The verdict in three sentences
For a software acquisition valued between EUR 2 and 30 million, technical due diligence at EUR 8,000 to 30,000 excl. VAT is less than 0.5% of the price and feeds directly into valuation negotiation or warranties. The risks that cost most after closing rarely show in a demo: unpriced technical debt, contaminating open source licences, security flaws and the departure of a developer who alone holds the knowledge. A serious audit delivers a priced remediation cost and a 12-month plan, not just a score.
What technical due diligence costs in 2026
| Format | Scope | Duration | Budget excl. VAT (estimate) |
|---|---|---|---|
| Flash review | CTO interviews, architecture, automated static analysis | 5 to 7 days | EUR 8,000 to 12,000 |
| Standard audit | Code, dependencies, security, licences, infrastructure, team | 2 to 3 weeks | EUR 15,000 to 22,000 |
| Deep audit | Standard + penetration test, cloud review, scalability, GDPR | 3 to 4 weeks | EUR 22,000 to 30,000 |
| Licence scan option (SBOM) | Full inventory of open source components | 2 to 4 days | EUR 2,500 to 5,000 |
| Penetration test option | Web app and API, certified pentest report | 5 to 10 days | EUR 6,000 to 15,000 |
| Post-closing support | Remediation plan and 100-day programme | 3 months | EUR 10,000 to 25,000 |
Pricing depends on codebase size (50,000 lines or 1 million), number of products, stack and real repository access. A data room without code access limits the audit to a document review, far less reliable.
The method: what we check and what it costs when missed
| Audited area | Measured indicators | Typical cost if found after the deal |
|---|---|---|
| Code quality | Duplication, complexity, test coverage (often under 20%) | EUR 80,000 to 300,000 of refactoring |
| Dependencies | Outdated versions, end-of-life frameworks (PHP 7, AngularJS) | EUR 60,000 to 250,000 of upgrades |
| Security | OWASP vulnerabilities, secrets in the repo, access management | Incident: EUR 50,000 to 500,000 plus GDPR fine |
| Open source licences | GPL or AGPL components inside a proprietary product | Rewrite or forced open sourcing |
| Infrastructure | Cloud cost, backups, disaster recovery | 20 to 40% avoidable cloud overspend |
| Documentation | Architecture, deployment, procedures | 2 to 4 months of ramp-up |
| People | Bus factor, key developers, contractors | Key person leaves: 6 to 12 months slowdown |
The bus factor is often the most underrated point: if 70% of commits over the last two years come from one person, a retention clause or an earn-out tied to their presence becomes essential.
The 4-week process
- Week 1: repository and data room access, interviews with the CTO and developers, static analysis (SonarQube, Snyk, SBOM tools).
- Week 2: manual review of critical modules (payments, authentication, business calculations), infrastructure and cloud cost review.
- Week 3: security tests, licence analysis, assessment of the team and delivery processes.
- Week 4: report with red flags, priced remediation cost, recommendations for the purchase agreement.
Mini case study
Caroline, investment director at a growth equity fund in Paris, is preparing to buy an HR SaaS vendor valued at EUR 12 million (4 times its EUR 3 million ARR). The standard audit at EUR 19,000 reveals an end-of-life framework, 12% test coverage and an AGPL component in the payroll module. Estimated remediation cost: EUR 280,000 over 12 months. The fund secures a EUR 250,000 price reduction and a EUR 150,000 escrow for licence risks. Return: 13 times the audit cost, not counting the retention agreement signed with the lead developer, author of 64% of the code.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
When should technical due diligence start?
After the letter of intent and before the purchase agreement, alongside financial and legal audits. Allow 2 to 4 weeks to keep the closing timeline.
Can the seller refuse access to the code?
They can restrict it, but read access under NDA, sometimes on an isolated machine, is standard for any deal above EUR 1 million.
Is an automated tool enough?
No, static analysis covers roughly 30 to 40% of risks. Architecture, team and licence risks need experienced human review.
What does the final deliverable contain?
A 25 to 50 page report with an executive summary, a ranked risk register, a priced remediation cost and recommended clauses (escrow, warranties, retention).
Is the audit useful for the seller too?
Yes, vendor due diligence at EUR 10,000 to 20,000 excl. VAT, done 3 to 6 months before the sale, lets the seller fix red flags and defend the valuation.
Let's scope your project. Tell us the codebase size, stack and signing timeline, and we will scope the audit and deliver a priced report in 2 to 4 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
