Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
Complete remediation plan across all scored domains. The Priority Fixes section below highlights the five ranked starting points.
| Domain | Layer8 Service | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | $67,473 | ⏱ 10+ wks | $8,000 – $14,000 | ~6x |
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | $57,834 | ⏱ 4–6 wks | $2,500 – $4,500 | ~16.5x |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | $48,195 | ⏱ 8–10 wks | $6,000 – $10,000 | ~6x |
OSOperational Scalability | Process Documentation & Systems Audit | $41,769 | ⏱ 10+ wks | $6,500 – $11,000 | ~5x |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | $32,130 | ⏱ 6–8 wks | $3,000 – $5,500 | |
HCHuman Capital | Workforce Retention & Bench Depth Sprint | $32,130 | ⏱ 10+ wks | $5,000 – $8,000 | ~5x |
FRFinancial Readiness | Books Cleanup & Add-Back Schedule | $22,491 | ⏱ 6–8 wks | $4,000 – $7,000 | ~4x |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | $19,278 | ⏱ 8–10 wks | $6,000 – $10,000 | |
| TOTAL | $321,300 | — | $41,000 – $70,000 | ~6x | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Layer8 Tech Group delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.Schedule a Discovery Call →
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt There is no evidence in the retrieved documents of any AI voice agent or automated after-hours call handling system at Apex Managed Solutions. The documents focus on IT service delivery, cybersecurity posture, and human capital structure, with no mention of inbound call automation, after-hours answering capability, or voice AI integration. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt Apex uses ConnectWise Manage as its CRM platform with documented client records and an active pipeline tracked ($380K Q1 2026 with $195K weighted value), but the assessment reveals no evidence of automated workflows—client relationships remain heavily owner-dependent, with [PERSON] holding direct relationships with 11 of 14 managed services clients and all hiring/onboarding decisions funneling through owner approval, indicating manual process dependency rather than systematized automation. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt The retrieved documents contain no evidence of after-hours or 24/7 lead capture capabilities, automated chatbots, or any lead management systems beyond standard ConnectWise Manage integration for service delivery. The company operates a traditional MSP model with no mention of website forms, automated lead routing, or round-the-clock prospecting infrastructure. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt The retrieved documents contain no mention of automated SMS appointment reminders, confirmation workflows, or any appointment management automation; the company's primary operational tools are ConnectWise Manage, IT Glue, and Huntress EDR with no evidence of SMS or appointment reminder capabilities integrated into their workflows. Staff coordination appears to be manual and owner-dependent, consistent with a 0 rating for this criterion. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt There is no evidence in the retrieved documents of any automated or manual post-service review solicitation process; the company's business development and operational procedures make no mention of systematic review requests, triggering, or review management capabilities. The MSP relies entirely on organic reviews without documented review solicitation workflows. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences AMS_CIM.txt · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt The retrieved documents contain no evidence of automated follow-up sequences for leads or dormant clients; the company relies on manual sales and business development processes managed by the sales director and owner without documented email drip campaigns or systematized re-engagement workflows. This represents a complete absence of smart follow-up automation capability. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 0/2 | MANUAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows. The ROI is measurable before you go to market.Schedule a Discovery Call →
Buyer Discount Risk
EBITDA (most recent FY): $378,000 (AI-extracted) · Exit Readiness: 3.7/10 — Material Gaps
| Score | Band | Buyer Discount Risk |
|---|---|---|
| 8.0 – 10.0 | Institutional Ready | Minimal — few gaps for buyers to exploit |
| 6.5 – 7.9 | Market Ready | Low — some negotiating leverage for buyers |
| 5.0 – 6.4 | Needs Preparation | Moderate — expect re-trade attempts |
| 3.5 – 4.9 | Material Gaps | High — significant discount likely |
| Below 3.5 | Not Ready | Very High — consider delaying go-to-market |
Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.
↑ What strengthens your position
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Financials.csv — High confidence — multiple documents corroborated Apex Managed Solutions has minimal formal documentation of processes and procedures, with critical operational knowledge concentrated in individual staff members rather than documented SOPs. The cybersecurity assessment explicitly identifies "documentation formality" as a gap requiring remediation before sale, and the HR profile reveals single points of failure across key roles—the senior network engineer is the only [LOCATION]-certified engineer with no backup, and the owner holds direct relationships with 11 of 14 managed services clients with no succession plan or cross-training program documented. ConnectWise Manage and IT Glue are used for operational tools, but there is no evidence of comprehensive, version-controlled, owner-assigned SOPs for core workflows. | 4/10 | NEEDS WORK | |
| fix_02 | Cybersecurity Posture AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated Apex maintains a solid cybersecurity foundation with MFA enforced across all staff, Huntress EDR deployed on all 11 endpoints, tested backup and disaster recovery procedures, and email security controls in place. However, critical gaps exist that prevent a higher score: no formal incident response plan (only informal procedures documented), no dedicated privileged access management solution for client credentials (shared admin credentials stored in IT Glue), no external penetration testing in the assessment period, and mobile device policy enforcement not technically implemented despite documented policy—all issues the assessment identifies as requiring remediation before a sale process. | 7/10 | ADEQUATE | |
| fix_03 | Owner Dependency AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The owner holds direct relationships with 11 of 14 managed services clients with no documented backups or succession plan, and is the sole decision-maker for all hiring, compensation, and strategic approvals. Critical technical knowledge is concentrated in individual contributors (the Senior Network Engineer is the only location-certified engineer and single point of failure for network-heavy clients), with no cross-training program or formal incident response procedures in place, creating severe operational risk upon owner departure or key staff turnover. | 3/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated Apex Managed Solutions demonstrates solid revenue quality with 62% recurring revenue base from 34 managed services clients averaging $3,200/month and multi-year contracts, placing it in the 7-8 range. The company serves diversified verticals (legal, accounting, healthcare-adjacent, real estate, dental, engineering) with no single client identified as exceeding 10% of revenue, and maintains a documented pipeline of $380K with $195K weighted value indicating predictable growth. However, the assessment is tempered by the lack of formally documented renewal rates and the owner's direct relationships with 11 of 14 managed services clients, creating concentration risk around key account ownership rather than client concentration. | 7/10 | ADEQUATE | |
| fix_05 | Customer Contracts AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information regarding customer contracts, their transferability, standardization, change-of-control clauses, centralized repositories, or contract renewal rates. While the CIM references "34 active managed services clients with average tenure of [DATE_TIME]" and "recurring contracts averaging $3,200 per month per client," there is no documentation of contract terms, assignment language, renewal tracking mechanisms, or the percentage of signed agreements. The absence of any contract documentation in the due diligence materials represents a critical gap for exit readiness. | 2/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated Apex maintains basic IT infrastructure supporting its MSP operations (ConnectWise Manage, IT Glue, Huntress EDR), but documentation and asset management maturity are incomplete. The cybersecurity assessment identifies critical gaps including no formal incident response plan, missing penetration testing in multiple years, and credential management risks through IT Glue without dedicated PAM controls—indicating inconsistent maintenance practices and undocumented procedures. No evidence exists of comprehensive asset lifecycle tracking, disaster recovery testing, or formal system inventory documentation required for higher readiness. | 4/10 | NEEDS WORK | |
| fix_07 | CRM & Pipeline Documentation AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Apex uses ConnectWise Manage as its CRM system and maintains a documented sales pipeline with 15 active opportunities tracked across defined stages (Discovery, Qualified, Proposal, Negotiation, Closed Won) with assigned probabilities and close dates. However, all pipeline opportunities are owned by a single sales director ([PERSON]), indicating limited distribution of pipeline responsibility and potential concentration risk for deal continuity post-acquisition. | 7/10 | ADEQUATE | |
| fix_08 | Key Employee Risks AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company presents severe key employee risks with multiple single points of failure and no documented succession planning. The Senior Network Engineer ([PERSON]) is the only [LOCATION]-certified engineer and his departure would eliminate the company's ability to service network-heavy clients; the Cisco/Network Architecture role has no backup documented, and the owner holds direct relationships with 11 of 14 managed services clients with no cross-training program in place. No employment agreements exist for technical staff, no retention bonuses or equity are offered, technical staff compensation is 6-10% below market with the Senior Network Engineer identified as highest flight risk due to his compensation gap, and 38% technical staff turnover over the past period (including loss of a senior systems engineer who was primary on the largest client) demonstrates the company's inability to retain critical talent. | 2/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Apex Managed Solutions reported $2.1M in revenue with an 18% EBITDA margin ($378K EBITDA), normalized to $412K after add-backs, demonstrating reasonable profitability with documented add-backs. However, the documents provide no evidence of audited or reviewed financials, multi-year growth trajectory, or historical margin trends, and the lack of formal financial documentation combined with ad-hoc owner-driven compensation decisions raises questions about financial rigor and cleanliness for due diligence purposes. | 6/10 | ADEQUATE | |
| fix_10 | Data Room Readiness AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The company has prepared a Confidential Information Memorandum and internal assessments (cybersecurity, human capital profile), indicating some documentation exists, but the retrieved excerpts reveal significant organizational gaps rather than data room readiness. Critical documents appear scattered across functional silos—cybersecurity assessment identifies multiple compliance gaps (no incident response plan, no penetration testing, undocumented PAM procedures), human capital profile documents lack formal employment agreements for key technical staff, and there is no evidence of organized financial documentation, cap table, customer contracts, or IP registers. The company would require substantial cleanup and organization before presenting a professional data room to potential buyers. | 4/10 | NEEDS WORK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated No formal succession plan exists for Apex Managed Solutions. The documents explicitly state "No succession plan or cross-training program exists for any role," and the owner holds direct relationships with 11 of 14 managed services clients with no documented handoff protocols. Critical technical roles lack backup coverage (the Cisco/Network Architect position is flagged as a "single-point-of-failure"), and key staff lack employment agreements, creating severe retention and transition risk. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company has minimal institutional knowledge documentation with critical processes remaining undocumented and highly dependent on key individuals. Onboarding is described as "no formal training program; learning is on-the-job" with "basic system access setup handled by [PERSON] (not documented)" and "no documented playbook" for helpdesk onboarding. Most critically, the owner holds direct relationships with 11 of 14 managed services clients, the Senior Network Engineer is a single-point-of-failure for Cisco/Network Architecture with "no succession plan or cross-training program" in place, and no employment agreements exist to provide contractual retention protections for key technical staff. | 3/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company lacks a formal management layer capable of independent operation. Owner [PERSON] holds direct relationships with 11 of 14 managed services clients, the only [LOCATION]-certified engineer ([PERSON]) represents a single-point-of-failure for network-heavy clients, and no succession plan or cross-training program exists for any role. The Operations Manager handles day-to-day functions but owner approval is required for all hiring decisions and key client matters, leaving the business operationally dependent on owner presence for 60+ days. | 3/10 | CRITICAL RISK | |
| owr_04 | Key Person Concentration Beyond Owner AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company has multiple critical single points of failure beyond the owner. The Cisco/Network Architect [PERSON] is explicitly documented as a "Single-point-of-failure" with no backup, and his departure would eliminate the practice's ability to service network-heavy clients; additionally, the Senior Network Engineer [PERSON] is significantly underpaid (7% below market) and flagged as "the highest flight risk given his compensation gap and market value," with no employment agreements in place to retain either engineer. The owner holds direct relationships with 11 of 14 managed services clients with no succession plan or cross-training program documented for any role. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration AMS_CIM.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_Financials.csv — High confidence — multiple documents corroborated Apex Managed Solutions exhibits significant customer concentration risk, with the largest client (Hendricks Medical Group) representing 18% of revenue according to the Human Capital Profile. The top customer concentration appears to exceed safe thresholds for an exit-stage company, particularly given that the departure of a senior engineer who was the "primary engineer for the largest client" created operational vulnerability and required management coverage post-departure, indicating dependency risk that is not adequately mitigated. | 3/10 | CRITICAL RISK | |
| cq_02 | Revenue Predictability & Recurring Mix AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated Apex Managed Solutions demonstrates strong recurring revenue predictability with 62% of revenue derived from managed services and monitoring contracts, supported by 34 active managed services clients with an average tenure documented in the CIM. The company maintains annual recurring contracts averaging $3,200 per month per client with an active pipeline of $380K (Q1 2026), indicating visibility into near-term revenue. However, the lack of documented renewal rates and the absence of formal renewal tracking procedures prevents a higher score, and recent technical staff turnover—particularly the departure of the primary engineer for the largest client (18% of revenue)—introduces some risk to revenue retention predictability going forward. | 7/10 | ADEQUATE | |
| cq_03 | Contract Transferability AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The documents provide no evidence of customer contracts with assignment or change-of-control clauses. Most critically, the company's 34 managed services clients are personality-dependent relationships: the owner holds direct relationships with 11 of 14 managed services clients with no succession plan, and all sales pipeline opportunities are owned by individual staff members with no documented contract terms addressing transferability. The absence of any contract language, centralized repository documentation, or assignment clause discussion in the due diligence materials indicates contracts cannot be transferred without individual customer consent and renegotiation post-acquisition. | 2/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_Financials.csv · AMS_CIM.txt — High confidence — multiple documents corroborated The company does not measure or track customer churn rate or net revenue retention metrics—no churn data appears in any financial or operational documents provided. While the CIM notes 34 active managed services clients with average tenure and 62% recurring revenue, there is no evidence of formal retention tracking, root-cause analysis of customer losses, or documented retention programs; the only retention focus in the documents relates to employee retention, where technical staff turnover stands at 38% annually, indicating a reactive rather than proactive operational approach. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated Apex Managed Solutions has minimal formal process documentation with heavy reliance on individual knowledge and informal execution. The onboarding process is not documented—"Basic system access setup handled by [PERSON] (not documented)" and "Helpdesk onboarding: [DATE_TIME] ticket shadowing; no documented playbook"—with learning occurring entirely on-the-job through owner involvement. Critical operational areas lack succession planning, with the owner holding direct relationships with 11 of 14 managed services clients and key technical roles having no formal backup, creating significant single-points-of-failure that would prevent business continuity without specific individuals. | 3/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company relies on a remote-first service delivery model supported by ConnectWise Manage, IT Glue, and Huntress EDR, but critical documentation and formalization gaps exist that would impede 3x scaling. The cybersecurity assessment identifies significant gaps in incident response procedures (no documented IR plan exists), privileged access management (credential exposure risk on staff departure), and penetration testing, indicating that core systems lack the documented architecture and formal processes required for enterprise-grade scalability. Additionally, the organization has no formal onboarding playbook, training program, or cross-training—learning is entirely on-the-job—and key technical roles are single points of failure (e.g., the senior network engineer with no backup), meaning 3x growth would require material rework of both systems and organizational capability. | 4/10 | NEEDS WORK | |
| ops_03 | Vendor & Supplier Concentration AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated Apex Managed Solutions has moderate vendor concentration risk with several key dependencies but some documented alternatives. The company relies on a core technology stack including ConnectWise Manage, IT Glue, and Huntress EDR for service delivery, with IT Glue specifically identified as a single-point-of-failure for credential management, though the cybersecurity assessment recommends migration alternatives (BeyondTrust/CyberArk) that are feasible. The company maintains preferred vendor relationships with Dell Technologies and Datto, and the assessment identifies switching options for email archiving (Barracuda Message Archiver) and compliance platforms, but lacks documented formal SLAs or comprehensive switching cost analysis for critical platforms. | 6/10 | ADEQUATE | |
| ops_04 | Financial Controls & Reporting Cadence AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no information about financial controls, reporting cadence, monthly close timelines, budget vs. actual reviews, or documentation of accounting controls. The documents focus exclusively on cybersecurity posture, human capital structure, and sales pipeline, providing no evidence of a CFO, Controller, or formal financial reporting process necessary to assess exit readiness on this dimension. | 2/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The retrieved documents contain no financial statements, audit reports, CPA relationship information, or accounting documentation whatsoever. The CIM references $2.1M revenue and $378K EBITDA with normalized add-backs, but provides no evidence of audited, reviewed, or compiled financial statements, nor any indication of a CPA firm relationship. Without any financial books, statements, or professional accounting oversight documented in the materials provided, the company is entirely unready for financial due diligence. | 2/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The documents contain minimal documentation of add-backs and EBITDA adjustments. While the CIM references "Normalized EBITDA of $412K after add-backs" compared to reported EBITDA of $378K, no supporting schedule, itemization, or verification of these adjustments is provided in any excerpt. The only identifiable add-backs mentioned are the owner's $180,000 S-corp distributions (which "must convert to employment agreement"), discretionary tech bonuses ("paid via owner check, not payroll — must formalize"), and a $680/month vehicle expense, but these lack formal documentation or CPA verification, requiring material rework before a buyer's accountant can independently verify normalized earnings. | 3/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no information regarding revenue recognition policies, GAAP compliance, deferred revenue tracking, or revenue consistency practices. The CIM mentions $2.1M in revenue and a 62% recurring revenue base, but provides no documentation of revenue recognition methodology, audit procedures, or consistency of application across periods. This complete absence of revenue accounting documentation represents a critical gap for exit readiness and poses significant restatement risk during due diligence. | 1/10 | CRITICAL RISK | |
| fr_04 | Three-Year Financial Trend AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The CIM shows $2.1M in revenue with 18% EBITDA margin ($378K EBITDA, normalized to $412K), indicating a profitable, stable business with a 62% recurring revenue base, but the documents do not provide multi-year revenue or EBITDA comparison data necessary to assess the full three-year trend or growth rate. While the business demonstrates operational maturity with established client relationships (34 active clients, $3,200 average monthly contract value) and an active pipeline, the absence of historical financial statements prevents confirmation of consistent growth trajectory or margin stability over the three-year period required by the rubric. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The retrieved documents contain no information regarding business licenses, permits, bar admissions, professional registrations, or transferability of any licenses in a change-of-control scenario. As a managed service provider, Apex Managed Solutions should maintain vendor certifications (Microsoft Gold Partner and CompTIA Managed Services Trustmark are mentioned), but individual technical certifications, compliance credentials, and entity-level licensing requirements are not documented in the materials provided, creating a material compliance gap for M&A readiness. | 1/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of a legal review of key vendor, customer, or lease agreements for change-of-control provisions, assignment clauses, or transferability risks. The only contract-related references are to Microsoft Gold Partner status, preferred vendor relationships with Dell and Datto, and managed services client contracts averaging $3,200/month, but no assessment of their assignability or change-of-control language is documented. This represents a critical gap for exit readiness, as the company's recurring revenue base (62% of $2.1M) and client relationships—particularly the 11 of 14 managed services clients held directly by the owner—lack documented contractual protections or portability analysis necessary for a successful transaction. | 1/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated The documents reveal material employment compliance gaps with no evidence of documented employment agreements, non-compete or non-solicitation agreements for technical staff, and no formal compensation benchmarking process. Critical gaps include: (1) no employment agreements for technical staff, leaving the buyer with "no contractual retention protections" for key engineers like the Senior Network Engineer; (2) owner compensation ($180,000 S-corp distributions) and discretionary bonuses paid outside payroll that "must formalize"; and (3) technical staff compensation 6-10% below market benchmarks with reactive, ad-hoc raises approved only upon employee request rather than through formal review cycles. The documents contain no mention of I-9 verification, EEOC compliance status, or review of any employment law compliance framework. | 3/10 | CRITICAL RISK | |
| lc_04 | Intellectual Property Ownership AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated IP ownership documentation is absent from the retrieved excerpts, with no evidence of formal entity assignment, trademark registration, or IP schedules in the data room. The documents reveal critical operational data (ConnectWise Manage, IT Glue, Huntress EDR, customer lists) are accessible via systems controlled by the owner and key personnel, but no formal policies or assignments establish entity-level ownership versus personal access rights. The cybersecurity assessment notes "credential exposure on staff departure" and references IT Glue passwords held in informal vaults, indicating IP access control gaps rather than clean entity ownership documentation. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt · AMS_HC_Profile.txt — High confidence — multiple documents corroborated No material litigation, claims, or contingent liabilities are disclosed in the retrieved documents. The cybersecurity assessment identifies operational gaps (undocumented incident response plan, missing penetration testing, privileged access management deficiencies) that represent reputational and potential regulatory exposure, particularly with healthcare-adjacent clients, but these are characterized as "MEDIUM-LOW" overall risk and addressable within standard remediation timelines at modest cost ($8,000-12,000 for pen testing). The only disclosed liability is $18,000 in accrued PTO on the balance sheet, which is a standard commercial obligation unrelated to litigation or undisclosed contingencies. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt — High confidence — multiple documents corroborated Core business systems are partially documented but contain significant personal account dependencies and lack formal ownership structure. The cybersecurity assessment identifies that "shared administrative credentials for client environments stored in IT Glue without dedicated vaulting" present a critical risk, and the company lacks a formal Privileged Access Management (PAM) solution, with credentials accessible through individual staff members rather than entity-owned vaults. Additionally, key technical functions show single-point-of-failure dependencies—the Cisco/Network Architect role has no backup, and the owner holds direct relationships with 11 of 14 managed services clients with no documented succession plan or cross-training, creating undocumented system ownership tied to specific individuals. | 4/10 | NEEDS WORK | |
| tm_02 | Cybersecurity & Data Protection Posture AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt · AMS_Customer_Contract_Hendricks.txt · AMS_Financials.csv · AMS_Customer_Onboarding_SOP.txt — High confidence — multiple documents corroborated Apex maintains EDR deployment (Huntress) across endpoints and RMM monitoring with patch management as evidenced by the Hendricks & Associates contract, placing it above baseline. However, critical gaps significantly limit exit readiness: no formal, documented incident response plan exists (only "informal procedures"), no penetration testing has been conducted in the assessment period, privileged access management relies on IT Glue with documented credential exposure risks on staff departure, and no mention of cyber insurance or annual vendor security reviews appears in the assessment. The internal assessment explicitly rates overall risk as "MEDIUM-LOW" with PAM and documentation as primary addressable gaps, but the absence of IR plan testing, pen testing, and insurance coverage falls short of the 7-8 threshold requirements. | 6/10 | ADEQUATE | |
| tm_03 | Data Integrity & Business Intelligence AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company lacks reliable, accessible operational data and exhibits significant individual dependencies across critical functions. The cybersecurity assessment identifies credential exposure risks with "no documented incident response plan" and informal procedures "not written down," while the human capital profile reveals that system access setup is "handled by [PERSON] (not documented)" and the owner holds "direct relationships with 11 of 14 managed services clients" with no succession plan or cross-training. Key operational data such as client relationship ownership, scheduling, and technical expertise reside entirely with individuals rather than in accessible, auditable systems. | 3/10 | CRITICAL RISK | |
| tm_04 | Technology Vendor & Subscription Management AMS_Cybersecurity_Assessment.txt · AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated Vendor relationships are partially documented but lack formal transfer mechanisms and entity ownership verification. The assessment identifies critical tools and subscriptions including Microsoft 365, Huntress EDR, Datto BCDR, and Fortinet FortiGate, but reveals that shared administrative credentials are stored in IT Glue without dedicated vaulting and that no formal documentation exists regarding license transferability or renewal date tracking. Additionally, the company has experienced recent staff turnover and lacks succession planning, creating risk that key vendor relationships or access credentials may depend on departing personnel rather than being fully entity-owned and portable. | 4/10 | NEEDS WORK | |
| tm_05 | Technical Debt & Modernization Risk AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The company operates a mixed technology stack with modern cloud components (Microsoft 365, Azure AD, Huntrest EDR, Datto BCDR) but carries material technical debt in privileged access management and documentation. The cybersecurity assessment identifies a HIGH-risk gap where "shared administrative credentials for client environments stored in IT Glue without dedicated vaulting" creates credential exposure risk, along with MEDIUM-risk gaps including no formal incident response plan, no external penetration testing in the assessed period, and incomplete email archiving—all addressable within documented timeframes at modest cost but requiring post-close buyer investment. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Workforce Retention & Tenure AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_Financials.csv — High confidence — multiple documents corroborated The company exhibits significant workforce retention risk with a 31% voluntary turnover rate over the rolling 24 months and average tenure of only 2.6 years across all staff. Technical staff turnover is particularly acute at 38%, including the departure of a senior systems engineer with 8 years tenure who was the primary engineer for the company's largest client (18% of revenue), creating critical knowledge loss that required owner coverage for an extended period. Compensation analysis reveals technical staff are paid 6–10% below Atlanta market benchmarks with no formal retention strategy, no equity offerings, and the Senior Network Engineer (CCNP-certified) identified as the "highest flight risk" due to his compensation gap. | 3/10 | CRITICAL RISK | |
| hc_02 | Compensation Competitiveness AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company lacks any formal benchmarking process with compensation set ad-hoc by the owner, and technical staff are compensated 6-10% below Atlanta MSP market benchmarks—notably the Senior Network Engineer earning $88,000 versus a $95,000 CompTIA median, with the employee raising concerns twice. The absence of employment agreements, retention bonuses, equity, or an annual review cycle, combined with a 38% technical staff turnover rate and early-hire compensation mismatch driving 71% new-hire retention, creates significant flight risk for the highest-value employee ([PERSON], the sole CCNP-certified engineer) and poses material retention risk post-acquisition without substantial pay restructuring. | 3/10 | CRITICAL RISK | |
| hc_03 | Recruiting & Training Capability AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CRM_Pipeline.csv — High confidence — multiple documents corroborated The company has no structured hiring process—the owner must approve all hires, there is no documented interview rubric, and onboarding is entirely ad-hoc with no formal training program or playbook. New-hire one-year retention stands at only 71%, driven by compensation mismatches discovered after hiring, and the documents explicitly state that "learning is on-the-job" with the owner involved in orientation for all technical hires, indicating the business cannot scale hiring without owner involvement. | 3/10 | CRITICAL RISK | |
| hc_04 | Bench Depth & Succession Beyond Owner AMS_CRM_Pipeline.csv · AMS_HC_Profile.txt · AMS_Cybersecurity_Assessment.txt · AMS_CIM.txt — High confidence — multiple documents corroborated The company has critical single-points-of-failure across multiple key roles with no documented succession plans or cross-training programs. Section 4 explicitly identifies the Cisco/Network Architect as a "Single-point-of-failure" whose departure would eliminate the company's ability to service network-heavy clients, while the owner holds direct relationships with 11 of 14 managed services clients with "no succession plan or cross-training program exists for any role." Additionally, there are no employment agreements for technical staff, providing the buyer with no contractual retention protections for key engineers. | 2/10 | CRITICAL RISK | |
| hc_05 | Compensation/Benefits Structure Transferability AMS_HC_Profile.txt · AMS_CRM_Pipeline.csv · AMS_Cybersecurity_Assessment.txt — High confidence — multiple documents corroborated The compensation structure is partially portable with significant owner-specific cleanup required at close. The company maintains entity-owned, portable benefits (Cigna group health/dental/vision, Fidelity Simple IRA, documented PTO with $18,000 liability), but critical issues include $180,000 in owner S-corp distributions that must convert to an employment agreement, discretionary tech bonuses paid via owner check rather than through payroll, and notably, no employment agreements exist for technical staff—creating zero contractual retention protections for key engineers like the Cisco CCNP-certified senior network engineer, who is already 7% below market compensation and has raised compensation concerns twice. | 5/10 | NEEDS WORK |
Top 3 Strengths
- Diligence Risk at 4.6/10 represents an adequate foundation for deal documentation, meaning Apex has avoided the most severe compliance and record-keeping failures that typically trigger deep-dive re-underwriting and extended closing timelines. This positions the company to move through buyer due diligence without the extended data requests and scope expansions that often create re-trade opportunities and compress purchase price negotiations.
- Technology & Systems Maturity at 4.7/10 demonstrates that core operational systems are functional and partially documented, reducing the risk that a buyer will discover undocumented technical debt or mission-critical single-person dependencies during technology review. This baseline maturity limits one major source of post-close integration cost surprises and price adjustments that buyers commonly invoke when systems assessment reveals hidden modernization liabilities.
- Customer Quality at 3.8/10, while requiring work, avoids the critical-risk threshold that would signal customer concentration, high churn, or contract instability—issues that trigger the most severe buyer discounts in MSP acquisitions. By operating above that threshold, Apex preserves negotiating position on customer-related earn-out mechanics and holdback structures that would otherwise lock in significant contingent price reductions.
Top 3 Risks
- Owner Risk at 2.8/10 (CRITICAL RISK) represents a critical gap in governance and founder dependency that will trigger a buyer discount during diligence. Buyers will conduct detailed underwriting of owner concentration, decision-making authority, and post-close transition risk, and will apply a material haircut to reflect the operational and retention liability created by inadequate owner-level governance structures and documented succession planning.
- Legal & Regulatory Compliance at 2.8/10 (CRITICAL RISK) creates a material liability that poses a deal-completion risk and will require remediation before or immediately after listing. Buyers will identify compliance gaps during vendor management, contractual, and regulatory review; expect significant price concessions and potential post-close indemnification obligations tied to remediation of outstanding regulatory or contractual exposure.
- Financial Readiness at 3.2/10 (CRITICAL RISK) will trigger a buyer discount due to the critical gaps in accounting systems, reporting infrastructure, and financial controls that undermine diligence confidence and increase post-close adjustment risk. A buyer's finance and operational due diligence teams will flag weak financial governance, audit-readiness deficiencies, and undocumented cost structures, creating negotiating leverage for price concessions and holdback provisions.
Recommended Priority Fixes
The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap above.
Compliance Notes
No PII was detected in the ingested documents.