Our Open Source Lessons Learned 2025

Old certainties are crumbling, and new questions are emerging. Who actually makes decisions about technology? How independent are we really? And what role does open source still play in all of this? We share our observations from a year that has reshaped so much.

Ihre Probleme möchte er haben

Fabian Stein
Fabian beschäftigt sich mit der Digitalisierung in Deutschland und der Entwicklung des Open Source Marktes als CEO von punkt.de.
Reading duration: approx. 7 Minutes

In 2025, open source is undergoing a period of profound change. Many things that were taken for granted over the past two decades—clear licensing models, community-driven development, a black-and-white understanding of “free” versus “proprietary”—are dissolving or being redefined. At the same time, the importance of digital sovereignty is rapidly increasing.

Companies, government agencies, and public institutions must grapple with where their data is stored, how independent their technology decisions truly are, and what role open source plays in all of this. As punkt.de, we have been operating precisely at this intersection for many years. And rarely has the momentum been as palpable as it is in 2025.

From a class reunion to a strategic stage:
TYPO3 on the rise

TYPO3 logo on a beige-gray background with a pattern

Anyone who’s been active in the TYPO3 community for many years still remembers the time before 2015–2020 well: T3CON was like a class reunion. Intimate, technically in-depth, but small. In 2025, the picture is different. The conference featured participants who, just a few years ago, had no connection whatsoever to TYPO3. Karim Marucchi, CEO of Crowd Favorite—deeply rooted in the WordPress world—spoke about digital sovereignty and open-source governance. The fact that figures from entirely different ecosystems are suddenly taking a serious interest in TYPO3 shows that our CMS is no longer just a tool—it’s infrastructure.

ITZBund, Materna, and other major players were also present throughout the event. This marks a qualitative leap. TYPO3 is now being considered strategically—not as an alternative, but as a foundation. The new version of the Government Site Builder (GSB) is based on TYPO3. The relevance of open source “made in Germany” is growing—and we are part of an ecosystem that will be more mature than ever by 2025.

Government Site Builder 11 is officially designated by ITZBund as the federal government’s standard solution and, starting with version 11, is based on the open-source CMS TYPO3—a clear commitment by the federal administration to open infrastructure.

Those interested in learning more can find further insights into the TYPO3 ecosystem and our collaboration with other agencies on GSB and public projects, for example in the article“1_Forge: Three Agencies, One Joint Effort—for Strong TYPO3 Projects on Equal Footing.”

Automation Takes Center Stage: Our Journey with n8n and CIB seven

Flowchart with arrows, boxes, and a check mark

For us, 2025 was a year of consistent automation—but with one clear principle: We only automate where we can retain data sovereignty. In this way, we deliberately set ourselves apart from the current trend of using Make, Zapier, or other SaaS integrators everywhere. Not because these tools are bad—on the contrary, they’re often great. But they require that business processes, login credentials, and internal data systems be hosted in a third-party cloud.

As customers increasingly turned to Make, we were faced with the question: How can we offer the same flexibility without sacrificing control? For us, the answer was a combination of tools: n8n as the central automation platform and CIB seven as a way to map more complex processes onto a sovereign workflow engine. We host both tools ourselves—and that’s a game-changer.

Here’s an example: Our public relations work is now largely automated. Once a week, a current list of articles is transmitted from our internal sources to services like PresseBox—error-free, traceable, and processed entirely on our servers. Small but significant: We save time, improve quality, and keep all data in-house.

We once summarized this approach—automation yes, but only with data sovereignty—on our blog as follows:“Automation only works sustainably if the company retains sovereignty over the data.”

In doing so, we had to expand our own understanding of open source. After all, n8n isn’t “classic open source.” The Sustainable Use License restricts certain types of use—in particular, operating it as a commercial SaaS service. At first, I was skeptical. To me, open source is more than just a license text. But n8n’s model won me over: It protects against exploitation by cloud giants while still allowing all the freedom needed for true sovereignty. This hybrid approach is a key building block for the future—and a personal lesson I’ve learned in 2025.

Jan Oberhauser, the founder of n8n, sums it up this way in the context of the Fair Code movement: We need to find models “in which everyone wins—users, the community, and companies.” The Sustainable Use License is exactly such an attempt: The source code remains viewable and extensible, but purely commercial resale without any revenue flowing back to the project is restricted.

What's New in the Communities: WordPress, Akeneo, Pimcore

Red icon with a stick figure

Hardly any other year has so clearly demonstrated just how fragile open-source governance can be. The conflict between Matt Mullenweg (Automattic) and WP Engine has deeply unsettled many customers. The final rift escalated in late 2024, but the repercussions rippled through the market in 2025: the threat to revoke trademark rights, the temporary removal of WP Engine customers from update channels, and the public war of words. Regardless of how one assesses the details—such a power imbalance would simply not be possible in many other open-source projects. TYPO3 and similar projects have a clear advantage here: governance is decentralized. No single actor can lock out entire user groups.

But WordPress is just one example. Akeneo has effectively frozen its Community Edition and is increasingly focusing on its SaaS and Enterprise models. In practice, this means that new features first (or exclusively) appear in the hosted versions and the Enterprise Edition, while the Community Edition largely remains in maintenance mode and the focus clearly shifts toward the “Serenity” SaaS approach.

Pimcore switched to its own POCL license this year—a move that to many sounds like a departure from true open source, but is also intended to minimize the legal risks of traditional copyleft licenses. Starting with version 2025.1, the Community Edition is no longer licensed under GPLv3 but under the Pimcore Open Core License (POCL), which promises full access to source code and customizability but clearly distinguishes between community use and commercial use.

And now comes the uncomfortable part:

It would be too easy to criticize these projects. The fact is: The demands placed on modern digital products have increased enormously. Architecture, security, scalability, compliance—all of this costs money. And to be honest: The open-source community rarely contributes enough to ensure that large projects can continue to be developed on a financially sound footing.

Anyone protesting this should ask themselves whether they’ve contributed enough in recent years to prevent commercialization. I myself look back with pride on TYPO3 and the founding of TYPO3 GmbH in 2016. That was foresight. It was the community’s answer to the question:

How do we secure the future of our project without selling out?

These governance structures are working today—and other systems will have to follow suit.

For 2026, I hope to see clear pricing structures and transparent onboarding models. We understand that systems have to incur costs, but the welcoming culture of the “old open-source” world must be preserved. This year, we tried to enter the enterprise world with some long-standing open-source systems, such as Sylius, Elastic, and n8n.

It was an absolute pricing jungle. After five phone calls, meetings, and rounds of documentation, we still had no price and no sense of a welcoming culture—just uncertainty.

Agencies, in particular, need the opportunity to try out new tools without immediately getting locked into an enterprise model. Otherwise, Europe won’t widely adopt these tools.

An example of how things can be done differently can be seen in the TYPO3 ecosystem: Thanks to the combination of an association, a limited liability company (GmbH), and a broad network of agencies, it’s clear who pays for what—and yet the core of the system remains open and community-driven.

Europe regulates—and that's a good thing

Red Stars in a Circle

Regulation is a contentious issue in the tech industry. Many companies view NIS2, CRA, the Accessibility Act, or the stricter GDPR requirements primarily as a burden. We see this every day: Initial reactions to EU laws often sound like people are overwhelmed or complain about “Brussels bureaucracy.” But the more deeply I delve into these topics professionally, the clearer it becomes to me: Europe has a strategic advantage here that we should communicate with much greater confidence.

I’ve had several conversations with American experts this year. The picture is clear: The U.S. envies us for our European regulation. Not because it’s convenient—but because it provides protection, clarity, and sovereignty. While data trading, profiling, and platform power remain largely unregulated in the U.S., Europe offers reliable guidelines that build trust.

NIS2 compels companies to take their own IT security seriously. The directive establishes a uniform framework for cybersecurity across numerous critical sectors and significantly expands its scope—including to many small and medium-sized enterprises. The Cyber Resilience Act ensures that software—whether open source or proprietary—must finally meet minimum standards, such as security by design, regular updates, and clear responsibilities. The Accessibility Act elevates accessibility from a “nice-to-have” to a quality feature. And above all else is the European commitment to viewing digital sovereignty as a key factor in attracting business.

Many view this as a burden. I see it as an opportunity.

Partly because, as a “ punkt.de,” we’ve set out to comply with ISO 27001 ourselves. Not because a customer demanded it, but because we want to show that we take security and sovereignty seriously. For us, the issue of regulation isn’t a millstone around our neck—it’s a driver of the future.

If you’d like to delve deeper into the topic, you’ll find regular posts on our blog offering insights into regulation, sovereignty, and real-world examples—ranging from small and medium-sized businesses to the public sector.

I’ve provided a more detailed explanation of why we view digital sovereignty not as a sacrifice but as a conscious decision in our blog post“Digital Sovereignty: Conscious Decisions Instead of Dogma.”

My Outlook: 2026 Will Be a Year of Clarity

2025 was a year of change. 2026 will be a year of clarity. Next year,we’ll see much more clearly which open-source projects have their governance under control—and which don’t. We’ll see which licensing models work and which alienate the community. We’ll recognize which EU regulations spur genuine innovation—and where adjustments are needed.

Personally, I look forward to actively shaping these discussions. For me, open source means: keeping options open. Taking responsibility. And remaining in control—technically, strategically, and legally.

As “ punkt.de,” we will continue to steadfastly follow our path in 2026:

Open source by default.
European technology as the foundation.
Sovereignty as an attitude.

Now is a good time to rethink technology. And it's a great time to take responsibility.

Share:

More articles

if (sad() === true) { sad().stop() ; beAwesome(); }
André Hoffmann, Entwicklung at punkt.de
Working at punkt.de