The launch gets the minister, the ribbon and the press release. Support gets a line in an appendix, if it's lucky.

That's backwards. A national system spends a few months being built and many years being run.

The short answer: after go-live, a digital public good needs ongoing support: fixes, monitoring, security testing, upgrades to new releases and help for users. It's usually delivered through an annual maintenance contract (AMC) with a local partner, a regional or global systems integrator, or the government's own team, often in combination. Decide who does it, from where and on whose budget before you sign the implementation contract, not after launch.

Key facts:

  • Brazil's Pix costs about $14 million a year to run, against about $4 million to build (DIAL)
  • Maintenance is often a "lost art" in government, leaving new digital tools to fall into disrepair (DIAL, citing Sarah Fisher)

Why support gets forgotten

Implementation is a project. It has a start, an end, a budget and people whose job depends on delivering it.

Support is an operation. It never ends, it's rarely exciting, and it tends to fall between the ministry, the funder and the implementation partner. So it becomes an afterthought, when in my view it's almost as important as the build itself.

Who provides support for a DPG?

There are three models, and most countries end up with a mix:

Model Who Works well when Watch out for
In-country team Government's own technical staff There's real capacity and the budget to keep it Staff turnover and hiring freezes
Local partner An in-country SI trained on the DPG You want fast response and local knowledge Depth on complex issues
Regional or global partner A larger SI or technology firm, often cross-border You need depth and specialist skills Time zones, travel, cost

The best setups I've seen pair a local partner for day-to-day support with a larger partner or the DPG's own team for the hard stuff.

Where should support be delivered from?

This matters more than people expect. Civil registration and ID systems hold the most sensitive personal data a state has. Some countries won't allow remote access from outside their borders at all.

Check three things early:

  1. Can support staff access the system remotely, and from where?
  2. Do data residency rules limit who can see production data?
  3. Is there a local partner who can be physically on site if needed?

If the answers push support in-country, build local capacity from day one. Don't wait until the international team flies home.

person gesturing during meeting with laptop
02 / IN CONTEXTPhoto: Headway / Unsplash

What should an AMC cover?

At a minimum:

  • Bug fixes and incident response, with agreed response times
  • Monitoring and backups
  • Security patches and regular penetration testing of your deployment
  • Upgrades to new DPG releases
  • User support and refresher training as staff change
  • Small configuration changes, such as new forms or certificate updates

Upgrades deserve special attention. DPGs keep improving. If your deployment falls several versions behind, you lose security fixes and new features, and catching up gets harder each year.

Implementation drift: the risk nobody talks about

Here's the risk I'd put above almost any other.

DPGs come with recommended setups for hosting, security and networking. But the government has the final say, and often runs the system on its own hardware, behind its own VPNs and security tools. Over time, the actual deployment can drift away from best practice.

No single change looks dangerous. Together, they can leave you with a poorly configured, insecure deployment of a perfectly secure product. I've seen it happen.

My take: the fix is boring and it works. Keep a written baseline of the recommended configuration, and check the live system against it every year as part of the AMC. More in the real risks of DPI.

Sustainability is the next frontier

Across the DPG world there's a strong push, from the DPGs themselves, funders and the wider community, towards sustainability: making sure these systems can be funded, supported and improved for decades.

For a government, that means treating support as a permanent budget line from day one. A budget without it isn't a budget. It's a down payment. See how much DPI costs to implement.

Frequently asked questions

What is an AMC? An annual maintenance contract: an agreement for ongoing fixes, upgrades, monitoring and support after a system goes live.

Who supports open source government software? Usually a local partner, a regional or global systems integrator, or the government's own team, often in combination, with the DPG's core team maintaining the product itself.

How much does DPG support cost? It varies with scale and scope. Budget for it from the start, for at least three years, rather than after launch.

Why do DPG deployments fall behind on versions? Usually because upgrades weren't in the support contract. Make them an explicit AMC line.

Sources

Planning support for a DPG deployment? Let's talk.

Choose from all 20 guides