For acquirers

IT Due Diligence: Infrastructure, Systems and Risk

Know what the target's IT estate really costs to run, integrate and secure before you commit. Independent IT due diligence across infrastructure, systems, licensing, contracts, integration cost and the cyber risk inside the systems, reported as a clear red, amber and green verdict and delivered in-house by CyPro's 3DD practice.

Why it matters

The estate you inherit, priced before you sign

An acquisition buys the target's IT estate along with the business: the infrastructure, the licences, the contracts and the risk inside the systems. Financial and legal due diligence rarely reach any of it, so the run cost, the integration bill and the cyber exposure land on the buyer after completion.

IT due diligence prices that estate before you commit. We map the infrastructure and systems, surface the licensing and contract exposure, size the integration cost and assess the cyber risk, then hand the deal team a clear verdict on each. You underwrite the IT with a number, not an assumption.

You receive

  • A red, amber and green verdict on each area of the IT estate, readable at a glance
  • A quantified view of integration, separation or migration cost for the deal model
  • The true run cost of the estate, with licensing and contract exposure surfaced
  • A key-risk register covering resilience, cyber exposure and supplier dependency
  • A debrief with the deal team where every finding can be challenged before you rely on it

What we cover

What an IT due diligence examines

Six areas of the IT estate, each examined against the deal and rated red, amber or green. Scope is set around the target and the transaction, not a generic checklist.

Infrastructure and systems

The estate the business actually runs on: servers, cloud tenancy, networks, endpoints and the core business systems. We map what exists, what state it is in, and what a buyer takes on.

Licensing and contracts

Software licences, cloud commitments, support agreements and supplier contracts. We surface the true run cost, the renewals, the lock-in and any licensing exposure that lands on the buyer after completion.

Integration cost

What it will realistically cost to integrate, separate or migrate the target's IT. We size the effort and the spend so the number sits in the model before you commit, not as a surprise in the first hundred days.

Resilience and continuity

Backup, disaster recovery and business continuity as they stand, not as the policy claims. We test whether the estate could recover from a failure or an incident and how long that would take.

Cyber risk in the estate

The security exposure sitting in the target's systems: patching, access, exposed services and the controls a buyer inherits. Drawn from CyPro's core security practice, not a tick-box scan.

IT team and dependency

How the estate is run and supported, in-house or outsourced, and where the key-person or single-supplier dependencies sit. The people and the contracts behind the systems are part of the risk.

Reporting and price

Acquirer-ready reporting, priced up front

Each area of the estate lands as a single red, amber or green rating the deal team can read in seconds, with the evidence and the cost impact behind it. The integration figure and the run cost are set out in numbers you can drop into the model.

The field quotes on request. We publish indicative fixed-fee prices by deal size instead, so you can size the work before the first call. Scope is confirmed per deal.

Sub-£10m deal

from £5,500

A focused review of the estate for smaller acquisitions, scoped to what carries the deal.

£10m to £50m

from £9,500

Full-scope IT due diligence across infrastructure, licensing, integration cost and cyber risk.

£50m and above

from £15,000

Deep review for larger or more complex estates, including multi-site and multi-cloud.

Indicative fixed-fee prices, confirmed per deal. Cyber, technology and IT due diligence are commonly commissioned together for a full pre-acquisition review; ask about a combined scope.

Quick answers

IT due diligence questions, answered

What is IT due diligence?

IT due diligence is an independent review of a target company's IT estate, commissioned before an acquisition. It examines the infrastructure and systems the business runs on, the software licensing and supplier contracts, the cost of integrating or separating the IT, the resilience of the estate and the cyber risk sitting inside it.

The purpose is to price the IT into the deal: what the buyer inherits, what it costs to run, and what it costs to bring into the fold after completion.

What is the difference between IT and technology due diligence?

IT due diligence looks at the estate the target runs on: infrastructure, systems, licensing, contracts, integration cost and the cyber risk in those systems. Technology due diligence looks at the product the target sells: the code, the architecture, the engineering team and the roadmap.

If the target is a software or product business, you usually want both. If you are acquiring for the operation rather than the product, IT due diligence on its own is often the right scope.

Technology due diligence, explained

Does IT due diligence cover integration cost?

Yes, and it is often the most valuable output. We size what it will realistically cost to integrate, separate or migrate the target's IT, so the figure sits in your model before completion rather than surfacing as an overrun in the first hundred days.

Does it include the cyber risk in the target's systems?

Yes. We assess the security exposure inside the estate: patching, access control, exposed services and the resilience of the systems, so you know the cyber risk you are taking on. It is drawn from CyPro's core security practice rather than a surface-level scan.

Who delivers the review?

It is delivered in-house by CyPro's 3DD practice, our own due-diligence methodology. The consultants who scope the work write the report and take the debrief, so you deal with the people doing the review throughout.

Rocket above the Cyber Due Diligence call to action

Talk to us about your deal

Scope an IT due diligence

A free 45 minute call establishes the target, the deal timeline, the scope you need and the indicative fixed fee for a clear, acquirer-ready report. It is taken by a consultant from our 3DD practice, not a salesperson.