Technical Due Diligence for Software Acquisitions
Independent, senior-led and vendor-neutral — fixed-fee cyber security advisory for Australian government, councils and enterprise, led by a practitioner with 27 years hands-on.
What we assess
A complete, read-only review of the platform and the operation around it — corroborated with tooling and a manual review, not opinion.
Cloud infrastructure
Architecture, configuration, scalability and cost trajectory — what holds, and what needs a rebuild under growth.
Security posture
Exposure, identity and access, secrets, and whether it survives an enterprise customer’s vendor security review.
Code & engineering quality
Maintainability, test coverage, technical debt and the practices that determine future velocity.
CI/CD & release
Build, test and deployment pipelines — how safely and repeatably the team ships.
Data & disaster recovery
Backups, recoverability and resilience — tested reality, not documented intent.
Key-person & bus-factor risk
Whether the platform lives in one engineer’s head — the single most common value-destroyer in software deals.
Who it’s for
Investors & acquirers
Private equity, venture capital, growth equity, corporate development and M&A teams who need independent technical DD on a target — slotted straight into the existing deal checklist, alongside financial and legal.
Software founders & boards
Owners, CEOs and CTOs who want to know what an acquirer’s DD will find — before they find it — ahead of a raise, a sale, or a major customer’s security review.
Financial DD tells you what you’re paying. Technical DD tells you what you’re actually buying.
What you receive
Board- and investment-committee-ready deliverables, in plain English:
Executive Summary
The verdict and the material risks, written for decision-makers — repriceable issues flagged before completion.
Risk Matrix
Every finding rated by likelihood and business impact, so the deal team sees exactly where the exposure sits.
Findings Register
The full technical detail behind the summary — severity, evidence and root cause for each item.
Remediation Roadmap
A prioritised, costed plan — the basis for a post-completion fix program and a second, value-add engagement.
How it works
1. Scope & access — a short call to agree scope and read-only access; fixed fee confirmed up front. 2. Assess — independent, read-only review across every domain above, corroborated with tooling and manual review; the target’s production environment is never touched. 3. Report — board-ready deliverables in 10–15 business days, with an investment-committee briefing on the Comprehensive tier.
Engagement tiers
Smaller targets (single product, one cloud). Executive Summary, Risk Matrix and red-flags register. ~10 business days.
The core engagement. Full scope, independently corroborated, complete deliverable set. ~15 business days.
Larger, multi-product or regulated targets, or where the report goes to an investment committee. Includes a one-hour IC briefing.
DD Panel Partner — for investors and acquirers with regular deal flow: priority scheduling (kick-off within five business days), a standing NDA and engagement framework so each deal starts with one email, and panel pricing. No retainer.
Why independent matters
CISO Advisory sells no products, holds no reseller agreements and takes no referral commissions. A technical DD report is only worth the independence of the assessor — advice from a firm that profits from the remediation it recommends is conflicted by construction. Ours is not. Every finding is driven by the evidence and your deal, which is precisely what makes the report defensible to an investment committee, a lender or a counterparty.
Frequently asked questions
Who provides independent technical due diligence for software acquisitions in Australia?
CISO Advisory Australia provides independent, senior-led technical and security due diligence on software platforms for private equity, venture capital, corporate development and acquirers — fixed-fee per deal, read-only, with board-ready deliverables and coverage across Australia, New Zealand and Singapore.
What does technical due diligence cover?
Cloud infrastructure and scalability, security posture, identity and access, source and code quality, CI/CD pipelines, data and disaster-recovery resilience, observability, and key-person (bus-factor) risk — independently corroborated and delivered as a Risk Matrix, Findings Register and prioritised remediation roadmap.
How long does it take and what does it cost?
Typically 10 to 15 business days from access, at a fixed fee per deal — from $25,000 for smaller targets, $35,000 for the standard full-scope engagement, and $45,000 for larger, multi-product or regulated targets. The fee is confirmed up front after a short scoping call.
Is the target’s production environment at risk during the assessment?
No. The assessment is read-only — the target’s production systems are never touched. Access is agreed and scoped before work begins.
Can you also assess our own platform before a raise or sale (sell-side)?
Yes. The same independent assessment works sell-side for founders and boards who want to find and fix issues before an acquirer’s due diligence does — turning negotiation risks into remediation items while there is still time.
Have a software deal in the pipeline?
One scoping call and you’ll know whether independent technical due diligence fits the deal, how it would be scoped, and the fixed fee. Confidential, no obligation.
Independent, read-only platform assessment per deal — architecture, security, scalability and key-person risk for investment committees. Fixed fee per deal.
Talk to a senior advisor — confidential, no obligation.
We respond the same business day, Australia-wide. Tell us what you need to secure.