{"id":3904,"date":"2026-09-22T06:00:00","date_gmt":"2026-09-22T06:00:00","guid":{"rendered":"https:\/\/www.torck.io\/?p=3904"},"modified":"2026-09-03T11:06:47","modified_gmt":"2026-09-03T11:06:47","slug":"technical-due-diligence","status":"publish","type":"post","link":"https:\/\/www.torck.io\/en\/technische-due-diligence\/","title":{"rendered":"Technical Due Diligence in Acquisitions: What the Code Reveals About the Company"},"content":{"rendered":"<p>Technical due diligence assesses, prior to signing, what is contained in a target company\u2019s code, what risks it poses, and what a takeover is actually worth from a technical perspective. Anyone who buys a company also buys its software, whether or not that is factored into the purchase price. According to the Bain Global M&amp;A Report, over 70 percent of transactions in the mid-market segment have a significant technology component, such as <a href=\"https:\/\/plausity.com\/news\/software-due-diligence-code-review\" target=\"_blank\" rel=\"noopener\">Plausity<\/a> citing the report (Plausity, March 2026). A purchase price based on an overly superficial review can rarely be corrected retroactively after the deal is signed.<\/p>\n<div class=\"tk-key\">\n<b>In a nutshell<\/b><\/p>\n<p>Technical due diligence assesses the target company\u2019s architecture, dependencies, security posture, test coverage, operational readiness, and the origin of its intellectual property prior to an acquisition. High levels of technical debt often result in significant rework after the purchase and directly impact the return on investment. It is important to <a href=\"#pruefteile\">Full scope of testing<\/a>, interviews with the development team alone aren't enough for that.<\/p>\n<\/div>\n<h2 id=\"pruefteile\">What a Technical Due Diligence Review Specifically Examines<\/h2>\n<p>An audit consisting solely of interviews with the development team reveals only a fraction of the relevant risks. It must go beyond interviews and examine the code itself, the security posture, and the origin of the intellectual property, because in practice, statements made during interviews often do not match the actual state of the systems. Those who rely on management presentations rarely identify the areas of the system that will later cost the most during the acquisition. Only those who examine the code themselves\u2014rather than relying on a summary\u2014can identify precisely these areas.<\/p>\n<div class=\"tk-stat\">\n<strong>more than 70 percent<\/strong><\/p>\n<p>According to the Bain Global M&amp;A Report, transactions in the mid-market segment have a significant technology component.<\/p>\n<p><cite>Plausity on the Bain Global M&amp;A Report, March 2026<\/cite>\n<\/div>\n<div class=\"tk-tablewrap\">\n<table>\n<caption>Areas Covered by a Technical Due Diligence Review<\/caption>\n<thead>\n<tr>\n<th scope=\"col\">Area<\/th>\n<th scope=\"col\">Key Question<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<th scope=\"row\">Architecture<\/th>\n<td>Can the system be scaled and replaced in parts without having to rebuild everything from scratch?<\/td>\n<\/tr>\n<tr>\n<th scope=\"row\">Dependencies and Licenses<\/th>\n<td>What third-party components are included in the product, and under what license terms?<\/td>\n<\/tr>\n<tr>\n<th scope=\"row\">Test Coverage<\/th>\n<td>Can changes be implemented with minimal risk, or does quality depend on specific individuals?<\/td>\n<\/tr>\n<tr>\n<th scope=\"row\">Operational readiness<\/th>\n<td>How often does the system fail, and how quickly is a failure detected?<\/td>\n<\/tr>\n<tr>\n<th scope=\"row\">Key Individuals<\/th>\n<td>How many people would have to be absent for development to come to a standstill?<\/td>\n<\/tr>\n<tr>\n<th scope=\"row\">Documentation<\/th>\n<td>Can the system be maintained without the original developers?<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>These six areas are interrelated; a weakness in one area usually exacerbates the risks in the others. If documentation is lacking, the key-person risk becomes more significant. If test coverage is lacking, any further development of the architecture becomes riskier than it appears on paper.<\/p>\n<p>When it comes to the origin of intellectual property, it\u2019s worth taking a close look at the contracts. According to <a href=\"https:\/\/www.gesetze-im-internet.de\/urhg\/__69b.html\" target=\"_blank\" rel=\"noopener\">\u00a7 69b of the German Copyright Act (UrhG)<\/a> Unless otherwise agreed, the employer holds the property rights to software created by employees in the course of their duties. This rule does not apply to freelancers. In such cases, an explicit transfer of rights must be stipulated in the contract\u2014and this is precisely what is often missing in codebases that have evolved over the years.<\/p>\n<p>In the audits we conduct, a pattern emerges time and again. Systems with good test coverage almost always have clearer documentation as well, because both stem from the same work discipline within the development team. If both are lacking at the same time, that is a stronger warning sign than either metric on its own.<\/p>\n<h2 id=\"technische-schulden\">Why Technical Debt Affects the Purchase Price<\/h2>\n<p>Technical debt can be measured as a metric, unlike the vague impression gained from a single conversation. Outdated dependencies, missing tests, and an architecture that makes every change a risk result in real follow-up costs after the purchase\u2014whether through rework, delayed further development, or a higher risk of failure during ongoing operations. These costs directly impact the transaction\u2019s return on investment, regardless of how well the business model itself performs.<\/p>\n<p>Quantifying these liabilities is therefore not merely an academic exercise. It provides the basis for purchase price negotiations and for a realistic \u201efirst 100 days plan\u201c following the acquisition, during which the most urgent risks must be addressed before they lead to outages or security incidents. An amount in the purchase agreement based on this figure is easier to justify to a committee than a blanket discount based on gut feeling.<\/p>\n<p>In practice, the amount identified is usually incorporated into the transaction in one of two ways. Either the purchase price is reduced by the estimated follow-up costs, or a portion of the purchase price is held in escrow until the most critical issues have been resolved. Which approach is appropriate depends on the bargaining power of both sides, not solely on the amount of the identified debts. This article illustrates just how costly such remedial work can be. <a href=\"\/en\/erp-project-failed\/\">ERP Projects in Crisis: Typical Patterns and Solutions<\/a>.<\/p>\n<div class=\"tk-note\">\n<b>What a two-week exam Can't Achieve<\/b><br \/>\nAn audit conducted in two weeks can reveal the biggest risks, but it cannot provide a complete review of every line of code. Anyone expecting a foolproof guarantee is confusing a risk assessment with a full audit, which takes weeks or months and rarely fits within a transaction\u2019s timeline.\n<\/div>\n<div class=\"tk-inline-cta\">\n<p><b>Technical Review Before Signing<\/b><br \/>\nAn initial assessment of the target company can often be arranged within a week.<\/p>\n<p><a class=\"tk-btn\" href=\"\/en\/#contact-us\">Get in touch<\/a>\n<\/div>\n<h2 id=\"faq\">Frequently Asked Questions<\/h2>\n<h3 class=\"tk-faq-item\">How long does a technical due diligence take?<\/h3>\n<p>For an initial, reliable overview, one to two weeks is often sufficient with a small team that has access to the code, the ticket system, and the key contacts. Larger transactions involving multiple product lines or distributed teams take correspondingly longer, especially if access needs to be arranged before the actual review can begin. Setting a fixed timeframe at the outset helps both sides because it prevents the audit from dragging on unnoticed for weeks and delaying the entire transaction process.<\/p>\n<h3 class=\"tk-faq-item\">What are some typical exclusion criteria?<\/h3>\n<p>These include unclear ownership of the code\u2014for example, when significant portions were developed by freelancers without a documented transfer of rights\u2014serious security vulnerabilities in production systems, and an architecture that can only be further developed by effectively rebuilding the system from scratch. None of these criteria automatically precludes a transaction, but they do significantly affect the purchase price or the structure of the deal\u2014for example, through a longer liability period for the seller or a portion of the purchase price being withheld.<\/p>\n<h3 class=\"tk-faq-item\">Who should conduct the review?<\/h3>\n<p>A team with real development experience delivers different results than consultants who have never been responsible for writing productive code themselves. Ideally, the people who will be responsible for addressing the identified risks after the acquisition should be involved as early as the audit phase; this significantly shortens the transition from assessment to actual integration. In practice, an audit report that does not include responsibility for implementation often ends up in a drawer rather than leading to concrete actions.<\/p>\n<p>Technical due diligence is only as valuable as the ability to subsequently address the risks identified. torck evaluates target companies using the same development teams from Maxh\u00fctte-Haidhof, Vienna, and Rabat, who then <a href=\"\/en\/interim-cto-services\/\">Technical Integration as an Interim Assignment<\/a> can take over the process, rather than simply handing over the results in a report. The contract partner for the audit is the German company torck GmbH, which facilitates confidentiality during an ongoing transaction. Anyone who needs a technical assessment prior to an acquisition can do so in a <a href=\"\/en\/#contact-us\">Initial Consultation<\/a> .<\/p>\n<p><a class=\"tk-btn\" href=\"\/en\/#contact-us\">Schedule a meeting<\/a><\/p>\n<div class=\"tk-note\">\n<b>Legal note<\/b><br \/>\nThis article refers to laws and regulations to put technical decisions in context. It is not legal advice. Whether and how a rule applies to your company is a question for your legal department or a law firm.<\/div>","protected":false},"excerpt":{"rendered":"<p>A technical due diligence reveals what the code says about a target company, from its architecture to its technical debt. This article outlines the full scope of the review.<\/p>","protected":false},"author":10,"featured_media":3907,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_mbp_gutenberg_autopost":false,"footnotes":""},"categories":[23],"tags":[],"art":[31],"class_list":["post-3904","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interim-cto-projektrettung","art-grundlagen"],"_links":{"self":[{"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/posts\/3904","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/comments?post=3904"}],"version-history":[{"count":3,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/posts\/3904\/revisions"}],"predecessor-version":[{"id":5685,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/posts\/3904\/revisions\/5685"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/media\/3907"}],"wp:attachment":[{"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/media?parent=3904"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/categories?post=3904"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/tags?post=3904"},{"taxonomy":"art","embeddable":true,"href":"https:\/\/www.torck.io\/en\/wp-json\/wp\/v2\/art?post=3904"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}