Crescent Capital Advisors

The technology diligence method, published in full.

PRISM™ is how we score technology inside a transaction. This page is the method itself: the five dimensions and what each one asks, how a score is read, how a finding is turned into a deal action, and what a report will and will not claim. Everything here is what we run on a live engagement, so you can test the method against your own asset before you speak to anyone.

A score you cannot inspect is not evidence.

Technology diligence is usually sold as a scored assessment. The sponsor receives a number, a color, and a list of observations, and is asked to accept that something consistent produced them. The method behind the number is held back as proprietary, which leaves the one part a buyer could actually test on the other side of the wall.

Ours is on this page. The five dimensions below are the five we score on every engagement, the bands are the bands we report against, and the four classifications are the only places a material finding is allowed to land. Anyone who wants to argue with the method now has enough of it to argue with, including a competing provider. We would rather be judged on the work than protected by an unpublished rule.

Publishing the method does not make the read mechanical. The questions are fixed and the thesis they are asked against is not. A platform that is sound under a hold-and-optimize case can be a liability under a buy-and-build case, and the same evidence produces a different score in each.

Five questions the deal actually turns on.

Each dimension is a business question first and a technical one second. The role is what a weak score in that dimension does to the transaction, which is why the five are not interchangeable and are not averaged as though they were.

P

Portfolio Fit

Gate

Can the technology support the investment thesis?

A strong read
Technology is tied to the thesis with a named owner, and the headroom the plan assumes is headroom the team has already shown. The deal can be underwritten as written.
A weak read
Nobody owns the technology roadmap against the thesis. The model assumes capability the platform has not demonstrated.
R

Risk Quantification

Price

What technology risks create financial exposure?

A strong read
Material risks are documented and, where they matter, priced. Few surprises should surface after close.
A weak read
Risk is anecdotal and unquantified. Security, compliance, or key-person exposure can reset terms that were agreed without it.
I

Infrastructure & Engineering

Foundation

Can the platform scale with the plan?

A strong read
The platform ships safely and scales without a rebuild. Infrastructure is a foundation rather than a ceiling on growth.
A weak read
Delivery is manual and the architecture caps growth. Reaching the model's volume means CapEx and a rebuild, not tuning.
S

Strategic Data Assets

Upside

Can the data create value?

A strong read
Data is trustworthy and is being turned into value, with AI past the pilot stage. Real upside sits in this dimension.
A weak read
Data is unreliable or unused and AI is ungoverned. The upside case rests on foundations that are not there yet.
M

Management & Execution

Multiplier

Can this team deliver the thesis?

A strong read
The team ships on a predictable cadence and the technology leader can carry the value story to a board.
A weak read
Delivery is ad hoc and leadership cannot yet own the value story. Execution risk then sits on top of every other finding.

Why I and S are scored apart

I and S are asked about different money. A failing I score is CapEx: servers to buy, engineers to hire, systems to rebuild. A strong S score is enterprise value waiting to be captured through data and AI. They also call for different operators, so collapsing them into one technology dimension hides both the bill and the upside.

Every dimension is scored 0 to 100.

One scale across all five dimensions, and one composite over them, weighted to the thesis. The composite places the asset in a band, and the band is a read on what the technology means for the deal rather than a grade on the engineering team.

80–100Technology StrengthAn asset. The work after close is value creation, not remediation.
60–79Technology ReadySound foundation. Targeted remediation supports the thesis.
40–59Technology RiskPriced remediation required. The 100-day plan is critical.
20–39Technology LiabilityMaterial exposure that changes the offer, the terms, or both.
0–19Technology Deal RiskA thesis-level problem. The question becomes whether to proceed.

Where red, amber and green come from

The color on a dimension is derived from the same 0-100 score rather than kept as a second scale: green from 60, amber from 40 to 59, red below 40. One number underneath, one presentation on top, which is what lets two engagements be compared at all.

The weighting is agreed before the work starts.

The five dimensions are fixed. What each one is worth in the composite is not, and it is set at scoping with the deal team in the first days of the engagement, before any evidence is collected.

Deal type moves it first. A buy-and-build weights integration architecture and whether the data model survives merging. A carve-out weights separation cost, standalone running cost, and how long the transition services agreement really runs. A take-private weights the cost structure and what breaks under cost pressure. Growth equity weights whether the moat is real and whether unit economics hold at scale. One weighting applied across all four would flatter some deals and mislead others.

Hold strategy moves it again. The same platform is weighted differently when the plan is to grow it organically over five years than when the plan is to bolt six businesses onto it inside eighteen months, because the questions that decide those two plans are not the same questions.

The weighting is written down and discussed with the client rather than applied quietly underneath a composite. A sponsor who disagrees with an emphasis can say so at the start, when changing it costs nothing, instead of finding at the readout that the number rested on a judgment they would not have made.

This page publishes no weight table, because the report template carries none either. A fixed set of percentages would be right for one deal shape and wrong for the rest, and publishing it would make the composite look more objective than a weighted score can be. What is fixed is the rest of the method: the same five dimensions, the same 0 to 100 scale, the same five bands, and a weighting stated in writing at the start of every engagement.

Weighting cannot rescue a gate. A high composite carrying one unresolved GATE finding is still a deal that does not close on the terms agreed, which is why the classification a finding receives decides more than the arithmetic does.

Three dimensions are built from four components each.

All five dimensions are scored on the same 0 to 100 scale. Three of them are built from four named components rather than one judgment: R across four areas of exposure, I across four engineering sub-dimensions, and S across four gates. P and M are scored as a single read against the dimension question, because the evidence there does not divide into stable parts. Each of those two carries a named artifact into the report instead, so there is still something specific for a deal team to argue with.

P

Thesis Assumptions Tested

One read, stated assumption by assumption

  • Whether the business can operate standalone, and what standalone costs
  • Whether the margin and growth plan is achievable on the stack as it stands
  • Whether certifications and customer contracts transfer cleanly
  • Whether the plan can be executed in-house or assumes capability that has to be hired
  • Whether the upside in the model is underwritable in the base case

Every assumption the thesis depends on is written out and given a verdict against the evidence: supported, partly supported, not supported, or dependent on how the deal is structured. Anything short of supported carries into the Financial Exposure Summary instead of staying a caveat in the narrative.

R

Risk Exposure Score

0 to 100 across four areas of exposure

  • Security posture and what is still open from the last independent test
  • Intellectual property ownership and open-source licensing
  • Compliance and regulatory exposure
  • Business continuity, and whether recovery has been tested rather than documented

This is where GATE and PRICE findings concentrate, so each area is carried to a cost rather than a rating: what closing the gap takes, over what period, and whether it moves price, escrow, or an indemnity.

I

Engineering Health Score

0 to 100 across four sub-dimensions

  • Architecture & Scalability
  • Cloud/Infrastructure & COGS Reality
  • SDLC & Engineering Practice
  • Technical Debt

The Tech Debt Cost Calculator prices the Technical Debt sub-dimension on its own, returning an annual cost and a five-year cost of inaction.

S

AI Readiness Index

0 to 100 across four gates

  • Data Trust
  • Model & Agent Governance
  • Operational Integration
  • Value Realization

The four gates are a diligence-grade summary of the Enterprise AI Control Plane's pillars, so a target that has been through this read carries the same vocabulary into the hold period.

M

Key-Person Risk Register

One read, with the register and a feasibility test behind it

  • Leadership depth, and the bench behind the technology leader
  • Key-person concentration: who holds knowledge nobody else holds
  • Delivery record: what was committed against what shipped
  • Hiring and ramp capacity at the rate the plan assumes
  • Engineering attrition, particularly senior and tenured
  • Reliance on contractors and offshore capacity, and the continuity that carries

The register names the people the plan depends on and prices that exposure where it moves terms, through retention or escrow. The 100-day plan is then tested against what the organization can absorb, which is a different question from whether the plan is sensible.

Four classifications, and every finding lands in one.

An observation with no classification is a note, and notes do not change deals. Every material finding carries a bucket, a remediation window, and a confidence level, so it reaches the deal team as a decision with an owner attached.

GATE

Stops the deal until it is resolved or contractually protected before close.

Validated interim controls, a funded remediation plan, an accountable owner, and the escrow or holdback that protects the buyer until the work is done.

PRICE

Changes the offer rather than the plan.

A costed remediation, the mechanism it travels through (purchase price, escrow, or indemnity), and the evidence the number rests on.

THESIS

Changes what the deal is supposed to achieve, and by when.

The part of the underwritten plan that is affected, and what has to be true, in what order, for that plan to hold.

LEVER

Quantified upside that becomes part of the 100-day plan.

The value modeled and the validation step that clears first. Upside is earned before it is underwritten, so it stays out of the base case until a pilot proves it.

Every number carries a confidence level.

Confidence describes how a number was derived, not how serious the finding is. It is what separates a figure a sponsor can put into an offer from a figure that needs a named validation step first.

High confidence

Grounded in direct invoices, current vendor pricing, unit counts, contractual terms, or operating data management has validated.

Medium confidence

Usable for initial underwriting, with the report naming the specific validation step required before the figure moves final price, escrow, or the capital plan.

Low confidence

A directional scenario, flagged as one, that should not sit in base underwriting.

What the report says it did not do

Every report states what was reviewed, what was not independently validated, and which specialist workstreams sit outside a technology scope (environmental and legal, asset-condition engineering, commercial diligence, and financial-statement diligence). The confirmatory work that belongs to someone else stays visible instead of being implied.

Six outputs, and one of them runs after close.

The report is the artifact, and these are the pieces a deal team and an operating team actually use from it.

PRISM Score

A 0-100 composite over the five dimensions, weighted to the thesis and reported with the band it falls in.

Engineering Health Score

The I dimension, 0 to 100 across its four sub-dimensions.

AI Readiness Index

The S dimension, 0 to 100 across its four gates.

Financial Exposure Summary

CapEx requirement, EBITDA drag, and the three-year cost of inaction.

100-Day Plan input

Remediation priorities and the quick wins, sequenced for the first hundred days.

CLEAR™ handoff

The diligence file becomes the post-close operating playbook rather than a binder filed after signing.

Three to four weeks, and the readout is the point.

A PRISM review is document review, interviews, a written deliverable, and a readout with the people who have to act on it. The deliverable is board-ready: two to three pages of executive summary plus a 100-day technology roadmap the operating team can start on day one.

  1. 01

    Document review

    Architecture, roadmap, incident history, contracts, security posture, spend, and whatever the data room already holds.

  2. 02

    Stakeholder interviews

    CEO, CTO or VP Engineering, CISO, product lead, and one or two key engineers. The engineers are where the architecture diagram and the running system stop matching.

  3. 03

    Written deliverable

    Findings classified, priced, dated, and carrying a confidence level, consolidated into one register.

  4. 04

    Readout

    A working session with the deal team and, where it helps, management. Questions get answered live rather than in a follow-up memo.

What a review covers

Diligence becomes the operating playbook.

PRISM is how we see the asset. CLEAR™ is how we operate it. Each dimension has a phase it hands into, so the numbers underwritten before close are the numbers measured against during the hold.

PRISM dimensionCLEAR™ phaseWhat carries over
P: Portfolio FitClarifyThesis alignment confirmed
R: Risk QuantificationRealizePriced risk converted to verified exit value
I: Infrastructure & EngineeringLeverage + ExecutePlatform scaled
S: Strategic Data AssetsAccelerateAI deployed, data monetized
M: Management & ExecutionExecuteTeam deployed, 100-day plan runs

Three other ways to check the work.

The framework entry

PRISM in the method library, alongside the other frameworks the practice runs on.

The deliverable

What a report reads like: the fifteen sections, a worked finding in each classification, and the evidence discipline applied.

The self-assessment

The same five dimensions scored on your own asset in about ten minutes, returning one of the five bands.

Before you ask.

Does publishing the method let someone else run it?
They can run the questions. The questions are the cheap part. What decides whether a read is worth anything is the judgment applied to the answers: knowing which finding moves price and which one is noise, what a remediation actually costs, and what a management team can carry alongside its day job. That comes from having run the systems, not from having the list.
If the method is fixed, is the read just a checklist?
The dimensions are fixed and the weighting is not. The same evidence scores differently under a buy-and-build thesis than under a hold-and-optimize one, because the question is always what this technology does to this deal. A checklist ends in a color. This ends in a classification, a window, and a number someone can put in an offer.
How is this different from a code review or a large-firm technology diligence?
A code review tells you the code is messy. A thorough process read gives you a long list of observations. Neither tells you what a finding does to the deal. PRISM classifies every finding as GATE, PRICE, THESIS, or LEVER and ties it to price, terms, or the 100-day plan, and it is written by an operator who has carried the P&L for a sponsor who has to make an offer.
How long does a live engagement take?
A full review runs three to four weeks. Inside a live process, core diligence is typically seven to ten business days after a substantially complete data room and timely access to management. Multi-site coverage, passive OT asset discovery, specialist certification review, and detailed value-creation modeling are scoped to the thesis, the structure, and the timeline.
Can I score my own company before talking to anyone?
Yes. The PRISM Technology Readiness Scorecard runs the same five dimensions in about ten minutes and returns the same five bands. It is a directional read rather than a diligence report, which is the difference between knowing where to look and knowing what it costs.
What sits outside the scope?
Environmental and legal, asset-condition engineering, commercial diligence, and financial-statement diligence. Each report names them so a sponsor can see which confirmatory work still belongs to another provider, and who owns it.

Bring us a deal and we will run this against it.

Tell us the situation in a few lines: the asset, the thesis, and the date the offer has to be defensible by. If a PRISM read fits, you have already read the method it will be run to. Sujit reads every note.