IT Due Diligence Before Buying a Small Business
A business can look profitable on paper and still carry expensive technology problems. Outdated servers, weak account controls, missing backups, and non-transferable software can create costs soon after the purchase closes.
IT due diligence helps you find those problems before they become your responsibility. You can confirm what technology the business owns, what it pays for, who controls its accounts, and how quickly it could recover after an outage. Start the review before signing a final purchase agreement, then use the findings to plan the transition.
Why IT due diligence matters in a small business acquisition
Technology often supports nearly every part of a small business. Employees may depend on Microsoft 365, cloud applications, point-of-sale systems, customer databases, file servers, internet services, payment platforms, and specialized software. If one of those systems fails, the business may lose sales, records, or access to customers.
The purchase price doesn't show the full cost of the technology environment. A company with an old server may need an immediate replacement. A business with no tested backup may need a new recovery system. A software subscription may be tied to the seller personally, while the business domain may be registered under an employee's private account.
Those problems affect your first-year budget and your ability to operate after closing. They can also affect the value of the business itself. If the seller claims that the company has "secure cloud systems," ask which platforms are involved, who administers them, and when the last recovery test took place.
A practical IT review should answer four questions:
- What systems does the business use every day?
- Who owns, administers, and pays for those systems?
- What weaknesses could interrupt operations or expose data?
- What will you need to spend during the first 12 months?
A low monthly technology bill can hide a high replacement cost. Confirm the age, condition, and ownership of every system before treating low IT spending as a benefit.
IT due diligence also gives you negotiation evidence. You may request a price adjustment, a seller-funded upgrade, a transition service agreement, or a longer handoff period when the review finds a serious issue.
What to request before reviewing the technology
Ask the seller for an organized technology packet. A rushed or incomplete response doesn't prove that the business has serious problems, but it does tell you to investigate further.
Request the following information:
- A list of computers, laptops, servers, firewalls, wireless equipment, printers, cameras, and other business technology.
- Equipment purchase dates, warranties, leases, financing agreements, and maintenance records.
- Internet, phone, hosting, cloud storage, software, security, and support contracts.
- A list of business domains, public websites, social accounts, and related registrars.
- An application list that identifies the business owner, administrator, users, renewal date, and monthly cost for each platform.
- Network diagrams, office layouts, vendor contact information, and technology policies.
- Backup reports, recovery test results, incident records, and insurance questionnaires.
- A list of employees, contractors, and vendors with administrative access.
- Any open technology projects, unresolved outages, past ransomware events, or data loss incidents.
Request read-only reports whenever possible. You don't need broad administrative access during the initial review. You do need enough evidence to confirm that the seller's description matches the actual environment.
Build a system inventory
Walk through the business with someone who knows how employees work. A spreadsheet can track the device name, assigned user, operating system, age, location, warranty status, and business purpose. Record serial numbers when available.
Include equipment that employees may overlook. A small office may have a network-attached storage device, a backup appliance, a security camera recorder, or a machine that runs a line-of-business application. These systems may not appear on a standard computer list, yet operations could depend on them.
Ask employees which tools they use to complete a normal customer order. Their answers often reveal applications that don't appear in official documents. Marketing platforms, scheduling systems, shared mailboxes, and personal spreadsheets can become important after the sale.
Confirm ownership and transfer rights
A business can use a service without owning the account behind it. Check whether domains, phone numbers, software licenses, cloud tenants, and social profiles belong to the company or to the seller.
Review each contract for transfer restrictions, early termination charges, renewal dates, and required notices. Ask the seller to identify accounts that require a new owner, new payment method, or new license after closing.
Your attorney should review the legal effect of these contracts and the purchase agreement. An IT professional can identify operational dependencies, but contract interpretation belongs with qualified legal counsel.
IT due diligence checklist for the core systems
The following checklist focuses on technology that can affect daily operations, data protection, and transition costs.
Hardware, network, and internet services
Start with the equipment employees touch and the infrastructure they depend on. An aging laptop may be inconvenient, but an unsupported firewall or overloaded network switch can affect the entire office.
Review the age and condition of servers, desktops, laptops, wireless access points, switches, firewalls, printers, and battery backups. Check whether vendors still support the hardware and operating systems. Unsupported equipment may not receive security updates or replacement parts.
Ask these questions during the review:
- Does the business have a current network diagram?
- Which device provides firewall and remote access services?
- Who has administrative access to the firewall and wireless network?
- Does the office have separate guest and business wireless networks?
- What happens if the main internet connection fails?
- Are internet, phone, and equipment contracts transferable?
- Does the business need a battery backup or generator for key equipment?
- Are any systems stored in a room vulnerable to heat, water, theft, or storm damage?
For a Fort Myers business, include hurricane and extended power outage planning. Ask how employees would work if the office closed for several days. Confirm whether staff can securely access required applications from another location.
Cloud platforms, software, and data
Cloud services can reduce the need for local servers, but they still require careful ownership and administration. Microsoft 365, Google Workspace, QuickBooks Online, Salesforce, Dropbox, and industry-specific platforms each have separate accounts, permissions, billing, and retention settings.
Identify the primary administrator for every service. Confirm that the administrator uses a company-controlled email address rather than a personal mailbox. Review the number of licenses, inactive users, shared accounts, renewal terms, and storage limits.
Pay close attention to data exports. Ask whether customer, accounting, employee, and operational data can be exported in a usable format. A vendor may allow access to the account while limiting data portability or charging for exports.
The business may also rely on integrations that aren't obvious at first. A website could send orders to a fulfillment system. An online form might create records in a customer relationship platform. Accounting software may receive data from a point-of-sale system. Document these connections before changing passwords or cancelling subscriptions.
Accounts, access, and security controls
Access control determines who can enter systems and what they can change. Review administrative accounts across email, file storage, accounting, networking, websites, backup tools, and vendor portals.
Look for shared passwords and former employees who still have access. Confirm whether multi-factor authentication is enabled for administrator accounts and remote access. Ask how the business handles new hires, departures, lost devices, and password resets.
Create a list of accounts that need attention during the transition:
- Domain registrar and website hosting accounts.
- Email and cloud administrator accounts.
- Firewall, router, wireless, and remote access accounts.
- Backup, security, and endpoint management consoles.
- Banking, payroll, payment, and accounting platforms.
- Customer relationship management and scheduling systems.
- Phone system and business text messaging accounts.
Don't test systems by launching scans or attempting access without permission. A qualified cybersecurity professional can perform authorized testing and review security evidence. Your attorney and insurance adviser should also review privacy, breach reporting, and coverage requirements that apply to the transaction.
Backup and disaster recovery
A backup exists to support recovery, not to create a reassuring report. Ask which systems are protected, how often backups run, where copies are stored, and who receives failure alerts.
Request recent backup logs and evidence of restore testing. A file restore test answers a different question than a full server recovery test. Both may matter if the business depends on a database or specialized application.
Review recovery targets in plain language:
- How long can the business operate without each system?
- How much recent data can the business afford to lose?
- Who decides when to restore or shut down systems?
- Can employees work if the office is unavailable?
- Are backup accounts separate from ordinary administrator accounts?
- Does at least one backup copy remain inaccessible to routine network activity?
A business that needs stronger recovery planning may benefit from data backup and recovery solutions that cover local and offsite copies. The right design depends on the systems, data, recovery needs, and available budget.
Business applications and integrations
List the applications that directly support revenue and customer service. For each one, record its purpose, users, owner, vendor, renewal date, integration points, and replacement options.
Ask the owner to demonstrate a complete business process. For example, follow a customer request through scheduling, fulfillment, invoicing, payment, and record storage. Note every system involved and every manual step.
This walkthrough can reveal single points of failure. One employee may know how to process refunds. A desktop computer may hold a spreadsheet that controls inventory. A local server may run a database that no one else knows how to restart.
Document those dependencies while the seller and key employees are available. Their knowledge is part of the transition, even when it isn't listed as a formal business asset.
Identify hidden IT costs and liabilities
After collecting information, separate normal operating costs from near-term replacement and remediation costs. Don't estimate only the monthly support bill. Include licenses, hardware refreshes, migration work, training, data cleanup, security improvements, and downtime during the transition.
This table can help organize the review.
| Area | What to verify | Possible post-close effect |
|---|---|---|
| Hardware | Age, warranty, support status, and condition | Replacement or repair budget |
| Software | License count, ownership, renewals, and transfer rights | New subscriptions or migration |
| Internet and phones | Contract terms, service levels, and portability | Early fees or service changes |
| Security | Account controls, endpoint protection, and incident history | Security review and corrective work |
| Backups | Coverage, retention, offsite storage, and restore tests | New backup and recovery system |
| Staff knowledge | Documented procedures and administrator access | Training or transition support |
A server replacement may require more than hardware. You may also need application migration, new licenses, configuration, testing, and employee training. Similarly, replacing a phone system can affect business numbers, call routing, voicemail, recordings, and customer communications.
Review recurring costs for unused accounts. Former employees may still have paid licenses. The seller may pay for separate tools that could be consolidated after the transition. Avoid cancelling anything before you confirm data retention and operational dependencies.
Use a simple risk rating for each finding:
- High: The issue could stop operations, cause data loss, or block access after closing.
- Medium: The issue increases cost or exposure but has a workable short-term solution.
- Low: The issue is inconvenient and can wait for normal improvement planning.
Ask your CPA to assess how technology findings affect the financial model. Ask your attorney to address representations, warranties, indemnification, contract transfers, and ownership terms. An IT review can supply facts for those discussions, but it doesn't replace professional legal or financial advice.
How to verify the seller's claims
Documents help, but a live walkthrough often shows whether the environment is understood and maintained. Schedule time with the seller, the internal administrator, and any outside IT provider.
Ask the seller to demonstrate how an administrator performs routine tasks. The walkthrough might include creating a user, disabling a user, restoring a file, locating a vendor contract, reviewing a backup alert, or responding to an internet outage. You don't need to change anything during this session. You need to see whether the process exists and whether another person can repeat it.
Use a controlled verification process:
- Compare the equipment inventory with what you see in the office and network management system.
- Match active users with the current employee list, then investigate old or shared accounts.
- Review backup reports and observe an authorized test restore of a non-production file.
- Trace one important customer or financial workflow across every connected application.
- Confirm that the seller can transfer administrator rights, domains, phone numbers, and vendor relationships.
- Record each unresolved item, its owner, its deadline, and the evidence needed to close it.
A seller who can't produce a recent restore test may still have recoverable data, but you shouldn't assume that result. Arrange an authorized assessment with a qualified IT or cybersecurity professional before relying on the backup.
You should also review security incidents honestly. Ask when the incident occurred, what systems were affected, how the business responded, and whether anyone verified that the problem was resolved. Have qualified counsel and security professionals review any suspected breach or privacy issue.
Plan the technology transition before closing
The first 90 days after acquisition often contain more technology work than buyers expect. A written transition plan keeps urgent tasks separate from longer-term improvements.
Before the closing date
Create a shared list of systems, owners, transfer steps, and deadlines. Decide which services must remain active on the closing date. Arrange payment changes with vendors, but don't terminate services until the data and replacement plan are ready.
Include these tasks in the pre-close plan:
- Confirm the closing-day transfer of domains, phone numbers, cloud accounts, and administrator credentials.
- Obtain written permission for any security assessment or data migration.
- Schedule the seller's technical handoff with key employees and vendors.
- Capture current network, backup, application, and contact documentation.
- Define who can approve account changes during the transition.
- Agree on the seller's availability after closing if a system fails.
A transition service agreement may help when the seller or an outside contractor controls important systems. Have your attorney draft and review that agreement.
During the first week
Secure administrative access without disrupting operations. Change passwords through an organized process, enable multi-factor authentication where appropriate, remove departed users, and verify recovery methods. Update billing and ownership information for critical accounts.
Avoid making broad system changes on the first day. Keep a record of every change, and schedule migrations during low-volume periods. If a system is unstable, make a backup or recovery copy before modifying it.
Review the managed IT services checklist when comparing ongoing support options. The checklist includes practical areas such as monitoring, backup alerts, test restores, storm planning, and recovery targets.
During the first 90 days
Address high-risk findings first. Replace unsupported security equipment, close former-user accounts, document recovery procedures, and verify that backups protect the systems the business actually needs.
After urgent work, create a technology roadmap with clear priorities. The plan might include a laptop replacement schedule, network upgrades, cloud migration, application consolidation, employee training, or improved reporting.
Set an owner and target date for every project. Assigning a project to "IT" without a named person usually delays the work. Review progress with the business manager and the IT provider during regular meetings.
When to bring in an IT professional
A buyer can gather documents and ask useful questions, but a qualified IT professional can validate technical details that aren't easy to judge from a vendor invoice. Consider outside help when the business has servers, multiple locations, regulated information, remote access, custom applications, or a history of outages.
An IT assessment should produce clear findings rather than a long list of technical terms. Ask for a current-state summary, risk ratings, estimated remediation effort, transition dependencies, and a first-year budget range.
Different professionals may handle different parts of the review:
- An IT consultant or managed service provider can assess infrastructure, support needs, vendors, and operating costs.
- A qualified cybersecurity professional can perform authorized security testing and review controls.
- A CPA can assess how technology costs affect cash flow, earnings, and the purchase model.
- An attorney can review contracts, data obligations, representations, warranties, and liability terms.
- An insurance adviser can review technology-related coverage and required security controls.
Give the reviewer enough time and access to do the work properly. A short conversation with the seller may identify obvious issues, but it won't validate every system or recovery process.
Conclusion
A profitable business can still be a poor purchase if its technology can't transfer, recover, or support daily operations. IT due diligence turns hidden dependencies into documented costs, risks, and transition tasks before you commit.
Inventory the systems, verify ownership, test recovery, review access, and plan the first 90 days. Then have qualified IT, legal, financial, cybersecurity, and insurance professionals review the areas that fall within their expertise. The goal is a business you can operate with confidence after the keys change hands.

