SaaS-specific diligence layers contract-level revenue cohort analytics on top of the generic FDD scope. ARR, NRR and GRR by cohort, contract length and ramp dynamics drive valuation; data-protection and IT-cyber posture drive deal risk.
Direct answer
A UK SaaS M&A due diligence checklist supplements the 14 generic Schedules with ARR / NRR / GRR cohort testing, contract-level revenue recognition under IFRS 15 or FRS 102, change-of-control mapping across customer contracts, open-source licence exposure, security-incident history under DPA 2018 and a SOC 2 Type II or ISO 27001 review.
Sector add-on clauses
- IV.12Test ARR / NRR / GRR by cohort over the last 24 months.Severity A
- IV.13Confirm logo and net-revenue retention against an explicit cohort definition.Severity A
- V.6Identify any open-source software dependencies and licence compatibility.Severity B
- VII.5Confirm DUAA 2025 Part 5 alignment for any digital-verification or smart-data processing (in force 5 Feb 2026).[DUAA 2025]Severity B
- VII.9Review breach register and any reportable incidents within the last six years.Severity A
- VIII.4Confirm Cyber Essentials Plus or ISO 27001 certification status.[NCSC CE]Severity B
- VIII.11Identify open-source software dependencies and any GPL-style licensing risk.Severity B
- VIII.12Confirm software-development lifecycle: code review, SCA, SAST, DAST.Severity C
- VIII.14Obtain SOC 2 Type II report (or evidence in-scope alternative).Severity B
These add-ons supplement, not replace, the generic 14-Schedule scope. Begin with the generic checklist and layer these on.
This page is anchored to UK primary legislation and named regulator guidance only. Not legal advice. Confirm position with your appointed adviser before signing.