16 minute read

TL;DR / Summary

My study “National Support Structures and Capabilities for growing Digital Sovereignty through Sharing and Reuse of Open Source Software in the Public Sector” is now out, commissioned by the Danish Agency for Digital Government (Digitaliseringsstyrelsen) and Local Government Denmark (KL). “Support structures” here means Open Source Program Offices (OSPOs) - the support functions that help organisations adopt, develop, and collaborate on open source in a structured, sustainable way.

Denmark, like much of Europe, increasingly frames digital sovereignty as a policy priority - and open source software as a practical lever for it, alongside interoperability, cost efficiency, and reduced vendor lock-in. But Danish public-sector organisations currently lack the shared capabilities needed to collaborate on OSS at scale.

Based on several interviews and workshops with Danish and European stakeholders, the study identifies ten capabilities public-sector organisations need to build - spanning policy translation, procurement guidance, license compliance, investment and prioritisation, shared digital infrastructure, stewardship of OSS projects, measurement, inner source enablement, community building, and training. Rather than a checklist, these span the full arc from strategy to day-to-day practice, and rarely fit within a single organisation working alone.

To grow and provision these capabilities, the study proposes a federated OSPO structure across levels of government:

  • a national government OSPO anchoring policy translation and shared infrastructure
  • a regional government OSPO coordinating across the five regions
  • an association-based OSPO (through OS2) pooling municipal needs and resources
  • local government OSPOs embedded where capacity allows
  • institution-centric OSPOs for large public bodies with specific needs
  • supporting national functions, including stewards, a project brokerage, procurement bodies, and funding programmes, that ensure the long-term sustainability, discoverability, and operationalisation of shared OSS projects

Recurring barriers were rarely about the technology itself. Years of outsourcing eroded internal technical capacity, procurement remains risk-averse toward OSS, and leadership support across government levels is inconsistent - reinforcing a status quo where incumbent vendors retain the advantage.

The study proposes a staged roadmap - from foundational planning to a fully embedded, “open-by-default” ecosystem - and argues throughout that closing these gaps takes practical infrastructure (catalogues, templates, funding mechanisms, stewardship models), not policy statements alone.

Longer version

European sense of urgency for digital sovereignty

Across Europe, governments are becoming more digitally interconnected while awareness is growing regarding the lack

 of control over the technologies that underpin public services (Folketinget, 2025). Long-standing dependencies on a small number of dominant vendors across hardware, cloud and software have reduced choice, escalated costs, and introduced new geopolitical and security risks (Di Marco et al., 2025; Edler et al., 2023). Digital sovereignty has therefore become a central European policy priority, emphasising the ability to design, govern and sustain key digital technologies on domestic terms (European Parliament, 2026; von der Leyen, 2026).

For Denmark, digital sovereignty is considered a major concern and priority (Folketinget, 2025), with calls for increased promotion and growth of choice and competition, as well as investments into pilots to grow experience and capabilities (Regeringen, KL, & Danske Regioner, 2025). Recent analysis further strengthens concerns regarding the lack of control, governance, and transparency over data and software, as well as the cybersecurity and geopolitical risks that accompany them (PA Consulting, 2026).

Open source software provides a lever – but requires new capabilities

The same analysis further centres attention to Open Source Software (OSS) as a key tool for enabling and promoting digital sovereignty and innovation, something also echoed across research (Blind et al., 2021; Edler et al., 2023), ministerial declarations (European Commission, 2017a, 2020a, 2022), and more recently in EU’s coming sovereignty package, including an EU-level OSS strategy, and the Cloud and AI Development Act (European Commission, 2026). However, the ability to leverage OSS strategically requires common capabilities that many Public-Sector Organisations (PSOs) in Denmark do not currently possess. Years of outsourcing have eroded internal technical competence, procurement practices remain risk-averse, and political support is inconsistent. With current policy concerns in mind, there is now an opportunity to address this gap and to see new capabilities emerge that enable Denmark to fully leverage the potential of open technologies and innovation in shaping its digital future.

Open Source Program Offices – a vehicle for change management

Adoption of OSS at a strategic level (i.e., as a means of achieving overarching strategic goals, such as digital sovereignty) essentially requires organisational and cultural change, as well as support structures to advise and execute the strategy (Linåker & Muto, 2024). In response, an organisational construct referred to as Open Source Program Offices (OSPOs) has emerged, originally from the software industry shortly after OSS was introduced (Ruff, 2022).

The OSPOs provide support for their respective organisations (European Commission, 2020b), helping to accelerate organisational readiness and to grow capabilities to adopt, develop, and collaborate on OSS to reach the organisation’s strategic goals (Digitaliseringsstyrelsen, 2025). Essentially, the OSPOs act as change agents in their respective contexts, working to onramp cultural mindsets and ways of working into the open innovation paradigm (Linåker et al., 2024). Each OSPO will look different and be shaped by the conditions and goals of the overarching organisation. Still, there are overlaps, and a joint best practice has emerged from industry as goals commonly converge, including supply-chain control and market power.

The OSPO construct is now increasingly adopted internationally, including in the public sector across Europe, addressing needs for digital sovereignty while enabling the potential innovation and economic upside that OSS offers (Linåker & Muto, 2024). The Centre for Digital Sovereignty (ZenDIS) in Germany and the regional OSPO of Schleswig-Holstein are two prominent examples (PA Consulting, 2026), while several others have been studied at the national, regional, and local levels of government (Linåker et al., 2024). These include single governments and PSOs, as well as association-based OSPO structures where PSOs collaborate and pool resources through a co-owned entity (Digitaliseringsstyrelsen, 2025). In cases where governments lack the resources and political will, civil society has been found to provide complementary support structures. Academic OSPOs have also been reported across Institutes for Research and Higher Education.

The OSPO as a driver for digital sovereignty in Denmark

In this report, commissioned by Local Governments Denmark (KL) and the Danish Agency of Digital Government (Digitaliseringsstyrelsen), we consider the specific context of Denmark, and how its governments and PSOs can grow the capabilities necessary to enable sharing and reuse of OSS, grow a strategic autonomy (Edler et al., 2023), and exploit the innovation opportunities OSS provides (Blind et al., 2021).

Specifically, we build on the recommendation from the analysis of digital sovereignty in the Danish public sector, which proposes establishing a national centre for digital sovereignty and innovation (PA Consulting, 2026). Using the OSPO construct (Digitaliseringsstyrelsen, 2025), we aim to propose a design and strategy for the consideration and implementation of public-sector OSPOs that can support incentives and policy goals related to digital sovereignty in Denmark.

Through this study, we ask and address the following questions:

  • RQ1: How are strategic goals and vision in terms of digital sovereignty and potential opportunities of cross-government collaboration, sharing and reuse of OSS solutions characterised among Danish PSOs?
  • RQ2: What are the central barriers for cross-government collaboration, sharing and reuse of OSS solutions among Danish PSOs?
  • RQ3: What capabilities are required for cross-government collaboration, sharing and reuse of OSS solutions among Danish PSOs?
  • RQ4: How can the identified capabilities be enabled and realised through public-sector OSPOs in Denmark?

Digital sovereignty, interoperability and cost efficiencies core incentives

Interviews show a clear shift from viewing OSS primarily as a tool for vendor independence to understanding it as a practical instrument for digital sovereignty. OSS provides the power and freedom to switch and adapt systems, ensures credible exit options, and strengthens control over data and infrastructure. Innovation and interoperability are added value, with open standards and OSS enabling efficient data exchange and cross-government reuse. Cost and efficiency reinforce the case, as shared development reduces duplication, lowers operating expenses and strengthens the domestic and European supplier ecosystem.

(For further reading, see section 4)

Structural barriers and legacy culture hinder change

Progression towards policy goals and potential benefits is, however, hindered by structural barriers present across the public sector. Strategic misalignment leads to parallel efforts and inconsistent leadership support. A procurement culture shaped by dominant vendors reinforces lock-in and makes it difficult to mobilise early funding for OSS alternatives. Many PSOs lack the organisational and technical capabilities needed to adopt, maintain or contribute to OSS after years of outsourcing. Concerns about usability, security and operational risk further slow uptake, with short-term productivity perceptions often outweighing long-term benefits in flexibility, resilience and sovereignty.

(For further reading, see section 5)

Growing diverse and interconnected capabilities

Addressing challenges highlighted requires a coordinated set of capabilities that together form the foundation for a national OSS support structure:

Meeting with solid fillPolicy translation and strategic advice – Interpreting EU legislation and national priorities, and helping develop OSS strategies and governance models, while aligning cross-government policies on OSS and related areas and topics, including cloud, AI, data governance and security.

Open hand with solid fillDesign and operationalisation of policy instruments – Guiding when source code ownership is needed, and how necessary control mechanisms can be created including and beyond OSS; providing procurement guidance and hands‑on support, while maintaining essential templates and resources; enabling decision‑making for OSS release; supporting project initiation and community development; strengthening sustainability and supply‑chain risk management; and preparing organisations for emerging areas such as open source AI, and use of Agentic AI-support in software development.

Treasure chest with solid fillInvestment, prioritisation and scaling - Facilitating and promoting strategic seed funding and impact demonstration, as well as maintenance funding for critical digital infrastructure; developing prioritisation frameworks and migration pathways, and enabling joint agreements and coordinated rollouts.

 Tools with solid fillShared digital collaboration infrastructure – Establishing, growing, and governing a national government social code collaboration platform and OSS solution catalogue with related communities, templates, resources, on-ramps and taxonomies.

  Books with solid fillLicence compliance management - Providing routines, tools and guidance to ensure compliant OSS intake, SBOM‑based monitoring, pre‑release checks and ongoing auditability.

  Home1 with solid fillStewardship of public‑sector OSS projects - Ensuring long‑term sustainability and shared governance through association‑based, supplier‑based, internal, or state‑owned stewardship models.

 Ruler with solid fillMeasurement and follow‑up - Tracking adoption, reuse, project health, and compliance to guide risk management, improve infrastructures, and inform iterative policy refinement.

 Cheers with solid fillInner Source enablement - Supporting internal and cross‑government code sharing and collaboration to build open‑working habits before full external release is feasible; enabling government-internal sharing of assets deemed unfit for open dissemination and reuse.

Megaphone with solid fillAdvocacy and community building - Driving cultural change, building trust, and convening communities of practice across PSOs, suppliers, and civil society to normalise OSS collaboration.

 Classroom with solid fillTraining and competence development - Providing role‑specific capability building and training for policymakers, procurement officers, developers, legal teams, security specialists and end‑users.

(For further reading, see section 6)

A structure that fits Denmark’s decentralised governance

A comprehensive support structure is needed to develop and provision such capabilities, and must reflect Denmark’s decentralised, multi-actor public sector while strengthening national coherence. The analysis shows the value of building on and leveraging existing actors and distributing responsibilities across national, regional and local levels rather than concentrating them in a single entity. Any OSPO needs positioning where mandate, authority, and trust-based relationships align, along with presence of, and close feedback-loops from technical capabilities and standardisation efforts. Staffing with socio-technical OSS expertise and community-trust as key competencies are crucial for success. Strategic guidance must be paired with practical enablers such as catalogues, templates, shared platforms and procurement support. Internal capability building must progress alongside cross-government collaboration, supported by strong communication and change management functions. Sustainable stewardship models are required to maintain shared OSS solutions over time. Stable funding for both new alternatives and critical maintenance, combined with reusable artefacts and automation, is essential for scaling adoption.

(For further reading, see section 7.1)

Comparing organisational models for open source support

Three organisational models were assessed. A centralised model provides clarity but does not match the diversity and autonomy of Denmark’s public sector. A decentralised model provides flexibility but results in fragmentation and uneven capacity. A federated model, with national, regional, and local OSPOs supported by shared infrastructure and coordinated governance, offers the most resilient, scalable, and context-appropriate architecture.

(For further reading, see section 7.2)

A federated model for national, regional and local support

Figure 1: Overview of the national support structure, including the National Government, Regional Government and Association-based OSPOs supporting the national, regional and local levels of government respectively. Institution-centric OSPOs may be present across all levels. Local government OSPOs occur within single resourceful municipalities. National support functions as the National Project Steward and Project Broker supports the whole network.

Considering the characteristics and needs, the report presents a pragmatic, federated support structure for Denmark. The model reflects the Danish governance context - decentralised, multi‑actor, and capability‑uneven - while drawing on empirical lessons from European reference cases. It is designed to grow and coordinate the capabilities necessary for public‑sector OSS adoption, reuse, collaboration, and stewardship, as detailed in Section 6, and to connect these capabilities across levels of government through a coherent national OSPO network.

The structure comprises and depends on several building blocks:

  • A National Government OSPO hosted by the Agency of Digital Government, anchoring policy translation, national instruments, shared infrastructures, and cross‑government coordination.
  • A Regional Government OSPO providing coordinated support for the five regional governments, hosted by one of the Regions, or through a common-owned entity.
  • An Association-based OSPO through OS2 providing proximity support, localisation of guidance, and aggregation of municipal needs.
  • Local Government OSPOs are embedded where needs and capacity align in local governments, and are focused on internal governance, intake/release processes, and developer enablement.
  • Institution‑centric OSPOs are embedded where need and capacity align in single PSOs (regardless of the level of government), and are also focused on internal governance, intake/release processes, and developer enablement.
  • Supporting national functions, including stewards, a project brokerage, procurement bodies, and funding programmes, that ensure the long‑term sustainability, discoverability, and operationalisation of shared OSS projects.

Together, these entities form a distributed yet coordinated ecosystem capable of delivering the technical, organisational, and policy‑related support that Denmark requires to scale OSS-based collaboration and improve digital sovereignty.

(For further reading, see section 7.3)

A stage-based model for practical, sequenced implementation

Figure 2: Five stage maturity model prescribing how the national support structure can evolve and mature in a coherent and systematic approach.

The development of a national, federated support structure for OSS requires a sequenced, capability‑building approach. A staged maturity model is, therefore, defined, prescribing how Denmark can move from today’s fragmented practices to a coherent, resilient ecosystem that supports national digital sovereignty.

Stage 0 – Foundational planning and alignment establishes the mandate and minimal structures needed to begin coordinated action. A National Government OSPO is set up within the Agency for Digital Government and staffed with OSS expertise and community trust as key requirements, an OSPO Network is formed across key actors, initial strategy work begins, and prototypes for essential guidelines and processes, as well as the national OSS catalogue and social code collaboration platform are launched.

Stage 1 – Structural formation and early community build‑up focuses on validating early tools, processes, and support functions. A Regional Government OSPO is established, and OS2 is formalised as an Association-based OSPO responsible for scaling OSS support across municipalities. Procurement templates with sovereignty requirements are drafted and evaluated, intake and release processes are formalised, communities of practice emerge, stewardship pathways for OSS project archetypes are defined, and initial training builds basic competence across PSOs.

Stage 2 – Federated foundations and structured support matures support through revised processes and guidelines based on lessons learned, national funding programmes are launched, and communities of practice mature into national working groups supported by shared governance and maintenance cycles.

Stage 3 – Coordinated scaling and institutionalised practice formally embeds OSS considerations into procurement, compliance, and development routines. Reuse becomes standard practice, compliance processes and SBOM‑based checks are widely adopted, and multi‑year funding strengthens critical shared infrastructure.

Stage 4 – Embedded, resilient, and strategically aligned ecosystem completes the transition. Open‑by‑default becomes routine where appropriate, long‑term stewardship and funding are stable, and Denmark actively contributes to European digital commons while maintaining a metrics‑driven, sovereignty‑aligned digital ecosystem.

(For further reading, see section 7.4)

Recommendations and guardrails to guide national action

OSS provides a strategic tool (among many) for countries, such as Denmark, to build digital autonomy and resilience. Yet it is important to stress that it is a tool, not a magic wand, and to use a tool correctly, one needs to learn how to use it. OSS in this context requires a culture and practice of collaboration, openness, and transparency, where change management, training, and advocacy are essential. Capabilities as such need to be organised and coordinated within a support structure that enables collective growth and learning, and action towards the vision of a more digitally sovereign future.

Although Denmark already benefits from strong forerunners and promising collaborations, these efforts remain fragmented, lacking scale and mandate. Nevertheless, they offer a valuable foundation and a strategic opportunity to advance toward greater digital sovereignty. Building on this reality, the report outlines the capabilities required and proposes pathways for organising them so that Denmark can progress from today’s dispersed initiatives to a coherent, sustainable, and sovereignty‑aligned digital ecosystem. The commissioning bodies are therefore strongly encouraged to adopt the proposed stage‑based approach to systematically grow these capabilities over time.

The scope of this report has been limited to investigating how OSS can be supported on a national scale in Denmark and its public sector. Some consideration, though limited, has been given to using other open technologies that provide a complementary toolset to OSS, including open standards and open source AI. The academic and scientific contexts, civil society, as well as general linkage, policy and support for the industry have also received limited attention. Future work and investigation are strongly encouraged into how the public-sector support structure can extend and integrate with the wider society, considering open technologies at large as a lever for digital sovereignty, interoperability, and innovation.

References

  • Aarhus Kommune. (2014). Handlingsplan for open source i Aarhus Kommune: En del af vores it‑strategi. https://gambit.aakb.dk/opensource/Handlingsplan_for_OpenSource_i_Aarhus_Kommune.pdf
  • Asterès. (2025, April). Technological dependence on American software and cloud services: An assessment of the economic consequences in Europe [PDF]. Cigref. https://www.cigref.fr/wp/wp-content/uploads/2025/05/TECHNOLOGICAL-DEPENDENCE-ON-AMERICAN-SOFTWARE-AND-CLOUD-SERVICES-AN-ASSESSMENT-OF-THE-ECONOMIC-CONSEQUENCES.pdf
  • Blind, K., Böhm, M., Grzegorzewska, P., Katz, A., Muto, S., Pätsch, S., & Schubert, T. (2021). The impact of open source software and hardware on technological independence, competitiveness and innovation in the EU economy (Final Study Report). European Commission.
  • Digitaliseringsstyrelsen. (2025). Open source i den offentlige sektor. https://digst.dk/media/2zlfki2v/open-source-i-den-offentlige-sektor.pdf
  • Di Marco, D., Thabit, S., Kotsev, A., Christensen, A., & Minghini, M., et al. (2025). Open but not powerless: Towards a common understanding of EU digital sovereignty (JRC144908). European Commission.
  • Edler, J., Blind, K., Kroll, H., & Schubert, T. (2023). Technology sovereignty as an emerging frame for innovation policy. Research Policy, 52(6), 104765.
  • European Commission. (2017a). Tallinn Declaration on eGovernment. https://digital-strategy.ec.europa.eu/en/news/ministerial-declaration-egovernment-tallinn-declaration
  • European Commission. (2020a). Berlin Declaration on Digital Society and Value‑based Digital Government. https://digital-strategy.ec.europa.eu/en/news/berlin-declaration-digital-society-and-value-based-digital-government
  • European Commission. (2020b). Open Source Software Strategy 2020–2023: Think Open. https://commission.europa.eu/system/files/2023-02/en_ec_open_source_strategy_2020-2023.pdf
  • European Commission. (2022). Strasbourg Declaration on the Common values and challenges of European Public Administrations. https://joinup.ec.europa.eu/collection/open-source-observatory-osor/news/new-strasbourg-declaration
  • European Commission. (2026, January 12). Commission opens call for evidence on open‑source digital ecosystems. https://digital-strategy.ec.europa.eu/en/news/commission-opens-call-evidence-open-source-digital-ecosystemsEuropean Parliament. (2026, January 22).
  • European technological sovereignty and digital infrastructure (2025/2007(INI)). https://www.europarl.europa.eu/doceo/document/TA-9-2026-0022_EN.pdf
  • Færdselsstyrelsen. (2025). Færdselsstyrelsen tager første skridt mod open source‑pc’er i staten. https://www.fstyr.dk/nyheder/2025/dec/faerdselsstyrelsen-tager-foerste-skridt-mod-open-source-pc’er-i-staten
  • Folketinget. (2025, April 23). DIU høring digital suverænitet. https://www.ft.dk/da/aktuelt/nyheder/2025/04/diu-hoering-digital-suveraenitet
  • Kummer, C. (2025, June 18). Aarhus and Copenhagen choose open source. Interoperable Europe Portal. https://interoperable-europe.ec.europa.eu/collection/open-source-observatory-osor/news/aarhus-and-copenhagen-choose-open-source
  • Laursen, J. (2025, October 22). Aarhus udfaser Microsoftpakken. HK Kommunal. https://www.hk.dk/aktuelt/nyheder/2025/10/22/aarhus-udfaser-microsoftpakken
  • Linåker, J., & Muto, S. (2024). Software reuse through open source software in the public sector: A qualitative survey on policy and practice. RISE Research Institutes of Sweden.
  • Linåker, J., Nummelin Carlberg, A., & O’Riordan, C. (2024). Public Sector Open Source Program Offices – Archetypes for how to grow (common) institutional capabilities. European Commission, DIGIT. https://arxiv.org/pdf/2603.04891OS2. (2025, December 3).
  • OS2skole – en ny digital platform. https://boks.os2.eu/PA Consulting. (2026, January). Digital suverænitet i den offentlige sektor: Sammenfattende analyse. KL. https://www.kl.dk/
  • Regeringen, KL, & Danske Regioner. (2025). Den fællesoffentlige digitaliseringsstrategi 2026–2029. Digitaliseringsstyrelsen. https://digst.dk/
  • Ruff, N. (2022). The rise of the Open Source Program Offices (OSPO). In A. Brock (Ed.), Open source law, policy and practice. Oxford University Press.
  • von der Leyen, U. (2026, January 20). Special address at the World Economic Forum (SPEECH_26_150). European Commission. https://ec.europa.eu/