M&A Security Due Diligence Form
Provide details to assess the security posture of the target company for merger or acquisition due diligence.
Company Name
*
Overall Security Maturity Level
*
Please Select
Ad hoc
Developing
Defined
Managed
Optimized
Have there been any security incidents in the past 24 months?
*
Yes
No
Briefly describe any major security incidents or breaches (if any):
Which security compliance frameworks does the company currently adhere to?
*
ISO 27001
SOC 2
NIST
HIPAA
GDPR
None
Other
Does the company regularly assess third-party/vendor security risks?
*
Yes
No
In Progress
Briefly describe access control practices (e.g., least privilege, MFA, user reviews):
*
How is sensitive data classified and protected?
*
Are there any open or ongoing security remediation items?
*
Yes
No
List any critical open remediation items and their status:
Submit
Should be Empty: