
New VDC Strategy Research Finds Memory-Safe Languages Cut Costs and Strengthen Software Quality
A survey of more than 500 embedded software decision-makers ranks Ada, SPARK, and Rust as the leading languages for safety and security, with memory-safe projects reporting lower development costs and up to 60 percent savings in lifecycle maintenance.
VDC today released a new independent research report, Memory-Safe Languages Offer Protection for Devices and TCO, which finds that the choice of embedded software development language has a direct, measurable impact on safety, security, schedule, and total cost of ownership. Authored by the analyst firm VDC Strategy, the report draws on a survey of more than 500 decision-makers responsible for embedded software across the automotive, aerospace, defense, energy, industrial, and medical device industries.
The findings make a clear business case for memory-safe languages such as Ada, SPARK, and Rust. More than 85 percent of engineers surveyed report that programming language choice can affect product safety and security, and respondents ranked Ada, SPARK, and Rust as the three best languages for meeting safety and security requirements out of 26 languages evaluated.
Key Findings:
- Lower development costs: Projects using memory-safe languages reported median development costs that were two to four times lower than those of projects using C and C++.
- Faster delivery: Ada projects were four times more likely to finish ahead of schedule than C projects (69 percent versus 15 percent). SPARK showed the strongest result in the survey, with 80 percent of projects reported ahead of schedule.
- Reduced lifecycle costs: Over a typical seven-year deployment, memory-safe languages were associated with patch and defect remediation savings approaching or exceeding 60 percent in some cases.
- More focus on innovation: Organizations using memory-safe languages devoted 1.7 times more development effort to value-adding work in analytics and AI than those using C.
- Stronger trust in AI-generated code: Users of memory-safe languages reported higher trust in AI-generated code than developers using C or C++; SPARK's formal verification was cited as a way to increase confidence in code produced by agentic AI workflows.
- Accelerating adoption: Ada and Rust have steep growth curves, with Ada usage having already doubled over the past two decades and Rust expected to do the same within the next three years.
A Shifting Landscape for Safety-Critical Software
The report situates these findings against the backdrop of rising regulatory and technical pressure. More than 70 percent of engineering projects must align with a safety-critical process standard such as DO-178 for avionics, IEC 61508 for industrial systems, or ISO 26262 for automotive. At the same time, public policy is reinforcing the shift: the U.S. Office of the National Cyber Director has urged organizations to adopt memory-safe languages, and initiatives including the Cyber Resilience Act and the Secure by Design guidance from CISA and the NSA are accelerating the move away from memory-unsafe languages.
AI-generated code adds further urgency. The majority of engineers surveyed expect the volume of AI-generated code in their next project to grow, yet many cite concerns about its safety, compliance, and security. The report points to memory-safe languages, and to SPARK's formal verification in particular, as a means of shifting verification earlier in the development cycle and raising confidence in code produced with the help of AI.
“These results confirm what our customers in the most demanding industries have known for years: memory safety is not only a safety and security decision, it is a business decision,” said Quentin Ochem, Chief Product Officer of AdaCore. “The data shows that teams using Ada, SPARK, and Rust ship sooner, spend less over the life of a product, and free up engineers to focus on the features that differentiate them. As AI takes on a larger role in code generation, that foundation of verifiable, memory-safe code becomes more important, not less.”
“Memory-safety vulnerabilities remain one of the most significant sources of software defects, and our research shows that language choice is a powerful and often underused lever for reducing risk and cost,” said Chris Rommel, Executive Vice President at VDC Strategy. “The schedule and lifecycle cost differences we observed between memory-safe languages and traditional alternatives were substantial and consistent.”
Report Availability
The full report, Memory-Safe Languages Offer Protection for Devices and TCO, is available to download here.





