Due diligence & M&A
Vendor-neutral guides for founders, CTOs, and acquirers — technology, cybersecurity, and AI due diligence, investor and PE lenses, and how to prepare a readiness report. Not legal advice. Not investment advice.
What belongs on a technology due diligence checklist?
Categorized technology due diligence checklist: architecture, code, security, scale, IP, team, operations. Seed vs growth vs late-stage. Not legal or investment advice.
What belongs on a cybersecurity due diligence checklist?
Cyber due diligence by control domain: posture, vulns, incidents, supply chain, data protection, certifications. Verify scope and dates, not logos. Not legal advice.
What belongs on an AI due diligence checklist?
AI due diligence: model inventory, training-data rights, governance, EU AI Act / ISO 42001 / NIST AI RMF. Applicability aid, not a determination. Not legal advice.
What do investors look for in technical due diligence?
What investors evaluate in technical due diligence: scale, bus-factor, quality, security, roadmap. Green flags vs red flags. Not investment advice.
What do PE firms look for in an engineering organization?
What private-equity firms assess in engineering: delivery, unit economics, technical debt, key-person risk. PE vs VC contrast. Not investment advice.
How do you run security due diligence before an acquisition?
Pre- and post-close security diligence: phases from pre-LOI to integration, certification checks, inherited risk. Reps are legal territory. Not legal advice.
What open-source software risks show up in M&A?
OSS risk in M&A: SBOM, permissive vs copyleft obligations, provenance, known vulnerabilities. Informational — not license-interpretation advice.
How do you assess technical debt in an M&A deal?
How to assess technical debt in M&A: taxonomy, worked quantification example, measurable indicators vs judgment. No single-metric verdicts. Not investment advice.
What AI-generated code risks show up in due diligence?
AI-authored code in diligence: unsettled IP and copyright questions, license contamination, security patterns, how to measure share. Not legal advice.
How do you prepare for technical due diligence?
Prepare for technical due diligence: 90/60/30-day timeline, data-room contents, common mistakes, artifacts investors ask for. Not legal or investment advice.
How do you create an engineering readiness report?
Engineering readiness report outline: scope, metrics, security posture, risks, remediation. Honest denominators, no cherry-picked numbers. Not investment advice.
How does ShipReady Metrics support M&A technical due diligence?
How ShipReady Metrics maps to M&A diligence: Passport, readiness, controls crosswalk, evidence, vulns, AI, DORA. Honest caveats. Not legal or investment advice.