Commercial Due Diligence

We test whether the market and the customers support the price. Market sizing, win rates, cohort retention, pricing power, and 12 to 20 customer reference calls, built into a bottoms-up revenue forecast your investment committee can defend.
Contact us
Definition

What is commercial due diligence?

Commercial due diligence, sometimes called strategic due diligence, tests whether the market and the customers support the price you are paying. It answers four questions: how big the market really is and how fast it grows, whether this company wins or loses against the competitors it meets in deals, whether its customers stay and spend more, and whether its prices hold. BD Emerson builds a bottoms-up revenue forecast from cohort data, win-loss records, and 12 to 20 customer reference calls, then reconciles it against management's plan. The gap between those two numbers is the finding that moves price.

  • Market and growth: the addressable market built from qualifying buyers and spend per buyer, and the growth rate the forecast actually assumes.
  • Customer evidence: cohort revenue retention against logo retention, net revenue retention by segment, and top-ten customer share with contract expiry dates.
  • Pricing power: realized price against list, discount depth across the last eight quarters, and what happened the last time the company raised prices.
  • Forecast credibility: management's plan rebuilt from the bottom up, with the gap between the two explained driver by driver.
Services

What does commercial due diligence cover?

BD Emerson's commercial due diligence services run nine workstreams in parallel across three to five weeks. Each one produces a number that lands in the model.

Market sizing and growth rate
Competitive position and win rates
Customer concentration and retention
Pricing power and discounting
Customer reference calls
Channel and route to market
Sales pipeline quality
Management forecast stress test
Synergy and cross-sell validation

Market sizing and growth rate

We build the addressable market from the bottom up: the number of qualifying buyers, current spend per buyer, and realistic penetration. Then we test the growth rate the model assumes against unit demand, price, and mix, and show which of the three is carrying the forecast.

More

Competitive position and win rates

We map the company against the four or five competitors it actually meets in deals. Win rate by segment, deal size, and competitor, drawn from CRM records rather than management recollection. Lost deals get more attention than won ones, because the reasons buyers give for choosing someone else predict the next twelve months better than the wins do.

More

Customer concentration and retention

Top-ten customer share of revenue and gross margin, contract expiry dates for each, and renewal terms including auto-renew and termination for convenience. We separate logo retention from cohort revenue retention and report net revenue retention by cohort year, because a business can hold 95 percent of its logos while losing 15 percent of its dollars.

More

Pricing power and discounting

Realized price against list price by segment and year, then discount depth and frequency across the last eight quarters, which is where discount creep shows up before it reaches reported revenue. We also test the last price increase: how much of it stuck, who churned, and whether the company has the pricing authority the plan assumes.

More

Customer reference calls

We run 12 to 20 calls with current customers, churned customers, and buyers who chose a competitor. The seller approves every name before a call is placed, and calls run blind or disclosed depending on the stage of the process. Reference calls surface switching intent, budget pressure, and unpriced product gaps that no data room document records.

More

Channel and route to market

Direct sales, partners, resellers, and marketplaces, each measured on cost to acquire, margin retained, and concentration. Where a partner controls the customer relationship, we test what happens to renewals if that partner is acquired or changes its terms.

More

Sales pipeline quality

Pipeline coverage against quota, stage conversion rates, average age by stage, and how much of next year's plan already sits in the pipeline today. We flag opportunities that have been re-dated more than twice, which close at a fraction of the rate the forecast assumes.

  • Coverage ratio by quarter and segment
  • Stage conversion and slip rates
  • Average deal age against the stated sales cycle
  • Re-dated opportunities and their historical close rate
  • Committed pipeline against the plan's first two quarters
  • Quota capacity and the count of fully ramped reps
More

Management forecast stress test

We rebuild the forecast from the bottom up using customers, price, volume, and hiring, then set it against management's plan and explain every dollar of difference. The output is a base case, a downside, and the specific assumptions that separate them.

  • Bottoms-up rebuild from customers, price, and volume
  • Bridge from the current run rate to plan year one
  • Headcount and capacity required to deliver the plan
  • Base case and downside with named assumptions
  • Forecast accuracy over the last three years
  • The gap to management's plan, quantified
More

Synergy and cross-sell validation

Where the thesis depends on cross-sell or a revenue synergy, we test it with the customers who would have to buy. Named accounts, expected attach rate, price point, and time to first dollar, with the share we judge unsupported called out separately.

  • Named accounts that would have to buy
  • Attach rate tested against reference calls
  • Price point and time to first dollar
  • Channel conflict from overlapping partners
  • Cost to deliver the cross-sell
  • The share of claimed synergy we judge unsupported
More
Our approach

How we run a commercial due diligence engagement

Three to five weeks from kickoff to final report, run on the deal timetable. Seven steps, each one producing a number that goes into the model.
01

Scope and hypotheses

Week 1. We agree the three to five questions that would actually change the price, then design the workplan around them. The deliverable is a hypothesis map with the evidence needed to confirm or kill each one.

02

Data request and extract

Week 1. We pull the transaction-level data behind the reported numbers: invoices by customer and month, CRM opportunity history, contract files, and the price book. Revenue by segment on a summary tab is not enough to rebuild cohorts.

03

Bottoms-up market build

Weeks 1 to 2. Qualifying buyers, spend per buyer, and realistic penetration, tested against third-party data and the company's own win rates. We report the growth rate the evidence supports, not the one the deck assumes.

04

Customer and pricing analytics

Weeks 2 to 3. Cohort retention, net revenue retention, top-ten concentration, contract expiry dates, realized price, and discount trend across eight quarters. Every chart traces back to source data the seller can reproduce.

05

Reference call program

Weeks 2 to 4. Twelve to twenty calls with current customers, churned customers, and lost prospects, run under confidentiality terms the seller approves in writing. Findings are reported in aggregate and quotes are anonymized.

06

Forecast stress test

Week 4. We rebuild the plan from the bottom up, bridge it to management's forecast driver by driver, and quantify the gap. The base case and the downside come out of the same model.

07

Report and price implication

Weeks 4 to 5. Findings with dollar impact, the diligence questions still open, the negotiation points they support, and the items that carry into the value creation plan after close. You keep the model itself, so every number can be traced and rerun.

contact us

Test the plan before you price it

Send the teaser or the CIM and we will scope a commercial due diligence workplan against your deal timetable, usually within two business days.

Our Advantage

Why BD Emerson for commercial due diligence

Commercial diligence is only useful if the numbers survive the investment committee. Ours are built from source data, sized in dollars, and handed over in a model you keep.

Senior practitioners run the file

The people who scope the engagement make the customer calls, build the revenue model, and write the report. There is no handoff to a junior team after the pitch.

One firm, one set of numbers

BD Emerson runs financial, tax, technology, and cyber diligence alongside the commercial work, so the revenue build and the quality of earnings reconcile to a single model instead of arriving as four vendors' reports.

Findings sized in dollars

Every finding carries a number and a place in the model: revenue at risk from concentration, margin at risk from discount creep, and the dollar gap between the plan and the bottoms-up build.

The work continues after the report

Commercial findings carry into the 100-day plan and the value creation plan: the pricing actions to take first, the accounts to protect, and the cross-sell that survived testing.

Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Commercial due diligence FAQs

What is commercial due diligence?

How does it differ from financial and operational due diligence?

How long does commercial due diligence take?

What do customer reference calls involve and how is confidentiality handled?

How do commercial due diligence findings change price?

What does a commercial red flag look like?

Is buy-side commercial due diligence different from sell-side?

What data do you need to start?

How do the findings feed the value creation plan?

Who actually does the work?

What does commercial due diligence cost?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners