skip to content
SaaS Due Diligence Checklist

Know What You Are Buying.

Use this working checklist to examine the financial, recurring revenue, customer, product, technical, legal, security, operating, commercial, and transfer risks that can matter before acquiring a SaaS business.

Start the Checklist
This checklist is an educational framework, not a substitute for professional financial, accounting, legal, tax, technical, cybersecurity, privacy, or transaction advice. Adapt the depth of diligence to the business and transaction.
60 checks Actual working checklist

Mark items complete as evidence is reviewed rather than reading another generic acquisition article.

12 categories Whole-business coverage

Move beyond revenue and review customers, product, technology, legal, security, operations, and transferability.

Private notes Record unresolved questions

Add notes under every category and keep them locally in your browser while you work.

Reusable Print or save your review

Use your browser print dialog to print the completed checklist or save it as a PDF for your own records.

How to use it

Diligence Is Evidence, Not a Checkbox Exercise

The objective is not to reach 100 percent as quickly as possible. The objective is to understand what you can verify, what remains uncertain, what requires specialist review, and whether unresolved risks affect the transaction.

01

Screen the Opportunity

Decide whether the business fits your acquisition criteria before asking for detailed information.

02

Request Evidence

Ask for records that support the claims material to your evaluation rather than relying only on seller summaries.

03

Verify and Reconcile

Compare financial, customer, technical, product, contractual, and operating information for consistency.

04

Escalate Specialist Issues

Move legal, tax, accounting, technical, privacy, or security questions to qualified specialists when needed.

05

Resolve Before Closing

Decide whether unanswered questions should change price, terms, conditions, structure, or your decision to proceed.

Working checklist

SaaS Acquisition Due Diligence Checklist

Work through the categories below. A checked item means you have reviewed it to the level appropriate for your transaction, not that the underlying business has automatically passed the review.

0 of 60 reviewed
0%
01 Deal Scope and Counterparty Confirm who is selling, what is being sold, and whether the conversation itself is properly grounded. 0 / 5
02 Financial Health Understand what the business earns, spends, owns, owes, and requires to continue operating. 0 / 5
03 Recurring Revenue Quality Test whether reported SaaS revenue is genuinely recurring, durable, and correctly understood. 0 / 5
04 Customers and Retention Understand who pays, why they stay, why they leave, and how durable the customer base may be. 0 / 5
05 Product and Technology Understand what the software depends on, how maintainable it is, and what ownership will actually require. 0 / 5
06 Security, Privacy and Data Understand how the business handles access, customer data, incidents, backups, and privacy obligations. 0 / 5
07 Legal, Corporate and Intellectual Property Confirm that the seller can transfer what you think you are buying and identify obligations that survive the sale. 0 / 5
08 Team and Operations Determine how much of the business exists as a repeatable operation rather than inside the founder's head. 0 / 5
09 Sales, Marketing and Commercial Position Understand where customers come from and whether growth depends on channels that may not transfer to a new owner. 0 / 5
10 Deal Terms and Payment Mechanics Understand the transaction structure and how money and control are expected to change hands. 0 / 5
11 Asset Transfer and Handoff Confirm that the business can actually be moved to the buyer without losing critical systems, access, or relationships. 0 / 5
12 Final Risk Review and Decision Bring unresolved issues together before price, terms, or enthusiasm make them easy to ignore. 0 / 5
Evidence requests

Ask for Evidence, Not Just Answers

The appropriate evidence depends on the transaction, but important claims should generally be supported by records that let you understand how the seller arrived at them.

Area Examples of evidence What you are testing
Financial performance

Accounting records, profit and loss statements, bank records, payment processor reports, invoices, tax records where appropriate, and supporting schedules.

Whether reported revenue, expenses, profitability, liabilities, and adjustments are reasonably supported.

Recurring revenue

Subscription exports, billing records, customer-level recurring revenue data, plan information, cancellations, refunds, and cohort records.

Whether MRR, ARR, churn, retention, expansion, and concentration are being calculated consistently.

Customers

Customer contracts, renewal terms, support records, customer lists where appropriate, major account history, and concentration analysis.

Whether revenue is durable and whether major customers create material dependency.

Product and technology

Architecture documentation, repositories, infrastructure inventory, dependency lists, issue trackers, deployment documentation, and technical walkthroughs.

Whether the product is maintainable, transferable, scalable enough for your plan, and understood by people beyond the founder.

Legal and IP

Incorporation documents, capitalization information, employment and contractor agreements, IP assignments, licenses, customer contracts, and material vendor agreements.

Whether the seller owns or controls what the transaction intends to transfer and whether material obligations exist.

Transfer readiness

Account inventory, access matrix, vendor list, domain ownership, repository ownership, cloud ownership, billing systems, operating procedures, and transition plan.

Whether the business can actually change control without breaking important systems or relationships.

Investigate further

Signals That Deserve More Questions

These situations do not automatically make a SaaS business unattractive. They are reasons to investigate the underlying facts before deciding how much weight to give them.

Reported figures do not reconcile

Revenue, customer counts, recurring revenue, or profitability differ materially between presentations, billing systems, accounting data, or supporting records.

One customer dominates revenue

A major customer relationship may materially change business economics if it is lost, renegotiated, or cannot transfer cleanly.

Founder knowledge is undocumented

Critical deployment, sales, customer, technical, or operational knowledge exists primarily with the founder and has not been documented.

Important accounts may not transfer

Cloud, app marketplace, payment, advertising, social, domain, or vendor accounts may have ownership or transfer restrictions.

Code ownership is unclear

Former contractors, agencies, employees, open-source licenses, or third-party components create uncertainty around intellectual-property rights.

Growth depends on one channel

The business relies heavily on one search ranking, integration partner, advertising account, marketplace, reseller, affiliate, or founder relationship.

Know when to escalate

Some Questions Need Specialists

A checklist helps organize questions. It does not turn the buyer into an accountant, lawyer, tax adviser, software architect, or cybersecurity professional.

Accounting or finance Revenue recognition, financial statements, working capital, liabilities, profitability adjustments, quality of earnings, and financial reconciliation.
Legal counsel Corporate ownership, IP, contracts, transaction structure, purchase documents, representations, liabilities, employment matters, and jurisdiction-specific issues.
Tax adviser Transaction taxes, historical exposure, asset versus equity structure, cross-border issues, and tax consequences relevant to the parties.
Technical specialist Architecture, code quality, dependencies, technical debt, infrastructure, maintainability, scalability, and transfer risks.
Security and privacy specialist Security controls, vulnerabilities, incident history, privacy obligations, sensitive data, access control, and customer security commitments.
Transaction safety

Diligence Does Not End With the Numbers

Before closing, buyers and sellers should also understand how payment, legal ownership, access, customer relationships, systems, and post-close support will move from one side to the other.

Before payment and closing

Align the Transaction Mechanics

The parties should understand the relationship between signed agreements, closing conditions, payment, and transfer obligations.

  • Define exactly what is being purchased
  • Agree payment timing and closing conditions
  • Use appropriate legal agreements
  • Consider escrow or other third-party payment arrangements where appropriate
  • Document representations, transition obligations, and remedies
Before ownership changes

Prepare the Operational Handoff

Transfer planning should cover the systems and relationships required for the SaaS business to continue operating after closing.

  • Domains, repositories, hosting, cloud and infrastructure
  • Payment, billing, analytics, support and communication systems
  • Administrative accounts, keys, MFA and recovery methods
  • Customer, vendor, employee and contractor transition requirements
  • Founder transition support and post-close responsibilities

What This Checklist Does Not Do

Completing this checklist does not verify a business, certify financial information, guarantee that all risks have been identified, determine valuation, recommend an acquisition, or guarantee a successful transaction. Buyers and sellers remain responsible for their own evaluation, professional advice, agreements, payment arrangements, transfer process, and transaction decisions. HTBS may facilitate marketplace discovery and deal conversations, but marketplace participation or listing review should not be treated as independent transaction diligence.

Common questions

SaaS Due Diligence FAQ

What should I check before buying a SaaS business?

Depending on the business and transaction, diligence commonly includes financial performance, recurring revenue quality, churn and retention, customer concentration, product and technology, security and privacy, intellectual property, contracts, team dependencies, sales and marketing, transaction terms, and transfer readiness.

Is checking MRR and ARR enough?

No. MRR and ARR can help describe recurring revenue, but a buyer may also need to understand how those figures are calculated, retention, churn, concentration, margins, customer contracts, non-recurring revenue, and the records supporting the reported figures.

How much diligence is appropriate for a small Micro SaaS acquisition?

The depth should be proportionate to the transaction, but a smaller purchase price does not automatically eliminate important risks. Ownership of code, revenue quality, payment accounts, platform dependencies, customer concentration, and transferability can matter even for very small SaaS businesses.

Does HTBS verify every business listed on its marketplace?

No blanket independent verification should be assumed. HTBS may review founder submissions and request clarification as part of its marketplace process, but that review is not an accounting audit, legal due diligence, technical certification, security assessment, valuation opinion, or investment recommendation.

Should I ask for source-code access during diligence?

Technical diligence may require enough access or evidence to understand architecture, maintainability, dependencies, ownership, and technical risk. The exact access, timing, confidentiality protections, and reviewer should be agreed by the parties based on the transaction.

Should I use an NDA before receiving sensitive information?

An NDA may be appropriate when a conversation progresses toward commercially sensitive information. It is not automatically required for every initial discussion, and the parties should obtain legal advice if they need help deciding what confidentiality terms are appropriate.

Does this checklist cover payment and transfer risk?

Yes. The checklist includes transaction structure, payment timing, closing conditions, possible third-party payment arrangements, account transferability, credentials, domains, infrastructure, customer communication, and transition support.

Can I save my checklist progress?

Yes. Your selections and category notes are stored locally in your current browser. You can also use the Print or Save PDF button to open your browser's print dialog and save a copy as a PDF if your browser supports that option.

Found a SaaS Worth Investigating?

Use the checklist to organize your evaluation, involve specialists where necessary, and separate what has been verified from what still needs answers before you decide whether to proceed.

How To Buy SaaS
Logo
Compare items
  • Total (0)
Compare
0
Shopping cart