Technology due diligence

For private equity and M&A: what a target's IT, security, licensing and custom software are worth, what they cost to own, and whether that changes your offer. Deal Scan £7,500, Technical Due Diligence from £18,000, both excluding VAT.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor CISSPHeld by Daniel McClure Fisher
ISO 27001 and ISO 9001 certified, via a UKAS-accredited certification body

Certified for ISO 27001 and ISO 9001 by a UKAS-accredited certification body

The diligence here comes from a firm that holds both certificates itself, 00508-ISMS-001 and 00508-QMS-001.

The team behind the certificates
Deal Assurance / 01 · What it is

What technology due diligence tells you

Technology due diligence, also called technical or IT due diligence, answers four questions before you commit capital.

01What you are buying. The state of the estate: infrastructure, cloud, licensing and what it costs to run, not what the deck says.
02Where the risk sits. Security posture, exposed services, breach history, end-of-life software, key-person dependency.
03The custom-software question. What the custom systems are, whether they are maintainable, and what they cost to keep, wrap or replace.
04A number for the model. A remediation and integration estimate that changes the price or confirms it.
Deal Assurance / 02 · Three ways in

Three engagements, each priced before we start

Read access to the data room, then scope, timetable and fee agreed before any work begins. All fees exclude VAT.

01Screen

Deal Scan

A red-flag assessment before you make an offer, run off the data room and the target's external footprint. You get a proceed, caution or walk call, and it credits in full against a Technical Due Diligence within 90 days.

Pre-offer3-5 days£7,500 + VAT, fixed
02Assess

Technical Due Diligence

The full report, run in exclusivity: infrastructure, security posture and licensing, plus the custom-software question, whether it is maintainable and what it costs to keep, wrap or replace, with integration cost and a remediation estimate for the model.

In exclusivity~10 working daysFrom £18,000 + VAT
03Integrate

First 100 Days

Post-completion remediation and integration: Cyber Essentials or Cyber Essentials Plus readiness for the target, with the formal assessment run separately; a cross-tenant collaboration model rather than a forced tenant merge; SharePoint-to-SharePoint migration; device and Intune enrolment; and a security uplift to what the group's contracts require.

Post-completionScoped per dealRemediation + integration
Deal Assurance / 03 · Sell-side

Sell-side IT readiness

The same work from the other side of the table. Before you go to market we get the IT story clean: documentation, certifications, warranty-disclosure preparation, and the estate mapped against the checklist a buyer's diligence team works through. We have sat on both sides, including live IT-warranty disclosure during SPA negotiations. From £12,000 excluding VAT.

Where deal assurance sits in what we do

We are an NCSC Assured Service Provider and an appointed Cyber Essentials certification body, certified for ISO 27001 and ISO 9001 by a UKAS-accredited certification body.

Technology due diligence draws on the team that handles the rest of a deal's technology lifecycle: the Cyber Essentials certification and NCSC-assured security work that hardens a target, the software engineering team who can read its codebase and take it over, and the managed IT service that runs the estate after completion. The report is a standalone piece of work under our governance and audit practice.

Our technology due diligence checklist sets out the six areas and the custom-software question in full.

FAQ

Common questions

What is technology due diligence?

Technology due diligence is an assessment of a target company's technology before you complete a deal, its infrastructure, security posture, licensing, and any custom software, carried out for the buyer to work out whether the technology changes what the business is worth and what it will cost to own after completion.

It is also called technical due diligence or IT due diligence. A good report ends with a number: a remediation and integration estimate the deal team can put straight into the model.

How is technology due diligence different from cyber due diligence and financial due diligence?

Financial due diligence checks the numbers; technology due diligence checks whether the technology behind those numbers is sound, secure, and affordable to run. Cyber due diligence is one part of it, the security posture, breach history, and exposure, whereas technology (or technical) due diligence also covers infrastructure, licensing, integration cost, and the state of any custom software. We can cover the cyber question inside a full technical report, or as a standalone Deal Scan.

How long does technology due diligence take?

A pre-offer Deal Scan takes 3-5 days. A full Technical Due Diligence takes around 10 working days, depending on the size and complexity of the target. We agree the timetable up front and work to your deal calendar, including in exclusivity.

How much does technology due diligence cost?

We publish fixed fees, and all of them exclude VAT. A Deal Scan is £7,500 excluding VAT, and it credits in full against a full Technical Due Diligence commissioned within 90 days. Technical Due Diligence starts from £18,000 excluding VAT, tiered by the size and complexity of the target and quoted before we start. Sell-side IT readiness starts from £12,000 excluding VAT. Every fee is agreed before you commit.

You also do the remediation, doesn't that bias the report?

No, and we structure it so you do not have to take that on trust. The report is a standalone fixed fee for the diligence itself. Any remediation or integration is quoted separately and is entirely yours to award, to us, to your own team, or to another supplier. The findings stand whoever does the work.

What about bespoke or custom software with no documentation?

That is often the hardest part of a deal. Our software engineers assess the codebase itself, architecture, stack, code quality, and documentation, and answer the questions that matter: is it maintainable, would one key person leaving sink it, and what does it cost to keep, wrap, or replace? If you complete, the same team can take the software over, so a risk we flag is one we can also close.

Can you work in exclusivity and to a fixed deal timetable?

Yes. Most Technical Due Diligence runs during exclusivity against a fixed completion date. We agree scope and timetable before we start and keep to it. If a deal is moving faster, the Deal Scan gives you a proceed, caution, or walk call in 3-5 days.

Do you cover sell-side as well as buy-side?

Yes. Sell-side IT readiness is the same work from the other side of the table: we get a business's IT story clean before it goes to market, documentation, certifications, and warranty-disclosure preparation, so it is ready for the buyer's diligence process. It starts from £12,000 excluding VAT, and it suits investors and lenders preparing an asset for sale, not only trade owners.

Have a deal on the table?

Tell us about the target and where you are: pre-offer, in exclusivity or preparing for exit.

Reading, Berkshire  /  UK-wide / fixed-fee reports, quoted before we start  /  reply within one working day