Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What belongs on a technology due diligence checklist?

Last verified

A technology due diligence checklist covers architecture, code quality, security, scalability, IP and licensing, team, and operations — sized to maturity. It is a preparation aid, not a pass/fail score. This page is not legal advice and not investment advice.

Technology due diligence checklist, last verified 10 September 2026 against ISO/IEC 25010 quality characteristics, OWASP ASVS, NIST CSF 2.0, and SPDX / OpenChain license practice. Institutional-investor diligence outlines are cited descriptively, not as a ranking. Not legal advice. Not investment advice.

A checklist, not a valuation

Audience: a CTO or founder facing a fundraise or sale. This page is not legal advice and not investment advice. Kind of text: ISO/IEC 25010 is a quality model (standard). OWASP ASVS is a community standard. NIST CSF 2.0 is a framework (guidance). SPDX and OpenChain (ISO/IEC 5230) are license/compliance practice. None of them determines that a deal should close. ShipReady Metrics recommendation: share a ShipReady Passport and readiness score as posture, not as a fairness opinion.

Categorized checklist (the core deliverable)

Print or copy this table into the data room. Last verified 10 September 2026. Not legal advice. Not investment advice.

Technology due diligence checklist by category (printable aid; not a pass/fail; not legal or investment advice)
CategoryAsk forKind of text
ArchitectureSystem context, trust boundaries, tenancy model, recovery objectives, documented single points of failure.ISO/IEC 25010 reliability / maintainability; industry practice.
Code qualityLanguages, CI quality gates, test strategy, known hotspots, AI-authored-code share if measured.ISO/IEC 25010; DORA research as metrics practice.
SecurityControl coverage, vuln posture (KEV/EPSS/CVSS), last independent test, incident history. Open the cyber checklist on this site.NIST CSF 2.0 / OWASP ASVS — framework and community standard, not YOUR mandate.
ScalabilityCapacity story, load-test evidence, cost-to-serve, multi-region facts (not slides).ISO/IEC 25010 performance efficiency; industry practice.
IP and licensingSBOM, license inventory, assignment agreements, inbound OSS policy. Open the OSS-risk page on this site.SPDX / OpenChain practice — not legal advice on a license.
TeamOrg chart, bus-factor, on-call, contractor mix, key-person agreements.Industry practice; not employment-law advice.
OperationsChange, incident, backup, observability, customer commitments (uptime exhibits).NIST CSF 2.0 Identify / Protect / Detect / Respond / Recover — guidance.

Maturity-stage table

Expectations scale. A seed company that fabricates an enterprise packet is a red flag; a late-stage company with no SBOM is a different red flag. Last verified 10 September 2026. Not investment advice.

Seed vs growth vs late-stage expectations (descriptive; not a scoring model; not investment advice)
AreaSeedGrowthLate-stage / pre-exit
Architecture packOne current diagram and a verbal tenancy story.Versioned diagrams, DR notes, known debt.Reviewed architecture decision records and measured recovery tests.
Security evidenceMFA, backup, vuln ingest on; no fake ISO logo.Mapped controls, recent test or documented alternative.Attestation or certification with scope and dates verified.
MetricsHonest deploy and incident anecdotes.DORA-style measures with denominators.Board-ready readiness report with coverage-as-confidence.
IP / OSSAssignment hygiene and a lockfile.SBOM plus license exceptions list.OpenChain-style process and counsel review of copyleft.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice. Not investment advice.

  • Copy the categorized table into the data room and mark each row present / missing / not applicable with a reason.
  • Do not pad seed-stage gaps with logos you have not earned.
  • Open the prepare-for-diligence and readiness-report guides on this site for the 90/60/30 sequence.
  • If you already have a session: signed-in app → Compliance → Evidence and the readiness score (A–E) are the posture pack. Passport is shareable posture, not a valuation.

Checklist

Packing-list reminder. Not a deal recommendation. Not legal advice.

  • Seven categories populated or explicitly N/A?
  • Maturity-stage row matches how you actually operate?
  • Security and debt deep-dives linked, not duplicated poorly?
  • Any statistic in the pack has a denominator and a date?

Where this shows up in ShipReady Metrics

ShipReady Passport (shareable posture), readiness score with A–E ratings, evidence collection, and DORA engineering metrics. The product does not value the company, does not give investment advice, and does not determine that a framework applies to YOU.

Primary sources (last verified 10 September 2026)

ISO/IEC 25010. OWASP ASVS. NIST CSF 2.0. SPDX License List and OpenChain (ISO/IEC 5230). Institutional diligence outlines cited only as a descriptive genre, not ranked. Not legal advice. Not investment advice.

Frequently asked questions