State of M&A Data Rooms — Q2 2026 Read the report →

SaaS Due Diligence (2026): The ARR-to-GAAP Bridge + 12-Metric Verification Stack

Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.

Last updated: August 2026

I'm Deqian Jia, co-founder of Peony, and I've spent the last year watching SaaS deals get repriced in diligence over a single word: ARR. Founders bring me a clean-looking $20M ARR number and assume the buyer will underwrite it at face value. The buyer's quality-of-earnings team does the opposite — it treats ARR as a starting hypothesis and re-derives revenue under ASC 606 / IFRS 15, and the gap between reported ARR and defensible, GAAP-recognized revenue becomes the repricing lever. ARR is a management metric with no GAAP definition; the buyer underwrites the GAAP number, and the delta is where deals get cut. This post is the sourced version of the SaaS diligence playbook: the ARR-to-GAAP bridge, the 12-metric verification stack, and the contract, technical, and data-room mechanics that surround them — every external number named to its source, because the numbers are the whole point.

I run Peony, a data room platform used by 6,800+ customers across M&A, venture capital, and diligence workflows. This is the buy-side verification companion to the seller-side SaaS M&A data room 2026 playbook — that post owns the readiness ladder and the deal landscape; this one owns how a buyer actually checks the numbers.

Quick answer: SaaS due diligence is the buyer-side verification of a software target's recurring-revenue quality, retention, unit economics, and technical posture. Its defining exercise is the ARR-to-GAAP bridge: ARR has no GAAP definition, so the buyer's QofE team re-derives revenue under ASC 606 / IFRS 15 — walking reported ARR down to committed ARR (removing pilots and month-to-month annualizations) and then to GAAP-recognized, defensible revenue (removing usage overages, terminated-but-counted logos, bundled services, and un-ramped contract value). On top of that, a 12-metric stack (ARR, NRR, GRR, gross margin, CAC payback, Rule of 40, churn cohorts, expansion, logo retention, deferred revenue, billings, burn multiple) is verified against source. Per SEG, the public SaaS median EV/TTM-revenue multiple fell from 5.7x (2Q25) to 3.2x (2Q26) — so every unverified point costs real value.

Peony data room organized for SaaS due diligence — ARR schedule, cohort retention files, deferred-revenue roll-forward, top-25 customer contracts, and SOC 2 report staged behind per-reviewer-group permissions


Why is SaaS due diligence different in 2026?

SaaS due diligence is different in 2026 because multiples have compressed to the point where verification, not narrative, sets the price — and the target's headline metric isn't a GAAP number.

Start with the market. The Software Equity Group (SEG) SaaS Index median EV/TTM-revenue multiple compressed from 5.7x in 2Q25 to 3.2x in 2Q26 — a roughly 44% cut in twelve months. Category spreads persist: DevOps & IT Management held the top median at ~5.3x, ERP & Supply Chain ~4.6x, and Security ~4.3x as of 2Q26. SEG also recorded 2,698 SaaS M&A transactions in 2025, a record and a 28% year-over-year increase — so deal volume is high, but buyers are selective, and every point of unverified growth or retention translates directly into enterprise value at a lower multiple than it would have two years ago.

Layer the AI repricing on top. Per Bain's Software M&A 2026 analysis, almost half of all deals in the technology industry already have an AI angle, up from 1 in 4 in 2024, and 1 in 5 strategic dealmakers walked away from a deal in 2025 due to AI's anticipated impact on the target. For a SaaS buyer, that means two questions run simultaneously: is the revenue real, and is the product defensible against agentic substitution? The financial workstream can't be separated from the technical one when AI-feature adoption is what's driving expansion.

Then the structural fact that makes SaaS diligence its own discipline: ARR is not a GAAP measure. It is a management-constructed annualization of the current subscription run-rate. GAAP revenue under ASC 606 and IFRS 15 is recognized ratably over each performance obligation as the service is delivered — a customer paying $12,000 for an annual subscription generates $1,000 of recognized revenue per month, not $12,000 on signing. The buyer underwrites the recognized, defensible number. Every diligence procedure below exists to close the gap between the ARR the seller reports and the revenue the buyer will actually own.


What is SaaS due diligence?

SaaS due diligence is the buyer-side process of verifying that a software target's recurring revenue, retention, unit economics, and technical and security posture are what the seller represents — and of quantifying the gap where they are not.

It runs across the same workstreams as any M&A due diligence process — financial, commercial, technical, legal, tax — but reweighted for a recurring-revenue software asset. The financial workstream centers on the ARR-to-GAAP bridge and the metric-verification stack. The commercial workstream centers on retention cohorts and customer concentration (the commercial due diligence TAM×NRR 4-quadrant is the framework there). The technical, IT, security, and AI workstreams verify the product itself. And the whole thing is compressed onto the deal's critical path, because the quality-of-earnings report has to finalize before the working-capital peg and the purchase agreement can be set.

The distinction from generic diligence is worth restating because it drives everything: in a widget business, the buyer audits a P&L built on delivered goods. In a SaaS business, the buyer audits a forward-looking metric — ARR — that management defined, and re-derives the GAAP revenue underneath it. That re-derivation is the ARR-to-GAAP bridge, and it is the highest-leverage exercise in the entire process.


What are the 12 metrics a buyer verifies in SaaS due diligence?

A buyer verifies twelve metrics, and for each one the diligence job is the same three-part move: know the definition, know where it gets overstated, and run the procedure that proves the real number. The table below is the verification stack.

#MetricDefinitionWhere it gets overstatedVerification method
1ARRAnnualized current subscription run-ratePilots/POCs counted; month-to-month annualized as permanent; churned logos not removedTie each schedule line to a signed order form + live billing record; reconcile to billings and deferred revenue
2Committed / contracted ARROnly contractually committed subscriptionsNon-binding LOIs and verbal renewals includedMatch every line to the contract register with a term end date
3GAAP revenueRecognized ratably under ASC 606 / IFRS 15Point-in-time recognition of subscription; bundled services mislabeledTie to audited/reviewed financials; test the recognition policy
4Net revenue retention (NRR)Cohort expansion − churn − downgrade, existing customers onlyDenominator re-basing; new logos folded inRebuild cohort matrix from billing system with fixed denominator, 24 months
5Gross revenue retention (GRR)Retention before expansion, caps at 100%Rarely overstated — it's the honesty check on NRRSame cohort matrix, expansion stripped out
6Gross marginSubscription revenue − cost to deliverHosting, support, success, API/model costs parked in opexRe-map GL cost centers to a standard SaaS COGS definition
7CAC paybackMonths to recover fully loaded acquisition costBlended CAC; S&M costs excluded from numeratorRecompute fully loaded, new-logo-only, from the raw S&M ledger
8Rule of 40Growth rate + profit marginNon-GAAP "adjusted" margin; ARR growth used where revenue growth is standardRecompute on consistent GAAP inputs
9Logo churn / retention cohortsCount-based retention by vintageAggregate masks vintage decayCohort matrix by count, trend the vintages
10Expansion revenueGrowth from existing customers, by sourceUndecomposed; one-time upsells counted as recurringDecompose into seats, modules, usage
11Deferred revenue & billingsBalance-sheet liability and cash collectionsUsed inconsistently with ARR narrativeReconcile ARR → billings → Δ deferred revenue → recognized revenue
12Burn multipleNet burn ÷ net new ARRNet new ARR overstated (see #1) upstreamRecompute using verified net new ARR

Reference anchors, from the KeyBanc Capital Markets and Sapphire Ventures 2024 Private SaaS Company Survey (104 private SaaS companies, median ~$26M ARR): median net dollar retention ~101%, median gross retention ~90%, median CAC payback 20 months. These are reference points for sanity-checking a target against its cohort — not values to assume. The verification job is always to rebuild the target's own numbers from its own systems.

Metrics 1 through 5 are the core of the ARR-to-GAAP re-derivation and the retention verification, and they get their own sections below.


Why does the ARR-to-GAAP bridge reprice deals?

The ARR-to-GAAP bridge reprices deals because ARR and GAAP revenue are different numbers answering different questions, and the buyer applies the multiple to the GAAP-defensible one.

ARR is a management metric — the current subscription book annualized — with no definition in US GAAP or IFRS. GAAP revenue under ASC 606 / IFRS 15 follows a five-step model (identify the contract, identify the performance obligations, determine the transaction price, allocate it, recognize revenue as obligations are satisfied) and is recognized ratably as the service is delivered. The buyer's QofE team walks reported ARR down through a series of adjustment classes to committed ARR, then to GAAP-recognized, defensible revenue. Each step removes something the seller counted that the buyer won't underwrite.

The adjustment classes

Adjustment classWhat comes outWhy
Pilots / POCsTrials annualized before conversionNot yet recurring or committed
Month-to-month annualizedM2M contracts multiplied ×12 as if permanentNo commitment; churnable at will
Usage overagesVariable overage revenue projected as steady-stateNon-contractual, non-recurring
Terminated-but-counted logosChurned/downgraded accounts never removedNo longer live revenue
Services bundled as subscriptionProfessional services / implementation mislabeledNot recurring subscription; different margin and recognition
Ramp dealsUn-ramped future contract value counted at full rate todayRevenue not yet contractually live
FXForeign-currency ARR at stale or favorable ratesShould be re-struck at current rates

A worked example (hypothetical)

The following is a hypothetical illustration, not a real company or transaction — the figures are invented to show the bridge math.

A target reports $20.0M ARR going into a process at a 5.0x revenue multiple ($100M headline). The buyer's QofE re-derivation:

StepAmountRunning total
Reported ARR$20.0M
Less: pilots/POCs annualized pre-conversion−$1.2M$18.8M
Less: month-to-month contracts annualized as permanent−$1.5M$17.3M
Less: usage overages projected as recurring−$0.8M$16.5M
Less: terminated/downgraded logos still counted−$0.6M$15.9M
Less: professional services bundled as subscription−$0.7M$15.2M
Less: un-ramped contract value on ramp deals−$0.5M$14.7M committed/defensible ARR

Reported ARR of $20.0M becomes $14.7M of defensible, committed ARR — a 26.5% haircut. At the same 5.0x multiple, headline value falls from $100M to about $73.5M — a ~$26.5M repricing before any multiple compression. If the multiple also re-rates from 5.0x toward the SEG public median (3.2x in 2Q26), the compound effect is far larger. This is why the bridge is the single highest-leverage exercise in SaaS diligence, and why sellers who build it themselves pre-market keep control of the story instead of discovering it across the table.

The bridge connects directly to the quality-of-earnings add-back discipline and the financial due diligence price bridge — the ARR-to-GAAP walk is the SaaS-specific front end of the same re-derivation logic those posts cover for EBITDA.


How is deferred revenue treated in a SaaS acquisition?

Deferred revenue in a SaaS acquisition is now generally carried over under ASC 606 rather than written down to fair value — a change buyers modeling on pre-2023 assumptions consistently get wrong.

Under ASU 2021-08 (effective for public companies in fiscal years beginning after December 15, 2022, and private companies one year later), an acquirer recognizes and measures acquired contract assets and contract liabilities — including deferred revenue — as if it had originated the contracts itself, generally on a carryover basis under ASC 606, not at fair value. Before this standard, purchase accounting wrote deferred revenue down to fair value — a "haircut" reflecting only the remaining cost to fulfill plus a normal profit — which meant a chunk of pre-acquisition billings never hit the post-close income statement, artificially suppressing recognized revenue in the periods after close.

Two diligence implications follow:

  1. The deferred-revenue haircut is no longer the automatic revenue drag it once was. A buyer using a legacy model that still writes deferred revenue down to fair value will overstate the post-close revenue write-down and misjudge the ramp. Confirm the current carryover treatment applies.
  2. Deferred revenue becomes a primary cross-check on ARR. The buyer reconciles ARR → billings → change in deferred revenue → recognized revenue. If any leg fails to tie, that's a finding. Deferred revenue is the balance-sheet anchor that keeps the ARR narrative honest.

One caveat the buyer must confirm: carryover only holds cleanly when the acquiree applied ASC 606 consistently and its revenue policies align with the acquirer's. A divergent or incorrect ASC 606 application — common in venture-stage targets that never had an audit — reopens the measurement and adds remediation work. That is exactly the kind of thing the recognition-policy review in the financial workstream is designed to surface.


How do you verify NRR and churn cohorts?

You verify net revenue retention and churn cohorts by rebuilding them from the billing system of record — never by accepting the seller's summary chart at face value.

NRR measures how a fixed cohort of existing customers' recurring revenue changes over 12 months from expansion, contraction, and churn; it excludes new logos entirely. The procedure: pull a cohort matrix from the billing or subscription-management system, group customers by the quarter or year they started, hold each cohort's denominator fixed at its starting recurring revenue, and roll forward expansion, downgrade, and churn month by month for at least 24 months. Three checks catch the standard overstatements:

  • Denominator integrity. NRR is trivially inflated by re-basing the starting cohort or by folding new logos into the "existing customer" bucket. Fix the denominator and the number stops flattering itself.
  • GRR as the honesty check. Gross revenue retention strips out expansion and caps at 100%. A target reporting 120% NRR but 82% GRR is masking heavy small-account churn under a handful of large expansions — and that concentration is itself a finding, not a footnote.
  • Cohort-vintage trend. If newer cohorts retain worse than older ones, the acquisition mix is deteriorating even when the aggregate looks stable. Trend the vintages, don't average them.

The reference band, again from the KeyBanc / Sapphire 2024 Private SaaS Company Survey: median net dollar retention ~101% (down from a 2021 peak of ~109%) and gross retention ~90% across 104 private SaaS companies. A target claiming 130% NRR is possible — but it is above the survey median by 30 points and the burden of cohort proof rises accordingly.

Once the retention number is verified, the commercial due diligence TAM×NRR 4-quadrant map turns it into a posture — compound-and-hold, re-underwrite pricing, repair retention, or walk-or-reprice. This post verifies the number; that post decides what to do with it. Don't rebuild the 4-quadrant here — route to it.


What do contract and customer diligence cover?

Contract and customer diligence covers the terms that determine whether the acquired revenue actually survives the change of ownership — because a dollar of ARR under a consent-required, month-to-month contract is worth far less than a dollar under a multi-year committed one.

Six areas dominate:

  1. Assignment and change-of-control (CoC) clauses. Review the customer terms of service and master subscription agreements for consent-to-assign-on-CoC provisions. If a material share of ARR sits under contracts that let customers walk (or renegotiate) on a change of control, that revenue is at risk on close, and the buyer prices the consent risk directly.
  2. DPA chain and sub-processors. Enterprise customers impose data-processing-agreement obligations that flow to the acquirer, along with sub-processor lists that must be kept conforming. A missing or non-conforming DPA is a remediation cost and, for regulated buyers, a gating item.
  3. Auto-renewal and termination-for-convenience. A book heavy on month-to-month or terminate-anytime terms is worth less than the same ARR under committed multi-year terms — the same distinction the ARR-to-GAAP bridge captures on the revenue side.
  4. Customer concentration. Top-10 and top-decile revenue share. A single anchor customer above ~15% of ARR is a concentration finding regardless of contract quality — a tighter SaaS-specific bar than the 20%-of-revenue threshold general M&A diligence applies — and it drives the concentration stress test the commercial due diligence post details.
  5. Pricing-change and discount history. A target that pulled growth forward with deep discounts has lower defensible ARR and a harder path to post-close price increases.
  6. MFN, price-protection, and cap clauses. Provisions that constrain the buyer's post-close pricing levers — critical if the thesis includes a pricing reset.

The verification method is a source-cited clause extraction across the top customer agreements, each tied back to its ARR contribution so the buyer can weight the risk by dollars, not document count. Peony's AI extraction pulls renewal dates, assignment terms, CoC provisions, and auto-renew language across the contract set with exact page citations, and visitor groups gate the named-customer contracts behind a post-LOI tier so competitor-affiliated bidders never see customer identities before signing.


How do technical, security, and AI reviews route?

Technical, security, and AI reviews run in parallel with the financial and commercial workstreams, and in a SaaS deal they are mandatory — the product is the asset. Rather than duplicate those playbooks, route each to its anchor:

  • Technical due diligence — architecture, code quality, scalability, and technical-debt inventory.
  • IT due diligence — the 6-axis stack-fragility audit: license compliance, vendor concentration, integration debt, infrastructure.
  • Cybersecurity due diligence — breach history, attack-surface assessment, SOC 2 posture, OAuth-token exposure, regulatory compliance.
  • AI due diligence — model provenance, training-data rights, integration debt, EU AI Act exposure.

The SaaS-specific overlay on top of those four is the interaction between the technical review and the revenue review. If AI-feature adoption is what's driving expansion — and therefore NRR — then the technical review must confirm the feature is genuinely defensible and not a thin wrapper over a foundation model that a buyer's own stack could replicate. That is where Bain's finding bites: with almost half of technology deals now carrying an AI angle and 1 in 5 strategic dealmakers walking in 2025 over AI impact, the buyer is underwriting both the revenue and its durability against agentic substitution. Keep the technical and financial reviewers in the same room (literally — one data room, segmented permissions) so the retention story and the architecture story get reconciled rather than assessed in isolation.


What does SaaS due diligence cost and how long does it take?

SaaS due diligence cost and timeline track the broader M&A ranges, with the financial/QofE workstream as the heaviest line item because the ARR-to-GAAP re-derivation is labor-intensive. This is a summary — the full line-item build lives in the due diligence cost breakdown.

  • Quality of earnings (the core of SaaS financial diligence): roughly $10k–$35k on small deals, $25k–$60k on mid-sized deals, $60k–$100k+ on larger, multi-entity targets — typically the single largest line item in financial DD.
  • Timeline: a standard mid-market QofE runs 3–6 weeks depending on data quality; complex or multi-entity SaaS deals run 6–8 weeks; Big Four AI-tooled QofE can compress to as little as 5 days on a clean target.
  • Surrounding workstreams on a lower-mid-market SaaS deal: legal $25k–$60k, tax $15k–$35k, tech/cyber $10k–$25k, focused commercial scan $20k–$40k.
  • All-in: total external diligence typically runs 0.2%–4% of deal value, and a well-organized data room can cut adviser time 25–35% — the single most controllable cost lever, because the ARR-to-GAAP reconciliation is exactly the kind of work that balloons when records are disorganized.

The QofE sits on the critical path — it must finalize before the working-capital peg and the purchase agreement — so its speed gates the deal. The critical-path sequencing is in the due diligence timeline. And the diligence window sits inside a much longer arc: across 334 M&A transactions on the Peony platform, the average deal now takes about 8.6 months to close (State of M&A Data Rooms, Q2 2026) — so data quality, not calendar pressure, is the lever that matters most.


How do you run the data room for SaaS due diligence?

You run a SaaS diligence data room in five moves, and the honest framing up front is that the room is the evidence layer, not the verification layer — the ARR-to-GAAP re-derivation happens in the QofE firm's model, and the cohort truth lives in a metrics warehouse or RevOps system. The room's job is to stage that evidence cleanly, traceably, and with the right eyes on the right sections.

  1. Build the workstream folder taxonomy. Corporate/cap table; financials and ARR schedule; revenue recognition and deferred-revenue roll-forward; customer contracts; product and architecture; security and compliance; HR; legal. Each reviewer group lands in its own section instead of a flat dump. Peony's AI auto-indexing organizes the set into this structure in under 3 minutes.
  2. Set per-reviewer-group permissions. The QofE team gets the financial and revenue-recognition folders; the technical reviewers get product and architecture; the named-customer contracts stay behind a post-LOI gate. Visitor groups handle the segmentation without rebuilding the room per bidder.
  3. Protect competitor-sensitive material. Top-customer lists, pricing tables, and architecture diagrams get dynamic per-viewer watermarks and screenshot protection — essential when the SaaS bidder pool includes strategic acquirers who compete with the target.
  4. Run Q&A in waves. Route every question through a structured workflow rather than email so it reaches the right answerer and the audit trail is preserved. This is what front-loads and compresses the rolling buyer-side question burden.
  5. Read the analytics. Page-level analytics show which reviewer engaged with which section. A bidder who spent hours on the cohort matrix and the contract register is building a model; one who never opened anything past the summary is not a real bidder — and the deadline-extension decision should follow that signal, not a banker's anecdote.

Where the room loses to a dedicated tool — honestly. For the actual metric computation, a metrics warehouse (or the target's RevOps stack) is the system of record for cohorts, and a Big Four QofE is the verification authority for the ARR-to-GAAP bridge. The data room does not replace either; it stages their inputs and outputs so every number in the IC memo traces back to a source document. That division of labor is the point. The companion seller-side readiness ladder — how a founder gets the room to a state that survives this scrutiny — is in SaaS M&A data room 2026, and the permissions mechanics are in the data room permissions for due diligence guide.

Peony Data Room at $52 per admin per month gives unlimited deal-team rooms with visitor groups, watermarks, page analytics, and AI Q&A built in — a flat fee versus the per-deal room charges legacy VDRs bill as expense reimbursement.


What are the common mistakes in SaaS due diligence?

The common mistakes fall into two buckets: buyers who trust the seller's metric definitions, and sellers who never re-derive their own numbers before the buyer does.

Buyer-side mistakes:

  • Accepting ARR at face value. ARR is a starting hypothesis, not a verified number. Every schedule line ties to an order form and a billing record, or it comes out.
  • Trusting a summary NRR chart. Rebuild the cohort matrix from the billing system with a fixed denominator, or the number is unfalsifiable.
  • Skipping the GRR cross-check. NRR without GRR hides small-account churn under large expansions. GRR caps at 100% and cannot lie the same way.
  • Modeling deferred revenue on pre-2023 rules. Post-ASU-2021-08, deferred revenue generally carries over — a buyer still writing it down to fair value overstates the post-close revenue drag.
  • Assessing the technical review in isolation. If AI-feature adoption drives expansion, the architecture review and the retention review have to be reconciled, not filed separately.
  • Using unsourced benchmark medians. Quote KeyBanc/Sapphire or SEG by name, or describe the verification method and omit the number.

Seller-side mistakes:

  • Never building the ARR-to-GAAP bridge pre-market. The seller who discovers the 26% haircut across the table has already lost the narrative. Build it first.
  • Bundling services into the subscription line. It inflates ARR and gross margin on paper and gets fully unwound in diligence — at a cost to trust.
  • A flat, unsegmented data room. Competitor-affiliated bidders in a SaaS process must not see named-customer contracts pre-LOI. Gate them.

The through-line is the same on both sides: source-cited reconciliation. Every claimed number traces to a document, page, and line. The buyer that demands it and the seller that supplies it both come out ahead.


For SaaS due diligence specifically, Peony's data room — used by 6,800+ customers — handles AI auto-indexing of the ARR schedule, cohort files, deferred-revenue roll-forward, top-25 customer contracts, and SOC 2 report into a structured folder tree in under 3 minutes; AI extraction that answers cross-document questions like "list every contract with a month-to-month term and its ARR contribution" with source-cited page references; per-reviewer-group permissions and visitor groups to gate named-customer contracts behind a post-LOI tier; dynamic per-viewer watermarks and screenshot protection to deter leakage during multi-bidder processes; and page-level analytics revealing which bidder is doing real diligence. Try Peony free for 14 days — no credit card required.

About the author: Deqian Jia is co-founder of Peony, the data room used by 6,800+ M&A, PE, venture capital, and diligence teams. He works with buy-side and sell-side teams on SaaS transactions where the gap between reported ARR and GAAP-defensible revenue is the number that sets the price.