Private Equity & M&A

DORA and NIS2 turn cyber-DD into a closing condition. We make it doable.

Mid-market PE and strategic acquirers can't treat cyber due diligence as nice-to-have from 2025 onward. It's a closing condition. Kopexa scans targets against DORA, NIS2 and ISO 27001 in 14 days instead of 6 weeks, SPA-ready and multi-entity-capable for post-merger integration.

  • DORA Art. 28–30, NIS2 Art. 21–23 and ISO 27001 Annex A in one scan
  • Multi-entity platform for portfolio rollout after closing
  • LP-reporting ready (quarterly cyber-health across portfolio)
14 days
DD scan vs 6 weeks
frameworks in parallel
n + 1
multi-entity portfolios

Example: cyber-DD score

Hohes Risiko

SaaS target · 120 employees · Hesse

Planned acquisition · closing Q3

DD-Score
38/ 100

DORA

In scope (via AIFM relationship)

NIS2

Essential entity

ISO 27001

No ISMS, no DPO designated

Closing-Empfehlung

SPA clauses on cyber-compliance required. Risk reserve to be calculated.

Current regulatory drivers

Three regulations change DD scope 2024–2026.

Cyber-DD is no longer optional. Buying a target without DORA/NIS2 check means inheriting open fine risk and personal executive liability.

Live since 17 Jan 2025

DORA

Financial entities, AIFMs, crypto service providers

ICT third-party risk (Art. 28–30) must be documented at closing. SPA clauses on DORA compliance becoming standard.

Bußgeldrahmen

up to 2 % of global group turnover

Transposition Q1–Q3 2025

NIS2 (BSIG amendment)

30,000+ German companies (essential + important entities)

From 50 employees / EUR 10M turnover potentially in scope. § 38 BSIG: personal executive liability. Buyer checks threshold status in target.

Bußgeldrahmen

up to EUR 7M / 1.4 % turnover

Live since 25 May 2018, fine wave from 2024

GDPR

All companies processing personal data

Check target's fine backlog, verify DPO designation, inspect ROPA and TOM documentation. Rep & Warranty insurance requires evidence.

Bußgeldrahmen

up to 4 % of global group turnover

Sources: regulations, BSI activity reports, German Data Protection Conference (DSK).

Full deal lifecycle

Four phases, one platform.

Cyber compliance is no longer a one-off DD point. It's continuous oversight across the investment cycle. Here is what Kopexa delivers per phase.

Phase 1 · Buy-side DD14 days

Cyber-DD before LOI / SPA

Scan target against DORA, NIS2, ISO 27001 and (where applicable) TISAX. Check thresholds, quantify fine risk, surface missing structures (DPO, ISMS, vendor management).

Mit Kopexa

Standardised DD template on Pro plan. OSCAL import of target docs. SPA-ready findings report with risk score and concrete recommendations.

See Pro plan
Phase 2 · Post-merger integration60–180 days

Roll out group standards to subsidiaries

After closing, compliance standards must apply to the new subsidiary, alongside existing portfolio companies. Painful manually, chaotic with n separate tools.

Mit Kopexa

Multi-entity platform (Enterprise plan): define group frameworks once, instantiate n times. Cross-framework mapping avoids duplicate work.

ISO 27001 Roadmap
Phase 3 · Pre-sale vendor DD8–12 weeks

Cyber compliance as multiple driver

Before exit, sellers want a clean cyber story. Documented ISMS / DORA / NIS2 compliance justifies higher multiples and disarms vendor DD findings.

Mit Kopexa

Audit trail over multiple quarters, exportable compliance dossiers for the data room, auditor workspace for external confirmation.

DORA Hub
Phase 4 · Portfolio monitoringongoing

LP reporting and risk aggregation

LPs ask for ESG, cyber and governance quarterly. An aggregated view across portfolio companies isn't possible with n separate compliance stacks.

Mit Kopexa

Aggregated dashboard across portfolio. Cyber-health score per company. Quarterly export for LP reports. Escalation workflow on incidents via § 38 BSIG / DORA reporting.

NIS-2 Hub

Killer argument vs DD boutiques

One control covers four regulations.

NCC, KPMG Cyber and other DD houses sell DORA, NIS2 and ISO-DD as separate workstreams. Kopexa maps them automatically: one scan, one findings report, four regulations covered.

Control areaDORANIS2ISO 27001TISAX 6.0
ICT third-party risk / supply chainArt. 28–30Art. 21(2)(d)A.5.19–5.238.x
Risk management & governanceArt. 5–15Art. 21(1)A.5.7, A.6.x1.x
Incident reporting & notificationArt. 17–18Art. 23A.5.24–5.255.x
Executive responsibilityArt. 5Art. 20 (BSIG § 38)A.5.11.1
Resilience testing / pen testingArt. 24–27Art. 21(2)(f)A.8.295.2
Asset & configuration managementArt. 9Art. 21(2)(c)A.5.9, A.8.91.4

Mapping based on Kopexa cross-framework engine. Full 200+ mapping points in the Pro and Enterprise plans.

Multi-entity

Holding view. Subsidiary workspace. One platform.

In the Enterprise plan you build group frameworks once and roll them out n times. Each portfolio company has its own workspace, the holding dashboard aggregates for LP reports.

  • Maintain group policies once

    Holding defines cyber standards, all subsidiaries inherit automatically. No n Excel graveyards.

  • Aggregated LP reports

    Cyber-health score across portfolio companies, exportable as PDF for quarterly LP calls.

  • Escalation workflow

    Incidents per § 38 BSIG / DORA Art. 17 are automatically escalated to holding oversight.

Holding · Aggregated view

5 Portfolio-Companies

Ø Cyber-Score

71/100

Portfolio companies

PortCo A

SaaS · 80 employees

84

PortCo B

Fintech · 240 employees

71

PortCo C

Industrial · 450 employees

58

PortCo D

Maritime · 120 employees

92

PortCo E

Healthcare · 95 employees

49

Pay once, use forever

Boutique DD vs. Kopexa across 3 years.

Move the slider to your portfolio size. The comparison shows traditional DD boutique per target plus separate platform per portfolio company against an Enterprise plan covering DD and ongoing compliance.

Portfolio size

5 portfolio companies

Time horizon

3 years

DD boutique setup

593.000 EUR

  • Cyber-DD boutiques3 × 95.000 EUR285.000 EUR
  • GRC tools per portfolio company5 × 8.000 EUR × 3 J.120.000 EUR
  • Post-merger consulting3 × 36.000 EUR108.000 EUR
  • LP reporting (manual)5 × 16.000 EUR80.000 EUR

Kopexa Enterprise

52 % günstiger

285.000 EUR

  • Enterprise plan (scales with portfolio)90.000 EUR / Jahr270.000 EUR
  • Onboarding & success managereinmalig15.000 EUR
  • Cross-framework mappingim Plan enthaltenin plan
  • LP reporting dashboardim Plan enthaltenin plan
  • DD templates + OSCALim Plan enthaltenin plan

Difference over 3 years

308.000 EUR

Plus soft factor: documentation outlives closing, findings live outside the PDF graveyard.

Assumptions: mid-market complexity, 1 acquisition per year over the horizon. Specific Enterprise pricing on request.

FAQ for PE & M&A teams

Two entry points

Single-deal DD or portfolio rollout. Both paths start here.

Single-target DD is the fastest entry, portfolio rollout the biggest lever. Both run on the same platform.

Pro plan

DD for one target

Single workspace with unlimited frameworks, OSCAL import, SPA-ready findings report. Right for buy-side DD before LOI or pre-sale vendor DD.

Preis

599 EUR / month

See pricing
Enterprise plan

Multi-entity portfolio

Define group frameworks once, instantiate n times. Aggregated dashboard for LP reporting. SSO/SAML, dedicated success manager, SLA.

Preis

custom

Request demo