Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do you assess technical debt in an M&A deal?

Last verified

Assess technical debt by type — quality, architecture, operational, and knowledge — then estimate remediation as a ranged cost with assumptions. Do not treat one metric as a verdict. This page is not investment advice and not legal advice.

Technical-debt assessment for M&A, last verified 10 September 2026 against ISO/IEC 25010, SEI/CMU technical-debt research (cited descriptively), and DORA research. Indicators are measurable; judgment still applies. Not investment advice. Not legal advice.

Debt is a portfolio, not a smell score

Audience: an acquirer or portfolio CTO. This page is not investment advice and not legal advice. Kind of text: ISO/IEC 25010 is a quality model. SEI/CMU papers are research. DORA reports are research / industry practice. None of them prices YOUR deal. ShipReady Metrics recommendation: combine DORA, A–E readiness, SAST signals, and per-committer metering — never a single number.

Technical-debt taxonomy

Last verified 10 September 2026. Not a complete academic taxonomy. Not investment advice.

Debt taxonomy for walkthroughs (descriptive; not a valuation model)
TypeWhat you are looking atExample indicator
Quality / codeComplexity, duplication, missing tests in hot paths.SAST hotspots + test coverage on changed lines (coverage-as-confidence).
ArchitectureUnowned shared kernels, impossible tenancy, hard-coded single-region.Decision records vs the running system.
OperationalManual deploys, no restore test, pager without runbooks.DORA restore time and change-fail, if defined honestly.
Knowledge / key-personOnly one person can ship a subsystem.Bus-factor count — still qualitative around the count.

Worked quantification example

Illustrative only — not YOUR numbers and not a quote. Suppose confirmatory review finds: (1) one payments service with no automated restore test, (2) a module that four product lines import and only one engineer understands, (3) a SAST cluster of injection findings on that module. A defensible memo estimates two streams: a 6–10 engineer-week hardening and test-enablement stream, and a 3–6 engineer-week knowledge-transfer stream, plus a contingency band if the shared module must be split. State the assumptions (team cost, parallelism, whether you pause feature work). Do not publish a single “debt equals X dollars” headline. Last verified 10 September 2026. Not investment advice.

Debt walkthrough checklist

Use on a shared screen with the target’s tech lead. Not a verdict. Not legal advice.

  • Which systems are in the deal perimeter?
  • For each taxonomy row, what is evidenced vs anecdotal?
  • What happens to customers if that debt is untouched for 12 months?
  • What is the ranged spend, the assumptions, and what would falsify them?

What to do now

Operational steps. Last verified 10 September 2026. Not investment advice.

  • Run the taxonomy before you open a spreadsheet of story points.
  • Write the worked-example style memo with ranges and assumptions.
  • Open the PE-firms, investors, and readiness-report pages on this site so the memo has a home.
  • If you already have a session: DORA, A–E ratings, SAST signals, and per-committer metering are inputs — not the verdict.

Checklist

Question list. Not investment advice.

  • Did we avoid a single-metric headline?
  • Are quality, architecture, operations, and knowledge all represented?
  • Is every dollar figure a range with assumptions?
  • Would the target’s tech lead recognize the system in the memo?

Where this shows up in ShipReady Metrics

DORA engineering metrics, readiness score and A–E ratings, code-scanning / SAST signals, and per-committer metering. The product does not compute a debt valuation and does not give investment advice.

Primary sources (last verified 10 September 2026)

ISO/IEC 25010. SEI/CMU technical-debt research (descriptive). DORA research. Not investment advice.

Frequently asked questions