Due Diligence Data Room Checklist for M&A Sellers (2026)
Key Takeaways
- •In the processes we have run, a buyer's request list runs past 170 line items across ten categories. The checklist is not the hard part. Answering every line with a document, a version, or a stated reason is.
- •Give every request-list line an owner and one of four statuses: have it, have a version, cannot locate, does not exist. That gap register is a deliverable, not an embarrassment.
- •A room that flags its own gaps closes faster than one that buries them, because the buyer finds every gap anyway and finds it later, when the price is already agreed.
- •Stage 1 opens to every bidder and carries top-level corporate and financial material. Stage 2 opens after round one and carries customer contracts, detailed financials, and IP.
- •Three things never go in: privileged material, customer-level pricing before exclusivity, and unredacted personnel files. There is no undo once a guest has read a page.
A due diligence data room checklist is a buyer's request list turned into a filing plan. The request list is the easy half: ten categories, essentially the same on every mid-market deal. The hard half, and the reason deals stall in week ten, is the seller's answer to each line, because a real company never has every item sitting in a folder.
Every number in this article is our own rule of thumb from processes we have run rather than a published survey, and the ranges are wide on purpose. On our count a full request list runs past 170 line items, and a mid-market room ends up holding somewhere between five thousand and fifty thousand pages against them.
Two buy-side checklists on this site already list what a buyer asks for: the complete M&A due diligence checklist and its companion request list. This article does not duplicate them. It is the seller's side of the same document: how to organize the room around that list, how to run the gap register while you do it, what gets staged to which bidder, and what never goes in the room at all.
What will the buyer actually request?
Ten categories cover the request lists you will see. A fourteen category variant circulates, but it splits the same material rather than adding new material. Here is the map, with the line that stalls most often in each category.
| Category | Core requests | Where sellers stall |
|---|---|---|
| Corporate and governance | Charter, bylaws, minute books, stock ledger, board and stockholder consents, subsidiary records | Consents for past equity issuances that were never papered |
| Financial | Audited and management financials, monthly reporting pack, budget, working capital detail, debt schedule | Reconciling management numbers to the audited set |
| Tax | Federal, state, and local returns, nexus analysis, sales tax filings, audit correspondence | State nexus in jurisdictions nobody registered in |
| Legal and contracts | Material agreements, leases, licenses, litigation, settlements, insurance | Amendments and side letters filed apart from the base agreement |
| Customers and revenue | Top customer contracts, cohort and churn data, pipeline, backlog | Change of control and assignment consent provisions |
| HR and benefits | Census, offer letters, equity grants, benefit plans, contractor agreements, handbooks | Contractor classification and unpapered contractor IP |
| IP and technology | Registrations, assignments, open source inventory, escrow, architecture | Missing invention assignments from founders and early hires |
| Security and privacy | Policies, audit reports, breach history, DPAs, subprocessor list | Privacy commitments made in sales cycles and never tracked |
| Operations and real estate | Leases, key vendors, supply agreements, capex | Auto-renewing vendor contracts nobody has read since signing |
| Regulatory | Licenses, permits, compliance filings, correspondence | Permits held in a subsidiary name after a reorganization |
The page count is not a quality signal, and this is the one place we would argue with a buyer. A small room with a clean index does more for the associate on the other side than a large one without, because the associate's job is to find what they were sent to find and a dump makes that harder rather than easier.
How long does preparation take, and what does it consist of?
On our own experience, budget four to six weeks before the room opens, then eight to sixteen weeks of live diligence on a mid-market process. The preparation weeks are not upload weeks. They are:
- Pull the request list first. Start from the buyer's standard list, not from your own file structure. If you do not have one yet, our guide to building a due diligence checklist covers how to construct one from scratch, and the complete M&A due diligence checklist is the buy-side view of the same document.
- Assign an owner per category. Finance owns financial and tax, the general counsel or outside counsel owns legal and corporate, the head of people owns HR, engineering owns IP and technology. One name per category, not a committee.
- Run the inventory before the cleanup. Locate what exists before deciding what to fix. Sellers routinely spend a week fixing a problem that a signed original in someone's email would have closed in an hour.
- Clear the disclosure questions early. Privilege, personal data, and competitively sensitive customer economics all need a decision before anything goes in a folder, not after.
- Build the index. Every folder and document gets a stable number, and the numbering becomes the shared vocabulary for the rest of the deal. How to organize a data room covers structure and naming; how to set up a data room covers the mechanics of getting live.
The teams that skip preparation do not save the work. They move it to week ten, under a signed letter of intent, with a buyer watching every day of slip.
How do you run the gap register?
This is the part almost nobody writes about, and it is the difference between a room that closes and a room that grinds.
Give every request-list line an owner, a due date, and exactly one of four statuses:
- Have it. The document exists, it is signed, and it is filed against the right line item.
- Have a version. An unsigned draft, an unexecuted amendment, or a document you believe is superseded. It goes in the room with a note saying which it is.
- Cannot locate. It existed. Nobody can find it. Someone owns the search, and the search has a deadline.
- Does not exist. It was never created. This is an answer, not a failure.
The rule that matters: a stated absence with a reason is a diligence answer, and silence on the same line is a red flag. Buyers find every gap. The only variable is whether they find it in week one, when it is a data point, or in week ten, when it is a price adjustment, an indemnity, or a closing condition.
So treat the gap register as a deliverable your own team reads weekly. Sort it by whether closing the gap requires a third party to act. A missing invention assignment needs a former employee to sign. A change of control consent needs a customer's legal team to respond. Those two lines set your critical path, and they are the reason a deal signs in March and closes in June.
How do you map the room to the buyer's request list?
Buyers do not read your folder structure. They read their own list and check items off. The seller's job is to make that check trivial.
- Number everything. Every folder and document carries a stable index number, and your responses cite the number rather than a filename. A filename changes; an index number should not.
- Answer at the line item, not the folder. When the buyer asks for line 4.12, the response names documents 4.12.1 through 4.12.4, not the folder they live in.
- Keep the response log in one place. Every request list has a response column. Buyers reconcile against it, and a stale column costs you a call.
- File amendments with their parents. An amendment that sits three folders from the agreement it modifies produces a question, then a follow-up, then a suspicion that the chain is incomplete.
- Answer the questions you know are coming. If the top ten customer agreements have a consent provision, put that fact in the response rather than waiting for the buyer's associate to find it in six of them and ask about the other four.
Most virtual data rooms run a formal Q&A module for this exchange, where buyer questions are routed to the right seller-side expert, answered, and logged with a timestamp. If your process is running through a banker, that module is how the whole conversation gets tracked, and it is worth confirming who on your side has the authority to release an answer before the first question lands.
What is Stage 1 versus Stage 2 disclosure?
Staged disclosure is standard on any process with more than one bidder, and it is the single most common gap in checklist articles.
Stage 1 opens to every party that signs an NDA. It carries the confidential information memorandum, financial highlights, top-level corporate structure, an anonymized customer picture (contract values without customer names), and a product overview. Enough to price an indication of interest, not enough to reconstruct your business.
Stage 2 opens to the shortlist after indications of interest arrive. It carries detailed financials, named customer contracts with their economics, IP assignments and registrations, the employee census with compensation, security audit reports, and litigation detail.
The split protects competitively sensitive material from bidders who will never sign, and some of those bidders are competitors doing a fully legitimate look. Enforce it with scoped access rather than by keeping Stage 2 documents out of the room. Prepare everything, then open folders as the process advances. A folder you have to build under time pressure in week nine is a folder with errors in it.
One practical note: exclusivity changes the calculus. Customer-level pricing that stays closed to five bidders can open to one signed exclusive buyer, and that trade is usually worth making, because the alternative is a diligence condition that follows you to closing.
What should never go in the room at all?
Three categories, and the discipline here is absolute because there is no undo. Revoking a link stops future access. It does not retrieve the page a guest already read.
Privileged material. Counsel memoranda analyzing the exact risks the buyer is diligencing are the most tempting and most dangerous documents in the building. Disclosure to a third party can waive privilege over the subject matter. Litigation assessments, internal investigations, and tax opinions go through counsel before anyone considers uploading them.
Competitively sensitive customer economics before exclusivity. Customer-level pricing, discount schedules, and churn by named account handed to a bidder who is also a competitor is an antitrust and commercial risk regardless of the NDA. Aggregate it in Stage 1, name names in Stage 2, and take advice on the clean team arrangement if a direct competitor is bidding.
Unredacted personnel files. Performance reviews, medical and leave records, immigration files, and disciplinary history. Employee data carries privacy obligations that the sale process does not suspend. Buyers get a census with the fields they need, not the file.
Two more that belong on the same list: anything under a third-party confidentiality obligation that prohibits disclosure in a sale process, and any document you cannot authenticate. An unsigned agreement presented as executed is worse than an acknowledged gap.
The checklist, condensed
Print this one. It is the sell-side sequence, not the buyer's list.
- Obtain the buyer's request list, or a standard one, before you touch a folder.
- Assign one owner per category, with a name and a date.
- Inventory what exists before fixing anything.
- Mark every line: have it, have a version, cannot locate, does not exist.
- Sort the gaps by whether a third party must act. Start those first.
- Clear privilege, privacy, and competitive sensitivity questions before uploading.
- Split Stage 1 from Stage 2 and scope access by folder rather than by omission.
- Number every folder and document, and cite numbers in every response.
- File amendments, exhibits, and side letters with the agreement they modify.
- Publish the gap register internally and review it weekly against the critical path.
- Track who opened what, and follow up on the bidder who never opened anything.
- Keep an export of the full room and its index for the closing binder.
Which parts of this can the room do for you?
Disclosure: we build a data room, and the sequence above is the workflow it was built around. Two steps in that sequence are the ones a room can genuinely take off your desk, and the rest is judgment that stays with counsel.
The gap register is the first. Each Mage room carries a readiness checklist of what an acquirer's counsel expects to find, each item marked present, partial, missing, or not applicable, scored against the room's actual inventory rather than a static template. Curation you do by hand survives every recompute, which is the property that decides whether a register stays trustworthy for sixteen weeks or gets abandoned in week three. Amendments, exhibits, and side letters are linked to the agreement they modify, so an amendment filed three folders away stops reading as a missing item when it is really a misfiled one.
Staged disclosure is the second. Sharing is per recipient, so Stage 1 and Stage 2 are two scopes on one room rather than two rooms: each invite carries its own scope, view only by default, printing gated separately from download, an NDA gate on by default that can produce a countersigned PDF, plus expiry and instant revocation. That is the mechanic the staging section above asks for, and it is the reason you can prepare everything up front and still open folders as the process advances. Every folder and filed document also takes a stable dotted index number exportable to XLSX, which is the numbering your responses are supposed to cite.
Two things the room does not do. There is no redaction, so anything requiring redaction gets handled before upload. And Ask Mage, the room's assistant, answers from the room's documents for members only, which means it is not the buyer-facing Q&A module described above; guests never see it.
The Mage Data Room is free for a limited time. The product page is Mage Data Room, the rest of our writing on rooms sits in the data rooms topic hub, and the two posts that pick up where this one ends are how to identify material contracts in a data room and the data room to diligence workflow. The checklist produces the room. The room still has to produce findings.
Frequently Asked Questions
What documents go in a due diligence data room?
Ten categories cover almost every request list: corporate and governance, financial, tax, legal and contracts, customers and revenue, HR and benefits, IP and technology, security and privacy, operations and real estate, and regulatory. In the processes we have run, a full buyer request list expands those into more than 170 individual line items, though that is our own count rather than a published standard. The categories are stable across deals; the depth inside each one scales with the target's size and the buyer's risk appetite.
How long does it take to prepare a sell-side data room?
Plan four to six weeks of preparation before the room opens, then eight to sixteen weeks of live diligence for a typical mid-market process. The preparation is not uploading. It is locating signed originals, chasing missing amendments and consents, deciding what is staged and what is held, and clearing anything that should not be disclosed. Teams that skip preparation spend the same hours later, under a signed letter of intent, with the buyer watching.
What is Stage 1 versus Stage 2 disclosure in M&A?
Stage 1 is what every bidder sees in round one: the confidential information memorandum, financial highlights, top-level corporate records, and an anonymized customer picture. Stage 2 opens to the shortlist after indications of interest, and carries detailed financials, named customer contracts, IP assignments, and employee-level compensation. The split protects competitively sensitive material from bidders who will never sign, and it is enforced with folder-scoped access rather than by holding documents back from the room entirely.
What should never go in a data room?
Privileged legal advice, including counsel memoranda on the very risks the buyer is diligencing, because disclosure to a third party can waive the privilege. Customer-level pricing and contract economics before exclusivity, particularly when a bidder is a competitor. Unredacted personnel files and any personal data your privacy obligations do not permit you to disclose. Once a guest has opened a page, revocation stops future access, not the copy already read.
How do you handle a document the buyer asks for that does not exist?
Say so on the line item, in writing, at the moment it comes up. A stated absence with a reason is a diligence answer. Silence on the same line reads as evasion and becomes a closing condition, an indemnity, or a price adjustment. The pattern that costs sellers real money is a gap discovered by the buyer in week ten that the seller knew about in week one.
Which missing items most often delay a closing?
Change of control and assignment consents on material customer contracts, missing IP assignment agreements from early employees and contractors, board and stockholder approvals for past equity issuances, and unsigned or unlocatable amendments to agreements that are otherwise clean. Each one requires a third party to act, so the delay is measured in that third party's response time, not yours. All four are findable in week one if someone is looking.
Ready to transform your diligence?
See how Mage can help your legal team work faster and more accurately.
Contact UsRelated Articles
7 Best Intralinks Alternatives for 2026
Intralinks alternatives for banks, lenders and mid-market deals: who owns each vendor now, how each one prices, and when no real substitute exists.
Investor Data Room Checklist: Exactly What to Include for Seed Through Series B
What belongs in a fundraising data room at seed, Series A and Series B, what to leave out, and the paperwork failures that stall rounds at diligence.
The Data Room CLI: A Live, Permissioned Data Room from Your Terminal
Two commands turn a local folder tree into a live, permissioned data room. The full command reference, the scoped-key auth model, and the honest limits.