LegitScript certification explained
Applying before you have launched, and what has to exist first
Certification assesses a website, so a pre-launch telehealth business cannot file against a landing page and a promise, and the sequencing question that decides a launch date is which parts of the build have to be finished before a LegitScript application can be submitted at all.
By VeriScripts · · 5 min read
Founders building a telehealth business hit this in planning. Payments and advertising both need certification, certification needs a website, and the website is the thing being built. Sequenced badly, that becomes a launch that slips twice: once waiting for the site, once waiting for a review that could have started earlier.
The constraint
Certification assesses a website. Not a business plan, not a staging link behind a password, not a coming-soon page with an email capture. The review reads what a patient would read: what the product is, who prescribes it, what it costs, what happens after purchase.
So a substantially complete site is the entry condition, and "substantially complete" is a lower bar than "finished". It does not mean every variant is built or the blog has posts. It means the pages that carry the substance exist and say what they will say.
What has to be real before you can file
Six things, and they are the same six the review is going to read.
- The product pages, including what the preparation is, whether it is compounded, and who prepares it.
- The clinical model, described. Who prescribes, under what licences, what the intake involves, and that a prescriber may decline.
- Pricing and subscription terms, where a patient can see them before paying, including what renews and how to stop.
- The legal and privacy documents, with a website privacy policy and a Notice of Privacy Practices as two documents rather than one wearing two names.
- Contact routes, including how a patient raises a clinical concern and how an adverse event is reported.
- The pharmacy relationship, documented internally even where the site names it only in passing.
What does not have to be finished: your design system, your paid funnel, your email programme, your affiliate creative. Those are places the claims problem will later be introduced, which is a reason to write the allowlist early rather than a reason to delay.
The order that wastes least
Certification is not the last step before launch and it is not the first. It sits in the middle, and the parts of it that take longest are parts you can start on day one.
- Decide the domain architecture before you buy anything. Every domain that takes intake or transacts is its own application, so the funnel-per-offer plan a growth team sketches in week one is a cost decision before it is a marketing one.
- Write the claims allowlist alongside the product, not after the copy. It is far cheaper to write compliant copy than to rewrite persuasive copy.
- Collect the corporate, clinical and pharmacy documentation while you build. It depends on third parties and it takes longer than anybody plans for.
- Finish the substantive pages, then file.
- Run the processor conversation in parallel, because underwriting asks for overlapping evidence and the acquirer will want the certification before going live either way.
- File the platform advertising approvals last, once the listing exists, because that is a second application rather than a consequence of the first.
The mistakes specific to pre-launch businesses
Filing against a site that is still a placeholder. The application fee is charged when you apply and is not refunded whatever the reviewer decides, so an application filed against an unfinished site spends money to learn what you already knew.
Building the funnel before the allowlist exists. New businesses write their strongest claims first, when the product is most exciting and nobody has told them what may not be said. Rewriting that copy later is harder than writing it correctly, because by then it is what the team believes the brand sounds like.
Registering a domain per offer. Three test funnels on three domains is three applications and three annual renewals. Paths on one certified domain test the same thing.
Assuming the launch date is yours to set. The preparation clock belongs to you. The review clock does not, and what LegitScript will and will not commit to is worth reading before a launch date is announced to anybody outside the business.
If you only have a month, build in this order
Founders arrive at this article with a launch date already promised to somebody, so here is the triage that protects the most of it.
Week one: the domain decision and the pharmacy paperwork. Both gate other work and one of them depends on a third party's calendar. Decide what gets certified, what redirects, what never gets registered, and ask your compounder for its entity, registration and state licensure the same day.
Week two: the product and clinical pages. What the preparation is, who prescribes, what the consultation involves, and that a prescriber may decline. Write them against the allowlist rather than writing them twice.
Week three: money and privacy. Pricing, renewal terms and the cancellation route where a patient can see them, then the two privacy documents and the contact routes.
Week four: read it as a stranger. Open the site cold and try to find, in under a minute each, what the product is, who prescribes it, what it costs to keep receiving it and how to stop. Fix what you cannot find, then file.
Everything else, the paid funnel, the email programme, the affiliate creative, happens after submission and gets read against the allowlist as it ships.
What to tell your investors and your calendar
Two clocks, stated separately, because merging them is how a plan becomes undeliverable. The first is preparation: assembling the file and getting the website to the state a reviewer would pass. That is work you schedule. The second is the review, which begins on submission and runs as long as the questions take.
Expedited processing buys a start rather than a finish. It moves an application forward so that review begins within two business days of submission, which is worth having when waiting is what costs you money and worth nothing at all against a file that is not ready.
The honest recommendation
Build the substantive pages first, write the allowlist alongside them, collect the documentation in parallel, and file once rather than twice. A pre-launch business has one genuine advantage over an established one: nothing is live yet, so nothing has to be unpicked. Almost every expensive certification problem in this industry is a decision made early and discovered late.
Frequently asked questions
Can I apply before my website is live?
The review reads the website, so a site that is substantially complete is the entry condition. That means the pages carrying the product, the clinical model, the pricing, the terms and the privacy documents exist and say what they will say, not that every variant and campaign is built.
Can I certify a staging site behind a password?
No. The reviewer reads what a patient would read, and a site nobody can reach answers nothing. Get the substantive pages onto the public domain you intend to certify, then file.
How early should I decide my domain architecture?
Before you buy the domains. Certification attaches to a website, so a plan built on one funnel domain per offer multiplies both the application work and the annual renewals, and it is far cheaper to test offers as paths on a single certified domain.
More on LegitScript certification explained
General compliance information, not legal or medical advice.