Evaluating Target Defensibility During Commercial Due Diligence

Evaluating Target Defensibility During Commercial Due Diligence

Image: Plausity

Key Takeaways

  • Treat every moat claim as a hypothesis: name the mechanism, then evidence it with documents, cohort data and customer behaviour or discount it in the valuation.
  • Retention must be segmented before it proves anything: median private B2B SaaS NRR was about 101% in 2024, with enterprise accounts above $100K ACV near 118% and SMB under $25K at 97%.
  • Test every moat claim against five factors: customer benefit, observable proof, barrier to imitation, duration, and transfer to the buyer after closing.
  • Access to customers and suppliers usually drives the diligence timetable, so primary research must be scoped at kickoff rather than mid-process.
  • Model explicit erosion cases such as a price cut to defend share or a two-point churn increase; a moat premium on the multiple plus superior forecasts double-counts the thesis.

What defensibility means in commercial due diligence

A target is defensible when its growth and returns rest on mechanisms that rivals cannot quickly copy, bypass or buy: contractual switching costs, proprietary data, regulatory approvals, distribution lock-ups, network effects or genuine brand equity. Management assertions about a strong moat are not evidence of any of these. In commercial due diligence, every defensibility claim should be treated as a hypothesis that the deal team must either corroborate with documents, data and customer evidence, or discount in the valuation.

Defensibility has moved to the centre of the CDD agenda because the ground beneath it is shifting. Software that customers can swap out cheaply is already repricing in the retention data: median net revenue retention for AI-native products sat near 48% in late 2025, with plans priced under $50 a month at about 32% against roughly 85% for plans above $250 a month. A product without switching costs can leak revenue inside a single renewal cycle while an embedded one holds. Underwriting AI disruption risk therefore belongs inside the commercial workstream: a buyer who accepts a replicable advantage as durable pays a premium multiple for returns a competitor can erode within one contract cycle.

Where defensibility sits in the CDD scope

Defensibility is not a standalone chapter bolted onto the report. It is the cross-cutting test that connects the established commercial due diligence workstreams, and it should be answered for each claim the management team and the investment thesis make:

  • Market structure and sizing: is the target's addressable market growing for reasons the target itself captures, or for reasons any competitor captures equally?
  • Customer economics: what does it actually cost a customer to leave, measured in contract terms, re-implementation effort and retrained workflows?
  • Competitive positioning: which rivals have tried to replicate the advantage, and what did it cost them in time and capital?
  • Plan critique: does the growth plan depend on the moat holding, and what happens to the model if it erodes faster than assumed?

A structured commercial due diligence checklist helps ensure these tests are asked consistently, but the analytical work is moat-specific: each type of advantage fails in a different way and demands different evidence. The sections that follow set out that framework, the evidence tests per moat, and the triangulation needed before a defensibility conclusion reaches the investment committee.

The moat framework: six sources of structural advantage

Every defensibility claim a management team makes should be mapped to one of six mechanisms: network effects, switching costs, proprietary data, distribution, brand, and regulatory or licensing barriers. The mapping matters because each mechanism protects a different economic outcome. Network effects and brand primarily defend volume and pricing power; switching costs defend retention and renewal pricing; proprietary data defends product quality and cost-to-serve; distribution defends customer acquisition cost; regulatory barriers defend market access itself. A claim that names no mechanism, or a moat that protects nothing measurable, is not a moat. It is a description of the target's current position, and it will not survive contact with a competitor's pricing decision.

Two common shortcuts fail here. A concentrated market is not a moat; concentration describes the competitive landscape, not the target's ability to hold its share when a credible entrant appears. A large customer base is likewise not a moat unless it generates a mechanism, such as data scale or reference effects, that a competitor cannot buy its way past. Size without a mechanism is simply a bigger target.

Regulators treat these same mechanisms with the seriousness CDD teams should. The DOJ and FTC's 2023 Merger Guidelines state that switching costs, scale economies and network effects can operate as barriers that entrench a dominant position, and that limiting rivals' access to scale or customers can entrench dominance over the long run. If antitrust authorities treat these forces as durable sources of market power, an investment committee should expect a diligence report to evidence them, not merely assert them.

Evidence tests for each moat claim

A moat claim becomes diligence-grade only when it is converted into a testable hypothesis. A useful standard asks five questions of every claimed advantage: what customer benefit does it deliver, what observable proof exists, what barrier does it raise against imitation, how long does that barrier hold, and does it transfer to the buyer post-close? A claim that survives all five is an asset; one that survives none is a narrative. Commercial due diligence is an objective enquiry that critiques and challenges the commercial logic behind a business plan on evidence the deal team develops itself, not a relay of management's view.

Rank evidence by how hard it is to fake

Not all evidence is equal. The strongest layer is realised customer behaviour: cohort retention curves, net revenue retention by vintage, realised price increases, gross margin stability, and customer acquisition cost with payback period. The second layer is competitive and contractual fact: lost-deal records, competitor responses to the target's pricing moves, exclusivity clauses, change-of-control terms, and the IP chain of title. The weakest layer is management narrative, however credible the leadership team. The working rule is that every moat conclusion needs at least two compatible evidence layers. Switching costs, for example, should be supported both by customer interviews and by renewal behaviour reconciled against migration effort and observed churn; if interviews say lock-in is high but renewal data shows customers leaving at will, the claim fails.

A document checklist per moat type

  • Network effects: cohort engagement and multi-homing data, marketplace fill-rate and match-quality reports, and contribution volumes by each side of the network.
  • Switching costs: master agreements showing term, notice and auto-renewal mechanics, implementation statements of work, integration inventories, and post-mortems on churned accounts.
  • Proprietary data: data-rights clauses in customer contracts, third-party licensing agreements, documentation of data lineage and volume, and model or analytics performance over time.
  • Distribution: reseller and partner agreements with exclusivity and change-of-control terms, revenue by partner, and customer acquisition cost by channel.
  • Brand: realised price and discount schedules, win-reason and loss-reason fields from the CRM, and trademark register extracts.
  • Regulatory: licences, certifications and approvals with expiry dates and transferability terms, plus correspondence with the relevant regulator.

Triangulate the layers before the finding reaches the investment committee. Where the target's systems make this hard to assemble, structured data room ingestion and cross-document analysis help extract the underlying contract terms, cohort data and win/loss records, while findings and risk intelligence surfaces claims that rest on a single evidence layer. The output is a moat map in which every conclusion carries its evidence, and every gap in that evidence is stated rather than smoothed over.

Customer interviews and triangulation

Interview programs are where moat hypotheses either survive or quietly die, and the sample design decides which outcome you get. Reference customers supplied by management are useful for tone and near-useless for evidence, because they were selected precisely because they are happy. A rigorous program selects its own sample from the customer list and deliberately over-weights the voices management did not offer: churned and declining accounts, lost prospects, channel partners, suppliers, and former employees who saw the pipeline from the inside. It should also reach beyond customers to competitors and channel partners, run off a structured guide, and use an interviewer the respondent has no reason to flatter. A distributor quietly building a competing line, or a churned account that left over reliability rather than price, is a finding no management-curated reference call will surface.

Design questions that test behaviour, not sentiment

Satisfaction scores confirm nothing about a moat. The questions that matter probe the behaviour the moat claim predicts: what would have to change for the customer to switch, what happened the last time the target raised prices, whether the renewal was a decision or a default, and which alternative the customer evaluated in the last procurement cycle. Useful prompts include:

  • Switching: walk me through the cost, effort and timeline of moving to the nearest alternative today.
  • Renewal intent: did you actively re-evaluate the market at your last renewal, and who else did you shortlist?
  • Price sensitivity: what increase would force a procurement review, and what discount did you actually negotiate?
  • Substitution: what internal or workaround solution could replace part of what the target sells?

Triangulate the answers against ordinary-course records rather than process material. Cohort retention, CRM win-loss data, support tickets and contract terms generated in the normal course of business carry more evidential weight than the data room assembled for the sale, and any gap between what customers say and what the records show is itself a finding. Expert calls with former operators and industry specialists help you interpret the deltas, not replace them. Structured voice-of-customer work of this kind is what separates a tested moat from a asserted one, and the voice of customer diligence discipline applies directly here.

Scope the primary research at kickoff, because the timetable rarely forgives a late start. On a typical engagement the interview program is the pacing item: recruiting and scheduling a full sample of customer conversations absorbs a large share of the fieldwork window before a single answer is analysed. Interview access is frequently the binding constraint, so agree the sample, the access mechanism and the fallback sequence with management in week one, not week four.

Unit-economics signals of defensibility

A moat that exists only in management's narrative eventually has to show up in the numbers. Unit economics are where a claimed advantage either compounds or quietly leaks, and the discipline is to read each metric as a test of a specific defensibility claim rather than as a standalone scorecard. Three families of signals do most of the work: retention read properly, pricing power evidenced in realised prices, and acquisition economics that show customers staying and deepening.

Retention read properly: NRR only means something next to GRR and by segment

Net revenue retention is the metric most often quoted and most often abused. The 2024 median for private B2B SaaS sat at about 101%, but that blended figure conceals enormous variance: enterprise accounts above $100K ACV hold near 118% median NRR while SMB accounts under $25K sit at 97%, so a single blended number can describe two completely different businesses. In diligence, always request the retention build-up segmented by contract value, cohort start date and pricing model, and reconcile it to the finance team's revenue schedule rather than accepting the customer success team's deck.

The pairing rule matters just as much as the segmentation. Gross revenue retention is the honest floor because it counts only losses and cannot exceed 100%, so a company can post a healthy 110% NRR while its GRR quietly erodes to 82%, masking heavy churn with a handful of large upsells. Strong NRR built on a weak GRR floor is fragile: it depends on continued expansion into a base that is eroding underneath it. Ask which customers are expanding and why. Expansion that is organic, spread across the base and driven by usage or seat growth supports a switching-cost or network-effect claim; expansion concentrated in a handful of accounts, or manufactured by list-price increases, does not.

Pricing power and acquisition economics

Pricing power is the cleanest observable of a real moat, and it lives in realised prices rather than list prices. Test the trend in realised price per unit or per seat, discounting depth and frequency by cohort, and gross margin by customer cohort over time. A defensible position shows stable or rising realised prices with flat or narrowing discounts; a commoditising one shows the opposite, often masked by volume growth. On the acquisition side, CAC payback and the share of new ARR that comes from expansion are the two signals that customers both stay and deepen. Rising expansion share of new ARR is direct evidence that the installed base values the product enough to grow into it, which is the behavioural version of a moat claim.

  • Request NRR and GRR together, segmented by ACV band and cohort, for at least three years
  • Tie every expansion dollar to a cause: seats, usage, modules or price increases
  • Track realised price, discount trends and gross margin by cohort, not blended
  • Test CAC payback and expansion share of new ARR against the moat claim being made

Separating durable advantage from cyclical tailwinds and red flags

Every growth number in a CDD is a blend of four components, and only some of them survive the holding period. Decompose historical revenue growth into market growth the target rode, share gains it earned, price increases it pushed through, and one-off effects such as a competitor's exit, a regulatory change or a single large contract. Market growth and one-offs are borrowed; share gain and repeatable pricing are owned. The test is persistence: did the target win share in years when the market was flat, and does pricing power show up in renewal cohorts rather than in new-business discounts? A target growing barely faster than its market has demonstrated momentum, not advantage, and underwriting the blend as if it were structural is the most common way a CDD validates a management narrative instead of testing it.

Red flags that a moat is weak or eroding

  • Rising discounting or longer sales cycles at flat win rates, which signal that buyers no longer accept list price as fair
  • Churn concentrated among the most informed customers, the ones who see competing tools and switch first, while retained revenue sits with captive or legacy accounts
  • Advantage tied to a founder's relationships or a single distribution partner, where the asset walks out of the room or sits on someone else's contract
  • Contractual rights, exclusivities or certifications that do not survive change of control, leaving the acquirer with a weaker position than the target enjoyed standalone
  • Gross retention drifting below the segment median; median private B2B SaaS GRR was about 88% in 2024 alongside 101% net retention, so a target materially below its ACV band is losing the customers best placed to judge it

When these signals surface, resist the temptation to resolve them with a moat premium on the exit multiple, which double-counts the thesis you are supposed to be testing. Model explicit erosion cases instead: a price cut needed to defend share, a two-point increase in churn, the loss of the key distribution partner. If the deal only works when none of these occur, the defensibility claim has not been validated, it has been assumed. Logging each erosion case as a tracked risk with its evidence base, the way a structured red flag reporting process does, keeps the sensitivity visible to the investment committee rather than buried in an appendix.

How Plausity supports the defensibility workstream

Assembling this evidence base is largely a document and data problem, which is where a structured diligence workspace helps. Plausity organizes the moat tests as a workstream and keeps every verdict traceable to the contract, cohort or call it came from.

  • Data Room Ingestion connects directly to the VDR and processes contracts, churn cohorts, pricing schedules and customer lists, so the evidence base for every moat hypothesis is assembled before the first interview call.
  • The AI-Analysis Engine cross-references those contracts, retention data and customer evidence against each of the six moat tests, surfacing contradictions between what management claims and what the documents support, with source-linked traceability on every finding.
  • Risk Radar scores each finding by materiality, financial impact and deal relevance, so the two or three defensibility questions that genuinely move valuation reach the investment committee ahead of the noise. The capability keeps every score traceable to its underlying evidence.
  • The Collaboration Hub coordinates the workstreams and the customer-interview program, so commercial, legal and technical teams see the same moat verdicts and the same open evidence gaps.
  • Report Builder drafts the investor-ready deliverable with full source traceability, which means every retention figure and every interview insight in the IC memo can be traced back to the document or call it came from.

How to use this in your next diligence workflow

Treat the moat tests as a standing CDD workstream rather than a one-off assessment. Re-run them at screening to kill weak theses early, again during confirmatory diligence with the full evidence base, and once more in the first hundred days of ownership, when the same framework becomes the baseline for the value-creation plan. Built for today's investment and deal teams. Trusted by >200 firms. The funds and advisory teams that institutionalise this discipline, as outlined for VC and PE funds, enter every process with the same advantage: their defensibility conclusions are tested, evidenced and priced, not assumed.

How Plausity accelerates this workflow

Plausity is an AI-native due diligence and deal intelligence workspace that helps M&A advisory firms, VC and PE funds, corporate development teams and investment-banking teams structure evidence, findings and questions across a data room. Plausity supports evidence extraction, source grounding, findings management and IC preparation — it does not replace human analysts, advisers or investment professionals, does not provide legal, tax, audit, regulatory or investment advice, and does not make autonomous investment decisions. All findings require human review. Built for today's investment and deal teams. Trusted by >200 firms.

To explore the underlying capabilities, see the Plausity AI analysis engine and the findings and risk intelligence product page. For team-level workflows, see how VC and PE funds and M&A advisory firms use Plausity across live deals.

Sources

Frequently Asked Questions

PLAUSITY

AI Summary

Ask an AI assistant to summarise Plausity.