Guide
IT Due Diligence Checklist for M&A
A practical, evidence-based framework for evaluating a target's technology before close. Use it to separate marketing claims from operational reality across infrastructure, security, code, cloud spend, and IT operations.
1. Infrastructure & Cloud Architecture
- Inventory all cloud accounts (AWS, Azure, GCP) and on-prem environments with owner and purpose.
- Map network topology, VPCs, peering, ingress/egress, and trust boundaries.
- Verify environment separation: prod, staging, dev with distinct credentials and IAM boundaries.
- Confirm disaster recovery plan: RPO/RTO targets, last successful restore test, multi-region posture.
- Reconcile claimed scale (RPS, DAU, data volume) against actual cloud telemetry.
2. Security Posture
- Pull findings from the cloud-native security scanners (GuardDuty, Defender, SCC) and any third-party tooling (Wiz, Snyk, Orca).
- Confirm MFA enforced for all human users; rotate or revoke long-lived access keys.
- Review IAM: least-privilege roles, service accounts, cross-account trust, no shared admin.
- Check secrets handling: KMS-backed secret manager, no plaintext secrets in repos, CI, or env files.
- Validate SOC 2 / ISO 27001 / HIPAA evidence is current and matches systems actually in use.
- Review breach history, incident response playbooks, and time-to-detect / time-to-resolve metrics.
3. Codebase & Engineering Practices
- Static analysis: code quality, complexity, duplicated code, language sprawl.
- Open-source license scan, flag GPL/AGPL contamination in proprietary code paths.
- Dependency health: outdated packages, known CVEs, end-of-life runtimes.
- Test coverage and CI signal: are tests run, are flaky tests masking failures, does main stay green.
- Review PR cadence, branching model, and deployment frequency, these reveal engineering maturity faster than headcount.
- Verify the claimed tech stack and AI/ML capability actually exists in the repo, not just on slides.
4. Cloud Spend & Unit Economics
- Reconcile last 12 months of cloud invoices against the COGS line in the model.
- Identify top 10 cost drivers and unused / oversized resources.
- Quantify reserved-instance or committed-use coverage and renewal risk.
- Check egress and data-transfer costs, these scale non-linearly with growth.
- Stress-test the unit-economics story: cost per active user, per transaction, per inference.
5. IT Operations & SaaS Stack
- Inventory SaaS subscriptions with renewal dates, seat counts, and owner.
- Identify shadow IT and duplicate tooling.
- Review endpoint management: MDM coverage, disk encryption, patch SLA.
- Confirm offboarding process: SSO de-provisioning closes all critical access in under 24 hours.
6. Data, Privacy & AI Governance
- Map where customer data lives, who can access it, and how it's classified.
- Confirm DPIA / ROPA records for GDPR, CCPA, and other applicable regimes.
- Review data-retention policies and actual deletion practice, not just the policy doc.
- For AI/ML systems: training-data provenance, model cards, and contractual restrictions on customer data use.
7. Reconciliation Against Seller Claims
- Compare every quantified claim in the CIM (uptime, scale, ARR per engineer, security posture) against direct evidence from the systems.
- Document gaps as priced risk items in the cost-to-cure ledger, not as soft caveats.
- Flag any claim that cannot be verified, unverifiable is a finding.
Run this checklist as a priced reconciliation, not a document review
NexusDiligence ingests the target's own evidence, scores it against the diligence pillars, and reconciles every claim against live infrastructure findings. Gaps land in the cost-to-cure ledger so you price technical risk before signing, not after.