There's also security concerns to take into account - which I know someone will say is a good thing, because of transparency and so forth. But just realize that it's not a trivial amount of work to clean up a code-base and display it to the public all of the time.
And if the policy were open-source by default, the unspoken policy for project managers would be "automatically submitting a request to be closed source"
It's not perfect, but I know that 20% is a lot, and I think anyone who's worked in the sector would agree.
I'm definitely aware of the difficulties involved in open sourcing significant amounts of your work. The bigger burden is less, in my opinion, about cleaning up your code base. If you're committing potential security vulnerabilities into your code that are then tracked by your version control system – and you're a Federal agency – that's already a problem that's just going to be exacerbated by making it public; making that code private doesn't make the problem disappear.
The real meaty problems that all open source projects share is people: people like me who come in and overwhelm the project with support requests. I just opened four issues tonight just for this website, in the span of several minutes. (Sorry team!) If you already have poor project management practices in place, or your team is too small, this can quickly overload you.
Of course, with a vibrant community around your project, even the social and management problems could become trivial with time. Look at especially great examples like Hoodie. Given the number of technical people who have left cushy, high-paying jobs to serve in 18F, USDS, and the other alphabet agencies of late, I have to imagine the rallying cry to support truly useful code by compassionate people will be significant enough to justify the upfront expense here.
Not only is 20% not perfect, I don't think it's enough. I want 100%, and I think it's a fair request as a taxpayer, even if there is some burden. This country has fought two world wars and gone to the moon. We can always do better.
Are you saying the federal government is running insecure code in production? I'm shocked. /s
The companies hired would need to be new companies to contacting, with higher costs. Don't forget, government contracts are a lowest bidder war. Going full open source immediately might expose code that built using proprietary technology from a different division of a company. Therefore open source from scratch will have a high startup cost.
The existing projects can be small, open source, but more importantly these projects begin to build a foundation others can build on. The library of code created to support the framework of these projects will eventually be used as the basis for larger projects.
Wrapping back to the 80% this allows the existing, proprietary code reuse. While new, it's useless without its is proprietary components. This code, if released with proprietary components (and that's a big if since the binary would then be openly distributed) may not qualify as open source. One step further, public free binaries can be reverse engineered (the legality of which isn't something I'm well versed in). Which may not be in a companies current best long-term interest.
Tldr; The largest effort to being 100% open source is the library of code built on must also be open source or commonly distributed. Starting at 0 the current goal is 20%.
Provide costs don't rise too much expect 30% within 2 to 3 years (I'm being optimistic) or the next major government project timeline.