The Year Tech Due Diligence Got Real
December 2025. I'm reviewing notes, comments and direct messages related to the first seventeen editions of this newsletter, and one pattern screams louder than the rest: the tolerance for "we'll handle it later" disappeared completely this year - investors now demand "show me the evidence" from day one.
2025 was the year tech due diligence stopped being a checkbox exercise and became the front door to every serious conversation. Let me tell you what actually happened, what you told me in the comments and tons of direct messages, and what's worth carrying into 2026.
Three things that changed the game in 2025
1. Supply chain became the "kill chain"
Verizon's 2025 report dropped a bomb: 30% of all data breaches involved third parties, double the previous year. Average remediation cost hit $4.91 million per incident.
The headlines kept coming. In June, procurement provider Chain IQ was breached, exposing internal customer data including UBS executive contact details. Between June and August, multiple organizations reported unauthorized access to Salesforce-hosted or Salesforce-integrated CRM systems, affecting companies including Google and Workday, primarily through social engineering and third-party access. Qantas disclosed that 5.7 million customer records were accessed via a contact-center vendor and later published after a ransom demand was refused. Allianz Life confirmed 1.4 million records exposed through a third-party CRM in July.
Edition 9 on vendor due diligence became my most-shared piece. Why? Because founders realized their stack's weakest link could rewrite their valuation more than any internal tech debt. DORA kicked in for financial services, NIS2 started rolling across EU member states, and suddenly "we have an SBOM" stopped being sufficient. Investors wanted continuous monitoring, vendor-risk scoring in live dashboards, and proof you could swap a critical vendor in 48 hours.
2. The AI Act went from theory to leverage
The EU AI Act hit enforcement back in September. What surprised me wasn't the regulation itself, it was how quickly it became a sales tool for prepared companies. B2B SaaS selling into Europe suddenly had to answer one question: "Which risk tier? Show me your conformity file."
Companies that had already mapped their AI risk classification, documented their data governance, and proven their human-oversight mechanisms started closing enterprise deals faster than competitors who were still scrambling. One founder told me their Data Protection Impact Assessment and SOC 2 controls basically wrote their AI Act conformity documentation. That 70% overlap I mentioned in Edition 8? Turned out to be pretty close.
The penalty structure (up to 7% of global revenue) made this non-negotiable. Investors started treating AI compliance readiness the way they treated GDPR in 2018, as a gating item, not a nice-to-have.
3. People risk became quantifiable
This one surprised me. Edition 11 (The People Lens) started as the piece I thought would get the least traction. Org charts and succession planning feel "soft" compared to API contracts and database sharding. I was completely wrong.
Investors in 2025 started asking for bench-depth models alongside burn-down charts. They wanted to know: "If your principal engineer is out for a month, what slows down?". Bus-factor-of-one became a deal discount. On-call health metrics started appearing in data rooms next to deployment frequency.
The shift? People finally connected fragile teams to fragile deliveries. A clean codebase with a hero culture is just technical debt with better PR. Three weeks before one close, a buyer asked: "If your principal engineer is out for a month, what slows down?" The CTO said: "only he knows the data plane and deployment system end-to-end." That answer triggered a holdback tied to succession planning and delivery predictability.
The patterns that paid off across 17 editions
Looking back at every conversation, every comment, every "this burned us" story, five habits separated teams that sailed through diligence from teams that scrambled:
They treated evidence like a product. The winners didn't create artifacts for diligence, they created them as operating tools. Data ownership maps updated with every schema change. Vendor registers refreshed quarterly. SBOMs generated in CI, not assembled the week before close. When diligence asked, they just pointed at what already existed.
They priced risk before investors did. Edition 4's Debt Ledger, Edition 1's Risk Register, Edition 5's FinOps dashboard, these weren't compliance theater. They were steering mechanisms. Teams that tracked tech debt with owners and estimates, cloud costs per ARR Euro, and incident post-mortem velocity didn't negotiate with fear. They negotiated with data.
They made residency and sovereignty architectural, not contractual. The companies that aced Edition 10 and 14 didn't bolt on data residency later. They designed for it: regional sharding from day one, KMS keys pinned in-region, telemetry that never crossed borders. When customers asked "prove EU data stays in EU," they exported a dashboard, not a promise.
They automated the boring parts of governance. Tagging policies enforced in Terraform. Secrets scanning in every commit. Policy-as-code for IaC changes. Vulnerability SLAs tracked per service with automated escalation. This wasn't DevSecOps theater, it was margin protection. Every hour not spent chasing down an untagged resource or a leaked secret was an hour of shipping features.
They ran drills, not slides. Business continuity plans that had never been tested became liabilities (Edition 13). API contracts that drifted from production became integration hell (Edition 12). But teams that ran quarterly failover drills, chaos exercises, and "assume vendor down" scenarios turned operational discipline into a competitive moat. Investors trust what's rehearsed, not what's promised.
What I got wrong (and learned fast)
I underestimated how fast supply chain risk would dominate. When I wrote Edition 9 in early fall, third-party breaches were a concern. By December, they were the primary attack vector. The Salesforce cascade, the island hopping attacks, the procurement vendor compromises, these weren't edge cases. They were the new normal. If you haven't stress-tested your vendor exit clauses or run an "assume critical vendor compromised" drill, make that your January priority.
I didn't emphasize multi-account architecture enough early. Edition 5 touched on it, but I should have screamed it from page one: separate cloud accounts for each product and environment from Day 1. Every founder who told me "we're trying to untangle mixed environments now" paid for it in diligence time and FinOps headaches.
I should have written the People Lens edition earlier. Org design, succession planning, and on-call health, these aren't nice-to-haves at Series B. They're gating items. The technical stack is easier to fix. Fragile teams take quarters.
Looking ahead: what's coming in 2026
The regulatory ratchet keeps tightening. The AI Act is enforcing. DORA is live. NIS2 is rolling out. The EU Data Act kicked in September 2025, with full switching-fee elimination coming January 2027. Every one of these shifts costs from "we'll figure it out" to "show me the controls." If your compliance posture is reactive, 2026 will hurt.
Unit economics become non-negotiable. Cheap capital is gone. Every Series B and beyond will face one question: "Prove your cloud spend grows slower than ARR." FinOps isn't optional anymore, it's margin defense. Edition 5's habits (tagging, showback, right-sizing) are table stakes now.
Supply chain scrutiny becomes standard. SBOM generation, vendor-risk scoring, continuous monitoring, and exit-clause negotiation won't be "nice work if you have it," they'll be expected in every data room. The companies that treat third-party risk as a feature, not a footnote, will close deals faster.
Platform engineering becomes the differentiator. The gap between teams with paved roads (golden paths, self-service IDP, automated guardrails) and teams without is widening. In 2026, investors will ask: "How long does it take a new engineer to ship to production?" and "What percentage of teams can deploy without a ticket?"
If you read only three editions before your next round
If time is short and a term sheet is close, start here:
- Edition 1 (Deal-Maker, Not Checkbox) - Build your risk register. Frame risk, don't hide it.
- Edition 3 (The Metrics That Matter) - Get your five signals clean: speed, stability, quality, reliability, unit economics.
- Edition 9 (Vendor Due Diligence & Third-Party Risk) - Map your supply chain. Continuous monitoring, not annual PDFs.
Then layer in whatever matches your stage and sector: APIs if you're B2B SaaS, sovereign data if you touch EU customers, DevSecOps if you're post-Series A.
Your turn
This newsletter exists because you've shared your scars, your surprises, and your shortcuts. Over seventeen editions, the comments and direct messages taught me as much as the research.
So here's my ask: What topic did I miss in 2025 that bit you during a deal? Was it M&A carve-out complexity? Product-market fit under technical constraints? IP ownership in distributed teams? Kubernetes cost chaos? AI model governance beyond compliance checkboxes? Drop it in the comments. The best suggestions become Edition 18 and beyond in 2026.
Founders: Need a year-end tech health check before the next fundraise? A fast gap-scan of your data room readiness? Let's talk.
Investors: Want a second pair of eyes on a live deal, or a portfolio-wide benchmark of tech maturity? Let's talk.
Here's to a year of better questions, cleaner evidence, and deals that close on momentum instead of surprises. See you all in 2026. Stay tuned!
Originally published on the Tech Due Diligence Playbook newsletter on LinkedIn.