The market is changing, and so are we
Over the past couple of years, more than one company we've talked to has watched the open source software they built on quietly change its license. Same code, new terms, and suddenly a five-figure bill to explain to management. What stays with me is how fast the conversation turns from features to harder questions. Who owns this? How much control do we still have? Where does this leave us in five years?
I've been thinking about that a lot. Partly because it sits next to a bigger shift in what companies are trying to build, where a website is no longer the whole job, but the starting point for something larger. And partly because it raises a fair question about us, too. We've spent this year evolving, adding products alongside our open source core, and more than one person has asked whether that's a sign of strength or a reaction to pressure. Honestly? It's both. I don't think that's a contradiction. Let me explain, because the answer runs right through what's happening in our market.
Ownership and scope: two shifts changing the market
The first shift is the one I just described: ownership. For a while, open source worked as a growth tactic. Attract developers with something free and open, build a moat, then tighten the terms once everyone is too invested to leave. Buyers have caught on and learned to read the fine print. But the lesson is simple: open is only as real as the license behind it.
The second shift is about scope. What companies are actually trying to build keeps growing beyond a single website. Content now connects to products, users, services, and the other systems a business runs on. A page is rarely the endpoint anymore; it's one piece of something larger. Content management still matters, and it's still what we do best, but for a lot of teams it has quietly become the starting point rather than the whole job.
Put those two shifts together and you get the question serious teams are really asking: who can I trust to build on for the next ten years, without losing control of what I've built along the way?
Why open source still matters, and what it really means
This is where I get to the part I care about most. Open source, done honestly, is the answer to that question. It sounds strange to answer a problem "caused" by open-source licensing with more open source — but that's exactly the point. The same tool that gets used as a trap is also the only real guarantee. The license is what decides which one you're holding.
Done honestly, open source isn't a badge; it's a practical guarantee. It means you can read the code, run it where you want, meet your own compliance and data requirements, and leave whenever you want without a rewrite. The code outlives any single vendor, including us.
That's also why the distinction between open source and open core matters. In an open-core model, the base is open but the features you actually need in production sit behind a commercial license. It's a legitimate business, but it changes the deal: the open part slowly becomes the demo, and "open source" turns into a marketing word for the free tier.
We chose a different line, and I want to be exact about it. The entire Sulu codebase is MIT licensed. Not a core with the useful parts held back — all of it. There is no edition of Sulu where the features that matter in production live behind a paywall, and there is no plan to build one. What's open today stays open, and nothing that sits in the codebase now will ever move behind a license later. Because that license is MIT, it's a promise you can hold us to in writing rather than take on faith.
So where do Sulu.ai and Sulu.cloud fit? They're "additional" products — an AI layer and managed hosting — built alongside that open codebase, not carved out of it. Neither one gates anything that used to be free; they don't turn the open part into a demo. They add capabilities for teams that want them, while the CMS itself stays completely open.
It's also worth separating two things people lump together. A license fee is payment for permission to keep using software you depend on. Support is payment for people who help when something breaks. We will never charge you for permission to use Sulu. We're glad to earn your business for support, and for products like Sulu.ai and Sulu.cloud that save your team time.
Funding open source without closing it
So let me come back to that „both." We didn't set out to reinvent ourselves. A lot of how Sulu has grown happened naturally, project by project, as we and our partners kept hitting the same needs and building for them. But yes, there's pressure behind it too, and last year drove that home. We shipped some of our best work in 2025, and then the economy tightened. Promising partner conversations quietly slid to „let's talk in January," and we felt how exposed leaning on services revenue, roughly 85% of ours, actually makes you.
The reason we're building a healthier business around the open codebase is almost boring: we want Sulu to still be here, and still be open, in ten years. Open source only survives if the people maintaining it can keep the lights on. And yes, you could read our code and walk away tomorrow. But most teams would rather not fork and self-maintain alone. What they want is for the people who know it best to still be shipping updates a decade from now.
That's why the products we add, like Sulu.ai and Sulu.cloud, exist to fund and protect that open foundation, not to replace it or wall parts of it off. And to be honest about the homework: some of our packaging and pricing could be clearer today, and we're working on that too.
An open foundation you can build on, without losing control
Over the past few years, Sulu has quietly grown into more than the CMS we first set out to build. Not through one big pivot, but through a hundred small, deliberate decisions. Every so often I look up and realize the thing we've built has started to outgrow the single word we've always used for it.
I'm not going to reach for a shiny new label today, though, because I'd rather show it than announce it. What I can tell you is the direction. We want to be the dependable, open foundation that teams build real, long-lived things on, without ever losing control of what they've built. We're still strong at what we've always been good at: structured content and multisite, multilanguage setups, built on Symfony and open source all the way down. Exactly how we describe where this is going is something we'll grow into over the coming months.
What we're working on next
In the near term, the focus is depth, not fireworks. Sulu 3.1 is on the way, we're growing the ecosystem, and Symfony 8 support is in progress. The foundation we rebuilt in 2025 is exactly what lets us move faster now.
You'll also see us follow the logic of that second market shift. When a business runs on product information as much as on pages, managing that product data belongs closer to the core, not bolted on at the edges. The timing there is hard to ignore: one of the most established open-source names in product information management recently moved its community edition off an open-source license and onto an open-core one. That's a legitimate business decision, and I won't guess at anyone's reasons. But it's a clear sign of where things are heading, and of the choice we've made to go the other way. Product data is a direction we're actively building into, MIT-licensed like everything else we ship. I'll leave the rest of the hint there for now.
Questions to ask any vendor about lock-in
The market is changing. We're changing with it, on our own terms, and out in the open where you can see it. Content management was the start of the story, not the end of it.
If you're choosing software to build on right now, here's the question I'd put to any vendor, us included: show me what you are today, be honest about what you're not, and prove I can leave if I ever need to. I'd genuinely love to hear how you're thinking about all of this.
