A government official once put it to me like this: "We're already using one or two DPGs in our stack. What else is out there?"
That question is the whole commercial case for becoming a digital public good. If you're on the list, you're in the answer.
The short answer: to become a digital public good, a solution is nominated through the Digital Public Goods Alliance's public form, then reviewed by the DPGA technical team against the nine indicators of the DPG Standard. If it passes, it's added to the DPG Registry and gets the DPG badge. Status lasts one year, then gets re-reviewed automatically. For most open source products serving governments, it's worth it.
Key facts:
- Anyone can nominate a solution, including its own team (GitHub Social Impact)
- Review is against all nine indicators of the DPG Standard (DPGA)
- Approved DPGs are listed on the DPG Registry, which also feeds partner catalogues such as DIAL's (DPGA)
- Status is valid for one year, followed by automatic review against the latest standard (DPGA)
How does the DPG application process work?
- Nomination. Submit the solution through the DPGA's public form. You can nominate your own product.
- Technical review. The DPGA team checks your documentation against the nine indicators.
- Registry listing. Pass, and you're added to the DPG Registry with the DPG icon.
- Annual re-review. After a year, you're automatically reviewed again against whatever the current standard is.
That last step matters. DPG status isn't a trophy you win once. You have to keep earning it.
What does the DPG Standard ask for?
Nine things. The full list is in my guide to what a DPG is, but in practice they fall into four groups:
| Group | What reviewers look for |
|---|---|
| Purpose | Clear relevance to at least one Sustainable Development Goal |
| Openness | An approved open licence, clear ownership, and a way to get data out |
| Reusability | Platform independence and documentation good enough for someone else to deploy |
| Responsibility | Privacy and legal compliance, standards and best practice, and do-no-harm by design |
Most serious open source projects already clear the openness bar. Where teams come unstuck is usually documentation and do-no-harm. Writing down how you handle privacy, security and misuse takes real work if you've never had to.
Is DPG status worth it?
In my view, definitely. Here's what it actually gets you.
Doors. DPG status opens conversations directly with governments and the wider ecosystem: funders, multilaterals, the DPGA's own network. For a small product team, that access is hard to buy any other way.
Positioning. The badge does a lot of marketing work for you. It tells a ministry your product has been independently checked for openness, privacy and harm, before you've said a word.
Company. You join a mature ecosystem of DPGs already delivering for governments. That's where the "what else is out there?" question comes in. Governments running one DPG actively look for others that fit alongside it. See how DPGs work together.
Discoverability. The registry feeds partner catalogues, so your product turns up in places where governments and funders are actively searching.
What it won't do is win you a contract on its own. The badge gets you in the room. Delivery, references and a credible implementation network are what close the deal.

Who should bother?
It's worth it if:
- Your product is genuinely open source, not open core with the useful bits locked away
- Governments, NGOs or multilaterals are your buyers
- You can commit to documentation and do-no-harm practices for the long run
It's probably not worth it if your commercial model depends on keeping key features proprietary. The standard is specifically designed to rule out lock-in.
What comes after the badge?
The smart DPGs build an ecosystem around themselves once they're listed. Most run accreditation or partner programmes that train systems integrators to implement the product.
That solves the question every government asks next: "Who's going to implement it here?" A DPG with accredited partners across regions can answer with names. At OpenCRVS, where I lead commercial partnerships, we see Tier 1 firms like Deloitte and EY alongside small local tech companies getting trained up and taking on projects in their own markets. More in how systems integrators make money on DPGs.
My take: DPG status is the entry ticket. The partner ecosystem is what turns it into deployments.
Frequently asked questions
How long does it take to become a DPG? It depends mostly on how ready your documentation is. Products with solid documentation and clear licensing move fastest.
Does it cost anything to become a DPG? Nomination is through the DPGA's public form. The real cost is the time spent on documentation and do-no-harm policies.
Can a commercial company's product be a DPG? Yes, if it's openly licensed, has clear ownership and meets the other indicators.
Can you lose DPG status? Yes. Status is reviewed every year, and a product that no longer meets the current standard can drop off.
Sources
- Registry process, Digital Public Goods Alliance
- Digital Public Goods, Digital Public Goods Alliance
- What are digital public goods and the DPGA?, GitHub Social Impact
Building a product for governments and weighing DPG status? Let's talk.

