Statistics

Software Bug Statistics: Costs, Frequency, Testing, and Reliability Data

Software bug statistics covering defect frequency, testing costs, technical debt, reliability issues, and software supply-chain risk.

Software bugs create measurable costs across development, testing, operations, and security. Available estimates range from average annual bug counts in specific industries to trillions of dollars in US software-quality costs. The figures below keep their original measurement periods, geographies, and source definitions explicit.

Contents

The scale of software quality costs

The CISQ 2022 Report estimated that the cost of poor software quality in the United States reached at least $2.41 trillion in 2022. The same report estimated accumulated software technical debt at approximately $1.52 trillion. CISQ said the technical-debt principal had grown because software deficiencies were not being fixed.

These figures were framed against a projected US GDP of $23.35 trillion for 2022. The report also assumed a 15% inflation rate over the prior two years, so its 2022 estimates should be read in that stated economic context rather than treated as timeless prices. The IT labor base was estimated at $1.51 trillion in 2022, up 4% over two years, while approximately 300,000 IT jobs were unfilled at the end of August 2022. (CISQ 2022 Report)

The earlier CISQ 2020 Report estimated total US cost of poor software quality at about $2.08 trillion in 2020. It estimated failures in operation at roughly $1.56 trillion and said legacy-system problems contributed $520 billion to the cost of poor software quality in 2020. These are separate period estimates, not a measured year-over-year series. (CISQ 2020 Report)

MeasureEstimatePeriod and geographySource
Cost of poor software qualityAt least $2.41 trillion2022, United StatesCISQ 2022 Report
Accumulated software technical debtApproximately $1.52 trillion2022, United StatesCISQ 2022 Report
Cost of poor software qualityAbout $2.08 trillion2020, United StatesCISQ 2020 Report
Failures in operationRoughly $1.56 trillion2020, United StatesCISQ 2020 Report
Legacy-system contribution to poor quality cost$520 billion2020, United StatesCISQ 2020 Report

Cybercrime adds another software-quality dimension. CISQ reported that cybercrime losses tied to existing software vulnerabilities rose 64% from 2020 to 2021. Its 2020 report said US cybercrime costs had increased to $10.2 billion over the prior five years, with $3.5 billion occurring in 2019 alone. It also reported that public companies lost about 1% of market value in the seven days after an adverse cyber event. (CISQ 2022 Report; CISQ 2020 Report)

How many bugs organizations report

The NIST Planning Report 02-3 provides sector-specific bug counts rather than a universal defect rate. Approximately 60% of surveyed automotive and aerospace manufacturers reported significant software errors in the previous year. Those respondents reported an average of 40 major software bugs per year and 70 minor software bugs per year. The survey therefore distinguishes severity categories and identifies a particular respondent group; the figures should not be generalized to every software organization. (NIST Planning Report 02-3)

Financial-services software showed a different reported pattern in the same NIST source. Respondents reported an average of 40 major software bugs per year and 49 minor software bugs per year. About two-thirds of financial-services software users reported experiencing major software errors in the previous year.

The reported sources of financial-services bugs were divided into three categories. About 16% were attributed to router and switch problems, about 48% to transaction software problems, and about 36% had an unknown source. These percentages describe the source breakdown reported in that study; they do not establish that every bug in the sector has one of those causes. (NIST Planning Report 02-3)

The scale of modern codebases creates another way to express reliability risk. Sonar found roughly 2,100 reliability issues, described as bugs, per million lines of code. Its analysis covered more than 7.9 billion lines of code across over 970,000 developers and more than 40,000 organizations, and it flagged 16 million reliability issues. (Sonar State of Code: Reliability)

What inadequate testing costs

NIST estimated the national annual cost of inadequate software testing at $59.5 billion. The estimate applied to the United States and was also expressed as about 0.6% of US GDP. NIST estimated that about 40% of those costs were borne by software developers and about 60% by software users. This distribution matters because bug costs are not confined to the team that introduced a defect: users can absorb disruption, rework, and operational consequences later in the software lifecycle. (NIST Planning Report 02-3)

The same NIST analysis estimated a potential cost reduction of $22.2 billion from feasible infrastructure improvements. That potential reduction represented about 0.2% of US GDP. The estimate is a modeled opportunity, not a recorded saving, so it should be interpreted as a forecast of possible reduction under the report’s assumptions.

Testing effort also appears in the financial-services findings. Companies spent about 65 hours per month for two months on installation and acceptance testing. Installation and acceptance testing represented about $393,500 per installation on average, and about 16% of installation costs were associated with software errors and bugs. NIST estimated that eliminating those bugs would have saved about $62,960 per firm in installation and acceptance testing. (NIST Planning Report 02-3)

Installation, maintenance, and workaround costs

Defects can continue generating expense after an installation is complete. Annual maintenance expenditures on FEDI and clearinghouse software averaged $1,578.3 per year in the NIST analysis. Those maintenance expenditures could be reduced by about 11% if software errors and bugs were eliminated, implying average savings of about $174 per year. The source presents these as averages for the studied software context, not as a general maintenance price for all applications. (NIST Planning Report 02-3)

About half of the companies maintained redundant backup systems after installing new software. Those redundant systems were maintained for about three months on average and cost about $400 per month on average. For companies using these workarounds, NIST estimated that eliminating bugs would save about $1,595 per new system installed.

Taken together, the NIST figures show several distinct cost channels: the direct cost of testing, maintenance that continues after deployment, and temporary duplication used to manage installation risk. They should not be added together unless the underlying populations and accounting definitions are known to match. The source supports each estimate separately.

Technical debt and legacy software

Technical debt connects unresolved defects with recurring engineering effort. The CISQ 2022 Report found that the average developer at a company spent 13.5 of 41.1 weekly hours addressing technical debt. That workload represented 33% of weekly developer time. A 2019 forecast cited in the report said 40% of IT budgets would be spent maintaining technical debt by 2025. Because the 2025 figure is a forecast cited by a 2022 report, it should not be read as a measured outcome.

Open-source use was also increasing in the CISQ 2022 findings: 77% of organizations reported increased use of open source software in 2021. A medium-sized application with fewer than 1 million lines of code carried 200 to 300 third-party components on average. More components can mean more maintenance relationships and more opportunities for an issue in an external part to affect an application, although the cited component count alone does not quantify resulting bug rates. (CISQ 2022 Report)

The CISQ 2020 Report stated that legacy systems typically consumed 70% to 75% of the total IT budget and accounted for 80% of total cost of ownership. Those percentages describe typical legacy-system cost patterns in that report, while the 2022 technical-debt estimate describes an accumulated US dollar principal. They are related indicators, but they measure different things.

Dependency and software supply-chain risk

The CISQ 2022 Report said failures due to weaknesses in open-source parts of the software supply chain increased 650% between 2020 and 2021. Datadog’s State of DevSecOps 2026 found that 87% of organizations had at least one known exploitable vulnerability in deployed services. It also found that 42% of services relied on libraries that were no longer actively maintained.

Datadog reported a clear relationship between language support status and exploitable vulnerabilities: services using end-of-life language versions had exploitable vulnerabilities in 50% of cases, compared with 31% for services using supported versions. The same report found that the median software dependency was 278 days out of date. Half of organizations adopted new library versions within 24 hours of release, yet only 4% pinned all public GitHub Actions to a specific version using commit hashes. (Datadog State of DevSecOps 2026)

Runtime context changed how Datadog assessed severity. Only 18% of vulnerabilities with a critical CVSS score remained critical after runtime context was applied. This does not mean the other vulnerabilities were harmless; it means the cited critical classification changed when deployment context was considered. (Datadog State of DevSecOps 2026)

Datadog’s State of DevSecOps 2025 reported that 44% of Java applications contained a known-exploited vulnerability. Across Go, Python, .NET, PHP, Ruby, and JavaScript services, the average share of applications with a known-exploited vulnerability was 2%. Java-based Apache Maven applications took 62 days on average for library fixes, compared with 46 days for .NET-based applications and 19 days for npm-based applications.

The 2025 report also found that 63% of organizations used long-lived credentials at least once to authenticate GitHub Actions pipelines in the prior year, while the current-year share was 58%. Dependencies in services deployed less than once a month were 47% more outdated than dependencies in services deployed daily. Datadog again reported that only 18% of vulnerabilities with a critical CVSS score remained critical after runtime context was applied, and its supply-chain research identified thousands of malicious PyPI and npm libraries. (Datadog State of DevSecOps 2025)

These dependency figures put software bug statistics in a broader maintenance context. A defect can be introduced in application code, inherited through a component, left exposed by an unsupported runtime, or delayed by a slow remediation cycle. The reported measurements do not provide one universal bug probability, but they show why testing guides need to cover reliability, maintenance, deployment context, and supply-chain controls alongside defect discovery.

Written by

sasqag.org Editorial Team

Editorial team

sasqag.org publishes practical how-to guides and educational articles with clear steps and useful context.