Skip to main content

M&A diligence

License compliance for M&A: what diligence teams actually need

How sellers and buyers assess third-party license risk in a deal, what a lockfile dump is not, and how a reviewed attestation page plus exports satisfy diligence without last-minute fire drills.

Last updated: July 19, 2026

Mergers and acquisitions put third-party license risk on a clock. Counsel, diligence teams, and technical advisors need to know what open-source and commercial components ship in the target’s products, what each license requires, and whether the seller can prove that record is current.

This guide is practical, not legal advice. It describes what “good enough” operational proof looks like in a deal, the red flags that slow closing, and how to assemble a diligence pack without inventing a one-off spreadsheet the week before signing.

Why M&A counsel cares about third-party licenses

License risk is deal risk. Undeclared copyleft, missing attribution, or a public page that no longer matches the build can become holdbacks, price chips, or post-close remediation programs.

Buyers ask because they inherit the shipping products and the obligations that travel with them. Sellers who already maintain a reviewed inventory answer faster and with fewer surprises.

  • Confirm which products and release lines are in scope for the deal.
  • Identify copyleft, network copyleft, and proprietary SDK terms early.
  • Separate security findings from license disclosure. Diligence often needs both, but they are not the same deliverable.
  • Ask whether the record is tied to what actually ships, not a marketing site scan alone.

What “good enough” proof looks like

Diligence-ready proof is a reviewed inventory for each in-scope product, frozen at a known publish, with full license text and attribution where required. A buyer-facing attestation page plus matching exports is the usual shape.

A pasted lockfile, an unreviewed SBOM, or a NOTICE file from three years ago is input, not proof. Proof means someone approved the representation before it left the building.

  • Product-scoped inventory (direct and transitive per your policy).
  • Human-reviewed license identifiers and attached full text.
  • A stable URL or export generated from the same approved snapshot.
  • A clear statement of what release or date the record covers.

Red flags that slow deals

Most fire drills start from the same gaps. Spot them before the data room request lands.

None of these mean the deal fails. They mean someone must rebuild a defensible record under time pressure.

  • Undeclared or unresolved GPL, LGPL, or AGPL components in shipped builds.
  • Stale NOTICE or attribution files that do not match the current lockfile.
  • An SBOM treated as finished disclosure, with no reviewed license text.
  • One spreadsheet covering multiple products with no per-product scope.
  • Public pages or exports that cannot be traced to a publish approval.

How to produce a diligence pack

Build the pack from the same loop you should already run for customers: import what ships, review it, publish, then export. Do not invent a parallel diligence-only process the week of signing.

When the buyer asks for both a URL and files, generate both from one frozen snapshot so the data room does not contain conflicting versions.

  1. Scope the products

    List each shipped product in the deal and the release line diligence covers.

  2. Import and review

    Pull lockfiles or SBOMs for those releases. Clear needs-review rows before any share.

  3. Publish the attestation page

    Freeze a snapshot buyers can reopen. Name the product and date on the page.

  4. Export the pack

    Attach SPDX, CycloneDX, PDF, or NOTICE from that same publish when the process requires files.

Limits to state plainly

A maintained compliance page and matching exports are infrastructure for diligence, not a substitute for counsel. High-risk licenses, outbound distribution questions, and deal-specific indemnities still need legal review.

SourceTrust helps teams keep the operational record current so lawyers argue about the few hard cases, not about missing inventory.

Does an SBOM satisfy M&A license diligence?

Usually not by itself. An SBOM identifies components. Diligence still needs reviewed licenses, full text, and a clear product scope. Treat the SBOM as the import, then complete review and publish before you share.

What should sellers prepare before a process letter?

Per product: a current reviewed inventory, an attestation URL or equivalent disclosure, and exports from the same snapshot. Knowing which release each file covers saves days when the data room opens.

What should buyers ask for in the first request list?

Ask for product-scoped proof tied to the builds in the deal: a maintained page or disclosure pack, matching SPDX or CycloneDX if required, and confirmation that copyleft rows were reviewed. Avoid accepting a single undated spreadsheet as complete.

Next step

When you are ready to move from reading to action:

Request a walkthrough

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.