Open Source Isn’t Free: Structuring Your Company’s Contribution Strategy
Software underpins nearly every modern industry, from automotive and healthcare to climate technology. Behind that infrastructure sits a global community of open-source developers, maintainers, and contributors. The future of software development depends on this ecosystem, yet the relationship between large enterprises and the community remains asymmetric. A Tidelift study found that only 15% of organizations are extremely confident in their open-source management practices, while a Red Hat survey reported that 80% expect to increase their use of enterprise open-source software for emerging technologies.
Bridging that gap requires more than passive consumption. Companies must actively participate in and support the open-source projects they depend on. Here are three practical steps for building a sustainable open-source strategy.
Take Stock of Your Current Engagement
Before expanding involvement, organizations need a clear picture of how they already work with open-source developers. Do teams have dedicated internal resources that explain collaboration processes? Is there a defined path for making upstream contributions?
The absence of formal processes creates friction. The Tidelift study noted that while 61% of organizations have a formal approval process for introducing new open-source components, the process in large enterprises can take a week or more to complete. This red tape discourages developers from contributing back to the projects they use.
To counter this, companies should make it easier to release open-source code and aim to open-source everything possible. Establishing lightweight guidelines for creating and maintaining open-source projects accelerates approval timelines and clarifies what good governance looks like.
Formalize Governance with an Open-Source Program Office
Once processes exist, an open-source program office (OSPO) can scale them across the organization. An OSPO works cross-functionally—with legal, HR, engineering, and security—to reduce barriers for developers. It serves as the front-line support team for anyone in the company with open-source questions, boosting confidence and reducing friction.
OSPOs are not exclusive to tech giants. Startups, financial services firms, and academic institutions can all establish them. Leadership for these initiatives often comes from unexpected places; developers, engineers, and program managers have all successfully spearheaded OSPOs. For organizations starting from scratch, the TODO Group offers case studies, guides, and surveys as a public resource for building a program.
Invest Directly in the Community
As software supply chains grow more complex, companies face a responsibility to give back to the open-source community that supports them. Events like the Log4j vulnerability demonstrated this dynamic starkly: volunteer developers dedicated personal time to patch critical libraries that enterprises relied on for core operations. Those efforts merit recognition and financial support.
Sponsorship is an accessible entry point. Companies can fund the projects and developers they depend on, opening a direct conversation with maintainers. Options range from platforms like Outreachy, Open Collective, and GitHub Sponsors to established foundations including the Linux Foundation and OpenJS. No contribution is too small to begin the relationship.
Open source is not a one-way dependency; it is a collaboration. Organizations that implement a formal strategy—starting with an internal audit, adding structural governance through an OSPO, and then investing in the community—position themselves to accelerate development while supporting the ecosystem that makes modern software possible.



