Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you prepare for technical due diligence?
Last verifiedPrepare on a 90/60/30-day clock: inventory and gaps first, then evidence and metrics, then a clean data room and rehearsal. Surprises in confirmatory are usually missing artifacts, not new physics. This page is not legal advice and not investment advice.
Preparing for technical diligence, last verified 10 September 2026 against ISO/IEC 25010, NIST CSF 2.0, AICPA TSC evidence expectations, and descriptive diligence-process notes. Not legal advice. Not investment advice.
Preparation is a project, not a weekend
Audience: a founder or CTO entering a raise or sale. This page is not legal advice and not investment advice. Kind of text: ISO/IEC 25010, NIST CSF, and TSC are the same kinds of text as on the hub checklist. Diligence timelines here are operational best practice, not a regulator’s clock. This page does not start a deal clock.
90 / 60 / 30 prep timeline
Count backward from the date you expect to open the room. Last verified 10 September 2026. Not YOUR dates. Not legal advice.
| When | Focus | Done looks like |
|---|---|---|
| 90 days out | Inventory: systems, owners, certifications, known incidents, OSS, AI use. | A gap list with owners. No fake logos started. |
| 60 days out | Evidence: reports, restore tests, metrics with denominators, SBOM, policies you actually follow. | Artifacts collected; missing items have a written story. |
| 30 days out | Room hygiene and rehearsal: naming, permissions, Q&A doc, readiness report draft. | A reviewer who is not the author can find every hub-checklist row. |
Data-room contents checklist
Examples of requested artifacts: architecture pack, org chart, DORA definitions, last incident review, SOC 2 or honest absence, ISO certificate or honest absence, pen-test report or documented alternative, SBOM, AI inventory, customer-security exhibits. Match the tech-DD hub. Last verified 10 September 2026.
- Index file that maps folder names to the hub checklist categories.
- Current vs historical attestations clearly dated.
- Redacted exploit appendices in a tighter-ACL folder.
Common mistakes
Starting the room the week of the first call. Uploading expired certificates. Inventing statistics. Granting world-readable access to exploit detail. Briefing the CEO on a metric the CTO cannot define. Treating Passport or a readiness score as a substitute for the underlying artifacts.
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice. Not investment advice.
- Pick the open-room date and write the 90/60/30 owners this week.
- Open the hub checklist, the investor-lens page, and the readiness-report page on this site.
- If you already have a session: Passport, evidence collection, A–E readiness, and the policies library are the assembly line — not the deal.
Checklist
Question list. Not legal advice.
- Is every hub category assigned?
- Can a stranger navigate the room without Slack?
- Have we rehearsed the top ten questions?
- Are we about to send a number without a denominator?
Where this shows up in ShipReady Metrics
ShipReady Passport, evidence collection, readiness score and A–E ratings, and the policies library. The product does not run the process for you and does not give investment advice.
Primary sources (last verified 10 September 2026)
ISO/IEC 25010. NIST CSF 2.0. AICPA TSC (evidence expectations). Diligence frameworks cited descriptively. Not legal advice.