The process

How it works

Due diligence runs as a clear sequence: a scoping call, access to the target and the data room, the review across cyber, technology and IT, findings triaged and rated red-amber-green, a report the deal team can act on, and a debrief. The same sequence runs whether you commission one strand or all three, and whether the review is buy-side or sell-side. It is delivered in-house by CyPro's 3DD practice, one team from first call to final report.

Six steps

From scoping call to a deal-ready view

Every engagement runs this sequence. What changes between cyber, technology and IT due diligence is what gets examined in the review, not the shape of the process around it.

measurable client outcomes for cyber and technology due diligence

Step 1

The scoping call

Free, taken by a consultant from our 3DD practice rather than a salesperson. We establish the target, the deal timeline and the pressure you are under, which of the three strands the deal needs (cyber, technology and IT), and the deal-size bracket you sit in. You leave knowing the indicative fixed fee already published on the pricing page.

secure technology for cyber and technology due diligence

Step 2

Scope confirmed, access arranged

We confirm in writing the strands in scope, the deal-size bracket, and the systems and boundaries the review covers, then arrange access to the target and the data room under the deal's confidentiality terms. A fixed-scope statement of work is agreed before the review begins, so there are no moving goalposts once it is under way.

secure technology for cyber and technology due diligence

Step 3

The review across cyber, technology and IT

Our 3DD practice reviews the target across the strands you commissioned: security posture and breach history for cyber, architecture, code, scalability and the engineering team for technology, and the IT estate, infrastructure, licensing and integration cost for IT. The review draws on the data room, management sessions and any technical access agreed at scoping.

supporting distributed teams for cyber and technology due diligence

Step 4

Findings triaged and rated

Every finding is weighed for its bearing on the deal and rated red, amber or green: a deal-breaker is separated from a first-100-days fix, and noise from the things that actually move valuation or warranties. Each finding is quality-assured for accuracy and relevance before it reaches you, not passed on raw.

structured project delivery for cyber and technology due diligence

Step 5

Red-amber-green reporting the deal team can act on

You receive a clear report: what is red, amber and green, the risk each finding carries to valuation, warranties and integration, and what it means for the deal, ordered for the people who will act on it. It is written to drop into the deal process, an investment committee paper or a board pack, without reworking it first.

measurable client outcomes for cyber and technology due diligence

Step 6

The debrief

We walk the deal team through the findings, take the questions they raise, and talk through what the risks mean for price, warranties, the sale and purchase agreement and the first 100 days. Where you want support closing the gaps after completion, that is scoped as a separate engagement; the same 3DD team stays with you throughout.

Buy-side and sell-side

Who commissions the review, and when

The same review is commissioned from two sides of a deal. The sequence above does not change; the commissioner and the timing do, and both are delivered by the same 3DD practice.

Buy-side. The acquirer commissions the review before they sign, to understand the cyber, technology and IT risk in the target: what it means for the price on the table, the warranties to seek, and the work waiting in the first 100 days after completion.

Sell-side. The vendor commissions the same review before going to market, to find and fix the issues a buyer would otherwise raise. Going in with the risks understood and the worst of them closed protects the price and keeps the sale on the front foot. See the sell-side option on the pricing page.

The exchange

What the review needs from you, and what you get back

What it asks of you

  • A named deal contact: someone who receives the findings and can reach the target and its management.
  • The target and the deal defined: which entity, the deal-size bracket, and which of the three strands are in scope.
  • Access to the data room, management and the technical evidence the review draws on, arranged at scoping.
  • Written authorisation for any technical access to or testing of the target's systems, agreed at scoping; we never test systems we have not been authorised on.

What it hands back

  • A red-amber-green view of the target across the strands you commissioned, and exactly where the risk sits.
  • Findings ordered by their bearing on the deal, valuation, warranties and the first 100 days, not a raw list to decode.
  • A report the deal team can put in front of an investment committee or a board without reworking it.
  • One 3DD team throughout, a debrief on the findings, and a route back for post-completion support once the deal closes.

Common questions

What deal teams ask before they commission

What is the technology due diligence process?

It runs as a clear sequence: a scoping call to fix the target and the strands in scope, access to the target and the data room, the review itself across the areas you commissioned, then every finding triaged and rated red, amber or green, a report the deal team can act on, and a debrief. The same shape runs whether you commission cyber, technology or IT due diligence, or all three together. What changes is what gets examined in the middle, not the order of the work.

What is the difference between buy-side and sell-side due diligence?

The review is the same; the commissioner and the timing differ. Buy-side is commissioned by the acquirer, before they sign, to understand the cyber, technology and IT risk they are buying. Sell-side is commissioned by the vendor, before going to market, to find and fix the issues a buyer would otherwise raise, so the sale runs to a cleaner, better-supported position. We deliver both from the same 3DD practice.

How long does due diligence take?

It runs to the deal timeline, not a fixed calendar. What sets the depth is the scope you commission and the size and complexity of the target: a single strand on a sub-£10m deal is a lighter piece of work than all three on a £50m-plus target. We agree the reporting sequence at scoping so the review fits the deal window and the findings land when the deal team needs them.

What happens after we get the findings?

We hold a debrief and talk through what the red and amber findings mean for price, warranties, the sale and purchase agreement and the first 100 days after completion. The findings are yours to act on in the negotiation and post-deal; where you want hands-on support closing the gaps once the deal closes, we scope that with you as a separate engagement.

See indicative pricing

Rocket above the Cyber Due Diligence call to action

Step one costs nothing

Book the scoping call

Bring the target, the deal timeline and a rough idea of the scope. We bring the sequence above, the indicative fixed fee, and a clear view of which strands the deal actually needs.