Why Technology DD Isn't IT DD
"IT due diligence" usually means someone checking whether the servers work, the backups run, and the licenses are current. That's operational hygiene — necessary but not sufficient. It doesn't answer the questions a PE deal team actually needs answered.
Technology due diligence sits one level up. It answers:
- Does the technology stack support the investment thesis, or is a major re-platforming baked into the first 24 months?
- What is the real post-close capex requirement — not what the seller has been budgeting, but what the platform actually needs?
- Where are the single points of failure — vendor concentration, key-person dependency, cybersecurity exposure — that the LBO model isn't pricing?
- Can this business survive a customer security questionnaire from a Fortune 500 buyer, or will the cyber posture cost the platform a major account?
- What technology work must be completed before this company is exit-ready three to five years from now?
Those aren't questions an operational IT audit answers. They require a technology executive who has sat in board seats and investment committee rooms.
The Vertex CIO Diligence Framework
Every diligence sprint covers seven areas. Each area produces a red / yellow / green rating, a plain-language explanation, and — where applicable — a dollar figure the deal team can use in the model.
1. Infrastructure & Cloud Architecture
Physical and cloud footprint. Server age and support status. Cloud spend efficiency (are you paying for reserved capacity you don't use). Network architecture and single points of failure. Disaster recovery posture and last successful test.
2. Cybersecurity Posture & Controls
Current controls mapped against a defensible framework (typically NIST CSF for lower-mid market, CIS Controls for smaller targets). Endpoint and identity posture. Prior incidents. MFA coverage. Cyber insurance status and any pending renewal risk. Compliance obligations by customer contract (HIPAA, SOC 2, PCI, defense-related if applicable).
3. Vendor Contracts & Concentration
Every material technology vendor — reviewed for auto-renewal, termination notice periods, price escalators, exclusivity clauses, and single-vendor concentration on business-critical systems. Special attention to MSP contracts, which are often the single largest technology line item and frequently structured against the buyer's interest.
4. IT Organization & Key-Person Risk
Who runs technology today. What happens if that person leaves 30 days after close. Contractor vs. FTE mix. Institutional knowledge captured in documentation vs. locked in heads. MSP relationship — is the MSP a genuine leadership function or a break-fix vendor.
5. Application & Data Architecture
Core business systems (ERP, CRM, financial). Customization debt. Integration architecture. Data ownership and portability. Whether the data model supports the reporting the new owner will demand from month one.
6. Integration or Separation Readiness
For add-ons: how difficult is technology integration into the existing platform. For carve-outs: what shared services need to be replicated, what TSA (transition services agreement) coverage is required, and how long the separation actually takes.
7. Post-Close Capex & Opex Requirements
A 24-month forecast of technology capital and operating requirements — including deferred capex the seller has been avoiding, immediate remediation items, and the cost of bringing controls up to the standard the new owner will expect.
Most common findings
Across our diligence work, the top three findings that repeatedly cost deal value are: (1) MSP contracts that auto-renew for 24–36 months and materially exceed market rates, (2) end-of-life infrastructure that will fail the next round of customer security questionnaires, and (3) key-person dependency on a single IT contractor with no documentation and no succession plan.
Timeline & Process
A standard 3-week sprint runs as follows:
- Week 1 — Data room review and management sessions. Full review of technology-related data room contents. Interviews with the target's IT lead, MSP, and CFO on technology topics. Initial risk register drafted.
- Week 2 — Technical validation and vendor review. Direct technical inspection where access permits, review of every material vendor contract, cybersecurity posture assessment against framework, capex forecast built.
- Week 3 — Draft memo, deal-team review, final memo. Draft memo delivered mid-week. One review call with the deal team to answer questions and refine the risk register. Final memo delivered end of week 3 in time for investment committee.
Accelerated 5–10 business day sprints are available for competitive processes. Scope is trimmed to the highest-risk areas rather than the full framework.
Deliverables
- Diligence memo (20–35 pages). Executive summary, seven-area assessment with red/yellow/green ratings, prioritized risk register, deal-team recommendations.
- Post-close remediation roadmap. First 100 days, first 12 months, and 24-month view — sequenced with cost estimates.
- Capex and opex forecast. Model-ready line items the deal team can insert into the LBO.
- Vendor contract summary. One-page-per-vendor summary of every material technology contract with commercial terms flagged.
- Investment committee readout (optional). Live presentation to IC on the technology thesis and risk profile.
See a sample deliverable
An 8-page illustrative sample of a Technology Diligence Sprint — findings register, technology risk score, and deal-model impact. Composite; no client information reproduced. View the sample →
Fees and When to Engage
Fixed project fees, known upfront. Typical range $10,000–$40,000 for a 3–4 week sprint. Larger and multi-entity deals scoped individually. No hourly billing. No contingent or success fees.
See our full pricing philosophy → — the reasoning behind fixed fees, and how technology DD, fractional CIO, and assessment engagements compare.
The best time to engage is immediately after LOI. Earlier if you want a pre-LOI screen on shortlisted targets. Waiting until confirmatory diligence in the final weeks before close is usually too late to price findings into the deal — by then the negotiation is committed.