Live: Tesla PDF 3s (DI-1F0059F32F) · median 15s across 4 real orders · code DI20-WELCOME · $49 → $39.20 · Order now →
Home / Sectors / Software PE Due Diligence

Software PE Due Diligence: What Buyout Teams Actually Check

Private equity software deals die on revenue quality, retention, concentration, tech debt, and security — not on pretty ARR headlines. Use this guide to screen software and SaaS targets before LOI and run a sharper confirmatory workstream after it.

Software Private Equity
6
Workstreams
50
Checklist items
3-8
Confirmatory weeks
$49
First-pass pack

Why software PE diligence is different

Software PE due diligence is the structured review of a software, SaaS, or software-enabled business before a buyout, growth equity check, or platform add-on. Buyers are underwriting a cash-flow machine whose assets are code, customers, and contracts — not factories and inventory.

That changes the kill criteria. A manufacturer with messy working capital can still close. A SaaS business with collapsing net revenue retention, one customer at 35% of ARR, or a forced platform rewrite can destroy entry multiple assumptions before SPA redlines start.

Best practice: Run a public-info kill screen (filings, reviews, hiring, litigation, competitive maps) before you burn banker process fees. Confirmatory QoE and tech diligence should only start on names that survive open-source risk checks.

Six workstreams PE teams actually staff

1. Revenue quality

ARR/MRR bridge, bookings vs billings vs revenue, deferred revenue, contract term mix, multi-year vs monthly, price increases, and one-time services contamination.

2. Retention & cohorts

Logo churn, dollar churn, GRR/NRR, expansion vs contraction, cohort curves by segment, and whether growth is real expansion or new logos papering over churn.

3. Customers & GTM

Concentration, NRR by cohort, sales efficiency (CAC, payback, magic number), channel dependence, win/loss themes, and pipeline quality for the next 12 months.

4. Product & technology

Architecture age, cloud cost structure, roadmap credibility, technical debt, single points of failure, open-source license risk, and engineering capacity to ship.

5. Security & compliance

SOC 2 / ISO claims, breach history, data residency, pen-test findings, access control, and customer-contract security SLAs that become deal conditions.

6. Legal / IP / people

IP assignment chain, key-person risk, equity/option overhang, change-of-control clauses, litigation, and founder/executive retention post-close.

Core SaaS metrics checklist (what must reconcile)

MetricWhat good looks like (context-dependent)Red flag
ARR / MRR bridgeClean new / expansion / churn / contraction bridge monthlyBridge does not reconcile to recognized revenue
NRR (net revenue retention)Often 100%+ for durable SaaS; segment itNRR falling quarter over quarter with no plan
GRR (gross revenue retention)High 80s-90s+ depending on SMB vs enterpriseGRR collapse in core logo base
Gross marginSoftware COGS discipline; hosting efficiencyHosting + support costs exploding with scale
CAC paybackPayback aligned to sales cycle and churnPayback longer than useful customer life
Rule of 40Growth % + margin % balanced for stageGrowth only via unsustainable spend
Deferred revenue / billingsBillings support ARR narrativeARR up, cash billings flat/down
Customer concentrationTop 10 diversified; contracts protectTop customer above 25-30% without lock-in

If the CIM shows ARR without a bridge to cash and recognized revenue, treat the number as marketing until proven. PE models that price on headline ARR without GRR/NRR cohorts overpay systematically.

Screen 10 software targets for the cost of one junior analyst day

Traditional software multi-workstream diligence often runs $50K-$250K+ and 3-8 weeks. A structured first-pass public-info pack is $49 per target — or $129 for a 3-Pack shortlist with a comparison PDF.

Order a software PE pack · $39.20 launch →    See software sample PDF

50-point software PE diligence checklist

First-pass list for buyout screening. Severity tags: Deal-Killer, High, Watch.

A. Revenue quality (10)

  • Deal-Killer: ARR/MRR bridge reconciles to GL revenue and cash collections
  • High: Bookings vs billings vs recognized revenue are separately disclosed
  • High: One-time professional services not baked into recurring ARR
  • High: Multi-year deals: revenue recognition vs cash timing understood
  • Watch: Price-increase contribution vs pure volume expansion separated
  • High: Deferred revenue roll-forward available and clean
  • Watch: Usage-based revenue volatility modeled (not treated like seat SaaS)
  • High: Related-party or channel-stuffing risk reviewed
  • Watch: Seasonality and year-end deal spikes documented
  • High: Bad debt / collection issues immaterial to ARR claims

B. Retention and cohorts (8)

  • Deal-Killer: Logo and dollar churn trends by quarter (not only annual averages)
  • Deal-Killer: NRR and GRR by segment (SMB / mid / enterprise)
  • High: Cohort retention curves for last 8-12 cohorts
  • High: Contraction vs logo loss split explained
  • High: Expansion driven by seats/modules — not one-time upsells mislabeled
  • Watch: Win-back and reactivation quality (not double-counted ARR)
  • High: Churn reasons coded (product, price, competitor, budget)
  • Watch: Early-life churn vs mature base churn separated

C. Customers and GTM (8)

  • Deal-Killer: Top 1 / top 5 / top 10 revenue concentration quantified
  • High: Change-of-control and termination rights on top contracts
  • High: CAC, payback, LTV assumptions match actual retention
  • High: Pipeline coverage and stage hygiene for next 2-4 quarters
  • Watch: Partner/channel revenue quality vs direct
  • High: Sales capacity plan vs growth thesis (quota, ramp, attrition)
  • Watch: Competitive displacement risk in top logos
  • High: Referenceability: recent NPS/CSAT and public review trends

D. Product and technology (10)

  • Deal-Killer: Forced rewrite / EOL platform risk in next 24 months
  • High: Architecture fit for scale (multi-tenant, reliability, regions)
  • High: Cloud COGS trajectory and unit economics under growth
  • High: Roadmap vs customer-requested features — delivery credibility
  • High: Key engineering attrition and bus-factor on core modules
  • Watch: Open-source license compliance (copyleft exposure)
  • High: Integration surface area (APIs, ecosystem lock-in)
  • Watch: Tech debt backlog quantified in eng-months
  • High: Uptime history and major incident postmortems
  • Watch: Data portability and customer exit friction

E. Security and compliance (7)

  • Deal-Killer: Material undisclosed breach or ransomware history
  • High: SOC 2 / ISO / sector attestations current and scoped correctly
  • High: Pen-test findings severity and remediation status
  • High: Access control, SSO/SAML, encryption at rest/in transit
  • Watch: Data residency and privacy (GDPR/CCPA) obligations
  • High: Customer security addenda that create close conditions
  • Watch: Vendor risk program for critical subprocessors

F. Legal, IP, people (7)

  • Deal-Killer: IP assignment gaps (contractors without assignment)
  • High: Litigation / IP claims that threaten core product
  • High: Key-person risk (founder, CTO, top AEs)
  • High: Cap table, options, and retention packages post-close
  • Watch: Customer and vendor change-of-control consent requirements
  • High: Inbound/outbound license restrictions on distribution
  • Watch: Employment classification and non-compete enforceability by geo

Software PE red flags (walk or reprice)

SignalSeverityWhy it matters
NRR falling while ARR still growingDeal-KillerNew logos may be masking a rotting base
Top customer above 30% revenue, short contractDeal-KillerSingle renewal can break the model
ARR up, cash billings flatHighAccounting narrative without cash truth
Major rewrite planned year 1Deal-Killer / HighCapex + delivery risk on day-one thesis
Security incident + weak disclosureDeal-KillerEnterprise sales freeze; legal exposure
Contractor-built core without IP assignmentDeal-KillerYou may not own what you are buying
CAC payback longer than useful lifeHighGrowth destroys value
Heavy services revenue labeled recurringHighMultiple compression when cleaned

Cost and timeline: traditional vs first-pass

ApproachTypical costTypical timeBest use
Public kill screen + structured pack$49 / target ($129 3-Pack + comparison PDF)Minutes to hoursPre-LOI triage, shortlist ranking
Boutique commercial + tech memo$15K-$75K1-3 weeksSerious process before exclusivity
Full QoE + tech + legal software stack$50K-$250K+3-8 weeksPost-LOI confirmatory

Use cheap screens to decide which names deserve expensive specialists. Do not reverse the order.

How dodilligence helps software PE teams

dodilligence delivers institutional-style public-information diligence PDFs for named software targets. Use them to:

  • Kill weak software names before banker process fees
  • Build a shortlist of 3 with a side-by-side comparison PDF
  • Walk into management meetings with a written issue list
  • Brief IC on open-source risk themes before confirmatory spend

Related: Software company library · Software sample report · Technology DD guide · Financial DD guide · PE teams · Valuation guide

FAQ: Software PE due diligence

What is software PE due diligence?

It is the structured review of a software or SaaS company before a private equity buyout, growth equity investment, or add-on acquisition. It covers revenue quality, retention, customers, technology, security, and legal/IP risk.

What metrics matter most in SaaS buyout diligence?

ARR bridges, GRR/NRR, churn, CAC payback, gross margin, deferred revenue/billings, concentration, and cohort retention. If those do not reconcile, stop trusting the CIM narrative.

How long does software PE diligence take?

Public screening: hours to days. Full confirmatory stacks: often 3-8 weeks after LOI.

What are common software PE deal-killers?

Collapsing NRR, extreme concentration, forced rewrites, IP ownership gaps, material security incidents, and revenue that does not match cash.

How much does software due diligence cost?

Specialist stacks often $50K-$250K+. First-pass public-info packs start at $49 per target; 3-Pack shortlist with comparison PDF is $129.

Should PE run tech diligence before LOI?

Light public product and security signals: yes. Deep code review: usually after LOI access.

How is software PE diligence different from general M&A diligence?

It overweights recurring revenue quality, retention cohorts, product risk, cloud costs, cybersecurity, and IP chains versus plant and inventory.

Can a first-pass public screen replace a full stack?

No. It prioritizes questions and kills weak names early. Specialists still run confirmatory work on finalists.

Software / SaaS targets you can screen now

Each target has a free 1-page brief and a full 20-page PDF diligence report ready to order. Pick a name to start screening.

Ready to screen a software target?

Institutional PDF pack from public sources. $49/report · $129 3-Pack with comparison PDF · dual legal acceptance at checkout.

Order report → Order 3-Pack → Software sample

More PE due diligence guides

Screening frameworks across every active deal sector. Each guide maps to buyable company reports.