Pietro Vanghetti

All writing

Beyond “buy or build”: navigating digital investment in the public sector

02/2026

Running a country has never been simple. Running it with systems built for another century is harder still. Yet, that is the frustrating reality many civil servants across the globe are facing today.

To fix this mismatch, governments need to undergo a profound transformation, but when they decide to drag their legacy systems into the 21st century, they usually end up confronting a dilemma: to build a custom system from scratch, or to buy Commercial Off-The-Shelf (COTS) digital solutions from private vendors?

While describing the issue as a “buy or build” decision may provide a useful shorthand, it risks painting too simple a picture. In reality, modernising government requires a much more nuanced approach to decision making, with the “buy or build” catchphrase actually concealing several interlocking and complicated tradeoffs.

Hopefully this post will do a decent job of exposing some of them and capturing the essence of this dilemma. It will focus on fleshing out four key factors and their underlying tradeoffs: time, talent, budget and sovereignty, and then reflect on what a sensible approach to decision-making might look like when deciding how to invest in digital systems in the public sector.

Time – Speed to value vs customisation

When it comes to public service delivery, time is of the essence. Whether the intervention focuses on redesigning a user-facing service or an intergovernmental protocol to facilitate service delivery, the sheer scale of the functions government needs to carry out means that even a minor delay might generate massive negative consequences for citizens.

In this context, deciding to buy Commercial Off-The-Shelf (COTS) software offers an undeniable advantage: speed. A public sector body can procure and deploy an off the shelf product in only a few months, while building one from scratch can take years of development. However, increased speed to value is not for free, and it usually comes at the cost of process fidelity. Off the shelf products are put together for common use cases, often keeping in mind the needs of private sector actors, which can differ significantly from unique statutory requirements public agencies need to comply with. Buying standardised solutions might therefore force government actors to adapt complex internal processes, or even regulations, to ensure system integration.

Essentially, public servants need to decide whether to accept varying degrees of friction when it comes to adapting to a standardised tool or to endure the long lead times required to build a tailored solution.

Talent – Building knowledge vs leveraging market expertise

When taking into consideration the talent factor, a good case could be made for both building or buying a digital system.

At first glance, public officials might feel buying off the shelf is the best path forward, given that internal digitally-savvy employees are often a scarce resource and it might not be worth reassigning them from their current tasks. At the end of the day, buying a solution off the shelf allows public institutions to both leverage best in class technological expertise and – potentially even more appealing – outsource management and operational risks to some degree.

On the other hand, the build approach might provide government bodies with the leverage necessary to hire the talent they so desperately need, ensuring it is readily available for future projects. An argument could also be made vis a vis the long-term cost savings that could be attributed to such an approach, as it would reduce the public sector’s reliance on expensive consultants whose incentives are not often aligned with those of the public. However, the reality of the public sector labour market constrains this vision. Like everyone else, governments want to attract top talent. To do so, they need to compete with private sector companies, which are able to offer significantly higher salaries, equity stakes and high degrees of work flexibility, severely limiting the attractiveness of public sector work.

Budget – CapEx vs OpEx

When assessing whether to build or buy, public officials are weighing two very distinct funding models. Building a custom digital solution is a capital intensive endeavor requiring a substantial lump-sum, upfront investment to hire personnel and build digital infrastructure, but promises lower operational costs in the long run. When buying off the shelf, on the other hand, the initial cost is much lower, but it will compound over time.

There are also other factors that might affect this decision. When deciding to buy off the shelf, vendor lock-in can be a real risk, particularly when it comes to certain solutions, such as cloud. Because major cloud operators store and manage data in radically different ways, it is very costly for their customers to shift from one offering to another. For public bodies, this might mean withstanding inflated subscription fees with no possibility of finding a financially viable alternative.

At the same time, greenlighting the substantial investment required to build a solution from scratch will require significant political backing, which is far from guaranteed. In most cases, this is a factor mainly because of government’s misperception that a project - and therefore its budget – needs to be large to deliver results at scale. This credence however should stick less now, thanks to examples such as the Government Digital Service in the UK, which has successfully pioneered the start small, test and iterate approach in digital public sector projects.

Sovereignty – Dependency vs ownership

This might be the most profound tradeoff, and is certainly one that has sparked debate in political circles as of late, particularly in the context of US-EU trade relations. Of course, sovereignty is only a factor when considering a purchase from foreign vendors, but that is often the case unless we’re talking about American public institutions.

Suffice it to think that the European market share of domestic cloud service providers plummeted from 29% in 2017 to 15% in 2025, with Google, Amazon and Microsoft accounting for a 70% share. While these firms offer plenty of technical advantages, growing geopolitical tensions are forcing European governments to reevaluate the nature of their relationship with the United States and their companies, and rightly so.

However, building solutions from scratch might be both costly and outright counterproductive, especially if the goal is to achieve complete technological independence.

The definition of sovereignty here is of utmost importance. Interpreting it as total ownership of the digital stack is misguided, as it might lead governments to both overspend and reduce – if not wipe out entirely – their ability to adopt better technology down the line. As Mike Bracken, David Eaves and Michelle Wronski put it, sovereignty can be achieved through agency over policy, rather than total control.

Reframing sovereignty in this way provides a clear roadmap for governments looking to avoid falling victim to digital weaponisation: enforce new interoperability standards to ensure private sector providers retain their market share through improved service offerings rather than lock-in.

How to decide?

Having covered some of the reasons why “buy vs build” is not a simple binary decision, let’s look at what public officials can do to tackle complexity.

The starting point to make an informed decision should be to ensure the right people are involved. While this might seem like an obvious requirement, it is not a given in government, where working in silos is usually the standard. If someone in charge of the financial side of things was to take a unilateral decision, for instance, they would probably go for a buy decision in order to avoid larger upfront costs. A multidisciplinary team is needed to have a holistic approach to this dilemma.

Secondly, the team must define what they need the system for, whether they need it at all or whether they only need some parts of it. This requires another, non-trivial capability: situational awareness. A Wardley map might come in handy in this instance. Taking its name from technologist, researcher and “context smuggler” Simon Wardley, a Wardley map enables an organisation to visualise the value chain of an existing system by breaking down its components, understanding their value to end users and plotting their stage of evolution from genesis to commodity. This visualisation helps decision makers understand if they need to invest in custom built solutions or can simply buy one off the shelf. A good example is the map by Mili Malde, who plotted the UK’s teaching vacancies service on a Wardley map.

Let’s take the “job alerts” system component of that map. In this instance, the map might have enabled decision makers to realise they did not have to build their own notification system for job alerts, as they could instead leverage Notify, the UK government’s notification service developed by GDS.

Thirdly, the team needs to understand whether existing products match their technical and operational reality: are they compliant with regulation? Are they resilient to external threats? Can they meet performance thresholds? How hard is the system to interact with for non-technical administrators?

Fourthly, the team needs to assess the vendor as a long-term partner. Simply looking at a vendor’s offering as it is today might be shortsighted. Technology consulting firm ThoughtWorks suggests looking at nine criteria when undertaking this assessment, including culture, financial stability and quality of support.

Finally, the team should get their hands dirty before committing to a purchase. As much as possible, they should try running small scale, real world experiments to test the vendor’s solution and the quality of their collaboration.

Ultimately, to successfully tackle the “buy vs build” dilemma, decision makers need to understand it not as a binary decision, but as a spectrum of flexible possibilities.