What the target’s technology actually is, in writing, by someone independent of the deal.
You are about to commit to an investment, acquisition, or merger. The seller has shown you what they want you to see. Their team will tell you what they have always told their own leadership. What you need — and what you cannot get from inside the deal — is an independent reading of the target’s technology, written for the people deciding whether to sign.
That is what this engagement is.
€30,000. Two to four weeks. Delivered in writing, with a presentation to the deal committee.
Fixed fee. Not paid on whether the deal closes. Independent of buyer and seller. Extended scope — regulated targets, multi-entity groups, post-deal integration — quoted separately.

Why clients commission a review
Technology due diligence is commissioned in specific moments. Most often, one of these:
- An investor is preparing to commit €2m or more to a software-dependent business.
- A buyer is evaluating an acquisition where the target’s technology is material to deal value.
- A board is preparing to sell and wants to know what the buyer will find — before they find it.
- A lender is financing a transaction and needs an independent view of the technology risk.
- A management team is preparing investment-committee papers that require a written technology assessment.
- A previous due diligence report has surfaced concerns that warrant an independent second view.
- A vendor due diligence process needs a credible technology view to anticipate buyer questions.
- A regulatory or major-customer condition requires evidence of technology resilience before the deal closes.
If one of these is the position you are in, the engagement is built for it.
Who this is for
Private equity, venture, and family-office investors preparing to invest in software-enabled or technology-dependent businesses.
Strategic and financial acquirers evaluating M&A transactions where technology is material to deal value.
Boards and management teams preparing for a sale, recapitalisation, or significant external investment, who want to anticipate what the buyer will surface.
Lenders and credit committees financing transactions where technology risk affects covenants or repayment.
Who this is not for
Founders and operators seeking an independent reading of their own technology. That work is an Architecture Review, not a due diligence engagement.
Pre-deal exploratory work where no transaction has been identified. This is a deal-driven engagement; without a deal, the framing does not apply.
Targets where the technology fits on one page — generally under 25 staff or under €5m revenue. The engagement scope exceeds what the target’s complexity warrants.
Cyber-only assessments. Security architecture is in scope; specialist penetration testing and red-team exercises are a separate engagement, run by specialist firms.
What you receive
The engagement tells you three things in writing: what the target’s technology is, what about it should move the deal, and what it will cost to address after. Five artefacts, delivered together, written for a deal committee.

A red-flag summary. The deal-stopping or price-affecting issues, surfaced in the first week. Delivered before the deeper work is complete, so the deal team can decide whether to continue, renegotiate, or step away.
A current-state assessment. What the target’s technology is. Major systems, how they fit together, what they do well, where they are exposed. Written for the deal committee — financial readers, not engineers.
A risk register sorted by deal impact. Every material technology risk identified, ranked by what it does to the deal. Operational, key-person, vendor, regulatory, cyber, and integration. Each entry priced in deal terms: what it should do to the valuation, and what it will cost to address post-deal.
A dependency and vendor map. The integrations, vendors, libraries, and external services the target relies on. Single points of failure identified. Concentration risk and contract-renewal exposure named.
A deal-committee presentation. A two-hour session with the deal committee, the investor’s operating partners, or the buyer’s leadership. Findings presented, challenged, and discussed. Questions answered with reference to the underlying evidence.
Typical outcomes
Most engagements result in one of four conclusions.
The technology supports the deal as priced. Material risks are identified but manageable. No material renegotiation indicated.
The technology supports the deal with adjustments. Specific risks merit price adjustment, warranties, or escrow. The deliverables name what and how much.
The technology will require significant post-deal investment. The deal can proceed, but the buyer should price in twelve to twenty-four months of remediation work and the resources to do it.
The technology surfaces deal-stopping concerns. Issues identified during the review go to the heart of the target’s value or operability. The buyer should renegotiate substantially or step away.
The engagement tells you which of these the target is in, and what follows from it.
How the engagement runs
Two to four weeks, depending on the target’s size and complexity. Four phases.
Phase one — access and inventory. Data room review. NDA-bound interviews with the target’s technology lead. Vendor contract review. Where the data room has gaps, we identify them.
Phase two — deeper interviews. Senior engineers. Operations team. Key vendors where relevant and access permits.
Phase three — synthesis and red-flag surfacing. Red flags surfaced to the deal team early — typically by end of week two, not week four. So you can decide whether to continue before the deeper work is done.
Phase four — presentation. The deal-committee session, scheduled around the deal timetable. Revisions if anything in the report needs tightening for the closing papers.
Everything is written before it is presented. Nothing reaches the deal committee that the engagement lead has not signed off.
What this is not
Financial due diligence. We assess the technology; we do not value the business or audit the financials.
Commercial due diligence. We assess what the technology does; we do not assess the market opportunity or customer base.
Legal due diligence. We identify regulatory exposure; we do not provide legal opinion.
Post-deal remediation. We identify and price; we do not implement. For the work that follows, see Build & Oversee or Fractional CTO.
A penetration test or red-team exercise. Security architecture is in scope; offensive testing is a specialist engagement, run by firms who do nothing else.
Technology due diligence is not a check-the-box exercise. It is an input to a specific decision: should this deal proceed, at what price, with what conditions, and what happens after.
The purpose of the engagement is not to find every flaw. It is to surface what the deal committee needs to know — the issues that move price, change terms, or stop the deal — and to do so in writing, before the deadline.
Proof
References available on request, subject to NDA and prior-client permission. Anonymised excerpts from prior diligence reports available on request.
What happens next
Start a ConversationThirty minutes. We confirm fit, scope, timing, and confidentiality. You decide whether to proceed. No proposal is sent unless you ask for one.
Start with a Pre-LOI Red Flag Review — €4,950A focused, three-to-five-day technology scan for buyers at the pre-LOI stage. Surfaces deal-stopping risks before the full diligence process commits. The right starting point if the deal is still being evaluated.
For post-deal integration and ongoing technology oversight, see Build & Oversee or Fractional CTO.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.