What We See From the Certification Table
Less than 25% of submitted assets pass the CIFSO v4.0 certification threshold. Here is what the top 5 refusal reasons tell us about the state of European tech.
Less than 25% of submitted assets pass the CIFSO certification threshold. Here is what the top 5 refusal reasons tell us about the state of European tech.
The most common refusal reason is F-11a: ARR declared without Stripe or billing access. This affects 34% of submitted assets. Sellers declare revenue figures that they cannot substantiate with billing system access. Buyers walk away. This is the most preventable reason for a deal to fail.
I-21 — software rights not formally assigned to the entity — affects 28% of submissions. Founders build products on personal GitHub accounts, use contractor code without IP assignment clauses, or never formalised the transfer of software rights to the company entity. This is a clean kill for any strategic acquirer.
F-42 — founder dependency exceeding 60% of revenue — affects 24% of submissions. The asset is operationally viable, but the founder is the product. Search funds will not touch it. PE will only consider it with a long earnout and a transition plan. The discount is significant.
S-16 — no pentest in the past 18 months — affects 19% of submissions. Security posture is increasingly a first-filter for institutional buyers, particularly in regulated sectors. The absence of a pentest is not just a technical concern. It is a signal about management hygiene.
I-27 — no legal basis for personal data transfer under GDPR — affects 17% of submissions. Data controllers that have not established a legal basis for cross-border data flows face acquisition blockers in due diligence. This is particularly common in SaaS companies with US buyers.
