Skip to main content
401kROBSCheck eligibility
SaaS acquisition guide

Can ROBS Buy a SaaS Company?

By Dennis Shirshikov · Updated July 31, 2026

Yes, but the ROBS plan does not buy the SaaS company. The C corporation buys after the plan stock transaction is complete and corporate cash has been properly released.

Direct answer: a ROBS-funded C corporation can buy a SaaS company

Conditionally, yes. A SaaS acquisition can fit a ROBS structure when eligible retirement assets roll into a qualified plan, the plan buys newly issued stock of the sponsoring C corporation, and the corporation then uses corporate cash for a bona fide business acquisition. The IRS describes ROBS as a qualified plan using rollover assets to purchase stock of a new C corporation. The same IRS materials warn that the plan remains a separate qualified plan with valuation, filing and operational duties.[1][2][3]

A SaaS dashboard is not proof of legal title, collected revenue, assignability, consent, cybersecurity condition, fair value, lender approval, tax treatment or privacy compliance. The buyer has to prove what is being bought, what obligations come with it and whether the corporation can operate the business after closing.[4][9][10][11][14]

The ROBS money path comes before the SaaS closing

The sequence is source account → plan trust → plan-owned employer stock → C corporation → seller or escrow. The source account is the former employer plan, IRA or other eligible account. The plan trust is the receiving qualified plan. Plan-owned employer stock is the plan asset received in exchange for the stock purchase. The C corporation is the operating buyer. Seller proceeds and escrow are outside the plan trust after corporate funds are validly released.[1][2][3][4][5][6][7][8]

The plan does not own the target SaaS code, customer contracts, domains, cloud accounts or data merely because the plan owns stock of the ROBS corporation. The corporation must document its own purchase authority, acquisition agreement, bank movement, assignments and post-closing records.

Source account

Property: Former employer plan, IRA or other eligible source

Control: Releases only eligible rollover dollars after distributable-event and source checks; never pays the SaaS seller, broker or escrow directly.

Record: Distribution statement, rollover election, source verification

Plan trust

Property: Qualified plan trust

Control: Accepts, rejects or quarantines rollover money, then may buy newly issued C corporation stock after fiduciary process.

Record: Trust receipt, acceptance memo, subscription agreement

Plan-owned employer stock

Property: Plan asset

Control: Represents plan ownership in the ROBS C corporation; it is not target SaaS equity, code, contracts, data, domains, repositories or seller cash.

Record: Valuation report, fiduciary minutes, share ledger

C corporation

Property: Buyer/operator after stock sale

Control: Receives validly released corporate cash and may buy documented SaaS assets or target equity under corporate authority.

Record: Board consent, corporate bank, closing statement

Target equity/assets

Property: What the seller owns

Control: Equity deal transfers company ownership; asset deal transfers named assets, IP, contracts and obligations only if assignments and consents work.

Record: Cap table, asset schedule, assignment schedule, consent log

Seller proceeds

Property: Seller-owned cash after release

Control: Seller cash is separate from plan trust cash, corporate reserves, escrow holdback, refund reserve and deferred-service liability reserve.

Record: Settlement statement, wire confirmation, release certificate

Escrow

Property: Conditional third-party control

Control: Holds purchase price, holdbacks, disputed MRR, prepaid obligations, credential variances and refund/security reserves under written release rules.

Record: Escrow agreement, variance ledger, release signatures

Corporate reserves

Property: Buyer cash retained in the corporation

Control: Funds payroll, hosting, support, deferred service delivery, security remediation, tax, refunds and transition costs after closing.

Record: Board reserve memo, bank ledger, budget

Customers/subscribers

Property: Revenue and obligation base

Control: Signed contracts, subscription terms, renewals, discounts, credits, refunds and SLAs outrank dashboard MRR screenshots.

Record: Executed contracts, order forms, cohort export, support queue

Payment processor/bank

Property: Collection evidence

Control: Settlement reports, Form 1099-K, fees, refunds, credits, processor reserves and bank deposits must reconcile before revenue is accepted.

Record: Processor export, 1099-K, bank statement, reserve schedule

Code repository

Property: Product source control

Control: Repository access is not IP title; require ownership, commit history, secrets scan, deploy test and seller access removal.

Record: Repo admin export, assignment, SBOM, secret-rotation log

Employees/contractors

Property: Creators and operators

Control: Confirm invention assignment, contractor IP, payroll status, transition support and restrictive-covenant limits.

Record: Employment agreements, contractor assignments, payroll records

Open-source/dependency owners

Property: License constraint layer

Control: Inventory copyleft, notice, source-availability, commercial-use, vulnerability and unsupported-package risks before release.

Record: SBOM, license inventory, vulnerability report

Domains and repositories

Property: Access and brand infrastructure

Control: DNS, registrar, GitHub/GitLab, package registry, CI/CD and admin accounts transfer separately from legal title.

Record: Registrar export, repo org export, deploy-key list

Cloud/data/security providers

Property: Infrastructure and data processors

Control: Cloud commitments, reserved instances, credits, logs, backups, data locations, IAM, incidents and security controls need acceptance tests.

Record: Cloud bill, IAM export, backup restore test, incident log

Tax/privacy/regulatory authorities

Property: Government obligation layer

Control: Income, sales tax, payroll, privacy, data retention, breach notice and sector rules need named review without promised outcomes.

Record: Tax returns, notices, privacy/security memo

How SaaS asset and equity purchases differ

Define the deal form before relying on revenue, code or customer records. In an asset purchase, the C corporation buys specified assets. In an equity purchase, the C corporation buys ownership of the target entity. Either structure can fail if assignment, consent, liabilities, tax treatment, data transfer or security issues are unresolved.

Asset purchase

The buyer lists the assets it is acquiring: source code, copyrights, trademarks, domains, repositories, customer contracts, documentation, data, goodwill and going-concern value. It also lists what is excluded. Assignments, lien releases, contract consents, privacy review, security review and purchase-price allocation need to be handled before value is accepted.[9][10][12][13][14]

Equity purchase

The buyer acquires the target company ownership. Existing contracts, bank accounts, employees, tax history, debt, privacy commitments and security incidents may remain with that entity. That can reduce assignment friction, but debt, taxes, payroll, customer, data and security liabilities still need diligence.[9]

Subscription revenue must be tied to contracts and cash

Monthly recurring revenue and annual recurring revenue are useful shorthand only after the underlying contracts and cash have been tested. Signed customer contracts, order forms, renewal terms, cancellation rights, credits, refunds, discounts, related-party accounts, churn, contraction, expansion, cohorts and concentration all affect the accepted revenue base.

Payment processor reports and Form 1099-K can help reconcile collections, but IRS guidance says Form 1099-K is a payment report to use with other records to figure and report correct income. It does not prove revenue quality, valuation or collectability by itself.[9][11]

Deferred revenue is a service obligation. If customers prepaid for support or subscription periods the buyer must serve after closing, the purchase agreement should identify how that obligation affects consideration through a reserve, price adjustment, escrow or holdback. Otherwise the buyer may count the same cash as seller value while still owing post-close service.[9][10]

Code, IP, domains, repositories, cloud, data and security need separate acceptance

The technical transfer should prove both legal ownership and operational control. A repository login is not copyright ownership. A domain login is not trademark ownership. A cloud admin account is not proof that credits, reserved instances, logs, backups, customer data and service commitments can transfer.[12][13][14]

Code and IP

Review founder, employee and contractor invention assignments; copyright documents; trademark owner records; repository history; package registries; software bills of materials; open-source license obligations; vulnerability reports; secrets; deployment process; and seller access removal.[12][13][14]

Security and data

Use a cybersecurity risk-management frame: identify assets and data, protect accounts and systems, detect incidents, respond to problems and recover through tested backups. For a SaaS acquisition, that means IAM exports, credential rotation, incident history, data location, backup restore tests and customer notice analysis.[4][14]

Escrow, holdbacks and quarantine rules protect against unresolved SaaS facts

Escrow and holdbacks should be written release mechanisms, not vague comfort. The agreement should say who controls the funds, what evidence releases them, what variance is acceptable, what happens if the evidence fails and who signs off.

Before release, the buyer should verify: signed customer contracts, dashboard metrics are not contract proof, MRR/ARR normalization, churn, contraction, expansion, cohorts, customer concentration, discounts, credits/refunds, deferred/prepaid service obligations, payment processor/bank/tax reconciliation, entity authority, beneficial owner, asset vs equity structure, consent/change-of-control/assignment, support/SLA liabilities, code/IP chain of title, employee/contractor assignments, open-source/license inventory, domains, repositories, package registries, cloud commitments/credits, data/privacy/security, credential rotation, seller-access removal, transition services, escrow/holdback/earnout, closing deliverables, post-close acceptance tests.

Ready to use

Corporate acquisition spend supported by board authority, source, counterparty, agreement, signed contract evidence, bank clearance, IP assignment, security acceptance and post-close test.

Do not rely on

Dashboard MRR, ARR multiple, repository login, cloud console screenshot, unpaid invoice, seller promise or personal reimbursement lacking title, consent, bank tie-out or business purpose.

Set aside for review

Rollover amount, disputed MRR, prepaid obligation, refund, processor reserve, assignment gap, security incident, open-source issue, credential variance or holdback pending named release authority.

Released after proof

Previously quarantined cash, contract value, code, credential or holdback released only after documents, formulas, consent, security reset and approval signatures match the written conditions.

Held in escrow

Third-party-held purchase price, deferred-service reserve, refund/security holdback or earnout controlled by written instructions, variance tolerances and return-to-payer rules.

Three reproducible SaaS acquisition scenarios

The examples below are simplified decision checks. They show arithmetic and controls, not a conclusion that the target is worth buying or that ROBS is appropriate.

SaaS asset purchase with funded escrow, deferred-service reserve and remaining corporate cash

The scenario uses these assumptions.

  • Released corporate cash after stock sale: $640,000
  • Asset purchase price: $480,000
  • Funded escrow holdback: $90,000
  • Deferred/prepaid service obligation reserve: $52,000
  • Security remediation budget: $18,000
  • Corporate operating reserve: $85,000
  • Price allocation: code/IP $210,000 + customer contracts $120,000 + domain/brand $35,000 + goodwill/going concern $115,000 = $480,000

The arithmetic works as follows.

  • Seller release at close = $480,000 - $90,000 = $390,000
  • Funded escrow ledger = $90,000 ESCROW until assignment, credential, support and security tests clear
  • Immediate corporate cash committed = $390,000 + $90,000 + $52,000 + $18,000 = $550,000
  • Corporate cash after funded escrow, reserves and remediation = $640,000 - $550,000 - $85,000 = $5,000
  • Allocation ledger checks $210,000 + $120,000 + $35,000 + $115,000 = $480,000

Control: No double counting: the same $90,000 cannot be seller proceeds and escrow; the $52,000 reserve covers service already sold but not yet delivered.

MRR quality bridge from dashboard ARR to signed-contract verified recurring revenue

The scenario uses these assumptions.

  • Dashboard ARR: $720,000
  • One-time setup fees annualized by seller: $60,000
  • Expired/pilot/unsigned accounts: $48,000
  • Discount credits and refunds: $36,000
  • Related-party subscriptions: $24,000
  • Monthly churn/contraction reserve annualized: $72,000
  • Verified signed-contract ARR after exclusions: $480,000
  • Processor and bank deposits supporting annualized recurring collections: $468,000

The arithmetic works as follows.

  • Normalized signed-contract ARR = $720,000 - $60,000 - $48,000 - $36,000 - $24,000 - $72,000 = $480,000
  • Collections variance = $480,000 - $468,000 = $12,000 QUARANTINED until processor, bank and tax records reconcile
  • Accepted recurring revenue for valuation model remains $468,000 unless the variance file supports a higher amount

Control: Dashboard ARR is not proof of collectible recurring revenue. Signed contracts, payment records and exclusions drive the accepted number.

Closing holdback for credentials, open-source issue and SLA backlog

The scenario uses these assumptions.

  • Purchase price: $575,000
  • Credential/security/open-source holdback: $100,000
  • Refund/support/SLA holdback: $45,000
  • Accepted seller release at close expected by agreement: $430,000
  • Unrotated admin and deploy keys: $12,500
  • Copyleft/source-notice remediation estimate: $18,000
  • Open priority SLA credits/refunds: $14,500

The arithmetic works as follows.

  • Accepted seller release at close = $575,000 - $100,000 - $45,000 = $430,000
  • Variance quarantine = $12,500 + $18,000 + $14,500 = $45,000
  • Releasable technical holdback after acceptance = $100,000 - $45,000 = $55,000 if written release conditions are met

Control: Release requires named human, qualified reviewer, credential rotation, license remediation evidence, support queue acceptance and escrow signatures.

Risks and alternatives to compare before using ROBS

The main ROBS risk is not a tax form. It is the exchange of diversified retirement-plan assets for stock in one privately held company. If the SaaS business loses value, the plan-owned employer stock may lose value too. Compliance risk remains even when the product works: plan operations, valuation, Form 5500 reporting, prohibited transactions, employee eligibility, service-provider monitoring and corporate records still matter.[1][4][5][6]

SaaS-specific risks include dashboard-only MRR, phantom annual contracts, one-time setup fees counted as recurring, discounted pilot customers, related-party subscriptions, high churn cohort, contraction masked by expansion, customer concentration, credits/refunds, prepaid service backlog, unassigned contractor code, copyleft/open-source breach, repository secret exposure, nontransferable cloud credits, unconsented data transfer, security incident, SLA/support backlog, credential gap, seller access, valuation impairment. These risks are controllable only if the deal documents, escrow instructions, technical acceptance and post-close operations give someone authority and budget to resolve them.

Compare ROBS with alternatives using the same facts: SBA 7(a) or conventional acquisition loan, seller note or earnout, smaller asset purchase with staged transition, outside equity, cash savings, taxable retirement distribution after tax review, waiting until more nonretirement capital is available. A loan may add debt service and guarantees but preserve retirement diversification. Seller financing may align incentives but require collateral and default terms. Outside equity may reduce retirement concentration but dilute control.

Next steps before a ROBS-funded SaaS purchase

First, confirm whether the retirement assets are eligible for rollover and whether the receiving plan will accept them. Second, separate the ROBS stock transaction from the SaaS purchase closing. Third, choose asset or equity structure with M&A counsel, tax advice and valuation support. Fourth, build the revenue, IP, security, cloud and escrow files before release.

Pause before closing if any of the following conditions are still unresolved.

  • No person has authority to resolve escrow timing, credential acceptance, contract variances, support backlog or SLA exposure.
  • Rollover eligibility, fiduciary process, party-in-interest treatment, employer-stock valuation or plan-document compliance remains uncertain.
  • The buyer has not confirmed corporate authority, asset or equity structure, title, customer consents, change-of-control terms, lien releases or seller representations.
  • The CPA and deal counsel have not reconciled purchase-price allocation, Form 8594, Form 1099-K records, payroll, sales tax, deferred revenue, refunds or earnout classification.
  • The plan administrator, custodian and accounting records do not match the rollover, stock subscription, Form 5500 position, corporate bank receipt or share ledger.
  • Employer-stock value, target purchase price or accepted recurring revenue lacks support from signed contracts, bank records, valuation work and reconciled assumptions.
  • Founder, employee, contractor, trademark, copyright, repository or open-source ownership is unresolved.
  • Data transfer, breach history, retention duties, access controls or customer notice questions still need privacy and security review.
  • Cloud commitments, credits, backups, IAM records, logs, deploy keys, package registries, migration testing or seller-access removal cannot yet be accepted.
  • Any SBA lender, conventional lender, seller-note holder or escrow party has not approved the source of funds, deal structure or closing flow.

When these points are cleared, the buyer still needs a final review of the signed closing file rather than a dashboard or informal handoff.

Frequently asked questions

These answers summarize the main decision points for a ROBS-funded SaaS acquisition.

Can ROBS buy a SaaS company?

Conditionally. A standard ROBS funds a qualified plan purchase of newly issued C corporation stock. After a valid release, the C corporation, not the plan or participant, may acquire documented SaaS assets or target equity.[1][2][3][4]

Is a SaaS asset purchase different from an equity purchase?

Yes. An asset deal buys specified code, IP, contracts, domains, data and other assets if assignment and consent work. An equity deal buys the target company ownership and still needs debt, tax, customer, change-of-control, data, employee and security review.[9][10][12][13][14]

Can dashboard MRR or ARR prove purchase value?

No. Dashboard metrics are diligence inputs. Accepted revenue needs signed customer contracts, processor and bank reconciliation, exclusions for one-time fees, credits, refunds, discounts, churn, contraction and related-party accounts.[9][11]

How do prepaid subscriptions affect the deal?

Prepaid or deferred service obligations are not free seller value. They require a corporate reserve, price adjustment or holdback so the buyer can deliver post-close service without counting the same cash twice.[9][10]

What code and IP records matter most?

Require assignments from founders, employees and contractors, copyright and trademark records where applicable, repository and package-registry control, open-source/license inventory, vulnerability review and seller-access removal.[12][13][14]

What should be held back or quarantined?

Quarantine disputed ARR, unsigned or nonassignable contracts, credits/refunds, prepaid obligations, processor reserves, security incidents, open-source issues, credential gaps, SLA liabilities and seller access until release conditions are satisfied.[4][9][11][14]

Sources and update triggers

Sources were directly reopened July 31, 2026. Update this page when IRS changes ROBS, rollover, verification, Form 8594 or 1099-K guidance; DOL or OLRC changes fiduciary, prohibited-transaction or employer-security text; SBA changes buying-existing-business guidance; USPTO or Copyright Office changes assignment or recordation guidance; NIST changes Cybersecurity Framework guidance; or the page makes a broader claim than the cited official source supports.

  1. [1] IRS ROBS Compliance Project

    Reopened July 31, 2026. Used for the ROBS sequence, C corporation stock purchase, separate qualified plan obligations, Form 5500/Form 1120, valuation, discrimination and prohibited-transaction cautions; not transaction approval.

  2. [2] IRS ROBS examination guidelines

    Reopened July 31, 2026 through the IRS ROBS page. Used for the sequence from C corporation and qualified plan to rollover or transfer, employer-stock purchase, corporate capitalization, valuation and case-by-case examination framing.

  3. [3] IRS verifying rollover contributions to plans

    Reopened July 31, 2026. Used for receiving-plan verification, source checks, direct rollover treatment, invalid-rollover correction and the rule that a plan need not accept rollovers.

  4. [4] DOL Meeting Your Fiduciary Responsibilities

    Reopened July 31, 2026. Used for written plan, trust, recordkeeping, fiduciary-by-function, prudence process, service-provider monitoring, cybersecurity questions, prohibited transactions, employer-stock fair-market-value framing and Form 5500 reporting.

  5. [5] ERISA section 404 fiduciary duties

    Reopened July 31, 2026. Used for loyalty, prudence, diversification, plan-document compliance and plan-asset decision process.

  6. [6] ERISA section 406 prohibited transactions

    Reopened July 31, 2026. Used for sale or exchange, lending, services, transfer or use by a party in interest and fiduciary self-dealing prohibitions.

  7. [7] ERISA section 407 employer securities

    Reopened July 31, 2026. Used for employer-security definitions and why plan-owned employer stock remains distinct from target SaaS equity, code, contracts, data, domains and cloud accounts.

  8. [8] ERISA section 408 exemptions

    Reopened July 31, 2026. Used for conditional exemption concepts, reasonable compensation and no-commission fair-market-value employer-security language; not deal approval.

  9. [9] SBA Plan your business: buy an existing business or franchise

    Reopened July 31, 2026. The current canonical page resolved to SBA Plan your business; used only the buy-existing-business/franchise scope for diligence into contracts, cash flow, employees, investment size, infrastructure, attorneys, accountants, value methods, sales agreement and purchase-price adjustment.

  10. [10] IRS Instructions for Form 8594

    Reopened July 31, 2026. Used only for bounded asset-acquisition allocation, intangibles, goodwill and going concern value, consideration and later price-adjustment reallocation; not employer-stock valuation.

  11. [11] IRS Understanding your Form 1099-K

    Reopened July 31, 2026. Used only for payment-card and third-party-network reporting distinctions and the need to use other records to report correct income; not proof of cash or value.

  12. [12] USPTO trademark assignments

    Reopened July 31, 2026. Used for trademark ownership transfer, assignment recording, TSDR owner checks and assignment-with-goodwill caution.

  13. [13] U.S. Copyright Office recordation overview

    Reopened July 31, 2026. Used for copyright ownership transfers, assignments, exclusive licenses, other copyright documents and public recordation limits.

  14. [14] NIST Cybersecurity Framework

    Reopened July 31, 2026. Used for cybersecurity risk-management framing and the need to identify, protect, detect, respond and recover when accepting SaaS code, cloud systems, credentials and data.

Keep SaaS cash, contracts, code and credentials separate

Use the guide to prepare records, then have qualified ERISA, corporate, M&A, tax, valuation, IP, privacy, security, cloud, accounting and lender professionals review the actual transaction.

Compare business acquisition basics