August 25, 2026
DCSA Completed 38% of Required Contractor Reviews. Its 436-Position Plan Was Not Adopted.
DCSA recovered to more than 4,600 contractor security reviews and expanded mission staffing, but its last published requirement denominator still showed 37.6% coverage.
By Evan Mercer
Published August 25, 2026Last edited August 25, 2026

In fiscal 2023, the federal agency responsible for checking whether defense contractors protected classified information had 9,611 facilities due for a security review. It completed 3,618.
That is 37.6% of the requirement identified in Defense Counterintelligence and Security Agency data. The remaining 5,993 reviews were not completed against the baseline. The figures do not mean thousands of contractors lost clearances or that classified information was compromised at those facilities. They show the scale of an oversight obligation that DCSA did not meet.
The agency recovered from pandemic-era disruption. Completed reviews rose to 4,692 in fiscal 2024 and remained above 4,600 in fiscal 2025. Industrial-security mission staffing also increased, from 394 people in fiscal 2023 to 479 in fiscal 2025. Spending rose sharply.
Yet the Government Accountability Office's April 2026 review found that DCSA still lacked a sufficient response to the gap. The agency's recommended investment option called for 436 additional positions. The Pentagon office overseeing the mission had not adopted that option as of September 2025, saying DCSA had not sufficiently connected its proposal to policy requirements and data.
The result is more complicated than a simple inspector shortage. DCSA increased staff and reviews, changed how it prioritized facilities, used remote oversight for lower-risk sites and began replacing aging information systems. It also operated a national program in which a small facility can take one person one day to review while a large contractor can require a team and a deeper look at classified computer systems.
But the last published requirement denominator still shows less than 40% coverage. DCSA's own workforce assessment said current staffing meant accepting risk. That unresolved difference between a risk-managed inspection program and an unmet baseline is the central fact in the public record.
More than 12,500 cleared facilities, with 9,611 due for review
The National Industrial Security Program sets the rules for protecting classified information released to private companies, universities and other cleared organizations. DCSA administers the Defense Department's portion of the program for DOD and 35 other federal agencies.
The agency's industrial-security overview describes about 10,000 cleared companies and 12,500 cleared facilities. The count is larger than the number of companies because one company can operate multiple cleared locations. DCSA also oversees authorization of classified information systems, facility clearances, foreign ownership concerns and related security requirements.
This is not the same as DCSA's personnel-vetting mission. Personnel vetting investigates people and supports decisions about whether individuals may hold positions of trust or access classified information. Industrial security examines whether cleared organizations and their systems, procedures and facilities protect information entrusted to them. The missions share an agency but not a workload denominator.
In fiscal 2023, DCSA had 12,519 cleared contractor-owned facilities under its purview. DOD guidance generally set a baseline review frequency of every 12 months for facilities authorized to possess classified material and those operating under certain foreign-ownership mitigation arrangements. Other facilities generally had an 18-month baseline.
Applying those intervals, DCSA reported that 9,611 facilities required a review in fiscal 2023. It completed 3,618.

The 37.6% calculation divides completed reviews by facilities due under the baseline. It is not a measure of employee productivity. Reviews are not uniform tasks. GAO noted that a small facility with no classified material stored onsite might take one Industrial Security Representative one day. A large facility can require more people, more time and participation by Information System Security Professionals.
The baseline is also risk-adjustable. DOD guidance allows DCSA to defer, accelerate or continue a facility's review schedule based on risk. A review that did not occur in the baseline year is therefore not automatically evidence that DCSA ignored the facility. It may have been deferred while a higher-risk site received attention. The problem GAO identified was that DCSA had not fully documented and implemented a risk response adequate to the size of the gap.
Review output recovered, but later coverage rates are unknown
DCSA completed just 49 security reviews in fiscal 2021 and 2,775 in fiscal 2022. Agency officials attributed those unusually low totals to the COVID-19 pandemic. DCSA used other remote monitoring activities in place of some formal reviews, so the bars do not measure all contact with contractors during those years.
Completed reviews rose to 3,618 in fiscal 2023, then 4,692 in 2024 and 4,634 in 2025.

The 2024 and 2025 totals are meaningful evidence of recovery. They are not evidence that DCSA reached 48% or any other later completion rate. GAO published the 9,611-facility requirement only for fiscal 2023. FederalHiringData did not find a comparable public denominator for fiscal 2024 or 2025 and does not reuse the 2023 denominator as if the facility universe and schedules were unchanged.
That distinction matters because facilities enter and leave the program, their security posture changes, and DCSA can alter review frequency based on risk. A larger numerator does not by itself establish a larger share of the requirement.
The agency's own analysis nevertheless treated delays as consequential. DCSA officials reported finding 1.5 to 2.5 times more vulnerabilities for every year a security review was delayed. That was an agency finding cited by GAO, not an independently established causal estimate. Facilities with greater underlying risk may also be the ones where delayed reviews reveal more problems.
Regional employees gave GAO a consistent operational warning. Participants in all 12 focus groups said more officials could mitigate industrial-security risk and that limited staffing hindered the mission. Ten groups said longer intervals and delays increased risk; eight emphasized the importance of onsite review. The groups included 80 selected employees across four regions and were not designed to produce a statistically representative survey of every DCSA worker.
Most of the 2025 staffing increase was at headquarters
GAO obtained a mission-specific workforce series from DCSA's Fourth Estate Management Tracking System. This is the most useful public staffing denominator for the inspection mission because it does not treat every DCSA employee as an industrial-security worker.
The mission had 400 personnel in fiscal 2021, 412 in 2022, 394 in 2023 and 403 in 2024. The total rose to 479 in fiscal 2025, a one-year increase of 76 people, or 18.9%.

Field staffing rose from 293 in fiscal 2024 to 329 in fiscal 2025, an increase of 36. Headquarters operations rose from 90 to 132, an increase of 42, while headquarters administration fell by two. DCSA told GAO that 42 of the 76 new personnel were added to headquarters partly to support a statutory requirement to expand entity vetting.
Looking from fiscal 2023 to 2025, total mission staffing rose 21.6%. Field staffing rose by 35 people, or 11.9%, while headquarters operations rose by 49, or 59.0%.
Those numbers complicate two easy narratives. It would be wrong to say DCSA did nothing about staffing: the mission added people, including field staff. It would also be wrong to assume that all 85 positions added from 2023 to 2025 directly increased facility-review capacity. More than half of that two-year increase was in headquarters operations, and some of the 2025 expansion supported a related entity-vetting requirement.
Review output did not rise with total staffing in the latest year. DCSA completed 58 fewer reviews in fiscal 2025 than in 2024, a 1.2% decline, while the mission added 76 personnel. That is not evidence that the added staff reduced productivity. Hiring timing, training, headquarters assignments, facility complexity, remote-review strategy and work beyond formal reviews can all separate annual headcount from annual output.
Industrial Security Representatives do more than scheduled reviews. They advise facility security officers, receive suspicious-contact and security-violation reports and coordinate oversight across a contractor's security program. Information System Security Professionals assess classified systems and review contractor risk packages. Field office chiefs and team leads manage schedules and priorities. A review count captures one visible output, not the entire mission.
DCSA proposed 436 additional positions
DCSA completed an industrial-security manpower assessment in 2023. The agency concluded that its staffing level required it to accept risk across the cleared industrial base and developed three investment options.
Its recommended option was labeled the 100% investment level. It proposed 436 additional positions over the Future Years Defense Program:
| Proposed position type | Additional positions |
|---|---|
| Industrial Security Representatives | 230 |
| Information System Security Professionals | 164 |
| Field office chiefs | 25 |
| ISSP team leads | 17 |
| Total | 436 |
The proposal was designed to identify nearly all projected violations and vulnerabilities by enabling more of the required reviews. It was not an approved hiring plan, an independent estimate from GAO or proof that exactly 436 positions would close every gap. The projections depended on DCSA's risk assumptions and estimates of issues that additional reviews could find.
The Office of the Under Secretary of Defense for Intelligence and Security had not implemented any of DCSA's three options as of September 2025. Officials told GAO that the proposal showed limited linkage to policy requirements and lacked data or requirements needed for further action. DCSA said it therefore had not hired the additional ISRs, ISSPs, field chiefs or team leads identified in the options.
That disagreement is important. DCSA's operators and headquarters described a capacity problem. The Pentagon office responsible for policy and oversight questioned whether the workforce proposal sufficiently demonstrated the requirement. GAO did not simply endorse the 436-position number. It recommended that DOD implement a risk response plan, which could include changing review periodicity, sharing duties with military departments or taking other steps instead of adopting DCSA's preferred staffing package unchanged.
As of Aug. 25, 2026, GAO listed that recommendation as open. The other three recommendations, covering regional analytic tools, the National Access Elsewhere Security Oversight Center and end-user engagement on a replacement information system, were also open.
Spending rose faster than field staffing
DCSA reported $102.8 million in industrial-security mission expenditures in fiscal 2023. Spending rose to $139.0 million in 2024 and $163.2 million in 2025. The two-year increase was $60.4 million, or 58.8%.

The spending figures include federal labor, contract support and research, development, testing and evaluation costs for industrial-security systems. They exclude some training costs. They are not a staff payroll and cannot be divided by reviews to produce a meaningful cost per inspection.
DCSA attributed part of the increase to development of a replacement for the National Industrial Security System and positions added for NISP oversight and administration. That helps explain why spending could rise 59% while field staffing rose 12% from 2023 to 2025.
Federal Hiring Data Weekly
Get the biggest federal workforce changes in your inbox.
Subscribe to Federal Hiring Data Weekly for federal hiring trends, salary data, agency movements, and original investigations, with email confirmation before delivery.
The agency launched National Industrial Security System Increment II in January 2026 to replace an older contract-classification workflow. That launch is genuine evidence of modernization. It does not establish that the broader system concerns documented by GAO were resolved.
GAO reported that regional users found the existing system slow, difficult to query and unable to provide some trend analysis. It said poor interoperability created duplicate work. The auditors also found that DCSA had not continuously engaged regional and military end users during development of the replacement. A system can launch on schedule and still require user testing, integration and follow-through.
The reviews were finding concrete weaknesses
DCSA documented 815 security violations that were open at some point during fiscal 2025. Most were reported by contractors, and 576 were closed by September. GAO reported an average of about 67 days to close those completed cases.
Violations are incidents that could reasonably result in loss or compromise of classified information, such as a data spill onto an unclassified system. Vulnerabilities are weaknesses in a contractor's security program that could be exploited. The terms are related but not interchangeable.
As of September 2025, DCSA had 1,032 open vulnerabilities. Procedures were the largest category at 231. Training and briefings accounted for 204. Together, those two categories made up 435, or 42.2%, of the total.

Another 162 involved determinations of access to classified information, 137 involved reporting requirements and 111 involved information-system security. The remaining 187 were spread across 10 other categories.
Most open vulnerabilities were relatively recent. Some 638, or 61.8%, had been open 60 days or less. But 225, or 21.8%, had remained open more than 90 days. Fifty-three had been open more than 199 days, including one for at least 1,000 days.
These are program-wide aggregates. FederalHiringData does not publish or infer the identity of facilities associated with the findings. The data show why review coverage matters without revealing a contractor's location, classified work or specific security posture.
They also show why counting completed reviews alone is incomplete. DCSA personnel must follow up after a review, assess mitigation and determine whether a facility has addressed findings. Time spent closing a serious vulnerability can be more consequential than adding one more routine review to an annual total.
The remote-review strategy is a real countermeasure, with its own staffing questions
DCSA established the National Access Elsewhere Security Oversight Center in 2019 for lower-risk facilities that do not possess classified material or operate classified systems onsite. The center oversees approximately 5,000 facilities, about 40% of the program, with the goal of allowing regional staff to concentrate on more complex sites.
In 2024, DCSA gave the center responsibility for coordinating and conducting remote security reviews without additional resources. As of June 2025, GAO reported that it had 11 civilians and 47 contractors.
All 12 GAO focus groups criticized the center's staffing, responsiveness or effectiveness. Center officials acknowledged challenges. DCSA had not comprehensively assessed whether its staffing, performance goals and placement within the organization were aligned with the mission.
The agency did not abandon the model. A fiscal 2026 cross-directorate task force planned 800 to 1,200 remote reviews for eligible access-elsewhere facilities. If effective, that approach could increase coverage while reserving onsite teams for facilities that possess classified material or operate classified systems.
Remote reviews are therefore neither a loophole nor a complete answer. They are a risk-management tool whose success depends on staffing, usable data, contractor responsiveness and a defensible method for selecting facilities. GAO recommended a comprehensive assessment rather than assuming the center was either inherently effective or inherently inadequate.
DCSA's larger workforce cannot be used as the inspector count
OPM Federal Workforce Data provide a longer agency-wide view, but the series has a hard break.
The DD12 subelement was called Defense Security Service through May 2019. Executive Order 13869 renamed it DCSA and transferred the National Background Investigations Bureau from OPM to DOD effective Oct. 1, 2019. The transfer brought a large personnel-vetting organization into the same agency code.
Covered employment rose from 893 in December 2018 under Defense Security Service to 4,502 in December 2019 under DCSA. That was an organizational transfer, not a claim that the industrial-security workforce grew by 3,609 people in one year.

Related research
Put this finding in context

Data investigationsAugust 20, 2026
634 Applications, Eight Completed Rotations: Why the Federal Cyber Exchange Stalled
Employees showed interest in the federal cyber rotation program. Home-agency approval, unreimbursed staffing costs and senior qualification demands narrowed the path.

Data investigationsAugust 24, 2026
FAA Received 23 Electric-Propulsion Projects. Its Certification Skill-Gap Review Is on Hold.
FAA says current electric-aircraft projects remain supported, but two certification branches reported an eight-position specialty gap as a selected technical workforce fell 7.3%.
After the break, DCSA's agency-wide covered headcount rose to 5,596 in December 2024. It then fell to 5,181 in December 2025 and 4,975 in May 2026. The decline from December 2024 was 621 employees, or 11.1%.
That contraction spans personnel vetting, industrial security, counterintelligence, training, technology and support work. It should not be subtracted from GAO's 479-person mission table or presented as a loss of 621 inspectors.
Occupation data make the same distinction necessary. Series 0080, Security Administration, fell from 1,746 covered employees in December 2024 to 1,608 in May 2026. General Investigation fell from 1,678 to 1,465. Compliance Inspection and Support fell from 179 to 133. Management and Program Analysis fell from 290 to 235.

Series 0080 includes both personnel-security and industrial-security specialists. An employee's occupation code does not disclose a directorate or assignment. The defensible finding is that several security and investigative occupations were smaller across DCSA as a whole by May 2026, not that every decline came from the contractor-review mission.
The timing still matters. The broader agency contracted after the fiscal 2025 mission-staffing point used by GAO. Public OPM data do not show whether industrial-security staffing also fell after September 2025. A new mission-specific table would be needed to answer that question.
Public recruiting shows a recurring need, not realized hiring
FederalHiringData searched its historical USAJOBS archive for DCSA announcements with “industrial security” in the title. The bounded search found 518 distinct announcements from March 2017 through 2026.
The archive found 43 in partial 2017, 77 in 2018, 72 in 2019, 36 in 2020, 69 in 2021, 70 in 2022, 62 in 2023 and 57 in 2024. Recent 2025 and 2026 totals are incomplete and are not used as a full-year trend.
Many announcements used the 0080 Security Administration series and titles such as Industrial Security Specialist, Supervisory Industrial Security Specialist and Senior Industrial Security Specialist. The record confirms that DCSA repeatedly recruited publicly for the occupation central to facility oversight.
It does not show 518 vacancies or hires. One announcement may seek multiple people, one person or no final selection. DCSA can fill positions through internal merit promotion, reassignment and other authorities not visible as public announcements. The archive also cannot identify whether a selected employee stayed long enough to complete training or was assigned to field reviews.
The strongest use of the recruiting record is narrower: the mission depended on a recurring federal occupation with a national footprint, and public recruiting was sustained across the pre-pandemic and post-pandemic years. It does not validate the 436-position proposal or supply a current vacancy count.
The unanswered question is what risk DOD will formally accept
DCSA has already changed the operation. It uses risk indicators to prioritize facilities. It expanded remote oversight for access-elsewhere facilities. It rebuilt foundational training for Industrial Security Representatives. It launched a new system increment. It added mission personnel and spent more money.
Those steps helped raise formal reviews from pandemic lows to more than 4,600 a year. They are substantial counterevidence to the idea that the program simply stopped working.
They do not resolve the published gap. In the one year with both parts of the ratio, DCSA completed 3,618 reviews against 9,611 facilities due. Its recommended workforce option was not adopted. Regional employees across all 12 GAO focus groups said limited staffing hindered the mission. The organization created to relieve lower-risk workload was itself described as under-resourced.
DOD now has choices beyond accepting or rejecting 436 positions. It can revise baseline periodicity, share work with military departments, improve analytics, make remote reviews more effective, add targeted federal positions or combine those approaches. Each choice changes where risk sits: with delayed reviews, with thinner onsite coverage, with military components, with contractors or with assumptions embedded in an automated score.
What the public record does not contain is a completed plan that maps the facility universe, risk categories, review intervals and required workforce into one accountable operating model. GAO's open recommendations ask DOD to build that link.
The 37.6% figure should not be used to claim that 62.4% of cleared industry was unsafe. It should be used for the question it actually answers: how much of the published baseline review requirement DCSA completed in fiscal 2023. Until DOD publishes a later denominator and a formal risk response, it remains the clearest measure of the oversight gap.
Methodology and limitations
FederalHiringData used GAO-26-107861 for the fiscal 2023 facility universe and requirement, fiscal 2021-2025 completed reviews, mission personnel and expenditures, fiscal 2025 violations and vulnerabilities, DCSA's workforce options, focus-group findings, risk-management efforts, NAESOC staffing, information-system findings and recommendations. The 37.6% completion share and 5,993-review baseline gap are FederalHiringData calculations using GAO's DCSA-supplied numerator and denominator.
The fiscal 2023 requirement is not reused for 2024 or 2025. Facility schedules can change, and DCSA can defer or accelerate reviews based on risk. Reviews vary in time, staffing and complexity, so reviews per employee are not calculated as productivity.
OPM Federal Workforce Data use agency subelement DD12. December observations are shown for 2015 through 2025, with May for the latest 2026 observation available in the local research warehouse. The 2019 renaming and transfer of the National Background Investigations Bureau are treated as a scope break. Agency-wide headcount and occupations are context, not industrial-security staffing.
The USAJOBS analysis counts distinct control numbers for DD12 announcements with “industrial security” in the title. Historical archive coverage begins in approximately March 2017. Announcements are not vacancies, applications, selections, hires or onboard employees; recent annual coverage is incomplete.
The article does not identify individual cleared facilities, locations or security findings. GAO focus groups involved selected participants and were not statistically generalizable. DCSA's recommended 436 positions were an agency proposal, not an approved plan or independently verified requirement. Analysis was completed Aug. 25, 2026. Article research and writing used no OpenAI API calls.
Official records and further reading
- GAO-26-107861: Industrial Security
- DCSA National Industrial Security Program oversight
- DCSA security review and rating process
- DCSA organizational history
- OPM Federal Workforce Data downloads
- DVIDS image credit: John Joyce, Defense Counterintelligence and Security Agency, public domain
- How DOD's independent testing office changed in 2025
- Browse current federal jobs
- Explore FederalHiringData statistics
- Read more FederalHiringData investigations
Continue reading
More from FederalHiringData

Data investigationsAugust 23, 2026
Passport Waits Fell. State's Plan for the Next Surge Is Still Unfinished.
State rebuilt passport staffing and processed record demand after the 2023 crisis, but key measures of durable surge capacity remain unpublished.

Data investigationsAugust 24, 2026
VA Left 584 HUD-VASH Case-Manager Jobs Unfilled. Most Nonreferrals Had No Recorded Reason.
VA expanded HUD-VASH staffing and vouchers, but 584 case-manager positions were vacant and most nonreferrals had no documented explanation.

Data investigationsAugust 23, 2026
FAA's Aviation-Weather Network Was Designed for 90 Meteorologists. Staffing Fell to 69.
The last verified federal count found 69 meteorologists in a 90-position aviation-weather design. Public records show recruiting in 2026, but not a verified recovery.
Federal Hiring Data Weekly
Get the biggest federal workforce changes in your inbox.
Subscribe to Federal Hiring Data Weekly for federal hiring trends, salary data, agency movements, and original investigations, with email confirmation before delivery.