---
url: "https://dfylegitscript.com/blog/who-requires-legitscript-certification"
title: "Who actually requires LegitScript certification, and why they do"
description: "Nobody is legally required to hold LegitScript certification, but the card networks, acquiring banks, advertising platforms and marketplaces that a telehealth business depends on have each independently adopted it as an entry condition, which is why the requirement reaches you through four different counterparties at once."
published: "2025-12-04T12:56:57+00:00"
modified: "2025-12-04T12:56:57+00:00"
---

# Who actually requires LegitScript certification, and why they do

Nobody is legally required to hold LegitScript certification, but the card networks, acquiring banks, advertising platforms and marketplaces that a telehealth business depends on have each independently adopted it as an entry condition, which is why the requirement reaches you through four different counterparties at once.

## Key takeaways

- No law requires the credential, and it still reaches you through four counterparties at once: acquirers, advertising platforms, pharmacy and fulfilment partners, and marketplace or enterprise buyers.
- On the payments side the mechanism is the acquiring bank's own obligation to register and vet a high integrity risk healthcare merchant, so your bank is passing on a rule it did not write.
- Because all four screen on the same credential, it sits upstream of payments, advertising and partnerships rather than beside them, which decides the order the work has to happen in.
- Work out which ring is actually blocking you before sequencing anything, because held settlement and a stalled affiliate conversation deserve very different urgency.

The requirement never arrives from one place. It arrives from a payment
processor, then from an ad platform, then from a fulfilment partner, each in
slightly different language, and it is easy to conclude that some regulator
somewhere has mandated it. None has. Four separate commercial ecosystems reached
the same conclusion about healthcare merchants, and certification is the
credential they all settled on.

Knowing which of them is asking, and why, changes what you do about it.

## The card networks and the banks that acquire for them

Card-not-present healthcare transactions sit in merchant categories the networks
treat as high integrity risk. That designation is not about fraud rates, it is
about the risk that the underlying transaction is for something unlawful, and it
brings registration obligations for the acquiring bank rather than for you.

Under the Visa Integrity Risk Program, an acquirer must register merchants in
those categories and is answerable for them. That is the mechanism. Your
acquirer requires certification because their obligation to the network is
easier to discharge if every healthcare merchant on their book has been vetted
by a third party the network recognises.

Which is why the requirement is usually non-negotiable at the processor level,
and why the answer to "can I find a processor who does not ask" is generally
yes, briefly, and then no.

## The advertising platforms

Google and the other major platforms restrict healthcare and medicines
advertising, and certification is the gate into the restricted categories. It is
worth being precise about the sequence, because the two applications get
conflated constantly:

1. **The certification comes first.** It certifies the website.
2. **The platform approval comes second.** It is filed per advertising account,
   it references the public certification listing, and it is reviewed by the
   platform on its own timetable.

Holding the first does not automatically deliver the second. Merchants routinely
finish certification, assume ads will now serve, and discover a further review
in the way. Building the platform approval into the plan from the start is
covered in
[Google Ads healthcare certification for telehealth](/blog/google-ads-healthcare-certification-for-telehealth).

## The pharmacy and fulfilment side

Compounding pharmacies and fulfilment partners screen the telehealth brands they
work with, and they screen hard, because their own registration and their own
liability are attached to who they dispense for. Certification is a cheap first
filter for them.

This one runs in both directions, and operators miss that. Your pharmacy partner
is checking you, and the certification reviewer is checking your pharmacy
partner. A relationship with a compounder that cannot survive scrutiny is a
problem in your application, not just in theirs.

## Marketplaces, affiliates and enterprise buyers

The fourth ring is the one nobody plans for. Affiliate networks in the health
vertical increasingly require it before they will approve an offer.
Marketplaces require it for healthcare listings. Employer and benefits buyers
ask for it in diligence questionnaires because it is a single credential that
answers a page of questions.

None of these will shut you down. They will just quietly not work with you, and
you will read it as poor conversion on partnership outreach rather than as a
missing credential.

## Why they all landed on the same standard

Because the alternative is each of them building a healthcare diligence function
of their own. A network cannot audit every telemedicine site that wants to
accept cards. A platform cannot verify every pharmacy that wants to advertise.
Outsourcing the vetting to a specialist certifier, and requiring the credential
as a condition of access, is cheaper for all of them and produces a consistent
standard for the merchant.

Accreditation from the National Association of Boards of Pharmacy is accepted by
some platforms as an alternative for the businesses it covers, and state boards
and payers recognise it more directly. It is not a general substitute, and for
most telehealth models it does not answer the question the acquirer is asking.

## What this means for sequencing

The four requirements do not arrive at once, but they do arrive in a predictable
order, and the expensive mistake is treating each as a separate fire.

Certification is upstream of all of them. Whatever forced the issue first,
usually a processor, the same credential unlocks the others, and the work you do
on your website to pass it is the same work the ad platform review will look at.
Doing it once, properly, for every domain you intend to operate is materially
cheaper than doing it three times reactively as each counterparty notices.

What that sequencing costs in time is covered in
[how long certification takes](/how-long-does-legitscript-take), and what it
costs when it goes wrong in
[what a denied application actually costs](/blog/what-a-denied-legitscript-application-actually-costs).

## Working out which ring is actually blocking you

Businesses usually arrive with one symptom and assume it is the whole problem.
It is worth mapping all four before you act, because the fix is the same
credential and the sequencing is different depending on what is at risk.

- **Payments.** Are you boarded? Is settlement being held? Has your acquirer
  asked for documentation? Anything here is urgent, because it is revenue rather
  than margin.
- **Advertising.** Are the accounts serving? Have you been asked for a
  healthcare certification at the account level? A suspended account is worse
  than a paused one, because the history goes with it.
- **Partners.** Are affiliate or marketplace conversations stalling without an
  explanation? This is the silent one, and it reads as a business development
  problem rather than a credential problem.
- **Buyers.** Has a diligence questionnaire asked for it? That usually gives you
  the longest runway of the four.

## The order that wastes the least time

Certification is upstream of all four, and the preparation work is the same work
regardless of which one forced the issue. So the sequence that wastes least is:
settle the domain architecture, fix the website, assemble the documentation, file
once for every domain that needs it, and only then work the downstream
approvals.

The expensive alternative is reactive: certify one domain because a processor
asked, then discover the advertised domain needs its own, then discover a
partner wants a third. Same work, three times, with a gap between each.

## Frequently asked questions

### Can I find a payment processor that does not require certification?

Occasionally, and rarely for long. The requirement usually originates with the acquiring bank rather than the processor, because network programs make the acquirer answerable for merchants in high integrity risk categories, so a processor who waives it is generally between acquirers rather than exempt.

### Is NABP accreditation an alternative?

For some businesses and some platforms, yes. Accreditation from the National Association of Boards of Pharmacy is accepted by certain advertising platforms and is recognised more directly by state boards and payers, but it is not a general substitute and does not usually answer what an acquirer is asking.

### Do I need certification before I have a payment processor?

You need it before the processor will go live, and certification requires a website that is substantially complete. Most operators build the site, prepare the application against it, and run the processor application in parallel rather than in sequence.

## Disclaimer

LegitScript is a trademark of LegitScript LLC. VeriScripts is an independent application-preparation service. It is not affiliated with, endorsed by, or certified by LegitScript LLC, and claims no sponsorship or partnership with it. We prepare, submit, and manage the application; LegitScript alone decides whether certification is granted. "LegitScript" is used here only to name the certification these applications are for.
