Deal
Due diligence

Cybersecurity due diligence in a business acquisition: NIS2 and IT risks

Cybersecurity due diligence in acquisitions: review NIS2 exposure, incidents, IT contracts, insurance and warranties before signing.

BRANDAUER Rechtsanwälte
Your law firm

BRANDAUER Rechtsanwälte

Salzburg law firm for corporate, company and transaction law

Every transaction is handled by a coordinated team of lawyers, legal staff and specialists. In company acquisition matters we look at structure, contract, tax and liability together.

13 July 2026 · Mag. Bernhard Brandauer, Rechtsanwalt

Cybersecurity due diligence is not merely a technical workstream. Unresolved security incidents, missing incident documentation or unclear NIS2 exposure can affect price, warranties and the closing plan. Buyers should understand before signing which systems are business-critical and whether personal data breaches under Articles 33 and 34 GDPR were handled properly. This article complements our pieces on data protection due diligence and IP and IT contracts.

Classify cyber risk

Is IT security documented for the transaction?

Answer two questions on the specific finding.

Already know you want to get in touch? Go straight to the enquiry form.

01 Question 1

Is there a documented overview of systems, providers and security incidents?

The first finding determines whether documentation is enough or contract mechanics are needed.

All paths at a glance

Overview of all answers.

01

Clarify the document base first.

Structure the data-room evidence and open questions. Only then should the point be translated into price, warranty or condition precedent.

02

The point is well prepared contractually.

If documents and contract align, the finding can be carried into negotiations, the signing list and the closing plan.

03

Sharpening is needed before signing.

Generic wording is not enough. The contract should state which documents matter, who bears risk and which action is expected before closing.

Which documents belong in the cyber data room

The data room should include a system map, provider overview, access roles, backup concept, incident log, information security policies and material cloud contracts. Without these documents the buyer cannot reliably assess continuity or liability risks.

For targets with critical or important services, parties should also review whether NIS2 obligations or sector-specific security requirements may become relevant. Directive (EU) 2022/2555 is a regulatory framework, not an automatic defect of every company.

Data breaches, GDPR and technical weaknesses

Data breaches are not only a privacy topic. Articles 33 and 34 GDPR concern notification, communication and documentation. In a transaction it matters whether incidents were detected, assessed and remediated.

Open vulnerabilities, unclear deletion concepts or missing processor lists can lead to warranties, indemnities or closing conditions. For digital business models, also review our guide to buying a software or SaaS business.

How cyber risks are reflected in the SPA

The SPA should not merely state that IT systems work. Specific warranties on known incidents, material contracts, security software rights, cyber insurance and technical measures are more useful.

If a finding can be fixed before closing, a condition precedent or closing deliverable may fit. If the risk remains open, price adjustment, holdback or indemnity should be considered. Existing insurance policies should also be reviewed.

Review grid

Make cybersecurity visible as deal risk

The overview shows typical review points and contractual effects.

Review fields in cybersecurity due diligence
Point Why it matters Contract effect
Systems Systems Identifies critical applications and dependencies Data-room schedule or closing deliverable
Incidents Incidents Breaches and outages show liability risks Warranty, disclosure or indemnity
Regulation Regulation NIS2 and CRA may trigger post-closing cost Cost clause or condition precedent
Insurance Insurance Coverage gaps influence risk allocation Review policy and continuation

The contract, data room and economic relevance in the individual case are decisive.

Practical note: Cybersecurity should not be requested only at the end of due diligence. Early structure helps translate technical findings into warranties and the closing list.

FAQ

Frequent questions.

Does every target need a special NIS2 review? +

No. Industry, size and activity are decisive. Still, NIS2 can be a useful review framework because buyers need to understand security organisation and incident processes.

Why do historic data breaches matter in an acquisition? +

They may trigger notification issues, authority correspondence, customer concerns and reputational risk. They belong in the data room, disclosure and contract negotiation.

Is a technical IT review enough? +

No. Technical findings must be translated into legal mechanisms such as warranties, indemnities, closing deliverables or purchase-price logic.

Topics
CybersecurityNIS2Due diligenceData protectionIT contracts

Structuring a deal, reviewing a contract, securing the risks?

When buying a company, structure, review and contract decide. Call us directly or send an email, callback within one business day.

Contact

A direct line to the firm.

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg