Before moving ahead with an MSP acquisition, you need a clear picture of the business you’re buying. That means looking closely at its finances, client relationships, technology, staff, vendor agreements, and cybersecurity.
This checklist walks you through the key records, agreements, and operational details to review. Use it to keep your due diligence focused and organized, from the initial review through to deal discussions.
If you’re considering an MSP acquisition, you’re probably already familiar with recurring revenue, service delivery, and client relationships. That experience can help you work through the review more quickly, but it can also make it easier to take things at face value.
Even if a target business looks familiar, it may operate very differently from other MSPs you have evaluated or worked with. Making assumptions based on your own experience, or skipping steps because you have seen similar situations before, can leave important details untested.
Reviewing the financials is a core part of due diligence in any business acquisition, and MSPs are no exception. The financials provided by the seller are a useful starting point, but buyers should check them against source documents before using them to assess the value of the business.
Check that reported MRR and ARR line up with the billing records. Pull invoice data or exports from the PSA system and reconcile them with the figures provided.
Watch for one-time fees, hardware markups, or project work counted as recurring revenue. Check that seat counts, contract dates, and renewal terms support the numbers too.
Adjustments to EBITDA are common, but every add-back needs a clear explanation. Adjustments for owner compensation, personal expenses, and genuine one-time costs may be reasonable.
Take a closer look when recurring or vaguely defined expenses are presented as one-offs. If normalized EBITDA looks unusually high or low compared with similar MSPs, dig into the assumptions behind it.
Gross margin helps show how efficiently the business delivers its services. Lower margins can point to underpriced contracts, inefficient labour allocation, or a heavy reliance on subcontractors.
Compare the target’s cost structure with your own, while accounting for differences in the services you provide. Lower margins may reflect costs you can reduce after the acquisition rather than underlying problems with the client base.
Financial statements show what the business has earned. Client contracts help you judge how dependable that revenue will be after the acquisition.
Don’t assume every managed services agreement will transfer automatically when ownership changes. Some contracts require client consent, while others may give clients the right to leave if they don’t approve the acquisition.
Review a representative sample of contracts, including larger and smaller accounts, and confirm which ones need client sign-off before the deal can close.
If one client accounts for around 15–20% or more of MRR, take a closer look at how losing that account could affect the business and the deal.
Look at the top five clients as a group as well. A business where the top five account for well over half of recurring revenue may carry more risk than the headline MRR figure suggests, regardless of how strong that figure looks in isolation.
Churn is one of the easiest figures to present in a favourable light and one of the easiest to misread if you only look at the headline number.
Client churn, sometimes called logo churn, measures how many clients leave. Revenue churn measures the revenue lost. An MSP might lose very few clients but still lose significant revenue through downgrades, fewer seats, or reduced service levels at renewal.
Prepaid contracts and annual billing arrangements can leave you responsible for delivering services after the acquisition, even though the seller collected the payment.
Reconcile the deferred revenue balance and confirm which services you’ll need to deliver after closing. Factor those obligations into your purchase price discussions so you understand both the revenue position and the work ahead.
Technology should be a core part of IT due diligence when evaluating a managed service provider. The tools and systems an MSP relies on can introduce hidden costs, compatibility issues, and extra integration work.
Two MSPs rarely use exactly the same tools, and migrating the target business onto your RMM, PSA, or security platforms takes time and money.
Get a full inventory of the platforms in use, including tools individual technicians may have adopted without formal approval. A fragmented stack can make consolidation longer and more disruptive.
Check auto-renewal clauses, minimum volume commitments, and pricing tiers tied to client count.
Some vendor agreements carry penalties for ending a contract early or dropping below a committed volume. Those costs matter if you plan to consolidate tools soon after closing. Confirm which contracts can transfer to you and which need to be renegotiated.
An MSP’s value depends as much on its people as on its client contracts, so this section can easily be underweighted if you focus mainly on financials.
Ask who owns the key client relationships, who holds the deepest technical knowledge, and what would happen operationally if that person left during or shortly after the transition.
If the business relies heavily on the owner or one or two senior technicians, integration may be more challenging than the organizational chart suggests.
Review employment agreements, non-compete and non-solicit terms, and any retention arrangements already in place.
An acquisition can leave employees uncertain about their future. If key technicians leave soon after closing, you could lose technical knowledge, disrupt client relationships, and put day-to-day operations under pressure. Discuss a clear retention plan with the seller before closing to help reduce that risk.
An MSP may have access to client systems, credentials, backups, and sensitive business data. You need to understand how it manages security and whether any past issues could become your responsibility after the deal.
Review any known breaches, ransomware events, data exposure, or other security incidents involving the MSP or its clients. Look at how each incident was handled, what corrective action followed, and whether any related obligations or concerns remain unresolved.
Look at how the business manages client data, credentials, user access, and backups, and who is responsible for internal security. Gaps in these areas may require additional investment or process changes after the acquisition, so it is better to understand them before the deal progresses.
A closer review can uncover issues that are not immediately visible in the financials, contracts, or early deal discussions.
An outside perspective can be useful when reviewing a target business. A specialist broker can help compare the seller’s financial and operational claims with relevant market activity and flag areas that deserve a closer look before you agree on terms.
At The Host Broker, we specialize in helping buyers navigate acquisitions of hosting, MSP, and other IT services businesses. We can support you through due diligence, help you assess issues that come up during the review, and consider how they may affect negotiations and deal terms.
A useful due diligence review helps you distinguish between issues you can manage and concerns that could change the deal. You won’t remove every unknown, but you should understand where uncertainty remains and how it affects your decision.
By the end of the review, you should have a clearer picture of the business, the work ahead, and whether the acquisition still makes sense on the proposed terms.
MSP due diligence is the structured review of a provider’s financials, contracts, technology stack, staff, and cybersecurity practices before an acquisition.
Common red flags include unexplained EBITDA add-backs, undocumented verbal agreements with clients or staff, and unusually high staff turnover in the past year.
Review past security incidents, client data handling practices, and any known client data issues, including how those matters were handled and whether any concerns remain unresolved.
Request financial statements, billing and PSA exports, client contracts, vendor agreements, employment agreements, and any prior security or compliance documentation for a complete picture.
Due diligence often takes several weeks, although the timeline varies with business size, transaction complexity, and how organized the seller’s records are.