Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you run security due diligence before an acquisition?
Last verifiedAcquisition security diligence runs in phases — pre-LOI scoping, confirmatory evidence, then integration and remediation — so inherited risk is priced before close. Verify certifications by scope and date. Reps and warranties are counsel’s work. This page is not legal advice.
Security diligence before acquisition, last verified 10 September 2026 against NIST CSF 2.0, ISO/IEC 27001:2022, AICPA TSC, ENISA guidance, and breach-notification statutes referenced only descriptively. Those statutes are legal requirements if they apply — this page does not apply them to YOU and does not start a clock. Not legal advice. Not investment advice.
Inherited risk is the product you are also buying
Audience: an acquiring CISO or corp-dev lead. This page is not legal advice and not investment advice. Kind of text: NIST CSF 2.0, ISO/IEC 27001, and TSC are frameworks / standards / criteria as labeled on the cyber checklist. Breach-notification duties (GDPR, US state laws, others) are legal requirements only if they apply — last verified descriptively on 10 September 2026; open the breach-reporting hub for regime pages. Reps, warranties, and indemnity are legal territory.
Diligence-phase timeline
Last verified 10 September 2026. Phases overlap. This page does not start a deal clock. Not legal advice.
| Phase | Security work | Typical outputs | Kind of text |
|---|---|---|---|
| Pre-LOI / indication | Public signals, questionnaire, high-level incident ask, logo verification. | Go / investigate / walk-away recommendation to the deal team — not a legal opinion. | Best practice. |
| Confirmatory (between LOI and close) | Evidence room, control sampling, vuln and SBOM review, certification read-through, undisclosed-incident probe. | Risk memo with residual items and a draft 100-day plan. | Best practice; CSF / ISO / TSC as mapping aids. |
| Integration (post-close) | Identity merge, logging coverage, vuln backlog ownership, retune monitoring. | Named owners and dates. This is operations, not a new diligence fiction. | Best practice / CSF Recover and Identify. |
Certification-verification steps
Read type, period, exceptions, scope statement, legal entity, and expiry. Confirm the report’s systems are the ones you are buying. Last verified 10 September 2026. Not legal advice.
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Staff the three phases with different depth — do not pretend a questionnaire is confirmatory.
- Park reps-and-warranties and breach-disclosure language with counsel. Open the we’ve-been-breached guide if an incident is live.
- Open the cyber checklist and the SRM support page on this site.
- If you already have a session: Passport, evidence overlay, vuln ingest (KEV/EPSS/CVSS, dedup, blast radius), cyber risk register, and questionnaires. Naming signed-in surfaces is not a public href.
Checklist
Question list. Not legal advice.
- Which phase are we actually in?
- Have we read the SOC 2 / ISO artifacts, not the slide?
- Is there a written incident chronology?
- Who owns the 100-day security plan if we close?
Where this shows up in ShipReady Metrics
ShipReady Passport, evidence collection and met-verdict overlay, vulnerability management (KEV, EPSS, CVSS, dedup, blast radius), cyber risk register, and questionnaires. The product does not close a deal and does not draft reps.
Primary sources (last verified 10 September 2026)
NIST CSF 2.0. ISO/IEC 27001:2022. AICPA TSC. ENISA guidance. Breach-notification statutes named only as a class — see the breach-reporting hub for regime pages. Not legal advice.