1. Home
  2. Services
  3. Software Audits
  4. .NET Code & Architecture
.NET Code & Architecture Audit

Software that works today is not the same as software you can safely change tomorrow.

An independent .NET code audit and software architecture review examines how a C# application is really built: its structure, dependencies, error handling, tests and engineering practices. You get evidence-based findings, ranked by business impact, from engineers who build and support .NET systems for a living.

.NET Framework to .NET 10 Read-only access NDA as standard Findings ranked by impact

What is a .NET Code and Architecture Audit?

A .NET code audit is a structured, evidence-based review of a C# codebase and the architecture around it. It answers a practical question: could a competent engineering team maintain, extend and secure this application at a reasonable cost? It covers ASP.NET, ASP.NET Core, Blazor, Web API, WinForms, WPF, worker services and the SQL Server or Azure data stores behind them.

It is part of Assemblysoft's software audit and technical due diligence practice and can run on its own or as part of a comprehensive audit.

When to commission one

Situations where this review pays for itself

Changes are slow and risky

Every release breaks something else, estimates keep growing, and nobody can explain why simple features take weeks.

Checking a supplier's work

An independent view of what an agency or contractor has delivered, at a milestone, at sign-off, or before a renewal.

Before a new team takes over

Establish whether another team can realistically understand, build and extend the code before you change supplier.

AI-assisted or rushed code

Code produced quickly, by AI tools or under deadline pressure, that now carries real users and real data.

What we assess

Six areas, each rated for impact and urgency

Architecture & structure

Layering, separation of concerns, coupling, domain boundaries and whether the design matches what the business now needs.

Code quality & technical debt

Duplication, complexity hot-spots, dead code, naming and consistency, with material debt separated from cosmetic issues.

Dependencies & lifecycle

NuGet and npm packages, framework versions, end-of-support components and known vulnerable libraries.

Tests & build reproducibility

What is tested and what is not, whether the solution builds cleanly from source, and how reliable the tests are.

Error handling & observability

Exception handling, logging, telemetry and whether failures are visible before users report them.

Security in code

Authentication, authorisation, input validation, secrets handling and data access patterns, framed against OWASP ASVS requirements.

How it works

From scoping to a prioritised plan

Scope, access and timescales are agreed before work begins. Anything that could affect a live environment is agreed separately and controlled.

1
Day 1

Scope & access

We agree the question the audit must answer, the repositories in scope and read-only access arrangements.

Output: Scope note and access checklist
2
Days 2+

Automated & manual review

Static analysis, dependency and vulnerability scanning, then senior engineers read the code that matters most to the business.

Output: Evidence log
3
Where agreed

Build validation

We attempt a clean build and test run from source, the strongest evidence of whether a new team could take over.

Output: Build reproducibility result
4
Final week

Report & walkthrough

Findings ranked by impact and effort, with recommendations and a walkthrough for technical and non-technical stakeholders.

Output: Report, risk register, roadmap
What you receive

Clear findings, honest boundaries

  Deliverables

  • Executive summary in business language
  • Architecture overview reconstructed from the code
  • Findings with evidence, impact, severity and recommended action
  • Dependency and end-of-support inventory
  • Technical debt register ranked by business impact and effort
  • Prioritised remediation roadmap with indicative effort ranges
  • Clear statement of what could not be verified

See how findings are presented in our anonymised sample report.

What this review does not do

  • It cannot guarantee defect-free software or find every bug.
  • It is not a penetration test; where deeper security assurance is needed we will say so.
  • Effort ranges are indicative; detailed estimates may need further discovery.
Methodology

Aligned with recognised guidance

Recognised technical and regulatory guidance the audit methodology is aligned with
AreaSupporting authorityHow it shapes the audit
Application security review and verification Application Security Verification Standard (ASVS)OWASP Foundation Frames application security findings as verifiable requirements across authentication, access control, input handling and data protection, rather than a superficial vulnerability scan.
Secure development practices and software acquisition Secure Software Development Framework (SSDF), NIST SP 800-218US National Institute of Standards and Technology Gives a vendor-neutral vocabulary for judging whether software was produced with secure development practices, and explicitly supports using those practices when acquiring software.

These references support the audit methodology and its boundaries. They describe what a properly scoped audit can assess; they are not a claim that any particular client's systems have already been verified, and alignment with a framework is not a certification.

Confidentiality & evidence handling

Your code, credentials and data, handled with care

An audit means trusting an outside team with source code, infrastructure and sometimes personal data. Here is how access and evidence are controlled. Certification describes how we run our own business; it does not, on its own, guarantee the security of a client's application.

NDA before detail

We sign your NDA or provide ours before receiving anything confidential, including the identity of an acquisition target.

Due-diligence questions

Read-only by default

Repository and cloud access at the least privilege needed, time-limited and revoked at the end. Anything that could affect a live system is agreed separately.

Information security

Evidence handled deliberately

Working copies are held only as long as the engagement needs, production data is avoided wherever possible, and evidence is returned or deleted on completion.

Data residency

Cyber Essentials Plus

Assemblysoft holds Cyber Essentials Plus, independently audited. Our policies, insurance and certificates are published in the Trust Centre.

Visit the Trust Centre

Where personal data is in scope, a UK GDPR Article 28 Data Processing Agreement applies. Reports are confidential to you and shared only with the people you name, such as your advisors or board.

Frequently asked questions

.NET Code & Architecture, answered

Which .NET versions and application types can you audit?

.NET Framework 2.0 to 4.8.1 and modern .NET up to .NET 10, including ASP.NET Web Forms, MVC, ASP.NET Core, Blazor, Web API, WCF, WinForms, WPF, .NET MAUI, worker services and Azure Functions, together with SQL Server and Azure data stores.

Do you rely on automated tools?

Automated analysis is used to cover breadth quickly: static analysis, dependency and vulnerability scanning, complexity metrics. AI-assisted tools help us map unfamiliar code faster. Every material finding is verified by a senior engineer before it reaches the report, because tools produce false positives and miss context.

Will you change our code during the audit?

No. The audit uses read-only access. Where a build or test run is useful as evidence, it happens in an isolated environment and is agreed in advance.

Can you audit code written with AI tools?

Yes. AI-generated code is assessed in exactly the same way as hand-written code, with particular attention to security, validation, duplicated logic and missing tests. If it needs stabilising, see our vibe coding rescue service.

How much does a .NET code audit cost?

It depends on the size of the codebase, the number of systems and the depth required, so we scope it first and confirm the price before work starts. Our day rates are published on the rate card.

Find out what your codebase is really like

Tell us which application, what decision is riding on it and how much access you can provide. We will scope a proportionate audit and confirm timescales before any work begins.

Discuss Your Requirements All Software Audit Services

Cyber Essentials Plus certified  ·  NDA as standard  ·  UK-based team  ·  Microsoft Partner  ·  No obligation to appoint us for remediation

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor