Skip to content
MSPagenda

Exit Planning

MSP Due Diligence

Whether you are buying a competitor, selling your own firm, or a potential client is putting your business under the microscope, MSP due diligence is the process that separates professional operations from those just getting by. It is the deep-dive investigation into the financial health, technical standards, and operational resilience of a Managed Service Provider.

Whether you are buying a competitor, selling your own firm, or a potential client is putting your business under the microscope, MSP due diligence is.

Luis NavarroPublished 9 min read

TL;DR

  • Financial Accuracy: Quality of Earnings (QoE) is the cornerstone of MSP due diligence, focusing on the stability of recurring revenue.
  • Technical Debt: Buyers and clients look for standardised stacks; fragmented environments represent a significant operational risk.
  • Compliance and Security: Internal security practices are often more scrutinized than the services sold to clients.
  • Legal Clarity: Contractual terms, specifically around auto-renewals and liability caps, directly impact enterprise value.
  • Operational Maturity: Documentation and process repeatability prove that the business doesn't rely solely on the founder's heroics.
On this page

Whether you are buying a competitor, selling your own firm, or a potential client is putting your business under the microscope, MSP due diligence is the process that separates professional operations from those just getting by. It is the deep-dive investigation into the financial health, technical standards, and operational resilience of a Managed Service Provider.

In the context of M&A, it determines the final purchase price and the risk profile of the acquisition. For a client, it is the insurance policy that ensures the partner they trust with their data actually has their house in order.

MSP due diligence is the systematic process of evaluating a Managed Service Provider's business viability, technical proficiency, and financial stability. It involves a rigorous review of contracts, service delivery metrics, security posture, and the "stickiness" of the client base.

Ultimately, it answers one fundamental question: Does the reality of the business match the story being told in the sales deck or the P&L?

Core Components of a Thorough Review

  • Financial Audit: Validating EBITDA, analysing churn rates, and verifying Monthly Recurring Revenue (MRR).
  • Technical Assessment: Evaluating the RMM/PSA tools, documentation standards, and the age of the managed infrastructure.
  • Security & Compliance: Auditing internal MFA adoption, backup integrity, and adherence to frameworks like SOC2 or CIS.
  • Human Capital: Assessing team structure, skill gaps, and the risk of key-man dependency.
PillarPrimary FocusCritical Red Flag
FinancialMRR quality and EBITDA marginsHigh concentration (one client > 20% of revenue)
OperationalProcess standardisation and ticketingLack of documentation or "tribal knowledge" culture
TechnicalSecurity posture and toolstack alignmentOutdated OS versions or unmanaged backups

The Financial Perspective: Quality of Earnings

In my experience building and eventually exiting an MSP, the financial side of due diligence is where most deals face their first "haircut." It isn't just about the top-line number; it's about how that number is composed. MSP due diligence requires a granular look at the difference between project revenue and recurring revenue.

Buyers and sophisticated clients want to see that your revenue is predictable. If a large portion of your profit comes from one-off hardware sales, your valuation or perceived stability will drop significantly.

Revenue Concentration Risks

If your largest client accounts for more than 15% to 20% of your total revenue, you have a concentration problem. During due diligence, this is flagged as a high-risk item. If that client leaves, the business might no longer be profitable.

We always advised our teams to diversify the base. A healthy MSP has a "long tail" of clients where no single exit can cripple the payroll.

Churn and Retention Metrics

High growth numbers can hide a leaky bucket. Due diligence will uncover your "Net Revenue Retention." Are you growing because you’re adding new clients, or are your existing clients spending more? More importantly, why are clients leaving? If the churn is due to service failures, that’s a red flag that no amount of sales growth can fix.

Operational Due Diligence: The "Hero" vs. The System

One of the hardest lessons I learned while scaling Totality Services was that a business that relies on the founder to solve every technical crisis isn't a business—it's a high-paying job. During MSP due diligence, investigators look for the "hero culture."

They want to see that your Service Level Agreements (SLAs) are met because of your processes, not because your lead engineer worked until 2 AM to fix a preventable issue.

The Importance of Documentation

If it isn't documented, it doesn't exist. This is a mantra every MSP owner should live by. During an audit, you’ll be asked to show your Standard Operating Procedures (SOPs). This includes everything from client onboarding to offboarding, password management, and emergency response.

Proper documentation ensures that if a key engineer walks out the door tomorrow, the business continues to function. This lowers the risk for a buyer and increases the trust a client has in your longevity.

PSA and RMM Utilisation

A Professional Services Automation (PSA) tool is the heartbeat of an MSP. Sophisticated due diligence doesn't just check if you have a PSA; it checks if you're actually using it. They look at:

Average time to respond vs. time to resolve. Ticket backlog trends. Accuracy of time tracking (which affects your understanding of client profitability). Consistency in RMM (Remote Monitoring and Management) alerting.

If your PSA is a mess, it suggests your service delivery is reactive rather than proactive.

Technical and Security Due Diligence

This is where the rubber meets the road. In the modern landscape, an MSP is a prime target for supply chain attacks. Consequently, MSP due diligence now leans heavily into the security posture of the MSP itself, not just what they provide to clients.

Luis Navarro, the founder of MSP Agenda, often emphasises that security is not just a technical checkbox; it’s a commercial necessity. If you can’t prove your own environment is secure, why should a client trust you with theirs?

Internal Security Standards

Expect a deep dive into your internal tools. Are you using Multi-Factor Authentication (MFA) on every single portal? Is your RMM locked down with IP filtering? How do you manage administrative privileges? If the MSP’s internal security is lax, the entire client base is at risk. This is often a deal-breaker in M&A scenarios.

Standardisation of the Stack

A "snowflake" MSP—where every client has a different firewall, a different backup solution, and a different antivirus—is an operational nightmare. Due diligence teams look for standardisation. A standardised stack means:

Lower training costs for engineers. Faster troubleshooting. Better margins through vendor volume discounts. Easier scalability.

The more unique each client environment is, the more "technical debt" a buyer is inheriting.

Backup and Disaster Recovery (BDR) Validation

You can claim you have backups, but due diligence will demand proof of successful restores. They will look for the frequency of backup testing and the physical/logical separation of backup data. In the era of ransomware, an MSP that cannot prove the integrity of its clients' data is a liability.

Contracts are the foundation of your enterprise value. During MSP due diligence, legal teams will review every Master Service Agreement (MSA) and Statement of Work (SOW). They aren't just looking for signatures; they are looking for specific clauses that protect the business and ensure revenue continuity.

Key Contractual Elements

  1. Auto-Renewal Clauses: These provide revenue predictability and are highly valued by buyers.
  2. Limitation of Liability: Does your contract protect you if a client suffers a breach? Or is the MSP on the hook for unlimited damages?
  3. Assignability: If you sell the business, do you need the client's permission to transfer the contract? If so, the deal becomes much harder to close.
  4. Termination for Convenience: Contracts that allow a client to leave with 30 days' notice for no reason are significantly less valuable than those with fixed terms.

When Luis Navarro co-founded Totality Services, he spent years sitting between technical teams and business leaders. He learned that the commercial strength of a contract is just as important as the technical service it describes. A strong MSA is a sign of a commercially mature MSP.

Human Capital: The Team Behind the Tech

An MSP is a people business. During MSP due diligence, the focus shifts to the staff. Who are the key players? What is the turnover rate? If the top three engineers are the only ones who know how to manage the core infrastructure, the business has a "knowledge silo" problem.

Culture and Compensation

Buyers will look at payroll data to ensure engineers are being paid market rates. If you’ve artificially inflated your profit by underpaying your team, a buyer knows they’ll have to increase expenses post-acquisition to keep the talent. They will also look at non-compete agreements and employment contracts to ensure the intellectual property and client relationships are protected.

Preparing for a Due Diligence Audit

Whether you are preparing for a sale or just want to run a better business, conducting "self-due diligence" is a powerful exercise. It allows you to identify and fix issues before they are exposed by an outside party.

The Due Diligence Checklist

  • Financials: Three years of tax returns, P&Ls, and a clean balance sheet.
  • Client Data: A list of all clients, their MRR, contract end dates, and service history.
  • Technology Stack: A full inventory of internal and client-facing tools.
  • Security: Documentation of internal security policies and recent audit results.
  • Operations: Access to the PSA for ticket metrics and SOP libraries.

If you're finding that your security reviews are inconsistent or hard to track, tools like MSP Agenda can help standardise the process. By creating clear, commercially-minded security reports, you not only protect the client but also build the documentation trail that due diligence teams love to see.

Common Pitfalls in MSP Due Diligence

Even successful MSPs often stumble during the audit phase. One common mistake is "revenue masking," where hardware sales or one-time projects are lumped into recurring revenue figures. This is easily spotted and immediately erodes trust.

Another pitfall is the "messy" cap table or unclear ownership of IP. If a former partner still owns a piece of the company or if your custom automation scripts aren't clearly owned by the business, it can stall a deal for months.

Underestimating the Time Commitment

Due diligence is a full-time job on top of your existing full-time job. Many MSP owners become distracted, leading to a dip in service quality or sales during the process. This dip can then be used by a buyer to renegotiate the price. Staying focused on the day-to-day while managing the audit is crucial.

Strategic Value vs. Financial Value

In MSP due diligence, not all revenue is treated equally. Strategic value comes from having a niche (e.g., specialising in legal or healthcare) or having a proprietary way of delivering service that others can't easily replicate.

A buyer might pay a premium for an MSP that has a perfect SOC2 compliance record because it allows them to enter a new market. Conversely, a high-profit MSP with poor technical standards might be seen only as a "fixer-upper" and valued accordingly.

The Role of the Founder

As Luis Navarro experienced with the eight-figure acquisition of Totality Services, the goal is to make yourself redundant. If the due diligence team sees that the business can grow without the founder’s constant involvement in sales or technical escalations, the valuation goes up. The best MSPs are those where the founder focuses on strategy, not ticket resolution.

The Client Side of Due Diligence

It’s not just about M&A. Large enterprise clients or those in regulated industries (like finance or defence) will perform their own MSP due diligence before signing a contract. They will ask for your Cyber Essentials plus, your SOC2 reports, and your business continuity plans.

If you aren't prepared for these questions, you won't win the bigger, more profitable contracts. Security reviews should be a standard part of your relationship, not just something you scramble to provide when asked.

Demonstrating Value Through Accountability

When you present a security recommendation, the client needs to see the commercial impact. Using a structured approach to these reviews ensures that you are tracking decisions and creating accountability. This level of professionalism is exactly what due diligence teams look for when vetting a service provider.

Advanced Insights: The Shift to Cyber Due Diligence

The landscape of MSP due diligence is changing. Five years ago, the focus was almost entirely on the P&L. Today, "Cyber Due Diligence" is just as important. Insurance companies are now part of the conversation, as they won't insure an acquisition if the target MSP has significant security gaps.

Expect deep scans of your external footprint and potentially even "gray box" testing of your internal systems. A single unpatched vulnerability in your RMM could be the difference between a successful exit and a failed deal.

Standardisation as a Defence

The best way to pass a cyber audit is through radical standardisation. When every client is on the same version of the same software, managed by the same scripts, the attack surface is predictable and manageable. Fragmentation is the enemy of security and the enemy of a high valuation.

Key takeaways

  • Financial Accuracy: Quality of Earnings (QoE) is the cornerstone of MSP due diligence, focusing on the stability of recurring revenue.
  • Technical Debt: Buyers and clients look for standardised stacks; fragmented environments represent a significant operational risk.
  • Compliance and Security: Internal security practices are often more scrutinized than the services sold to clients.
  • Legal Clarity: Contractual terms, specifically around auto-renewals and liability caps, directly impact enterprise value.
  • Operational Maturity: Documentation and process repeatability prove that the business doesn't rely solely on the founder's heroics.

Frequently asked questions

How long does the MSP due diligence process usually take?

In an M&A scenario, the heavy lifting of due diligence typically takes between 60 and 90 days. However, the preparation for it should start at least 12 to 18 months in advance to clean up financials and standardise operations.

What is the 'Quality of Earnings' (QoE) report?

A QoE is a deep-dive financial analysis performed by an accounting firm. Unlike a standard audit, it focuses on the sustainability and accuracy of the EBITDA. It looks for 'add-backs'—one-time expenses that won't recur after a sale—which can increase the perceived profitability of the business.

Does having a small team hurt my due diligence results?

Not necessarily. Efficiency and high profit-per-employee are actually very attractive. The risk is 'key-man dependency.' If the team is small but every process is documented and the tools are standardised, the size of the team isn't a negative factor.

Why do buyers care about the specific tools in my stack?

Buyers often have their own preferred vendors (e.g., a specific RMM or EDR). If your stack is completely different from theirs, they have to factor in the cost and risk of migrating all your clients to their tools. Common, industry-standard tools usually make for a smoother due diligence process.

Can a security breach during due diligence kill a deal?

Yes. A significant security incident during the audit phase is one of the fastest ways to collapse a deal. It calls into question the MSP's competence and creates unknown future liabilities. This is why maintaining high security standards is a 24/7 requirement, not just a 'clean up' task for a sale.

What you get: one email with new reviews research, framework changes worth knowing about and any new templates. Frequency: occasional. No vendor fluff, unsubscribe in one click. You can unsubscribe at any time; see the privacy notice for details.

ShareLinkedIn

About the author

Luis Navarro

Founder, MSP Agenda

Luis co-founded the London managed service provider Totality Services in 2008 and spent seventeen years growing it from a two-person business to a team of around 45 people serving more than 150 organisations, before its acquisition by Lyra Group in 2025. He writes MSP Agenda from the commercial seat: winning the right clients, expanding the accounts you already have, and building a business that is worth buying.

Credentials
  • Co-founder, Totality Services (2008–2025)
  • MSP exit completed with Lyra Group, 2025
  • Founder, MSP Agenda
Writes about
  • MSP growth strategy
  • Prospect qualification
  • Account expansion
  • Valuation and exit readiness
LinkedIn profile

All Exit Planning articles

Growth beats guesswork.

Email us

We use analytics cookies to understand which pages are useful. Nothing is measured until you choose. Cookie details