BlogMergers and AcquisitionsIT due diligence in 2026: the software licences that don't survive the sale

IT due diligence in 2026: the software licences that don't survive the sale

14 min read
Marc Seitz

Marc Seitz

IT due diligence is the review of the systems a target company runs its business on: infrastructure, applications, licensing, security, and the people who keep them working. It exists to answer two questions before closing: what does this IT estate really cost to run, and what will it cost to integrate or separate it?

Quick recap

  • IT due diligence assesses a target's internal technology estate, as opposed to technical due diligence, which assesses the product the company sells.
  • A standard review covers 8 domains: infrastructure, applications, licensing, cybersecurity, data and privacy, IT operations, cost, and integration readiness.
  • Software licensing is the domain that most often produces an unbudgeted liability, because many enterprise agreements are non-transferable on a change of control.
  • Cybersecurity findings are increasingly deal-relevant because acquirers inherit breach notification duties, including the 72-hour GDPR reporting obligation.
  • In a carve-out, a transition services agreement usually keeps the seller running IT for the buyer for 6 to 18 months while systems are separated.
  • IT diligence is normally scoped alongside operational diligence, which runs $15,000 to $30,000 for a small company, $30,000 to $75,000 mid-market, and $75,000 to $200,000 for a large enterprise.
  • Disaster recovery is assessed against documented recovery time and recovery point objectives, not against whether backups exist.
  • Shadow IT, meaning tools bought on expense cards outside procurement, routinely accounts for a meaningful share of the true application count.
  • A data room for IT due diligence differs from a financial one: the documents are attacker-useful, so folders carry different permissions and the security folder is view-only and watermarked.
  • Papermark hosts a data room for IT due diligence with granular permissions, dynamic watermarking, and per-visitor analytics from €99/month.

Buyers underinvest in IT diligence more than any other workstream, usually because it feels like plumbing rather than strategy. Then the first post-close year arrives with an unbudgeted Oracle true-up, an ERP that cannot be extended to the new subsidiary, and an integration that takes 24 months instead of 9. This guide covers the eight domains, the licensing and security traps, how transition services agreements work, and what the review actually costs.

Running the review means putting network diagrams, penetration test findings and licensing agreements in front of four different reviewers who should not all see the same things. A data room for IT due diligence handles that with one link per party. Section 8 covers the setup step by step.

1. What is IT due diligence?

IT due diligence is a structured assessment of the information technology a target company uses to operate: its networks, servers and cloud accounts, business applications, identity systems, endpoints, security controls, vendor contracts, and IT staffing. It is commissioned by an acquirer or investor after a letter of intent and delivered as a report that quantifies run-rate cost, risk, and the effort required to integrate or separate the estate.

The distinction from technical due diligence is worth being precise about. Technical review covers the product the company sells, meaning architecture, source code, and the engineering team. IT review covers what employees use to do their jobs. A software company being acquired needs both, and they are usually run by different reviewers with different document requests. A distributor, a manufacturer, or a services business normally needs only the IT review.

The value of the workstream is that it converts vague integration assumptions into numbers. A deal model that assumes $2M of annual cost synergy from consolidating systems is only credible if someone has confirmed that the target's ERP can be retired, that its 340 employees can be migrated to the buyer's identity provider, and that the contracts allowing all of that do not carry termination fees. IT diligence is where those assumptions get tested.

It also surfaces liabilities that appear nowhere on the balance sheet. Unlicensed software, expired support contracts, unsupported operating systems still running production workloads, and a backup regime that has never actually been restored are all findings that convert directly into first-year spending.

2. The 8 domains of an IT due diligence review

The eight domains below make up the standard scope. Each one produces findings that are either a cost, a risk, or an integration constraint, and the report should express all three in the same units the deal model uses.

Infrastructure and applications come first because they define everything downstream. The reviewer inventories data centers, cloud accounts, network equipment, servers, and endpoints, then maps the application portfolio: what each system does, who owns it, what it costs, what it integrates with, and whether it is supported. Companies routinely discover during this exercise that they run 40 percent more applications than they thought, because tools bought on expense cards never entered the procurement record.

Licensing and contracts come next, and this is where the money hides. Enterprise agreements with Microsoft, Oracle, SAP, and similar vendors frequently include change-of-control provisions, and a licence that was compliant under the seller may need renegotiation, re-purchase, or a true-up payment once ownership changes. Cybersecurity, data and privacy follow, covering controls, incident history, penetration testing, regulatory posture under GDPR and equivalent regimes, and any open commitments to customers.

#DomainWhat the reviewer checksTypical red flag
1InfrastructureData centers, cloud accounts, network, servers, endpointsUnsupported operating systems in production
2ApplicationsPortfolio, owners, integrations, support statusHeavily customized ERP that cannot be upgraded
3LicensingEntitlements, compliance, change-of-control termsNon-transferable enterprise agreement
4CybersecurityControls, incident history, testing, certificationsNo penetration test in the past 24 months
5Data and privacyData map, retention, GDPR posture, processor contractsNo record of processing activities
6IT operationsTeam, MSPs, service levels, backup and recoveryBackups never restore-tested
7IT costRun-rate spend, contracts, capital planDeferred refresh creating a spending cliff
8Integration readinessSeparability, dependencies, TSA scopeShared systems with the seller's parent

The final three domains are operational. IT operations covers the internal team, managed service provider contracts, service levels, and disaster recovery, which should be assessed against documented recovery time and recovery point objectives rather than against a general assurance that backups run. IT cost covers total run-rate spending and the capital plan, including deferred refreshes that create a spending cliff. Integration readiness assesses how separable the estate is and what a transition services agreement would need to cover.

What each domain asks the seller to produce

Knowing the domains is one thing; knowing what lands in the data room is another. The table below maps each domain to the documents a reviewer will request, which is also the folder structure the seller should build before the room opens.

DomainDocuments requestedTypical countSensitivity
InfrastructureNetwork diagrams, cloud account inventory, server and endpoint lists15 to 40High
ApplicationsApplication portfolio, owner map, integration diagram, support status20 to 60Medium
LicensingEnterprise agreements, entitlement reports, audit correspondence30 to 90Medium
CybersecurityPenetration tests, SOC 2 or ISO 27001 reports, incident log, policies20 to 50Very high
Data and privacyData map, ROPA, processor agreements, transfer mechanisms15 to 40High
IT operationsMSP contracts, SLAs, org chart, DR plan and restore test evidence10 to 30Low
IT costRun-rate spend by vendor, capital plan, contract renewal calendar10 to 25Medium
Integration readinessShared-system inventory, dependency map, draft TSA schedules10 to 30High

The sensitivity column is the one that drives how the room is configured. Cybersecurity and infrastructure documentation is genuinely dangerous material: a penetration test report is a list of unfixed ways into the company, and a network diagram tells an attacker where to aim. Those two folders should never carry the same permissions as the cost folder.

3. Software licensing: the liability that hides in plain sight

Licensing is the domain where IT diligence most often pays for itself several times over. Enterprise software is licensed to a legal entity under specific metrics, and a change of control can invalidate the arrangement entirely. A buyer who assumes the target's Microsoft or Oracle position transfers with the shares can find themselves negotiating a new agreement from a weak position, with the vendor fully aware that the deal has closed.

Three checks matter most. The first is entitlement versus deployment: does the company hold licences for what it actually runs, counted by the metric the vendor uses, whether that is named users, devices, processor cores, or something else. The second is the change-of-control clause in every material agreement, because non-transferability is common and rarely noticed until it is too late. The third is audit history, since a vendor audit in the past three years is a strong signal that another one will follow the transaction.

How a finding is handled depends on which of those three checks produced it, and the commercial remedy differs in each case.

FindingHow it surfacesCommercial remedy
Deployment exceeds entitlementEntitlement report compared with actual install or user countsPrice adjustment sized to the true-up quote
Non-transferable agreementChange-of-control clause in the master agreementSeller re-negotiates pre-closing, or buyer budgets a new agreement
Open vendor auditAudit correspondence in the contracts folderSpecific indemnity, since the exposure is unquantified
Support lapsed on production systemsSupport renewal dates against the asset inventoryFirst-year budget line, not a price adjustment
Unsupported open-source in infrastructureComponent inventory with no named owner for patchingRemediation plan with a dated milestone

Link-level permissions restricting the licensing folder to the lender in an IT due diligence data room

Licensing documents go to the lender and the IT advisor, but not to the cyber specialist or the broker.

Open-source usage inside internal systems is a smaller but related exposure. Where technical diligence worries about copyleft components in the shipped product, IT diligence worries about unsupported open-source components in production infrastructure with nobody responsible for patching them.

The commercial handling is straightforward once quantified. A licensing gap becomes either a price adjustment, a specific indemnity, or a first-year budget line. What does not work is discovering it after closing, when the buyer has no leverage and the vendor has every incentive to price the remedy aggressively.

4. Cybersecurity, privacy, and inherited obligations

Security findings in IT diligence are not academic, because the buyer inherits both the exposure and the reporting duties. Under GDPR, a personal data breach affecting an acquired entity must be reported to the supervisory authority within 72 hours of awareness, and the acquirer will be the one holding that clock. Sector rules add more: financial services, healthcare, and increasingly any operator covered by EU network and information security rules carry their own obligations.

The reviewer looks at controls and at evidence that the controls work. That means identity and access management, multi-factor authentication coverage, privileged account handling, endpoint protection, patch cadence, network segmentation, logging, and vendor risk management. It also means incident history: what has happened, how it was handled, whether customers or regulators were notified, and whether the root cause was actually fixed.

Screenshot protection applied to penetration test findings in a data room for IT due diligence

Penetration test findings are the documents most worth restricting: view-only, watermarked, and screenshot-protected.

Certifications help but do not substitute for evidence. A current SOC 2 Type II report or ISO 27001 certificate tells a buyer that an external assessor tested controls over a defined period, which is far more useful than a policy document, but the scope statement matters. A SOC 2 covering only the production product says nothing about whether finance staff have multi-factor authentication.

Privacy diligence is its own thread. Reviewers look for a data map, a record of processing activities, retention schedules, processor agreements with sub-processors, transfer mechanisms for data leaving the EU, and any open data subject complaints. Where the target holds large volumes of personal data, this workstream often has more deal impact than the infrastructure review.

5. Transition services agreements and carve-outs

When a buyer acquires a division rather than a whole company, IT diligence stops being an assessment and becomes a separation plan. The target's systems are usually entangled with the parent's: shared ERP instances, a common identity provider, one email tenant, shared network and security tooling, and licences held at group level. None of that transfers automatically.

The mechanism that bridges the gap is a transition services agreement, under which the seller continues to provide IT services to the divested business for a defined period at a defined price. TSAs typically run 6 to 18 months for IT, longer than for most other functions, because migrating an ERP or separating an identity estate is genuinely slow work. The diligence job is to define the scope precisely and to price it, since sellers have every incentive to keep TSA terms vague and buyers discover the true cost only when the invoices arrive.

Three things determine whether a carve-out goes well. First, an accurate inventory of which systems are shared and which are dedicated, produced during diligence rather than after signing. Second, a costed standalone target state, because the divested business will need its own ERP, identity, and security tooling and that spending starts before the TSA ends. Third, an exit plan with dates, because TSAs that run past their term become expensive quickly and give the seller leverage.

For the broader planning that follows, our guide to acquisition integration covers how IT workstreams fit into the first hundred days.

6. Worked scenario: carving out Ostmark Components

A private equity fund agrees to acquire Ostmark Components, a €62M revenue industrial parts division being divested by a larger European group. The division has 410 employees across four sites and no standalone IT function, which is exactly the profile where IT diligence determines whether the deal model survives contact with reality.

The review inventories 71 applications in use. Only 22 are dedicated to Ostmark. The remaining 49 are group-provided, including the SAP instance that runs finance and supply chain, the Microsoft tenant, the identity provider, the security operations tooling, and the network. Eleven of those are licensed under group enterprise agreements with explicit change-of-control restrictions, meaning none of them transfer.

Ostmark Components: application portfolio at diligence
71applications
  • Dedicated to the division22 · 31%
    Transfer with the carve-out
  • Group-provided, transferable38 · 54%
    Replaceable or re-licensable standalone
  • Group-provided, change-of-control restricted11 · 15%
    SAP, identity, security operations, network

Worked scenario. The 11 change-of-control-restricted applications are the ones that set the transition services agreement length, because none of them transfer with the division.

Cost work produces the number that matters. Ostmark's allocated IT charge in the group accounts is €1.9M a year. The reviewer's standalone estimate is €3.4M, because the division loses group purchasing leverage and needs its own ERP, identity, security operations, and a service desk. That €1.5M gap flows straight into the model as a permanent cost increase and reduces the fund's entry valuation by more than the entire diligence budget.

Two more findings shape the agreement. The SAP separation is estimated at 14 months, so the TSA is negotiated at 18 months with two three-month extension options at a defined rate rather than at cost plus. And the security review finds that 140 endpoints run an operating system version past end of support, requiring a €190,000 refresh in the first six months.

Diligence runs through a data room holding 310 IT documents across eight folders. The fund's IT advisor, the fund's cyber specialist, and the lender each get their own link, with the security assessment folder view-only and watermarked. The deal closes with a costed 18-month separation plan rather than a hopeful one.

7. Common mistakes in IT due diligence

The most common mistake is starting the IT review late, after financial and commercial diligence have already fixed the model. IT findings routinely change the run-rate cost base, and a €1.5M standalone cost increase discovered in the final week is very hard to reflect in a price that has already been agreed in principle.

The second is accepting an application list from the target without validating it. Finance can produce a vendor spend report that reveals dozens of tools nobody mentioned, and comparing the two lists is one of the fastest ways to find shadow IT.

The third is treating disaster recovery as a yes or no question. Every company says it takes backups. The useful questions are what the documented recovery time and recovery point objectives are, when a restore was last tested end to end, and what the result was.

The fourth is sharing IT diligence material carelessly. Network diagrams, penetration test findings, and identity architecture documents are a genuine security asset, and circulating them over email to a lender, two advisors, and an insurance broker with no access control creates exposure for both sides. Our data room checklist covers how to structure this properly.

Manage due diligence with a virtual data room

No credit card required

Page by page analytics
Unlimited documents & folders
Permission management
Dynamic watermarks
NDA collection
Real-time alerts
Custom branding
Audit trail

8. Data room for your IT due diligence

A data room for IT due diligence is not the same artifact as the one finance uses. The financial folder holds numbers that are commercially sensitive; the IT folder holds a map of how to break into the company. That difference should change how the room is built, who gets which link, and what happens to the file after closing.

Papermark is a secure, fully customizable, and developer-friendly data room built for modern dealmakers, with page-by-page analytics, dynamic watermarking, and transparent pricing (open-source and self-hosting available).

Papermark data room for IT due diligence with folders organised by domain

An IT due diligence data room with one folder per domain, so permissions can differ by folder rather than by document.

Why you need a data room for IT due diligence

Most IT diligence still runs over email and shared drives, and it is the workstream where that habit costs the most. There are four reasons a dedicated data room for IT due diligence earns its place. If you are still choosing a platform, our comparison of the best virtual data rooms covers pricing model, bidder management and compliance across the main providers.

The documents are attacker-useful. A penetration test report is a list of unfixed ways into the company. A network diagram tells someone exactly where to aim. An identity architecture document explains which account to compromise first. Circulating those over email to a lender, two advisors and an insurance broker creates a genuine security exposure for both sides of the deal, and it is one the seller carries even if the transaction never completes.

Four parties need four different views. IT diligence is unusual in how asymmetric the access should be. The cyber specialist needs the penetration test findings; the lender needs the cost and licensing folders and nothing else; the insurance broker needs incident history alone. A shared drive gives you one permission set. A data room for IT due diligence gives you one per link, over the same underlying documents.

Request lists arrive in waves. The reviewer asks for an entitlement report, reads it, then asks for the three enterprise agreements it references. Across 310 documents and 60 open questions, an email thread simply loses track, and the same question gets asked twice by two workstreams.

The disclosure record matters years later. When a licensing dispute surfaces two years after closing, the question is what was disclosed, to whom, and when. A room with a per-visitor audit log answers that. An inbox does not.

The rest of this section is the practical setup: five steps to build a data room for IT due diligence that handles all four.

Step 1: build the room by domain, not by document

Create one folder per domain from the table earlier in this guide: infrastructure, applications, licensing, cybersecurity, data and privacy, IT operations, cost, and integration readiness. That structure is what makes differentiated access possible later. A room organised as a flat pile of 310 files forces you to choose between giving everyone everything or hand-picking documents per reviewer, and neither scales across four parties.

Upload in bulk by dragging the folder tree straight in. Automatic file indexing on the Data Rooms Plus plan builds and maintains the index as documents arrive, which matters in IT diligence because the request list grows in waves rather than arriving complete.

Step 2: set permissions per reviewer group

This is where an IT room differs most from a financial one. Four parties typically need four different views of the same document set.

ReviewerFolders grantedRights
Buyer's IT advisorAll eight domainsView and download
Cyber specialistCybersecurity, data and privacy, infrastructureView only, watermarked
LenderIT cost, licensingView only
Insurance brokerIncident history onlyView only, watermarked

Granular file-level permissions are set per link rather than per user, so each party gets its own link carrying its own folder scope, email allowlist or domain restriction, and download rule. Access is link-based, so no reviewer has to create an account, which removes the friction that makes busy advisors ignore a room entirely.

Granular folder-level permissions applied per reviewer link in a Papermark data room

Permissions are set per link, so the cyber specialist and the lender see different folders of the same room.

Step 3: protect the documents that would help an attacker

Switch the cybersecurity and infrastructure folders to view-only and turn on dynamic watermarking, which stamps every page with the viewer's email, IP address, and timestamp as it renders. Screenshot protection adds a further deterrent on the penetration test findings specifically.

The honest limit is worth stating: a file that has been downloaded is legally treated as read, and no platform can recall it. That is precisely why download is disabled rather than merely discouraged on these two folders, and why watermarking exists: it makes any leak traceable to a named viewer rather than merely regrettable.

Dynamic watermark showing viewer email, IP address and timestamp on a diligence document

Dynamic watermarking renders viewer identity onto every page, which is what makes a leak traceable.

Step 4: run the request waves through Q&A, not email

IT diligence arrives in waves. The reviewer asks for an entitlement report, reads it, then asks for the three enterprise agreements it references. Run over email, that thread fragments across the CIO, the controller, and two advisors, and nobody can tell which of 60 open questions is still unanswered.

The Q&A module attaches each question to the document that prompted it, with permissions controlling who sees which threads, so the lender never sees the cyber specialist's findings. Answers can be published to one group or to everyone, and the whole log exports for the closing file.

Step 5: read the analytics, then close the room properly

Page-level analytics show which reviewer opened which document, when, and for how long. In IT diligence this is a scoping signal: an advisor who has spent forty minutes in the licensing folder has found something, and you will usually hear about it a week before their report lands.

Per-visitor analytics across IT due diligence documents in a Papermark data room

Per-visitor analytics show which IT diligence documents each reviewer opened and for how long.

After closing, data room freeze makes the room immutable and exports it as an archived ZIP with a certificate. When a licensing dispute surfaces two years later, that archive is the record of exactly what was disclosed and to whom.

Tyler

Papermark is our #1 VDR provider for M&A transactions right now. In two deals we used custom branding, dynamic watermarking, and granular permissions.

Tyler

Fox Island Group

What it costs

The Data Rooms plan is €99/month with a 7-day free trial and includes 3 team members, unlimited data rooms, unlimited documents, custom domain, dynamic watermarking, NDA agreements, and granular file-level permissions. Data Rooms Plus at €249/month adds 5 team members, the Q&A module, the audit log, automatic file indexing, and SOC 2 Type II. For carve-outs where the same IT documentation goes to several bidders, unlimited data rooms under one subscription means one room per bidder with no per-project fee.

No credit card required.

FAQ

More useful articles from Papermark

Ready to create your deal room?