HomeGlossaryOpen Source in Government
Technology

Open Source in Government

Open source in government refers to federal policy encouraging agencies to release custom-developed code as open source and reuse open-source software, governed by OMB M-16-21.

Quick answer

Open source in government refers to federal policy encouraging agencies to release custom-developed code as open source and reuse open-source software, governed by OMB M-16-21.


Open source in government refers to federal policy requiring agencies to release at least 20 percent of newly commissioned custom-developed code as open source software and to actively seek opportunities to reuse open-source code developed by other agencies. OMB Memorandum M-16-21 (Federal Source Code Policy, August 2016) established this framework, directing agencies to create source code inventories, publish code through repositories such as code.gov, and assess reuse opportunities before funding new custom development. Contractors who develop custom software for federal agencies under this policy must understand how it affects deliverables, data rights, and licensing obligations.

What is open source in government?

The Federal Source Code Policy distinguishes between government-wide reuse and public release. At minimum, agencies must make custom-developed code available for reuse by other federal agencies. At least 20 percent of newly developed code must be released publicly as open source, subject to national security, privacy, and other exceptions listed in the policy.

For contractors, the critical question is who owns the code and what license applies. When the government pays for custom software development and the contract includes data rights clauses under FAR 52.227-14 (Rights in Data - General) or DFARS 252.227-7014 (Rights in Noncommercial Computer Software), the government typically receives unlimited rights to the deliverable software. The contractor retains no proprietary interest in code developed entirely with government funds, meaning the agency can release that code publicly without the contractor's permission.

NIST SP 800-218 (Secure Software Development Framework) addresses security practices that apply whether software is developed as closed-source or open source. Open-source releases create additional surface area for vulnerability discovery, so agencies and contractors must apply software composition analysis and dependency management practices before publishing code.

Why it matters for contractors

Contractors must account for the Federal Source Code Policy when negotiating data rights provisions in contracts for custom software development. If the contractor incorporates proprietary background technology, pre-existing IP, or commercial components into the deliverable, those elements must be identified and excluded from the government's unlimited rights grant. Failure to negotiate appropriate restrictions up front can result in the government releasing code that contains the contractor's proprietary methods or third-party licensed components.

The policy also creates competitive intelligence risk: publicly released agency code reveals the technical architecture of government systems, which competitors can study when preparing bids for follow-on work. Contractors who develop and maintain agency systems should monitor code.gov releases related to their programs and factor published code into their competitive analysis.

On the opportunity side, agencies that actively reuse open-source code reduce development costs and timelines, which can work in favor of contractors who contribute to or build on established government open-source projects such as the U.S. Web Design System or the CMS design system.

Example

A contractor develops a new benefits eligibility application for a civilian agency under a contract that grants the government unlimited rights to custom-developed code. The contractor incorporates a proprietary third-party identity verification library into the application under a commercial license that prohibits redistribution. Before the agency publishes the codebase on GitHub, the contractor provides a written notice identifying the proprietary library, its license terms, and the fact that it must be excluded from any public release. The agency publishes the remaining 85 percent of the codebase as open source and licenses the proprietary library separately for government use only.

How Bidovate helps

Bidovate puts Open Source in Government to work inside your capture and proposal workflow.

Discover opportunities

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.