
A due diligence list arrives with a completion date on it. Everything behind that date compresses, and the items that cannot compress become the ones that decide how the last few weeks go.
Information security and data protection sit in the middle of that list. They are also the areas where the honest answer to "can we have this by Friday" is sometimes no, for reasons that have nothing to do with effort.
Where a transaction moves personal data to a different organisation, the ICO treats it as data sharing and expects due diligence from both sides. That applies to a merger, an acquisition, other organisational change, and to data sold as an asset on insolvency. Particular care is expected where the controller changes or where the data ends up shared with an additional controller.
The obligations are specific. Both organisations need to establish what data is being transferred, why it is held and the lawful basis for sharing it. The diligence process should confirm that the recipient will protect people's rights, including confirmation that their staff receive regular data protection and information security training. Once the transfer has happened, the people whose data is held have to be told the circumstances have changed and reminded of their rights.
That is why the questions keep coming back after you have answered them once. The acquirer is building a record that they carried out the check, because they will need to produce it later.
What personal data you hold and on what basis. Most organisations can describe this and fewer can evidence it at the level a diligence process wants, which is a record of processing activities that matches what the systems actually do. Where the two disagree, the diligence team finds the disagreement.
Who has access to what, and when that was last reviewed. The question is rarely whether access control exists. It is whether you can produce the last review, dated, with the person who did it named.
Whether your certifications cover what the buyer thinks they cover. Scope is where this comes apart. A certificate covering one entity or one product line reads differently once someone opens it and looks at the scope statement.
That last one is checkable without you. Cyber Essentials certificates are publicly searchable through IASME by organisation name or certificate number for certificates issued in the last twelve months, and the result shows the level, the dates and the scope. An acquirer's adviser will look before they ask.
Certification is issued by a body working to its own audit programme. An ISO 27001 certificate follows a two-stage audit that expects the management system to have been operating long enough to produce evidence, with an internal audit and a management review already on record. None of that can be produced in the weeks before completion, whatever anyone is willing to spend.
The practical consequence is that a missing certificate stops being a task and becomes a fact about the transaction. It gets handled through the documents instead, as a warranty, a disclosure, a condition or a post-completion undertaking, and those are negotiated by people whose job is to price uncertainty.
Cyber Essentials is a shorter route and still not an overnight one, and the current Danzell marking has failure modes a rushed assessment tends to hit. See Cyber Essentials renewal 2026 and what a lapse costs for what now fails an assessment outright, and how long ISO 27001, Cyber Essentials and DSPT take for the sequences behind each.
The organisations that handle diligence well are usually the ones that were already keeping the record for another reason.
If a round or a sale is plausible in the next eighteen months, three things are worth having in place well before anyone signs a term sheet.
A record of processing activities that matches the systems, reviewed on a schedule somebody owns.
Access reviews, supplier reviews and incident records that carry dates and names, held somewhere other than an inbox.
Certification scoped to the entity and the product the transaction is about, with the scope statement read by someone who has seen the diligence list.
The work is the same work a large customer's procurement will ask for. Doing it for the transaction alone means doing it twice.
For the underlying controls, see the ISO 27001 and UK and EU GDPR framework pages.
Naq keeps controls, evidence and history together, which is the shape a diligence request comes in.
Each control sits against the requirements it satisfies with its evidence attached, so a question about access review or supplier assurance has a current answer and a record behind it. Every change is recorded on the activity stream with previous and new values, and records are archived instead of deleted, so the history survives the people who created it. Where a group holds several entities, each can run its own instance of the same framework, which matters when a transaction concerns one part of the business.
For organisations working towards ISO 27001, Naq gets you audit-ready. The certificate is issued by a certification body accredited by UKAS. Cyber Essentials and Cyber Essentials Plus run through Naq as a Cyber Essentials Certifying Body via IASME.
If a raise or a sale is on the horizon, book a fifteen-minute demo and we will look at what a diligence list would find today.