IT Due Diligence for Small Business Acquisitions
Send our IT Due Diligence Discovery Questionnaire to the target company, or fill in what you already know. We turn the answers into a written summary of the technology risk in the deal and a 30-day plan for after close. Both are free.
Already under LOI or post-close? See our post-close IT support for operators.
IT risk is cheap to find before close and expensive to find after
A target company can look healthy on the surface and still carry avoidable technology debt. Aging hardware, undocumented networking, messy Microsoft 365 administration, unsupported line-of-business software, and an overlooked phone system all turn into cost and disruption in the first year.
Technology due diligence gives you the facts early enough to act on them. One buyer we worked with learned during diligence that every laptop and PC in the business needed replacement. That was tens of thousands of dollars, and it became part of the price conversation with the seller.
What this questionnaire is built to surface
Current-state Environment
See what the business actually depends on today.
Document the basics of the environment, including sites, users, connectivity, hardware, cloud or virtualization choices, software, networking, voice, directory, email, and business-critical dependencies.
Resilience and Support Gaps
Find where continuity may be weaker than it looks.
Understand backup approach, offsite backup, firewalls, VPN usage, MDM, antivirus, spam filtering, DR planning, and whether the business has policies and documentation in place.
Near-term Cost Drivers
Spot what may turn into spend soon after close.
Spot where replacement, standardization, licensing cleanup, roadmap work, or vendor changes may be needed soon after close.
What the IT due diligence questionnaire covers
The questionnaire is a full technology review, not only a security review. It covers cybersecurity exposure and everything the business runs on day to day, because both create cost for a new owner. It works through the environment category by category:
- sites, users, and connectivity
- server and end-user hardware
- virtualization and cloud services
- proprietary software and platform requirements
- antivirus, spam filtering, and MDM
- storage, backup tools, backup targets, and offsite backup
- networking, firewalls, wireless, VPN, topology, and VLANs
- phone and communications setup
- Active Directory and group policy
- Microsoft 365, Exchange, DNS, and mailbox environment
- business dependencies such as compliance, employee IT policy, disaster recovery, and roadmap
Why that matters in diligence
You inherit the architecture decisions, the vendor contracts, the aging equipment, the backup practices, and the licensing choices. Gather those facts early enough to act on them.
Get the IT Due Diligence Discovery Questionnaire
Send the questionnaire to the target company or the seller's IT provider, fill in whatever you already know, and send us the answers.
We map those answers into a written report on the technology risk factors in the deal, ranked so you can see what matters now against what can wait. Some of what surfaces is cost savings rather than risk. You also get a 30-day plan for the period right after close.
Buyers can use the output several ways. Some take significant findings into price discussions with the seller. Others use it to budget the first year accurately. There is no cost for any of it.
What ETA searchers are usually trying to understand
Infrastructure Condition
How many servers exist, what platform they run on, how old they are, whether hardware will need replacement, and how standardized the environment really is.
Cloud & Software Dependencies
Which applications and cloud services are in use, what versions they run, which vendors support them, and whether there are proprietary or operational dependencies that need to be maintained.
Backup & Network Resilience
How backup is handled, whether offsite protection exists, what firewalls and VPN practices are in place, and whether the network is documented and segmented.
Business & Governance Risk
Whether the business has compliance requirements, retention policies, employee IT policies, a disaster recovery plan, and any current technology roadmap.
Hear the ETA perspective behind this questionnaire
Nick joins Ryan Condie on Let's Buy a Business to walk through the cybersecurity problems buyers find in diligence and inherit after close.
Frequently Asked Questions
IT due diligence is the process of reviewing a target company's technology environment before an acquisition closes. It establishes what the business runs on, where the environment is weak, and what technology spend the buyer should expect in the first year of ownership. It covers infrastructure, software, networking, communications, Microsoft 365, backup, and security.
Our IT Due Diligence Discovery Questionnaire is that tool. It works through the target environment category by category, covering sites and users, hardware, cloud services, line-of-business software, storage and backup, networking, phone systems, directory and Microsoft 365, and governance items like compliance requirements, data retention, employee IT policy, and disaster recovery planning. We structured it as a questionnaire because the practical use is handing it to the seller or the seller's IT provider and getting answers back.
Most buyers send it directly to the seller or the seller's IT provider and fill in whatever they already know themselves. Either approach works. Partial answers are still useful, and a question the seller cannot answer is itself a finding worth noting.
A written report mapping the answers to the technology risk factors in the deal, ranked so you can separate what needs attention now from what can wait. It includes cost drivers as well as risks, and a 30-day plan for the period right after close. There is no charge.
Common findings include aging servers and end-of-life firewalls, inconsistent hardware standards, undocumented networks, backups that have never been restore-tested, shared or reused administrator credentials, Microsoft licensing shared across multiple people, and missing disaster recovery planning. We have found business passwords stored in an employee's personal Gmail account and, in another deal, written on paper in the break room. Each of these becomes post-close cost or cleanup if nobody finds it before signing.
The technology environment affects continuity, support burden, future spend, and how quickly the business stabilizes after close. Finding problems before signing gives you options: price them into the deal, plan the first 90 days around them, or walk away. Finding them after close leaves only the third option gone.
Cybersecurity due diligence looks at exposure: identity, endpoints, email, and whether the business could survive an incident. IT due diligence covers that and adds everything the business runs on day to day, including hardware lifecycle, software licensing, vendor contracts, network documentation, and communications. Security gaps create risk you inherit. Infrastructure gaps create spend you did not budget.
Establish the IT baseline before you close
Send the questionnaire to your target, get back a written view of the technology risk in the deal, and start the first 30 days with a plan instead of a surprise.