Published, banded by deal size

Due Diligence Pricing: Cyber, Technology and IT

Indicative fixed-fee prices for the three reviews our 3DD practice delivers: cyber, technology and IT due diligence, each priced by deal size and scope. Where the rest of the market shares figures only once you are on a call, we set our ranges out up front. Every review is delivered in-house by CyPro's 3DD practice, and your engagement is confirmed at scoping.

Indicative pricing

Three reviews, priced up front

Where most reviews start

Cyber Due Diligence

The target's security posture, breach history and the cyber risk that bears on the deal

From £6,500

per deal, indicative, ex VAT

  • Sub-£10m deal from £6,500; £10m to £50m from £11,000; £50m and above from £18,000
  • Assessment of the target's security posture, controls and any live or historical compromise
  • The cyber exposure that touches valuation, warranties and the first 100 days after completion
  • Red-amber-green findings the deal team can act on before signing
  • Delivered in-house by CyPro's 3DD practice, the same team from scoping to report
What this covers

Technology Due Diligence

The target's architecture, code, scalability, technical debt and engineering team

From £9,500

per deal, indicative, ex VAT

  • Sub-£10m deal from £9,500; £10m to £50m from £16,000; £50m and above from £28,000
  • Architecture, code quality, scalability and the technical debt carried into the deal
  • The engineering team, delivery process and key-person risk
  • Product and platform risk that shapes the investment case and the value-creation plan
  • Delivered in-house by CyPro's 3DD practice
What this covers

IT Due Diligence

The target's IT estate, infrastructure, licensing and the cost of integration

From £5,500

per deal, indicative, ex VAT

  • Sub-£10m deal from £5,500; £10m to £50m from £9,500; £50m and above from £15,000
  • Infrastructure, systems and the real state of the IT estate
  • Licensing exposure, key contracts and the cost of integration or separation
  • Operational IT risk in the target's day-to-day systems
  • Delivered in-house by CyPro's 3DD practice
What this covers

Commissioned together

A full pre-acquisition review, scoped as one

Cyber, technology and IT due diligence across a single target

From £18,000

combined, indicative, ex VAT

Most acquirers commission all three strands for a full view of the target. Where that applies, the reviews are scoped and priced as a single managed engagement, delivered by one 3DD team and reported together, rather than billed apart. The combined figure is confirmed for your deal at scoping. How the process runs.

Preparing to sell

Sell-side vendor preparation

The same review, run for a vendor readying a business for sale

Scoped per deal

priced from the relevant review above

A buy-side acquirer commissions due diligence before they sign. A vendor can run the same review before going to market, to find and fix what a buyer would otherwise raise. Sell-side work is priced from the relevant service line above, adjusted for the scope a vendor preparation needs. Buy-side and sell-side.

What sets the fee, stated plainly

The figures above are indicative fixed-fee "from" prices, not quotes, and are confirmed for your deal at scoping. Two things set the fee: deal size, because a sub-£10m deal carries less to review than a £50m-plus one, and scope, meaning how many of the three strands you commission and how deep each needs to go. Fees exclude VAT. Every review is delivered in-house by CyPro's 3DD practice; you deal with one team from the scoping call to the final report.

For comparison

Three ways to buy due diligence, side by side

This market is quote-only from end to end: the specialist boutiques and the large advisory firms alike hide the figure until you have had a call. A specialist review delivered in-house gives you deal- focused findings with the scope certainty of a published price, and the table shows the differences.

Quote-only boutique Large advisory firm Due diligence by CyPro's 3DD practice
Pricing Quoted only after a call, no figure published Quoted after scoping, day-rate led Indicative fixed-fee prices, published on this page
Who performs it Their own consultants A large team, due diligence is one of many practices CyPro's 3DD practice, in-house, the same team throughout
Scope certainty Unknown until you are quoted Unknown until you are quoted Fixed fee against agreed scope, banded by deal size
Strands covered Often a single strand Broad, but generalist on cyber Cyber, technology and IT in one place, scoped as one
What you leave with A report A report Red-amber-green findings the deal team can act on, and a debrief

Asked about the fees

Pricing, explained further

Why show fees up front when the rest of the market keeps them back?

Because a scoped review carries a knowable cost, and holding the figure back tends to suit the seller more than the buyer. Others in this space reveal a number only once you are on a call, and while a few will talk about what it costs, none put a figure in writing. We would rather put indicative prices on the page from the outset, the open pricing CyPro applies right across its specialist services. That way a deal team can plan and compare before speaking to anyone, and your engagement is still confirmed at scoping.

Are these fixed fees?

They are indicative fixed-fee 'from' prices, not quotes. What sets the final figure is the size of the deal and the scope of the review: how many of the three strands you commission, the size and complexity of the target, and the depth the deal calls for. Where the scope is clear, we hold the engagement to a fixed fee rather than an open day rate, which is the whole point of publishing them.

Who actually carries out the due diligence?

CyPro's own 3DD practice, in-house, from the scoping call to the final report. The work is not subcontracted to a delivery partner, so you deal with one team throughout and the people who scope the review are the people who run it. 3DD is CyPro's due diligence methodology, and the same practice delivers cyber, technology and IT due diligence.

Which of the three do we need?

Cyber due diligence covers the target's security posture and breach risk. Technology due diligence covers its architecture, code, scalability and engineering team. IT due diligence covers the IT estate, infrastructure, licensing and integration cost. Most pre-acquisition reviews take all three, scoped and priced as one engagement, but you can commission a single strand. The scoping call confirms what the deal actually needs.

See how the process runs

Does the fee include fixing what you find?

The fee covers an independent review and a prioritised, red-amber-green view of the risk, which is the point of due diligence: a clear-eyed read of the target, not a sales pitch for remediation. Acting on the findings sits with the target's team or yours post-completion; where you want hands-on support closing the gaps after the deal, we scope that as a separate engagement. None of the figures above hides a retainer.

Rocket above the Cyber Due Diligence call to action

Prices published, scope confirmed on a call

Find the review that fits your deal

One scoping call, taken by a consultant from our 3DD practice, confirms which strands the deal needs, the deal-size bracket you sit in, and the fixed fee for a clear, deal-ready review.