The verdict in three sentences
When software represents more than 30% of a target's value, technical due diligence at 8,000 to 25,000 EUR (6,800 to 21,500 GBP) over 2 to 4 weeks is the cheapest insurance in the deal. It turns vague risks into priced figures: remediation cost, security flaws, incompatible licences, reliance on one or two developers. These figures feed directly into price negotiation, an escrow or the warranties and indemnities in the SPA.
What technical due diligence checks
A London private equity fund or a trade buyer is not looking for perfect code. It wants to know how much remediation will cost and whether the software can support the 5-year business plan.
| Audit area | What is measured | Red flag |
|---|---|---|
| Technical debt | complexity, duplication, test coverage | coverage under 20%, unsupported frameworks |
| Security | OWASP Top 10, vulnerable dependencies, secrets in code | critical CVEs unpatched for over 6 months |
| Open source licences | SBOM inventory, compatibility with commercial use | GPL or AGPL components in a proprietary SaaS |
| Key people | share of commits per developer, documentation | over 70% of code written by one person |
| Architecture and scalability | ability to absorb 3x or 5x users | single saturated database, no environment separation |
| Compliance | UK GDPR, hosting, logging | health data outside compliant hosting |
| Intellectual property | IP assignment from freelancers and contractors | missing assignment agreements |
Price and timeline by target size
Cost depends on code volume, number of applications and expected depth (tool report review or in-depth manual review).
| Target profile | Codebase size | 2026 price | Timeline |
|---|---|---|---|
| SME, single app, 2 to 4 developers | under 100,000 lines | 8,000 to 12,000 EUR | 2 weeks |
| SaaS vendor, 5 to 15 developers | 100,000 to 400,000 lines | 12,000 to 18,000 EUR | 3 weeks |
| Multi-product platform with mobile app | over 400,000 lines | 18,000 to 25,000 EUR | 3 to 4 weeks |
| Penetration test option | web and API scope | 5,000 to 12,000 EUR | 1 to 2 weeks in parallel |
| Cloud infrastructure review option | AWS, Azure, GCP | 3,000 to 6,000 EUR | 1 week |
Access usually runs through the data room, with read access to the Git repository and 3 to 5 interviews with the CTO and team, under NDA.
From audit to purchase price
The report should not just list defects. It must produce a priced remediation plan, ranked in three categories: blocking before completion, to address within 12 months, to monitor.
| Typical finding | Estimated remediation cost | Usual legal treatment |
|---|---|---|
| End-of-life framework (e.g. AngularJS, PHP 7) | 60,000 to 180,000 EUR | price reduction |
| AGPL component in the SaaS core | 15,000 to 50,000 EUR to replace | condition precedent or specific warranty |
| Exploitable critical vulnerability | 5,000 to 20,000 EUR | fix before completion |
| Missing freelancer IP assignment | 2,000 to 10,000 EUR (to regularise) | condition precedent to completion |
| Key developer dependency | 40,000 to 90,000 EUR (hiring, handover) | retention package or earn-out |
Mini case study
Caroline, investment director at a London fund, is assessing the acquisition of a SaaS vendor serving architecture firms, valued at 6 million EUR (5x EBITDA of 1.2 million). The audit, billed 16,000 EUR over 3 weeks, reveals an AngularJS front end out of support since 2022 (rebuild estimated at 140,000 EUR), an AGPL component to replace (30,000 EUR) and 78% of commits made by the co-founder.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Total remediation identified: 170,000 EUR, plus a 24-month co-founder retention plan. The fund secures a 150,000 EUR price reduction and a 100,000 EUR escrow backed by the warranties. Ratio of negotiated gain to audit cost: 150,000 / 16,000, more than 9 times the outlay.
FAQ
When in the process should the audit start?
After the heads of terms and before signing the SPA, ideally during exclusivity. Allow 2 to 4 weeks in the timetable, alongside legal and financial due diligence.
Must the seller grant access to the source code?
Yes, read-only and under NDA. If access is refused, the audit is limited to interviews and tool reports, which cuts its reliability by roughly 40 to 50%.
How does it differ from a standard security audit?
A security audit covers one area. Technical due diligence also prices debt, licences, key people and scalability, which feeds directly into valuation.
Can the findings be built into the warranties?
Yes. Identified risks become specific seller warranties or indemnities, with a cap and duration, often 18 to 36 months, or justify an escrow of 5 to 15% of the price. W&I insurers also read the report.
Should we audit again after the acquisition?
A follow-up audit 6 to 12 months after completion, for 4,000 to 8,000 EUR, checks remediation progress and supports investor reporting.
Let's scope your project. Describe the target, its stack and your deal timetable: we will propose technical due diligence at 8,000 to 25,000 EUR delivered in 2 to 4 weeks under NDA. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.