Free Tool

M&A Cybersecurity Due Diligence Checklist
twelve sections that turn cybersecurity diligence from a data-room browse into a defensible transaction artefact

A free, copy-ready M&A cybersecurity due diligence checklist for CISOs, GRC and compliance teams, internal security teams, AppSec teams, vulnerability management teams, security engineering teams, corporate development executives, integration leads, and deal sponsors who own the security side of acquisitions, divestitures, carve-outs, asset purchases, minority investments, and portfolio bolt-ons. Twelve structured sections covering header and scope, target identification and deal-shape context, pre-close evidence request list and data-room intake, security programme posture review, identity, access, and credential inventory review, application, infrastructure, and external attack surface review, data classification, residency, and customer commitments review, compliance, attestation, and audit history review, incident, breach, and litigation history review, walk-away, repricing, and SPA representations review, the day-one cutover and containment runbook, and the post-close integration verification and reassessment cadence across 30/60/90 days and the named survival window. Aligned with ISO/IEC 27001 Annex A 5.7, 5.19, 5.22, 5.23, 5.30, 5.31, and 8.30, ISO/IEC 27036 supplier relationships standard, SOC 2 CC9.2 vendor and business partner management, PCI DSS Requirement 12.8 service providers, NIST SP 800-53 SR family supply-chain risk management, NIST SP 800-161 cybersecurity supply chain risk management, NIST CSF 2.0 GV.SC supply chain risk management and ID.RA risk assessment, CIS Controls v8.1 control 15 service provider management, NIS2 Article 21 supply-chain risk management measures, DORA Articles 28 to 30 ICT third-party risk management where the target operates in the financial services value chain, GDPR Articles 28 and 30, and SEC Form 8-K Item 1.05 cybersecurity disclosure where the buyer is a US public registrant.

No credit card required. Free plan available forever.

Loading tool...

Run M&A cybersecurity diligence on the live engagement record, not on a side spreadsheet that dies at legal close

SecPortal pairs each diligence run to a versioned engagement record so the named target, the named deal shape, the named evidence requests, the named day-one runbook signatures, the named SPA representations linkage, and the named post-close 30/60/90-day verification cadence live on one workspace through the named survival window with a named-actor activity log. Free plan available.

No credit card required. Free plan available forever.