Due Diligence Checklist: What Buyers Look For in a Tech Acquisition
M&A Intelligence · The CODEW Intelligence
What buyers actually investigate during a tech acquisition — the six diligence categories, the red flags that kill deals, and how founders can prepare before diligence starts.
Due diligence is where tech acquisitions live or die. An LOI might signal strong mutual interest, but it is the diligence phase — typically 4 to 12 weeks of deep investigation — where buyers either confirm that interest or walk away.
A messy cap table, an undisclosed lawsuit, or a codebase full of unlicensed dependencies can sink a deal even after price has already been agreed. Here is what buyers actually dig into, organized by category, and why each one matters.
Financial Due Diligence
Revenue quality — Is revenue recurring and predictable, or lumpy and one-off? Buyers scrutinize the mix of subscription vs. one-time revenue closely.
Customer concentration — If a small number of customers make up a large share of revenue, that is a red flag for post-acquisition stability.
Churn and retention metrics — Net revenue retention, logo churn, and expansion revenue tell buyers whether the business is genuinely healthy or has been propped up by one-time deals.
Accounts receivable and payable — Are customers actually paying on time? Are there unpaid vendor obligations that will become the buyer's problem?
Historical financial statements — Usually 2–3 years of audited or reviewed financials, checked for consistency and accuracy.
The CODEW Lens: Financial diligence is not about whether the numbers look good. It is about whether the numbers are real. Consistency matters more than headline revenue.
Legal Due Diligence
Cap table accuracy — Every outstanding share, option, warrant, and SAFE needs to be accounted for. Cap table messes are one of the most common deal-delaying issues.
IP ownership — Does the company actually own its core technology outright, or are there unresolved claims from former employees, contractors, or co-founders?
Litigation history — Any pending or past lawsuits, employment disputes, or regulatory actions get flagged and factored into risk.
Material contracts — Customer agreements, vendor contracts, and partnership deals are reviewed for change-of-control clauses that could be triggered by the acquisition.
Employment agreements — Non-competes, IP assignment agreements, and any unusual compensation arrangements.
The CODEW Lens: Legal diligence is where the past comes back. A missing IP assignment or an unrecorded SAFE can turn a straightforward deal into a renegotiation. Build the record before you need it.
Technical Due Diligence
Codebase quality — Buyers (or their engineering teams) assess technical debt, code organization, and whether the system can scale or will need significant rework.
Open-source and license compliance — Unlicensed or improperly licensed open-source dependencies can create real legal exposure for the buyer post-acquisition.
Architecture and scalability — Can the current system handle the buyer's scale, or will it need to be rebuilt?
Security posture — Past breaches, vulnerability history, and current security practices, especially important if the target handles sensitive user data.
Infrastructure dependencies — Reliance on specific vendors, cloud providers, or hard-to-replace contractors.
The CODEW Lens: Technical diligence is where the product meets reality. A great demo can hide a codebase that cannot scale. Buyers bring in engineers to look past the demo.
Data Privacy and Compliance
Data handling practices — How customer data is collected, stored, and used, and whether it complies with relevant regulations (GDPR, CCPA, HIPAA, depending on sector).
Data breach history — Any past incidents, how they were handled, and what commitments were made to affected users.
Regulatory standing — Any open investigations or compliance gaps that could become the buyer's liability.
The CODEW Lens: Data privacy has moved from a footnote to a first-order concern. Regulators now expect that acquirers inherit the compliance posture of their targets. What the target did not fix becomes the buyer's liability.
Team and Organizational Due Diligence
Key person dependency — How much of the company's value is tied to specific individuals staying on, and are they actually willing to stay post-acquisition?
Organizational structure — Reporting lines, team composition, and any redundant roles that overlap with the buyer's existing teams.
Culture fit — Increasingly assessed formally, especially for deals where the acquired team will be integrated rather than run standalone.
Compensation and equity — Understanding what retention packages or accelerated vesting will be needed to keep key people through and after the transition.
The CODEW Lens: Team diligence is where culture meets contract. A retention package can keep people in their seats, but it cannot make them want to stay. The best acquisitions are the ones where the team actually wants to be there.
Customer and Market Due Diligence
Customer references — Buyers often speak directly with key customers to validate satisfaction and retention likelihood post-acquisition.
Competitive positioning — Is the target's market position defensible, or is it losing ground to competitors?
Total addressable market — Validating that the growth story the target is telling has room to actually play out.
The CODEW Lens: Customer diligence is the reality check on the growth story. Revenue tells you what happened. Customer interviews tell you what is likely to happen next.
Why Deals Fall Apart During Diligence
The most common deal-killers are not dramatic scandals — they are mundane issues that erode buyer confidence:
Inconsistencies between what founders said in early conversations and what the numbers actually show
Cap table surprises (undisclosed option pools, unclear SAFE terms)
Customer concentration that was not fully disclosed upfront
Technical debt significantly worse than represented
Key employees who make clear they do not intend to stay
The CODEW Lens: Deals do not die from the problems themselves. They die from problems the buyer discovers on their own. Disclosed issues are negotiable. Hidden issues are trust-breaking.
How Founders Can Prepare
If you are heading into an acquisition, the best move is to run your own diligence on yourself before the buyer does:
Clean up your cap table — Do this before you are in active deal conversations, not during them.
Get your financials in order — Clear, consistent records win trust fast.
Resolve IP ambiguity early — Make sure every contractor and former employee has signed proper IP assignment agreements.
Be upfront about known issues — Buyers are far more forgiving of disclosed problems than ones they discover themselves.
Know your key-person risk — Be ready to discuss retention honestly, since buyers will ask directly.
The CODEW Lens: Diligence preparation is not about hiding problems. It is about knowing them before the buyer does. Founders who have already run their own diligence arrive with clarity instead of surprises.
The Bottom Line
Due diligence is not a formality — it is the phase where a buyer's confidence in the deal is actually tested against reality.
Founders who go in with clean financials, a tidy cap table, documented IP, and honest disclosure dramatically improve their odds of a deal actually closing on the terms both sides shook hands on.
The CODEW Lens: Due diligence is a mirror. It reflects what the company actually is, not what the founder said it was. The best way to pass is to make the mirror unnecessary — by building a company that holds up to scrutiny long before anyone asks.
Related Reading
How Tech Acquisitions Work — The full acquisition timeline, step by step.
Glossary of M&A Terms — Common valuation, deal structure, and diligence terminology.
How Tech Company Valuations Work — Revenue multiples, comps, DCF, and strategic premium.
Tech M&A Database — Track real deals as they happen.
The CODEW Stat
6 categories · 4–12 weeks · 5 deal-killers Tech acquisition due diligence spans six categories — financial, legal, technical, data privacy, team, and customer/market. The process typically takes 4–12 weeks. And the five most common deal-killers are not scandals — they are mundane issues that erode buyer confidence. The lesson is not to hide problems. It is to know them first.
No comments: