Technology & Cyber Due Diligence · $500K–$10M Acquisitions

You're buying the technology, too.

The QoE covers the financials. Your attorney covers the contracts. Auditcraft covers the systems, security, and IT dependencies you inherit the day the deal closes — at a fixed price scoped for the deal you're actually doing.

Auditcraft · Findings excerpt Sample — Core Assessment
HIGH All infrastructure knowledge held by one employee

Deal implication: no documentation exists for network, backups, or vendor accounts. Retention agreement recommended before close.

HIGH Core software terminates on change of control

Deal implication: the system running daily operations requires vendor consent to assign. Condition to closing recommended.

MED Server hardware past end-of-life; no refresh budgeted

Deal implication: estimated $38–52K year-one replacement cost not reflected in seller's EBITDA.

LOW Email security controls partially configured

Deal implication: remediable post-close at minimal cost. Included in Day-30 priority list.

Fixed fee — no hourly billing 5–7 business days to delivery Risk-rated findings tied to deal terms NDA standard on every engagement
The gap

Technology is the diligence workstream small-deal buyers skip.

Not because it doesn't matter — because the firms that do it start at $25,000 and are built for private equity. On a $2M deal, that math doesn't work. So the IT environment goes unexamined, and the buyer finds out what they own after they own it.

These are the findings that surface again and again in small acquisitions:

Recurring finding 01

The IT lives in one person's head

Many small businesses run on a network one employee built and never documented. If that person leaves after close — and they often do — you own systems nobody understands, with passwords nobody has.

Recurring finding 02

EBITDA looks great because IT spend stopped years ago

Sellers preparing to exit quietly stop investing in technology. The margins look strong right up until you inherit end-of-life servers, unsupported software, and a six-figure modernization bill in year one.

Recurring finding 03

Software contracts that break when ownership changes

Change-of-control clauses let vendors terminate or reprice the moment the business sells. If the target's core operating software carries one, your revenue depends on a contract that may not survive the deal.

Recurring finding 04

Cyber exposure that transfers to you at close

Shared admin credentials, no MFA, unmonitored remote access, cyber insurance that doesn't carry over. A breach in month two is your breach — at exactly the moment you can least absorb it.

What we assess

A complete picture of the technology you're acquiring.

Every engagement works from the target's documents, a structured seller questionnaire, and a call with whoever runs the IT. Every finding is risk-rated and tied to a deal implication — something you can act on in negotiation, not a technical appendix you have to interpret.

Core + Extended

IT asset & infrastructure inventory

What the business actually runs on — hardware, software, cloud services, and where each stands against end-of-life. Includes estimated year-one replacement costs the seller's numbers don't show.

Core + Extended

Cybersecurity posture

Access controls, credential practices, MFA coverage, backup integrity, remote access exposure, and incident history — assessed against the standards cyber insurers now require.

Core + Extended

Key-person dependency

Who holds the knowledge, what's documented, and what walks out the door if they do. Where dependency is critical, we flag it for retention or transition terms before close.

Core + Extended

Data practices & compliance exposure

What sensitive data the business holds, how it's protected, and what regulatory obligations transfer with it. Healthcare target? Extended includes a HIPAA exposure review.

Extended

Vendor contracts & change-of-control review

Software licenses, managed IT agreements, and SaaS subscriptions reviewed for assignment restrictions, termination triggers, and repricing rights that activate when the business changes hands.

Extended

Post-close priorities: Day 1 / 30 / 90

A sequenced roadmap of what to secure immediately, what to fix in the first month, and what to plan for the first quarter — built from twenty years of integrating acquired companies.

Pricing

Fixed fees, published up front.

Diligence budgets are tight and deal timelines are unforgiving. You shouldn't need a discovery call to learn what an assessment costs.

For straightforward targets

Core Assessment

$2,500

Fixed fee · Delivered in 5 business days

  • IT asset & infrastructure inventory with end-of-life exposure
  • Cybersecurity posture assessment
  • Key-person dependency analysis
  • Data practices & compliance overview
  • Software licensing summary
  • Risk-rated findings with deal implications
Start with Core

Every engagement begins with a signed engagement letter defining scope, deliverables, and timeline before any fee is due. Unusual targets — multi-site operations, heavy custom software — get a scoped quote, still fixed, before you commit.

Process

Built to fit inside your diligence window.

Most engagements run signature-to-report in under two weeks — designed for a 30–60 day exclusivity period where every workstream competes for the same clock.

1

Send the deal profile

Industry, rough size, and your diligence window. An NDA is standard — happy to sign yours or provide ours. You'll have a proposal within one business day.

2

Scope confirmed, engagement signed

Fixed fee, defined deliverables, delivery date in writing. No hourly meters, no scope surprises mid-engagement.

3

Document request goes out

A focused request list and seller questionnaire, built to get what matters without burning your goodwill with the seller. Works alongside your data room.

4

Analysis, plus one call

We review everything submitted and speak with whoever runs the target's IT — usually thirty minutes. No invasive tooling, no disruption to the seller's operation.

5

Report delivered

Risk-rated findings, deal implications, and cost estimates — in language your lender and your attorney can both use. Extended engagements include a walkthrough call with your deal team.

Who's behind this

Operators who've lived the post-close mess this report prevents.

Senior IT and security leadership

Auditcraft assessments are led by senior IT executives with 20+ years running enterprise infrastructure and security — building NIST-based security programs, authoring breach response plans, and integrating acquired companies across three countries.

That last part matters most. We've been the team that inherits the acquisition on Day 1 — the undocumented network, the departed IT manager, the software contract nobody read. This report exists so you see those problems before you own them.

Full credentials are disclosed in every proposal.

Findings, not deal advice

We report what we find and rate the risk. We don't tell you whether to do the deal — that judgment belongs to you and your deal team. What you get is ammunition: findings you can carry into negotiation as price adjustments, escrow holdbacks, closing conditions, and retention terms.

And when the deal is a good one, a clean tech assessment is worth just as much — to you, and to the lender asking what's under the hood.

Common questions

Asked on most first calls.

Will this fit my diligence timeline?

Almost certainly. Core delivers in 5 business days from document receipt, Extended in 7. We're built for buyers mid-exclusivity — if your window is unusually tight, say so in the deal profile and we'll tell you honestly whether we can hit it.

Do you need access to the target's systems?

No. The assessment works from documents, a structured seller questionnaire, and one call with the target's IT contact. Nothing gets installed, nothing touches production systems, and the seller's operation is never disrupted — which also keeps the seller cooperative during a delicate stretch of the deal.

What happens if my deal falls through?

You keep the report and everything in it. Deals die — most buyers work through several LOIs before one closes. Buyers who've used us once tend to come back on the next target, and the second engagement moves faster because we already know how you work.

Is this an audit?

It's an independent assessment — not a CPA attestation, a certification, or a legal opinion. You get documented findings with risk ratings and deal implications, prepared by people who've run the systems they're evaluating. Your attorney and accountant handle their workstreams; this one covers what they don't.

Get started

The findings exist whether you look or not. Look first.

Send the deal profile — industry, size, timeline. Proposal within one business day.