Skip to content

LegitScript certification explained

What happens after certification is granted

Certification is a monitored state renewed annually per website rather than a certificate with a date printed on it, and because the public LegitScript listing shows the current status, a lapse breaks payments, advertising and partnerships before anybody inside the business notices it happened.

By VeriScripts · · 5 min read

Approval arrives as an email and a change to a listing, and for about a week it feels like the end of a project. It is closer to the beginning of an obligation. What you now hold is assessed against your website as it is rather than as it was on the day a reviewer read it, and nearly everything that goes wrong from here is an ordinary business decision nobody connected to the credential.

Monitoring reads the live site, not the submission

Certified merchants are monitored. In practice that means the pages read during the application get read again later, along with everything added since, and the standard applied is the same one.

So the risk profile of a certified business is not the file it submitted. It is the rate at which the business ships new pages, and who writes them. A brand publishing four landing page variants a week grows its monitored surface every month, and the person writing those pages is almost never the person who assembled the application.

The failure is rarely a decision anybody made. It is a page written to a conversion brief by somebody who was never told the rules applied to them.

Renewal is a date, and dates need an owner

The annual certification fee is charged per website and falls due on the anniversary of approval rather than on a calendar the business picked. Two consequences follow.

The first is arithmetic. Certify three domains and you have three renewals, on three dates, and what actually drives the cost was decided by that domain count long before any invoice arrived.

The second is administrative, and it is the one that catches people. A renewal that lapses because a card on file expired, or because the notice went to an address a departed founder controlled, breaks the listing. The listing is what every counterparty checks.

Four ordinary events that are disclosures first

Each of these is a normal thing a growing telehealth business does. Each is a disclosure obligation before it is a marketing decision, and each is cheap to handle at the time and awkward to explain afterwards.

  • A new domain. A funnel domain, a market-specific site, a rebrand. Certification attaches to a website, so a new one that takes intake or transacts is a new application rather than an extension of an old one.
  • A change of pharmacy partner. How your product is prepared and dispensed is part of the model that was certified, which your pharmacy partner is part of your application sets out in detail.
  • A change to the clinical model or the states served. New prescribers, a new intake workflow, a state switched on in advertising targeting.
  • A new product category. Particularly one in a higher-scrutiny group, where the eligibility question is worth reopening rather than assuming.

A merchant who reports one of these has a conversation. One who is found to have made the change quietly has a different conversation, and the difference is credibility rather than compliance.

What a lapse breaks, in the order it breaks

The listing is live state rather than a certificate with a date printed on it, which is what makes a lapse expensive out of all proportion to its cause.

Downstream, things tend to fail in this order. An advertising platform review finds no current listing for the advertised domain and the account stops serving. An acquirer's periodic check flags the merchant and settlement goes under review. An affiliate network drops the offer without saying why.

None of those three sends a notice explaining that a certification lapsed, which is why what the seal and the listing actually signal is worth reading before assuming the badge in the footer is the load-bearing part.

The quarterly hour that keeps it true

This is not a compliance programme. It is one recurring calendar entry with a named owner and six things on it.

  • Read the public listing for every certified domain, and check the status is current and the domain is spelled the way you think it is.
  • Pull the domain list from the registrar again and compare it with last quarter. New domains appear without anybody announcing them.
  • Read the landing pages shipped since the last review against the claims allowlist, and note any that were never checked at all.
  • Confirm the pharmacy relationship, the state coverage and the provider roster still describe what the website says they do.
  • Check the renewal date, and who is paying it.
  • Note anything that changed, and whether it was disclosed.

Fifteen minutes a quarter keeps the file true, and the document set that makes it possible is the same one the application was assembled from. That is the argument for keeping it rather than filing it away.

Who should own it

Somebody with a foot in both camps. Certification usually sits with operations or finance, because that is who handled the processor conversation, and the pages that put it at risk are shipped by marketing. An owner planted in only one of those two places learns about the other's decisions afterwards.

The arrangement that works in most businesses is split. Marketing owns the claims allowlist and one named person reads new copy against it. Whoever owns the certification owns the renewal, the listing and the disclosure obligations. Both halves have to exist: a business with the second and not the first keeps its paperwork immaculate while its website drifts away from it.

The part worth being blunt about

Certification is not evidence that a business is behaving well. It is evidence that a private standard was met on the day it was granted, and it is monitored afterwards precisely because businesses change.

The merchants who lose it are not usually the ones who were never entitled to it. They are the ones who were, and then grew, and never told anybody.

Frequently asked questions

How often is a certified merchant checked?

Certification is a monitored state rather than a one-off assessment, so a certified website is assessed against the standard as it changes rather than only at renewal. The practical planning assumption is that anything you publish can be read at any time.

Do I have to tell anyone when I add a domain?

Yes. Every domain the business operates should be disclosed whether or not it is being certified, and a new domain that takes intake or transacts needs its own application. A domain discovered rather than disclosed damages credibility across the whole file.

What happens if my certification lapses?

The public listing shows current status, so downstream checks start failing straight away rather than at some later renewal. Advertising reviews, acquirer checks and partner screening all read that listing, and none of them will tell you the lapse is the reason.

General compliance information, not legal or medical advice.