Defense Tech Due Diligence Investors Miss

Bar chart showing the surge in defense tech venture funding alongside the compliance risks that complicate defense tech due diligence for investors.

More than $14.6 billion has moved into defense tech startups so far this year, according to Crunchbase — already past the $9.6 billion raised in all of 2025, itself a record at the time. In the first quarter alone, PitchBook counted $19.8 billion deployed across 262 deals, up from $5.7 billion in the same quarter of 2024. Capital is not trickling into this sector. It is flooding it.

Some of that money is going to real revenue. Shield AI closed a $2 billion Series G in March. Saronic raised $1.75 billion the same month. Mach Industries brought in $300 million for autonomous drone systems. Anduril, the sector’s bellwether, has been valued as high as $61 billion. But a growing share of the capital is chasing something thinner. Early-stage defense startups are now raising Series A rounds at 17 to 50 times revenue, and in several cases with no production contract at all — just a pitch deck and a founding team with the right resume. Anduril’s own CEO, Brian Schimpf, called it a bubble outright at a Fortune conference in June: “It’s easy to chase those valuations if you’re not being careful.”

What we’re seeing on our side of the table is a narrower problem, and it has less to do with valuation than with process. We tracked the underlying contracting base in an earlier review — defense AI contract value up more than 1,600 percent since 2024 — and private capital is now chasing that same growth. Deal teams that built their diligence muscle on SaaS and consumer software are applying that playbook to these defense targets. It doesn’t hold up. And the gap between the two isn’t cosmetic.

Why the Standard Diligence Playbook Breaks Down

Defense tech runs on a different clock than the software categories most diligence teams know best. A SaaS company starts lean and spends into growth once product-market fit is proven. A defense hardware company does the opposite — capital goes in years before revenue shows up, and the return, if it comes, arrives after a “program of record” clears a Pentagon budget cycle that can run longer than a fund’s entire hold period. Morgan Hitzig, general partner at Overmatch Ventures, put it plainly: defense tech is “in many ways the inverse of AI or SaaS economics.”

That mismatch shows up in diligence as a category error. A generalist tech-diligence process is built to validate a growth narrative — retention, expansion revenue, unit economics. It is not built to price in a contract vehicle’s transferability, a cost-accounting certification’s legacy liability, or a set-aside status that quietly expires the day the ownership changes. Those are the risks that actually move outcomes in this sector, and they rarely show up in a data room unless someone knows to ask for them.

Six 2026 Shifts That Change What “Clean” Actually Means

The compliance ground under defense M&A moved more in the past eighteen months than in the prior five years combined. A target that would have cleared diligence cleanly in 2024 can carry real exposure today. The items below are the ones we verify first in any defense tech engagement:

  • DOGE terminations and shutdown-distorted financials. More than 2,400 federal contracts were terminated by February 2025, with 200-plus stop-work orders layered on top, followed by a 43-day government shutdown that stalled awards and scrambled receivables. Standard quality-of-earnings normalization treats these as one-time add-backs. They aren’t — the real question is whether the revenue base that remains is actually stable.
  • FY2026 NDAA changes to CAS and TINA thresholds. Full Cost Accounting Standards coverage moved from $50 million to $100 million; contract-level CAS applicability moved from $2.5 million to $35 million; the pricing-data threshold under the Truthful Cost or Pricing Data Act rose from $2.5 million to $10 million for contracts signed after June 30, 2026. Fewer contracts trigger these rules now — but defective-pricing liability certified under the old thresholds survives the acquisition regardless.
  • SBA recertification rules, effective January 16, 2025. Buying a small government contractor no longer guarantees its set-aside revenue transfers with it. Eligibility has to be confirmed vehicle by vehicle, not assumed and modeled as if it converts cleanly to open, unrestricted revenue.
  • CMMC 2.0 becoming a condition of award. Starting November 10, 2026, applicable DoD solicitations can require Level 2 certification through a third-party assessor. That process takes nine to eighteen months, and False Claims Act exposure for past cybersecurity misstatements does not disappear at closing — the Department of Justice has been actively pursuing exactly these cases.
  • Firm-fixed-price contracting as the federal default. An executive order signed April 30, 2026 made fixed-price, performance-based contracting the preferred model across federal procurement. Integration costs, added overhead, and new management layers now come straight out of the contractor’s margin after close, with no government backstop. A target can look stable in trailing financials and still carry meaningfully more forward margin risk than the numbers suggest.
  • AI-specific data and authorization gaps. The FY2026 defense budget request includes $13.4 billion for autonomy and autonomous systems, which is keeping buyer appetite for AI-enabled targets strong. It’s also surfacing problems standard diligence wasn’t built to catch: government data baked into training pipelines, missing FedRAMP or DoD Impact Level authorization, license restrictions that don’t hold in restricted environments, and data rights that were never cleanly assigned in the first place.

The Flashiest Target Isn’t Always the Riskiest One

Here’s the part that runs against the obvious read of this market. A pre-revenue Series A company with a clean cap table and no government contract history can, in some respects, be the more straightforward diligence case — there’s less legacy exposure to inherit, even if the valuation is hard to justify on fundamentals. An established government contractor with real DoD revenue, by contrast, can be sitting on years of certifications, set-aside designations, and contract-type mix that nobody has re-underwritten since the rules changed. The company with the track record is often the one carrying the liability nobody’s re-priced.

That’s not an argument against buying revenue. It’s an argument for treating “has government revenue” and “has clean government revenue” as two different findings that require two different diligence tracks.

What This Means for Deal Teams

Three practices separate the groups that get burned from the ones that don’t. First, run compliance diligence and technology diligence as parallel tracks with different specialists, not one generalist team checking boxes on both. Second, confirm nontraditional-defense-contractor status directly, since NDC exemptions under the FY2026 NDAA are tied to the specific entity performing the work — they don’t automatically travel with a change in ownership structure. Third, model margin under a firm-fixed-price cost shock before signing, not after, using at least three years of contract-type mix rather than a single trailing period.

None of this argues against the sector. The $13.4 billion autonomy line in the FY2026 budget and the volume of capital chasing this space both say the demand is durable. The argument is narrower: the diligence infrastructure protecting that capital has not kept pace with how fast the compliance rules underneath it are moving. Our AI & XR Due Diligence Checklist walks through the technology-side questions we apply in live engagements, and it pairs directly with the compliance items above for any defense-adjacent target. For funds and corporate development teams building or refreshing a defense tech thesis, that’s the conversation we have through our investor advisory engagements — before the term sheet, not after.

Tags:

Comments are closed