The Government Accountability Office found that the Defense Counterintelligence and Security Agency is completing less than 40% of its required security inspections at cleared contractor facilities, according to GAO report GAO-26-107861 published in May 2026. The report, which covers the National Industrial Security Program (NISP), documents 815 security violations in FY2025 alone, with 1,032 open vulnerabilities identified across the cleared contractor industrial base — all against a backdrop of severe resource constraints.
Scale of the Shortfall
DCSA completed approximately 4,600 security assessments in FY2025 against a required baseline that the GAO found to be substantially higher. GAO Director Joe Kirschbaum stated in the report that DCSA is "unable with their current resources to cover the number and frequency of the security assessments they are required to do." The agency's 329 field operators are responsible for oversight of approximately 12,500 cleared facilities and more than 5,500 cleared information systems — a ratio that leaves a significant portion of the cleared contractor base going uninspected in any given year.
The consequences of that gap show up directly in the violation data. Of the 815 violations documented in FY2025, 60 percent were classified as data spills — unauthorized transfers or exposures of classified information. Another 11.5 percent involved improper storage of classified materials, and 6.5 percent involved unauthorized access or unauthorized disclosure.
A Resource Imbalance
The resource picture underlying these findings is striking. DCSA's industrial security program — the budget line that funds the field operators, IT systems, and administrative infrastructure for inspecting cleared facilities — operates on approximately $160 million annually. In the same period, DCSA's personnel vetting function, which processes security clearances for government and contractor employees, received approximately $1.3 billion. The ratio is roughly eight dollars for clearance issuance for every one dollar spent on verifying that cleared contractors are actually safeguarding classified information after those clearances are granted.
This imbalance is not a new observation in oversight circles, but the GAO report quantifies it with unusual precision. The cleared contractor base represents tens of billions of dollars in classified program investment annually. Cleared facilities handle everything from weapons system design data to intelligence collection requirements to cryptographic material. A security failure at a cleared contractor — through espionage, negligent handling, or insider threat — can compromise programs that cost far more than the entire NISP oversight budget to develop.
What GAO Recommended
GAO made four recommendations in the report aimed at improving DCSA's risk management approach and stakeholder engagement within the National Industrial Security Program. Whether those recommendations translate into a budget realignment — increasing the industrial security line at the expense of other priorities or through a net new appropriation — will depend on congressional action and Pentagon leadership decisions in the FY2027 budget cycle.
Federal News Network reported on the findings on May 27, 2026, noting the structural nature of the problem. DCSA did not create the inspection backlog through mismanagement alone; the cleared contractor base has grown in recent years as the Pentagon has pushed more classified work to industry, while the inspection workforce has not scaled proportionally. The result is a coverage gap that the GAO is now formally flagging as a risk to the integrity of the National Industrial Security Program.
Implications for Cleared Contractors
For defense contractors operating under facility security clearances, the GAO findings carry several practical implications. First, the low inspection frequency means that security vulnerabilities at a given facility may go undetected for extended periods — which is a two-edged concern. From a risk management standpoint, contractors should not assume that a clean inspection history reflects the full scope of their compliance posture. Internal security reviews and self-assessments become more important when external oversight is intermittent.
Second, the report may signal a coming increase in DCSA inspection intensity if Congress or the Pentagon acts on the GAO's recommendations. Contractors that have grown accustomed to infrequent site visits may need to sustain a higher state of readiness for physical security inspections, IT system audits, and employee security awareness documentation.
Third, for contractors in sensitive compartmented programs, the report's findings on open vulnerability tracking signal that DCSA will apply increased pressure on incident response timelines as the agency works to reduce its open vulnerability count. Program security officers should be prepared for closer scrutiny of how quickly they close out identified weaknesses.
What It Means for Contractors
This article covers a GAO oversight report on the Defense Counterintelligence and Security Agency's National Industrial Security Program. No specific contractors are named as parties to the findings; the report addresses systemic resource and coverage issues across the cleared contractor industrial base broadly.
For defense contractors operating under facility security clearances, the practical takeaways are significant. The inspection shortfall documented by GAO is a two-edged concern: a clean inspection history should not be read as a clean bill of health when fewer than 40 percent of required assessments are being completed. Internal security reviews, self-assessments, and proactive closure of known vulnerabilities become more important when external oversight visits are intermittent.
Program security officers should also plan for a changed posture going forward. If Congress acts on GAO's recommendations and funds an expanded DCSA inspection workforce, contractors accustomed to infrequent site visits should expect more frequent assessments — and should sustain readiness for physical security inspections, IT system audits, and employee security training documentation at any point in the year, not only during known inspection windows.
For contractors in sensitive compartmented programs, the GAO finding that 1,032 vulnerabilities remained open as of FY2025 signals that DCSA will apply increased pressure on incident response timelines. Facility security officers should review their open finding inventories and prioritize closures before the next assessment cycle, as the agency works to reduce its backlog under elevated congressional scrutiny. Contractors with outstanding vulnerabilities from prior assessments should treat closure as an immediate priority, not a deferred one.