Business Models Wiki
Open-Source Business Models
An open-source business model gives away rights under an OSI-approved licence to create adoption, then charges for operation, assurance, or enterprise capability.
Snapshot
What it is
A business that distributes software under a licence meeting the Open Source Initiative's Open Source Definition, then earns revenue from something scarce around it — operation, governance, assurance, convenience, or enterprise capability.
Why it matters
Open source is a licence property, not a revenue model. The licence decides who may compete with you using your own code; the commercial model decides what you sell. Founders who conflate the two make an irreversible distribution decision for a reversible pricing reason.
What it is not
It is not "you can read the source." Source-available licences such as the Business Source License (BSL/BUSL), the Server Side Public License (SSPL), and the Elastic License 2.0 are not open source under the OSI definition, and none of them is OSI-approved. They may be perfectly good commercial choices. They are a different product claim.
Key takeaways
Adoption is not monetization. Downloads, stars, and pulls do not pay salaries. You need a conversion trigger tied to real operating pain.
The paid boundary should track a real cost or value difference, not artificial degradation of the free product.
Relicensing is expensive. Every major relicensing since 2018 produced a competitor fork within weeks or months.
Community engineering is a fixed cost. Model it explicitly; it is the line that decides whether the funnel closes.
Gross margin depends on what you sell. A managed cloud buys compute; a support-and-licence business does not.
On this page10 sections
What actually counts as open source?#
The Open Source Definition requires ten things of a licence, not one. Beyond source availability it demands free redistribution, permission to create and distribute derived works, no discrimination against persons, groups, or fields of endeavour, licence portability with the software, no product-specificity, no restriction on other software, and technology neutrality. OSI maintains the list of approved licences. (OSI, The Open Source Definition; OSI, approved licences)
The three criteria that source-available licences usually fail are no discrimination against fields of endeavour, free redistribution, and no restriction on other software.
| Family | Examples | OSI-approved? | Commercial effect |
|---|---|---|---|
Permissive | Apache 2.0, MIT, BSD-3 | Yes | Maximum reuse and adoption; anyone, including a hyperscaler, may operate it as a service |
Weak copyleft | LGPL, MPL 2.0 | Yes | Reciprocity at file or library boundary; comfortable for embedding |
Strong / network copyleft | GPLv3, AGPLv3 | Yes | AGPL extends reciprocity to network use, which deters some corporate adopters and some cloud resale |
Source-available, use-restricted | Elastic License 2.0, Confluent Community License | No | Prohibits offering the software as a competing managed service |
Source-available, service-copyleft | SSPL | No | Requires anyone offering it as a service to release the entire service-management stack |
Time-delayed | BSL / BUSL 1.1 | No while restricted | Use restricted for a defined period, then converts to a stated open-source licence at the Change Date |
Be precise in your own materials. MongoDB submitted the SSPL to OSI and withdrew the submission in 2019; OSI has consistently stated that SSPL is not an open-source licence. (Percona, Is MongoDB Truly Open Source?) Calling a source-available product "open source" is a defensible business decision made indefensibly — the licence text, dependencies, trademarks, contributor agreements, and distribution method all matter, and this page is not legal advice.
Why does the licence choice matter commercially?#
Distribution can begin before a sales conversation. Developers evaluate, adopt, integrate, and advocate without a procurement cycle. That is genuine product-led growth, and it lowers technical trust barriers a proprietary vendor has to buy.
A permissive licence invites a well-funded operator to run your software. That is the trade, and it is the entire reason for the relicensing wave below. Copyleft, particularly AGPL, shifts the calculus without leaving the definition.
Community trust is a balance-sheet asset with no line item. Documentation, governance, security response, release quality, and honest licence communication drive adoption. A surprise relicensing or a deliberately crippled free edition destroys it faster than any price change in ordinary SaaS.
The relicensing episodes, and what they cost#
| Company | Date of change | Moved to | Fork that followed | Later |
|---|---|---|---|---|
MongoDB | October 2018 | SSPL v1 | — | Withdrew SSPL from OSI review, 2019 |
Elastic | January 2021 | SSPL + Elastic License | OpenSearch (AWS), April 2021 | Added AGPLv3 as an option, 29 August 2024 |
HashiCorp | 10 August 2023 | BUSL 1.1 (from MPL 2.0) | OpenTofu, Linux Foundation, MPL 2.0 | Acquired by IBM, closed 27 February 2025 |
Redis | March 2024 | RSALv2 + SSPLv1 (from BSD) | Valkey, Linux Foundation, BSD | Added AGPLv3 with Redis 8, 1 May 2025 |
Two of the four relicensers later re-added an OSI-approved option — Elastic in 2024 and Redis in 2025 — and in both cases the fork had already accumulated maintainers, cloud distribution, and its own release cadence. (Elastic, Elasticsearch is Open Source, Again; Redis, Redis is now available under the AGPLv3; OpenTofu, OpenTofu Announces Fork of Terraform) The practical lesson for founders is not "never relicense." It is that a licence change is a one-way door on the community side even when it is reversible on the legal side.
How do you build the commercial model?#
1. Define the free value#
Specify precisely what a capable user can run, modify, and operate without paying. The free product must solve a coherent problem on its own. If it does not, it is a trial wearing a community project's clothes, and developers will say so publicly.
2. Choose a paid scarcity#
| Model | What you sell | Where the margin comes from | Main risk |
|---|---|---|---|
Managed cloud | Hosting, upgrades, scaling, backups, SLAs | Operational leverage over many tenants | Compute cost caps gross margin; hyperscalers can run it too |
Open core | Governance, security, collaboration, administration | Software margin on the paid edition | Boundary disputes; accusations of feature hostage-taking |
Support and assurance | Response times, certified builds, LTS, indemnity | Labour leverage and expertise | Headcount scales with accounts |
Dual licensing | Alternative rights where copyleft is incompatible | Pure licence margin | Only works with a strong copyleft base and clear IP ownership |
Hardware or appliance | An integrated deployment | Bundle spread | Inventory and supply chain |
Services | Implementation and expertise | Utilisation | Not a software business; hard to scale |
3. Build the conversion funnel#
commercial ARR = active organizations × qualified-use rate × paid conversion rate × ACV
Count organizations, not events. A qualified-use signal is something like production volume above a threshold, multiple collaborators, regulated data, or a request for centralized controls — not a download.
4. Test capture after community investment#
managerial contribution = paid ARR × gross margin − commercial acquisition cost − community-specific investment
Community engineering, events, and documentation usually sit in R&D or marketing in the statements, not cost of revenue. Include them here anyway, and label the result a managerial measure so nobody mistakes it for a GAAP figure.
5. Protect portability and trust#
Publish the licence, the edition boundary, the security policy, the roadmap process, the trademark rules, and the contribution terms. Measure external contributors, issue response time, upgrade adoption, and community-to-commercial conversion — without treating community members as unpaid leads.
Two public reference points. Elastic combines self-managed subscriptions with a managed cloud: fiscal 2026 revenue was $1,739.3m, of which $837.3m (48%) was Elastic Cloud, up from 46% in fiscal 2025, with a net expansion rate of about 112%. GitLab describes itself as built on an open-core model: fiscal 2026 revenue was $955.2m (+26%), subscription revenue $864.7m (+28%), and users contributed more than 6,500 merge requests during calendar 2025. (Elastic Q4/FY2026 results, 28 May 2026; GitLab fiscal 2026 Form 10-K) Their brands, installed bases, and licences differ; these are illustrations, not templates.
Worked example: does the funnel cover the community?#
A project has 50,000 active organizations. 3% show qualified production use; 12% of those buy at an ACV of $18,000.
qualified organizations = 50,000 × 3% = 1,500
paid customers = 1,500 × 12% = 180
new ARR = 180 × $18,000 = $3,240,000
At 82% gross margin, gross profit is $2,656,800. Commercial acquisition cost is $3,500 per converted customer, or $630,000. Annual community-specific engineering, events, and documentation cost $1,400,000.
managerial contribution = $2,656,800 − $630,000 − $1,400,000 = $626,800
Contribution per paid customer before the fixed community investment:
$18,000 × 82% − $3,500 = $11,260
break-even customers = $1,400,000 ÷ $11,260 = 124.3 → 125
Now break it. If paid conversion falls from 12% to 5%, you win 75 customers and $1.35m of ARR. Gross profit is $1,107,000, acquisition cost $262,500, and managerial contribution is −$555,500. The community did not fail; the funnel did.
The gross-margin assumption matters as much as the conversion rate. 82% suits a support-and-enterprise-licence mix. A managed-cloud business buys compute, so 65% is a more honest planning number — and at 65%, contribution per customer falls to $18,000 × 65% − $3,500 = $8,200 and break-even rises from 125 customers to 171. Decide which business you are in before you pick the margin.
Caveat: this model treats community investment as a fixed cost independent of adoption, which is only true over a narrow range. Support load, security response, and release engineering all scale with installed base — including the part that never pays.
Key Facts
The Open Source Definition has ten criteria, not one
Source availability alone is insufficient; the licence must also permit free redistribution and derived works and must not discriminate against fields of endeavour.
OSI, The Open Source DefinitionSSPL is not OSI-approved
MongoDB submitted it in 2018 and withdrew the submission in 2019; OSI has since restated that SSPL is not an open-source licence.
Percona analysis of SSPLEvery major relicensing since 2021 produced a fork
Elastic (Jan 2021) → OpenSearch (Apr 2021); HashiCorp (10 Aug 2023) → OpenTofu; Redis (Mar 2024) → Valkey. Elastic added AGPLv3 on 29 August 2024 and Redis added AGPLv3 with Redis 8 on 1 May 2025, after the forks were established. (Elastic blog; Redis blog; )
OpenTofuManaged cloud can become half the revenue
Elastic Cloud was $837.3m of $1,739.3m (48%) of fiscal 2026 revenue, up from 46% in fiscal 2025.
Elastic Q4/FY2026 results, 28 May 2026Open core scales without the community disappearing
GitLab reported fiscal 2026 revenue of $955.2m (+26%) with more than 6,500 user-contributed merge requests in calendar 2025.
GitLab fiscal 2026 Form 10-KWhat are the common mistakes?#
- Equating visible source with open source. The licence determines the rights. Say "source-available" when that is what you mean.
- Choosing a licence for branding. It changes adoption, contribution, corporate legal review, and who may compete with you. Choose it with counsel, once.
- Treating downloads as customers. Measure active organizations and qualified production use.
- Giving away every scarce capability. Operation, governance, and assurance need an explicit paid thesis before launch, not after the first enterprise inbound.
- Relicensing as a pricing fix. Relicensing is a distribution decision. If the problem is that a cloud provider out-operates you, the answer may be operating better, or partnering, not restricting.
When does the model break?#
Self-hosting is genuinely easy. If a competent team can run the software on a weekend, the managed-cloud thesis has no scarcity to sell.
The paid edition is cosmetic. Users notice within one release cycle, and the community narrative turns before the revenue does.
Users have no budget. Many individual users and few identifiable commercial organizations is a viable project and a poor company.
A larger cloud operates it better than you do. Scale, hardware pricing, and distribution can beat authorship. Being the author is not a durable moat on its own.
Open source is the wrong shape for the asset. If the core advantage is a secret algorithm, if licensed data cannot be redistributed, if export or safety controls dominate, or if uncontrolled deployment creates unacceptable support burden, a hosted API or a source-available arrangement may fit better — described accurately.
Finally, community and company goals diverge structurally. The community values portability and extensibility; the company values cloud revenue. Governance cannot dissolve that tension. It can make the decisions legible, which is what preserves trust when they go against the community.
Frequently asked questions
01Is BSL open source?
No, not during the restricted period. BSL/BUSL 1.1 restricts use — typically barring competing production offerings — and converts to a stated open-source licence at a defined Change Date. It is source-available until then, and it is not on the OSI approved list.
02Should I use AGPL to stop cloud providers reselling my software?
AGPL is OSI-approved and does extend reciprocity to network use, so it raises the cost of a hosted competitor. It also causes some corporate legal departments to block adoption outright. Both Elastic and Redis chose it after their source-available experiments; both had already lost the fork. Weigh distribution loss against competitive protection with counsel.
03How do I count "active organizations"?
With a telemetry or registration signal you have disclosed and users can disable, and a documented deduplication rule. If you cannot measure it honestly, use a proxy you can defend — registry pulls by unique network, or support and forum organizations — and label it as a proxy.
04What gross margin should an open-source company plan for?
It depends entirely on what is sold. A managed cloud carries compute in cost of revenue and lands well below a licence-and-support mix. Publish the mix alongside the margin, and see gross margin for the classification traps.
05Does a fork kill the company?
Not necessarily — Elastic's revenue kept growing after OpenSearch, and HashiCorp was acquired after OpenTofu. But a fork permanently removes the option of being the only maintainer, and it hands a credible alternative to every procurement team you will ever negotiate with.
Note: This page is educational and does not constitute legal advice. Licence selection, relicensing, contributor agreements, trademark policy, and third-party dependency compliance are fact-specific and consequential. Consult qualified counsel before choosing or changing a licence.
Related concepts#
- SaaS — the recurring economics of the managed offering.
- API as a Product — commercializing hosted access when open distribution is the wrong shape.
- Managed Services — selling operation and assurance around complex software.
- Cloud Marketplaces — distributing a managed edition through committed cloud spend.
- Freemium Model — comparing a pricing tier with licence-based freedom.
- Product-Led Growth — the adoption motion an open licence enables.
- Moats — assessing whether community, ecosystem, and operations are durable advantages.
Sources#
- Open Source Initiative, The Open Source Definition and the list of OSI-approved licences, accessed 13 August 2026. Source for the ten criteria and approval status.
- Percona, Is MongoDB Truly Open Source? A Critical Look at SSPL. Source for MongoDB's October 2018 SSPL adoption, the 2019 withdrawal from OSI review, and OSI's position that SSPL is not open source.
- Elastic, Elasticsearch is Open Source, Again, 29 August 2024, and Elastic licensing FAQ. Source for the 2021 move to SSPL plus the Elastic License, the AWS OpenSearch fork, and the 2024 addition of AGPLv3.
- Elastic N.V., Elastic Reports Fourth Quarter and Fiscal 2026 Financial Results, 28 May 2026. Source for FY2026 revenue of $1,739.3m, Elastic Cloud of $837.3m (48%), and net expansion rate of ~112%.
- OpenTofu, OpenTofu Announces Fork of Terraform, 2023. Source for the fork following HashiCorp's 10 August 2023 move from MPL 2.0 to BUSL 1.1, and OpenTofu's move under the Linux Foundation.
- Redis, Redis is now available under the AGPLv3 open source license, 1 May 2025. Source for the March 2024 move from BSD to RSALv2/SSPLv1, the Valkey fork, and the addition of AGPLv3 with Redis 8.
- GitLab Inc., fiscal 2026 Form 10-K (year ended 31 January 2026), filed March 2026. Source for the open-core description, FY2026 revenue of $955.2m, subscription revenue of $864.7m, and 6,500+ community merge requests in calendar 2025.
- Apache Software Foundation, Apache License 2.0, and GNU Project, GNU General Public License v3. Primary licence texts for the permissive and copyleft families.
Author
Dr. Sarah Zou
Independent economist · EconNova
Commercial strategy for technical products, with a focus on pricing, unit economics, and the operating choices behind the model.
About SarahTopics
Cite this page
Suggested citation
Zou, S. (2026). Open-Source Business Models: From Adoption to Durable Revenue. In Business Models. Pricing & Monetization Wiki. https://sarahzou.com/wiki/business-models/open-source-business-models
Open license
Reuse with attribution
This content is available for reuse. When referencing or republishing it, please credit Dr. Sarah Zou and link back to the original source.
Licensed under Creative Commons Attribution 4.0 International. You may share and adapt the material with appropriate credit.