Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What belongs on a technology due diligence checklist?
Last verifiedA technology due diligence checklist covers architecture, code quality, security, scalability, IP and licensing, team, and operations — sized to maturity. It is a preparation aid, not a pass/fail score. This page is not legal advice and not investment advice.
Technology due diligence checklist, last verified 10 September 2026 against ISO/IEC 25010 quality characteristics, OWASP ASVS, NIST CSF 2.0, and SPDX / OpenChain license practice. Institutional-investor diligence outlines are cited descriptively, not as a ranking. Not legal advice. Not investment advice.
A checklist, not a valuation
Audience: a CTO or founder facing a fundraise or sale. This page is not legal advice and not investment advice. Kind of text: ISO/IEC 25010 is a quality model (standard). OWASP ASVS is a community standard. NIST CSF 2.0 is a framework (guidance). SPDX and OpenChain (ISO/IEC 5230) are license/compliance practice. None of them determines that a deal should close. ShipReady Metrics recommendation: share a ShipReady Passport and readiness score as posture, not as a fairness opinion.
Categorized checklist (the core deliverable)
Print or copy this table into the data room. Last verified 10 September 2026. Not legal advice. Not investment advice.
| Category | Ask for | Kind of text |
|---|---|---|
| Architecture | System context, trust boundaries, tenancy model, recovery objectives, documented single points of failure. | ISO/IEC 25010 reliability / maintainability; industry practice. |
| Code quality | Languages, CI quality gates, test strategy, known hotspots, AI-authored-code share if measured. | ISO/IEC 25010; DORA research as metrics practice. |
| Security | Control coverage, vuln posture (KEV/EPSS/CVSS), last independent test, incident history. Open the cyber checklist on this site. | NIST CSF 2.0 / OWASP ASVS — framework and community standard, not YOUR mandate. |
| Scalability | Capacity story, load-test evidence, cost-to-serve, multi-region facts (not slides). | ISO/IEC 25010 performance efficiency; industry practice. |
| IP and licensing | SBOM, license inventory, assignment agreements, inbound OSS policy. Open the OSS-risk page on this site. | SPDX / OpenChain practice — not legal advice on a license. |
| Team | Org chart, bus-factor, on-call, contractor mix, key-person agreements. | Industry practice; not employment-law advice. |
| Operations | Change, incident, backup, observability, customer commitments (uptime exhibits). | NIST CSF 2.0 Identify / Protect / Detect / Respond / Recover — guidance. |
Maturity-stage table
Expectations scale. A seed company that fabricates an enterprise packet is a red flag; a late-stage company with no SBOM is a different red flag. Last verified 10 September 2026. Not investment advice.
| Area | Seed | Growth | Late-stage / pre-exit |
|---|---|---|---|
| Architecture pack | One current diagram and a verbal tenancy story. | Versioned diagrams, DR notes, known debt. | Reviewed architecture decision records and measured recovery tests. |
| Security evidence | MFA, backup, vuln ingest on; no fake ISO logo. | Mapped controls, recent test or documented alternative. | Attestation or certification with scope and dates verified. |
| Metrics | Honest deploy and incident anecdotes. | DORA-style measures with denominators. | Board-ready readiness report with coverage-as-confidence. |
| IP / OSS | Assignment hygiene and a lockfile. | SBOM plus license exceptions list. | OpenChain-style process and counsel review of copyleft. |
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice. Not investment advice.
- Copy the categorized table into the data room and mark each row present / missing / not applicable with a reason.
- Do not pad seed-stage gaps with logos you have not earned.
- Open the prepare-for-diligence and readiness-report guides on this site for the 90/60/30 sequence.
- If you already have a session: signed-in app → Compliance → Evidence and the readiness score (A–E) are the posture pack. Passport is shareable posture, not a valuation.
Checklist
Packing-list reminder. Not a deal recommendation. Not legal advice.
- Seven categories populated or explicitly N/A?
- Maturity-stage row matches how you actually operate?
- Security and debt deep-dives linked, not duplicated poorly?
- Any statistic in the pack has a denominator and a date?
Where this shows up in ShipReady Metrics
ShipReady Passport (shareable posture), readiness score with A–E ratings, evidence collection, and DORA engineering metrics. The product does not value the company, does not give investment advice, and does not determine that a framework applies to YOU.
Primary sources (last verified 10 September 2026)
ISO/IEC 25010. OWASP ASVS. NIST CSF 2.0. SPDX License List and OpenChain (ISO/IEC 5230). Institutional diligence outlines cited only as a descriptive genre, not ranked. Not legal advice. Not investment advice.