Frameworks · Global standards
MVSP
Minimum Viable Secure Product (MVSP) is a vendor-neutral checklist of the essential security controls an enterprise-ready product or service should implement. It has 25 controls in four categories: business, application, operational and privacy. The controls range from patch management and single sign-on to disaster recovery and staff training.
Who it applies to
It applies to software vendors that sell to enterprises whose procurement teams use MVSP as the minimum requirement. Buyers also use it to screen suppliers.
Main requirements
Business
This category covers vulnerability disclosure, customer testing, self-assessment and third-party review, training and incident handling.
Application
This category covers single sign-on, HTTPS, security headers, dependency patching, logging and encryption.
Operational
This category covers physical and infrastructure security, backup and disaster recovery.
Privacy
This category covers data handling, retention and subprocessor disclosure.
How xmodo supports it
- 1
The 25 controls are set up with evidence, and xmodo generates your MVSP self-assessment from them.
- 2
Controls map to SOC 2 and ISO/IEC 27001, which satisfy most MVSP controls, and the answers can be published in the trust center.
Related frameworks
MVSP shares requirements with the frameworks below. Controls you already run for any of them count towards MVSP as well.
Frequently asked questions
Is MVSP a certification?
No. It is a checklist that buyers use in vendor reviews. xmodo answers it from the status of your controls and publishes the result in the trust center.