A software company may present strong growth and an ambitious product roadmap. Its value, however, often depends on assets outside the scope of financial due diligence: source code, architecture, data, infrastructure, intellectual property and the engineering team.

Software due diligence tests whether those assets support the investment thesis. Licence conflicts, fragile infrastructure, unsupported dependencies or technical debt may change the valuation, deal terms or integration plan.

Key Takeaways

  • Code review is only one part of software due diligence.
  • Product ownership must be supported by contracts and code provenance.
  • Claimed alignment with a security framework, or a certification, is evidence to test—not proof that a product is secure.
  • Findings should be translated into remediation costs, integration work and appropriate deal protections.

What Is Software Due Diligence?

Software due diligence is a transaction-focused assessment of the technology behind a company’s value. Buyers commission it before an acquisition or major investment, while a company may use it for IPO or sell-side readiness.

The review centres on revenue-generating products and the systems needed to build, operate and secure them. Internal tools still matter if their failure could interrupt delivery, expose data or create key-person dependence.

Software due diligence is typically narrower than a full technology review, yet broader than a code audit or penetration test. It cannot prove that software has no defects. It tests management’s claims and explains what the evidence gaps mean for the transaction.

What Should a Software Due Diligence Review Cover?

The scope depends on the product, business model, jurisdictions and deal thesis. Most reviews examine the following areas.

Architecture and scalability

The reviewer maps the product, hosting, databases, integrations and critical data flows. For a SaaS company, this includes cloud configuration, availability, recovery, capacity and infrastructure costs. Can the design support projected growth without disproportionate spending or a high-risk rebuild?

Code quality and engineering practices

Code should be assessed with repository history, documentation, automated tests, release processes and defect records. Poor documentation, limited testing or knowledge concentrated in one engineer can increase integration risk and future development costs.

Intellectual property and open-source software

The target should show that it owns, or has valid rights to use, the technology in its product. Reviewers examine employee and contractor assignments, third-party agreements and open-source components. Technical evidence can help trace code provenance; legal counsel should confirm title and licence obligations.

Open-source software can be used commercially, but licences impose different conditions. Depending on how a component is used, modified, combined and distributed, obligations may include notices, attribution or disclosure of corresponding source code. Component inventories must therefore be matched to the actual licence terms.

Dependencies and software supply chain

Modern products rely on libraries, APIs, cloud services and external vendors. Reviewers should identify unsupported components, known vulnerabilities, restrictive licences, poor dependency pinning, weak patch management and single points of failure. A current software bill of materials helps, but does not replace analysis.

Security, privacy and compliance

Cybersecurity due diligence should consider access controls, vulnerability management, encryption, logging, incidents, secure development and recovery. The NIST Cybersecurity Framework and Secure Software Development Framework provide useful reference points; claimed alignment does not prove that controls operate effectively.

Legal requirements depend on the target’s data, customers and jurisdictions. GDPR security duties apply where processing falls within the Regulation’s scope; the HIPAA Security Rule covers electronic protected health information handled by regulated US entities. ISO/IEC 27001 certification is evidence of an information security management system within its stated scope, not a guarantee that every product is secure.

Technical debt and operational resilience

Technical debt is future cost or risk created by earlier design and implementation choices. Reviewers should separate manageable backlog items from structural issues that threaten reliability, security or the roadmap. They should also assess backup restoration, incident response, monitoring, rollback and key-person dependence.

How to Conduct Software Due Diligence

1. Define the transaction questions

Start with the decision, not a standard checklist. A growth investor may test scalability; a strategic acquirer may focus on integration and IP ownership. The scope should identify the products, repositories, environments, entities and periods under review.

2. Collect evidence

Evidence may include architecture diagrams, repositories, roadmaps, cloud costs, test results, incident logs, security policies, licence inventories, vendor contracts and staff interviews. The report should separate verified findings, management statements and unresolved questions.

3. Test claims across sources

No single metric establishes software quality. Repository activity, deployments, incidents and interviews should be compared with the stated development process. Automated scans can flag possible issues, but judgement is needed to assess materiality and false positives.

4. Translate findings into deal consequences

A useful report ranks issues by severity, evidence and business impact. Where possible, it estimates remediation cost, timing and ownership. Findings may support a valuation adjustment, warranties or indemnities, pre-closing remediation, retention measures or a post-acquisition plan.

Software Due Diligence Is One Part of the Transaction

A sound product does not remove risks surrounding the company that owns it. Buyers may still need corporate due diligence to verify beneficial ownership, founders and key executives, related parties, litigation, sanctions exposure, major vendors and public claims.

Molfar Intelligence complements technical review through due diligence services that investigate the corporate, reputational and cyber-risk context around a target. Combining those findings with software, financial and legal due diligence gives decision-makers a clearer basis for proceeding, renegotiating or pausing before capital is committed.

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
No items found.
View all
View all
White Plus Icon
Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Our cases

Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.

View all cases
View all cases
White Plus Icon
Expanded Plus Icon

Investor Due Diligence: Mitigating Reputational Risks in Defence Tech

Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.

Investment

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Pre-Employment Screening for a Spacecraft Manufacturing Role

Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.

Space

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Sanctions Gaps — Supercam Drone Production Continues

Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.

Finance

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Cybersecurity Audit and Internal Data Exposure Mitigation

Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.

Cybersecurity

Learn more
Learn more
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.