M&A due diligence · SaaS & technology
M&A Privacy & Security Due Diligence for MSPs & IT Consultancies
M&A privacy due diligence for an MSP or IT consultancy examines what a roll-up acquirer actually inherits: standing privileged access into every acquired client's environment, MSA security schedules, and a different regulatory status for every account in the book. The trigger is a live acquisition, either buying a book of managed clients or preparing to sell one, with price and integration both riding on what diligence finds. We run that review for buyers and sellers, paced to the deal calendar.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What diligence has to examine on an MSP acquisition
The asset being bought is client relationships, and the hidden liability is everything those relationships give the target standing access to.
The GDAP and privileged-access inventory
Every domain admin, M365 global admin and GDAP role the target holds into client tenants, and whether that access is documented anywhere or exists only in individual technicians' heads.
The RMM/PSA and backup stack being acquired
Which RMM, PSA and backup platforms the target runs, their configuration and patch state, and whether the buyer's own stack can absorb them or a costly migration is coming.
MSA and security-schedule portfolio
Every live client contract's notification timelines, audit rights and data-handling promises, mapped to determine which obligations transfer and which are already breached.
Inherited regulatory status per client
Which acquired accounts make the combined firm a PIPEDA processor, a PHIPA electronic service provider, or a HIPAA business associate, since that status doesn't reset at closing.
IT Glue and documentation vault hygiene
Whether the target's network documentation and stored client credentials are current, access-controlled and ready to transfer, or a liability the buyer inherits alongside the client list.
Regulatory map
The regulatory questions a roll-up deal has to answer
Several regimes meet in an MSP acquisition, and each one attaches to specific client accounts in the book being purchased, not to the deal as a whole.
PIPEDA's business-transaction pathway
Personal information disclosed for due diligence, and the client data transferring at close, has to move within PIPEDA's business-transaction rules, with safeguards and use limits if the deal falls through.
Law 25 exposure travelling with Quebec clients
A target serving Quebec clients brings PIA obligations, incident-register duties and person-in-charge requirements into the combined firm, priced whether or not anyone checked before close.
OSFI B-10 flowing down from acquired FRFI clients
If the target serves a federally regulated financial institution, that client's third-party risk expectations, audit rights and subcontractor visibility, transfer to the buyer along with the account.
HIPAA business associate status transferring with US clients
An acquired book that includes US healthcare clients brings existing Business Associate Agreements, and the liability under them, into the buyer's hands at close, whether or not the buyer has ever supported a covered entity before.
What goes wrong
How MSP roll-ups go wrong on privacy and security
The failure patterns here are specific to a business whose product is standing access into other companies' networks.
Buying a breach that hasn't surfaced yet
A Kaseya- or ScreenConnect-style compromise can sit undetected in a target's environment through closing, then detonate under the buyer's ownership once the seller's escrow has already been released.
GDAP and credentials that don't get revoked
Former owners, departed technicians and legacy vendor accounts that still hold access into acquired client tenants after close are a routine finding, and a slow-burning liability if nobody audits the full access list.
Client attrition through the security door
Enterprise and regulated clients re-run vendor assessments on ownership change, and a target that scraped through past reviews on relationship goodwill alone can fail the buyer's first post-close questionnaire cycle.
Diligence itself leaking client data
Deal teams circulating a target's client-sensitive documentation, network diagrams, credential inventories, outside a controlled data room can itself create an incident mid-transaction, before the deal even closes.
Our m&a due diligence for msps & it consultancies
What our diligence covers on an MSP or IT consultancy deal
Risk assessment, compliance review and integration support, recut for a transaction where privileged access is the asset changing hands.

Access and contract-exposure mapping
Systematic review of client agreements and privileged-access records for security obligations, notification clocks and audit rights, ranked by revenue and regulatory exposure.
Stack and documentation review
Assessment of the target's RMM, PSA, backup platform and documentation vault, covering both technical fit and outstanding security debt.
Incident and notification history
Reconstruction of past events from tickets, insurance claims and interviews, assessed against what contracts and statutes required at the time.
Regulatory status mapping
A client-by-client determination of which accounts carry PIPEDA processor, PHIPA ESP or HIPAA BA status, so the combined firm knows what it owes on day one.
Findings for the deal team
Issues graded by severity with recommended handling: price adjustments, escrows, representations, and pre-close fixes where time allows.
Post-close integration support
Access rationalization, credential rotation, and merging policies and client-facing commitments so the combined firm's answers align before the first post-acquisition review lands.
How the engagement runs
Diligence paced to a live MSP transaction
The work slots into the deal calendar and the data room, not the other way around.
Step 1
Scope to the deal thesis
With counsel and the corporate team, we focus on what could move price or kill the deal: key client contracts, regulated accounts, and the access inventory itself.
Step 2
Review the data room and the access list
Contracts, policies, incident records and, critically, the full GDAP and privileged-access inventory are reviewed against a roll-up-specific checklist.
Step 3
Findings and negotiation input
A graded findings report lands in time to shape representations, indemnities, escrow and price, distinguishing deal-breakers from fix-later items.
Step 4
Close and integrate
Post-close, we run credential rotation, access rationalization and policy harmonization so client-facing obligations are met continuously through the transition.
What it costs
What drives diligence cost on an MSP roll-up
The dominant variable is the size and complexity of the client book: reviewing eighty MSAs across regulated healthcare, financial-services and general commercial clients is a different undertaking than a ten-client boutique acquisition. The state of the target's access documentation, whether GDAP and admin roles are recorded anywhere, moves the estimate significantly.
Sell-side preparation is typically lighter than buy-side review, since the goal is finding and fixing before the buyer looks. Either way the fee is small against the price movement a single undisclosed incident or an unrevoked credential list can cause, and we quote fixed once we see the deal's shape under NDA.
MSPs & IT Consultancies: M&A due diligence questions, answered
Expect four lines of questioning: access, the full inventory of domain admin, global admin and GDAP roles held into client tenants; contracts, MSAs' notification, audit and assignment clauses and whether any are currently breached; history, past incidents and how they were handled; and stack, RMM, PSA and backup platform configuration and patch state. Preparing honest, documented answers to those four before diligence opens is the highest-return work a seller can do.
Everything the target's contracts obligate it to, notification timelines, audit rights, data-handling promises, transfers along with the revenue, and so does each acquired client's regulatory status, PIPEDA processor, PHIPA ESP, HIPAA BA, whether or not the buyer has ever handled that status before. The access itself transfers too: every credential the target's technicians hold into those tenants is now the buyer's liability until it's rotated or revoked.
It can, though less directly than the underlying practice it represents: a current SOC 2 report signals documented access controls and change management, which tends to correlate with fewer surprises during technical diligence, and its absence often just means more diligence hours spent verifying the same things manually. A report alone doesn't substitute for reviewing the actual access inventory and contract portfolio, which is where roll-up-specific risk actually lives.
Every GDAP role and admin credential the acquired team holds needs to be reviewed, reassigned or revoked as part of integration, not left running on the assumption that the acquired technicians will simply keep doing their jobs under new ownership. Skipping this step is one of the more common post-close gaps, since operational continuity pressure often delays the access cleanup that should happen first.
Before, and ideally under NDA rather than waiting for client notification, since the findings shape price, representations and the integration plan, all of which are far harder to renegotiate once clients already know a deal happened. Client notification timing is itself something diligence should inform, particularly for regulated accounts whose contracts may require advance notice of a change in ownership.
More for msps & it consultancies
Other services for this niche
About this service
Answers & guides
- What is privacy and security due diligence in an acquisition?
- Is a SOC 2 report enough to prove an acquisition target is secure?
- How do we prepare for a customer security questionnaire?
- What is PIPEDA, and does it apply to my business?
- Privacy and Cyber Due Diligence Before You Acquire a Company
- The Privacy and Security Problems That Quietly Erode Deal Value
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.