The 2026 State of Open Source Report

But the data from the 2026 State of Open Source Report by Perforce OpenLogic (produced in collaboration with OSI and the Eclipse Foundation) suggests that the mindset has changed. This year’s findings point to open source as a strategic concern for IT leadership, shaped by geopolitical pressure, security risk, compliance complexity, and the growing operational burden of maintaining open source software at scale. The data shows that 31% of enterprise Java teams are devoting only 10-25% to new functionalities, which directly impacts delivery timelines, developer morale, and long-term innovation capacity. Key Finding #3: Security and Vulnerability Management Remain Core Weak Points Despite growing maturity in open source adoption, security updates and patching remain the most persistent challenge, regardless of organization size. Also notable: 20% of organizations report having no specific process for responding to CVEs 39% of large enterprises struggle to meet their internal SLAs for vulnerability remediation 55% of organizations that failed a compliance audit last year have EOL open source software in their stacks This gap is especially concerning for those responsible for risk management, compliance, and audit readiness. Less than 2% of organizations reported a decrease in their OSS consumption in the last year; for the 98% who increased or maintained their usage, the challenge is figuring out how best to support, secure, and sustain it at enterprise scale without sacrificing innovation, resilience, or control.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source