M&A technology | High Point, NC

IT Due Diligence and M&A Technology Services in North Carolina

Preferred Data assesses the technology of a business you plan to buy, tells you in writing what it will cost to fix, and then helps you take over and integrate its IT after closing. We work with search funds, independent sponsors, private equity firms and strategic acquirers from our High Point office. Schedule a call or phone (336) 886-3282.

Call (336) 886-3282
In business since 1987
39 years
Active clients
100+
Average client tenure
20+ years
BBB Accredited rating
A+
On-site radius from High Point
200 mi
QoT turnaround, by report type
1 to 3 wks

What is IT due diligence in an acquisition?

IT due diligence is an independent review of a target company's technology before you sign: its systems, cybersecurity, software licenses, data, vendors and the people who run IT. It matters because problems are common. In a 2019 Forescout survey of 2,779 IT and business decision makers, 53% said their organization had hit a critical cybersecurity issue or incident during an M&A deal.

The same survey found that 65% of respondents had experienced buyer's remorse over cybersecurity concerns after closing, and 73% agreed that an undisclosed data breach is an immediate deal breaker. Financial diligence rarely catches these issues, because an expired license, an unsupported server or an unpatched firewall does not show up on a balance sheet until it fails.

Preferred Data has written, installed and supported business software and networks for manufacturers and distributors since 1987. We read a target's technology the way an operator will have to live with it after closing, not only the way a checklist describes it.

Key takeaway: IT due diligence turns unknown technology risk into a written list of findings, each with a severity and an estimated cost to fix, that you can price into the deal.

What is a Quality of Technology (QoT) report?

A Quality of Technology (QoT) report is Preferred Data's written technology due diligence deliverable. It does for a target's technology what a Quality of Earnings (QoE) report does for its financials: it validates what the seller says, names the risks, and estimates what it will cost to fix them after closing. The standard full report takes 2 to 3 weeks.

The full report ends with a presentation to your deal team and time for questions. For the full scope and an instant price estimate, see the Quality of Technology report page. For background, read what a Quality of Technology report is and why acquirers use one.

  • Executive summary with key findings and risk ratings
  • Cybersecurity posture assessment
  • Compliance gap analysis with a remediation roadmap
  • Software and licensing inventory, with vendor contract review
  • IT personnel and key-person dependency review
  • Hardware, network and cloud infrastructure documentation
  • Risk register with prioritized actions and remediation cost estimates
  • Integration recommendations and a 90-day, 180-day and one-year technology roadmap

QoT Lite or a full QoT report: which does my deal need?

QoT Lite is a fixed-price review of the four highest-risk areas (cybersecurity, compliance, infrastructure and software licensing), delivered in 1 to 2 weeks, and suits self-funded searchers and smaller businesses. The full QoT report covers those areas in more depth plus IT people, vendors and integration planning, and suits larger deals or investors who require full documentation.

QoT Lite and the full QoT report compared (source: the QoT and QoT Lite pages on preferreddata.com)
FactorQoT LiteFull QoT report
Best fitSelf-funded searchers and smaller acquisitionsPrivate equity, independent sponsors, funded searchers and larger deals
Areas coveredCybersecurity, compliance, critical infrastructure, software licensingAll of QoT Lite, plus IT people and organization, vendors and contracts, a risk register and integration planning
Standard turnaround1 to 2 weeks2 to 3 weeks
Report length15 to 25 pages, executive summary focus40 to 80 pages, detailed documentation
Published priceFixed price by company size, $1,500 to $7,500Quoted by company size and scope, $7,500 to $50,000
Post-close planningDay-one integration priorities90-day, 180-day and one-year technology roadmap
Get a priceQoT Lite calculatorQoT report calculator

If a QoT Lite turns up something serious, you can upgrade to the full report, and the QoT Lite fee is credited toward it. For a search-fund view of the same decision, read our technology assessment framework for search fund acquisitions.

How much can a hidden technology problem cost a deal?

Enough to move the price. After Yahoo disclosed two large data breaches, Verizon and Yahoo agreed to cut the purchase price by $350 million, to about $4.48 billion. Marriott acquired Starwood in 2016, found in 2018 an attack on Starwood's systems that dated to 2014, and was later fined £18.4 million by the UK regulator over 339 million affected guest records, per Hunton Andrews Kurth.

Small deals carry the same risk at a smaller scale, and with less cushion to absorb it. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million, a record high. A breach inherited in a business bought for a few million dollars can erase the equity in it.

The more common findings are less dramatic and still expensive: servers and firewalls past end of support, software used beyond what the license allows, one employee who holds every password, and backups nobody has ever restored. Each one is a cost the buyer pays after closing unless it is found and priced first. Read more in how technical debt destroys M&A value.

Key takeaway: A technology finding before signing is a negotiating point. The same finding after closing is the buyer's expense.

What should technology due diligence cover for a small business acquisition?

For a small business acquisition, technology due diligence should confirm who owns and controls every system, whether the business can keep running without the seller or a single IT person, and what it will cost to bring security and licensing up to standard. Search fund deals are typically small businesses: the Stanford GSB 2026 Search Fund Study reports a median purchase price of $16 million for firms acquired in 2024 and 2025.

Use our IT due diligence checklist for small business acquisitions and our guide to IT vendor contract review during M&A to prepare your data room requests, or run a first pass with the free M&A technology readiness tool.

  • Access and ownership: domain names, Microsoft 365 or Google tenants, admin accounts and passwords, and who holds them
  • Key-person risk: whether IT lives in the owner's head, a nephew's laptop or an outside vendor with no contract
  • Security basics: multi-factor authentication, patching, endpoint protection and backups that have actually been restored
  • Licensing: software counts against what is paid for, and licenses that do not transfer with a change of ownership
  • Business systems: ERP, accounting and line-of-business software, who supports them, and what happens if that vendor leaves
  • Contracts: IT vendor, telecom and software agreements with change-of-control terms, auto-renewals or early exit fees

What happens to IT after the acquisition closes?

After closing, the buyer has to take control of every account and system on Day 1, separate from the seller's shared services, fix the risks diligence found, and then integrate or standardize IT across the business. Preferred Data plans that work from the QoT roadmap and can run it on-site anywhere within 200 miles of High Point.

For manufacturers, integration usually includes plant-floor networks and the ERP that runs order entry, inventory and production. Preferred Data builds and supports the PDC Software ERP suite for manufacturers and distributors, so we can assess and support that layer as well. Read our 90-day playbook for post-merger IT integration at NC manufacturers.

  • Day 1: transfer admin credentials, domains and vendor accounts to the new owner, and remove access for people who have left
  • First 90 days: close the critical security gaps, fix licensing and put restore-tested backup in place
  • Integration: consolidate email, networks and business systems where it makes sense, or keep them separate on purpose
  • Ongoing: day-to-day support and 24/7 threat detection and response through our managed IT plans, with cybersecurity services and network infrastructure as needed

Who does Preferred Data support on acquisitions?

Preferred Data works with search fund and ETA buyers, independent sponsors, private equity firms and strategic acquirers buying lower middle market businesses, with particular depth in manufacturing, distribution and other operational companies. Most QoT work can be done remotely for targets anywhere in the U.S., and on-site work is available within 200 miles of our High Point office.

  • Search fund and ETA buyers who need a clear, affordable read on a first acquisition
  • Independent sponsors and private equity firms that need a documented technology review for investors or lenders
  • Owners of an acquired business who need a technology partner after closing
  • Industry pages for manufacturing, furniture, textile and logistics businesses

Some of our M&A industry partners

We work alongside the platforms and advisors buyers use for search, deal sourcing and legal work.

IT due diligence questions buyers ask us

What is IT due diligence?

IT due diligence is an independent review of a target company's technology before an acquisition closes. It covers systems, cybersecurity, software licenses, data, IT vendors and the people who run IT, and ends in written findings with the estimated cost to fix each one.

How much does IT due diligence cost for a small business acquisition?

Preferred Data publishes its ranges. QoT Lite is a fixed price by company size, from $1,500 to $7,500, and the full Quality of Technology report is quoted by company size and scope from $7,500 to $50,000. Both pages have a calculator that gives an instant estimate.

How long does a Quality of Technology report take?

The standard turnaround is 1 to 2 weeks for QoT Lite and 2 to 3 weeks for the full QoT report, from the start of data collection. If your deal timeline is tighter, tell us when you call so we can scope the work to it.

How is a QoT report different from a Quality of Earnings report?

A Quality of Earnings report validates a target's financial results. A Quality of Technology report validates its technology: infrastructure, cybersecurity, compliance, software and IT people. It also estimates post-acquisition IT costs, which feed back into the financial model.

Do you perform technology due diligence outside North Carolina?

Yes. Most QoT assessment work can be done remotely for targets anywhere in the United States, with site visits scheduled when the transaction needs them. On-site support after closing is available within 200 miles of High Point, which covers the Piedmont Triad, Charlotte and Raleigh.

Does IT due diligence include a cybersecurity assessment?

Yes. Cybersecurity posture is part of both QoT Lite and the full QoT report. We look at controls such as multi-factor authentication, patching, endpoint protection and backup, because an undisclosed breach becomes the buyer's problem after closing.

Can Preferred Data manage IT for the business after we buy it?

Yes. Many buyers use the QoT roadmap as the starting plan for integration, then move the business onto one of our managed IT plans, each of which includes 24/7 threat detection and response. Integration projects are scoped and quoted in writing before work starts.

Sources

Know the technology risks before you sign

Tell us about the business you are buying and your timeline. We will recommend QoT Lite or a full Quality of Technology report, confirm the scope and price in writing, and plan the handover after closing.

(336) 886-3282

Preferred Data Corporation, 1208 Eastchester Drive, Suite 131, High Point, NC 27265