1. Home
  2. Services
  3. Software Audits
  4. Acquisition & Investment Due Diligence
Acquisition & Investment Technical Due Diligence

Is the software behind the deal what you think you are buying?

Technical due diligence gives buyers, investors and their advisors independent evidence about a target's software: whether it is maintainable, what risks could affect future investment and where additional expenditure is likely after completion.

NDA and data-room friendly Aligned to your deal timetable Verified vs. uncertain, stated Written for advisors and boards

What is an Acquisition and Investment Technical Due Diligence?

Technical due diligence is an independent assessment of a target company's software and engineering capability, carried out before an acquisition or investment completes. It informs commercial negotiations, warranties and post-deal planning. It does not value the business; that remains with your financial advisors.

It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.

When to commission one

Situations where this review pays for itself

Buying a business with custom software

The software is part of what you are paying for, and you need to know its condition before completion.

Investing in a software company

Private equity, venture or angel investors validating that the platform matches the pitch.

Acquiring a product or platform

Buying a product line, a customer platform or a codebase as an asset.

Post-deal integration planning

Understanding the engineering work needed to integrate, scale or separate systems after completion.

What we assess

Six areas, each rated for impact and urgency

Architecture & scalability

Whether the platform can support the growth assumptions in the investment case.

Code quality & technical debt

Material debt that will need investment, separated from acceptable compromises.

Security & data protection

Security controls and practices, and where personal data handling needs attention as the business changes hands.

Dependencies & lifecycle

Unsupported frameworks, third-party components and licences that could create cost or risk.

Team & key-person risk

How much depends on a few individuals, and how knowledge is shared and recorded.

Control of technical assets

Repositories, cloud accounts and operational access the business actually controls.

How it works

From scoping to a prioritised plan

Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.

1
Pre-access

NDA & document review

Architecture documents, data-room material and management presentations reviewed first.

Output: Initial question list
2
Early

Technical interviews

Sessions with the target's technical leadership to test claims and understand context.

Output: Interview notes
3
Where permitted

Code & infrastructure review

Deeper assessment of repositories and cloud configuration as the seller allows access.

Output: Evidence log
4
To deadline

Report for decision-makers

Material risks, open questions and their likely operational implications, in time for your decision.

Output: Due diligence report and briefing
What you receive

Clear findings, honest boundaries

  Deliverables

  • Executive summary for the deal team and board
  • Material risks with likely cost and operational implications
  • Red-flag items requiring attention before completion
  • Questions for the seller and areas for warranties, for your advisors to consider
  • Post-completion technical investment priorities
  • Verified findings clearly separated from areas of uncertainty

See how findings are presented in our anonymised sample report.

What this review does not do

  • A software audit does not determine the financial valuation of a business.
  • Legal terms, warranties and valuation remain matters for your professional advisors.
  • Depth depends on the access the seller permits; restricted areas are stated.
Methodology

Aligned with recognised guidance

Recognised technical and regulatory guidance the audit methodology is aligned with
AreaSupporting authorityHow it shapes the audit
Data protection during mergers and acquisitions Data sharing code of practice: due diligence following mergers and acquisitionsUK Information Commissioner's Office Identifies where personal data, its lawful basis and its security arrangements need attention when systems change hands. Legal conclusions remain with your advisors.
Secure development practices and software acquisition Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software.
Application security review and verification Application Security Verification Standard (ASVS)OWASP Foundation Frames application security findings as verifiable requirements across authentication, access control, input handling and data protection, rather than a superficial vulnerability scan.
Cloud reliability, security, cost and operational maturity Azure Well-Architected FrameworkMicrosoft Structures Azure workload assessment around its five pillars: reliability, security, cost optimisation, operational excellence and performance efficiency.

These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.

Confidentiality & evidence handling

Your code, credentials and data, handled with care

An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.

NDA before detail

We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.

Due-diligence questions

Read-only by default

Repository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.

Information security

Evidence handled deliberately

Working copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.

Data residency

Cyber Essentials Plus

Assemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.

Visit the Trust Centre

Where personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.

Frequently asked questions

Acquisition & Investment Due Diligence, answered

Can you work to a deal timetable?

Yes. Scope is agreed against your deadline, and depth is adjusted to the access the seller can provide in the time available. Where time is short, we prioritise the risks most likely to affect the decision.

What if the seller limits access to the code?

That is common early in a process. We start with documents, interviews and demonstrations, then go deeper as access is granted. The report states plainly which conclusions are verified and which remain uncertain.

Do you work with our lawyers and financial advisors?

Yes. We provide the technical evidence and explain its likely operational implications, so your advisors can reflect it in valuation, warranties and contract terms. Those decisions remain with them and with you.

Do you assess platforms that are not built on Microsoft technology?

Our deepest expertise is .NET and Azure. For targets on other stacks we will tell you honestly whether we are the right reviewer for the code itself, while architecture, operational and control findings remain broadly applicable.

Get the technical facts before you commit

Tell us about the transaction, the timetable and what access is likely. We are happy to sign an NDA before receiving any details about the target.

Discuss Your Requirements All Software Audit Services

Cyber Essentials Plus certified  ·  NDA as standard  ·  UK-based team  ·  Microsoft Partner  ·  No obligation to appoint us for remediation

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor