ensuring the continuity and evolution of digital commons.

This approach must involve IT, legal, procurement, security and business teams. Digital sovereignty is an organization-wide strategy combining architecture, governance, skills and funding.

Conclusion

Open source and digital commons are essential levers of strategic autonomy. They facilitate reversibility, resource sharing, transparency and supplier diversification, while encouraging the emergence of European technology ecosystems.

Their effectiveness nevertheless depends on organizations moving beyond the simple consumption of open software. Sustainable digital sovereignty requires active communities, inclusive governance, local expertise and regular funding. Open source is not free: it relies on contributions, shared responsibilities and investments capable of ensuring the continuity of critical digital building blocks.

Articles similaires