Layer8 Tech Group Exit Readiness Assessment
Peachtree Integrated Systems 2026-08-04

Prepared by: Layer8TechGroup  ·  Framework: 10 Technology Fixes — Tier 1  ·  Documents Ingested: cached collection (previously ingested)

Overall Score
5.0/10
8-domain blend
Buyer Discount Risk
Moderate
Needs Preparation
EBITDA
$1,000,000
most recent FY
Vertical
Technology / MSP
technology

Assessment Scores — 8-Domain Profile

Diligence Risk
5.4/10NEEDS WORK
Owner Risk
5.2/10NEEDS WORK
Customer Quality
4.8/10NEEDS WORK
Operational Scalability
5.0/10NEEDS WORK
Financial Readiness
4.0/10NEEDS WORK
Legal & Regulatory Compliance
4.3/10NEEDS WORK
Technology & Systems Maturity
4.8/10NEEDS WORK
Human Capital
6.0/10ADEQUATE
Value Recovery RoadmapTotal Recoverable Value: $1,550,000
Prioritized by estimated recovery impact

Complete remediation plan across all scored domains. The Priority Fixes section below highlights the five ranked starting points.

DomainLayer8 ServiceValue at RiskEst. TimelineTypical InvestmentEst. ROI
CQCustomer Quality✓ Quick Win
Contract Audit & CRM Implementation$325,500⏱ 8–10 wks$5,000 – $9,00020x+
DRDiligence Risk✓ Quick Win
Security Hardening & Data Room Preparation$279,000⏱ 4–6 wks$2,500 – $4,50020x+
OROwner Risk✓ Quick Win
Succession Planning & Knowledge Capture Sprint$232,500⏱ 6–8 wks$3,500 – $6,00020x+
OSOperational Scalability✓ Quick Win
Process Documentation & Systems Audit$201,500⏱ 8–10 wks$4,000 – $7,00020x+
TMTechnology & Systems Maturity
Technology Infrastructure Audit & Modernization Plan$155,000⏱ 6–8 wks$3,000 – $5,500Technology gaps are an increasingly standalone underwriting factor — buyers mode…
HCHuman Capital✓ Quick Win
Workforce Retention & Bench Depth Sprint$155,000⏱ 6–8 wks$2,500 – $5,00020x+
FRFinancial Readiness✓ Quick Win
Books Cleanup & Add-Back Schedule$108,500⏱ 4–6 wks$2,000 – $4,00020x+
LCLegal & Regulatory Compliance
Legal Compliance Audit & Contract Review$93,000⏱ 6–8 wks$3,500 – $6,500Reduces deal risk and supports clean diligence — unresolved legal gaps are the #…
TOTAL$1,550,000$26,000 – $47,50020x+

Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.

Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.

Ready to recover this value before you list?
Layer8 Tech Group delivers these services for businesses preparing for acquisition.
Schedule a Discovery Call →
Layer8 Service CatalogOne service per Roadmap row — purpose, inputs, deliverables, and success criteria
CQContract Audit & CRM Implementation
Purpose
Protect revenue base transferability by ensuring customer contracts survive a change of control and the pipeline is visible to buyers — two of the most scrutinized items in lower-middle-market diligence.
Client Inputs
All active customer agreements, CRM access or pipeline export, renewal history, list of top 10 accounts by revenue.
Engagement Approach
Contract review for assignment and change-of-control clauses, gap remediation with M&A counsel for missing language, CRM selection or cleanup, pipeline workflow configuration, and renewal tracking implementation.
Deliverables
Contract assignment analysis with remediation recommendations; updated agreements with assignment language; CRM implementation with documented pipeline stages; weighted renewal forecast report.
Success Criteria
All material contracts include assignment language acceptable to buyer counsel; CRM shows a 90-day pipeline with documented renewal rates; top-10 account relationships documented with transition plans.
DRSecurity Hardening & Data Room Preparation
Purpose
Eliminate the most common pre-close diligence findings — security gaps, disorganized documentation, and missing records — so the buyer's team moves efficiently and the seller enters negotiation with a clean record.
Client Inputs
Administrative access to email and file storage systems, current software and SaaS subscription list, contract inventory, data backup and recovery procedures.
Engagement Approach
Security posture assessment against buyer diligence checklists, MFA deployment verification, endpoint protection confirmation, data room folder structure built to standard buyer request formats, incident response procedure documented.
Deliverables
Organized data room with standard diligence folder structure; MFA confirmed across all systems; endpoint protection report; written incident response procedure; data backup and recovery procedure documented.
Success Criteria
Data room passes a sample buyer diligence checklist without gaps; security posture documented to buyer IT diligence standards; no security findings flagged during sale negotiations.
ORSuccession Planning & Knowledge Capture Sprint
Purpose
Convert undocumented succession risk into a written, buyer-acceptable transition plan that reduces Day 1 integration uncertainty and unlocks negotiation leverage on earn-out and escrow terms.
Client Inputs
Owner interview (2–3 hours), key staff interviews (1 hour each), access to current SOPs and operations documentation, current organizational chart.
Engagement Approach
Structured interview series capturing operational and relationship knowledge. Knowledge capture workshops with key staff. Drafting of formal succession plan with phased transition timeline and relationship handoff schedule.
Deliverables
Written succession plan (10–15 pages); phased 90-day transition timeline; key relationship introduction schedule; operational protocol handoff checklist; retention recommendations for critical staff.
Success Criteria
Plan reviewed and accepted by buyer counsel during diligence; transition timeline supports closing without operational disruption; no retention escrow required beyond standard market terms.
OSProcess Documentation & Systems Audit
Purpose
Demonstrate to buyers that the business can operate and grow without the owner — the core test for platform acquisition suitability and a prerequisite for earn-out terms that don't require owner involvement.
Client Inputs
Existing process documentation (any format), list of core operational workflows, technology stack inventory, vendor contracts, org chart and current role descriptions.
Engagement Approach
Process mapping interviews with key staff, SOP drafting for undocumented workflows, technology stack documentation and gap assessment, vendor contract review, financial controls walkthrough and documentation.
Deliverables
Core SOP library covering sales, delivery, billing, and support; technology stack documentation; vendor contract summary with renewal calendar; financial controls memo; org chart with documented decision authority.
Success Criteria
A buyer's operations team can assess day-to-day execution from documentation alone; no single staff member is required to explain how the business runs; operations continue during a 30-day owner absence.
TMTechnology Infrastructure Audit & Modernization Plan
Purpose
Produce the technology documentation and remediation roadmap buyers need to underwrite the business's systems without applying a 'black box' discount — demonstrating the tech stack is an asset, not a liability.
Client Inputs
List of all software, SaaS subscriptions, and hardware; IT vendor contracts; current cybersecurity policies; network or system architecture documentation; access to primary business applications for documentation.
Engagement Approach
Systems inventory and entity-ownership documentation, cybersecurity posture assessment, data integrity review, vendor rationalization, technical debt assessment, modernization roadmap drafting aligned to buyer integration requirements.
Deliverables
Complete systems inventory with entity-owned credential confirmation; cybersecurity findings report; data integrity assessment; vendor rationalization recommendations; written 18-month technology roadmap; technical debt disclosure memo.
Success Criteria
Buyer's IT diligence team can assess all systems from documentation alone; no critical vulnerabilities undisclosed; all material systems confirmed entity-owned and transferable; technical debt quantified and roadmap accepted by buyer's IT lead.
HCWorkforce Retention & Bench Depth Sprint
Purpose
Demonstrate that key staff will remain post-close and that the business has the organizational depth to operate without the owner — reducing the escrow holdback and earn-out provisions buyers use to hedge staff attrition risk.
Client Inputs
Employee roster with tenure and compensation, org chart with reporting lines, existing employment or retention agreements, list of key non-owner roles, comp benchmarking data if available.
Engagement Approach
Compensation benchmarking against vertical market rates, retention risk assessment per key role, training playbook documentation, succession identification for critical non-owner positions, comp and benefits structure review for post-close transferability.
Deliverables
Compensation benchmarking report by role; retention risk matrix with recommended retention bonus structures; written succession plans for key non-owner roles; training playbook for top-3 operational roles; comp and benefits transferability memo.
Success Criteria
Buyer's HR diligence confirms comp is at or near market for all revenue-generating roles; retention agreements in place for staff with >20% of revenue exposure; succession paths documented for all roles where departure would disrupt operations within 90 days.
FRBooks Cleanup & Add-Back Schedule
Purpose
Ensure the company's financial statements survive a Quality of Earnings review without re-trading — the single most common source of post-LOI price reductions in SMB transactions.
Client Inputs
3 years of P&L statements and balance sheets, accounting system access, list of all owner add-backs with supporting documentation, CPA contact.
Engagement Approach
Bookkeeping normalization review for consistency and GAAP alignment, add-back identification and documentation with evidentiary support, CPA coordination for reviewed or audited presentation, QofE preparation briefing.
Deliverables
Normalized 3-year P&L with documented add-backs; add-back schedule with supporting documentation for each item; buyer-defensible adjusted EBITDA calculation; QofE-ready financial package.
Success Criteria
Add-backs are documented with receipts or third-party statements that a buyer's QofE accountant will accept without pushback; EBITDA figure matches seller's stated number; no surprises in financial diligence.
LCLegal Compliance Audit & Contract Review
Purpose
Surface and remediate the legal and compliance gaps that most commonly trigger post-LOI price reductions — license transferability, IP ownership, employment compliance, and undisclosed contingent liabilities.
Client Inputs
Business licenses and permits, material vendor and customer contracts, employment agreements and contractor arrangements, corporate formation documents, prior litigation or regulatory correspondence.
Engagement Approach
Business license review and transferability confirmation with counsel, contract assignment analysis, IP ownership confirmation, employment classification and I-9 review, litigation disclosure review and representation letter preparation.
Deliverables
Legal compliance memo covering all identified gaps and remediation actions; license transferability confirmation; contract assignment analysis; IP schedule; employment compliance findings; attorney representation letter.
Success Criteria
No open legal items triggering a material adverse change clause; licenses confirmed transferable by buyer's counsel; no IP ownership gaps; employment practices reviewed; litigation disclosure complete and documented.
Ready to start a remediation sprint?
Layer8 Tech Group delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.
Schedule a Discovery Call →
Automation Opportunity AssessmentScored separately — upside signals for post-close value creation, not deal-value drivers
▲ Automation Maturity IndexScored separately — excluded from overall score
0.9/10MANUAL (raw: 1/16)

MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.

Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.

#Criterion & FindingScoreRatingBar
R01AI Voice / After-Hours Call Handling
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md
There is no evidence of AI voice agent or automated after-hours call handling in any of the retrieved documents; the company's technology stack focuses on managed IT services, CRM (HubSpot), and ticketing (ConnectWise) with no mention of inbound call automation or AI voice capabilities. After-hours calls are not addressed in operational procedures, indicating they likely go unanswered or to voicemail.
0/2MANUAL
R02CRM Presence & Workflow Automation
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md
Peachtree uses a CRM (HubSpot is referenced in the cybersecurity assessment and ConnectWise in the onboarding program), and a CRM pipeline export exists (PIS_CRM_Pipeline_2025Q2.csv), but the documents reveal inconsistent adoption—manual follow-up and owner dependence remain evident, particularly in late-stage sales and key account management where the owner holds primary relationships. Workflow automation is partial, with basic tool orientation during onboarding but no evidence of systematized automated workflows or fully tracked pipeline processes independent of staff oversight.
1/2PARTIAL
R0324/7 Lead Capture
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md
The retrieved documents contain no evidence of after-hours or 24/7 lead capture capability; there is no mention of a contact form, chatbot, automated lead routing, or any system designed to capture inbound inquiries outside business hours. The company's operations and sales processes described in the documents focus on manual handling and owner/sales director involvement, with no automation infrastructure for lead capture documented.
0/2MANUAL
R04SMS Appointment Reminders & Confirmations
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md
No evidence of automated SMS appointment reminders or confirmation workflows exists in the retrieved documents; the company's onboarding SOP and operational processes reference ConnectWise scheduling and manual field scheduling by the operations manager, but contain no mention of SMS automation, confirmation sequences, or no-show follow-up workflows.
0/2MANUAL
R05Automated Review Solicitation
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md
The retrieved documents contain no evidence of automated post-service review solicitation; review generation is not mentioned in the customer onboarding SOP, CRM processes, or operational workflows. The company relies entirely on organic customer feedback and manual processes, with no documented trigger-based or systematic review request mechanism.
0/2MANUAL
R06Smart Follow-Up Sequences
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · MASTER_PROMPT_Synthetic_Artifact_Generator.md
The retrieved documents contain no evidence of automated follow-up sequences, drip campaigns, or systematic re-engagement workflows for leads or dormant clients. While the company operates a CRM (pipeline data exists in PIS_CRM_Pipeline_2025Q2.csv), there is no documentation of automation rules, email sequences, or lead nurturing processes, indicating follow-up is either manual or absent entirely.
0/2MANUAL

Interpretation: Manual — buyer will underwrite operational risk, expect discount

A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.

📈 Buyer Opportunity: A buyer who systematizes these automation gaps post-close would deploy a proven playbook: AI voice handling, CRM workflows, and follow-up sequences that collectively recover 15–25% of leads currently lost to slow response. This is a predictable, acquirable value-creation lever.
► Operational Automation OpportunitiesVertical-specific — excluded from overall score
1.0/10MANUAL (raw: 1/10)

Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.

Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.

Automation OpportunityScoreStatusBarLayer8 Opportunity
Ticket Triage & Auto-Assignment0/2MANUAL
Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction.
Patch Management & Compliance Reporting0/2MANUAL
Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements.
Client Onboarding & Offboarding1/2PARTIAL
Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems.
Client Health Scoring & Churn Risk Alerts0/2MANUAL
Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation.
QBR Scheduling & Preparation0/2MANUAL
QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention.
Ready to build your automation infrastructure before you list?
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows. The ROI is measurable before you go to market.
Schedule a Discovery Call →

Buyer Discount Risk

EBITDA (most recent FY): $1,000,000 (AI-extracted)  ·  Exit Readiness: 5.0/10 — Needs Preparation

ScoreBandBuyer Discount Risk
8.0 – 10.0Institutional ReadyMinimal — few gaps for buyers to exploit
6.5 – 7.9Market ReadyLow — some negotiating leverage for buyers
5.0 – 6.4Needs PreparationModerate — expect re-trade attempts
3.5 – 4.9Material GapsHigh — significant discount likely
Below 3.5Not ReadyVery High — consider delaying go-to-market

Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.

↑ What strengthens your position

  • High MRR percentage >70%
  • Documented service contracts
  • NOC/helpdesk not owner-dependent
  • Stack standardization across clients

↓ What buyers will flag

  • Break-fix revenue dominant
  • No formal service agreements
  • Owner is primary engineer

Domain Detail & Findings

Diligence Risk5.4/10  NEEDS WORK (18% blend)
Deal Impact: Documentation gaps will extend diligence and require owner availability — expect timeline pressure and buyer discount attempts.
IDCriterion & FindingScoreRatingBar
fix_01Documented Processes & SOPs
README.md · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
Peachtree has documented some key processes, including a structured onboarding program for technical staff (Week 1–8 with defined milestones documented in Employee materials) and a Customer Onboarding SOP referenced in the deal room contents. However, the CIM explicitly states "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the Cybersecurity Assessment identifies reliance on "informal incident response practices" with no approved incident response plan, indicating significant gaps in core operational SOPs and lack of formal version control or annual review cadence.
5/10NEEDS WORK
fix_02Cybersecurity Posture
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company demonstrates partial security controls but significant gaps relative to buyer expectations. While Defender for Business is deployed to most endpoints and nightly backups with cloud retention are in place, the cybersecurity assessment explicitly identifies "inconsistent MFA enforcement, limited centralized log monitoring, and reliance on informal incident response practices" as material issues. The assessment rates overall risk as "Medium" and notes that "buyers will likely discount value or require a remediation plan until identity hardening, monitoring, and documentation are improved," with critical recommendations including completing MFA rollout, deploying SIEM/alert aggregation, and documenting a formal incident response plan with testing.
5/10NEEDS WORK
fix_03Owner Dependency
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The business demonstrates moderate owner dependency with some key operational functions delegated but critical client relationships and strategic decisions remaining concentrated with ownership. While the Operations Manager successfully ran operations during the owner's Q1 2026 surgical recovery with no SLA breaches, and the Sales Director manages the pipeline independently, the CIM explicitly notes "moderate owner dependence in late-stage sales, key client relationships, and vendor negotiations," with the largest customer account (Northside Medical Group, 16% of revenue) having only an operational-contact introduction to backup personnel. No formal succession plan is documented—only a verbal commitment to a transition period post-close with no written agreement.
6/10ADEQUATE
fix_04Revenue Quality & Concentration
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
Peachtree's revenue quality is mixed, with recurring revenue at approximately 42% of 2024 total revenue ($5.42M), falling into the 30-50% range. The top three customers represent 29.7% of total revenue, with the largest customer (Northside Medical Group) at 11.4%, which exceeds the 10% threshold for higher scores but remains below critical concentration risk. While the company has documented recurring contracts across MSP, network management, and support agreements, formal renewal rate documentation is not explicitly referenced in the materials, and the service mix is diversified across structured cabling, managed services, security systems, and network projects.
6/10ADEQUATE
fix_05Customer Contracts
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
The documents reference sample customer contracts ("PIS_Customer_Contract_*.docx/pdf") but provide no substantive evidence of contract standardization, change-of-control clauses, centralized repository management, or renewal tracking processes. The CIM notes that "documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the CRM pipeline shows renewal activity ("Q3 Service Agreement Renewal, Other SMB Accounts") tracked informally in spreadsheets rather than through a formalized contract management system. There is no evidence of contract review, assignment language validation, or documented renewal rates, indicating contracts exist but lack the structure and governance expected at exit.
4/10NEEDS WORK
fix_06IT Infrastructure & Asset Documentation
PIS_CIM.docx · README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
Peachtree maintains a basic IT asset inventory documented in the PIS_Financials_And_Operations.xlsx file that lists servers, network equipment, and mobile devices with status and location, indicating foundational asset tracking exists. However, the Cybersecurity Assessment Report identifies significant documentation gaps, noting that "backups are performed nightly with cloud retention and local replication; restore tests occur [DATE_TIME] but are not always documented," and the CIM explicitly states "Documentation maturity is improving but inconsistent across onboarding and engineering workflows." Additionally, the security assessment rates overall risk as Medium and recommends completing MFA rollout and establishing centralized monitoring, suggesting maintenance practices and system documentation remain incomplete relative to exit-readiness expectations.
5/10NEEDS WORK
fix_07CRM & Pipeline Documentation
PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
Peachtree uses ConnectWise and HubSpot as part of its operational stack (referenced in the cybersecurity assessment's MFA rollout recommendations), and a CRM pipeline export file exists (`PIS_CRM_Pipeline_2025Q2.csv` per the README), indicating CRM adoption. However, the CIM explicitly flags "moderate owner dependence in late-stage sales" and the human capital profile notes that "Mark Ellis runs pipeline independently" with the owner as a secondary contributor, suggesting the pipeline is not uniformly managed across the team. The documents do not provide evidence of current pipeline accuracy, forecast validation against actuals, or enforced stage discipline, placing the company in the mid-range of CRM maturity.
5/10NEEDS WORK
fix_08Key Employee Risks
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
Peachtree has documented some critical role backups and successfully operated without the owner for a quarter (Q1 2026) with no SLA breaches, and the operations manager can execute non-senior technical hiring and onboarding independently. However, there are multiple single points of failure: the owner holds the executive relationship with a key customer representing 16% of revenue (Northside Medical Group) with no formal handoff, Cisco networking architecture depends on only 2 of 3 senior engineers with CCNA certification and no CCNP on staff, and there is no formal succession plan despite the owner's verbal commitment to a post-close transition period with no written agreement yet.
6/10ADEQUATE
fix_09Financial Trajectory & EBITDA Quality
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company reported $5.42M in 2024 revenue with $1.00M EBITDA (18.5% margin) and demonstrates internally consistent financial data across multiple documents, but the financial review status is not explicitly stated as audited or independently reviewed. While the CIM highlights a growing recurring revenue base (~$190K MRR, 42% of total revenue) and the README confirms financial reconciliation across P&L and customer revenue views, there is no evidence of third-party audit, and the overall exit readiness score in narrative documents is noted as 6.5/10, suggesting mixed financial readiness for M&A purposes.
6/10ADEQUATE
fix_10Data Room Readiness
README.md · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company has organized a cohesive deal room with core financial documents (master workbook reconciling to $5.42M revenue, GL exports, AR aging), operational records (employee roster, IT assets, customer contracts), and key narrative documents (CIM, cybersecurity assessment, SOPs) as documented in the README.md. However, the CIM explicitly notes that "documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the overall exit readiness score cited in the narrative documents is only 6.5/10, indicating meaningful gaps in secondary documentation and standardization that would require cleanup before buyer review.
6/10ADEQUATE
Owner Risk5.2/10  NEEDS WORK (15% blend)
Deal Impact: Owner dependency creates integration risk — expect R&W scrutiny and potential purchase-price adjustment.
IDCriterion & FindingScoreRatingBar
owr_01Succession Readiness
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt · PIS_CIM.docx · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
No formal succession plan exists; the owner has only "verbally committed to a [DATE_TIME] transition period post-close" with "no written agreement yet" (PIS_HC_Profile.txt). While the business demonstrated operational resilience during the owner's absence in Q1 2026 with no SLA breaches, a critical single point of failure remains: the owner holds the exclusive executive relationship with Northside Medical Group (16% of revenue), and only operational contacts have been introduced to [PERSON] (PIS_HC_Profile.txt). The CIM explicitly identifies "moderate owner dependence in late-stage sales, key client relationships, and vendor negotiations" as a risk factor, with no documented handoff protocols for these relationships.
4/10NEEDS WORK
owr_02Institutional Knowledge Capture
README.md · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report.docx — High confidence — multiple documents corroborated
Core operational processes show partial documentation with a structured onboarding program documented in the Employee Handbook covering a 5-8 week ramp for technical staff, and the business successfully operated without the owner for a full quarter with no SLA breaches, indicating some knowledge transfer capability. However, the CIM explicitly notes "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and critical technical expertise remains concentrated—specifically, Cisco networking architecture depends on only 2 of 3 senior engineers with CCNA certification and no CCNP-level expertise, forcing complex issues to vendor support, while the top revenue client (Northside Medical Group, 16% of revenue) has the owner holding the executive relationship despite operational contact introductions to other staff.
5/10NEEDS WORK
owr_03Management Team Depth
PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md — High confidence — multiple documents corroborated
The company has a functional management layer with documented authority levels and demonstrated ability to operate independently. The business successfully ran without the owner for Q1 2026 during surgery recovery with no SLA breaches or client escalations, with [PERSON] and [PERSON] managing communications and [PERSON] (NOC lead) handling technical escalations. However, there are two material constraints: the owner holds the executive relationship with Northside Medical Group (16% of revenue) where [PERSON] has only operational-level introduction, and there is no formal succession plan despite the owner's verbal commitment to a post-close transition period.
7/10ADEQUATE
owr_04Key Person Concentration Beyond Owner
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt · PIS_CIM.docx · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
Two to three employees represent material concentration risk beyond the owner. The NOC lead manages all technical escalations with cross-training of only 2 others, and Mark Ellis (Sales Director) independently runs the sales pipeline and handles all commercial accounts, while a key client representing 16% of revenue (Northside Medical Group) has the owner as the sole executive relationship holder with only operational-level introductions documented for backup. The business successfully operated for a period without the owner, but the lack of a formal succession plan and limited backup coverage for Cisco networking expertise (only 2 of 3 senior engineers have CCNA, no CCNP on staff) create material disruption risk if these individuals depart.
5/10NEEDS WORK
Customer Quality4.8/10  NEEDS WORK (21% blend)
Deal Impact: Customer concentration or churn risk gives buyers discount leverage — expect sensitivity analysis and possible escrow.
IDCriterion & FindingScoreRatingBar
cq_01Top Customer Concentration
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
The top three customers represented 29.7% of total revenue, placing the largest customer within the 10-15% range and the top 5 customers likely in the 40-55% range, which aligns with moderate diversification. The company demonstrates manageable concentration risk with a diversified service mix across cabling, managed services, security systems, and network projects, plus a recurring revenue base of approximately 42% that provides additional revenue stability across customer segments.
7/10ADEQUATE
cq_02Revenue Predictability & Recurring Mix
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
Peachtree Integrated Systems derives approximately 42% of [DATE_TIME] revenue from recurring sources, primarily through MSP retainers, network management, and support agreements, with an estimated MRR of ~$190K. While this falls within the 30-50% recurring range with moderate predictability, the CIM notes that the company should "convert mixed and project-only accounts to recurring managed support and monitoring contracts," indicating renewal tracking exists but revenue predictability remains mixed rather than highly formalized, and the top three customers represent 29.7% of total revenue, creating concentration risk that affects 12-month forecasting confidence.
6/10ADEQUATE
cq_03Contract Transferability
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt · PIS_CIM.docx — High confidence — multiple documents corroborated
The retrieved documents do not contain substantive information about customer contract terms, assignment clauses, or change-of-control provisions. While the README references "PIS_Customer_Contract_*.docx/pdf" files as part of the deal room, the actual contract language and transferability terms are not included in the excerpts provided. The CIM notes "Moderate owner dependence in late-stage sales, key client relationships, and vendor negotiations," suggesting relationship risk, but provides no evidence of formal assignment or consent language in customer agreements.
3/10CRITICAL RISK
cq_04Churn Rate & Retention Metrics
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
The retrieved documents contain no quantitative customer churn rate, net revenue retention metrics, or monthly/quarterly tracking of customer attrition. While the CIM notes that "recurring revenue represented approximately 42% of [DATE_TIME] revenue" and mentions "top three customers represented 29.7% of total revenue," there is no documented root-cause analysis, recovery playbooks, or formal retention programs beyond a general growth opportunity to "convert mixed and project-only accounts to recurring managed support." The company demonstrates reactive rather than proactive churn management, with no evidence of systematic retention tracking or customer lifecycle processes.
3/10CRITICAL RISK
Operational Scalability5.0/10  NEEDS WORK (13% blend)
Deal Impact: Technology or process gaps require post-close investment — buyers will model remediation cost into their offer.
IDCriterion & FindingScoreRatingBar
ops_01Process Documentation & Repeatability
README.md · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
Peachtree has documented core operational processes including a structured 8-week technical onboarding program (documented in Employee handbook) and a Customer Onboarding SOP, with some staff able to execute non-senior hiring and onboarding independently. However, the company explicitly identifies "Documentation maturity is improving but inconsistent across onboarding and engineering workflows" (CIM risk factors), and key dependencies remain on specific individuals—particularly the owner holding the executive relationship with a 16% revenue customer (Northside Medical Group) and senior engineers for complex Cisco networking issues, indicating significant repeatability constraints.
5/10NEEDS WORK
ops_02Technology & Systems Scalability
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company relies on a hybrid services delivery model with systems including ConnectWise, Datta, SentinelOne, Microsoft 365, and HubSpot, but the cybersecurity assessment identifies "incomplete controls" including "inconsistent MFA enforcement, limited centralized log monitoring, and reliance on informal incident response practices." While the CIM notes "documentation maturity is improving but inconsistent across onboarding and engineering workflows," there is no evidence of cloud-native architecture assessment, documented scalability testing, or confirmation that core systems can handle 3x growth without material upgrades—only that "buyers will likely discount value or require a remediation plan."
5/10NEEDS WORK
ops_03Vendor & Supplier Concentration
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
Peachtree has moderate vendor concentration risk across multiple critical platforms without evidence of formal SLAs or documented alternatives. The cybersecurity assessment identifies dependencies on Microsoft 365, HubSpot, QuickBooks Online, ConnectWise, and CrowdStrike with incomplete rollout and no mention of backup vendors or contractual protections; additionally, Cisco networking architecture creates a single-source dependency for complex network issues, as only 2 of 3 senior engineers hold CCNA certification with no CCNP on staff, requiring escalation to vendor TAC for critical problems.
5/10NEEDS WORK
ops_04Financial Controls & Reporting Cadence
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company has a Controller on staff and uses QuickBooks Online with documented general ledger exports and AR aging reports, indicating basic financial infrastructure; however, the retrieved documents provide no evidence of monthly close timing, formal budget vs. actual reviews, documented control procedures, or audit trails. The CIM references "documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the cybersecurity assessment notes reliance on informal practices, suggesting financial controls documentation is similarly incomplete and not formalized to buyer expectations.
5/10NEEDS WORK
Financial Readiness4.0/10  NEEDS WORK (7% blend)
Deal Impact: Financial documentation needs work — expect QofE adjustments, timeline extension, and possible buyer discount.
IDCriterion & FindingScoreRatingBar
fr_01Books Quality & CPA Relationship
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents contain no evidence of audited, reviewed, or even compiled financial statements prepared by a CPA firm. The README references a "PIS_Financials_And_Operations.xlsx" master workbook and "QuickBooks-style general ledger export," suggesting internally maintained books rather than professional accounting oversight. The CIM provides only high-level financial summary data ($5.42M revenue, $1.00M EBITDA), with no mention of CPA engagement, audit status, or financial statement preparation standards, indicating these financials are not diligence-ready without substantial rework.
3/10CRITICAL RISK
fr_02Add-Back Documentation
PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The documents identify specific owner add-backs (vehicle at $740/mo, cell and personal expenses ~$3,800/yr, and a discretionary bonus pool of $18,000 in [DATE_TIME]), but documentation is acknowledged as limited and inconsistent. The CIM states "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the HC Profile notes that the bonus pool "should be formalized" despite amounts being "consistent" historically, indicating add-backs lack formal schedules or independent verification. No normalized EBITDA schedule with supporting evidence is presented, and a buyer's accountant would require material rework to independently verify adjustments and reconcile personal versus business expenses.
3/10CRITICAL RISK
fr_03Revenue Recognition & Consistency
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents do not contain specific revenue recognition policies, GAAP compliance documentation, or evidence of consistent application of revenue recognition methods across periods. While the CIM references that "recurring revenue represented approximately 42% of [DATE_TIME] revenue" and financial data reconciles to $5.42M across multiple views, there is no documentation of formal revenue recognition policies, deferred revenue tracking procedures, or audit confirmation of GAAP compliance. The absence of explicit revenue recognition policy documentation and audit evidence places the company in the "mostly consistent with some irregular practices" category, requiring material clarification during financial due diligence.
5/10NEEDS WORK
fr_04Three-Year Financial Trend
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The CIM reports 2024 revenue of $5.42M with $1.00M EBITDA (18.5% margin) and highlights a "growing recurring managed services base" with ~$190K MRR, but the retrieved documents provide no multi-year P&L comparison, CAGR calculation, or year-over-year trend data needed to assess three-year growth consistency. While the overall exit readiness score cited in the README is 6.5/10, the financial excerpts lack the historical revenue and EBITDA figures required to evaluate whether margins are stable or improving, or whether growth has been consistent above or below the 10-15% threshold.
5/10NEEDS WORK
Legal & Regulatory Compliance4.3/10  NEEDS WORK (6% blend)
Deal Impact: Compliance gaps will surface in diligence — expect buyer requests, timeline extension, and potential price adjustment.
IDCriterion & FindingScoreRatingBar
lc_01Business Licenses & Permits
PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents contain no evidence of required business licenses, permits, contractor certifications, or transferability confirmation for Peachtree Integrated Systems' service lines (structured cabling, access control, CCTV, managed IT services). The CIM, cybersecurity assessment, and HR profile files do not address state contractor licensing, EPA certifications, insurance carrier appointments, or any compliance documentation required for the company's technology services operations, representing a material gap in exit-readiness documentation.
2/10CRITICAL RISK
lc_02Contract Change-of-Control Provisions
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents contain no evidence of legal review of vendor, customer, or lease agreements for change-of-control provisions, assignment clauses, or contract portability. While the CIM identifies "moderate owner dependence in late-stage sales, key client relationships, and vendor negotiations" and references sample customer contracts in the deal room file listing, no actual contract language, assignment provisions, or change-of-control analysis is provided in any of the assessed excerpts. The only contractual transition reference is an informal verbal commitment by the owner to a transition period with "no written agreement yet," indicating material gaps in documented contract governance prior to exit.
2/10CRITICAL RISK
lc_03Employment Law Compliance
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The documents reveal inconsistent employment compliance documentation and material gaps in formal agreements. While compensation has been benchmarked against market data (CompTIA Salary Guide, Glassdoor) and benefits are portable (Cigna, Fidelity Simple IRA, Travelers workers comp), there is no evidence of current I-9 documentation, executed non-compete or non-solicitation agreements for technicians who could take customer relationships, or formalized employment agreements—particularly critical given the owner's planned post-close transition period is only documented via "verbal commitment" with "no written agreement yet." Additionally, the discretionary bonus pool ($18,000 in recent year) lacks formal documentation and should be formalized, and two senior engineers have expressed interest in market-rate adjustments, indicating potential retention/classification risk post-transaction.
5/10NEEDS WORK
lc_04Intellectual Property Ownership
PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt · README.md — High confidence — multiple documents corroborated
The documents provide no evidence of formal IP ownership documentation, trademark registration, or an IP schedule in the data room. While the company operates structured cabling, access control, CCTV, and managed IT services, there is no explicit confirmation that software, methodologies, customer data systems (ConnectWise, Datto, SentinelOne), or brand assets are formally assigned to the entity rather than held personally by the owner or embedded in third-party platforms. The cybersecurity assessment and HR profile reference operational tools and systems but do not address IP ownership formality, leaving material ambiguity about clean ownership transfer at close.
5/10NEEDS WORK
lc_05Litigation & Contingent Liability
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The retrieved documents contain no evidence of material litigation, open claims, or undisclosed contingent liabilities. The company operates as a hybrid services firm (structured cabling, access control, CCTV, and managed IT) without law firm, accounting firm, insurance agency, or real estate brokerage operations, so the specialized professional liability assessment categories (malpractice insurance, bar discipline, peer review, RESPA compliance, etc.) do not apply. The only identified contingent liability is a documented $28,000 PTO accrual balance sheet liability and a discretionary bonus pool ($18,000 in prior year) that management indicates should be formalized—both are disclosed, quantified, and represent standard employment obligations rather than material undisclosed exposure.
8/10STRONG
Technology & Systems Maturity4.8/10  NEEDS WORK (10% blend)
Deal Impact: Technology gaps will require buyer attention — expect technical due diligence deep-dive and possible price adjustment.
IDCriterion & FindingScoreRatingBar
tm_01Core Systems Documentation & Ownership
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_Financials_And_Operations.xlsx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
Core business systems are partially documented but show significant gaps in entity ownership and personal account dependencies. The Cybersecurity Assessment Report identifies incomplete MFA enforcement across critical systems (Microsoft 365, HubSpot, QuickBooks Online, ConnectWise, and remote admin tools) and notes that "privileged accounts are not fully separated from day-to-day identities," indicating personal account dependencies remain unresolved. Additionally, the CIM explicitly states "Documentation maturity is improving but inconsistent across onboarding and engineering workflows," and the assessment recommends standing up centralized monitoring and formalizing incident response procedures, suggesting current system documentation and ownership controls are incomplete relative to buyer expectations.
5/10NEEDS WORK
tm_02Cybersecurity & Data Protection Posture
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_CIM.docx · PIS_Financials_And_Operations.xlsx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company has deployed Defender for Business to most endpoints with CrowdStrike rollout in progress for select users, but the cybersecurity assessment explicitly identifies "incomplete controls" relative to buyer expectations, particularly around "inconsistent MFA enforcement, limited centralized log monitoring, and reliance on informal incident response practices." While backups are performed nightly with documented restore tests, there is no evidence of a formalized incident response plan, data classification framework, annual IR testing, cyber insurance, or structured vendor security reviews—with the CIM noting "no formal SIEM or fully mature cybersecurity program despite healthcare-adjacent customer base."
5/10NEEDS WORK
tm_03Data Integrity & Business Intelligence
PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
Peachtree has foundational financial and operational data exports (P&L, GL, AR aging, CRM pipeline, employee roster, IT asset inventory) that reconcile internally to $5.42M revenue and ~$190K MRR, but the documents explicitly state "Documentation maturity is improving but inconsistent across onboarding and engineering workflows" and note that "backup restore tests occur [DATE_TIME] but are not always documented." Critical gaps include no centralized log monitoring or SIEM ("limited centralized log monitoring" per the cybersecurity assessment), and key operational dependencies on individuals (owner holds executive relationships with 16% of revenue customer; [PERSON] manages all field scheduling and vendor relationships without formal handoff procedures).
5/10NEEDS WORK
tm_04Technology Vendor & Subscription Management
PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The documents provide no evidence of documented vendor contracts, renewal date tracking, or formal vendor relationship inventory. The Cybersecurity Assessment Report identifies multiple vendor tools in use (Microsoft Defender, CrowdStrike, Datto, SentinelOne, ConnectWise, HubSpot, QuickBooks Online) but notes "reliance on informal incident response practices" and lacks centralized documentation; additionally, the CIM acknowledges that "documentation maturity is improving but inconsistent across onboarding and engineering workflows," indicating core vendor relationships are known but not formally documented with transferability confirmed.
4/10NEEDS WORK
tm_05Technical Debt & Modernization Risk
PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · README.md · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company operates a mixed technology stack with both modern cloud components (Microsoft 365, Defender for Business, CrowdStrike, Datta, SentinelOne) and deferred modernization needs. The Cybersecurity Assessment Report identifies material gaps including "inconsistent MFA enforcement, limited centralized log monitoring" and incomplete endpoint security deployment (CrowdStrike "in progress for engineering and executive users only"), with the assessor noting that "buyers will likely discount value or require a remediation plan until identity hardening, monitoring, and documentation are improved." While no legacy systems are explicitly described as end-of-life, the documented security control gaps and incomplete tooling rollouts represent deferred upgrades that fall short of buyer expectations for a healthcare-adjacent managed services provider.
5/10NEEDS WORK
▲ Layer8's primary practice area. Technology & Systems Maturity is where Layer8 delivers directly — not just identifies gaps. Where this domain shows deficiencies, remediation is available immediately through Layer8 engagements.
Human Capital6.0/10  ADEQUATE (10% blend)
IDCriterion & FindingScoreRatingBar
hc_01Workforce Retention & Tenure
README.md · PIS_HC_Profile.txt · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
Peachtree demonstrates mixed retention signals with overall annual turnover appearing to fall in the 15-25% range based on reported rates: 0% management turnover, 12% senior technical turnover (1 senior engineer departure), 20% NOC/mid-level technical turnover (2 departures), and 30% administrative turnover. Average tenure metrics are redacted in the documents, but the company shows stability in key revenue-generating and management roles—the single senior engineer departure was replaced within the stated timeframe, and all four managers remain stable. However, compensation gaps noted for senior engineers with stated interest in market rate adjustments pose a near-term retention risk that could affect technical stability in the rolling 24-month outlook.
6/10ADEQUATE
hc_02Compensation Competitiveness
PIS_Cybersecurity_Assessment_Report.docx · README.md · PIS_HC_Profile.txt · PIS_CIM.docx — High confidence — multiple documents corroborated
Peachtree has documented benchmarking against CompTIA Salary Guide and Glassdoor Atlanta data, with most roles at or near market rates; however, senior engineers are paid 5% below the CompTIA median of $112,000 (current range $95,000–$108,000), and two senior engineers have already expressed interest in market-rate adjustments planned for a future review cycle. While the compensation philosophy is documented and systematic, the existing gap in a critical technical role combined with identified retention risk creates moderate exposure to post-close turnover or payroll inflation pressure from the buyer.
6/10ADEQUATE
hc_03Recruiting & Training Capability
PIS_CIM.docx · README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The company has a documented three-stage hiring process and structured onboarding program with defined milestones (Week 1–2 systems access, Week 3–4 shadowing, Week 5–8 independent work, and 90-day performance review), and the Operations Manager can execute all non-senior technical hiring and onboarding without owner involvement. However, owner approval is still required for senior role hires, and new-hire one-year retention of 81% falls slightly below the 85% threshold for higher scores, indicating room for improvement in onboarding effectiveness or role fit.
6/10ADEQUATE
hc_04Bench Depth & Succession Beyond Owner
PIS_HC_Profile.txt · README.md · PIS_CIM.docx · PIS_Cybersecurity_Assessment_Report.docx · PIS_Financials_And_Operations.xlsx — High confidence — multiple documents corroborated
The company has documented bench depth for most key non-owner roles with identified backups (e.g., NOC Operations has Jamie cross-trained 2 others; Billing/Finance has independent coverage; Sales Pipeline has documented overlap), and successfully operated without the owner for Q1 2026 during surgery recovery with no SLA breaches. However, critical single points of failure remain: Cisco networking architecture depends on only 2 of 3 senior engineers with CCNA certification and no CCNP on staff, and the key client relationship (Northside Medical Group, 16% of revenue) is held solely by the owner with only operational contact introduction to [PERSON]. No formal succession plan exists, with only a verbal owner commitment to a post-close transition period and no written documentation.
6/10ADEQUATE
hc_05Compensation/Benefits Structure Transferability
README.md · PIS_Cybersecurity_Assessment_Report.docx · PIS_CIM.docx · PIS_HC_Profile.txt — High confidence — multiple documents corroborated
The compensation structure is largely portable with entity-owned benefits (Cigna health/dental/vision, Fidelity Simple IRA, Travelers workers comp) that transfer cleanly at close. However, cleanup is required on owner-specific arrangements including vehicle allowance ($740/mo), personal expenses (~$3,800/yr), S-corp distributions requiring formalization, and a discretionary bonus pool ($18,000 in [DATE_TIME]) currently distributed by owner with limited documentation that "should be formalized." Additionally, senior engineer compensation gaps have been identified with two senior engineers requesting market rate adjustments planned for an upcoming review cycle, requiring post-close attention.
6/10ADEQUATE

Top 3 Strengths

Top 3 Risks

Recommended Priority Fixes

The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap above.

Fix 1CQ
Audit and Document Customer Retention and Contract Stickiness
Conduct a comprehensive customer quality audit covering concentration risk, renewal rates, churn patterns, and contract terms for the past 36 months. This directly addresses Risk 1 (Customer Quality at 4.8/10), which is the highest-weighted risk domain and will trigger aggressive buyer discounting during underwriting. Buyers will demand this analysis to verify revenue stability; a credible, third-party-validated retention narrative significantly reduces re-trade leverage and protects purchase price.
Fix 2FR
Restate and Certify Historical Financial Records and Controls
Engage a Big Four or top-tier regional accounting firm to audit or review the past two years of financial statements, validate revenue recognition policies against ASC 606 standards, and produce a written control attestation for buyer's CFO review. This addresses Risk 2 (Financial Readiness at 4.0/10), which creates critical diligence friction that buyers will exploit aggressively in re-trade attempts. Clear, externally certified financials eliminate a primary discount justification and reduce forecast uncertainty during earnout negotiations.
Fix 3LC
Complete Contract and Intellectual Property Audit with Legal Opinion
Commission external counsel to conduct a full audit of customer agreements, vendor contracts, IP registrations, and regulatory licenses, producing a gap report and remediation roadmap for any defects discovered. This addresses Risk 3 (Diligence Risk at 5.4/10 combined with Legal & Regulatory Compliance at 4.3/10), which positions the company to face material liabilities and buyer haircuts during third-party verification. A clean legal opinion and documented remediation plan substantially reduces buyer discount claims tied to compliance exposure and contract enforceability.
Fix 4OS
Develop and Document Operational Scalability and Process Roadmap
Create a formal operational scalability plan documenting current capacity constraints, process dependencies, and a 12–24 month growth roadmap that demonstrates how revenue can scale without proportional cost increases. This addresses Operational Scalability (5.0/10, 13% weight), the fourth-highest-impact domain, which directly influences buyer confidence in post-close synergy realization. A credible, detailed scalability narrative reduces buyer uncertainty and limits discount adjustments tied to operational friction and integration risk.
Fix 5TM
Assess Technology Stack and Commission Modernization Plan
Conduct a third-party technology assessment covering infrastructure, security posture, development maturity, and technical debt, then produce a written modernization and security roadmap for buyer CTO review. This addresses Technology & Systems Maturity (4.8/10, 10% weight), which influences buyer confidence in long-term operational and security risk. A transparent technical assessment and prioritized remediation roadmap reduce buyer discount demands tied to hidden technical liabilities and post-close integration complexity.

Compliance Notes

No PII was detected in the ingested documents.