Short answer: What is the due diligence for SaaS?
Due diligence for SaaS is the buyer’s process for verifying what the business really is before buying it. It usually covers revenue quality, churn, customer concentration, contracts, product and codebase health, security, legal ownership, financials, team dependencies, sales process, support burden, and transition risk.
The goal is not to find a perfect company. The goal is to confirm the facts, understand the risks, decide whether the price and terms still make sense, and know what has to happen after closing. For founders, good diligence is also a readiness test: if the buyer cannot verify it, they may discount it, delay closing, or walk away.
What this means in practice
SaaS diligence is different from diligence on a traditional services or local business because the buyer is not only buying past profit. They are buying recurring revenue, software assets, customer behavior, and the operating system that keeps renewals happening.
A practical diligence process usually looks at six areas.
1. Revenue quality
A buyer wants to know whether revenue is recurring, collectible, and likely to continue. This means reviewing subscription revenue, expansion revenue, one-time implementation fees, discounts, refunds, failed payments, and contract terms.
The key question is simple: does reported MRR or ARR tie back to billing records, contracts, and cash collected?
Common evidence includes:
- Billing platform exports
- Bank statements or payment processor reports
- Customer contract samples
- Revenue by month
- Refund and credit history
- Breakdown of recurring versus non-recurring revenue
A business with clean, easy-to-reconcile revenue is easier to underwrite. A business with messy billing or unclear definitions can still be valuable, but the buyer will spend more time validating the numbers.
2. Retention and customer concentration
SaaS buyers care deeply about whether customers stay. They will look at logo churn, revenue churn, expansion, downgrades, cancellations, cohort behavior, and the reasons customers leave.
They will also ask whether too much revenue depends on a small number of accounts. High concentration is not automatically a deal killer, but it changes the risk profile. If one customer represents a large share of revenue, the buyer will want to understand contract length, renewal history, relationship ownership, and whether the account depends personally on the founder.
Good diligence does not just ask, “What is churn?” It asks, “How is churn defined, how was it calculated, and what does it say about future cash flow?”
3. Product, code, and technical risk
SaaS buyers need confidence that the product can keep running after closing. Technical diligence usually reviews hosting, infrastructure, code quality, deployment process, uptime incidents, third-party dependencies, data backups, security practices, and roadmap commitments.
A buyer may not need every line of code reviewed, especially in a smaller acquisition. But they do need to know whether the product is maintainable, whether key knowledge lives only in the founder’s head, and whether there are urgent technical liabilities that will require investment soon after closing.
For founder-led SaaS companies, documentation matters. A clean architecture overview, admin access list, deployment notes, and known-issues log can reduce friction quickly.
4. Legal, IP, and data ownership
SaaS diligence should confirm that the company actually owns or has the right to use what it is selling. Buyers typically review customer contracts, contractor agreements, employee invention assignments, open-source usage, trademarks, privacy policies, data processing practices, and any disputes or claims.
This is an area where buyers should use qualified counsel. The commercial point is straightforward: if ownership, data rights, or customer obligations are unclear, the buyer may need stronger reps, indemnities, holdbacks, or a lower price to offset risk.
5. Sales, marketing, and growth engine
A SaaS company’s future value depends on how new revenue is created. Diligence should review lead sources, conversion rates, sales cycle, pricing, win-loss notes, pipeline quality, paid marketing efficiency, partner channels, and founder involvement in closing deals.
The buyer is trying to separate durable growth from founder hustle. If most sales require the founder’s personal credibility, the transition plan becomes more important. If acquisition channels are documented and repeatable, the buyer has more confidence in the forecast.
If you are new to acquisition work, HelloExit’s Ultimate Guide to Buying a Business is a useful companion because it puts diligence in the broader context of fit, financing, negotiation, and transition.
6. Operations and transition risk
Finally, diligence should show what happens on day one after closing. Who answers support tickets? Who owns product releases? Who manages renewals? What systems need to be transferred? Which accounts require personal introductions?
A small SaaS business can be excellent and still be fragile if the founder is the only person who understands customers, code, billing, and support. Buyers should identify those dependencies before signing, not after the wire goes out.
For sellers, this is where preparation pays off. A simple transition plan, documented processes, and clean access controls can make a buyer more comfortable. If you are a founder assessing sale readiness before conversations begin, use the Exit Readiness Tool to identify the gaps that may slow diligence or weaken buyer confidence.
What buyers should ask for first
You do not need to request every document on day one. Start with the materials that answer the biggest risk questions:
- Monthly revenue and customer count for the last 24 months, if available
- Current customer list with revenue by account
- Churn, downgrade, and expansion detail
- Billing exports and payment processor reports
- Product architecture summary
- Key customer contracts and standard terms
- Support ticket summary and major incidents
- Team, contractor, and founder responsibility map
- List of tools, vendors, licenses, and critical dependencies
- Transition plan for the first 30 to 90 days
Then build a short diligence scorecard. For each issue, write the evidence requested, what was confirmed, what remains unclear, and whether it affects price, terms, closing conditions, or post-close work.
This keeps diligence focused. The biggest mistake is treating diligence like a document scavenger hunt instead of a decision process. Another common mistake is falling in love with the product and ignoring the operating risk. HelloExit’s guide to mistakes to avoid when buying a business is worth reading before you make an offer or waive key conditions.
What to do next
If you are buying a SaaS business, start with the core question: “What must be true for this business to keep producing cash after I own it?” Then use diligence to test that answer.
If you are selling a SaaS business, prepare the evidence before buyers ask. Clean revenue schedules, clear churn definitions, documented systems, assigned IP, and a realistic transition plan can reduce uncertainty.
Next step: run the Exit Readiness Tool to see which diligence gaps are most likely to create buyer questions, delays, or renegotiation. It is a practical first pass before you go deeper with advisors, buyers, or a formal sale process.