Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do you run security due diligence before an acquisition?

Last verified

Acquisition security diligence runs in phases — pre-LOI scoping, confirmatory evidence, then integration and remediation — so inherited risk is priced before close. Verify certifications by scope and date. Reps and warranties are counsel’s work. This page is not legal advice.

Security diligence before acquisition, last verified 10 September 2026 against NIST CSF 2.0, ISO/IEC 27001:2022, AICPA TSC, ENISA guidance, and breach-notification statutes referenced only descriptively. Those statutes are legal requirements if they apply — this page does not apply them to YOU and does not start a clock. Not legal advice. Not investment advice.

Inherited risk is the product you are also buying

Audience: an acquiring CISO or corp-dev lead. This page is not legal advice and not investment advice. Kind of text: NIST CSF 2.0, ISO/IEC 27001, and TSC are frameworks / standards / criteria as labeled on the cyber checklist. Breach-notification duties (GDPR, US state laws, others) are legal requirements only if they apply — last verified descriptively on 10 September 2026; open the breach-reporting hub for regime pages. Reps, warranties, and indemnity are legal territory.

Diligence-phase timeline

Last verified 10 September 2026. Phases overlap. This page does not start a deal clock. Not legal advice.

Pre-LOI → confirmatory → integration (operational phases; not YOUR deal calendar; not legal advice)
PhaseSecurity workTypical outputsKind of text
Pre-LOI / indicationPublic signals, questionnaire, high-level incident ask, logo verification.Go / investigate / walk-away recommendation to the deal team — not a legal opinion.Best practice.
Confirmatory (between LOI and close)Evidence room, control sampling, vuln and SBOM review, certification read-through, undisclosed-incident probe.Risk memo with residual items and a draft 100-day plan.Best practice; CSF / ISO / TSC as mapping aids.
Integration (post-close)Identity merge, logging coverage, vuln backlog ownership, retune monitoring.Named owners and dates. This is operations, not a new diligence fiction.Best practice / CSF Recover and Identify.

Certification-verification steps

Read type, period, exceptions, scope statement, legal entity, and expiry. Confirm the report’s systems are the ones you are buying. Last verified 10 September 2026. Not legal advice.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice.

  • Staff the three phases with different depth — do not pretend a questionnaire is confirmatory.
  • Park reps-and-warranties and breach-disclosure language with counsel. Open the we’ve-been-breached guide if an incident is live.
  • Open the cyber checklist and the SRM support page on this site.
  • If you already have a session: Passport, evidence overlay, vuln ingest (KEV/EPSS/CVSS, dedup, blast radius), cyber risk register, and questionnaires. Naming signed-in surfaces is not a public href.

Checklist

Question list. Not legal advice.

  • Which phase are we actually in?
  • Have we read the SOC 2 / ISO artifacts, not the slide?
  • Is there a written incident chronology?
  • Who owns the 100-day security plan if we close?

Where this shows up in ShipReady Metrics

ShipReady Passport, evidence collection and met-verdict overlay, vulnerability management (KEV, EPSS, CVSS, dedup, blast radius), cyber risk register, and questionnaires. The product does not close a deal and does not draft reps.

Primary sources (last verified 10 September 2026)

NIST CSF 2.0. ISO/IEC 27001:2022. AICPA TSC. ENISA guidance. Breach-notification statutes named only as a class — see the breach-reporting hub for regime pages. Not legal advice.

Frequently asked questions