A Tech Stack Assessment for Acquisition That Produces a Decision, Not a Report

A Tech Stack Assessment for Acquisition That Produces a Decision, Not a Report

You have signed the LOI, or you are close to it. The model assumes the target’s software scales with the growth plan, that engineering cost stays flat while revenue doubles, and that a system migration during integration is a line item rather than a hole in the forecast. Confirmatory diligence is short, the seller controls access, and the operating partner needs to know before close whether the technology under the hood supports the thesis or quietly caps it. A tech stack assessment for acquisition exists to answer that question in a way the deal team, the CFO and the incoming CEO can act on. Most of what gets delivered under that label is a system inventory with a risk color code. That is a report. It is not a decision.

This piece names what an operating partner or portfolio executive actually needs to decide from a stack assessment, the tiers that produce those decisions, and how to judge whether the work you paid for is any good. It is written for a buyer with budget and a close date, not for someone learning the field. The commercial context is private equity, and the assessment should read against the deal thesis, not against a generic best-practice checklist.

1. What the assessment has to decide, before you scope it

The failure mode in technology diligence is scoping the work as coverage rather than as decisions. A vendor who bills for hours produces a thick document. A useful assessment produces a short list of decisions with the evidence behind each one. Before you engage anyone, write down what the report must let you decide.

For most mid-market deals, four decisions carry the weight:

  • Price and structure. Does the stack support the entry price, or does it imply a capex line the model does not carry? This is the difference between a clean bid and a retrade.
  • The 100-day plan. What must be fixed, rebuilt or migrated in the first 100 days, who owns it, and what does it cost in cash and management attention?
  • The growth thesis. Can the platform take the volume, the add-ons and the new markets the model assumes, or does the thesis rest on a rebuild nobody priced?
  • Key-person and continuity risk. Does the whole thing run on two engineers and an undocumented deploy process that leaves after close?

If the statement of work does not map to decisions like these, you are buying a report. The academic and practitioner literature on deal outcomes, including the M&A research aggregated by Harvard Business Review, keeps returning to the same point: value is lost in integration, not at signing, and integration risk is knowable during diligence if you look at the right things.

Four Decisions a Stack Assessment Must Produce | table with columns Decision / Question it answers / Owner. Rows: Price

2. The four-tier framework

Score the target across four tiers, from surface to structural. Each tier answers a harder question and touches a bigger number. Cheaper engagements stop at Tier 1 and 2. A full technology due diligence reaches Tier 3 and 4, where the money actually is.

Tier 1: Inventory and cost

What systems exist, what they cost, what the contracts say, and what the license and cloud spend actually is against what the seller reported. This is table stakes and it is where sellers most often overstate efficiency. The output is a reconciled run-rate technology cost, not a logo grid.

Tier 2: Condition and risk

Code quality, security posture, technical debt, single points of failure, and the state of documentation. This tier surfaces the deferred maintenance the seller capitalized as “the platform.” Security exposure belongs here too. Public enforcement and disclosure patterns tracked by the U.S. Securities and Exchange Commission make an unpatched breach a post-close liability, not a technical footnote.

Tier 3: Scalability against the thesis

This is where the assessment earns its fee. Take the growth model’s assumptions, 3x transaction volume, five bolt-ons, a new geography, and test whether the architecture, the data model and the team can carry them without a rebuild. A stack that runs fine today can be structurally incapable of the plan. That gap is a thesis risk, not a technical one.

Tier 4: People, ownership and continuity

Who actually knows how the system works, whether that knowledge is documented, and what happens on Day 1 when the founder-CTO’s earn-out clock starts. This tier connects directly to the integration and reporting build. It is the same discipline the CFO applies to financial ownership, described in the guide to Office of the CFO services in private equity.

Four-Tier Tech Stack Assessment | pyramid from base to top. Tier 1 Inventory & Cost (reconciled run-rate spend). Tier 2

3. How each tier turns into a number the model can carry

The reason CFOs and FP&A leads care about a stack assessment is that its findings should land in the model with a source and an owner attached. A finding without a dollar figure and a workstream owner is trivia. Each tier maps to a specific place in the forecast.

  • Tier 1 corrects the technology cost line and any overstated margin the seller built on unreported spend.
  • Tier 2 produces a remediation cost, timed into the 100-day cash plan.
  • Tier 3 either confirms the growth capex assumption or replaces it with a rebuild estimate that changes the return math.
  • Tier 4 sets retention cost and the risk-adjusted probability that the plan slips.

Classify each impact honestly. A reconciled cost overrun is realized. A remediation estimate is forecast. A scalability rebuild avoided by a design change is risk avoided. Do not let a forecast read as a realized saving, and do not let an “enabled” capability read as revenue in hand. That discipline is the same one the FP&A function needs on the reporting side, laid out in the piece on KPI tracking that actually informs a board decision.

The macro case for this rigor is well documented. The Bain & Company Global Private Equity Report has tracked for years how longer hold periods and higher entry multiples push returns toward operational improvement rather than multiple expansion, which means a mispriced stack shows up directly in the exit. Research from McKinsey on private capital and value creation, alongside BCG‘s work with principal investors, points the same way: the operating plan carries the return, and technology is now a load-bearing part of that plan rather than a back-office cost.

4. An applied example, labeled as illustrative

The following is an illustrative scenario, not a client outcome. Treat the numbers as placeholders that show how the tiers connect to the model.

A buyer signs an LOI on a $40M-revenue B2B software business. The model assumes technology cost holds at 9% of revenue as the company doubles, and it carries $500K of one-time integration capex.

  • Tier 1 reconciles cloud and license spend and finds the seller under-reported by $600K of run-rate, so the “efficient” margin is overstated. That changes the entry price conversation.
  • Tier 2 finds the billing engine has no automated tests and one engineer who understands it. Remediation and knowledge transfer are estimated at $350K over the first 100 days.
  • Tier 3 finds the reporting database cannot support the bolt-on data volumes the thesis assumes. A rebuild, not a tune-up, is required, estimated at $1.2M, none of which is in the $500K integration line.
  • Tier 4 finds that key knowledge sits with two people whose retention was not secured in the deal structure.

None of this stops the deal. All of it changes price, structure and the 100-day plan. That is the entire point of a tech stack assessment for acquisition: to move findings into the decision before the ink dries. The data-and-reporting half of that build, the part FP&A inherits, is treated in depth in the guide to what to buy from a portfolio company data strategy consultant.

Illustrative $40M SaaS Deal, Tier Findings | table columns Tier / Finding / Model impact. Row 1 Cost / +$600K unreported

5. How to judge the work you paid for

Once the report lands, apply a short test. A good assessment survives all five; a coverage document fails most.

  • Every finding has a number and an owner. No dollar figure, no workstream owner, no decision it feeds. If a finding cannot answer “so what,” it is noise.
  • It reads against the thesis, not a generic checklist. The scalability tier must reference the actual growth model, not “industry best practice.”
  • It separates realized, forecast and risk-avoided. A report that presents remediation estimates as facts is untrustworthy on the numbers that matter.
  • It names the migration risk explicitly. System migrations are where integration timelines break. The report should say what moves, when, who owns it, and what breaks if it slips.
  • It hands off cleanly to the 100-day plan. Findings should arrive as workstreams with owners, not as a PDF the operating partner has to re-translate.

For the reporting and analytics side of that handoff, the standards are the same ones described in how to judge an FP&A dashboard consultant and in the buyer’s guide to FP&A automation for portfolio companies. Buy the decision, own the recurring capability, and judge both by output rather than activity, a frame developed in the piece on what to buy, what to own, and how to judge it.

6. When each level of assessment is the right buy

Not every deal needs a full engagement. Match depth to the trigger and the check size.

Pre-LOI screen

Before you commit, a lightweight pass on Tiers 1 and 2 tells you whether there is a structural problem worth pricing. This is the $5K pre-LOI screen. It is cheap insurance against chasing a deal whose technology caps the thesis.

Confirmatory diligence

Between LOI and close, a five-day engagement reaching Tiers 3 and 4 produces the numbers that move price, structure and the 100-day plan. This is the $15K five-day tech DD. Deal-cadence data from PitchBook and Preqin, and the governance discussion carried by the Harvard Law School Forum on Corporate Governance, all point to compressed diligence windows, which makes a scoped, decision-first assessment more valuable than an open-ended one. Trade and market coverage from Private Equity International, Buyouts, PE Hub, S&P Global Market Intelligence, and the professional standards work of AICPA & CIMA reinforce the same operating reality: the finance and technology functions are being asked to produce decision-ready evidence on a shorter clock.

The connective work between this assessment and the ongoing analytics build is covered in the pieces on FP&A analytics that actually inform the decision and the FP&A dashboard consultant buyer’s guide.

Implementation note and next step

The practical discipline is this: scope the assessment backward from the four decisions, insist that every finding carries a number and an owner, and require the deliverable to arrive as 100-day workstreams rather than a report the operating partner has to reinterpret. That is what separates a stack assessment that changes the deal from one that merely describes it.

If you have a target under LOI or approaching confirmatory diligence and need a decision-ready read on the technology, route the engagement to the DevriX private equity data and technology practice and scope it to the five-day tech DD or the pre-LOI screen against your specific thesis.