£22,000. Two to three weeks.
Standard Technology Due Diligence
Our core assessment, and the one most deals need. A full independent read on the technology, the team behind it, and what the risks will actually cost you.
BOOK A DUE DILIGENCE CALL
What it is
Standard Technology Due Diligence is a complete independent assessment of a target company's technology, run in the window between term sheet and completion.
A fractional CTO leads the architecture, delivery, cost and team assessment. A fractional CISO leads security and compliance. Both have run the kind of systems they are assessing, in businesses of the kind you are buying, which is the difference between a report that tells you what exists and a report that tells you what it means.
The output is a prioritised, costed findings report that a deal team can act on: what the risks are, what they will cost to fix, which of them should change your price, and which you can live with.
When to use it
Use the Standard DD when the deal is live and heading to completion, and the technology carries a material part of the growth case.
That covers most software and technology-enabled transactions: a platform business where the product is the value, a services business where systems are the operating spine, or any target where the plan assumes scale the current technology may not support. If the investment committee paper needs a technology section that will stand up to challenge, this is the tier that produces it.
If you are still screening and need a faster, cheaper read, start with the Red Flag Review. If you are buying control and will own the outcome from day one, the DD Plus 100-Day Plan adds the plan for what you do afterwards.
What we assess
Six areas, each framed around the question an investor needs answered rather than the question an engineer finds interesting.
-
Architecture and scalability against the deal thesis. Not "is this good architecture" in the abstract, but "will this take the growth you are underwriting". We model the architecture against the plan's volume, geography and product assumptions, and tell you where it breaks and what fixing it costs.
-
Team and leadership capability, including key-person risk. Whether the engineering organisation can deliver the plan, whether the technology leadership is strong enough for where the business is going, and how much of the capability sits with individuals who may leave. We name the risk concretely rather than gesturing at it.
-
Security and compliance posture. Led by a senior CISO. Where the exposure is, what liabilities transfer with the deal, what state the target's data protection obligations are actually in, and what remediation would cost and take. Certifications are verified rather than accepted.
-
Technical debt, quantified and costed. The part most reports handle badly. We do not tell you the codebase has debt, which is true of every codebase. We tell you which debt constrains the plan, what it will cost in engineering time to address, and what happens if you do not.
-
Roadmap credibility against the delivery track record. The roadmap is a sales document. We compare it against what the team has actually shipped over the preceding periods and tell you whether the plan is achievable, optimistic, or fiction.
-
Run-rate technology cost, and where it goes after the deal. Current spend across infrastructure, licensing, and suppliers, plus the direction of travel. Cost that scales with revenue is very different from cost that scales with users, and the difference shows up in your model.
What you receive
- A prioritised findings report. Typically twenty five to forty pages depending on the target. Each finding carries a severity, a commercial implication, an indicative remediation cost, and a recommendation. Findings are ordered by what matters to the deal, not by which section they fall in.
- An executive summary that stands alone. One to two pages your investment committee can read without the rest. It states the overall technology view, the findings that should affect price or structure, and the conditions we would attach to proceeding.
- A risk register. Every finding in a single table, with severity, cost, and owner, so it can be carried into the transaction documents or the post-close plan.
- A full debrief with the deal team. Usually ninety minutes. We walk through the findings and answer the hard questions, including the ones about how confident we are and where we could be wrong.
- Follow-up availability through to completion. Questions come up late in a deal. We stay reachable until it closes, at no extra cost.
Three ways to buy it
Fixed prices, published, no hourly rates. You know what the work costs and what you get before you commission it, which is more than most of the deal process will offer you.
How the assessment runs
Week one: scoping and access. A kick-off with your deal team to understand the thesis, the timeline, and what would change your mind. Then data room access and scheduling with the target's technology leadership. We tell you within the first few days whether the access we are getting is sufficient.
Week one to two: assessment. Documentation and architecture review, security and compliance assessment, structured sessions with the target's CTO, engineering leads and, where relevant, their infrastructure or security people. Where code access is granted, targeted review of the areas that carry the most risk rather than a superficial pass over everything.
Week two to three: analysis, drafting and delivery. Findings quantified and costed, report drafted, and a factual accuracy pass where appropriate so the target can correct errors of fact without influencing our conclusions. Then delivery and debrief.
Two to three weeks is the normal range. Larger targets, carve-outs, regulated businesses, and deals with multiple entities or offshore teams take longer, and we tell you that on the first call rather than three weeks in.
Who it is for
-
Private equity firms running buy-side diligence on a platform or bolt-on acquisition. Venture capital investors at Series A and beyond, where the technology has to support a step change in scale. Corporate acquirers who need an independent view rather than their own team marking a competitor's homework. Corporate finance advisers and M&A lawyers commissioning on behalf of a client.
-
It also works vendor-side. Founders preparing to raise or sell commission the same assessment to find and fix problems before an investor's diligence finds them, which protects both valuation and negotiating position.
What it does not cover
The Standard DD tells you what is true about the technology and what it will cost. It does not tell you what to do about it in sequence, with owners and a budget, across the first quarter of ownership.
If you are taking control and will own the technology outcome from day one, the DD Plus 90-Day Plan adds exactly that for £35,000.
It also does not include remediation. If the diligence finds problems and you want help fixing them after completion, the same CTOs and CISOs can step in as fractional leadership. That is a separate engagement and there is no obligation to take it. The report stands on its own.
Frequently asked questions
What does a technology due diligence report cover?
How long does technology due diligence take?
What questions does technology due diligence answer?
Do you review the source code?
Do you offer sell-side or vendor due diligence?
Will the target find the process adversarial?
Are your fees fixed?
5-Minute Survey
Is Your Tech Ready To Scale?
Take our free survey, and get a personalised report & step-by-step action plan to optimize your tech.
TAKE THE SURVEY
Get actionable advice every Saturday
The CTO’s Playbook
Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.