UK-based • Supporting growing and regulated organisations

M&A / IT Due Diligence

IT Due Diligence Checklist for Acquisitions

Technology due diligence should identify operational risk, hidden cost and integration complexity before they become post-transaction surprises.

1. Technology estate

Document locations, networks, servers, cloud platforms, end-user devices, major applications, support arrangements and infrastructure dependencies. Identify unsupported or end-of-life technology.

2. Cybersecurity and identity

Review identity architecture, MFA, privileged access, endpoint controls, vulnerabilities, incident history, security monitoring, policies and material third-party risks.

3. Applications and licences

Identify critical business systems, ownership, integrations, renewal dates, licence restrictions, support status and whether applications can be transferred or separated after the transaction.

4. Data and compliance

Understand where important data resides, applicable regulatory requirements, retention obligations, privacy risks, backup arrangements and any material audit findings.

5. People, suppliers and contracts

Review key-person dependencies, outsourced support, supplier concentration, contract terms, notice periods, service levels and costs that may change after ownership or separation.

6. Integration and separation cost

Estimate work required for identity, email, networks, applications, licences, data migration, cybersecurity, support and transitional-service arrangements. A low purchase price can still hide significant technology remediation cost.

Choose your next step

Use the guidance in the way that suits you.

EaseThat can provide independent IT due diligence and a prioritised post-transaction technology roadmap.

Direct PDF download - no registration or email address required.