The Technology Due Diligence Report: What Good Looks Like
A diligence report serves four readers. Severity mapped to money, findings that survive challenge, reliance letters, and how to read a vendor report.
One Document, Four Readers
The four readers are not different audiences for the same content. They are different uses of the same facts, and a report that does not separate them physically will fail at least three of them.
| Reader | Decision | Will actually read | Needs |
| Deal partner | Bid, re-trade, or walk | One page | Thesis risks, the number, recommended terms |
| Investment committee | Approve the recommendation | Five to fifteen pages | Finding, evidence, consequence, mitigation |
| Portfolio CTO | Execute | All of it, repeatedly | Inventory, dependencies, sequenced work packages |
| Lender or co-investor | Extend credit or capital | Executive section plus scope | Reliance, scope boundaries, liability position |
The Deal Partner Needs One Page
Assume the deal partner reads one page, on a phone, twenty minutes before the call. Design for that and the report gets better for everyone.
That page contains three things and nothing else.
The thesis risks. Named against the investment thesis, not against a control framework. If the thesis is four bolt-on acquisitions consolidated onto one platform with six hundred basis points of margin expansion, the thesis risk is whether those platforms can be consolidated, at what cost, over how many months, and what breaks if the timeline slips two quarters. A finding that does not touch the thesis does not belong on page one, however severe it looks in a control matrix.
The number. Total identified remediation and normalization cost, split three ways: required before close, year one, and years two to three. Each with a stated confidence and a stated method. A single blended figure with no method is worthless in an investment committee because the first question will be how it was built, and there is no recovering from not knowing.
The recommended terms. Which findings are a price adjustment, which are an escrow, which are a specific indemnity, which are closing conditions, and which are accepted and funded in the plan. This is the part that converts diligence into deal outcomes, and it is covered in detail in Turning Diligence Findings Into Deal Terms.
What page one must not contain: a maturity score, a framework reference, a CVSS number, a vendor product name, or the word "posture." If the deal partner has to reach page forty to know whether to bid, page one has failed.
The Investment Committee Needs Findings That Survive Challenge
An investment committee is not an audience to be persuaded. It is a mechanism for testing a recommendation by attacking it. Write for the attack.
Every material finding in the committee section carries four elements: the finding, the evidence, the business consequence, and the mitigation. The evidence element is the one most reports fail, and it fails in a specific and recognizable way.
Weak: "Multi-factor authentication is not consistently applied across the environment." Strong: "Review of Entra ID sign-in logs for 1 June to 31 August 2026 identified 214 accounts with administrative role assignments, of which 61 authenticated without a second factor during the period. Source: tenant export provided by the target's IT director on 4 September; verified independently against the conditional access policy export."
The difference is not tone. The first statement cannot be defended when a committee member says the seller disputes it. The second can.
The committee section also has to state what the work could not establish. A report claiming full coverage of a four-hundred-server estate after five days of read-only access is not credible, and a committee member who has sat through a post-close incident will say so out loud. State the coverage honestly: which systems were in scope, which were excluded, who excluded them, what testing was performed versus observed versus asserted by management, and what a longer or deeper engagement would have added. A stated limitation is a credibility asset. A limitation discovered later by a committee member is a credibility loss that extends to every other finding in the document.
This matters most for the question that configuration review cannot answer. Reading policies and settings tells you what controls exist. It does not establish that nobody is currently inside the environment. Those are different questions requiring different work, which is the subject of What Is a Compromise Assessment and When Diligence Finds an Active Compromise. A report that does not say which question it answered has left the committee to assume the more reassuring one.
The Portfolio CTO Needs the Detail, Because the Report Becomes the Plan
Here is a fact about the industry that the industry does not advertise. The person who will own the estate was usually not in the diligence room, was frequently not hired when the report was written, and inherits the report as their entire starting brief. In the great majority of deals, the diligence report is the first draft of the 100-day plan whether or not anyone intended it to be.
Write it that way on purpose and the first ninety days get materially easier. The detail layer needs:
- Inventory. What actually exists: servers, endpoints, cloud accounts and subscriptions, SaaS tenants, databases, network devices, with counts and locations. Not a diagram. A list.
- Architecture and dependency description. How the revenue-generating path works, end to end, including the third parties in it.
- Contract and licence position. Every material technology agreement with renewal date, term, assignment restriction and change of control provision noted. This is the section the CTO will open in month two and be grateful for.
- Named single points of failure. Including people. If one engineer holds the deployment knowledge, name the role, describe what they hold, and say what it costs to transfer it.
- Remediation as work packages, not adjectives.
A remediation item written as an adjective cannot be executed, budgeted or tracked. Compare. Adjective: "Improve identity controls." Work package: "Enforce phishing-resistant MFA on 214 privileged accounts across three directories. Dependency: service account inventory must complete first (estimated three weeks). Estimated six weeks elapsed, 1.5 FTE, approximately 40,000 dollars in tooling. Illustrative figures. Owner: infrastructure lead. Evidence of completion: conditional access policy export plus a sign-in log review showing zero legacy authentication on in-scope accounts."
The second version can be put straight into a plan with a name against it. That translation is the subject of Post-Close Technology Integration, and the report either enables it or forces the CTO to redo the analysis from scratch in month one.
Lenders, Co-Investors, and the Reliance Letter
This is the section competing advisory content does not contain at all, and it is the one most likely to cost real money where third-party debt is involved.
A diligence report is addressed to the client who commissioned it. The engagement letter almost always states that no duty is owed to anyone else and that no other party may rely on it. That is the default and it is deliberate.
Where acquisition debt is involved, the debt providers' credit committee may require the technology and cyber report, particularly where the business is software, data or platform dependent. Co-investors may ask for it. A subsequent buyer in a secondary sale may ask for it. In each case the question is not whether they can read it. It is whether they can rely on it, which is a legal question with a real answer.
Under United States law, a party not in contractual privity with a report's author generally cannot recover for a negligent misstatement unless the author knew the report was being prepared for that party's use and there was conduct linking them. New York's formulation of that test comes from Credit Alliance Corp. v. Arthur Andersen & Co. (1985), which requires awareness that the report was for a particular purpose, knowledge of the specific party who would rely, and conduct evidencing the author's understanding of that reliance. Many other states apply the approach in section 552 of the Restatement (Second) of Torts, which extends liability to a limited group of persons the author intends to influence or knows the recipient intends to influence. Both routes share a common feature: the reliance has to be contemplated at the time, not asserted afterwards.
The practical consequence is that reliance is negotiated at engagement or it is negotiated from a position of no bargaining power. Retrofitting it is difficult for four reasons, all of which get worse as the deal progresses:
- The advisor's professional indemnity insurer has to accept an expanded class of claimants. That is an underwriting decision on someone else's timetable, not a signature.
- The advisor will want the liability cap restated, usually as an aggregate cap shared across all relying parties rather than a separate cap per party. If you did not ask which it was, you do not know what you have.
- The scope was designed for one reader. A lender's requirements may include coverage the engagement never had, and a reliance letter over a scope that omitted what the lender cares about is a document, not comfort.
- Pricing changes, and by the time reliance is requested the advisor knows exactly how badly you need it.
Three questions belong in the engagement conversation, before fieldwork, every time. Who may receive this report. Who may rely on it, and on what terms. What is the aggregate liability cap, and is it per party or shared.
That last question deserves saying out loud in the investment committee memo. A report with a liability cap set at the level of the fee, which is common, is a professional opinion and not a transfer of risk. Deal teams sometimes treat an advisor's report as a backstop. It is not one, and the cap is usually in clause 11 of a document nobody on the deal team read.
There is also a fifth reader who never signs anything. The representations and warranties insurance underwriter will read the report during underwriting and will ask what was found. What appears in the report shapes what gets excluded from the policy, which is a mechanism worth understanding before the underwriting call. See What Is M&A Cyber Due Diligence.
Severity That Maps to Money
Red, amber and green is a color. It tells a deal partner nothing they can put in a model.
The failure is structural, not cosmetic. A red finding that costs forty thousand dollars and a red finding that costs four million dollars are rendered identically. Worse, the traffic light collapses three separate variables into one token: how likely the bad outcome is, how expensive it is, and how urgently it has to be addressed. Those three answers select different deal instruments and different plan positions. Merging them into a color destroys the information the reader came for.
Replace it with a scale keyed to money and to action.
| Tier | Definition | Typical examples | Action |
| Deal-breaking | Changes the investment thesis or creates liability that is unbounded or exceeds the equity cheque | Active compromise; core IP not owned or not assigned; copyleft contamination of the distributed product; regulatory exposure larger than the deal | Pause. Expand scope. Reprice materially or walk. |
| Priced | Quantified cost above the deal's stated materiality threshold | Platform re-architecture; end-of-support estate replacement; licence true-up; migration off an unsupported core system | Price adjustment or escrow. |
| Conditioned | Fixable before close. Low in cash, meaningful in risk. | MFA enforcement; administrative credential rotation; data processing agreement execution; removal of a specific open source component | Closing condition with an objective, verifiable standard. |
| Planned | Real cost, below deal materiality, funded post-close | Logging consolidation; endpoint coverage gaps; backup testing; policy and process build-out | Budget line in the 100-day or year-one plan with a named owner. |
| Noted | Observed, no action recommended | Architectural preferences; deferred modernization with no current risk | Recorded so it is not rediscovered later as a surprise. |
Two rules make this work.
Materiality is the sponsor's number, not the advisor's. Set it before fieldwork, as a figure, expressed against enterprise value or against EBITDA. An advisor setting its own materiality will over-report small technical findings, because those are easy to evidence, and under-report thesis risk, because that requires an opinion. A stated threshold fixes both behaviors.
Probability and cost are reported separately. Give an expected cost and a plausible adverse case, label which is which, and state the assumption that separates them. "Expected remediation 1.4 million dollars. Adverse case 3.1 million dollars if the vendor declines to assign the enterprise agreement, which we assess as possible but not likely based on the contract language at section 14.2." Illustrative figures. The committee can work with that. It cannot work with "high."
The method behind the number matters as much as the number. Building costs that withstand a seller's challenge is a discipline in its own right, covered in Quantifying Technical Debt for the Deal Model.
The Anatomy of a Finding
A finding entry has six parts, in this order. Every part is load-bearing. Reports that omit parts four through six are describing a problem rather than proposing a decision, which is why they get read once.
- 1. Observation. What is true. Present tense, factual, no adjectives, no characterization.
- 2. Evidence. How you know. Source, date, method, sample size, and who provided it.
- 3. Business consequence. What happens because of it, stated in the operating model's language: downtime, revenue at risk, customer contract remedies, regulatory exposure, headcount, integration delay.
- 4. Remediation. The work, in sequence, with dependencies, duration, and the type of resource required.
- 5. Cost. A number, with a method, a confidence, and a split across pre-close, year one, and years two to three.
- 6. Recommended instrument. Price, escrow, specific indemnity, closing condition, plan item, or accept with a named accepter.
The Same Finding, Written Twice
What most reports produce:
"Privileged access management is immature. Administrative accounts are not consistently subject to strong authentication and privileged credentials are shared in some cases. This creates significant risk of unauthorized access. Recommend strengthening privileged access controls in line with industry best practice. Severity: High."
Six sentences. Nothing actionable. No number. No owner. No instrument. The words "significant," "immature," "consistently" and "best practice" are doing all the work, and none of them survive a seller saying "we disagree."
What the same facts look like written for use:
- Observation. 214 accounts hold administrative role assignments across three directories. 61 authenticated without a second factor between 1 June and 31 August 2026. Four service accounts hold domain administrator rights with passwords last rotated in 2021. One shared administrative credential is stored in a spreadsheet on a file share accessible to 40 users.
- Evidence. Directory exports and sign-in log extracts provided by the target's IT director 4 September 2026; conditional access policy export reviewed independently; file share permissions confirmed by inspection. Password age from directory attributes. Testing was read-only. No credential was used and no exploitation was attempted.
- Business consequence. A single phished credential among the 61 reaches administrative control of the directory that authenticates the billing platform and the ERP. The estate has 30 days of log retention and no endpoint detection on 40 percent of servers, so an intrusion would probably not be detected by the target. The company's largest three customer contracts include a security incident notification obligation at 48 hours and a termination right on a material breach of the security schedule.
- Remediation. (1) Service account inventory and ownership assignment, three weeks. (2) Rotate the four domain administrator service accounts, with application testing, two weeks, dependent on (1). (3) Enforce phishing-resistant MFA on all 214 privileged accounts, six weeks. (4) Remove standing privilege and implement just-in-time elevation, twelve weeks, dependent on (3). (5) Retire the shared credential and remove the file share, one week, no dependency.
- Cost. Approximately 40,000 dollars tooling in year one and 1.5 FTE for five months, total approximately 190,000 dollars. Illustrative figures. Method: vendor list pricing for the tooling and a loaded contractor rate of 165 dollars per hour. Confidence: high on items 1, 2, 3 and 5. Moderate on item 4, where the range is 90,000 to 240,000 dollars depending on how many applications require re-integration.
- Recommended instrument. Items 3 and 5 as closing conditions, evidenced by a conditional access policy export and written confirmation of file share removal. Items 1, 2 and 4 as a funded 100-day and year-one plan line. No price adjustment recommended: the total is below the stated materiality threshold of 500,000 dollars.
That entry is longer. It is also the only version that produces a decision, a clause, a budget line and a work package. Twelve of those beat a hundred pages of the first kind.
What Disqualifies a Finding
Five failure patterns, each of which should be caught in review before the report leaves the building.
- An adjective in the consequence field. "Creates significant risk" is not a consequence. Name the outcome and, where possible, the cost of the outcome.
- A cost with no method. Any number that cannot be reconstructed from stated inputs will be challenged and will lose.
- A recommendation with no owner type. Work that nobody can be assigned is work that will not happen.
- Management assertion presented as fact. Grade every piece of evidence with one of four words and use them consistently: observed (seen directly), tested (verified by an action), documented (supported by a contemporaneous artifact), asserted (stated by management, unverified). A report where most findings are graded "asserted" is an interview transcript, and the reader deserves to know that.
- The advisor's product preferences dressed as findings. If every recommendation maps neatly onto the advisor's own managed service catalogue, that is a commercial document.
Reading a Vendor Diligence Report
In a competitive process, the seller commissions a technology report and puts it in the data room, often before the first management presentation. It arrives professionally produced, carrying a recognizable brand, running to a hundred pages or more. Bidders under time pressure treat it as a head start.
It is a head start. It is also structurally incomplete, and the incompleteness is predictable enough to plan around. This is not an accusation of dishonesty against the firms that produce these reports. It is a description of who paid for it and who defined its scope.
Three Structural Facts
The party being examined set the scope. Everything excluded from a vendor report was excluded by the seller, with advice from its bankers, in a process designed to support a valuation. The exclusions are the most informative part of the document, and they are usually stated in the scope section in language designed not to draw attention. Read that section first. Read it twice.
It almost never includes a compromise assessment. This is the most consequential omission and the most reliable. Threat hunting across the seller's own estate, commissioned by the seller, creates a disclosure problem for the seller if it finds something, and it creates that problem during a sale process. Sellers do not commission that work. The result is that the single question with the most power to change a transaction, whether the environment is currently compromised, is almost always unanswered in a vendor report, while the report's overall tone suggests the environment has been examined. Marriott acquired Starwood in 2016 and the intrusion into Starwood's reservation system, which began in 2014, was not identified until 2018. A configuration review does not find that. See When Diligence Finds an Active Compromise.
Cost estimates skew low. Remediation estimates, migration estimates and technical debt paydown figures in seller-commissioned reports sit consistently at the optimistic end of the plausible range. No individual number has to be wrong for the aggregate to be materially understated. Assumptions get made favorably, contingency gets thinned, and the items that are hardest to estimate are the ones most likely to be scoped out.
Add a fourth practical fact: the date. A vendor report prepared four months before your bid describes an estate that has changed since, and estates change by accumulation rather than subtraction.
How to Use It Anyway
The correct posture is neither dismissal nor adoption. It is a three-part read.
Read it for the architecture description. The inventory, the topology, the technology stack, the headcount, the vendor list and the contract summary are genuinely useful and expensive to reproduce from scratch under a deadline. That factual layer is usually accurate, because it is checkable and because misstating it serves nobody. Take it.
Treat every conclusion as the seller's opening position. Not as a lie. As a negotiating stance produced by a scope the seller defined. A vendor report's assessment that the platform requires "modest investment to support the growth plan" is the beginning of a conversation about what modest means, measured how, against which plan.
Scope your own work around what it omitted. This is the step that converts the vendor report from a risk into an advantage. Build an explicit list of the questions the report does not answer, then price and scope your confirmatory work against that list rather than duplicating what has already been covered. A bidder who does this gets more decision-relevant information per dollar of diligence spend than a bidder who commissions a parallel full-scope review.
The list of common omissions is short and stable enough to use as a checklist:
- Compromise assessment or threat hunting of any kind
- Privileged access review with actual account counts rather than a policy description. See What Is Privileged Access Management
- Evidence of tested backup restoration, as opposed to backup job success rates, which measure whether copies were made and not whether anything can be recovered. See RPO vs RTO
- Third-party and fourth-party dependency mapping, including who holds administrative access from outside the company. See What Is Third-Party Risk Management
- Software licence compliance and true-up exposure, particularly where headcount or cores have grown
- Open source licence composition of the distributed product
- Change of control and assignment provisions in the material technology contracts
- Any assessment of the target's own ability to detect an intrusion, as distinct from its ability to describe a policy
Two further mechanics. If the engagement letter is in the data room, read it: scope limitations are usually stated there in plainer language than in the report body. And check whether reliance is available. Organized processes frequently offer the vendor report on reliance to the successful bidder on payment of a fee, and that offer comes with a liability cap and a set of assumptions worth reading before treating it as protection.
Five Report Failure Modes
Named so they can be recognized in a sample chapter before the engagement is signed.
- The framework report. Organized around a control catalogue instead of the deal. Produces a score. Answers no question anyone asked.
- The photograph. A careful description of the current state with no cost, no remediation and no time dimension. Accurate and useless.
- The everything report. Four hundred pages, no page one. Comprehensiveness substituting for judgment. The reader is left to perform the prioritization the advisor was hired to perform.
- The catalogue. Every recommendation resolves to a service the advisor sells.
- The report with no negatives. Everything is a risk, nothing was found to be adequate. A report that does not tell you what is fine has not prioritized anything, and it teaches the reader to discount all of it.
The test to apply to any sample report, before signing an engagement letter: pick one finding at random and ask what a deal team would do differently because of it. If the answer is not a clause, a number, a condition or a work package, the report is documentation rather than diligence. That distinction is the subject of What Is Cyber Due Diligence, and it determines whether the sponsor's money bought a decision or bought a file.
Related Reading
Frequently Asked Questions
What should a technology due diligence report contain?
Four layers, physically separated. A one-page executive section with the thesis risks, the total quantified cost split across pre-close, year one and years two to three, and the recommended deal instruments. A committee section where each finding carries observation, evidence, business consequence and mitigation. A detail layer with inventory, architecture, contracts, named single points of failure and remediation written as sequenced work packages. And a scope statement saying what was covered, what was excluded and who excluded it. Anything that does not resolve to a clause, a number, a condition or a work package is documentation rather than diligence.
Who actually reads a technology due diligence report?
Four readers with four different decisions. The deal partner reads one page and decides whether to bid, re-trade or walk. The investment committee reads five to fifteen pages and tests the recommendation by attacking it. The portfolio CTO, usually not present during diligence, reads all of it repeatedly, because in most deals the report becomes the first draft of the 100-day plan. Where acquisition debt is involved the lender's credit committee may require it, which raises the separate question of who is permitted to rely on it. A report designed for only one of the four fails the other three.
What is a reliance letter and why does it matter in due diligence?
A reliance letter extends the report author's duty of care to a party who did not commission the work, typically a lender, a co-investor or a subsequent buyer. It matters because the default is the opposite: engagement letters normally state that no duty is owed to anyone else. Under United States law a party without contractual privity generally cannot recover for a negligent misstatement unless the author knew the report was for that party's use, a standard set out in New York by Credit Alliance Corp. v. Arthur Andersen and in many states through Restatement (Second) of Torts section 552. Reliance must be contemplated at the time, so it is negotiated at engagement. This is not legal advice.
Why is a reliance letter hard to add after the report is finished?
Four reasons, all of which get worse as the deal progresses. The advisor's professional indemnity insurer has to accept an expanded class of claimants, which is an underwriting decision on someone else's timetable. The liability cap has to be restated, and whether it is shared across relying parties or separate per party is a material difference. The scope was designed for one reader and may not cover what the lender cares about, so reliance over the wrong scope gives no comfort. And pricing changes once the advisor knows how badly the reliance is needed. Ask at engagement.
How should findings be rated for severity?
Map severity to money and to action rather than to color. Five tiers work: deal-breaking, where the thesis changes or liability is unbounded; priced, where quantified cost exceeds the deal's materiality threshold and belongs in a price adjustment or escrow; conditioned, where the fix is cheap in cash and meaningful in risk and belongs in a closing condition; planned, where cost is real but below materiality and belongs in a funded plan line; and noted, recorded so it is not rediscovered as a surprise. Materiality is the sponsor's number, set before fieldwork, not the advisor's.
What should a single finding entry contain?
Six parts, in order. Observation: what is true, present tense, no adjectives. Evidence: source, date, method, sample size and who provided it. Business consequence: stated in the operating model's language, meaning downtime, revenue at risk, contract remedies or regulatory exposure. Remediation: the work, sequenced, with dependencies and duration. Cost: a number with a method, a confidence and a split across pre-close, year one and years two to three. Recommended instrument: price, escrow, specific indemnity, closing condition, plan item or accept with a named accepter. Entries missing the last three parts describe a problem instead of proposing a decision.
Can a buyer rely on a vendor due diligence report in a competitive process?
Read it, but understand what it is. The seller defined the scope, so every exclusion was the seller's choice. It almost never includes a compromise assessment, because threat hunting commissioned by a seller creates a disclosure problem for that seller during a sale process, which means the most consequential question in cyber diligence is usually unanswered. Cost estimates sit at the optimistic end. Use it for the architecture description, inventory and contract summary, which are accurate and expensive to reproduce. Treat conclusions as the seller's opening position. Then scope your own work around what the report omitted.
Does the diligence report become the 100-day plan?
In most deals it does, whether or not anyone intended that. The portfolio CTO was usually not in the diligence room and often not yet hired, and inherits the report as their entire starting brief. Writing it for that use costs nothing extra and saves a month. That means remediation items written as work packages with dependencies, durations, resource types, cost estimates and an evidence standard for completion, rather than as verbs like strengthen or improve. A finding that cannot be assigned to a named person with a date is a finding that will not be remediated.
Hewlett-Packard and Autonomy: What a Buyer Can Prove It Was Told
In August 2011 Hewlett-Packard agreed to acquire the British software company Autonomy for approximately 11.1 billion dollars. The deal closed in October 2011.
In November 2012, roughly thirteen months later, HP recorded an impairment charge of approximately 8.8 billion dollars against the acquisition. The company stated that more than 5 billion dollars of that charge related to what it described as serious accounting improprieties, misrepresentations and disclosure failures at Autonomy before the acquisition.
HP then sued Autonomy's founder Mike Lynch and its former chief financial officer Sushovan Hussain in the English High Court. The trial ran for more than ninety days. In January 2022 Mr Justice Hildyard held that HP had substantially succeeded in its claims, while indicating that the damages recoverable would be considerably less than the 5 billion dollars sought. In July 2025 the court quantified HP's loss at approximately 730 million pounds, roughly 944 million dollars. Lynch died in August 2024 when his yacht sank off Sicily; the claim proceeded against his estate.
State the limits of the analogy clearly. This was a dispute about accounting and about fraud, not about technology diligence, and the court found deliberate wrongdoing rather than a diligence failure. It is not a case about reports being badly written.
It is, however, the best available demonstration of what a report is actually for, because the entire fourteen-year dispute turned on questions of evidence and reliance. What was the buyer told. In which document. On what date. By whom. What was the buyer entitled to rely on, and what had it independently verified. Who owed a duty to whom. A trial of that length is, in substance, a forensic reconstruction of what a set of transaction documents did and did not establish, conducted a decade after the people involved stopped remembering clearly.
Three transferable points for a sponsor commissioning technology diligence.
- A finding is worth what its evidence trail is worth. "We understood that the platform was scalable" is not a finding. "On 12 August, the CTO stated X; we tested Y and observed Z" is. The distinction is invisible on the day the report is delivered and decisive if the deal is ever disputed.
- Reliance is a question with a legal answer, and the answer is determined at engagement. Who was entitled to rely on which document, and on what terms, is not something to work out after a problem surfaces. It is settled in the engagement letter, the reliance letter, and the liability cap, all of which are negotiated before anyone knows whether they will matter.
- The scope statement is the most important paragraph in the report. What the work covered, what it did not, and who decided. Years later, the boundary of the work is the boundary of what anyone can say the buyer knew.
Write every report as though a court will read it in 2038. Most will not. The ones that do will be the ones where it mattered most.
A technology diligence report has to work in four separate rooms: the deal partner deciding whether to bid, the investment committee testing the recommendation, the portfolio CTO who inherits the estate, and the lender whose credit committee may require it. Each needs something the others do not. Almost every report on the market is written for one of them, usually the fourth-most important one, and the other three readers quietly stop opening it.
How Cloudskope Can Help
Cloudskope runs technology and cyber due diligence for private equity sponsors, corporate development teams and their counsel, and we write the report to be used rather than filed. One page for the deal partner: thesis risks, the quantified number, recommended deal terms. A committee section where every finding carries its evidence, its business consequence and its mitigation in a form that survives challenge. A detail layer written as sequenced work packages with owners, dependencies and costs, so the portfolio CTO inherits a plan rather than a diagnosis. Our M&A Cyber and IT Technical Due Diligence practice is built around that output. We discuss reliance, recipients and liability caps at the engagement conversation, before fieldwork, because those terms are close to impossible to improve later.
Where the question is whether the target's environment is currently compromised, which is the question vendor reports almost never answer and configuration review cannot answer, Cloudskope SARTUS delivers a compromise assessment on a diligence timeline: scoped, evidence-preserving, and written so that counsel and an investment committee can act on it. The difference between a report that describes controls and a report that establishes whether someone is inside is the difference between a document and a decision.
.png)