Buying a SaaS company without rigorous due diligence is gambling with your personal liquidity. This guide provides the exact validation framework professionals use to verify revenue, code quality, and founder dependency before signing a term sheet.
Deal Alert AI is reader-supported. We earn commissions from affiliate links at no cost to you.
This post is based on a video from our Deal Alert AI YouTube channel. Watch the original or read the full breakdown below.
The acquisition of Software as a Service (SaaS) businesses has evolved significantly since the post-pandemic boom. In 2026, the market is less forgiving of inflated metrics and more attentive to the structural integrity of recurring revenue streams. For buyers, the barrier to entry is no longer just capital; it is the ability to distinguish between a business that yields predictable cash flow and one laden with hidden technical debt and revenue churn. The cost of error in this sector is not merely a poor return on investment; it is the potential for total capital destruction if the underlying product fails to scale or if the sales pipeline is fabricated.
I have seen well-intentioned buyers wipe out their entire liquidity because they skipped a single line item in the technical audit. They bought a company based on a Management Buyout presentation that showed strong year-on-year growth, only to discover six months later that 40% of that growth came from one-off enterprise contracts that were never renewed. The business model was not recurring revenue; it was a project-based service business wearing a SaaS costume. Due diligence is not a bureaucratic hurdle. It is the primary defense mechanism for your equity.
This guide outlines the specific architectural and financial questions you must ask before you sign a term sheet. We will move beyond generic checklists and dive into the granular details that separate professional acquirers from impulsive traders. If you are looking to source deals, platforms like Deal Alert AI can help you filter out high-risk assets before they even enter your pipeline, but once you have a target, the verification process described here is non-negotiable. We are talking about 35 critical questions, categorized by risk area.
We scan Empire Flippers, Flippa, Acquire.com and Quiet Light daily — scoring every listing. Start free.
The first and most painful section of due diligence involves verifying that the revenue reported by the founder is real, recurring, and not dependent on specific, non-renewable circumstances. In private acquisitions, you do not have access to a seasoned auditor at this stage, so you must perform the work yourself or hire a forensic accountant. The primary goal is to identify "revenue leakage." This occurs when a company books revenue upfront that they are obligated to deliver later, or when they count cancelled but unbilled accounts as active MRR (Monthly Recurring Revenue).
Start by demanding the full contract history for the last 24 months. Do not accept a spreadsheet dump. You need to see the actual purchase orders or signed Master Service Agreements (MSAs). You are looking for red flags such as multi-year prepayments that were booked in full rather than recognized over time. If the founder claims a 10% month-over-month growth rate, you need to verify that this growth is driven by new logo acquisition, not by price increases on existing accounts. Price increase revenue is a one-time event, not a structural indicator of market demand. If 50% of your growth comes from repricing old contracts, your "growth" is a mirage.
Furthermore, you must analyze the churn rate in high resolution. Many sellers present a "Gross Churn" number vs. a "Net Revenue Retention" (NRR) number that hides the decay. A company can have 10% logo churn but maintain high NRR if they upsell the remaining customers aggressively. However, if the underlying codebase is buggy, those upsells will eventually fail. You need to see the cohort analysis. Did customers acquired in Q1 2024 still exist in Q1 2025? If the retention curve flattens quickly, the product has a fundamental value problem. Ask specifically about "voluntary" vs. "involuntary" churn. Involuntary churn (failed cards) is an operations issue. Voluntary churn (customers leaving) is a product issue. If voluntary churn exceeds 2% monthly, the business is a leaky bucket, and no amount of marketing spend will fix it.
The second pillar of SaaS due diligence is technical. For buyers, the codebase is the asset. In traditional manufacturing, you inspect the machines. In SaaS, you inspect the code. A company can have perfect financials while sitting on a tech stack that is fundamentally unscalable. This is known as technical debt. If the code is brittle, any attempt to scale marketing spend will result in server crashes, data corruption, or security breaches. These events are existential threats to a SaaS business because trust is the only product you are selling.
You need to engage a senior software engineer, not a junior developer, to review the repository. Do not rely on the CTO to give you a tour; they have a bias for optimism. Your engineer should look at the deployment pipeline. Is it automated? If deploying new features requires manual database migrations performed by the founder, the business is entirely dependent on their availability. This is a single point of failure. In 2026, if a company is not running on cloud-native infrastructure like AWS or Azure with auto-scaling groups, it is a red flag. Ask about the incident history. How many P0 (critical) outages occurred in the last 12 months? What was the root cause? If the answer is "human error" or "legacy code patching," you are buying a liability, not an asset.
Security is the third technical dimension. SaaS companies hold sensitive user data. In the current regulatory climate, a single data breach can destroy the valuation of the company overnight. You must review their SOC 2 Type II report. If they do not have one, it is a massive warning sign. Ask about their data encryption practices. Is data encrypted at rest and in transit? How are API keys managed? Are they hard-coded in the source code? This is a common sloppy practice in early-stage SaaS businesses that becomes a fatal security vulnerability at scale. The cost of remediating poor security architecture is often 2-3x the cost of the acquisition itself, meaning you will lose money immediately upon closing.
Revenue quality is not just about the total number; it is about the distribution. A common trap in SaaS acquisitions is customer concentration risk. If one client represents more than 10-15% of your total MRR, you do not own a SaaS company; you own a Key Account manager. If that client leaves, your revenue drops significantly, and your multiple valuation collapses instantly. You must analyze the top 10 customers. What percentage of total revenue do they represent? If the top 3 customers account for more than 30% of revenue, you need to apply a heavy discount to the valuation. The risk is too high to justify a standard SaaS multiple.
Equally important is the health of the sales pipeline. SaaS businesses are valued based on future growth, which is driven by the pipeline. You need to audit the CRM (Salesforce, HubSpot, Pipedrive) for data integrity. Are there old deals that have been "stalled" for six months but are still marked as "active"? This is pipeline inflation. You need to calculate the "Win Rate" and "Sales Cycle Length" for the last two quarters and compare them to the projections for the next year. If the historical win rate is 20% but the board deck assumes a 40% win rate to hit revenue targets, the sales team is either incompetent or the forecast is fabricated. Ask for the call recordings. You want to hear the actual objections the sales team is facing. If customers are citing price as the main objection, but the seller raises prices every month, the company will hit a wall shortly after closing.
Additionally, look for "land and expand" dynamics. Are you making money by acquiring new logos, or by expanding contracts with existing logos? While expansion revenue is higher margin, it is also more fragile. If a key account decides to standardize on a competitor, you lose the initial contract and all future expansion. A healthy SaaS business in 2026 has a balanced mix: 70% new acquisition and 30% expansion. If the split is 50/50 or heavily weighted toward expansion, the founder may be neglecting new business development because it is harder to sell to cold leads than to warm upsells. You will inherit a sales team that does not know how to prospect.
In small SaaS companies (under $1M MRR), the founder is often the product, the salesperson, and the support lead. This is called Key Person Risk. If you buy a company where the founder personally calls on the top 5 clients, those clients will leave when the founder hands over the keys. Businesses are built on relationships, especially in B2B enterprise SaaS. You must quantify this dependency. How much of the sales pipeline was generated by the founder’s personal network? How much of the product roadmap is held in the founder’s head rather than documented in a project management tool? If the answer is "most," you are buying a job, not a business.
The operational aspect also involves software dependencies. Does the SaaS product rely on third-party APIs for core functionality? For example, if your "AI writing tool" relies entirely on the OpenAI API for its backend logic, you are at the mercy of their pricing changes, rate limits, and terms of service. If OpenAI raises their prices by 50%, your margins evaporate. You need to ask about fallback architectures. Do you have a backup plan? If the product is a wrapper around a third-party service, the IP (Intellectual Property) is thin, and the moat is non-existent. Competitors can build the same thing in a week. The value is then based solely on brand and distribution, which are harder to verify in due diligence.
Support operations are another hidden cost center. In SaaS, support is a product feature. If the Net Promoter Score (NPS) is low, it is because the support is poor. Ask for the last 100 support tickets. Read them. Are customers angry? Are resolutions taking weeks? If they use a shared inbox for 200 customers, their support model will not scale. You need to understand the Full-Time Equivalent (FTE) cost per ticket. If it takes 30 minutes of a human to close a ticket, and you have 10,000 tickets a month, you need a massive support team just to break even. If the current team is handling this with 2 people, they are either undercharging or the volume is misrepresented. You must model the support costs at scale, not at the current snapshot.
The legal due diligence phase is where many amateur buyers get trapped by technicalities. The most critical item is Intellectual Property (IP) assignment. The code, the database schema, the customer data, and the brand assets must all be owned by the holding company, not by the individual founders. It is shocking how many SaaS companies have been built on personal GitHub accounts or personal email addresses. If the code is owned by the founder personally, you do not own the business. You own a string of shell companies that rely on the goodwill of the founder to grant access. You need a clean chain of title. Every line of custom code must have a "Work for Hire" agreement or an IP Assignment document signed by the engineer who wrote it. If they used freelance developers on Upwork, check the contract. Did it assign the IP to the company? If not, you have legal exposure. The freelancer could claim ownership of the algorithms you just bought.
Contractual terms with customers are the second legal minefield. Review the Standard Terms of Service and Master Service Agreements. Do they contain non-cancellation clauses? In many jurisdictions, you cannot force a customer to stay. If the contracts are vague, customers may cancel at will, even if they have pre-paid. This creates a legal liability for refunds. Also, check for "Most Favored Customer" clauses. If you agreed to give Customer A a 20% discount, and Customer B finds out, you are legally or contractually obligated to match it. This erodes your margins unpredictably. In 2026, with stricter data privacy laws (GDPR, CCPA), you must also verify how customer data is handled. Is it stored in compliant regions? Have there been any data subject access requests (DSARs)? If the company has ignored these, you inherit a legal debt.
Finally, examine the incorporation structure. Is the operating company separate from the holding company? If the founders are drawing funds from the operating company to pay personal expenses, this commingles assets and creates liability issues. You need to clean up the balance sheet before you sign. The purchase agreement should include specific indemnification clauses for pre-closing liabilities. For example, if an old tax error is discovered 12 months after closing, who pays? It must be the seller. Without this clause, you are on the hook for the founder’s past mistakes. This is why you need to use professional deal structures, often facilitated through platforms that provide standardized legal templates, such as Deal Alert AI, which connects buyers with vetted legal partners who understand SaaS-specific liabilities.
Due diligence is not just about finding problems; it is about determining the fair price. In 2026, valuations are no longer based on a simple multiple of EBITDA. They are based on Adjusted Free Cash Flow (FCF) and Rule of 40 metrics. You must strip out the "founder discount." If the founder is paying themselves $300,000 a year in bonuses or car leases, that is not an expense; it is a distribution. You must add this back to cash flow but also model the replacement cost. If you cannot afford to pay a next-gen CEO that amount, your bottom line will shrink. The valuation must reflect the normalized run-rate, not the peak performance achieved by overworking the founder.
Your exit strategy is also a part of due diligence. Who will you sell this to in 3-5 years? If you acquire a niche vertical SaaS with a thin moat, your exit pool is limited to strategic buyers in that specific industry. If you acquire a horizontal SaaS with broad applicability, your exit pool is much larger, including private equity firms and larger tech companies. This dictates how much you can pay. A business with a wide exit pool commands a premium. You need to ask: "Does this software have a network effect?" If it does, the value compounds over time. If it is just a transactional tool, the value is capped by the profitability of the tools market. Most transactional SaaS companies sell for 3-4x SDE. High-growth, high-retention platforms sell for 5-8x or more. If your due diligence shows retention below 90%, drop your bid into the 3-4x range. Do not pay for growth that is not sticky.
Consider the liquidity event itself. How do you protect your investment during the transition? Use an Earnout structure. Put 20-30% of the purchase price in an earnout tied to post-closing performance metrics. If the founder promises $100k MRR in Year 2 and they only hit $40k, you pay less. If the revenue drops due to their departure, you recoup your capital. This aligns the incentives. The seller must ensure the business remains healthy after they leave. It is the most effective risk mitigation tool in SaaS M&A. Do not sign a deal with 100% upfront cash payment unless the technical and financial diligence is perfect. In 90% of cases, it is not.
Below is the condensed version of the 35 questions we discussed, organized into an actionable checklist. Print this out and go through it with your lead engineer, your accountant, and your lawyer. If you cannot answer "Yes" or provide the document for any of these, you do not have enough information to proceed. Do not rush this. The two weeks you spend in due diligence will save you two years of operational hell.
Once you have mastered the due diligence process, the next challenge is finding deals that align with your investment thesis. The SaaS registration volume is high, but the quality is uneven. You need platforms that aggregate data from multiple sources and provide transparency on key metrics. This is where specialized marketplaces come into play. They bridge the gap between motivated sellers and informed buyers, often providing pre-vetted financial data to save you time on initial screening.
If you are looking for established businesses with solid financial histories and larger revenues, Empire Flippers is a strong starting point. They are known for rigorous vetting standards, which means you have a higher likelihood of accurate data up front. However, their listings are often priced at a premium. For buyers who are comfortable doing deeper manual due diligence on smaller, micro-SaaS opportunities, Flippa offers a wider range of inventory, including pre-revenue projects that might be good for technical founders looking to build rather than just operate.
Ultimately, the best deal is one where you understand the risks completely. You must combine the human insight of founder interviews with the cold hard data of code audits and bank statements. Do not let emotional attachment to a "great idea" cloud your judgment. SaaS is a numbers game. If the numbers do not pass the stress tests outlined in this guide, the idea does not matter. Your capital is limited. Spend it on assets that survive the due diligence process. As you scale your buy-and-hold portfolio, rely on data-driven platforms like Deal Alert AI to surface trends in valuation multiples and sector-specific risks, ensuring you are always priced better than the market average.
We scan Empire Flippers, Acquire, Flippa, and Quiet Light daily. The best sub-$500K businesses are gone within 48 hours.
We scan Empire Flippers, Flippa & Acquire every morning. The best deals sell in 48 hours.