xmodoxmodo

Frameworks · Global standards

MVSP

Minimum Viable Secure Product (MVSP) is a vendor-neutral checklist of the essential security controls an enterprise-ready product or service should implement. It has 25 controls in four categories: business, application, operational and privacy. The controls range from patch management and single sign-on to disaster recovery and staff training.

Who it applies to

It applies to software vendors that sell to enterprises whose procurement teams use MVSP as the minimum requirement. Buyers also use it to screen suppliers.

Main requirements

Business

This category covers vulnerability disclosure, customer testing, self-assessment and third-party review, training and incident handling.

Application

This category covers single sign-on, HTTPS, security headers, dependency patching, logging and encryption.

Operational

This category covers physical and infrastructure security, backup and disaster recovery.

Privacy

This category covers data handling, retention and subprocessor disclosure.

How xmodo supports it

  • 1

    The 25 controls are set up with evidence, and xmodo generates your MVSP self-assessment from them.

  • 2

    Controls map to SOC 2 and ISO/IEC 27001, which satisfy most MVSP controls, and the answers can be published in the trust center.

Related frameworks

MVSP shares requirements with the frameworks below. Controls you already run for any of them count towards MVSP as well.

Frequently asked questions

Is MVSP a certification?

No. It is a checklist that buyers use in vendor reviews. xmodo answers it from the status of your controls and publishes the result in the trust center.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo