"How can it be free?"
That's the first question I get from almost every government official the moment digital public goods come up. Not "what does it do" or "who else uses it". Just a raised eyebrow and that question.
The short answer: a digital public good (DPG) is open source software, open data, an open AI model, an open standard or open content that respects privacy and the law, is designed to do no harm, and helps achieve the UN Sustainable Development Goals. Anyone can use, adapt and deploy it without a licence fee. The Digital Public Goods Alliance checks candidates against a nine-point standard and lists the ones that pass on a public registry.
Key facts:
- The definition comes from the UN Secretary-General's Roadmap for Digital Cooperation (DPGA)
- The Digital Public Goods Alliance was launched in late 2019 by Norway, Sierra Leone, UNICEF and iSPIRT (GitHub Social Impact)
- To qualify, a solution must meet all nine indicators of the DPG Standard (DPGA)
- DPG status lasts one year, then gets re-reviewed automatically (DPGA)
What counts as a digital public good?
Five kinds of thing can qualify:
- Open source software
- Open data
- Open AI systems
- Open standards
- Open content collections
Being open isn't enough, though. Plenty of open source projects are brilliant and still aren't DPGs. The difference is the public-good test: relevance to the SDGs, respect for privacy and the law, and a design that anticipates and prevents harm.
The nine indicators, in plain English
| Indicator | What it actually means |
|---|---|
| Relevance to the SDGs | It has to help with a real development goal |
| Approved open licence | Anyone can use and adapt it |
| Clear ownership | Someone identifiable is responsible for it |
| Platform independence | No hidden dependency on one vendor's closed tech |
| Documentation | Good enough for someone else to deploy it |
| Data extraction | You can get your data out in usable formats |
| Privacy and applicable laws | It respects data protection rules |
| Standards and best practice | It follows recognised technical standards |
| Do no harm by design | Privacy, security, content and harassment risks are addressed |
Indicators four and six are the ones governments should care about most. Platform independence and data extraction are, in effect, the anti-lock-in clauses.
Examples of digital public goods
| DPG | What it does |
|---|---|
| OpenCRVS | Civil registration: births, deaths, marriages |
| MOSIP | Foundational digital identity |
| DHIS2 | Health information and data |
| X-Road | Secure data exchange between systems |
| Mojaloop | Interoperable digital payments |
| OpenG2P / OpenSPP | Social protection and benefit payments |
A quick disclosure: I lead commercial partnerships at OpenCRVS, so I'm not neutral on the first one.
Some of these are building blocks a country uses to lay its core infrastructure, such as MOSIP for identity. Others, like OpenCRVS or DHIS2, deliver specific services on top. That's the DPI vs DPG distinction in a nutshell.

So why don't governments trust them?
Because for decades, government technology has meant big proprietary vendors, long contracts and hefty licence fees. Governments are used to paying a lot and assume that's what quality costs.
So when something shows up that's free, well documented and already running in other countries, the instinct is suspicion. It feels too good to be true.
The usual follow-ups are fair ones. Who maintains it? Who implements it? How long does it take? How secure is it?
The good DPGs answer those through open standards, security by design and open code anyone can inspect. OpenCRVS, for example, has every release penetration tested by an independent, CREST-certified third party, with testers including MDSec and Gofore. And because the code is open, anyone can check the work. A closed system can't offer that.
The trust gap is closing. The number of deployments and the size of the ecosystem around DPGs make the "it can't be good if it's free" argument harder to hold every year.
Is a digital public good actually free?
The software is. There's no licence fee and no vendor lock-in.
What isn't free is making it work in your country: configuration, integration, data migration, training, hosting and support. That's usually delivered by a systems integrator. I break the numbers down in how much DPI costs to implement.
My take: "free software" is the wrong way to sell DPGs. The real pitch is that every dollar goes into your country's capacity and not into someone else's licence revenue.
Why don't more consultants know about DPGs?
Because it's a genuinely small world. Most mainstream tech consultants have never heard of DPGs or DPI. The ones who have tend to work in emerging and frontier markets, often alongside development funders.
That's half the reason I wrote The Best-Kept Secret in Global Development. If you want the opinion piece, start there.
Frequently asked questions
Who decides what is a digital public good? The Digital Public Goods Alliance, which reviews nominations against its nine-indicator DPG Standard.
Is all open source software a DPG? No. It must also be relevant to the SDGs, respect privacy and the law, and be designed to do no harm.
Can a company own a DPG? Yes. Ownership must be clear, but the solution must be openly licensed so anyone can use and adapt it.
Where can I find a list of DPGs? On the DPGA's public DPG Registry.
Sources
- Digital Public Goods, Digital Public Goods Alliance
- Registry process, Digital Public Goods Alliance
- What are digital public goods and the DPGA?, GitHub Social Impact
- Security, OpenCRVS documentation
Weighing a DPG for your country? Let's talk.

