Buyer Guide 12 min read

Why Your SaaS Acquisition Dies in the Cloud Cost Audit: A Practical Guide to Infrastructure Due Diligence

The most expensive line item in a SaaS business is rarely software development; it is the infrastructure underneath it. If you miss the cloud bloat, you buy the problem.

2026-08-27  ·  By Sophal Lanh, Founder of Deal Alert AI

Deal Alert AI is reader-supported. We earn commissions from affiliate links at no cost to you.

This post is based on a video from our Deal Alert AI YouTube channel. Watch the original or read the full breakdown below.

The Invisible Margin Killer: Why Infrastructure Needs a Separate Audit

When most buyers approach a SaaS acquisition, their due diligence efforts are narrowly focused on revenue quality, churn rates, and key employee retention. And with good reason. These metrics determine the fundamental viability of the business. However, there is a massive trend in modern SaaS acquisitions where the real danger lies in the back end. I have reviewed hundreds of deals over the last decade, and consistently, the cloud infrastructure is the source of the most shocking margin discrepancies between the seller’s projected finances and the buyer’s reality.

Why does this happen? Because cloud costs are dynamic, complex, and often poorly documented by internal engineering teams. Sellers rarely itemize their AWS or GCP bills with the same granularity as their P&L. They might show you a total "Infrastructure" line item that looks reasonable against revenue, but they rarely explain the composition of that cost. They might be over-provisioning resources to avoid downtime, or they might be using a multi-tenant architecture that is inefficient at scale. If you do not audit these costs separately, you are flying blind.

I see this every week. A buyer thinks they are pouring $50k a month into a business that has $800k in Annual Recurring Revenue (ARR). That looks like a healthy percentage. But after I step into the technical due diligence process, I uncover that $50k actually includes $15k in unused development environments, $10k in inefficient data retrieval patterns, and $5k in legacy services that the product no longer uses. Suddenly, the true cost of goods sold (COGS) is not 6.25% of revenue, it is nearly 10%. That is a massive difference in risk. This is why a dedicated cloud cost analysis is non-negotiable for any buyer looking for a profitable entry point.

Key Insight: Cloud infrastructure costs are often under-reported in SaaS acquisitions because internal engineering teams do not track "waste" as a financial metric. They track uptime. You must translate technical inefficiency into financial loss during your offer phase.

Understanding the Difference Between IaaS, PaaS, and SaaS Hosting

Get Free Deal Alerts Every Morning

We scan Empire Flippers, Flippa, Acquire.com and Quiet Light daily — scoring every listing. Start free.

To effectively audit the infrastructure of a target company, you need to understand the hosting model they are using. Not all cloud bills look the same, and the risk profile differs significantly depending on whether the company is on Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or a managed SaaS hosting platform. Most early-stage SaaS companies start on PaaS to move quickly, but many struggle to transition to more cost-effective models as they scale. Your job as a buyer is to determine if their current model is a strategic advantage or a legacy burden.

IaaS, such as raw compute instances on AWS or Azure, offers the highest level of control but also the highest level of complexity and potential for waste. If the target company is running on IaaS, you need to look at their reserved instance utilization and auto-scaling policies. Are they running servers at 10% capacity 24/7? If so, that is pure cash burn. PaaS, such as Heroku or Render, abstracts away the server management. It is more convenient, but per-unit costs tend to be higher. As a company scales past a certain revenue threshold, PaaS often becomes a margin leak that is too large to ignore.

There is also the rise of specialized SaaS hosting platforms, which bundle the infrastructure, security, and maintenance. For smaller SaaS businesses, this can be a strength because it requires less internal engineering headcount to manage. However, for larger businesses with high transaction volumes, this can be a weakness due to egress fees and rigid pricing tiers. When evaluating a deal, you must identify where the target sits on this spectrum. If you are buying a business that is on a PaaS that is inefficient for its scale, you must price the business as if you are inheriting a transition project, not just a revenue stream. At Deal Alert AI, we flag these architectural mismatches in our initial deal screening reports to ensure buyers are aware of the technical debt before they commit capital.

Decoding the Cloud Bill: Line Items You Must Ask For

Never accept a single "Cloud Costs" number in a data room. It is too opaque. You need a breakdown. Demand a line-item view of the last 12 to 24 months of cloud invoices. I have found that when sellers are asked for specific line items, the conversation about the efficiency of their engineering department immediately becomes more transparent. You are looking for specific patterns. First, look at compute costs. Is spending on compute correlated with user activity? If your user base is static but your compute costs are climbing, you have a technical debt problem or an architectural flaw.

Second, examine data storage and retrieval. In SaaS, data is the product. Is the company charging for data they are not actually serving to users? Are they keeping historical logs on expensive high-performance storage instead of archiving them to cheaper cold storage? I once bought a log-based SaaS where 40% of their storage costs were for logs from a deprecated feature that had been turned off six months prior. Those logs were still being stored, indexed, and potentially transferred, costing thousands of dollars a month for zero user value. That was a direct add-back opportunity in my negotiation.

Third, look at data transfer and egress fees. This is the silent killer. If the SaaS product frequently downloads large files, datasets, or media content to the user, the egress fees can skyrocket. AWS, for example, charges for data leaving their data centers. If the target company has not optimized their content delivery network (CDN), you are paying for every megabyte sent to the end user. You need to compare the egress costs against the number of paid users and the average usage profile. If the egress cost per user is rapidly increasing while revenue per user stays flat, your gross margin will collapse over the next 24 months.

Warning: Many SaaS companies use free or discounted cloud credits during their early growth phase. These credits mask the true cost of infrastructure. When the deal is structured, ensure the credits are expiring or accounted for in the post-close EBITDA model. If you assume the current cloud bill is sustainable, and the seller is currently using $20,000/month in credits that expire next month, your profit margin will be artificially inflated by $20,000/month.

The ROI of Automated Cost Optimization Tools

Once you have the raw data, the next step in due diligence is to simulate an optimization pass. You do not need to fix the infrastructure; you need to know the maximum amount of money you could save by fixing it. In my experience, most SaaS companies waste between 20% and 40% of their cloud budget due to a lack of automated cost management. They do not have the time or the internal engineering focus to act as their own cost engineers. You can use third-party tools to model this. Tools like CloudHealth, Vantage, or native cloud cost managers can scan the account and provide an immediate report on provisioned capacity versus utilized capacity.

Let’s look at a practical example. Suppose a SaaS company spends $40,000 a month on cloud infrastructure. Using a cost intelligence tool, you find that 30% of their compute instances are consistently running below 10% CPU usage during peak hours. This indicates over-provisioning. You also find that they are paying for annual reserved instances that have not been fully utilized because their traffic is spiky. If you model a realistic consolidation strategy—rightsizing instances, implementing auto-scaling more aggressively, and shifting workloads to spot instances where possible—you might identify a $12,000 a month savings potential. That is $144,000 a year in pure margin improvement.

This number is critical for your valuation. If the business is being valued at 3x Net Income, that $144,000 in optimized savings is worth $432,000 in enterprise value. By identifying this during due diligence, you do not just buy a business that makes X; you buy a business that you can make make X plus Y. This is the power of financial and technical due diligence working in tandem. I always advise buyers to include an optional phase in their term sheet for a 14-day technical audit of the codebase and infrastructure. This gives you the visibility needed to make an informed decision. You can find many suitable targets with this kind of hidden upside on platforms like Flippa, but you must be ready to do the math before you bid.

Scalability Analysis: Will the Cloud Bill Grow Faster Than Revenue?

Cost savings are about the present, but scalability is about the future. When evaluating SaaS infrastructure, you must analyze the "cost per transaction" or "cost per active user." Is this metric trending up, down, or flat over the last 12 months? If the cost per active user is trending up, the infrastructure is not scalable. It is becoming less efficient as the business grows. This is a red flag. It suggests that the architecture is reaching its limits or that the engineering team has failed to optimize for growth. In these cases, the business may hit a "capacity wall" where further growth requires disproportionate increases in infrastructure spend.

Conversely, if the cost per user is trending down, the architecture is benefiting from economies of scale. This is the hallmark of a healthy, scalable SaaS model. I look for a "negative correlation" between revenue growth and infrastructure cost ratio. As revenue goes up, the percentage of revenue spent on cloud should go down. If you see the opposite, or if the ratio remains stubbornly high despite high growth, you need to dig deeper. Are they adding data centers? Are they migrating to a more expensive region for latency reasons? Every technical decision has a financial cost that eventually impacts your EBITDA.

You should also stress-test the infrastructure model. Ask the engineering team: "If our user base doubles in the next six months, what happens to the cloud bill?" A competent engineering team will have a plan. They will know that their current database size requires sharding, or that they need to implement queue-based processing for asynchronous tasks. If they do not have a plan, or if the estimate for doubling costs suggests a 250% increase in infrastructure spend for a 100% increase in users, you are buying an expensive problem. This scalability analysis is just as important as the current bill. It determines whether the margins you are buying today will exist tomorrow.

Strategic Insight: In SaaS acquisitions, "Technical Debt" is a financial liability. It is not just a code bug; it is an ongoing operating expense. When you calculate your return on investment, subtract the estimated cost of technical debt refactoring (including infrastructure re-architecture) from your Year 1 projections. If the deal does not work with that deduction, it is not a good deal.

Negotiation Leverage: How to Use Infrastructure Findings

Due diligence is not just about finding problems; it is about creating leverage. If you find that the cloud bill is bloated, do not just quietly adjust your internal valuation. Raise it in the negotiation. Position yourself as a buyer who understands the operational reality of the business. Tell the seller, "Our analysis suggests that the current infrastructure is not optimized for its scale. We project a $100,000 annual saving post-close due to rightsizing. We are adjusting our offer to reflect the current, un-optimized cash flow profile." This is a powerful psychological move. It shows you are not a naive buyer who thinks the financials are perfect. It validates their need to sell, but it also justifies your lower offer.

Alternatively, you can use this information to structure the deal with performance metrics. For instance, you might agree to the seller’s price, but you add a clause that the seller must help migrate the infrastructure to a more cost-efficient model within the first 90 days of closing. You can tie a portion of the earnout or the escrow holdback to the successful reduction of cloud costs by a specific percentage. This aligns the seller’s incentive with yours. They want the deal to close, and if they sign up to help optimize the cloud, they demonstrate good faith and technical competence. This can differentiate a professional buyer from a flipper.

Finally, use the infrastructure audit to identify synergies. If the target company is using a specific cloud provider that you or your other portfolio companies are already deeply integrated with, you can offer to consolidate their workloads onto your existing enterprise agreements. This can immediately lower their costs without any engineering effort. This is a sweetener that you can offer in the negotiation. It shows that you bring more than money; you bring operational expertise. I have successfully used this approach to close deals at a 10-15% discount to the asking price because the seller was relieved to offload the infrastructure complexity to a buyer who already had the framework in place. For more structured deals, platforms like Empire Flippers often have sellers who are open to these kinds of post-close integrations, provided they are discussed early in the process.

Building Your Due Diligence Checklist

To ensure you never miss a potential margin leak, you need a standardized process. I have compiled the following checklist based on the most critical areas where SaaS businesses lose money in the cloud. Use this in your initial data room review. If the seller cannot provide this information quickly, it is a sign that their operations are less mature than they claim. A mature SaaS business should have cloud cost visibility as a standard operational metric. If they do not, you are buying the cost of their immaturity.

  1. 12-Month Cloud Bill Breakdown: Obtain itemized invoices for the last 12 months. Verify that the total matches the COGS line item in the financial statements.
  2. Compute Utilization Report: Request a report on CPU and memory usage for all running instances. Identify the top 10 most expensive services and their average utilization rate.
  3. Reserved Instance Agreement: Check for any prepaid commitments (RI, Savings Plans). Identify the start and end dates of these contracts and the penalty for early termination.
  4. Auto-Scaling Policies: Review the rules that dictate when servers are added or removed. Are they scaling based on CPU, or are they stuck on static configurations?
  5. Database Storage Analysis: Break down the cost of data storage. Separate hot storage (frequently accessed) from cold storage (archived). Identify any data older than 12 months that is still on high-performance tiers.
  6. Egress and CDN Costs: Analyze the cost of data transfer out of the cloud. Compare this cost against the number of active users to determine the cost-to-serve ratio.
  7. Development vs. Production Spend: Ensure that the cost of development and staging environments is not being miscoded as production costs, or vice versa. This distorts the true unit economics.
  8. Cloud Credit Inventory: List all current and expiring cloud credits. Calculate the effective discount rate currently applied to the business's true infrastructure cost.
  9. Disaster Recovery Costs: Review the cost of automated backups and snapshots. Ensure that the frequency of backups is no more frequent than necessary for the business risk profile.
  10. Vendor Lock-in Risks: Identify any proprietary services or features that would make migration to a different cloud provider expensive or technically difficult. This affects your long-term flexibility.

This checklist is not exhaustive, but it covers the vast majority of financial exposure related to cloud infrastructure. By systematically working through these points, you transform the infrastructure from a vague line item into a set of actionable insights. You move from guessing the margin to calculating it. This precision is what separates professional buyers from hobbyists. It is the difference between buying a business and buying a house of cards that will collapse when the wind changes.

Common Mistakes Buyers Make in Infrastructure Audit

Even experienced buyers make mistakes in this area. The biggest one is assuming that because the business is profitable today, the infrastructure is fine. Profitability is a lagging indicator of current efficiency, but it does not guarantee future efficiency. Many businesses are subsidized by founder-run operations where the founder hawks the cloud bill personally. Once you buy the business, you no longer have that hawk. The costs will drift up. You need to build the controls that the founder lost, or price them in.

Another common mistake is ignoring the "hidden" costs of support. Infrastructure issues often lead to increased support tickets. If the infrastructure is unstable, your support team spends more time troubleshooting. This drives up your customer acquisition cost and churn. You must quantify the cost of downtime. Ask for an uptime report. If the business had 99.0% uptime last year, and they target 99.9%, the cost of achieving that reliability might be higher than your projected margins. There is a direct correlation between infrastructure stability and customer retention. Do not ignore this link.

Finally, many buyers fail to think about the "exit" from the current cloud provider. If you buy a business that is deeply entrenched in a specific, expensive ecosystem, and you plan to sell it in three years, you are limiting your buyer pool. Some buyers prefer AWS, others prefer Azure, and some prefer GCP. If the target is on a niche platform, you cannot easily migrate without significant engineering cost. This liquidity risk in the exit phase should be factored into your entry price. If the infrastructure is hard to move, it is harder to sell. That is a simple market truth that requires advanced planning. As I often remind my clients at Deal Alert AI, diligence is not just about the numbers on the page; it is about the options you preserve for the future.

Final Thoughts: Infrastructure as a Competitive Advantage

Cloud infrastructure is not just a cost center; it is a product feature. In some cases, low latency and high reliability are the main reasons customers choose a SaaS over a competitor. Therefore, your audit must be balanced. You are not trying to cut corners to the point of poor performance. You are trying to remove waste while maintaining the quality that justifies the revenue. This requires nuance. It requires you to talk to the engineers, not just the CFO.

I encourage you to view every SaaS acquisition as an engineering audit as much as a financial one. The numbers in the P&L are the result, not the cause. The cause is the code, the architecture, and the cloud bill. By understanding the cause, you can predict the result with high accuracy. You can buy a business that is not just profitable today, but efficient tomorrow. That is the true definition of value in the SaaS arena.

Doing this work requires the right data and the right intuition. Many buyers are good at one or the other, but few are good at both. That is where specialized platforms come into play. At Deal Alert AI, we provide the data context that allows you to blend financial rigor with technical insight. We help you see the wood for the trees. So, before you sign that next term sheet, pause. Look at the cloud bill. Ask the hard questions. And only then, make your offer. Your future EBITDA depends on it.

Frequently Asked Questions on SaaS Cloud Costs

How much of my revenue should cloud costs represent for a SaaS? There is no single rule, but for standard SaaS, 10-20% of revenue is a common baseline for COGS including infrastructure. However, for data-heavy applications like video hosting or data analytics, this can be higher. For lightweight tools, it can be lower. The key is the trend. If your cloud spend is growing faster than your revenue, you have a problem. If it is growing slower, you are scaling efficiently.

Should I allow the seller to fix the cloud costs before closing? Generally, no. Because the seller is incentivized to preserve their cash flow until the deal closes, they rarely have the motivation to actively cut costs or change architecture. By the time they make changes, you will have already closed. It is a classic moral hazard. You are better off paying the current inefficient price and fixing it yourself post-close, or adjusting the price to reflect the fixed state. Do not trust the seller to do your work for you for free.

What is the best cloud provider for a new SaaS buy? The "best" provider depends on your existing team and the target's architecture. Migrating an application from AWS to Azure is a massive project. If the target is on AWS, stay on AWS for the first 6-12 months. Learn the bill. Optimize what you have. Only consider a migration if the savings justify the engineering effort. Do not migrate for ideology; migrate for economics.

How do I verify the cloud bill provided by the seller? You need read-only access to the cloud account. This is the only way to verify the bill. Sellers often try to get away with providing PDFs of invoices. You must ask for a read-only AWS/GCP/IQ user that allows you to view the billing dashboard and the raw usage data. If they refuse, do not sign. It is a massive red flag that suggests they are hiding underutilized resources or misconfigured accounts.

Does cloud cost optimization help with seller's EBITDA add-backs? Only if the optimization is ongoing or can be applied immediately without significant one-off cost. If you can show that 15% of the cloud bill is "waste" that will disappear as soon as you take over and turn off unused instances, you can argue to add that back to their EBITDA. You are essentially saying, "The business is actually more profitable than they are reporting because they are failing to manage their costs." This is a valid and common add-back in SaaS due diligence.

What about data privacy costs? If your SaaS handles sensitive data, you are likely paying for higher-tier security features, encryption at rest, and compliance audits. These are not waste; they are necessary. Do not cut corners on compliance to save on cloud costs. If you are in a regulated industry, ensure your cloud audit includes a review of compliance-related spend. It will likely be higher than unregulated peers, and that is expected.

How do I price the cost of migrating to a new cloud provider? Estimate the fully loaded cost of an engineer’s time for 3-6 months of work, plus the cost of data transfer and dual-running environments during the migration. This is usually a significant six-figure expense for mid-market SaaS. Do not factor this in if you are not planning to migrate. Only factor it in if you have a strategic reason to go to a specific provider.

What are the signs of a "legacy" cloud architecture? Signs include: using instance-based pricing instead of serverless, no containerization (or very poor containerization), monolithic applications running on giant servers, and a lack of multi-region redundancy. These are all signs that the architecture was built quickly and has not evolved. It works, but it is expensive and brittle. It will require a rewrite or significant refactoring to scale further.

Is it worth hiring a cloud consultant for due diligence? For deals over $1M, the answer is almost always yes. A specialist can spend 20 hours in the codebase and cloud dashboard and find a six-figure optimization opportunity. For smaller deals, you might be able to do it yourself if you have the technical background. But if you are not technical, you are being exploited by the complexity. Pay for the expertise. It is the best insurance you can buy for your new business.

How does "reserved capacity" affect my negotiation? If the seller has a large reserved capacity contract (e.g., 3 years of compute time) that is expiring, you have a choice. You can negotiate the price down assuming they will not renew it at the same level, or you can assume they will renew it and lock in their costs. Expiring reserved instances are a key point of leverage. They give you immediate flexibility to restructure the stack without penalty, which lowers your risk.

By Sophal Lanh, Founder of Deal Alert AI: Sophal built Deal Alert AI after years of analyzing online business acquisitions and missing time-sensitive deals. The platform tracks and scores 100+ listings daily across Empire Flippers, Flippa, Acquire.com, and Quiet Light. Learn more →

Get Deals Before Other Buyers

We scan Empire Flippers, Acquire, Flippa, and Quiet Light daily. The best sub-$500K businesses are gone within 48 hours.