---
url: "https://dfylegitscript.com/blog/what-a-complete-legitscript-application-file-looks-like"
title: "What a complete application file actually looks like"
description: "A complete LegitScript application file is one where every question a reviewer could reasonably ask has already been answered in the submission, which in practice means five bodies of evidence assembled before filing rather than four assembled during the review."
published: "2025-12-28T13:10:56+00:00"
modified: "2025-12-28T13:10:56+00:00"
---

# What a complete application file actually looks like

A complete LegitScript application file is one where every question a reviewer could reasonably ask has already been answered in the submission, which in practice means five bodies of evidence assembled before filing rather than four assembled during the review.

## Key takeaways

- Complete means there is nothing left for a reviewer to ask, which is a much higher standard than every field on the form being filled in.
- Five bodies of evidence make up the file: identity and structure, the domain estate, the clinical model, the supply chain, and a website that has been audited rather than merely submitted.
- Three tests decide whether it is finished: does every account agree, would a stranger reach the same description, and is there one named owner for the duration.
- The file has a second life, because an acquirer, a marketplace and an enterprise diligence questionnaire ask for most of it again within the year.

"Complete" is not a synonym for "every field filled in". A complete file is one
where a reviewer reading it has nothing left to ask, and that is a higher and
more useful standard. Here is what it contains.

## One: identity and corporate structure

The entity that operates the business, its registration, its ownership, and its
principals. Where there are several entities, a professional corporation
employing the clinicians and an operating company running the brand, the
relationship between them stated plainly rather than left to be inferred.

Prior enforcement or regulatory history attached to the business or any
principal belongs here too. Disclosed, it is a fact with context. Discovered, it
is a credibility problem that colours the rest of the file.

## Two: the domain estate

Every domain the business operates, from the registrar account rather than from
memory, with a decision recorded against each one: certifying, redirecting only,
or retiring.

This is the section with the biggest cost consequence, because certification
attaches to a website. It is also the section most often incomplete, because
nobody in the business has the full list. Pull it from the registrar, the DNS
provider and the hosting account, not from the marketing team.

[What actually drives cost](/legitscript-certification-cost) is largely decided
here.

## Three: the clinical model

Who prescribes, under what licences, in which states, after what kind of patient
interaction.

Concretely: the provider roster with licence numbers and states, the medical
director, the entity that employs or contracts the clinicians, the intake
workflow, whether the encounter is synchronous or asynchronous, the
contraindication screening, what happens when a prescriber declines, the
follow-up cadence, and the adverse event route.

A state coverage matrix is worth building even though nobody asks for one in
that form: states you market in against states your prescribers are licensed in
against states your pharmacy can ship into. Gaps between those three columns are
the questions you would otherwise receive.

## Four: the supply chain

The dispensing pharmacy by legal entity, its registration type, its state
licensure, the scope of what it prepares for you, and the agreement itself.

The registration type matters and is frequently misstated:
[the distinction between a traditional compounding pharmacy and an outsourcing facility](/blog/503a-versus-503b-what-legitscript-asks-about-your-compounder)
carries different permissions, and describing your partner as the wrong one
introduces an inconsistency into your own file.

## Five: the website, audited rather than submitted

The largest piece of work and the one that decides most applications.

The audit covers every page a patient can reach, which is more than the site
map: landing page variants still receiving traffic, quiz result screens, email
sequences, support macros, affiliate creative, and the shop.

What it looks for: claims that overstate what the product is, comparisons to
approved products, implied outcomes, testimonials doing claim work, provider
descriptions that are vague, subscription terms that are hard to find,
cancellation paths that are hard to use, a privacy policy standing in for a
Notice of Privacy Practices, and tracking on pages where patients discuss
conditions.

The output is a claims allowlist per product plus a fix list. Both are useful
long after the application, because they are what stops the next landing page
reintroducing the problem.

## What complete feels like

Three tests, and they are more reliable than a checklist.

**The consistency test.** Application, website, public record and partners all
say the same thing about ownership, prescribing and fulfilment. Read them side
by side and look for the sentence that differs.

**The stranger test.** Could somebody who has never seen your business, reading
only your submission and your website, describe accurately what you sell, who
prescribes it, who makes it and what it is not? If not, that gap is a request for
information waiting to be sent.

**The named owner test.** One person, available for the duration of the review,
with access to every document above and the ability to get a website change
deployed. A file without that person is not complete however good the paperwork
is.

## Keep it as a document, not as a form you once filled in

The file is worth existing as an artefact of its own, separate from whatever
application form it eventually gets typed into. One folder, an index listing
what is in it, a date against each item and a named owner.

That reads as administration for its own sake right up until the first request
for information arrives, at which point the difference between having the file
and having the facts somewhere is the difference between a lookup and a search.

It has a second life too. An acquirer re-underwriting you, a marketplace running
diligence and a buyer in a data room all ask overlapping questions, and they ask
them at inconvenient times. A file that exists answers them in an afternoon. A
file that has to be reassembled from five people's inboxes takes a fortnight and
arrives inconsistent, which is the same defect the reviewer was looking for.

## Assembling it is the whole job

Nothing above is secret and none of it requires an outsider. What it requires is
somebody treating it as a project with an owner and a deadline rather than as a
form to be completed between other things, which is
[the loop self-filed applications fall into](/blog/the-rework-loop-that-stalls-self-filed-applications).

## The order to assemble it in

Sequence matters, because two of these five sections gate the others.

Start with the domain estate, because it decides how many applications there
are and therefore the scope of everything downstream. A business that audits one
website and then discovers three more has audited the wrong amount.

Then start the website audit immediately, because it is the long pole. Fixing
claims copy is a copywriting and engineering task with a queue in front of it,
and every day it does not start is a day added to the end.

Corporate structure, clinical model and supply chain can then run in parallel.
They are collection work: documents that exist somewhere and need finding,
chasing and checking. The pharmacy documentation is the one to start earliest of
the three, because it depends on a third party's response time rather than on
yours.

## Keeping it current after approval

The file is not disposable. Certification is monitored, partners run periodic
diligence, and acquirers re-underwrite.

Four events should trigger an update: a new domain, a change of pharmacy
partner, a change to the clinical model or the states served, and a new product
category. Each of those is a disclosure obligation before it is a marketing
decision, and each is cheap to handle at the time and awkward to explain later.

Set an owner and a quarterly review. Fifteen minutes a quarter keeps the file
true, which is a very small price for never having to reconstruct it under
pressure.

## Frequently asked questions

### What is the single most incomplete part of a typical file?

The domain list. Almost every business has more domains than the people filing remember, and an undisclosed domain found during review is one of the most damaging cheap problems in the process.

### Do I need to supply the pharmacy agreement itself?

Supplying it up front is cheaper than being asked. The reviewer needs to establish the dispensing entity, its registration and its permitted scope, and the agreement answers several questions at once.

### How long does assembling a complete file take?

The corporate and clinical documentation is usually days. The website audit is the long pole and is normally the constraint, because fixing claims copy is an engineering and copywriting task rather than a paperwork one.

## Disclaimer

LegitScript is a trademark of LegitScript LLC. VeriScripts is an independent application-preparation service. It is not affiliated with, endorsed by, or certified by LegitScript LLC, and claims no sponsorship or partnership with it. We prepare, submit, and manage the application; LegitScript alone decides whether certification is granted. "LegitScript" is used here only to name the certification these applications are for.
