Discover our new Policy Prototyping report on the EU AI Act's value chain requirement  

Read and download here
A person is holding a pen and writing something down on a piece of paper that is laying on a table. Another person is standing close. The setting looks professional. There is a white banner with the logo of the European Commission placed over the image. The image represents that this policy monitor item is about a report/document of the European Commission. 

Een persoon houdt een pen vast en schrijft iets op een stuk papier dat op een tafel ligt. Een andere persoon staat dichtbij. De omgeving ziet er professioneel uit. Er is een witte banner met het logo van de Europese Commissie over de afbeelding geplaatst. De afbeelding geeft aan dat dit beleidsmonitor item gaat over een rapport/document van de Europese Commissie.
17.07.2026

European Commission - The EU Open Source Strategy

Summary

On 3 June 2026, the European Commission published the EU Open Source Strategy as one of four instruments in the Digital Sovereignty Package, alongside the proposed Cloud and AI Development Act (CADA), the Chips Act 2.0, and the Strategic Roadmap for Digitalisation and AI in Energy. The strategy sets out four objectives: open source for tech sovereignty, a vibrant open source ecosystem, open source in public administration, and reinforced standards with international outreach and is supported by an indicative €2 billion envelope over seven years and anchored by concrete instruments including the Open Source Maintenance Instrument, the Open Internet Stack, the Digital Commons EDIC, and revised procurement guidance. The framing anchor is the observation that Europe spends over €260 billion annually on non-EU digital products and services, a figure the Commission now treats as a structural sovereignty deficit rather than a market inefficiency. This analysis examines what the strategy commits to, where it leaves ambiguities (particularly on open source hardware, the software–standardisation sequence, and the gap between ambition and funding scale) and how the Belgian and Flemish policy landscape stands to be shaped by its implementation.

What: Strategy

For whom: policymakers, businesses and citizens

URL: Open source strategy

Introduction

For more than two decades, open source has been present in European digital policy without ever occupying its centre. It has appeared in procurement footnotes, in research funding lines like the Next Generation Internet initiative, in the Open Source Software Strategy of the EU institutions, and in the Cyber Resilience Act's recital on free and open source software. It has been treated as useful but always adjacent to the main policy agenda. The Communication on European Tech Sovereignty of 3 June 2026 should mark the moment when that adjacency ends.

The strategy is not a legal instrument. It is a soft-law text that sets direction without creating obligation, but carries something that the legislative texts in the Digital Sovereignty package do not, which is a normative claim about the shape of Europe's digital future. That claim is that the concentration of European digital infrastructure in the hands of a small number of non-EU providers is not a market inefficiency to be corrected by competition policy but a structural vulnerability to be corrected by industrial policy. The strategy names open source as the primary industrial-policy answer.

Europe spends more than €260 billion each year on digital technologies procured from third countries, and depends on non-EU providers for over 80 per cent of key digital products, services, infrastructure and intellectual property. These numbers are not new but the strategy is the first document to treat them as evidence that the current model of European digital procurement produces sovereignty deficits at scale.

The response is a full-lifecycle strategy that follows open source from research and development through market uptake, deployment, and long-term maintenance and governance. Four objectives structure that lifecycle. 

The objectives of the strategy

The strategy organises its actions around four objectives. Each objective is attached to concrete instruments, some of which are entirely new and others extend existing frameworks. 

Objective 1 — Open source for tech sovereignty

The first objective covers both deployment and development. On deployment, the Commission commits to scaling the Open Internet Stack (a catalogue of open source solutions aligned with EU priorities and rules) and to supporting the uptake of open source alternatives to proprietary solutions in cloud, workplace tools, secure email, and decentralised social media, in cooperation with Member States and the Digital Commons European Digital Infrastructure Consortium (EDIC). The EU Digital Identity Wallet, the European Business Wallet, and age-verification infrastructure are explicitly bound to open source. On the development side, funding is to be prioritised in key strategic technology areas: semiconductors, operating systems, cloud and edge, artificial intelligence, cybersecurity, and future internet architectures.

Objective 2 — A vibrant open source ecosystem

The second objective is the one that most directly addresses the structural weakness of the European open source community itself: not the absence of contributors (Europe has more than three million) but the fragility of the institutional layer that supports them. The strategy commits to accelerators for open source startups, legal and licensing support, and procurement opportunities. It proposes a stewardship toolkit and support for EU-based steward organisations that can hold and govern strategic assets. On security and sustainability, it introduces the Open Source Maintenance Instrument, a mechanism intended to provide sustained financial support for critical open source dependencies, alongside critical dependency mapping and what the strategy calls "mirroring capabilities" for essential components. A separate skills strand covers schools, universities, civil servants, and learners.

Objective 3 — Open source in public administration

The third objective turns the Commission's own procurement power into a demand-side lever. Public procurement accounts for approximately fourteen per cent of EU GDP. The strategy commits to developing procurement guidelines for open standards and fair assessment of open source bids, strengthening the Commission Open Source Programme Office (OSPO) and the EU Public Sector OSPO Network, and setting common security baselines for Commission code repositories covering vulnerability management, licence compliance and dependency risk. The most consequential language in this objective is the commitment to embed "openness and sovereignty-by-design" in digital investment and governance checks.

Objective 4 — Reinforced standards and international outreach

The fourth objective addresses the interface between open source and formal standardisation. The Commission commits to integrating open source communities into standardisation processes, including through a revision of the EU Standardisation Regulation. Internationally, the newly announced EU Tech Business Offer is designed to promote European open source developers and solutions abroad, and to support the uptake of EU-grown tools (the Open Internet Stack, AI, Digital Identity and Business Wallets) in partner countries.

The software–hardware asymmetry

The strategy is a software document that gestures at hardware. It mentions RISC-V, the open Instruction Set Architecture that allows anyone to design and manufacture microchips without paying royalties, and it references open Electronic Design Automation tools. But hardware appears in the strategy as a footnote, not integrated into the main argument. This is the sharpest critique advanced in the technical policy commentary that followed the strategy's publication.

Open source hardware has existed nearly as long as open source software. CERN, a European institution, developed the Open Hardware Licence. Arduino, an Italian project, is one of the most widely used open source hardware platforms in the world. The White Rabbit precision timing system, also from CERN, exemplifies the kind of open hardware commons the strategy could build upon. 

A sovereign operating system running on a foreign-controlled chip with a proprietary instruction set offers only partial sovereignty; the software layer inherits the constraints of the hardware layer beneath it. Europe has invested roughly €500 million in open RISC-V development through the Chips Joint Undertaking, and the Chips Act 2.0 provides for an Open EU Foundry and accelerated pilot lines. Yet the Open Source Strategy draws no explicit connection between these hardware investments and its own software objectives. 

The strategy's language on open source is inclusive enough that a broad interpretation is possible. Whether that interpretation is adopted will depend on how the Commission's implementation texts read the word "open source": as a shorthand for open source software, which is how the current draft mostly reads it, or as a category encompassing both software and hardware, which is how the strategy's underlying logic would suggest it should be read.

Funding scale versus ambition

The €2 billion envelope is the single most contested figure in the strategy after €264 billion. It is not that the amount is small in absolute terms; it is that it is spread across accelerators, the Open Internet Stack, stewardship support, maintenance and skills programmes, and that the maintenance component in particular is where informed observers have priced the underlying need at a scale the envelope cannot meet.

A feasibility study by OpenForum Europe, the Fraunhofer Institute for Systems and Innovation Research, and the European University Institute, produced ahead of the strategy's publication, priced a functioning EU Sovereign Tech Fund at around €350 million for the Open Source Maintenance Instrument alone. That figure was itself described as conservative. Set against it, the €2 billion covering all four objectives across seven years produces a maintenance component that, if evenly spread, would fund perhaps one-quarter of what a conservative estimate identifies as the requirement.

There are two ways to read this. The first is the Commission's own reading: that the strategy is designed to catalyse additional funding through Member State contributions to the Digital Commons EDIC, through the pilot activities of the Sovereign Tech Agency, through private co-financing, and eventually through a share of the proposed €409 billion European Competitiveness Fund currently under Multiannual Financial Framework negotiation. The second reading is the more sceptical one: that maintenance funding on the scale actually needed is not politically achievable in the current budgetary cycle, and that the strategy's promise of sustained support for critical dependencies will run into a resource wall that the Commission has not yet found a way to break through.

Both readings can be true at the same time. The strategy's ambition is real, and its funding envelope is a first step rather than a ceiling. But the gap between the two is large enough that the credibility of the ambition will depend, over the coming budgetary cycle, on whether the additional resources actually materialise.

Procurement as sovereignty lever

Public procurement across the EU is worth approximately €2 trillion annually, or fourteen per cent of GDP. A meaningful fraction of this is spent on IT services, software, consulting and support. Every euro of that spending is a lever, and the strategy's third objective explicitly names procurement as the demand-side mechanism through which open source uptake will be driven.The strategy itself proposes only soft-law procurement tools (guidelines, OSPO strengthening, sovereignty-by-design checks in digital investment). The harder edge sits in its companion, CADA. Article 41 introduces an "open source first" duty in the operative text of an EU regulation, not a non-binding recital, a first for EU digital policy. Article 42 adds a reuse obligation for publicly developed software, and Article 43 creates an EU Open Source Solutions Catalogue. Together, this is the clearest legislative articulation yet of the 'Public Money, Public Code' logic civil society has pushed for over a decade.

The qualification matters as much as the achievement. CADA's Article 41 duty is weighed against "functionality, including security, total cost, and other relevant, duly justified objective criteria", a strengthened factor in the procurement calculus. That falls short of the binding "Public Money? Public Code!" mandate FSFE and OpenForum Europe have jointly pushed for, where the burden of proof would sit with the choice that creates dependency. Since CADA is still a proposal, this is exactly the terrain Parliament and Council will contest in trilogue: whether "encourage" hardens into "require," or is softened further by Member States and industry resisting a structural procurement preference.

The standardisation sequencing question

The fourth objective's commitment to integrate open source communities into standardisation is the most technically consequential of the strategy's provisions, and the one whose implications are least well understood outside the open source policy community itself. Behind the objective sits a longstanding tension in how standards and open source implementations relate to each other in time.

Two sequencing models are possible. In the first, an open source reference implementation establishes rough consensus among implementers before a formal standard is drafted; the standard, once published, codifies practices that already work in production. In the second, a standard is drafted first, in a formal standard-setting body, and open source implementations follow. The first model has historically been how much of the modern internet was built. The second model is more typical of the European standards system, where CEN, CENELEC and ETSI operate through formal committee processes with defined membership rules.

The strategy does not resolve this tension. It commits to integrating open source communities into standardisation, but the operational form that integration will take (reference-implementation-first or standard-first) is left to the revision of the EU Standardisation Regulation. This is the right sequencing on procedural grounds; committing the Commission to one model or the other in a Communication would foreclose options that the legislative process needs to keep open. But it also means that the strategy's most substantive technical commitment is currently a placeholder for a decision that has not yet been made.

Relevance for Belgian and Flemish stakeholders

The strategy assumes a Member State with a single digital-governance authority to coordinate with the Digital Commons EDIC and the OSPO Network. Belgium has no such authority: BOSA holds federal competence, Digitaal Vlaanderen the Flemish equivalent, with separate structures again in Wallonia and Brussels. For Belgian administrations, this means the coordination work the strategy assumes will happen automatically at Member State level instead has to be built domestically: someone will need to decide whether Belgium speaks with one voice into the EDIC and OSPO Network, or several. The same fragmentation multiplies down to procurement: over 500 municipal contracting authorities sit beneath the federal and regional layers, so a non-binding EU procurement preference is even less likely to produce uniform uptake in Belgium than across the EU as a whole, absent a domestic coordinating push.

Imec is where Belgium already sits inside the strategy's delivery architecture, and where the impact is most concrete. Its role in the RISC-V/DARE project and the NanoIC pilot line means Flanders holds real open-hardware capacity of exactly the kind the strategy's software-heavy text underuses. For Flemish research policy, the coherence the strategy is missing between software objectives and Europe's open hardware base is a gap Flanders can help close, but only if that connection is actively made in how imec and Flemish funders position their contribution.

For Belgian research funders, the strategy's skills and maintenance instruments are a test of whether existing capacity (e.g. KU Leuven's cryptography and distributed-systems work, UGent's networking research) gets channelled into EU stewardship and maintenance funding, or stays disconnected from it as most EU-funded research capacity historically has. And for federal and regional administrations already running open source in production (BOSA's eID middleware, the openpolice.be platform, iMio's shared software for Walloon municipalities) the strategy's real test is whether the Open Source Maintenance Instrument and Digital Commons EDIC actually fund the upkeep of what already exists, or whether Belgium keeps building good open source infrastructure project by project without the sustained funding layer the strategy proposes.

Auteur

Frederic Heymans

Frederic Heymans

email hidden; JavaScript is required