EU Procurement Proposal Adds Open-Source and Lock-In Provisions

European Union procurement graphic showing a policy document connected to code cloud settings data security and public institutions to represent new proof requirements for technology suppliers. Text reads "POLICY & GOVERNANCE". "Procurement Rules Could Shift What Technology Suppliers Must Prove". "Open-source access is only one part of the proposal".

Public buyers across the European Union could consider open-source solutions when pursuing innovation objectives under a proposed overhaul of procurement law. The European Commission published COM(2026) 590 on 9 September 2026. If adopted, the regulation would replace three procurement directives from 2014 with a single framework directly applicable across European Union member states.

For Drupal agencies and other open-source suppliers, the significance lies in open source appearing explicitly in the proposed procurement rules rather than being inferred from wider digital policy. Article 61 says public buyers pursuing innovation objectives may consider purchasing open-source solutions or solutions with open-source elements. Article 132 separately would require the solution developed for the Commission's own eProcurement platform to be made available as open-source software. Neither provision creates an automatic preference for open-source software in ordinary public tenders.

The proposal also addresses the contractual control public buyers retain over technology after an award. Article 63 would require suppliers to grant appropriate and sufficient non-exclusive licences covering rights needed to use, operate, adapt, configure, integrate, maintain, repair, support and upgrade contractual deliverables where necessary for their continued use. For a Drupal implementation, that could matter when an authority changes agencies, appoints another maintenance provider or needs to keep a system operating after a supplier relationship ends. Article 64 separately provides rules for ownership of intellectual property and allows public buyers using an innovation procedure to depart from supplier ownership of newly created rights where overriding public-interest reasons, including prevention of technological lock-in, justify doing so.

Cybersecurity and resilience would also become more explicit parts of procurement design. Article 68 requires cybersecurity requirements under the Cyber Resilience Act to be considered for products with digital elements that fall within its scope, while buyers may set additional contract-linked cybersecurity requirements. Article 69 applies additional resilience and security-of-supply requirements where contracts involve identified critical entities or specified critical infrastructure, including measures concerning supply-chain diversification, business continuity, disaster recovery and continued access to necessary components.

Award decisions would, as a rule, use the best price-quality ratio rather than price alone. Article 98 sets a minimum quality weighting of 30%, rising to 50% for labour-intensive contracts, although buyers may derogate where quality can be ensured through specifications, contract-performance conditions or an allowed combination of controls. Quality criteria may cover technical merit, accessibility, innovation, security, resilience and European-preference requirements when those requirements are used. For technology suppliers, that framework could increase the importance of demonstrating operational qualities alongside price.

The European-preference provisions require a separate distinction between software licensing and supplier origin. Article 73 allows buyers to restrict participation to Union operators and operators covered by the European Union's international procurement commitments, apply origin requirements or use evaluation preferences in specified circumstances. An open-source Drupal implementation therefore does not by itself determine whether a bidder or the other elements of its tender meet European-preference requirements.

The proposal would also create a more integrated digital procurement infrastructure, including an interoperability network, electronic eligibility services and national and European Union procurement data spaces. Providers of the eProcurement services governed by Article 131 would have to be established in the European Economic Area and owned and controlled by persons established there. Those requirements apply to the eProcurement service providers covered by that chapter and should not be read as a general location or ownership rule for every cloud or software supplier serving a public authority.

The Public Procurement Act remains a legislative proposal, and the European Parliament and Council can amend its open-source, security, market-access and digital-procurement provisions before adoption. As drafted, the regulation would enter into force 20 days after publication in the Official Journal of the European Union and apply two years after entry into force. There is therefore no current two-year implementation countdown while the proposal remains under consideration.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Related Organizations

Upcoming Events

Latest Opportunities