Skip to content
Osintpro

Cybersecurity Due Diligence Software: M&A Cyber Due Diligence Before You Have Access

Cybersecurity due diligence splits into three layers, and only one of them can run before the target company cooperates. That first layer is external and records-based: registration history, DNS and mail posture, certificate surface, corporate registry filings, breach exposure. It needs no NDA, no data room and no contact with the target, and it is the layer this tool automates into a sourced, timestamped report.

Written for whoever has been asked for a cyber view on a target before anyone has handed over a single document.

See pricing
  • Scope recorded before collection.
  • Passive collection only.
  • Evidence a reviewer can re-run.
  • Built to clear procurement.

The three layers of cyber due diligence, and when each becomes possible.

Deal teams treat cyber diligence as one workstream. It is three, they unlock at different moments in the timetable, and confusing them is why the cyber answer usually arrives after the price has already been agreed.

What it establishes

Layer 1: external records
What the target has published about itself, and what third parties have recorded about it
Layer 2: disclosed evidence
What the target says about its controls, policies, incidents and insurance
Layer 3: hands-on technical
What is actually true inside the estate

Needs the target to cooperate

Layer 1: external records
No
Layer 2: disclosed evidence
Yes, a questionnaire and a data room
Layer 3: hands-on technical
Yes, credentials and written authorization

Earliest it can run

Layer 1: external records
Before first contact. Nothing is disclosed to the target
Layer 2: disclosed evidence
After the NDA and the data room open
Layer 3: hands-on technical
Usually only in exclusivity, sometimes post-close

Typical published cost

Layer 1: external records
$149 to $1,190 a month, self-serve
Layer 2: disclosed evidence
Analyst hours, or bundled into legal diligence
Layer 3: hands-on technical
$3,000 to $150,000 depending on scope and size

Who performs it

Layer 1: external records
The deal team or the acquirer's security lead
Layer 2: disclosed evidence
The target, reviewed by you
Layer 3: hands-on technical
A consultancy or a specialist firm

Fails when

Layer 1: external records
You need to know about internal controls
Layer 2: disclosed evidence
The target answers optimistically, or slowly
Layer 3: hands-on technical
There is no time and no access

What you get

Layer 1: external records
A dated evidence file on the target and its domains
Layer 2: disclosed evidence
Assertions you now have to corroborate
Layer 3: hands-on technical
A findings report with remediation costs

Layer 3 ranges are the published figures from three US assessment providers, checked in September 2026: $3,000 to $10,000 for small business, $10,000 to $50,000 mid-market and $50,000 to $150,000 or more at enterprise scale, with regulated industries quoted at a 35 to 45 percent premium. Layer 3 vendors that sell into M&A specifically, including Kroll and Unit 42, publish no figure at all and route every inquiry to a scoping call.

The request that arrives before you have any access.

The awkward version of this job is not the one with a data room. It is the call on a Tuesday where corp dev says they are looking at a target, the indication of interest goes out Friday, and somebody would like to know whether there is anything obviously wrong with the target's security before the number is written down. There is no NDA yet. There is certainly no credential. The target does not know you are looking.

The standard toolkit is useless at that moment. A questionnaire needs a counterparty willing to fill it in. A scan needs authorization you do not have and would not get. A consultancy needs a scope and three weeks. What is left is a browser, an analyst, and an afternoon of tabs that ends in a paragraph nobody can audit later.

That is the specific gap this fills. Everything collected here is already public and already published by the target or recorded about it by a registry, a certificate log or a registrar. Reading it is not an intrusion and it leaves nothing behind, so it is the only cyber diligence available to you in the week that actually matters commercially.

The output is deliberately shaped like a document rather than a dashboard, because the thing you owe the investment committee is a page they can read and a finding they can point at, not a login.

Run a target domain and read what comes back.

Declare the scope, enter a domain you are authorized to assess, and look at the artifact. Every finding carries the raw record it came from, the source endpoint and the UTC time it was retrieved. It takes a domain and never a person.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

What the external layer establishes about a target.

None of this requires the target to lift a finger, and all of it is checkable by anyone reviewing your file afterwards.

How old the operation really is

Registration and RDAP history dates the domain, the registrar and the transfer events. A company presenting a decade of trading on a domain registered fourteen months ago is a conversation worth having before the LOI, not after.

Whether the mail domain can be spoofed

SPF, DKIM and DMARC posture is public by design. A target with DMARC on none, or no policy at all, is telling you something real about security maturity and about the invoice fraud exposure you would be inheriting on day one.

How much estate you are actually buying

Certificate transparency logs enumerate hostnames the target has requested certificates for, which routinely surfaces subsidiaries, staging environments and acquired brands nobody put on the asset schedule.

Whether the corporate story checks out

Registry filings give the incorporation date, the registered entity and the officers. Deals get repriced over a target that turns out to be three entities with the operating one incorporated last year.

Prior credential exposure

Breach corpora record which of the target's domains have appeared in known incidents. It does not prove current compromise and we do not claim it does. It does tell you what an attacker already has.

Hosting and dependency concentration

Where DNS, mail and web actually terminate. Concentration is not a defect, but it is a fact the integration plan needs and one that nobody volunteers in a management presentation.

How the external layer runs across a deal timetable.

The value is not one sweep. It is the same scoped sweep repeated at the moments a deal changes shape, with the diff between them being the finding.

  1. Step 1

    Before the indication of interest

    Run the target cold. Nothing is disclosed, nothing is contacted. You get a dated baseline and, occasionally, a red flag that changes whether the deal is worth pursuing at all. This is the run that costs you fifteen minutes and can save a quarter.

  2. Step 2

    When the data room opens

    Now you have the target's own answers. Hold them against the baseline. A questionnaire claiming enforced DMARC against a public record showing no policy is not a gotcha, it is the single most useful thing you can bring to the management meeting.

  3. Step 3

    During exclusivity

    Layer 3 starts here, because now there is access and authorization. The external file becomes the scoping input: the consultancy is not guessing at the estate, it has an enumerated hostname list to test against, which is the part of a technical scope that usually inflates the quote.

  4. Step 4

    At signing and again at close

    Re-run the same scope. The report is a diff against the baseline, which answers the question everyone forgets to ask: did anything about this target change while we were negotiating.

  5. Step 5

    Ninety days after close

    The target is now your estate and the same sweep becomes ordinary monitoring. Inherited domains are the classic post-close surprise, and the certificate log already listed them in the first report you ran.

What this does not cover, stated plainly.

The external layer is a genuine part of cyber diligence. It is not the whole of it, and a vendor telling you otherwise is selling.

We do not test the target's systems. No scanning, no penetration testing, no credentialed configuration review, no attempt to reach a host. That is Layer 3 work, it needs signed authorization, and firms like Kroll, Unit 42 and Sygnia exist to do it properly. If the deal is large enough for a technical assessment, buy one.

We do not read policies, interview the CISO, review the incident log, or price remediation. Those depend on disclosure and on judgment, and they belong in the workstream that starts when the data room opens.

We also do not produce a security score. A single number is easy to put in a deck and impossible to defend when the target's counsel asks how it was calculated. What comes back here is a finding, the record it came from, the endpoint and the retrieval time, which is a slower artifact and a much harder one to argue with.

What we do claim is narrow and worth having: the part of the picture that is available before anyone cooperates, collected consistently, cited, and dated so it can be re-run.

What the arithmetic looks like against a consulting engagement.

This is not an argument that a subscription replaces an assessment. It is an argument about which layer you should be paying engagement rates for.

The published spread on Layer 3

US assessment providers publishing rates in 2026 quote roughly $3,000 to $10,000 for a small business review, $10,000 to $50,000 mid-market, and $50,000 to $150,000 or more for enterprise scope, with penetration testing alone running $5,000 to $30,000. Providers who sell M&A cyber diligence as a named service, Kroll and Palo Alto's Unit 42 among them, publish no number and route you to a scoping call.

Why that is the wrong instrument early

Those figures buy depth that requires access. Spending them on a target you may not bid for, before you have the access that makes the assessment meaningful, is how diligence budget gets consumed on deals that die. The external layer is cheap precisely because it is shallow, and shallow is the right depth in week one.

The number that actually moves

For most deal teams the real cost is analyst hours. Assembling registration history, mail posture, certificate enumeration and registry filings by hand is a half day per target once you include the write-up, and it produces an artifact whose quality depends on who happened to do it. At $149 a month for a single seat, the subscription is cheaper than one afternoon of the person who currently does it. The pricing page shows the plans and the assumptions.

Where the saving compounds

A buy-and-build sponsor screening thirty targets a year runs twenty-nine external sweeps that never become deals and one that does. That ratio is exactly why the early layer has to be cheap and repeatable, and exactly why paying engagement rates for it does not work.

What your own procurement review will ask us.

Buying diligence software means clearing the review you run on everyone else. The line items are listed rather than hidden behind a call.

SSO and SAML

Okta, Entra ID or any SAML 2.0 provider

SCIM provisioning

Joiners and leavers handled by your directory

Roles and permissions

Who may open a case, who may sign one off

Audit log

Every case, every export, every scope declaration

Data residency

Choose where case data is stored

SLA

Written availability and support commitments

DPA

Signed data processing agreement

Invoicing and PO

Annual invoice, purchase order, net terms

Questions deal teams ask.

Cybersecurity due diligence is a structured review of a target company's security risk before a deal signs or closes. It covers what the target has published externally, what it discloses about its controls and incident history, and what a hands-on technical assessment finds inside the estate. Findings matter when they change the price, the indemnities or what has to be fixed before integration.

A defensible report states the scope that was declared before collection started, then each finding with the raw record it was derived from, the source endpoint and the UTC time it was retrieved. That structure matters more than length, because a finding without its provenance cannot survive a challenge from the target's counsel or an insurer six months later.

Published US assessment rates in 2026 run about $3,000 to $10,000 for a small business, $10,000 to $50,000 mid-market and $50,000 to $150,000 or more at enterprise scale. M&A specialists such as Kroll and Unit 42 publish no figure and quote per engagement. External records-based diligence is a subscription instead, from $149 a month.

You can assess the external layer, because it reads records the target already published or that registrars, certificate logs and corporate registries recorded about it. Nothing is disclosed to the target and nothing touches its systems. Questionnaires and technical testing both need cooperation, so those wait for the data room and for written authorization.

Vendor due diligence is commissioned by the seller and provided to bidders, so it is written to support a sale. Buyer due diligence is commissioned by the acquirer and answers to the investment committee. On the cyber side the practical difference is trust: seller-supplied material still needs independent corroboration against public records.

No, on its own. A questionnaire records what the target believes and is willing to state, which is useful and is not evidence. The cheapest correction is to hold the answers against public records: mail authentication policy, certificate surface and registration history are all externally verifiable and frequently contradict an optimistic questionnaire.

The external and disclosed layers are usually run by the acquirer's security lead or by the deal team itself, sometimes with support from IT diligence advisors. Hands-on technical assessment is normally outsourced to a specialist firm, because it needs testing skills, insurance and a signed authorization that a deal team cannot provide.

Where this sits next to the rest of the diligence stack.

Most teams reach this page from one of two directions, and the neighboring pages are worth ten minutes.

If the recurring job is screening counterparties rather than acquiring them, the same collection runs continuously and the page you want is third party risk management software, which covers the vendor file and the audit question rather than the deal timetable.

If what you inherited at close is the problem, attack surface management from public records covers the quarterly diff on an estate you now own, and pre-engagement screening covers the lighter check that runs before any counterparty relationship starts.

If you are still choosing a category, the comparison of OSINT tools is honest about where scanners and graph tools beat a report-first product, and the report structure shows what a finding looks like before you commit to anything.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.