Prepared by: Layer8TechGroup · Framework: 10 Technology Fixes — Tier 1 · Documents Ingested: cached collection (previously ingested)
Assessment Scores — 8-Domain Profile
Complete remediation plan across all scored domains. The Priority Fixes section below highlights the five ranked starting points.
| Domain | Layer8 Service | Value at Risk | Est. Timeline | Typical Investment | Est. ROI |
|---|---|---|---|---|---|
CQCustomer Quality✓ Quick Win | Contract Audit & CRM Implementation | $344,736 | ⏱ 8–10 wks | $5,000 – $9,000 | 20x+ |
DRDiligence Risk✓ Quick Win | Security Hardening & Data Room Preparation | $295,488 | ⏱ 6–8 wks | $4,500 – $7,500 | 20x+ |
OROwner Risk✓ Quick Win | Succession Planning & Knowledge Capture Sprint | $246,240 | ⏱ 8–10 wks | $6,000 – $10,000 | 20x+ |
OSOperational Scalability✓ Quick Win | Process Documentation & Systems Audit | $213,408 | ⏱ 10+ wks | $6,500 – $11,000 | 20x+ |
TMTechnology & Systems Maturity | Technology Infrastructure Audit & Modernization Plan | $164,160 | ⏱ 8–12 wks | $5,000 – $9,000 | |
HCHuman Capital✓ Quick Win | Workforce Retention & Bench Depth Sprint | $164,160 | ⏱ 10+ wks | $5,000 – $8,000 | 20x+ |
FRFinancial Readiness✓ Quick Win | Books Cleanup & Add-Back Schedule | $114,912 | ⏱ 4–6 wks | $2,000 – $4,000 | 20x+ |
LCLegal & Regulatory Compliance | Legal Compliance Audit & Contract Review | $98,496 | ⏱ 8–10 wks | $6,000 – $10,000 | |
| TOTAL | $1,641,600 | — | $40,000 – $68,500 | 20x+ | |
Quick Win items are flagged ✓ in the table above — these deliver the highest remediation ROI in the shortest timeline and are the recommended starting point for any remediation plan.
Typical investment ranges reflect market-rate remediation costs and are provided for prioritization purposes only. Actual engagement scope and pricing depend on business size, gap severity, and selected service provider. Layer8 Tech Group provides formal engagement proposals following assessment delivery.
Layer8 Tech Group delivers these services for businesses preparing for acquisition.Schedule a Discovery Call →
Layer8 Tech Group delivers each of these services for businesses preparing for acquisition. Engagements are scoped to your timeline and deal target.Schedule a Discovery Call →
MSP revenue infrastructure is evaluated on lead-to-contract automation, after-hours responsiveness, and client retention sequences — critical signals for buyers assessing whether ARR growth is system-driven or founder-dependent.
Automation maturity is scored separately from the overall readiness score. The gaps below represent operational efficiency opportunities and post-close value creation for a buyer — not buyer discount risk.
| # | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| R01 | AI Voice / After-Hours Call Handling PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt · company_dataset.json There is no evidence of AI voice agent or automated after-hours call handling in any retrieved documents; the company uses RingCentral cloud phone system with 4 lines but no mention of AI capabilities, auto-attendant, or after-hours call management beyond standard phone service. Calls after hours would default to voicemail or go unanswered, with no lead qualification or CRM logging occurring automatically. | 0/2 | MANUAL | |
| R02 | CRM Presence & Workflow Automation PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt The company uses ServiceTitan for job management and QuickBooks for invoicing, but CRM presence is incomplete and workflows are inconsistent—notably, HubSpot CRM is underutilized with "not all projects logged at closeout" and reporting is incomplete, while critical processes like monitoring alert protocols and customer satisfaction follow-up remain undocumented and person-dependent rather than systematized. | 1/2 | PARTIAL | |
| R03 | 24/7 Lead Capture PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt The retrieved documents contain no evidence of after-hours or 24/7 lead capture capabilities; the SOPs detail manual, person-dependent workflows with no mention of contact forms, chatbots, or automated lead routing systems. Lead generation and customer acquisition processes are not addressed in the available documentation, indicating this capability is either absent or entirely manual. | 0/2 | MANUAL | |
| R04 | SMS Appointment Reminders & Confirmations PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json The retrieved documents contain no evidence of automated SMS appointment reminders or confirmation workflows; the only customer communication method mentioned is email (monitoring confirmation email in Step 8 and invoice email in Step 9), with appointment scheduling occurring manually through ServiceTitan and staff coordination. No SMS automation capability or even manual SMS processes are documented in the company's onboarding procedures or operational systems. | 0/2 | MANUAL | |
| R05 | Automated Review Solicitation PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_IT_Asset_Inventory_2025.csv The company does not conduct automated post-service review solicitation; the internal SOP explicitly states "Customer satisfaction survey: Not currently conducted" and lists implementation as a future goal for Q2 2025. Reviews are entirely organic with no systematic or manual follow-up process currently in place. | 0/2 | MANUAL | |
| R06 | Smart Follow-Up Sequences PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json The retrieved documents contain no evidence of automated follow-up sequences for leads or dormant clients; instead, they document manual, person-dependent processes for project onboarding and invoicing with no systematic lead nurturing or re-engagement capability. The company explicitly notes that customer satisfaction follow-up is "not currently done," and CRM logging is incomplete, indicating an absence of both automated and manual follow-up infrastructure. | 0/2 | MANUAL |
Interpretation: Manual — buyer will underwrite operational risk, expect discount
A low Automation Maturity score for an MSP signals that growth is relationship-driven rather than systematic. Buyers will apply a meaningful discount and may require remediation commitments as a condition of close.
Vertical-specific operational automation gaps identified in MSP & Technology Operational Automation operations. These gaps represent immediate efficiency opportunities for the current owner and post-close value creation levers for a buyer.
Operational automation gaps identified below are framed as efficiency and revenue recovery opportunities. Dollar estimates reflect operational impact, not a valuation adjustment. Layer8 delivers these implementations directly.
| Automation Opportunity | Score | Status | Bar | Layer8 Opportunity |
|---|---|---|---|---|
| Ticket Triage & Auto-Assignment | 0/2 | MANUAL | Ticket automation reduces mean time to first response — the metric buyers use most heavily to benchmark MSP operational maturity and client satisfaction. | |
| Patch Management & Compliance Reporting | 0/2 | MANUAL | Automated patch compliance reporting is a premium tier differentiator — it demonstrates systematic security management and supports cyber insurance requirements. | |
| Client Onboarding & Offboarding | 1/2 | PARTIAL | Onboarding automation is the most visible quality signal to new clients — and the fastest way to surface the gap between an MSP that runs on people and one that runs on systems. | |
| Client Health Scoring & Churn Risk Alerts | 0/2 | MANUAL | Client health automation converts churn prevention from a reactive fire drill to a proactive managed process — directly protecting the MRR base that drives MSP valuation. | |
| QBR Scheduling & Preparation | 0/2 | MANUAL | QBR automation enables consistent executive engagement across the entire client base — not just the accounts that squeaky-wheel their way to attention. |
Layer8 runs 90-day Automation Sprints that close AMI gaps and systematize vertical-specific workflows. The ROI is measurable before you go to market.Schedule a Discovery Call →
Buyer Discount Risk
EBITDA (most recent FY): $864,000 (AI-extracted) · Exit Readiness: 3.2/10 — Not Ready
| Score | Band | Buyer Discount Risk |
|---|---|---|
| 8.0 – 10.0 | Institutional Ready | Minimal — few gaps for buyers to exploit |
| 6.5 – 7.9 | Market Ready | Low — some negotiating leverage for buyers |
| 5.0 – 6.4 | Needs Preparation | Moderate — expect re-trade attempts |
| 3.5 – 4.9 | Material Gaps | High — significant discount likely |
| Below 3.5 | Not Ready | Very High — consider delaying go-to-market |
Scores reflect readiness relative to what buyers examine in diligence — not a valuation guarantee. For a specific valuation range, share your Exit Readiness Score with your broker or M&A advisor.
↑ What strengthens your position
- High MRR percentage >70%
- Documented service contracts
- NOC/helpdesk not owner-dependent
- Stack standardization across clients
↓ What buyers will flag
- Break-fix revenue dominant
- No formal service agreements
- Owner is primary engineer
Domain Detail & Findings
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fix_01 | Documented Processes & SOPs PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company has documented core processes for customer onboarding with assigned owners and target completion timelines, but documentation is incomplete and inconsistently applied. Specific gaps include undocumented alert protocols for monitoring clients managed from memory by one person, inconsistent as-built documentation with many projects lacking formal drawings, and missing customer satisfaction follow-up procedures. Additionally, critical operational knowledge is concentrated in individuals rather than systematized processes, as evidenced by the cybersecurity assessment noting that IT management is handled "ad hoc" by one person serving dual field and administrative roles. | 5/10 | NEEDS WORK | |
| fix_02 | Cybersecurity Posture company_dataset.json · PIS_company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated The company's cybersecurity posture is critically deficient, with the assessment report explicitly stating an overall risk rating of "HIGH" and documenting complete absence of multi-factor authentication (MFA) across all critical business systems and an exposed Remote Desktop Protocol (RDP) port on the public IP address. The internal posture summary confirms "minimal formal cybersecurity program" with security controls that are "ad hoc and rely largely on default configurations," no formal security assessment has been conducted, and the company lacks dedicated IT management with a network technician managing the environment in addition to field responsibilities. | 2/10 | CRITICAL RISK | |
| fix_03 | Owner Dependency PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · PIS_HC_Profile.txt · company_dataset.json — High confidence — multiple documents corroborated The owner is a critical single point of failure across sales, operations, and financial management. The internal documents explicitly identify that "[PERSON] is required for all significant sales and customer decisions," "[PERSON] is the sole technically qualified field supervisor — no backup," and "[PERSON] (owner spouse) manages all financial operations — key person and succession risk." Additionally, the owner personally covered field service during technician departures, manages all hiring decisions exclusively, and holds vendor accounts in his personal name that are "not transferable without vendor consent," creating severe dependency risk for any acquirer. | 3/10 | CRITICAL RISK | |
| fix_04 | Revenue Quality & Concentration PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company generates 40% recurring revenue ($1.92M annualized MRR) from managed services and monitoring contracts across approximately 40 active accounts, placing it in the middle range for predictability. However, revenue concentration and renewal documentation are weak—the documents do not disclose customer concentration metrics, formal renewal rates, or multi-year contract terms, and the internal dataset assigns a "revenue_quality_score" of 6, noting that exit readiness is materially impaired by undocumented monitoring protocols and key-person dependencies that threaten revenue continuity. | 5/10 | NEEDS WORK | |
| fix_05 | Customer Contracts PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The company lacks standardized customer contracts with assignment language and has no centralized contract repository or formal renewal tracking system. The onboarding SOP references contract execution and terms in QuickBooks but contains no evidence of change-of-control clauses, assignment provisions, or documented renewal dates; additionally, the document explicitly states "As-built documentation is inconsistent. Many projects have no formal as-builts" and notes that "HubSpot CRM: Not all projects logged at closeout. Reporting incomplete," indicating contracts and renewal obligations are not systematically tracked across the ~40 active accounts. | 3/10 | CRITICAL RISK | |
| fix_06 | IT Infrastructure & Asset Documentation PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_company_dataset.json · company_dataset.json · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company maintains a basic asset list documenting field tools, network equipment, and systems (Milestone VMS, Lenel S2, Cisco Meraki firewall, Seagate NAS), but infrastructure documentation is severely deficient with significant deferred maintenance and no disaster recovery testing. Critical gaps include: expired firewall security licenses, UPS battery last tested in 2022 with replacement overdue, no verified backup restore tests documented, no offsite backup capability, and ad hoc IT management by a single part-time administrator with no dedicated IT function. Additionally, many customer projects lack formal as-built documentation, monitoring alert protocols are undocumented and managed "from memory," and the cybersecurity assessment rates overall risk as HIGH due to exposed RDP ports, absence of MFA, and lack of network segmentation. | 3/10 | CRITICAL RISK | |
| fix_07 | CRM & Pipeline Documentation PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated The company has minimal CRM adoption with "LOW" maturity per internal assessment—HubSpot is used only by one person for active pipeline tracking, while a second sales leader "tracks deals primarily in email and memory." Sales proposals are drafted in Excel rather than within the CRM, projects are scheduled in ServiceTitan (an operations tool, not a sales pipeline system), and the documents explicitly state "HubSpot CRM: Not all projects logged at closeout. Reporting incomplete," indicating no consistent pipeline documentation or forecast validation discipline. | 3/10 | CRITICAL RISK | |
| fix_08 | Key Employee Risks PIS_company_dataset.json · company_dataset.json · PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company exhibits severe key employee risks with multiple critical single points of failure and minimal documentation or retention protections. The owner is "required for all significant sales and customer decisions," the owner's spouse "manages all financial operations," there is "one sole technically qualified field supervisor with no backup," and processes exist "in people's heads" with "LOW — No formal SOPs documented." No retention agreements are mentioned, and new-hire 58% retention indicates compensation and onboarding deficiencies; additionally, the low-voltage license and vendor accounts are personally tied to the owner, creating additional transfer risks upon departure. | 2/10 | CRITICAL RISK | |
| fix_09 | Financial Trajectory & EBITDA Quality PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company demonstrates consistent revenue growth over three years ($4.05M to $4.8M) with stable and improving EBITDA margins (17% to 18%), and normalized EBITDA of $994,000 after documented add-backs totaling $130,400 in 2024. However, the financials appear to be compiled rather than audited (no third-party financial review is mentioned), and the internal assessment notes a "revenue_quality_score" of 6 with operational maturity concerns, indicating the financial data lacks the independent verification and process documentation expected for a higher exit-readiness rating. | 6/10 | ADEQUATE | |
| fix_10 | Data Room Readiness PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated The company's data room contains some key operational and assessment documents (cybersecurity report, customer onboarding procedures, confidential information memorandum), but is severely hampered by multiple critical gaps and disorganization. Internal process documentation explicitly identifies "known gaps" including undocumented alert protocols managed "from memory," inconsistent as-built documentation with "many projects have no formal drawings," incomplete HubSpot CRM logging, and missing HIPAA Business Associate Agreements for three healthcare clients. The cybersecurity assessment itself—prepared specifically for "M&A Data Room" use—documents material security deficiencies (expired firewall license, no network segmentation, no offsite backup, exposed RDP ports, absent MFA) that will require substantial remediation and likely result in buyer price reduction demands or escrow holdbacks, indicating the data room as currently organized is not ready for sophisticated buyer technical review. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| owr_01 | Succession Readiness PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated There is no formal succession plan in place, and the company exhibits critical single-point-of-failure dependencies that would severely impair business continuity in a transition. The owner is "required for all significant sales and customer decisions," the owner's spouse "manages all financial operations," key vendor accounts (ADI, Anixter, bonding) are "tied to [PERSON] personally and not transferable without vendor consent," and the low-voltage license is "personally tied to [PERSON]" and "must be replaced pre-close or post-close by new license holder," with no identified successor or transition plan documented. | 2/10 | CRITICAL RISK | |
| owr_02 | Institutional Knowledge Capture PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company has no formal SOPs documented, with the internal assessment explicitly stating "documentation_level": "LOW — No formal SOPs documented. Processes exist in people's heads, particularly [PERSON] and [PERSON]." Critical processes including alert response protocols remain entirely undocumented, and institutional knowledge is concentrated in 1-2 key individuals, with the owner serving as a single point of failure for all sales, customer decisions, and major operations. The business has not operated without the owner for more than 3 business days, indicating complete dependency on individuals rather than documented systems. | 2/10 | CRITICAL RISK | |
| owr_03 | Management Team Depth PIS_company_dataset.json · company_dataset.json · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company lacks a formal management layer and is heavily dependent on the owner and owner's spouse for critical functions. The documents explicitly identify that "[PERSON] is required for all significant sales and customer decisions," "[PERSON] is the sole technically qualified field supervisor — no backup," and "[PERSON] (owner spouse) manages all financial operations — key person and succession risk," with processes existing "in people's heads, particularly [PERSON] and [PERSON]" and "NO formal SOPs documented." The internal exit readiness assessment assigns an owner dependency score of 3 and operational maturity score of 4, indicating the business cannot operate independently for 60+ days without the owner present. | 2/10 | CRITICAL RISK | |
| owr_04 | Key Person Concentration Beyond Owner PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated The company has multiple employees who represent critical single points of failure beyond the owner. The Senior Technician is "the sole technically qualified field supervisor — no backup," a person identified as "single point of failure for VMS administration" with no documented backup, and the dispatcher (Tanya Morris) whose "departure would create immediate operational disruption" with "no documented backup for [PERSON]." Additionally, vendor accounts are "held in [PERSON]'s name and personal credit — not transferable without vendor consent," and the company's low-voltage license is "tied to [PERSON] personally," creating material operational and revenue risks if any of these individuals depart. | 2/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| cq_01 | Top Customer Concentration PIS_Confidential_Information_Memorandum.txt · PIS_Financials_2024.csv · PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The largest customer (Northside Hospital Affiliates) represents 13.0% of total revenue ($624,000 of $4.8M), and the top 5 customers combined represent 44.0% of revenue ($2.112M), placing the company in the moderate concentration range with manageable risk. The remaining 29.0% of revenue is distributed across "various small accounts (<$50K each)," demonstrating meaningful diversification beyond the top accounts, though the company's customer base of approximately 40 active accounts shows moderate dependency on the top tier. | 7/10 | ADEQUATE | |
| cq_02 | Revenue Predictability & Recurring Mix PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company generates 40% recurring revenue ($1.92M annualized MRR of $160K in FY2024), consisting of managed network services retainers, 24/7 remote monitoring, and annual maintenance contracts across approximately 40 active accounts. However, revenue predictability is materially constrained by undocumented renewal tracking, lack of formal contract term documentation, and critical operational dependencies—particularly that alert protocols for monitoring clients are "largely undocumented" and managed from memory by a single individual, creating execution risk around the recurring revenue base. The internal dataset explicitly assigns a "revenue_quality_score" of 6, reflecting moderate predictability and recurring mix within the 5-6 band. | 5/10 | NEEDS WORK | |
| cq_03 | Contract Transferability PIS_Confidential_Information_Memorandum.txt · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json — High confidence — multiple documents corroborated The company lacks formal assignment or change-of-control clauses in customer contracts, with no evidence of a centralized contract repository or transferability provisions. The documents explicitly state that the top two revenue relationships (Northside Hospital Affiliates at 13% and Paces Properties at 10% of total revenue) are "personal relationships with [PERSON]," and the risk factors section identifies "OWNER DEPENDENCY" as requiring "a transition plan and appropriate earnout structure" due to the company's inability to transfer these relationships without individual customer consent. Additionally, critical vendor accounts (ADI Global, Anixter) are held in the owner's personal name and are "not transferable without vendor consent," further constraining contract portability in an M&A context. | 3/10 | CRITICAL RISK | |
| cq_04 | Churn Rate & Retention Metrics PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · PIS_CRM_Pipeline_Q1_2025.csv — High confidence — multiple documents corroborated The documents provide no evidence of tracked churn rate, net revenue retention metrics, or formal retention programs. While the company maintains 40 active accounts and generates 40% recurring revenue ($1.92M annualized), there is no mention of customer churn analysis, retention monitoring, or documented recovery playbooks. The company's known operational gaps include incomplete CRM logging, undocumented customer alert protocols, and notably absent post-project customer satisfaction surveys, indicating a reactive rather than proactive approach to customer retention. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| ops_01 | Process Documentation & Repeatability PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company has explicitly "LOW" documentation level with "no formal SOPs documented" and processes that "exist in people's heads, particularly [PERSON] and [PERSON]." While a Customer Onboarding SOP exists, it identifies multiple critical undocumented processes including "Alert response protocols not documented" and notes that "[PERSON] manages [monitoring protocols] from memory," and the company acknowledges "As-built documentation is inconsistent. Many projects have no formal as-builts." The business exhibits heavy reliance on specific individuals, with "[PERSON] required for all significant sales and customer decisions," "[PERSON] is the sole technically qualified field supervisor — no backup," and vendor accounts tied personally to named individuals, making process execution non-repeatable without these key people. | 2/10 | CRITICAL RISK | |
| ops_02 | Technology & Systems Scalability company_dataset.json · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated The company's technology stack is a critical liability for 3x growth. Core infrastructure shows significant aging and single points of failure: the Cisco switch is "end of sale" with "no redundancy," the UPS battery "last tested 2022" and "replacement due," alert response protocols are "not documented," and a single unnamed person is the "sole point of failure for VMS administration." Additionally, the company has "minimal formal cybersecurity program" with "security controls ad hoc and rely largely on default configurations," and critical operational processes exist "in people's heads" with "LOW" documentation levels, making any scaling effort dependent on undocumented knowledge rather than documented, maintainable systems. | 2/10 | CRITICAL RISK | |
| ops_03 | Vendor & Supplier Concentration PIS_company_dataset.json · company_dataset.json · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company has critical single-source vendor dependencies that create existential exit risk. Key vendor accounts for procurement (ADI Global and Anixter) are held personally in the owner's name and personal credit and are "not transferable without vendor consent," and the company's low-voltage license—essential for operations—is tied to the owner personally and "must be replaced pre-close or post-close by new license holder." Additionally, critical IT infrastructure shows dangerous concentration: the Cisco Meraki MX67 firewall security license is expired with no active threat protection, and there is no offsite or cloud backup for business-critical systems including customer monitoring data, creating vulnerability to total data loss in a ransomware or disaster event. | 3/10 | CRITICAL RISK | |
| ops_04 | Financial Controls & Reporting Cadence PIS_company_dataset.json · company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The retrieved documents contain no evidence of financial controls, reporting cadence, monthly close processes, budget vs. actual reviews, or the presence of a CFO or Controller. While QuickBooks is mentioned as a tool used for purchase orders and invoicing in the customer onboarding SOP, there is no documentation of financial close timelines, control procedures, audit trails, or management review processes. The documents focus on operational procedures and cybersecurity posture rather than financial reporting infrastructure, suggesting financial controls and reporting cadence are not formally established or documented. | 2/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| fr_01 | Books Quality & CPA Relationship PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The documents provide no evidence of audited, reviewed, or compiled financial statements prepared by a CPA firm, nor is there any mention of a CPA relationship. While financial summary data is presented (revenue, EBITDA, margins for FY 2022-2024), the documents indicate that "[PERSON] (owner spouse) manages all financial operations" with no reference to external CPA oversight, and the internal dataset notes "overall_score": 4 with significant operational and documentation gaps that would require material rework before diligence readiness. | 3/10 | CRITICAL RISK | |
| fr_02 | Add-Back Documentation PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json · PIS_HC_Profile.txt — High confidence — multiple documents corroborated The documents contain no evidence of formal add-back documentation, normalized EBITDA schedules, or CPA verification of owner adjustments. Instead, the materials reveal pervasive commingling of personal and business expenses—vendor accounts are held in the owner's personal name and credit, the billing specialist position is vacant with billing "handled manually" by the owner and spouse, and the overall documentation level is characterized as "LOW" with processes "exist[ing] in people's heads." A buyer's accountant would face significant obstacles verifying any normalized EBITDA, as the financial operations lack formal separation of add-backs and depend entirely on undocumented personal decisions by the owner. | 2/10 | CRITICAL RISK | |
| fr_03 | Revenue Recognition & Consistency PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · company_dataset.json — High confidence — multiple documents corroborated The company demonstrates consistent recurring revenue tracking, with recurring revenue held steady at 40.0% of total revenue across all three fiscal years ($1.62M to $1.92M), and monthly recurring revenue clearly documented at $160,000. However, the internal assessment notes a "revenue_quality_score" of 6 and overall exit readiness score of 4, with no evidence in the documents of formal revenue recognition policy documentation, GAAP audit procedures, or deferred revenue tracking mechanisms—indicating the consistency is operational rather than formally documented and audited. | 5/10 | NEEDS WORK | |
| fr_04 | Three-Year Financial Trend PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_HC_Profile.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company demonstrates consistent three-year revenue growth from $4.05M (FY2022) to $4.8M (FY2024), representing an 8.6% CAGR with stable and improving gross margins (44.0% to 45.0%) and EBITDA margins (17.0% to 18.0%). While year-over-year growth rates moderate from 9.6% to 8.1%, the trend remains positive with documented add-backs totaling $130,400 in FY2024 ($84K owner compensation above market, $14.4K personal vehicle, $32K one-time legal settlement), normalizing EBITDA to $994K and demonstrating underlying operational consistency. | 7/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| lc_01 | Business Licenses & Permits PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company's low-voltage contractor license (LVA003847) is personally held by the owner rather than by the entity, creating a critical transferability barrier; the documents explicitly state "the low-voltage license is tied to [PERSON] must be replaced pre-close or post-close by new license holder" and note this requires either a buyer's qualifying individual or a transitional arrangement with the current owner. While the company maintains an Alarm Systems Contractor license (GA-ASC-28841), no documentation is provided confirming current status, renewal dates, or transferability of either license, and no evidence exists of formal legal review regarding change-of-control implications or licensing continuity planning. | 3/10 | CRITICAL RISK | |
| lc_02 | Contract Change-of-Control Provisions company_dataset.json · PIS_company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company's key vendor accounts (ADI Global, Anixter) are held personally in the owner's name and are explicitly noted as "not transferable without vendor consent," creating material change-of-control risk. Additionally, the Georgia Low-Voltage Contractor license is held personally by the owner and must be replaced pre-close or post-close by a new license holder, and there is no evidence of formal legal review of customer contracts, service agreements, or change-of-control provisions in any material agreements. | 2/10 | CRITICAL RISK | |
| lc_03 | Employment Law Compliance PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_company_dataset.json — High confidence — multiple documents corroborated The documents reveal material employment compliance gaps and significant classification risks for a home services/trades business. The Georgia Low-Voltage Contractor license is held personally by [PERSON], the owner, with no documented succession plan or arrangement for license transfer post-close, creating immediate regulatory and operational risk. The documents contain no evidence of non-compete or non-solicitation agreements for licensed technicians, no documented I-9 verification procedures, and no clear W-2 versus 1099 classification policy for field technicians, despite this being a common area of misclassification risk in trades businesses as specifically flagged in the assessment rubric. | 3/10 | CRITICAL RISK | |
| lc_04 | Intellectual Property Ownership company_dataset.json · PIS_company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated Pinnacle IS has critical IP ownership gaps that would severely impede an acquisition. Key vendor accounts (ADI Global, Anixter, bonding) are held in the owner's personal name and personal credit and are "not transferable without vendor consent," the low-voltage license is personally tied to the owner and "must be replaced pre-close or post-close," and critical operational and technical knowledge—including alert response protocols, monitoring configurations, and VMS administration—exist only in individual employees' heads with no entity-level documentation or ownership. Additionally, the company acknowledges that processes "exist in people's heads, particularly [PERSON] and [PERSON]" with "LOW" documentation levels, meaning core IP assets and operational methodologies lack formal entity ownership or assignment. | 3/10 | CRITICAL RISK | |
| lc_05 | Litigation & Contingent Liability company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The documents do not disclose any open litigation, material claims, or bar disciplinary proceedings against the company or its licensed personnel. However, a critical licensing dependency exists: the Georgia Low-Voltage Contractor license (LVA003847) is personally tied to an individual and "must be replaced pre-close or post-close by new license holder," creating a material operational contingency that must be resolved before close. Additionally, vendor accounts (ADI Global, Anixter, bonding) are held in personal names and "not transferable without vendor consent," which could expose the buyer to account disruption but does not constitute disclosed litigation or contingent liability at this time. | 6/10 | ADEQUATE |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| tm_01 | Core Systems Documentation & Ownership PIS_company_dataset.json · company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_SOP_Customer_Onboarding_v1.txt — High confidence — multiple documents corroborated Core business systems (Milestone VMS, Lenel S2 access control, QuickBooks) lack formal documentation of ownership and access controls, with critical dependencies on individual staff members managing systems ad hoc. The cybersecurity assessment identifies that "[PERSON], Network/Systems Tech, serves as the de facto IT administrator in addition to his field technician responsibilities" with no dedicated IT management function, and customer monitoring alert protocols are "largely undocumented — [PERSON] manages from memory." Additionally, the assessment reveals no multi-factor authentication across critical systems, no network segmentation, and expired security licenses, indicating shadow IT conditions and vendor relationship non-transferability risks. | 3/10 | CRITICAL RISK | |
| tm_02 | Cybersecurity & Data Protection Posture PIS_Cybersecurity_Assessment_Report_2025.txt · company_dataset.json · PIS_company_dataset.json · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The company presents critical cybersecurity deficiencies that align with the lowest tier of the rubric. The assessment report explicitly states "complete absence of multi-factor authentication (MFA) across all critical business systems" and identifies an "exposed Remote Desktop Protocol (RDP) port on the Company's public IP address" as known attack vectors, while the cybersecurity posture summary confirms "Pinnacle IS has minimal formal cybersecurity program" with "security controls are ad hoc" and notes the company "has not undergone a formal security assessment." No evidence of endpoint protection, data classification, incident response planning, cyber insurance, or vendor security reviews appears in any of the retrieved documents. | 2/10 | CRITICAL RISK | |
| tm_03 | Data Integrity & Business Intelligence PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated Financial data exists and is tracked in QuickBooks with clear revenue and EBITDA metrics, but operational and customer data integrity is severely compromised by manual processes and individual dependencies. Critical gaps include undocumented monitoring alert protocols managed entirely by one person from memory, inconsistent as-built documentation with many projects lacking formal drawings, incomplete HubSpot CRM logging at project closeout, and no customer satisfaction tracking—all indicating scattered data without reliable reporting infrastructure. The cybersecurity assessment confirms the environment lacks formal data governance, with security controls "ad hoc and relying largely on default configurations," and the IT environment managed by a single part-time administrator with no dedicated IT management function. | 3/10 | CRITICAL RISK | |
| tm_04 | Technology Vendor & Subscription Management PIS_SOP_Customer_Onboarding_v1.txt · PIS_Cybersecurity_Assessment_Report_2025.txt · PIS_Confidential_Information_Memorandum.txt · PIS_company_dataset.json · company_dataset.json — High confidence — multiple documents corroborated Core vendor relationships for critical systems (ADI Global, Anixter/Wesco, QuickBooks Online, ServiceTitan, RingCentral) are referenced in operational documents but lack centralized documentation of renewal dates, license terms, or transferability status. The Cisco Meraki firewall license expired as of the assessment date with no documented renewal tracking process, and the Georgia Low-Voltage Contractor license is held personally by the owner rather than by the entity, creating a significant transfer impediment noted as requiring "transitional arrangement with [PERSON] post-close." | 3/10 | CRITICAL RISK | |
| tm_05 | Technical Debt & Modernization Risk company_dataset.json · PIS_company_dataset.json · PIS_Confidential_Information_Memorandum.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company operates aging on-premises infrastructure with critical security and modernization gaps that will require material post-close buyer investment. Specifically, the Cybersecurity Assessment Report identifies an "Overall Risk Rating: HIGH" due to exposed RDP ports, complete absence of multi-factor authentication, two aging Dell PowerEdge servers running legacy systems (Milestone VMS and Lenel S2), an expired Cisco Meraki firewall license, and a UPS with batteries last tested in 2022. Additionally, the company lacks a dedicated IT management function and operates a "primarily on-premises IT environment" managed ad hoc by a field technician with dual responsibilities, creating both technical debt and operational risk that a buyer will need to remediate post-close. | 3/10 | CRITICAL RISK |
| ID | Criterion & Finding | Score | Rating | Bar |
|---|---|---|---|---|
| hc_01 | Workforce Retention & Tenure PIS_HC_Profile.txt · PIS_Confidential_Information_Memorandum.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_CRM_Pipeline_Q1_2025.csv · PIS_Financials_2024.csv — High confidence — multiple documents corroborated The company exhibits significant workforce retention and stability risks. New-hire 90-day retention is only 58%, with "high early attrition, particularly for technicians who discover the compensation gap upon joining," and the senior technician is compensated 6% below market with no written employment agreement. The organization has no formal compensation review cycle, merit increase process, or documented onboarding program, instead relying entirely on owner discretion and informal practices, creating substantial retention vulnerability for a buyer evaluating post-acquisition staff continuity. | 3/10 | CRITICAL RISK | |
| hc_02 | Compensation Competitiveness PIS_Confidential_Information_Memorandum.txt · PIS_HC_Profile.txt · company_dataset.json · PIS_company_dataset.json — High confidence — multiple documents corroborated The company has no formal compensation benchmarking process, with the owner setting all compensation "at his discretion based on informal market awareness and employee requests." Multiple key roles are positioned below market: the Senior Technician earns $72,000 (6% below the CompTIA benchmark of $78,000), and two of three Field Technicians earning $48,000–$56,000 fall below the $52,000–$62,000 market range. Combined with a 36% voluntary turnover rate, 40% technical staff turnover, and no documented merit increase process or employment agreements, this compensation gap creates significant retention risk post-acquisition and will likely require material payroll increases to stabilize the workforce under new ownership. | 3/10 | CRITICAL RISK | |
| hc_03 | Recruiting & Training Capability PIS_HC_Profile.txt · PIS_company_dataset.json · PIS_Cybersecurity_Assessment_Report_2025.txt · company_dataset.json — High confidence — multiple documents corroborated Pinnacle Integrated Systems lacks documented hiring and training processes with no evidence of formal job descriptions, structured onboarding, or multi-stage interviews. The owner personally approves all hires and covers field service gaps himself when technicians depart, as evidenced by the statement that "the owner personally covered field service during both transition periods" following two technician departures in the referenced period. The company exhibits severe retention issues with a 36% voluntary turnover rate practice-wide and 40% technical staff turnover, with only one non-owner employee having tenure longer than the stated baseline period, indicating the hiring and training capability is entirely owner-dependent and ineffective at producing retained productive staff. | 2/10 | CRITICAL RISK | |
| hc_04 | Bench Depth & Succession Beyond Owner PIS_company_dataset.json · company_dataset.json · PIS_Confidential_Information_Memorandum.txt · PIS_HC_Profile.txt · PIS_Cybersecurity_Assessment_Report_2025.txt — High confidence — multiple documents corroborated The company has severe single points of failure across multiple critical non-owner roles with no documented succession planning. Specifically, the owner holds all sales relationships and key account management with "none" listed as backup, the sole technically qualified field supervisor has no backup, and Tanya Morris in dispatch/coordination is identified as a critical dependency whose departure would create "immediate operational disruption" with "no documented backup." The internal assessment explicitly states "No succession planning has been considered" and "the business has not operated without [PERSON] for more than 3 business days," indicating the organization has never tested its ability to function without key personnel. | 2/10 | CRITICAL RISK | |
| hc_05 | Compensation/Benefits Structure Transferability company_dataset.json · PIS_company_dataset.json · PIS_HC_Profile.txt · PIS_SOP_Customer_Onboarding_v1.txt · PIS_Confidential_Information_Memorandum.txt — High confidence — multiple documents corroborated The compensation and benefits structure requires major restructuring at close. The owner takes $168,000 through S-corp distributions (not on payroll) and pays performance bonuses ($3,500) from his personal account without documentation or formal employment agreements; additionally, the company has no employer-sponsored health insurance (estimated $42,000–$58,000 annual cost increase for a buyer to implement), no retirement plan, and informal PTO with no documented policy or accrual tracking. A buyer would inherit a largely undocumented, owner-dependent compensation system with significant portable and cost liabilities requiring immediate formalization. | 2/10 | CRITICAL RISK |
Top 3 Strengths
- Customer Quality at 4.5/10 represents the company's most adequate operational foundation and carries the highest assessment weight at 21%. While the score signals that work remains, this domain's relative strength versus the broader portfolio means buyer diligence will encounter a customer base with measurable stability—reducing the risk of post-close churn surprises that typically trigger price re-trades and holdback disputes. A buyer can focus corrective effort on other domains rather than dismantling customer relationships during transition.
- Financial Readiness at 4.2/10, though still in the needs-work range, avoids the critical-risk designation that plagues most other domains and carries meaningful weight in buyer underwriting. This positioning means the company's books and records are unlikely to surface hidden liabilities or accounting irregularities during diligence—a common source of material adverse effect claims and last-minute discount demands. Cleaner financial documentation reduces friction and buyer negotiating leverage based on surprise findings.
- Diligence Risk at 3.5/10, while still presenting challenges, sits meaningfully above the critical-risk threshold and carries 18% blend weight as a primary driver of buyer confidence. This score suggests that core due-diligence workstreams—legal holds, contract review, compliance verification—will not unearth deal-killing gaps or material misrepresentations that force buyer step-downs in price or extended closing timelines. A buyer can proceed to closing with lower expectation of post-signing disputes or escrow draws tied to undisclosed liabilities.
Top 3 Risks
- Owner Risk at 2.0/10 (CRITICAL RISK) represents a material liability in any transaction. Buyers will apply a significant haircut to account for founder or key-owner dependency, non-compete exposure, or unclear governance structures that create post-close execution risk. This critical gap will dominate seller-side negotiation leverage and is likely to trigger earnout structures, escrow holds, or retention provisions that reduce immediate proceeds.
- Operational Scalability at 2.2/10 (CRITICAL RISK) will trigger a buyer discount due to process maturity, systems integration, and team-leverage gaps that limit the company's ability to grow without proportional cost increases. Diligence teams will flag constraints in repeatable operations, staffing models, and infrastructure that create material post-acquisition remediation costs and operational risk, forcing price concessions or extended working capital adjustments.
- Human Capital at 2.4/10 (CRITICAL RISK) creates a deal-risk factor centered on talent retention, succession planning, and organizational depth. Buyers will apply a haircut to account for key-person dependencies, skills concentration, and the cost and timeline required to build out management bench strength post-close, positioning this domain as a significant source of re-trade and pricing negotiation friction.
Recommended Priority Fixes
The five highest-priority actions for the next 90 days, ranked by deal impact. For the complete domain-by-domain remediation plan and cost estimates, see the Value Recovery Roadmap above.
Compliance Notes
No PII was detected in the ingested documents.