Our Expert in Italy
No results available
M&A due diligence Italy is entering a decisive new phase in 2026, and sellers who treat readiness as an afterthought will pay for it in price chips, delays and failed deals. The turning point is regulatory: NIS2 is now operational across Italian essential and important entities following the Italian transposition, and DORA’s digital resilience regime is spilling into any target that supplies the financial sector. Buyers increasingly demand evidence of cybersecurity posture, data governance and clean corporate records as standard sell‑side deliverables, not optional extras.
This practical guide sets out a step‑by‑step sell‑side playbook for owners, CFOs, corporate secretaries and corporate advisory teams preparing an Italian company for sale, with a realistic timeline, a required‑documents table, cost ranges and the new 2026 compliance checks you must anticipate.
The gap between seller and buyer expectations is where value leaks. A buyer’s team arrives assuming problems until the record proves otherwise; a well‑prepared seller reverses that presumption. Sell‑side due diligence Italy is the discipline of assembling, cleaning and stress‑testing your own records before a buyer’s advisers ever open the data room, so that questions are anticipated and answered rather than discovered.
Three forces make readiness sharper in 2026. First, cyber and digital resilience: with the NIS2 Directive (Directive (EU) 2022/2555) transposed into Italian law by Legislative Decree No. 138/2024 and DORA (Regulation (EU) 2022/2554) reshaping expectations across financial supply chains, buyers routinely request incident logs, risk assessments and supplier mapping. Second, data protection: the Garante per la Protezione dei Dati Personali expects lawful, documented processing even inside a data room, consistent with the GDPR (Regulation (EU) 2016/679) and the Italian Privacy Code. Third, antitrust: transactions crossing thresholds must reckon with the AGCM.
A quick readiness scorecard, rating your company red, amber or green across corporate, financial, tax, contracts, IP, IT, HR and regulatory domains, is the fastest way to see where remediation is needed before you go to market.
Strong M&A readiness Italy is not about presenting a flawless company. It is about knowing your weaknesses first, quantifying them, and controlling the narrative around them.
Not every disposal warrants the full sell‑side exercise, but most meaningful transactions do. The exercise scales with deal ambition and buyer sophistication.
Some sectors attract intensified scrutiny regardless of deal size. Financial services and fintech targets face DORA‑driven resilience testing. Healthcare and life sciences face licensing, patient‑data and regulatory‑file review. Operators within the NIS2 perimeter, including energy, transport, digital infrastructure, ICT service management and public administration suppliers, must produce cyber governance evidence as a matter of course. Certain transactions in strategic sectors may also trigger the Italian foreign‑investment screening (“Golden Power”) regime, which sellers and buyers should assess early. If your company touches any of these, plan for a longer, deeper preparation phase.
The following ten steps form a repeatable HowTo for preparing an Italian company for sale. Each identifies the typical role responsible so that accountability is clear from kick‑off.
The table below summarises who typically owns each step and how long it takes. Many steps run in parallel; the critical path is usually financial and tax preparation.
| Step | Who (typical owner) | Typical duration |
|---|---|---|
| 1. Project kick‑off & sell‑side plan | Seller (CEO/CFO) + lead advisor (commercialista) | 1 week |
| 2. Data mapping & initial internal review | Internal legal & finance + advisor | 2–4 weeks |
| 3. Corporate & statutory cleanup | Company secretary / corporate counsel + advisor | 1–3 weeks (parallel) |
| 4. Financial clean‑up & tax pre‑checks | CFO + external tax advisor / commercialista | 2–6 weeks |
| 5. Contracts & commercial diligence | Commercial counsel + deal advisor | 2–4 weeks |
| 6. IT/cyber assessment (incl. NIS2 evidence) | IT manager + cyber consultant | 2–4 weeks |
| 7. HR review & labour exposure | HR lead + employment advisor | 1–3 weeks |
| 8. Public filings & certificates (visura, p.iva checks) | Company admin + chamber of commerce | 1 week |
| 9. Data room population & QA | Deal team + virtual data room manager | 1–2 weeks |
| 10. Q&A & confirmatory prep | Seller + advisors | 4–8 weeks (agile) |
Understanding what a buyer will look for helps you present the same material persuasively. The comparison below aligns each domain’s sell‑side deliverable with the corresponding buyer concern.
| Area | Sell‑side focus (what sellers must show) | Buy‑side focus (what buyers check) |
|---|---|---|
| Financial | Clean historical accounts, reconciliation, tax disclosures, working capital bridge | Quality of earnings, forecasts, off‑balance items, forensic adjustments |
| Corporate & governance | Valid corporate minutes, authorisations, share capital, shareholder agreements | Title, restrictions, contingent liabilities, change‑of‑control clauses |
| Contracts | Key commercial contracts, assignment/consent rights, termination triggers | Change of control, pricing, exclusivity, termination exposure |
| IT & Cyber | Inventory of systems, incident logs, third‑party SLAs, NIS2 evidence | Penetration test results, vulnerability remediation, supplier security |
| HR & Benefits | Employee contracts, collective bargaining, severance liabilities | Key person risk, union exposure, pensions |
| Regulatory & licences | Permits, sectoral licences, regulatory correspondence | Pending investigations, licence transferability |
| IP | Ownership chain, licences, open source review | Freedom to operate, encumbrances, litigation |
The due diligence checklist Italy below sets out the categories buyers expect. Documents should be legible, dated, and where public, corroborated by certified extracts. Certified company extracts (visura camerale) and other public filings are obtained through the Registro Imprese, accessible via the Chambers of Commerce system and Infocamere; tax certificates and filings originate with the Agenzia delle Entrate. For cross‑border buyers, budget for certified translations of the most material items.
| Category | Typical documents required | Notes / source |
|---|---|---|
| Corporate & statutory | Articles of association, shareholder register, list of directors, corporate minutes, powers of attorney | Obtain visura camerale (Registro Imprese / Infocamere) for certified extracts |
| Financial | Last 3–5 years financial statements (audited where applicable), management accounts, tax returns, bank statements | Include reconciliations and any external audit reports |
| Tax | VAT filings, tax assessments, rulings, deferred tax schedules, transfer pricing docs | Agenzia delle Entrate certificates and correspondence |
| Contracts & commercial | Customer/supplier contracts, lease agreements, distribution/agency agreements | Highlight change‑of‑control clauses |
| Employment & benefits | Employment contracts, collective bargaining agreements, pension obligations, payroll records | Include social security filings and any disputes |
| Intellectual property | Registrations (patents, trademarks), assignment agreements, licences, development agreements | Chain of title documents, filings |
| IT & cybersecurity | IT inventory, incident log, penetration test reports, ISO/IEC certifications, supplier SLAs | NIS2 relevant evidence: risk assessments, incident response plan |
| Regulatory & licences | Sector licences, permits, regulatory correspondence, compliance certificates | CONSOB/sector regulator docs where applicable |
| Litigation & disputes | Claims ledger, court pleadings, settlement agreements | Provide status and reserves |
| Environmental & real estate | Environmental permits, site assessments, property deeds, lease titles | For asset‑heavy targets |
| Insurance | Policies, claims history, directors’ & officers’ insurance | Including policy limits and exclusions |
| Miscellaneous | Customer lists (where permissible), marketing materials, cap table | Redact personal data as necessary for GDPR compliance |
A disorganised data room signals a disorganised company. Structure it before you populate it.
Owners consistently underestimate preparation time. A credible sell‑side programme runs in three phases. Preparation, steps 1 to 9 above, typically takes four to twelve weeks depending on company size, group complexity and the state of existing records. Once a live process opens, the main buyer Q&A period usually spans four to eight weeks, and confirmatory due diligence in the run‑up to signing adds a further two to four weeks. Cross‑border structures, regulatory filings and any AGCM notification extend these windows materially.
Gating milestones matter more than aggregate duration. Financial and tax clean‑up (weeks two to six) is almost always the critical path; corporate, HR and IT workstreams should run in parallel so they are complete before the data room opens. Treat the timeline table above as your master schedule and resist launching to market before the red items on your scorecard are resolved or clearly disclosed.
Preparation costs vary widely with size and complexity. The ranges below are indicative only and exclusive of VAT; foreign‑buyer transactions add translation, notarisation and, where thresholds are met, antitrust costs. Always obtain a specific engagement quotation, as fees depend heavily on deal structure and the state of the company’s records.
| Item | Typical cost range (EUR) | Notes |
|---|---|---|
| Lead advisor / commercialista (sell‑side advisory) | 8,000 – 40,000+ | Depends on company size, complexity; retainer + success fee possible |
| Financial advisor / valuation specialist | 5,000 – 50,000+ | Higher for PE or complex groups |
| Tax advisor / tax due diligence | 3,000 – 25,000 | Disclosures, pre‑clearance and opinions |
| IT/cyber audit & pen test | 3,000 – 30,000 | NIS2/DORA readiness assessments add cost |
| Virtual data room subscription | 500 – 5,000 | Depends on volume and duration |
| Legal counsel (contracts & corporate cleanup) | 4,000 – 40,000+ | May be higher for cross‑border and antitrust filings |
| Notarisation / translations / certified copies | 200 – 5,000 | Notarised documents or certified translations for cross‑border deals |
| Antitrust filing (AGCM) | Filing fees and legal costs as applicable | Merger‑filing fees are set by the AGCM under current rules; budget if deal triggers notification thresholds |
| External audits / forensic work | 5,000 – 60,000 | Forensic QA or historical adjustments |
| Miscellaneous (certificates, searches) | 200 – 2,000 | Visure camerali, certificates from Registro Imprese |
These costs are an investment in deal certainty. Sellers who skimp on IT/cyber assessment or tax pre‑checks routinely surrender multiples of the saving in later price reductions or escrow retentions.
The NIS2 Directive (Directive (EU) 2022/2555), transposed in Italy by Legislative Decree No. 138/2024 and supervised by the Agenzia per la Cybersicurezza Nazionale (ACN), strengthens cybersecurity risk‑management and incident‑reporting obligations for essential and important entities across a broad list of sectors. Entities within scope register with the ACN and become subject to phased obligations. In 2026, buyers evaluating in‑scope targets expect documented governance: a management‑approved risk assessment, an incident‑response plan, supplier security requirements and evidence of incident notification where applicable. For any company in the NIS2 perimeter, absence of this documentation is now treated as a material finding in M&A due diligence Italy.
The DORA Regulation (Regulation (EU) 2022/2554), which has applied since January 2025, imposes digital operational resilience requirements on financial entities and, crucially for sellers, on their ICT third‑party providers. If your company supplies software, hosting, payments or other ICT services to banks, insurers or investment firms, buyers will test whether you can meet DORA‑aligned contractual and resilience expectations. This spillover means a technology target with financial‑sector customers faces DORA scrutiny even though it is not itself a regulated financial entity.
To move from reading to action, owners and advisers should begin with these immediate steps:
Preparation is the single greatest lever a seller controls. In 2026, credible M&A due diligence Italy readiness, anchored in clean corporate records, resolved tax positions and defensible cyber governance under NIS2 and DORA, is what separates a smooth, full‑value exit from a discounted, delayed one. Start early, know your weaknesses before the buyer does, and present a company that answers questions rather than raising them. That is what makes M&A due diligence Italy work in the seller’s favour.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Filippo Lanteri at Studio Scarabosio Lanteri SRL STP, a member of the Global Law Experts network.
posted 24 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message