Software for councils and public bodies: first, you look at what already exists
The Digital Administration Code (CAD) asks you to compare the options before having new software written, and to remain the owner of software developed specifically for you. The code we write specifically for a public body belongs to that body.
What does a council or public body need to know before having software developed?
First compare the options, as Article 68 of the Digital Administration Code requires: reuse, free software, cloud, licences, new development. If you develop, the project specifications must give the body the rights, barring proven excessive costs, and the code is normally released under an open licence. Then the ACN class of the data decides where it is installed.
Before having new software written: the comparative assessment
To acquire a program, Article 68 of the Digital Administration Code (Legislative Decree 82/2005) asks your organisation for a comparative assessment, both technical and economic, between six options: software developed on behalf of the administration, reuse of software already developed for another one, free or open-source software, a cloud service, a product under a user licence, or a combination of these.
The criteria are in the same provision. You look at the total cost, that is purchase, deployment, maintenance and support. You look at how far the software uses open formats and interfaces, and whether it cooperates with the other systems of the public administration. And you look at the supplier’s guarantees on security, personal data protection and service levels.
The provision also sets a limit. A proprietary product under a user licence can only be purchased if the assessment shows, with a stated reason, that there are no solutions already available in the public administration, or open-source ones, suited to what you need.
The Guidelines of AgID (the Agency for Digital Italy) on the acquisition and reuse of software suggest starting from a document describing your requirements, with the needs and constraints of your organisation. Then they say where to look: first in the Developers Italia catalogue, where administrations publish software that others can reuse, then in third-party open-source software. Licences and new development come afterwards, if no suitable solution turns up there.
Article 69: who owns the code, and where it is published
Article 69 of the Code asks for the project specifications to state that the administration holds all rights to software developed specifically for it, unless this proves excessively burdensome for proven technical and economic reasons. With us, the code of software written specifically for your organisation belongs to your organisation: it belongs to whoever paid for the work, together with the documentation and the environments.
Paragraph 1 adds an obligation for the administration that holds the rights: to make the source code available, complete with its documentation, in a public repository and under an open licence, for free use by other public administrations or by legal entities that want to adapt it. The only exceptions are justified reasons of public order and security, national defence and elections.
AgID’s Guidelines recommend developing directly on the platform where you will publish the code, from the start of the design work. The publiccode.yml file describes the software, and Developers Italia builds its catalogue entry from it.
Where the code is written, on your platform from day one or with a release at the end of the work, is something we agree before we start.
Software of ours already in use at a public body
It transcribes meetings live and afterwards, tells speakers apart and sends the text to the participants. It runs on the body’s own infrastructure, speech recognition included, and no third-party service is involved between the recording and the text.
We wrote it in two months, with three people. Other bodies can have it too, in the form that suits each of them.
If you take software under reuse
If the Developers Italia catalogue has software that does almost everything you need, your organisation can take it under reuse and have it adapted, without asking permission from whoever holds the rights to it. Annex D of the AgID Guidelines says who can do the work on the organisation’s behalf: its own staff, one of its in-house companies or a supplier it chooses.
The changes fall under Article 69, like software developed specifically for the organisation: it acquires ownership of what it has added, and releases it under an open licence. Before developing new features you contact whoever maintains the software, through the public channels of its repository, and at the end fixes and new features are proposed to them.
Where the data is kept, and where the software runs
Where the software can run depends on the class of the data: ordinary, critical or strategic, under the Regulation of the National Cybersecurity Agency (Agenzia per la cybersicurezza nazionale, ACN) on digital infrastructure and cloud services for the public administration, which applies from 1 August 2024.
The Regulation asks every administration for a list of its data and digital services, each with its class, and a digital service that has not yet been classified cannot be made available to users. The minimum levels rise with the class, for the organisation’s data centres as for cloud services; which cloud services are qualified, and at what level, is stated in the catalogue published by ACN.
What we write is installed where you decide, on your organisation’s servers or in the cloud, and in both cases the infrastructure must meet the levels the Regulation requires for that class.
The cloud Regulation for public administration, on the ACN website →
The systems your organisation already uses
New software for a council reads from or writes to what is already there: the electronic document register (protocollo informatico), the accounts, the management software of individual departments. It is the part that takes the most time, and how it is done depends on what those systems allow: exchange files, database access, middleware, or APIs we write where there are none.
If the data sits with another administration, there is the National Digital Data Platform (Piattaforma Digitale Nazionale Dati) under Article 50-ter of the Code. Administrations are required to become accredited, to develop their own interfaces and to make their databases available, and the interfaces, written according to AgID’s Guidelines on interoperability, are listed in an API catalogue.
For licensed software, the Guidelines on acquisition and reuse also require that you can export the entire database, free of charge and at any time, in a standard, open and documented format. It is a question to ask anyone who offers you software.
Services for citizens: SPID, pagoPA, the IO app and accessibility
If the service needs to identify who logs in, Article 64 of the Code requires SPID (the public digital identity system) or the electronic identity card (CIE), and also allows the national services card. The electronic payments the organisation receives go through pagoPA, which administrations are required to join under Article 5, and Article 64-bis asks for online services to be reachable from the IO app.
For accessibility, the AgID Guidelines implementing Legge 4/2004 (Law 4/2004) refer to the European standard EN 301 549, that is level AA of WCAG 2.1 for the web. Every website and every app of the organisation has its own accessibility statement, filled in on AgID’s platform and to be reviewed by 23 September every year.
Security, and the guarantees to ask the supplier for
Among the criteria of the comparative assessment are the supplier’s guarantees on security, personal data and service levels. They are the first things to ask for in writing.
dotenv is certified UNI CEI EN ISO/IEC 27001:2024, the standard for information security management: certificate IIS-1225-06, issued by Dasa-Räegister, a body accredited by ACCREDIA, valid until 15 December 2028. The certificate PDF can be downloaded from the certifications page.
Your organisation’s security rules, if they go beyond the standard, go into the contract and the project.
After release
Changes made during maintenance also fall under Article 69, and under AgID’s Guidelines they are made in the repository where the code is already published, without opening another one.
We fix defects in the delivered software at our own cost, under the statutory warranty. Ongoing maintenance is a separate, paid agreement, and there we put in writing the response times you need. The code stays yours even if one day you hand the maintenance to another supplier.
Who is needed from your organisation, and who is there from dotenv
From your organisation we need a person who can make decisions, and who is there when the running software is reviewed. We need whoever looks after the information systems, because where the data is kept and what the software talks to are decided together. The office for the digital transition, or its manager, should also be involved early: under Article 17 of the Code it coordinates the development of information systems. And we need the people who will use the software every day, who try the prototype first, and whoever will look after it after release.
On our side, at least two people work on every project and there is written documentation: if one of them is away, the work carries on. We work in phases, and at the end of each one you decide whether to continue.
What to prepare for the first call
It starts with a call, free of charge, which can also be a video call. Then a visit on site, to see how you work today in the department where the need comes from. For the call we ask you for these, if you have them:
- The department where the need comes from, and who is responsible for it.
- The requirements document and the assessment of the alternatives, if they already exist.
- The class of the data the software will handle, if it has already been decided, and your organisation’s security rules.
- The systems the software will need to talk to.
- Whether the software opens a service to citizens, or collects payments.
How we also work: For startups · For SMEs · For enterprises
Frequently asked questions
- What does taking software under reuse mean?
- It means using software that another administration has published under an open licence in the Developers Italia catalogue, adapting it if needed. The changes can be made by the organisation’s own staff, an in-house company or a supplier chosen by the organisation, and they are proposed to whoever maintains the original software.
- Can a council buy licensed software?
- Yes, if the comparative assessment justifies it. Article 68 of the Code allows it only when it is shown, with a stated reason, that nothing suited to what the organisation needs exists among the solutions already available in the public administration or among open-source software.
- Are you ISO 27001 certified?
- Yes, with certificate IIS-1225-06 issued by Dasa-Räegister, accredited by ACCREDIA, valid until 15 December 2028. The standard covers information security management; the public body’s rules that go beyond it go into the contract.
- Do we need a requirements document before contacting you?
- It is enough to know what the software must do and what data it touches. If there is a document we read it, and we write the scope together.
- How is the work awarded to dotenv?
- The purchasing procedure is defined with the public body, case by case. dotenv is listed on MEPA.
- If we stop after the prototype, what does the organisation keep?
- The screens and the design work, which stay yours even if you do not go ahead.
- Can we stop halfway through the work?
- Yes, at the end of a phase: we work in phases, and that is where you decide whether to continue. What has been done up to that point stays with the organisation.
- Do you use artificial intelligence?
- Yes, as support, on every project. The decisions are made by people, and dotenv answers for what we release. The organisation’s data only passes through private AI services of our own, never through external services. The people at Neurally, the company we founded, also bring us their expertise on AI.
Tell us what the software needs to do, and where the data must be kept.