Software defects create costs long before a user reports an error. They can appear as unreliable code, operational failures, security vulnerabilities, technical debt, or delayed projects. The statistics below show the scale of that problem across US software economics, 2024 zero-day exploitation, weakness classification, and large-scale code reliability analysis. Because the source studies use different definitions and periods, their figures should be compared as indicators rather than combined into one total.
Contents
- The economic cost of poor software quality
- Defects, code growth, and software supply chains
- What historical CISQ estimates show
- Zero-day vulnerabilities in 2024
- The weakness patterns tracked by MITRE
- Reliability issues found in large codebases
The economic cost of poor software quality
CISQ’s 2022 report estimated the cost of poor software quality in the United States at at least $2.41 trillion in 2022. The same report estimated accumulated software technical debt at about $1.52 trillion. These are US estimates for 2022, not global measurements, and CISQ said the poor-quality figure remained at least $2.41 trillion even after excluding much of the possible overlap among categories.
The scale becomes clearer beside the wider economic figures in the report. CISQ projected US GDP at $23.35 trillion for 2022. It said US inflation had risen 15% over the two-year period ending in 2022, while the IT labor base grew 4% over those two years to $1.51 trillion. About 300,000 IT jobs were unfilled at the end of August 2022, according to the same source.
One direct defect-related estimate was the $607 billion cost of finding and fixing bugs in the US during 2022. That figure places debugging and remediation within the broader quality-cost picture rather than treating defects as only a testing concern. CISQ also reported that cybercrime losses due to existing software vulnerabilities totaled $1.44 trillion in 2022.
| 2022 US measure | CISQ estimate |
|---|---|
| Poor software quality | At least $2.41 trillion |
| Accumulated technical debt | About $1.52 trillion |
| Finding and fixing bugs | $607 billion |
| Cybercrime losses due to existing vulnerabilities | $1.44 trillion |
| Projected GDP | $23.35 trillion |
The categories above describe different economic effects, so they should not be added together. They are useful for testing leaders because they connect defect prevention with maintenance budgets, incident exposure, and business impact.
Defects, code growth, and software supply chains
Software scale is another reason defect statistics matter. CISQ estimated approximately 1.655 trillion lines of code worldwide in 2022 and 513 billion lines of code in the US. It reported code growth of about 100 billion new lines per year, equivalent to about 7% annual growth in 2022. More code creates more opportunities for defects, but line count alone does not measure risk or quality.
Third-party dependencies add another layer. CISQ said a medium-sized application with fewer than 1 million lines of code carries 200 to 300 third-party components on average. Those components may introduce weaknesses that are outside the immediate team’s authorship, testing history, or release schedule. CISQ also reported that the number of failures due to weaknesses in open-source parts of software supply chains increased by 650% between 2020 and 2021.
The figures suggest several practical testing questions: Which dependencies are in production? Which versions are still supported? Can the team reproduce a component’s build and test results? How quickly can a vulnerable dependency be replaced? A growing codebase and a large component inventory make defect detection, software composition analysis, and regression coverage increasingly connected activities.
CISQ said its 2022 cost estimate was constructed using 88 existing sources of available online information. That methodology detail matters when interpreting the results: the estimate is a synthesis of available evidence, not a count of every defect reported by every US software team.
What historical CISQ estimates show
CISQ’s earlier reports provide context, but they describe earlier measurement periods and should not be presented as current measurements. In its 2020 report, CISQ estimated the US cost of poor software quality at approximately $2.08 trillion. It attributed $260 billion to unsuccessful IT and software projects, $520 billion to poor quality in legacy systems, and $1.56 trillion to operational software failures.
The 2020 report also said cybercrime costs over the previous five years had risen to $10.2 billion by 2020, compared with $3.5 billion in 2019. It reported that firms lost about 1% of market value on average in the seven days after news of an adverse cyber event. These figures connect defect and vulnerability management with both operational expense and market response.
The report included staffing benchmarks relevant to quality work. The average 2020 IT manager count was 461,000, at a pay rate of $146,360. The average count of IT project managers, SQA professionals, and testers was 412,800, at a pay rate of about $88,550. These are workforce and pay figures from the CISQ 2020 report, not measures of tester productivity.
CISQ’s maturity comparisons also distinguish stronger and weaker delivery performance. It said first-year maintenance costs should be under 1% of total development effort for top-performing organizations. A 2020 project maturity benchmark placed cost and schedule performance under 10% for the best performers, while post-delivery maintenance above 10% of total development effort was associated with the lower-maturity end of the benchmark.
The CISQ 2018 report used sigma-based quality measures. It said average performance at 2.5 sigma corresponded to about 10% buggy code, and that about 40% of annual revenue could be consumed by cost of quality at that level. At 3 sigma, the reported cost-of-quality range was about 25% to 40% of annual revenue. CISQ also said software quality costs can amount to nearly 20% to 40% of company sales, with more than half of the quality cost at 3 sigma identified as the cost of poor software quality.
For historical scale, CISQ estimated poor software quality in the US at about $2.84 trillion in 2018, falling to $2.26 trillion when future principal technical debt was removed. Its 2018 breakdown estimated legacy system problems at $635 billion, software system failures in operation at $1.275 trillion, and troubled or cancelled projects at $177.5 billion. CISQ described the revised 2018 US cost of poor software quality as about $2.84 trillion when technical-debt principal was included.
Zero-day vulnerabilities in 2024
Google’s 2024 zero-day analysis reported that 56% of tracked 2024 zero-days, or 42 vulnerabilities, targeted end-user platforms and products. Browsers were targeted by 11 zero-days, down from 17 the year before. Mobile devices were targeted by 9, also down from 17 the year before. Google characterized browser zero-day exploitation as down by about one-third in 2024 compared with 2023, and mobile exploitation as down by about one-half.
Mobile attacks often involved chained weaknesses. Google said exploit chains made of multiple zero-day vulnerabilities were used almost exclusively—about 90%—to target mobile devices in 2024. Of the 7 exploited Android zero-days, 3 were flaws in third-party components. This is a reminder that mobile testing must include platform behavior and dependency exposure, not only application-owned code.
| 2024 Google zero-day measure | Reported figure |
|---|---|
| End-user platform and product targets | 42, or 56% of tracked zero-days |
| Browser zero-days | 11, versus 17 the prior year |
| Mobile-device zero-days | 9, versus 17 the prior year |
| Android zero-days involving third-party components | 3 of 7 |
| Mobile attacks using multi-zero-day chains | About 90% |
Google tied 26 zero-days to Microsoft, 11 to Google, 5 to Apple, and 7 to Ivanti. By vulnerability type, use-after-free accounted for 8 zero-days. Code injection and command injection were each observed in 8 cases, while cross-site scripting appeared in 6.
The analysis also described threat-actor patterns. Google said North Korean threat actors exploited 2 zero-day vulnerabilities in Chrome and 3 in Windows products. It said PRC-backed exploitation heavily targeted security and network technologies: 20 of 33 enterprise-software-and-appliance zero-days were aimed at those products. These counts concern tracked zero-day exploitation in 2024 and do not represent all software defects discovered during that year.
The weakness patterns tracked by MITRE
MITRE’s 2024 CWE Top 25 contained 19,797 individual mappings. Of those, 16,298 mapped to Allowed CWEs, or 82.33%; 1,481 were Allowed-with-Review, or 7.48%; and 2,017 were Discouraged, or 10.19%. MITRE said CWE contains more than 900 weaknesses, so the Top 25 is a prioritized view rather than a complete inventory.
The 2024 Top 25 used 14,342 Base-level maps, or 72.45% of the total. It also used 3,498 Class-level maps (17.67%), 1,301 Compound maps (6.57%), and 655 Variant maps (3.31%). These map types describe how weaknesses are represented and grouped, which helps teams interpret trends without treating every mapping as a separate defect in a separate codebase.
MITRE reported that the number of CVE records mapped to CWE-787 fell by more than 2,000 in 2024 compared with the prior-year analysis. Only three weaknesses kept the same ranking as the previous year in the 2024 Top 25. Ranking movement therefore matters when selecting secure-coding training and static-analysis rules: a stable shortlist should not be assumed from one year’s ordering.
Reliability issues found in large codebases
Sonar’s State of Code: Reliability analysis covered more than 7.9 billion lines of code, work from over 970,000 developers, and more than 40,000 organizations globally. Sonar said it found roughly 445 million code issues across 5,300 unique quality and security rules. About 16 million of those issues were reliability issues or bugs.
The reported density was about 2,100 bugs per million lines of code analyzed. Sonar also said developers encountered about three reliability issues per developer per month during the measured period. These measures are analysis findings under Sonar’s rules and definitions; they are not a universal defect density for every programming language or development process.
Sonar identified dead code and illegal memory access as the most frequently found reliability issues. The most frequent blocker bug involved unclosed resources in Java, and Sonar said that bug accounted for over 8% of Java issues found. For testing teams, the practical implication is that defect prevention spans more than functional test cases. Static analysis, code review, resource-lifecycle testing, memory-safety checks, and dependency controls each address different portions of the reliability risk shown by these studies.