Independent EU engineering opinion · deal-side partner
M&A technical due diligence services,
a written opinion — not a checklist.
TrustChange runs M&A technical due diligence for acquirers, PE funds, LPs and founders preparing for exit — in EU-facing crypto and fintech: crypto exchanges, wallet and custody, PSPs, EMIs, neobanks and licensed VASPs. A named senior EU engineer reads the architecture, custody, controls, compliance posture and delivery discipline, then signs the report and stands up on the IC call. No contingent fee, no equity, no vendor kickback.
- EU-based engineers
- Named lead on the report
- MiCA · PSD2 · AML · PCI · GDPR literate
- No contingent fee
What "M&A TDD" means here
Buy-side, sell-side and investor technical due diligence — the honest comparison
Most searches for M&A technical due diligence assume one shape. In practice three sides commission this work — acquirers under LOI, founders in advance of a process, and investors doing follow-on or portfolio review — and the access, deliverable and cadence differ across each. Below is how the three shapes actually play out. TrustChange runs all three.
Related advisory shapes: CTO advisory, fractional CTO services, technical due diligence services (the broader page, not deal-specific). Post-close delivery: dedicated development teams, nearshore staff augmentation.
| Dimension | Buy-side | Sell-side | Investor |
|---|---|---|---|
| Who commissions | Acquirer or PE fund | Founders / advisor preparing for exit | Investor or LP on a fund level |
| Access model | Cleanroom, VDR, controlled interviews | Full access — running a mock buyer diligence | Portfolio walk-through, existing docs first |
| Output shape | Diligence report + IC read-out + rep-and-warranty support | Vendor diligence pack + buyer-ready remediation plan | Portfolio-level engineering risk view + follow-ups |
| Typical duration | 2–4 weeks under LOI | 3–6 weeks in advance of process launch | Rolling; per portfolio company |
| What we are not | Not your reps & warranties insurer | Not your investment bank | Not your legal counsel |
Deliverables
Three deliverables in every M&A technical due diligence engagement
A diligence engagement is not one PDF. It is a report your IC can act on, a remediation plan a post-close team can size, and a named engineer who defends both on the call. We agree the three up front, so nobody is surprised on read-out day.
-
01
Written diligence report
A structured engineering opinion covering architecture, delivery, controls, custody and compliance readiness — with issues rated, sourced to evidence and mapped to remediation.
- Executive summary
- Rated issue register
- Evidence citations
-
02
Remediation & CAPEX roadmap
The engineering work required to close the gaps — sized in effort and cost, sequenced for post-close, and calibrated against the deal thesis and integration plan.
- Sized remediation plan
- Post-close CAPEX view
- Integration sequencing
-
03
Independent expert on the call
A senior engineer available for the negotiation calls with the target, the IC and the reps-and-warranties workshop — same person who signed the report.
- IC-ready read-out
- Reps & warranties support
- Post-close follow-through
Review dimensions
Eight dimensions we review on a crypto or fintech target
One system, eight lenses. Every dimension names an owner, a control question and a piece of evidence — no green light without a source.
Domain-specific detail we lean on: wallet and custody engineering, payment gateway engineering, compliance engineering and crypto exchange development.
| Dimension | What we look at |
|---|---|
| Architecture & scalability | Topology, ingress, matching or ledger core, event-sourcing, replay, data model and blast-radius review Rated against the deal thesis (5x growth? new market? new regulator?). |
| Custody & key material | MPC / HSM setup, hot/warm/cold split, key ceremonies, withdrawal policy, audit trail The single biggest source of insurable and uninsurable loss on crypto targets. |
| Payments & rails | Card, SEPA, open banking, PSP router, idempotency, reconciliation cadence and exception queue depth Aged breaks and stuck payouts are the tell for hidden operational debt. |
| Compliance readiness | MiCA, PSD2, AML/Travel Rule, PCI DSS and GDPR posture with evidence of controls in flight We map the shipped controls; your legal counsel maps the licence position. |
| Security & DevSecOps | SDLC, secrets, dependency & container hygiene, pen-test history and prior incident post-mortems Absence of history is a finding, not a green light. |
| Delivery discipline | Release cadence, review culture, test coverage, on-call, change-management and audit trail practice The multiplier on every other finding. |
| Team & knowledge risk | Org shape, bus factor, retention risk, undocumented systems, single-point-of-knowledge review Post-close integration usually starts here. |
| Data & tenancy | Data model, PII handling, retention rules, EU data residency and multi-tenant boundaries Determines integration cost more than the marketing deck ever does. |
Independence & ownership
What stays yours when we deliver
TrustChange is a bespoke M&A technical due diligence consultancy: your file, your findings, your remediation plan, your independent read on the deal. Nothing sits with a broker or a licence pool.
Report & annexes
Delivered under NDA; you own the file
Evidence citations
Every rating linked to a source we saw
Remediation plan
Sized in effort and cost, sequenced for post-close
Independence
No contingent fee, no equity, no vendor kickback
Team
Named senior engineer signs the report
Contracts
Fixed-scope engagement, notice period agreed up front
Exit
Take the report and follow through in-house
Delivery
How we deliver an M&A technical due diligence engagement
Five phases, in this order. The cadence is deal-driven — cleanroom access and IC dates set the clock, not our sprint calendar.
- 01
Scoping
Days 1–3
Deal thesis, target profile, access model and reporting shape agreed. Access to VDR, code, environments and interview slots confirmed.
- 02
Evidence
Week 1–2
Structured review across the eight dimensions. Interviews with the target's CTO, heads of engineering, security and compliance. Code and infra walkthroughs.
- 03
Findings
Week 2–3
Rated issue register with evidence citations; remediation plan sized in effort and cost; risks flagged for reps and warranties.
- 04
Read-out
Week 3–4
IC read-out with the deal team, the target if relevant, and the CFO. Q&A on findings, remediation and integration cost.
- 05
Post-close
Optional
Independent follow-through: quarterly reviews of remediation progress, integration engineering support, or a dedicated squad if needed.
Post-close
Four ways to keep working with us after the deal closes
Same engineers, same standard — from deal-week diligence into steady-state delivery.
-
Fractional CTO
A named senior engineer in the target's CTO seat during integration. Best for the first two quarters post-close.
-
Dedicated team
A standing squad closing the top-rated findings. Best when remediation is heavy.
-
Staff augmentation
Senior engineers into the target's team. Best when the plan is clear and headcount is missing.
-
Fixed-scope build
A defined remediation outcome at a fixed price and date. Best when scope is settled.
Questions
FAQ: M&A technical due diligence services
Six answers up front on scope, investor vs buy-side vs sell-side, review coverage, independence, compliance handling and post-close follow-through. Bring the rest to the call.
What do M&A technical due diligence services from TrustChange actually cover?
A written engineering opinion on a crypto or fintech target across eight dimensions — architecture, custody, payments, compliance readiness, security, delivery discipline, team and data — with rated findings, evidence citations and a sized remediation plan. TrustChange is an M&A technical due diligence consultancy, not a law firm and not an investment bank. Legal position, deal terms and licence opinions stay with your counsel and advisers.
How is technical due diligence for investors different from buy-side or sell-side work?
Investor-side technical due diligence usually runs at portfolio or fund level — a rolling engineering risk view across multiple companies, calibrated against the investment thesis and follow-on decisions. Buy-side (acquisition technical due diligence) is deal-specific under LOI, with cleanroom access and rep-and-warranty support. Sell-side technical due diligence is founder-commissioned in advance of a process — a mock buyer-side diligence, so the remediation happens before a real buyer finds it. The comparison table on this page shows the honest differences.
Which parts of a crypto or fintech stack do you review?
The eight dimensions cover architecture and scalability, custody and key material, payments and rails, compliance readiness (MiCA / PSD2 / AML / PCI DSS / GDPR), security and DevSecOps, delivery discipline, team and knowledge risk, and data and tenancy. On crypto targets, custody, key ceremonies and market surveillance get particular weight. On fintech targets, reconciliation cadence, PSD2 posture and exception-queue depth are usually the tell.
How independent are you as an M&A technical due diligence consultancy?
Fully. TrustChange takes no contingent fee, no equity in the target and no vendor kickback from any third party we might name in the report. The named senior engineer who signs the report is the same person on the IC read-out and, if you engage us post-close, on the follow-up work. If we surface findings that kill the deal, we still get paid — that is the point of hiring us instead of your existing engineering vendor.
How are MiCA, PSD2, AML/Travel Rule and GDPR handled in the review?
TrustChange is an engineering partner, not a law firm — your counsel maps the licence position and takes the legal view. We map the controls the target has shipped and the controls it has not, against MiCA-ready architecture, PSD2-aware payment flows, AML/Travel Rule messaging on crypto legs, PCI DSS scope and GDPR-aware storage. Findings feed the remediation plan and the rep-and-warranty workshop. Nothing about supervisor approvals or licences is claimed on your behalf.
Can you follow through after the report — remediation, integration, post-close support?
Yes. Common shapes: quarterly reviews of remediation progress, a dedicated development team to close the highest-rated gaps, staff augmentation into the target's engineering team, or a fractional CTO seat during the integration window. We keep the same lead across the report and the follow-through, so context does not get lost handing between vendors.
Book a discovery call for M&A technical due diligence services
Bring the deal thesis, the target profile, the access model and the IC date. We come back with a scope, a diligence plan and a costed proposal. Under NDA from the first call.