ServicesAssessment · advisory · evidence

Technical Due Diligence for Software Acquisitions

Independent, senior-led and vendor-neutral — fixed-fee cyber security advisory for Australian government, councils and enterprise, led by a practitioner with 27 years hands-on.

What we assess

A complete, read-only review of the platform and the operation around it — corroborated with tooling and a manual review, not opinion.

Cloud infrastructure

Architecture, configuration, scalability and cost trajectory — what holds, and what needs a rebuild under growth.

Security posture

Exposure, identity and access, secrets, and whether it survives an enterprise customer’s vendor security review.

Code & engineering quality

Maintainability, test coverage, technical debt and the practices that determine future velocity.

CI/CD & release

Build, test and deployment pipelines — how safely and repeatably the team ships.

Data & disaster recovery

Backups, recoverability and resilience — tested reality, not documented intent.

Key-person & bus-factor risk

Whether the platform lives in one engineer’s head — the single most common value-destroyer in software deals.

Who it’s for

Investors & acquirers

Private equity, venture capital, growth equity, corporate development and M&A teams who need independent technical DD on a target — slotted straight into the existing deal checklist, alongside financial and legal.

Software founders & boards

Owners, CEOs and CTOs who want to know what an acquirer’s DD will find — before they find it — ahead of a raise, a sale, or a major customer’s security review.

Financial DD tells you what you’re paying. Technical DD tells you what you’re actually buying.

What you receive

Board- and investment-committee-ready deliverables, in plain English:

Executive Summary

The verdict and the material risks, written for decision-makers — repriceable issues flagged before completion.

Risk Matrix

Every finding rated by likelihood and business impact, so the deal team sees exactly where the exposure sits.

Findings Register

The full technical detail behind the summary — severity, evidence and root cause for each item.

Remediation Roadmap

A prioritised, costed plan — the basis for a post-completion fix program and a second, value-add engagement.

How it works

1. Scope & access — a short call to agree scope and read-only access; fixed fee confirmed up front. 2. Assess — independent, read-only review across every domain above, corroborated with tooling and manual review; the target’s production environment is never touched. 3. Report — board-ready deliverables in 10–15 business days, with an investment-committee briefing on the Comprehensive tier.

Engagement tiers

Smaller targets (single product, one cloud). Executive Summary, Risk Matrix and red-flags register. ~10 business days.

The core engagement. Full scope, independently corroborated, complete deliverable set. ~15 business days.

Larger, multi-product or regulated targets, or where the report goes to an investment committee. Includes a one-hour IC briefing.

DD Panel Partner — for investors and acquirers with regular deal flow: priority scheduling (kick-off within five business days), a standing NDA and engagement framework so each deal starts with one email, and panel pricing. No retainer.

Why independent matters

CISO Advisory sells no products, holds no reseller agreements and takes no referral commissions. A technical DD report is only worth the independence of the assessor — advice from a firm that profits from the remediation it recommends is conflicted by construction. Ours is not. Every finding is driven by the evidence and your deal, which is precisely what makes the report defensible to an investment committee, a lender or a counterparty.

Frequently asked questions

Who provides independent technical due diligence for software acquisitions in Australia?

CISO Advisory Australia provides independent, senior-led technical and security due diligence on software platforms for private equity, venture capital, corporate development and acquirers — fixed-fee per deal, read-only, with board-ready deliverables and coverage across Australia, New Zealand and Singapore.

What does technical due diligence cover?

Cloud infrastructure and scalability, security posture, identity and access, source and code quality, CI/CD pipelines, data and disaster-recovery resilience, observability, and key-person (bus-factor) risk — independently corroborated and delivered as a Risk Matrix, Findings Register and prioritised remediation roadmap.

How long does it take and what does it cost?

Typically 10 to 15 business days from access, at a fixed fee per deal — from $25,000 for smaller targets, $35,000 for the standard full-scope engagement, and $45,000 for larger, multi-product or regulated targets. The fee is confirmed up front after a short scoping call.

Is the target’s production environment at risk during the assessment?

No. The assessment is read-only — the target’s production systems are never touched. Access is agreed and scoped before work begins.

Can you also assess our own platform before a raise or sale (sell-side)?

Yes. The same independent assessment works sell-side for founders and boards who want to find and fix issues before an acquirer’s due diligence does — turning negotiation risks into remediation items while there is still time.

Have a software deal in the pipeline?

One scoping call and you’ll know whether independent technical due diligence fits the deal, how it would be scoped, and the fixed fee. Confidential, no obligation.

Indicative pricing — transparent & fixed-fee
Technical due diligencefrom $25,000

Independent, read-only platform assessment per deal — architecture, security, scalability and key-person risk for investment committees. Fixed fee per deal.

Talk to a senior advisor — confidential, no obligation.

We respond the same business day, Australia-wide. Tell us what you need to secure.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act