How SOC 2 and Security Posture Change M&A Due Diligence
A buyer's diligence team found an unresolved ransomware incident from 14 months earlier, disclosed to nobody, in the target's help desk tickets. The deal closed anyway. It closed 90 days late, with $2 million held in escrow against cyber liabilities, a required remediation program written into the agreement, and a purchase price that had absorbed the cost of both.
Ten years ago security was a paragraph in the IT section of a diligence report. On any deal involving customer data, software, or meaningful technology dependence, it now gets its own workstream, its own findings, and its own line items in the purchase agreement. We work both sides of this: our firm runs SOC 2 examinations as a licensed CPA firm, and our deal teams run technology and cybersecurity diligence inside M&A transactions. This article is what that vantage point teaches.
Why buyers started caring
Three forces pushed security into the deal file.
Deals now transfer data liabilities. When you buy a company, you buy its breach history, including the breaches nobody has found yet. Regulators and plaintiffs do not care that the incident predates your ownership.
Insurance stopped absorbing the risk quietly. Cyber insurers ask hard questions at underwriting and renewal, and an acquisition that degrades the combined company's security posture shows up in premium and coverage terms.
And buyers got burned in public. The pattern of acquirers discovering breaches after closing, then paying for them in fines, litigation, and remediation, taught the market that security diligence is cheaper than security surprise.
What buyers actually check
The security workstream in diligence is more specific than a general sense of good security. Expect requests for:
Certifications and reports. SOC 2 Type 2 reports, ISO 27001 certificates, PCI attestations where relevant. Buyers read the exceptions and the scope carefully, and a report with a carved-down scope raises more questions than it answers.
Penetration test history. The last two or three test reports, who performed them, and what happened to the findings. A pen test with the same critical finding open across two consecutive years tells a buyer the security program is paper.
Incident history. Breaches, near misses, ransomware events, and the help desk tickets that reveal what never got formally reported. Undisclosed incidents found in diligence do more damage to trust than the incidents themselves.
Access and identity basics. Offboarding discipline, admin account sprawl, MFA coverage. Cheap to check, and a reliable proxy for operational maturity.
Vendor and data-flow exposure. Where customer data lives, which third parties touch it, and what the contracts promise customers about it. Those promises transfer to the buyer at closing.
What a SOC 2 report proves in a deal, and what it doesn't
A current SOC 2 Type 2 report is the single most useful security document in a data room. It gives the buyer a year of independently tested evidence that defined controls operated, which collapses weeks of diligence questions into a document review.
Know its limits. A SOC 2 report covers the systems and criteria in its scope, tested against the company's own control descriptions. It is not a penetration test, it does not evaluate the product's code, and a clean report over a narrow scope can coexist with real exposure outside that scope. Sophisticated buyers read the system description first for exactly this reason.
The practical translation: SOC 2 accelerates diligence and builds credibility. It does not replace the security workstream, and sellers who present it as a shield invite deeper digging.
Where security findings hit the deal
Security findings land in five places, in escalating order of pain: the diligence timeline, when findings trigger deeper investigation; the price, when remediation costs and risk get quantified and deducted; the structure, when specific exposures move into escrows and indemnities; the covenants, when the agreement requires remediation by defined dates; and the deal itself, in the rare cases where an unresolved incident or a fundamental trust break kills it.
The mechanics matter for sellers. A $400,000 remediation project you complete before going to market costs $400,000. The same gap discovered by a buyer costs more than the remediation would have, because buyers price the uncertainty on top of the work.
The seller's playbook
Start 6 to 12 months before a process. Get the SOC 2 or ISO 27001 program current if customers already expect it. Run a penetration test and close the findings, because a test with closed findings is an asset and a test with open ones is a liability. Document your incident history honestly and completely; disclosure controlled by you beats discovery controlled by them. Fix the access hygiene, since it costs almost nothing and reads as competence. This is standard scope inside sell-side exit readiness.
If there is no security leadership at all, a fractional CISO engagement in the year before a sale is one of the few pre-market investments that shows up directly in diligence outcomes.
The buyer's playbook
Put security in the letter-of-intent timeline explicitly so the workstream has room to run. Ask for the SOC 2, the pen tests, and the incident log in the first document request, and read the scopes before the conclusions. Interview whoever runs security without the CEO in the room. Price what you find, even roughly: a security finding without a dollar figure attached will not survive the negotiation, and a quantified one usually does.
Then carry the findings into integration planning, because the gaps you priced at closing become your remediation program on day one.
One team, both lenses
Security diligence works best when the people reading the SOC 2 report have written SOC 2 reports, and when the people pricing the findings sit inside the deal team rather than beside it. That combination is unusual, and it's the one we built: audit practice and transaction diligence under the same roof, findings connected to price and terms rather than filed as an appendix.
If a transaction is on your horizon in either direction, the security conversation is worth having before the data room opens.
