What we found
90%
Time decides engagement
Among programs securing more than two hours of Champion time a month, 90% report their Champions staying engaged. Below that line, 25% do.
44%
Position beats scale
Programs their organization counts on to meet security goals report 44% active participation, against 24% for programs sitting outside the strategy.
4.0
Measurement if still the barrier
Measuring program impact rates 4.0 out of 5 for difficulty, the hardest challenge for the second year running, and it moved up from 3.9 in 2025.
FINDING ONE
Time is the scarcest resource, and it's the one that decides engagement
Among programs that secure more than two hours of Champion time each month, 90% report that their Champions are staying engaged. Among programs asking for two hours or less, 25% do. It is the strongest relationship in our data, and it is stronger than anything budget produces.
Time is also the reason Champions disengage. Among programs reporting that engagement has faded, time management was cited four times as often as lack of budget.
FIGURE 12: Programs Reporting that Champions Stay Engaged, by Time Commitment
.png)
FIGURE 20: Champions and Central Security Team per 100 Developers
.png)
FINDING TWO
Where the program sits predicts more than how big it is
Neither organization size nor Champion count shows a meaningful relationship with reported effectiveness. What does is position. Programs their organization counts on to meet security goals report 44% active participation, against 24% for programs sitting outside the strategy with goals of their own.
BSIMM16 points the same way from a different angle. Among the highest-scoring software security organizations there are 12.3 Champions per 100 developers and 2.7 central security staff. At the bottom, those numbers are 4.6 and 6.8. Expertise moves outward as programs mature.
FINDING THREE
Measuring impact is still the hardest problem, and what you measure matters
Measuring program impact rated 4.0 out of 5 for difficulty, up from 3.9 last year. Yet programs tracking security posture measures report effectiveness of 3.7 against 2.9 for those that do not.
The shift shows up across program age. Security posture measures rise from 22% of programs under a year old to 88% of programs past their fourth year, while counts of bugs found and departments covered fall away. Early programs count what they can see. Established programs measure the posture of what they touch.
FIGURE 16: What Programs Measure, by Program Age

Most programs sit between Guided and Integrated
Standards exist and Champions are modelling them. Far fewer programs have moved those checks into daily engineering workflows. The report reads every finding against this model and closes with the specific next move at each stage.
.png)
What's inside
The Current State: who runs Champion programs, how far they reach, and what they focus on.
The Investment Question: what programs cost in budget and in time. No one has published this before.
Running the Program: structure, engagement, recognition, measurement, and what owners find hardest.
Benchmarks and Playbooks: our data compared against BSIMM16 and Layer 8, and the next move at each maturity stage.
How it was made
34 respondents, 33 with an active program
37 questions, up from roughly ten in 2025
Fielded January – August 2026, covering calendar year 2025
Every cohort figure carries its sample size. Small sample; findings are directional rather than statistically representative, and we say so throughout.
Take the whole report with you
Forty pages, twenty-two figures, and the full methodology. Useful when you are making the case internally and need something to send round.
FREE GUIDE
The Security Champion Success Guide
The seven-step process behind the maturity model, published openly.
LAST YEAR'S FINDINGS
The 2025 report
The first edition, and the baseline every year-over-year comparison in this one is drawn against.
YOUR PROGRAM
Program Assessment
An objective read on where yours stands, with a roadmap for what to fix.

