No census of the critical open source dependencies underpinning UK government and CNI
DSIT's commissioned research from 2025 tells businesses to keep software bills of materials, and the NCSC warns of active dependency-compromise attacks while urging organisations to check their dependencies. The state has never aggregated the picture for itself. No inventory exists of which open source components government services and critical national infrastructure depend on, who maintains them, or how healthy they are; the Harvard and Linux Foundation Census II of most-used open source and the US federal SBOM aggregation under Executive Order 14028 show what the exercise looks like. Without this evidence base, neither NCSC prioritisation nor any future UK maintenance fund can be targeted, and ministers can honestly say they do not know what the UK runs on.
Mapping converts open source risk from anecdote into a ranked, actionable list; Log4j surprised everyone because nothing like it existed. The census is also the analytic precondition for a UK Sovereign Tech Fund.
An NCSC and DSIT-commissioned recurring census aggregating software bills of materials across departments and infrastructure operators, published with criticality and maintainer-health rankings, deliverable by an academic and industry consortium in under a year using existing analysis tooling.
// Build together: Counterparty: NCSC/DSIT commission plus departmental and CNI SBOM access; privileged data outsiders cannot scrape.
Cheap, deliverable within a year on existing tooling and entirely unowned, this evidence base is the precondition for targeting any maintenance fund.