The Technology Due Diligence Red Flags That Kill Deals
Most technology diligence findings get priced rather than proving fatal. Six categories are different, because they either reprice a deal by 5 to 15 percent of enterprise value or end it outright: key-person concentration, unlicensed open source in the core product, cloud costs growing faster than revenue, security debt that transfers as buyer liability, roadmap fiction, and integration impossibilities. What they share is that none of them appears in a management presentation. Each shows up in commit history, cloud invoices, dependency manifests, customer contracts, and conversations with engineers who were not prepped. Below is how each one surfaces and what it does to price once it does.
Key-person concentration
How it surfaces: commit history by author over 24 months, the on-call rotation, who has deployed to production in the last quarter, and the bus factor question asked separately of three people who all name the same engineer. The threshold worth flagging is one person authoring more than half the commits to revenue-critical services, or being the only person who has ever touched billing, provisioning, or the pricing engine.
What it does to price. Retention packages for one to three people typically cost 15 to 40 percent of base salary and get funded out of the purchase price. Buyers commonly hold 3 to 10 percent of consideration in escrow tied to 12 to 24 months of retention. Where nothing has been written down, the buyer also prices 6 to 12 months of reduced velocity while someone else learns the system.
Deals die here in one specific pattern: the key engineer is related to the departing founder, is not staying, and will not sign anything. At that point the buyer is purchasing a codebase without its operating manual, and most strategic acquirers would rather build.
Unlicensed open source in the core
How it surfaces: software composition analysis run against the actual repositories, not a questionnaire answer. The findings that matter are copyleft licenses such as GPL, AGPL, or SSPL linked into a product that is distributed or hosted, dependencies with missing license metadata, code lifted from public forums or a former employer without attribution, and the total absence of a license policy or a software bill of materials. Check customer contracts in parallel, because a source escrow clause or an on-premise deployment right converts a hosting question into a distribution question.
What it does to price. Replacing a copyleft component on a non-core path runs $25,000 to $150,000 of engineering time. When it sits underneath the actual differentiator, the buyer is pricing a rewrite, which means two to four quarters of the engineering team's capacity and a paused roadmap. Responses range from a special indemnity to an escrow of 2 to 8 percent held 18 to 24 months to a straight price reduction.
Strategic buyers walk away from this more often than financial buyers do, because after integration the exposure attaches to their entire codebase rather than a standalone asset.
Cloud costs scaling faster than revenue
How it surfaces: eight to twelve quarters of cloud invoices placed next to revenue for the same periods. Look at infrastructure cost per dollar of revenue as a trend rather than a snapshot, cost per customer wherever tagging allows it, commitment and reserved capacity coverage, and whether the architecture is single-tenant in a way that makes every new customer add fixed cost. Check what is being capitalized while you are there.
What it does to price. This is the finding that moves the multiple rather than the price, because it corrects gross margin. A 5 to 10 point margin correction on a business valued against revenue changes value more than any one-time remediation on this list, and it is close to unarguable, because invoices are invoices.
Buyers also discount the standard answer that costs will be optimized after close. A 20 to 40 percent reduction is achievable in most neglected estates, but it consumes engineering capacity that competes directly with the roadmap the buyer just paid for. Sellers who instrument unit economics before a process get to make that argument with data instead of intent.
Security debt that becomes buyer liability
How it surfaces: an external attack surface scan, a review of identity and privileged access configuration, and reading customer contracts against actual practice. The findings that change deals are an unreported incident discovered during diligence, production data sitting in test environments, administrative accounts without multi-factor authentication, shared root credentials, internet-facing systems missing patches for known exploited vulnerabilities, and contractual security commitments the target does not meet, whether that is a promised SOC 2 report, an encryption standard, a breach notification window, or a testing cadence.
Why it transfers: the buyer inherits both the data and the notification obligations. A breach discovered after close involving pre-close data is operationally and reputationally the buyer's problem even where the purchase agreement allocates the cost cleanly.
What it does to price. Expect escrow or a special indemnity of 1 to 5 percent of enterprise value held 12 to 24 months, remediation budgets of $100,000 to $750,000 depending on scale, and a 60 to 120 day delay when the buyer insists on a penetration test and remediation before signing. Deals end when there is an active compromise, or when the target has been selling a compliance posture it never had. We go deeper on that workstream in SOC 2 and cybersecurity in M&A due diligence.
Roadmap fiction
How it surfaces: compare the roadmap in the diligence deck against sprint history, the headcount plan, and repository activity. Ask which named engineer owns each item, and what percentage of committed scope actually shipped in each of the last four quarters. The tell is a feature that appears in the growth model with no design work, no assigned team, and no code, or a demo that exists as a prototype shown to three friendly customers and nowhere else.
The thresholds worth pricing: a team consistently delivering under 60 percent of committed scope, and any plan where 30 percent or more of forward revenue depends on product that has not been built.
What it does to price. This one rarely kills a deal and almost always restructures it. Buyers discount forward revenue, shift consideration into an earnout tied to delivery milestones, or extend the payout period. The practical outcome is that the seller carries the delivery risk they had been presenting as certainty, which is usually a worse trade than accepting a lower headline number.
Integration impossibilities
Mostly a strategic buyer problem, and the most common source of a late no. How it surfaces: an architecture review against the acquirer's own stack, plus an integration estimate built by the engineers who would actually do the work rather than by the corporate development team. The blockers repeat: a different cloud provider with enough data gravity to make migration a multi-quarter project, a monolith with no API surface to integrate against, hard-coded single tenancy that cannot express the acquirer's customer model, an identity layer that cannot accept the acquirer's single sign-on, and data schemas that cannot be reconciled without a mapping project nobody scoped.
What it does to price. Integration cost commonly lands at two to five times the number in the model. A $3 million synergy case that needs $8 million and 18 months of engineering stops being a synergy case, and the deal fails on the buyer's own math rather than on anything the seller did wrong. When the deal survives, it survives as a standalone hold with the synergy value stripped out, which is a materially lower price.
How a finding becomes a number
Every technology finding resolves into one of four mechanisms, and knowing which one applies is most of the negotiation.
- One-time cost. Fixable with money and time: license replacement, security remediation, cloud optimization. Comes off the price close to dollar for dollar, sometimes with a contingency on top.
- Recurring economics. Anything that changes gross margin or run-rate cost. Hits the multiple, which is why cloud unit economics is the most expensive category on this list.
- Contingent exposure. Real risk with an uncertain probability, such as an intellectual property claim or an undisclosed incident. Handled with escrow, a special indemnity, or representation and warranty insurance rather than price.
- Delivery risk. Value that depends on work not yet done. Handled by restructuring consideration into earnouts and holdbacks.
Sellers lose money by conceding a price reduction for something that belonged in escrow. Buyers lose by accepting an escrow for a problem that permanently changed the economics.
Surfacing these before a buyer does
Sell-side technology diligence run 6 to 12 months ahead of a process costs a fraction of what these findings cost inside a negotiation, mostly because the fixable ones stop being findings. A workable order of operations: run composition analysis and clear license problems first, since they take the longest to remediate; instrument cloud cost per customer so gross margin is defensible with data; close the security items that appear on every buyer's list; document the systems only one person understands, and have someone else deploy them; then rebuild the roadmap so every item has a named owner and a date the engineering team actually believes. Our software due diligence checklist is the working version of that list.
Where BD Emerson fits
We run software due diligence for buyers with engineers who read the code, the invoices, and the contracts rather than the data room summary, and deliver findings sorted by which of the four mechanisms applies so the deal team knows what to negotiate. On the sell side, our technology due diligence consulting work runs the same tests early enough that most of what a buyer would find has already been fixed or documented, which is the cheapest version of this exercise available.
