What is technical due diligence?
Short answer
Technical due diligence is an independent assessment of a company’s technology, carried out for investors or acquirers before a deal. It covers architecture and scalability, code quality, security and compliance, the engineering team and key-person risk, and the cost of fixing what it finds. Founders can run the same review beforehand to close gaps.
What does it cover?
- Architecture, scalability and technical debt
- Code quality, testing and delivery practices
- Security, data protection and compliance (SOC 2, ISO 27001, GDPR, HIPAA)
- Infrastructure, reliability and cloud costs
- Team structure, hiring and key-person risk
- Intellectual property and open-source licence use
Common red flags
- One engineer understands a critical system
- No tested backups or disaster recovery
- Security questions answered with intentions rather than evidence
- Infrastructure costs growing faster than revenue
- Core product built on an unmaintained framework
How founders can prepare
Run a self-assessment three to six months before a raise or sale, fix the cheapest high-severity risks first, and prepare written evidence: architecture diagrams, security policies, incident history and a team chart.
Related questions
How long does technical due diligence take?
The scope and timing depend on the business, the transaction and the evidence available. Agree the questions and decision deadline before the work begins.