What Happens to IP Addresses During a Merger or Acquisition?

  • Post author:
  • Post last modified:October 1, 2026
  • Reading time:25 mins read
You are currently viewing What Happens to IP Addresses During a Merger or Acquisition?

Table of Contents

What Happens to IP Addresses During a Merger or Acquisition?

IP addresses do not necessarily move automatically when one company acquires another.

What happens depends on:

  • how the transaction is structured;

  • which legal entity remains;

  • how the resources were originally registered;

  • which Regional Internet Registry manages the records;

  • whether the resources are directly held or provider-assigned;

  • what documentation supports the change.

A merger or acquisition may require updates to:

  • IPv4 and IPv6 registry records;

  • Autonomous System Numbers;

  • RIR accounts;

  • administrative contacts;

  • BGP routing;

  • RPKI ROAs;

  • IRR route objects;

  • reverse DNS;

  • internal documentation.

The most important principle is:

A corporate transaction can change legal and administrative relationships without immediately changing the running network.

That means M&A due diligence should examine registry records, documentation, authorization and live routing separately.

 

Do IP Addresses Automatically Transfer With a Company?

Not always.

An acquisition can take many forms.

For example:

Share acquisition

The legal entity holding the resources may continue to exist.

Asset acquisition

Specific network assets may move to a different legal entity.

Merger

Two entities may combine and one may survive.

Corporate restructuring

Resources may need to be moved between related entities.

These structures can have different consequences for Internet number resources.

ARIN, APNIC and RIPE NCC each maintain processes for mergers, acquisitions, restructurings and related changes.

For example, APNIC states that when business structure changes, a different organization may need to become registered to manage the relevant IP addresses and AS numbers, with supporting legal documentation required for the transfer process.

ARIN similarly provides a specific process for transfers due to mergers, acquisitions and reorganizations.

The practical lesson is:

Do not assume that IP resources transfer simply because commercial ownership of a company or network has changed.

 

Start With a Complete Internet Number Resource Inventory

Before closing a transaction, the acquiring organization should know exactly which Internet number resources are involved.

That inventory should include:

  • IPv4 allocations and assignments;

  • IPv6 allocations and assignments;

  • ASNs;

  • RIR account identifiers;

  • registry handles;

  • administrative contacts;

  • RPKI access;

  • IRR objects;

  • reverse DNS zones;

  • current BGP announcements.

A useful inventory might look like:

ResourceRegistryRegistered EntityOrigin ASNRPKINotes
203.0.113.0/24Example RIRCompany AAS64500ValidProduction
2001:db8::/32Example RIRCompany AAS64500ValidIPv6 core
AS64500Example RIRCompany A——Main ASN

This should be completed before assuming the resources are part of the transaction.

NRS provides a broader framework in How to Audit Your Company’s Internet Number Resources.

 

Check Who Is Registered to the Resource

The next step is to review registry information.

RDAP can help identify:

  • the registered range;

  • organization information;

  • network name;

  • status;

  • contacts;

  • relevant registry.

This establishes the current registry state.

But registry data should not be treated as the only source of truth.

It does not automatically answer:

  • who is routing the resource;

  • whether the current routing is authorized;

  • which company internally controls the resource;

  • whether supporting corporate documents are complete.

NRS explains how to interpret this information in How to Read an RDAP Record for an IP Address.

 

Registry Information Is Evidence, Not the Entire Legal Picture

During M&A due diligence, it is important to use precise language.

A registry record may provide important evidence about:

  • which organization is registered;

  • how the resource is administered;

  • current registry contacts;

  • historical resource relationships.

But technical registry data should not automatically be treated as a complete determination of legal ownership.

Depending on the transaction, relevant evidence may also include:

  • original allocation or assignment documents;

  • transfer records;

  • corporate acquisition agreements;

  • historical contracts;

  • board resolutions;

  • service agreements;

  • applicable RIR documentation;

  • applicable law.

For this reason, technical due diligence and legal due diligence should support one another.

 

Review the Relevant RIR Account

An acquisition can fail operationally even when the commercial transaction is complete if nobody can access the relevant RIR account.

Check:

  • who can log in;

  • which email addresses are associated with the account;

  • whether MFA is enabled;

  • whether contacts belong to former employees;

  • whether billing information is current;

  • whether administrative and technical contacts remain valid.

This is especially important where resources are managed through:

  • ARIN Online;

  • RIPE NCC LIR Portal;

  • MyAPNIC;

  • other registry account systems.

Access should not depend on one individual employee.

A resilient organization should be able to recover administrative control after staff changes, restructuring or acquisition.

 

ARIN Mergers and Acquisitions

ARIN has a specific transfer category for mergers, acquisitions and reorganizations under its number-resource policies.

ARIN states that an organization that acquires assets using IP addresses or ASNs, or acquires the relevant network or organization as a whole, may request transfer of those resources.

ARIN may require evidence that the acquiring organization actually acquired the assets using the resources or acquired the registrant organization.

Organizations should review ARIN’s current requirements directly before planning a transaction:

ARIN — Transferring IP Addresses & ASNs

The key operational point is:

The corporate transaction and the registry transfer process are connected, but they are separate processes.

 

APNIC Mergers and Acquisitions

APNIC also has a specific process for transfers caused by:

  • mergers;

  • acquisitions;

  • reorganizations.

APNIC explains that where the organization managing the resources changes, the recipient may need an APNIC account and the Internet number resources may need to be transferred to that account.

Supporting legal documents may be required.

APNIC then updates its Whois records to reflect the new organization managing the resources.

See:

APNIC — Transfer Due to Merger, Acquisition or Reorganization

This illustrates an important distinction:

The registry update reflects the administrative result of the transaction; it does not itself perform the network migration.

 

RIPE NCC Corporate Changes

RIPE NCC documentation also addresses changes caused by:

  • merger;

  • sale;

  • takeover;

  • organizational restructuring.

The RIPE NCC may require organizations to clarify the type of corporate change and provide supporting information and legal documentation.

It also reviews the status of Internet number resources held by organizations affected by ownership changes.

See:

RIPE NCC — Internet Number Resources

The specific process may depend on whether:

  • an existing LIR remains open;

  • one LIR takes over another;

  • a non-LIR acquires an LIR;

  • the legal entity changes;

  • only the company name changes.

This is why due diligence should identify the exact transaction structure before assuming which registry process applies.

 

A Legal Name Change Is Not Always the Same as a Resource Transfer

This is another important distinction.

Suppose:

Before:
Example Networks Ltd.

After:
Example Infrastructure Ltd.

If the legal entity remains the same and only its registered name changes, the required process may differ from a transfer to a different legal entity.

By contrast:

Company A
        ↓
assets acquired by
        ↓
Company B

may require a resource-transfer process.

Organizations should therefore distinguish between:

name change

and

change of legal resource holder or administrator

before submitting registry requests.

 

Check Whether the Resources Are Directly Held

Not every public IP address used by a company is held directly from an RIR.

Some may be:

  • provider-assigned;

  • cloud-provider addresses;

  • hosting-provider addresses;

  • connectivity-provider addresses.

For example:

Company A uses:
198.51.100.0/24

But the address space may actually be assigned by ISP B.

If Company A is acquired, the address block may not automatically be portable to the buyer’s new network provider.

The acquirer needs to determine:

  • who actually holds the resource;

  • whether it can move;

  • whether it depends on a service contract;

  • whether renumbering will be required.

This distinction can have major operational consequences after closing.

 

Check the Allocation and Transfer History

M&A due diligence should reconstruct the resource history where possible.

Ask:

  • When was the resource originally issued?

  • To which entity?

  • Has it been transferred previously?

  • Was the current company renamed?

  • Was there an earlier acquisition?

  • Does the registry record match current corporate records?

  • Are there gaps in documentation?

This is especially important for older IPv4 blocks.

Some resources may have been allocated decades ago and passed through several corporate restructurings.

The older the resource history, the more important it becomes to maintain a clear chain of documentation.

 

Review the Autonomous System Numbers

An acquisition may involve one or more ASNs.

Do not assume the IP resources and ASN must move in exactly the same way.

An acquiring company might:

  • retain the acquired ASN;

  • continue routing under the seller’s existing network structure;

  • migrate the prefixes to its own ASN;

  • temporarily operate both;

  • retire an ASN later.

NRS explains the functional difference in ASN vs IP Address: What Is the Difference?.

The M&A team should document:

Prefix → Current ASN → Future ASN

for every important production network.

 

What Happens to BGP After an Acquisition?

Nothing may change immediately.

A legal transaction can close while BGP continues exactly as it did the day before.

For example:

Before acquisition:

203.0.113.0/24 → AS64500

The next day, the company may still announce:

203.0.113.0/24 → AS64500

even though the corporate ownership has changed.

That may be entirely intentional.

Later, the buyer may migrate the resource:

203.0.113.0/24 → AS64501

This is why legal closing and network migration should not be treated as the same event.

 

Verify Who Is Actually Announcing the Prefix

During and after the transaction, check live BGP.

Verify:

  • which prefixes are visible;

  • which origin ASNs are observed;

  • whether there are more-specific routes;

  • whether multiple origins appear;

  • whether the state matches the migration plan.

NRS explains the process in How to Check Who Is Announcing an IP Prefix in BGP.

This is where Heng.lu MD’s distinction becomes particularly important:

Registry state may change while routing remains unchanged, or routing may change before every administrative record has been updated.

The objective is to understand and coordinate both.

 

Review RPKI Before Changing the Origin ASN

If the acquired prefixes are protected by RPKI, review every relevant ROA before changing production routing.

A ROA can authorize an ASN to originate a prefix.

RFC 9582 defines a ROA as a digitally signed object that allows verification that an address block holder has authorized an AS to originate routes for one or more prefixes.

See:

RFC 9582 — A Profile for Route Origin Authorizations

Suppose the acquired company currently has:

ROA:
203.0.113.0/24 → AS64500

and the buyer changes BGP to:

203.0.113.0/24 → AS64501

without updating the authorization.

The legitimate new route may become RPKI Invalid.

That can create reachability problems on networks enforcing Route Origin Validation.

 

RPKI Changes Should Be Part of the Migration Plan

A safe migration should identify:

Current state

Prefix → Current ASN → Current ROA

Future state

Prefix → Future ASN → Required ROA

The process should consider:

  • new origin ASN;

  • old origin ASN;

  • permitted prefix lengths;

  • migration overlap;

  • timing of ROA changes;

  • removal of obsolete authorization.

NRS discusses this relationship in ROA Coverage vs ROV Adoption in 2026: Why the Routing Security Gap Matters.

 

Review IRR Route Objects

IRR data should also be reviewed.

An acquired network may have route objects such as:

route: 203.0.113.0/24
origin: AS64500

If the network migrates to:

AS64501

the relevant IRR information may also need updating.

Stale IRR objects can create problems for networks that generate filters from routing-registry data.

After the acquisition, verify that IRR entries reflect the intended routing state.

 

Review Reverse DNS

Reverse DNS is another dependency that is easy to miss.

The transaction may involve:

  • in-addr.arpa zones for IPv4;

  • ip6.arpa zones for IPv6;

  • DNSSEC configuration;

  • nameserver access;

  • delegation authority.

Changing registry records does not necessarily guarantee that the buyer has access to all systems used to manage reverse DNS.

This should be tested before legacy staff or systems are decommissioned.

 

Check RPKI, IRR and DNS Access Before Employee Offboarding

One of the highest-risk moments in an acquisition is employee transition.

A key engineer may currently control:

  • the RIR account;

  • RPKI;

  • IRR credentials;

  • DNS;

  • BGP configuration;

  • monitoring;

  • upstream-provider contacts.

If that employee leaves before access is transferred, the acquiring organization may technically control the company but lack practical control over important network functions.

Before offboarding, verify organizational access to every critical system.

 

Provider Contracts Can Matter as Much as Registry Records

A company’s ability to route its addresses may depend on upstream agreements.

Review:

  • transit contracts;

  • BGP sessions;

  • Letters of Authorization;

  • DDoS mitigation agreements;

  • colocation services;

  • hosting arrangements;

  • managed routing services.

For example, a prefix may be registered to Company A while Provider B originates it under a valid operational arrangement.

The acquisition of Company A does not automatically recreate that provider relationship for Company C.

Contractual continuity needs separate review.

 

What About Letters of Authorization?

A Letter of Authorization, or LOA, is often used operationally to demonstrate that one party authorizes another to perform a particular network action.

For example:

Resource administrator
        ↓
authorizes
        ↓
Transit or hosting provider
        ↓
to announce the prefix

LOAs can be relevant evidence for operational relationships.

But they should not be treated as a substitute for:

  • registry records;

  • RPKI;

  • contracts;

  • transfer documentation;

  • legal due diligence.

After an acquisition, existing LOAs should be reviewed to determine whether they remain valid and whether new ones are required.

 

Check Geolocation and Reputation Systems

IP addresses may retain historical associations after an acquisition.

Third-party databases may still associate a block with:

  • the old company;

  • old country information;

  • previous network names;

  • past abuse reports;

  • stale reputation data.

After the transaction, teams may need to review:

  • geolocation;

  • abuse contacts;

  • blocklists;

  • security vendors;

  • reputation services.

This is particularly important where address space is transferred or redeployed into a new network environment.

 

What Happens During an Asset Purchase?

Asset purchases deserve extra care.

Suppose Company B purchases:

  • servers;

  • customer contracts;

  • routers;

  • data-centre infrastructure.

That does not automatically mean every IP address or ASN used by those assets transfers in the same way.

Due diligence should determine whether the Internet number resources were:

  • directly registered to the seller;

  • provider-assigned;

  • included in the transaction;

  • separately documented;

  • subject to an RIR transfer process.

The acquisition agreement should be consistent with the technical reality.

 

What Happens During a Share Acquisition?

A share acquisition can be different.

If the underlying legal entity continues to exist, many registry relationships may remain attached to the same entity.

But the acquirer should still review:

  • contacts;

  • credentials;

  • agreements;

  • billing;

  • RPKI access;

  • internal documentation;

  • routing plans.

Even when a formal resource transfer is unnecessary, operational control may still need to change substantially.

 

What Happens During a Corporate Restructuring?

A restructuring may move resources between:

  • subsidiaries;

  • parent companies;

  • regional entities;

  • newly formed companies.

This can create hidden dependencies.

The company may think of the entire group as one organization.

The RIR may see several separate legal entities.

That difference matters.

Internet number resource records should accurately reflect the organization that is responsible for the relevant resources under the applicable registry framework.

 

Pre-Closing IP Address Due-Diligence Checklist

Before completing an acquisition, review the following:

AreaWhat to Check
IPv4Complete prefix inventory
IPv6Complete prefix inventory
ASNAll public ASNs
RegistryRegistered entities
RIR AccountsAccess and authorized users
DocumentationAllocation and transfer history
Corporate RecordsLegal entity continuity
BGPCurrent origin ASNs
RPKIROAs and access
IRRRoute objects
Reverse DNSDelegations and access
Upstream ProvidersTransit and BGP agreements
LOAsRouting authorization documents
MonitoringRoute and resource monitoring
ReputationBlocklists and geolocation
Staff AccessKey-person dependencies

Any unexplained mismatch should be investigated before closing where practical.

 

What to Verify Immediately After Closing

After the transaction closes, repeat the technical audit.

Confirm:

Registry

Are the intended organization records correct?

RIR Account

Does the acquiring organization have working access?

BGP

Are prefixes still visible from the expected ASNs?

RPKI

Are important routes Valid?

IRR

Do route objects match the intended routing?

DNS

Does forward and reverse DNS continue to work?

Providers

Are upstream routing relationships still active?

Monitoring

Are alerts being received by the new team?

Closing the transaction should not be the final network-management step.

It should trigger a verification phase.

 

The Most Important M&A Principle: Separate the Layers

A useful model is:

Corporate transaction
        ↓
Legal / contractual records
        ↓
Registry records
        ↓
Routing authorization
        ↓
Live BGP
        ↓
Operational services

These layers influence each other.

But they do not automatically update one another.

A signed acquisition agreement does not update BGP.

A registry update does not rewrite a ROA.

A new ROA does not change DNS.

A BGP change does not prove a corporate transfer occurred.

The strongest M&A process verifies every relevant layer independently.

 

Why This Fits a Broader Internet Resource Governance Model

Internet number resources depend on coordination.

Accurate registry information is valuable because independent operators need reliable information about resources.

At the same time, the registry record is only one part of the operational picture.

An effective governance and operational model should support:

  • accurate records;

  • verifiable authorization;

  • continuity;

  • auditability;

  • recoverable administrative access;

  • stable routing;

  • clear organizational responsibility.

The goal is not to make every system perform the same role.

It is to keep the systems sufficiently aligned that organizations can understand and recover the network relationships on which they depend.

 

Common M&A Mistakes

Assuming the IP Addresses Transfer Automatically

They may require separate registry action.

Ignoring ASNs

An ASN can be just as important as the address block.

Forgetting RPKI

A routing migration can become Invalid if the ROA is stale.

Ignoring Provider-Assigned Space

Not every address is portable.

Removing Legacy Staff Too Early

Key credentials may disappear with them.

Looking Only at RDAP

Registry data does not reveal complete live routing.

Looking Only at BGP

BGP does not prove administrative or legal authority.

Updating the Registry but Not the Network

Administrative and operational transitions need separate planning.

 

Final Takeaway

A merger or acquisition does not reduce IP address management to one question of “ownership.”

The real task is to determine how the transaction affects:

  • the legal entity;

  • registry records;

  • RIR accounts;

  • IPv4 and IPv6 resources;

  • ASNs;

  • BGP;

  • RPKI;

  • IRR;

  • reverse DNS;

  • provider relationships;

  • internal documentation.

The most reliable approach is to separate the layers.

Ask:

Who is registered?

Who has administrative access?

Who is authorized to originate the prefix?

Who is actually announcing it?

What does the transaction documentation say?

Can the new organization recover and operate the resource after closing?

A well-managed acquisition keeps these answers consistent.

That is what protects operational continuity.

 
1. Do IP addresses automatically transfer when a company is acquired?

No. The required process depends on the transaction structure, legal entity, registry records and applicable RIR procedures.

2. Can IPv4 addresses be part of an acquisition?

Yes, but organizations should verify the relevant registry and transfer requirements rather than assuming commercial acquisition automatically updates the resource records.

3. What happens to ASNs after an acquisition?

An ASN may remain in use, be transferred where applicable, or eventually be replaced. The acquiring organization should review the ASN separately from the IP prefixes.

4. Does a company need to update the RIR after a merger?

It may. Merger, acquisition, reorganization and legal-name-change processes differ by RIR and transaction structure.

5. Does changing the registry automatically change BGP?

No. Registry changes and BGP routing are separate processes.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Leave a Reply