Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do you prepare for technical due diligence?

Last verified

Prepare on a 90/60/30-day clock: inventory and gaps first, then evidence and metrics, then a clean data room and rehearsal. Surprises in confirmatory are usually missing artifacts, not new physics. This page is not legal advice and not investment advice.

Preparing for technical diligence, last verified 10 September 2026 against ISO/IEC 25010, NIST CSF 2.0, AICPA TSC evidence expectations, and descriptive diligence-process notes. Not legal advice. Not investment advice.

Preparation is a project, not a weekend

Audience: a founder or CTO entering a raise or sale. This page is not legal advice and not investment advice. Kind of text: ISO/IEC 25010, NIST CSF, and TSC are the same kinds of text as on the hub checklist. Diligence timelines here are operational best practice, not a regulator’s clock. This page does not start a deal clock.

90 / 60 / 30 prep timeline

Count backward from the date you expect to open the room. Last verified 10 September 2026. Not YOUR dates. Not legal advice.

Phased prep timeline (operational; not a regulator clock; not legal or investment advice)
WhenFocusDone looks like
90 days outInventory: systems, owners, certifications, known incidents, OSS, AI use.A gap list with owners. No fake logos started.
60 days outEvidence: reports, restore tests, metrics with denominators, SBOM, policies you actually follow.Artifacts collected; missing items have a written story.
30 days outRoom hygiene and rehearsal: naming, permissions, Q&A doc, readiness report draft.A reviewer who is not the author can find every hub-checklist row.

Data-room contents checklist

Examples of requested artifacts: architecture pack, org chart, DORA definitions, last incident review, SOC 2 or honest absence, ISO certificate or honest absence, pen-test report or documented alternative, SBOM, AI inventory, customer-security exhibits. Match the tech-DD hub. Last verified 10 September 2026.

  • Index file that maps folder names to the hub checklist categories.
  • Current vs historical attestations clearly dated.
  • Redacted exploit appendices in a tighter-ACL folder.

Common mistakes

Starting the room the week of the first call. Uploading expired certificates. Inventing statistics. Granting world-readable access to exploit detail. Briefing the CEO on a metric the CTO cannot define. Treating Passport or a readiness score as a substitute for the underlying artifacts.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice. Not investment advice.

  • Pick the open-room date and write the 90/60/30 owners this week.
  • Open the hub checklist, the investor-lens page, and the readiness-report page on this site.
  • If you already have a session: Passport, evidence collection, A–E readiness, and the policies library are the assembly line — not the deal.

Checklist

Question list. Not legal advice.

  • Is every hub category assigned?
  • Can a stranger navigate the room without Slack?
  • Have we rehearsed the top ten questions?
  • Are we about to send a number without a denominator?

Where this shows up in ShipReady Metrics

ShipReady Passport, evidence collection, readiness score and A–E ratings, and the policies library. The product does not run the process for you and does not give investment advice.

Primary sources (last verified 10 September 2026)

ISO/IEC 25010. NIST CSF 2.0. AICPA TSC (evidence expectations). Diligence frameworks cited descriptively. Not legal advice.

Frequently asked questions