Guide

IT Due Diligence Checklist for M&A

A practical, evidence-based framework for evaluating a target's technology before close. Use it to separate marketing claims from operational reality across infrastructure, security, code, cloud spend, and IT operations.

1. Infrastructure & Cloud Architecture

  • Inventory all cloud accounts (AWS, Azure, GCP) and on-prem environments with owner and purpose.
  • Map network topology, VPCs, peering, ingress/egress, and trust boundaries.
  • Verify environment separation: prod, staging, dev with distinct credentials and IAM boundaries.
  • Confirm disaster recovery plan: RPO/RTO targets, last successful restore test, multi-region posture.
  • Reconcile claimed scale (RPS, DAU, data volume) against actual cloud telemetry.

2. Security Posture

  • Pull findings from the cloud-native security scanners (GuardDuty, Defender, SCC) and any third-party tooling (Wiz, Snyk, Orca).
  • Confirm MFA enforced for all human users; rotate or revoke long-lived access keys.
  • Review IAM: least-privilege roles, service accounts, cross-account trust, no shared admin.
  • Check secrets handling: KMS-backed secret manager, no plaintext secrets in repos, CI, or env files.
  • Validate SOC 2 / ISO 27001 / HIPAA evidence is current and matches systems actually in use.
  • Review breach history, incident response playbooks, and time-to-detect / time-to-resolve metrics.

3. Codebase & Engineering Practices

  • Static analysis: code quality, complexity, duplicated code, language sprawl.
  • Open-source license scan, flag GPL/AGPL contamination in proprietary code paths.
  • Dependency health: outdated packages, known CVEs, end-of-life runtimes.
  • Test coverage and CI signal: are tests run, are flaky tests masking failures, does main stay green.
  • Review PR cadence, branching model, and deployment frequency, these reveal engineering maturity faster than headcount.
  • Verify the claimed tech stack and AI/ML capability actually exists in the repo, not just on slides.

4. Cloud Spend & Unit Economics

  • Reconcile last 12 months of cloud invoices against the COGS line in the model.
  • Identify top 10 cost drivers and unused / oversized resources.
  • Quantify reserved-instance or committed-use coverage and renewal risk.
  • Check egress and data-transfer costs, these scale non-linearly with growth.
  • Stress-test the unit-economics story: cost per active user, per transaction, per inference.

5. IT Operations & SaaS Stack

  • Inventory SaaS subscriptions with renewal dates, seat counts, and owner.
  • Identify shadow IT and duplicate tooling.
  • Review endpoint management: MDM coverage, disk encryption, patch SLA.
  • Confirm offboarding process: SSO de-provisioning closes all critical access in under 24 hours.

6. Data, Privacy & AI Governance

  • Map where customer data lives, who can access it, and how it's classified.
  • Confirm DPIA / ROPA records for GDPR, CCPA, and other applicable regimes.
  • Review data-retention policies and actual deletion practice, not just the policy doc.
  • For AI/ML systems: training-data provenance, model cards, and contractual restrictions on customer data use.

7. Reconciliation Against Seller Claims

  • Compare every quantified claim in the CIM (uptime, scale, ARR per engineer, security posture) against direct evidence from the systems.
  • Document gaps as priced risk items in the cost-to-cure ledger, not as soft caveats.
  • Flag any claim that cannot be verified, unverifiable is a finding.

Run this checklist as a priced reconciliation, not a document review

NexusDiligence ingests the target's own evidence, scores it against the diligence pillars, and reconciles every claim against live infrastructure findings. Gaps land in the cost-to-cure ledger so you price technical risk before signing, not after.