
Short answer: Minimum Viable Secure Product (MVSP) is a short, free, vendor-neutral security baseline for B2B software and business process outsourcing suppliers. It groups essential controls into four areas: business, application design, application implementation and operations. Startups use it as a first security checklist, but it does not replace SOC 2, ISO 27001 or HIPAA evidence when buyers require them.
Related guides:
Key takeaways
- MVSP is a minimum, not a certification. It describes the controls any B2B software vendor should have before selling to businesses, with no auditor and no fee.
- It is organized into four areas: business controls, application design controls, application implementation controls and operational controls.
- It is a great first roadmap for a pre-revenue or seed-stage SaaS or HealthTech team, because almost every control also shows up later in SOC 2 and ISO 27001.
- It rarely closes enterprise or healthcare deals on its own. Regulated buyers will still ask for a SOC 2 report, an ISO 27001 certificate or HIPAA evidence such as a risk analysis and a signed BAA.
- Treat MVSP as the foundation of your control library, so the work carries straight into your first audit.
What is Minimum Viable Secure Product (MVSP)?
MVSP is a freely available, vendor-neutral checklist that defines the baseline security a B2B software or outsourcing supplier should meet. It was launched in October 2021 by Google, Salesforce, Okta, Slack and other companies that were tired of sending, and receiving, sprawling security questionnaires that mostly asked the same basic questions. Their answer was a short list of controls that every vendor should be able to meet, published openly and maintained at mvsp.dev.
The checklist is versioned and has been revised since launch. The current version is v3.0, dated November 9, 2023, and the site still links to the earlier v1.0 and v2.0 for reference.
A few things make MVSP different from the frameworks most startups hear about first:
- It is deliberately short. An engineer can read it in one sitting.
- It is prescriptive. It states concrete expectations, such as supporting single sign-on or encrypting data in transit, rather than asking you to design a risk-based program.
- It is free and unaudited. Vendors self-assess, and buyers decide how much to trust that self-assessment.
Just as a minimum viable product is the smallest thing worth shipping, MVSP is the smallest set of security controls worth having before a business customer trusts you with its data.
What are the four MVSP control areas?
MVSP groups its controls into four areas that follow how a SaaS product is run, built and operated. The table is our own summary of each area's themes in MVSP v3.0, not the checklist text, so read the current version at mvsp.dev before relying on it.
| Control area | What it covers | Typical evidence |
|---|---|---|
| Business controls | How the company handles vulnerability reports, external security testing, staff training, incident notification, data handling and legal or regulatory obligations | Vulnerability disclosure page, recent penetration test summary, training records, incident response plan |
| Application design controls | Security built into the product itself, such as SSO support, HTTPS everywhere, sensible security headers, password handling, safe libraries and frameworks, dependency patching, logging and encryption | Architecture notes, configuration screenshots, dependency scanning results |
| Application implementation controls | How the product is built and changed: knowing where sensitive data flows, preventing common vulnerability classes, fixing vulnerabilities on a timeline and running a controlled build and release process | Data flow diagram, secure coding guidelines, vulnerability SLAs, CI/CD pipeline configuration |
| Operational controls | How the company and its infrastructure are run: physical and logical access, managing subprocessors, and backups with tested recovery | Access reviews, MFA enforcement, subprocessor list, backup and restore test records |
Much of this sits inside engineering, because MVSP assumes a small vendor may not have a security team yet. If you are designing a new product, the secure by design guide linked above goes deeper on the application design area.
MVSP checklist: what should an early-stage startup do first?
Start with the controls a buyer can verify quickly and that reduce the most risk: access, encryption, vulnerability handling and incident response. This working order for a seed or Series A SaaS team follows the MVSP areas, in our own words.
Week 1 to 2: business basics
- Publish a security contact or vulnerability disclosure page and route reports to a monitored inbox.
- Write a short incident response plan that names who decides, who communicates, and how quickly customers are told about a breach affecting their data.
- Run security awareness training for everyone, and keep completion records.
- Define how customer data is deleted or returned when a contract ends, including in backups.
Week 2 to 4: lock down access and operations
- Enforce MFA on your identity provider, cloud console, source control and any admin tool.
- Remove shared accounts and give each person named, least-privilege access.
- Build a subprocessor list: every vendor that touches customer data, what it receives and where it is hosted.
- Turn on automated backups for production data and perform a restore test. Write down how long it took.
Month 2: secure the product
- Offer SSO for customers, at least on business plans, through a standard protocol such as SAML or OIDC.
- Serve everything over HTTPS only, redirect plain HTTP, and set modern security headers.
- Encrypt customer data in transit and at rest, and keep keys out of source code.
- Enable dependency scanning and set a policy for patching vulnerable libraries.
- Log security-relevant events such as logins, permission changes and admin actions, and keep the logs long enough to investigate incidents.
Month 3: harden the build pipeline and test it
- Draw a data flow diagram that shows where sensitive data enters, is stored and leaves.
- Require code review and protected branches for production changes.
- Set target timelines for fixing vulnerabilities by severity, and track them.
- Commission an independent penetration test of the application, and keep a shareable summary.
Laptops hold production credentials too, so pair this list with our endpoint security baseline for startups.
What should HealthTech startups add on top of MVSP?
HealthTech startups should treat MVSP as the floor and add HIPAA-specific safeguards before handling protected health information (PHI). MVSP is industry neutral, but if you handle PHI for a covered entity, HIPAA applies to you directly whether or not a buyer asks.
Add these items to your checklist:
- Map where PHI lives. Extend your MVSP data flow diagram to mark every system, log, backup and vendor that touches PHI.
- Complete a documented HIPAA risk analysis. This is a specific HIPAA requirement and is broader than a generic risk review.
- Sign business associate agreements. You need BAAs with healthcare customers and with any subprocessor that handles PHI on your behalf.
- Add PHI-aware access and audit logging. Make it possible to show who accessed which patient records and when.
- Extend incident response for breach notification. Add the steps for assessing whether an incident is a reportable breach and notifying covered entities.
HHS published a proposed rule to update the HIPAA Security Rule in the Federal Register on January 6, 2025, and the comment period closed on March 7, 2025. It would make some safeguards more prescriptive. As of October 2026, HHS has not published a final rule, so the proposal is not yet law. Building MFA, encryption and asset inventories now is sensible, but confirm the current rule text with HHS before treating any proposed requirement as final.
How does MVSP compare to SOC 2 and ISO 27001?
MVSP is a free self-assessed baseline, while SOC 2 and ISO 27001 are independently audited programs that buyers accept as formal assurance. They are complements, not alternatives. Most MVSP controls map neatly onto SOC 2 criteria and ISO 27001 Annex A controls.
| MVSP | SOC 2 | ISO 27001 | |
|---|---|---|---|
| Scope | A short list of baseline controls for B2B software and outsourcing suppliers | Controls relevant to the Trust Services Criteria you choose, with Security always included | A full information security management system (ISMS) plus applicable Annex A controls |
| Cost | Free to use. Your cost is engineering time and any penetration test | Auditor fees, readiness work and ongoing evidence collection | Certification body fees, readiness work and annual surveillance audits |
| Audit | None. Vendors self-assess and buyers may ask for supporting evidence | Attestation by a licensed CPA firm, as a Type 1 or Type 2 report | Certification audit by an accredited body, with periodic surveillance and recertification |
| Buyer acceptance | Useful for early deals and for structuring questionnaire answers. Rarely sufficient for enterprise or regulated buyers alone | Widely expected by US mid-market and enterprise buyers | Widely expected by international and many enterprise buyers |
If you are weighing the two audited frameworks, our comparison of SOC 2 vs ISO 27001 walks through the trade-offs.
When is MVSP enough, and when will buyers want more?
MVSP is usually enough while you are selling to small and mid-sized customers with light procurement, and it stops being enough once enterprise, regulated or healthcare buyers enter your pipeline. The signals are usually obvious.
MVSP is often enough when:
- Your customers are startups or small businesses that send short questionnaires, or none at all.
- You handle limited sensitive data, such as business contact details rather than financial or health records.
- You are running pilots or design partnerships where the buyer accepts a self-assessment plus a call with your CTO.
Expect buyers to require more when:
- A deal stalls because procurement asks for a SOC 2 report or an ISO 27001 certificate.
- You sell to hospitals, health systems, payers or digital health platforms that will send PHI. They will want HIPAA evidence and a signed BAA, and many will also want SOC 2.
- Your contracts include security addenda, audit rights or specific regulatory clauses.
A practical approach: adopt MVSP now and start SOC 2 readiness when the first enterprise or healthcare deal is on the horizon. The MVSP work becomes the first chunk of your SOC 2 program. When the program needs an owner, see our guide to your first security hire.
How do you use MVSP in sales and procurement?
Use MVSP as a shared vocabulary: keep a self-assessment, attach evidence, and answer questionnaires from it.
- For vendors: record a status and an evidence link for every control, so most baseline questionnaire answers come straight from it.
- For buyers: use MVSP as the minimum bar in your own vendor reviews, and ask follow-up questions only where a vendor falls short.
Revisit the self-assessment on a regular cadence and reassign control owners after team changes, so the evidence behind each answer does not go stale.
Be honest. A control marked as met that is only planned will surface the first time a buyer asks for evidence, and it damages trust more than an honest "in progress" with a target date.
How SecureSlate helps
SecureSlate helps SMB and HealthTech teams turn a baseline like MVSP into a program that grows with them. Policy templates cover incident response, access control and data handling. Continuous control monitoring flags gaps in your cloud and SaaS stack, vendor risk management keeps your subprocessor list current, and evidence collection stores proof against each control. Multi-framework mapping carries that work into SOC 2, ISO 27001 and HIPAA, and a trust center lets buyers review your posture without another questionnaire.
Start your free SecureSlate trial
FAQ
Is MVSP a certification?
No. MVSP has no certification body, auditor or badge. Vendors assess themselves against the checklist and share the result, often with supporting evidence. Buyers decide how much weight to give that self-assessment.
Can MVSP replace SOC 2?
Usually not for enterprise or regulated buyers. MVSP sets a minimum baseline, while SOC 2 provides independent CPA attestation that controls are designed and, for Type 2, operating effectively over time. Most startups use MVSP first and then build on it for SOC 2.
Does MVSP cover HIPAA requirements?
No. MVSP is industry neutral and does not address PHI, business associate agreements, HIPAA risk analysis or breach notification. HealthTech companies should add those HIPAA safeguards on top of the MVSP baseline.
How long does it take a startup to meet MVSP?
It depends on your starting point. MFA, HTTPS and backups are quick configuration changes, while a penetration test, a data flow diagram and vulnerability fix timelines take longer.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds