Commercial Due Diligence (Cyber)
Commercial due diligence for cyber targets covers the diligence checklist, the red flags, and the post-close operating model. It relates to Valuation, Value Creation, and Product & Competitive Strategy. (Book: enriches Part III, Ch. 11 & Part IV, Ch. 18.)
The CDD checklist
1. Revenue quality - ARR mix: recurring vs. one-time/services; multi-year vs. annual contracts. - NRR / GRN (net & gross retention); cohort retention curves — the truest quality signal. - Customer concentration (top-10 % of ARR); logo vs. dollar churn. - Billings vs. revenue (deferred-revenue health); RPO trend.
2. Growth durability - Growth rate and its source (new logos vs. expansion); Rule of 40. - Pipeline coverage and conversion; sales-cycle length trend. - Net-new ARR trajectory (accelerating or decelerating).
3. Unit economics & efficiency (growth-stage focus) - CAC payback (months); magic number; sales & marketing efficiency. - Gross margin (and software-vs-services mix — the multiple driver). - Burn multiple / FCF trajectory.
4. Product & moat (see 33) - Differentiation type (data/workflow/distribution vs. raw tech); pricing power. - Platform-bundling exposure; category life-cycle (filling/draining). - Second-product progress; integration/marketplace breadth.
5. Go-to-market (see 19) - Channel vs. direct mix; partner concentration; channel conflict. - Marketplace traction; regional coverage (channel-enabled vs. fragile-direct).
6. AI exposure (2026 essential) - Does AI strengthen or erode the moat? (data/automation vs. commoditization) - Is the product AI-native or retrofitting? "Analytical SaaS" risk. - For services: agentic-SOC adoption status (manual = margin risk).
7. People & retention (see 25) - Founder/key-person dependence and lock-ups; engineering attrition. - Org scalability; security-talent access.
8. Tech, security & compliance - Architecture scalability; technical debt; the vendor's own security posture (a breached security vendor is an existential risk). - Certifications held (FedRAMP/CMMC/SOC2/ISO) — moats and gating.
9. Legal/structural - Customer contract assignability; IP ownership; open-source exposure. - Deal-completion risk: antitrust/CFIUS/financing (see 29).
Top red flags (deal-killers / price-breakers)
- NRR < 100% or deteriorating cohort curves.
- Growth bought (CAC payback >2–3 yrs) rather than earned.
- High platform-bundling exposure in a draining pool.
- Services revenue dressed as software (margin/multiple mismatch).
- Customer/partner concentration; founder flight risk.
- The vendor's own security weak (incident history).
- AI commoditizes the core value ("analytical SaaS").
The 100-day plan and portfolio KPIs (post-close)
- First 100 days: secure the team (retention/incentives), stabilize GTM, rationalize product overlap, set the integration plan (treat integration as the product — see 30), define the value-creation bridge and the bolt-on pipeline.
- Cyber-specific portfolio KPIs to monitor: NRR, GRN, net-new ARR, Rule of 40, CAC payback, gross margin (and mix shift toward software), pipeline coverage, channel-sourced %, and — for services — SOC automation ratio / analyst productivity.
- Exit-readiness: scale + durable growth + margin + a clean equity story; mix shifted toward software multiples; a buyer universe mapped (03/08).
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.