GAO: Defense Security Agency Completes Fewer Than 40% of Required Contractor Inspections
The Defense Counterintelligence and Security Agency completes less than 40% of the inspections it is required to conduct at contractor facilities handling classified information, according to a new Government Accountability Office review.
GAO released the 63-page report, GAO-26-107861, on April 24, 2026. The review identified workforce limitations and an inadequate information-technology system at DCSA, the Defense Department agency responsible for helping protect classified information held by defense contractors.
The finding points to a substantial gap between the inspections required under the national industrial-security program and the inspections completed. Those inspections are intended to help the government assess whether facilities handling classified information are meeting security requirements.
Workforce and technology gaps
GAO said DCSA’s ability to carry out its inspection responsibilities is limited by staffing problems and weaknesses in its information-technology system. The agency’s current system lacks analytic capabilities needed to identify risks and regional trends more effectively.
That limitation affects more than recordkeeping. Without stronger analysis, DCSA has less ability to determine where security risks may be concentrated, compare conditions across regions and direct limited inspection resources toward the facilities or issues requiring the most attention.
The inspection shortfall is a documented oversight concern for the national-security information held by defense contractors. The report does not establish that the gap caused a specific classified-information breach, and it does not identify a particular contractor facility as having been compromised.
The public report also does not provide a current estimate of how many contractor facilities went uninspected. Its central finding is instead expressed as a share of the inspections DCSA was required to complete: less than 40%.
Recommendations remain open
GAO issued recommendations aimed at improving how DCSA responds to security risks, sets performance goals, aligns its organization and engages with stakeholders. The recommendations remained open pending documented agency action.
The recommendations address both the agency’s immediate inspection work and the management systems used to oversee that work. Clearer performance goals could make it easier to measure whether DCSA is closing the gap between required and completed inspections. Better organizational alignment could clarify responsibilities, while stronger stakeholder engagement could improve coordination with the contractors and other participants in the security program.
GAO also linked the agency’s mission gaps to risk management. The report’s title calls for improved risk management and stakeholder engagement to help the Defense Department address those gaps, underscoring that the issue is not limited to the number of inspections performed.
Why the finding matters
Defense contractors are part of the National Industrial Security Program, which governs the protection of classified information in the private sector. DCSA’s inspection role gives the Defense Department a way to evaluate security practices at facilities that support national-defense work.
A completion rate below 40% means that most of the required inspections were not completed during the period covered by GAO’s review. That does not by itself show that classified information was lost or exposed, but it does show that the government’s planned oversight did not occur at the level required.
The result also places greater importance on the agency’s ability to prioritize. GAO’s concerns about analytics, staffing and performance goals suggest that DCSA’s response will involve not only conducting more inspections, but also improving how it identifies risk and measures progress.
The next known step is documented action by the Defense Department and DCSA on GAO’s open recommendations. The April 24 report does not announce a new inspection deadline. Until the recommendations are addressed and closed, GAO’s findings remain an unresolved oversight issue for the federal program responsible for protecting classified information held by defense contractors.
Sources
- Industrial Security: Improved Risk Management and Stakeholder Engagement Needed to Help DOD Address Mission Gaps, U.S. Government Accountability Office
- Report on the President’s Surveillance Program — Recommendation 4, Council of the Inspectors General on Integrity and Efficiency
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.