Tag Archives: linux foundation

Measuring OSPO Value: A new Linux Foundation Report

Regular readers of this blog know that helping organizations demonstrate the value of their open source efforts is something I’ve been focused on for a while, and it’s one of the consulting services that I offer. I recently summarized some of my thoughts on this topic into a single blog post where you can learn more: A Strategic Approach to Demonstrating the Value of OSS Efforts.

This is why I was so delighted to review and provide feedback on a recent Linux Foundation report on this topic along with writing a blog post summarizing the report. The blog post originally appeared on the Linux Foundation blog, but I wanted to also re-post it here for reference.


Measuring OSPO Value

Originally posted on 29 June 2026 at https://www.linuxfoundation.org/blog/measuring-ospo-value

Open Source Program Offices (OSPOs) play important roles within organizations, but that role isn’t always appreciated or understood within the executive team or by other stakeholders. In the current financial climate, some OSPOs have been the targets of cutbacks and layoffs, so this is a particularly important time for OSPOs to be clear about the value that they provide to their organization. Leaders within every organization are responsible for making sure that their organization focuses on the activities that have the biggest impact on helping that organization achieve their goals. As a result, OSPOs need to be able to demonstrate that the value of their work can have a larger impact on the organization than the other initiatives that are also competing for resources. As the CHAOSS OSPO Metrics Working Group co-chair and CHAOSS board member, the topic of measuring OSPO value is one that I have cared deeply about for years, and I recently gave a talk on this topic at the Open Source Summit North America in May. This is why I was so excited to read Ibrahim Haddad’s latest report, Measuring OSPO Value: A Framework for ROI, Resilience, Risk Foresight, and Strategic Influence, and share a few highlights from the report in this blog post.

It’s easy to say that OSPOs should be better at measuring value, but it’s not quite that straightforward. OSPO value has always been difficult to measure because much of the work is preventative, the effects are distributed throughout the organization, the impact is spread across multiple time horizons, and the work is cross-functional. However, it’s become increasingly urgent with the ubiquity of open source software impacting revenue-critical systems, security and supply chain expectations increasing, regulations having a bigger impact on open source, and AI-generated code adding complexity.

There is no one way to measure OSPO value, so the report uses a framework with 4 interrelated dimensions that can help OSPOs reason about value from multiple perspectives that can be applied through the lens of their unique organizational goals.

ROI and cost avoidance. In my experience, when executive leadership and finance are questioning an OSPO’s value, they usually start by asking questions about ROI, but this narrow framing doesn’t tend to be particularly useful in my opinion. OSPOs don’t typically generate direct revenue, but they can have an impact on cost avoidance, including reduced duplication, improved efficiency, and lower maintenance costs that can be used for financial justification.

Resilience. Engineering and security leadership on the other hand want to better understand how the OSPO is helping the organization avoid disruption through preparation related to visibility and management of dependencies, SBOM coverage, licensing or provenance concerns, and readiness around engineering decisions. When this is done well, everything proceeds smoothly and crises are avoided, but this is why measuring resilience proactively is an important part of measuring OSPO value.

Risk foresight. While resilience is about preparedness, risk foresight is about detecting potential issues early enough to mitigate the impact and avoid incidents. This includes detecting potential license issues, governance problems, supply chain concerns, security vulnerabilities, and regulatory / policy changes. This value can be measured and communicated by documenting near-misses and creating a narrative around how the OSPO took action to prevent the issues. The CHAOSS Assessing Viability Practitioner Guide provides additional insight into this dimension.

Strategic influence. This dimension measures an OSPO’s long-term value, including how the OSPO strategically invests in the open source ecosystem with presence, engagement and influence in technologies, standards, and organizations that are critical for the organization now and in the future. We also covered some of this in the CHAOSS Demonstrating Organizational Value Practitioner Guide.

The report also highlighted a few principles for building a measurement system across these 4 dimensions, including measuring outcomes (not activities), focusing on a smaller number of indicators, using both quantitative and narrative approaches, explicitly documenting assumptions, distinguishing between enabled value and owned value, avoiding metrics that punish disclosure, designing for maturity, stating framework limits, and having metric continuity. Ultimately, all of this work to measure and demonstrate value needs to be communicated to executives and other stakeholders in a way that they can understand the importance of the OSPO. Ibrahim’s report has more details on tailoring communications to specific audiences, using scorecards, evolving your approach over time, and a practical roadmap for implementation.

If you work in an OSPO or do open source work within an organization, now is the perfect time to rethink how you measure and demonstrate the value of this work, and this report is a great way to get started or get you thinking about how you can improve your existing approach to measuring OSPO value.

Link to read the full report.


I hope you enjoyed reading this blog post! If you want feedback or help with your open source strategy and how to demonstrate value for your organization, I’m available for consulting engagements.

Related blog posts:

LinuxCon Review: It's All About Community

I had a great time at LinuxCon this week, and I loved that it was held here in Portland, OR. My favorite part of the event was running into old friends and ex-coworkers from my days at Intel who I haven’t seen in ages. It was great catching up with everyone, and I even managed to introduce a few of them to Whiffies and some of my other favorite food carts for quick lunches or late night snacks.

LinuxCon

I did a much longer review of the event over on the Olliance Blog, but I wanted to highlight a few things here on Fast Wonder, too.

Community.

I love the sense of community that you get at conferences where most of the audience members are open source developers. People with laptops were clustered together in little groups having conversations, working on code, and eating Voodoo donuts (how many conferences have strangely colored donuts covered with things like bacon and breakfast cereal?)

My favorite community-related session was a keynote by Bdale Garbee on The Freedom to Collaborate. Much of what he said is common knowledge for those us in the open source world, but it got me thinking more about how companies and communities interact. I won’t duplicate everything here, but I wrote several paragraphs with my thoughts on this session on the Olliance Blog.

Linus Torvalds. The Linux Kernel Roundtable was one of the most popular sessions with a room full of geeks listening to Linus and other kernel developers talk about various Linux kernel topics.

Moblin. This was a hot topic at the event, and I’m not just saying this because Intel is a client. People were talking about Moblin in hallways and presenters kept mentioning them in sessions. This was a Linux Foundation event, and Moblin was turned over to the Linux Foundation by Intel in early April, so that could explain at least some of the buzz.

Fun. We had the Fake Linus Torvalds contest where Matt Asay came out ahead of Dan Lyons (the famous FakeSteveJobs guy). We even had an appearance from Steve Ballmer, or maybe it was Jeremy Allison as Steve Ballmer at the Golden Penguin Bowl, which was filled with funny geek trivia and a live helicopter battle.

If you want to know more about LinuxCon, you can read my longer review of the event.