I just went through LegitScript certification, so this is written while it is all still fresh. If you run a business in a regulated or "high-risk" category and you want to advertise on Meta or Google, or you want to keep a stable relationship with a payment processor like Stripe, there is a decent chance someone has already told you that you need to be "LegitScript certified." And there is an equally decent chance that nobody actually explained what that means, why it exists, or what you are walking into.
So here is the plain version. Everything below is public information, pulled from LegitScript's own materials and the card network rules that sit underneath all of this. My goal is that by the end you understand the why, not just the checklist, because the why is what tells you how to prepare.
First, what LegitScript actually is
LegitScript is a private, for-profit company based in Portland, Oregon. It was founded in 2007, originally to police rogue online pharmacies, and it has since expanded into monitoring and certifying merchants across a whole range of high-risk industries. That is the first thing worth internalizing: it is a business, not a government agency and not an industry board. It does not issue licenses. It is not a regulator.
What it sells is essentially two things: a certification credential (a seal that says you have been vetted), and ongoing monitoring (someone continuously watching whether you still behave). Those two things are related but not the same, and confusing them is one of the most common mistakes people make. More on that below.
Why Meta, Stripe, and basically everyone else uses it
Here is the part that made everything click for me, and it is the part almost nobody explains.
LegitScript is basically hired by companies like Meta and Stripe to make sure that you, the merchant, comply with the rules. Not because those companies are being nice, but because they are legally and financially on the hook for who they do business with. This is called vendor management, and it applies to essentially every large company, not just the payment and ad giants. The difference is that the big platforms and processors have the scale, the regulatory scrutiny, and frankly the deep pockets that make them a target, so they take it seriously and they build gatekeepers into the process.
Think about it from their side. If Stripe processes payments for a merchant selling something illegal or dangerous, Stripe can get fined, lose its standing with Visa and Mastercard, and take serious reputational damage. If Meta runs ads for a sketchy telehealth operation that harms someone, Meta owns a piece of that mess. They are liable for the behavior of the companies they enable. That is the whole ballgame.
Now, the platforms could theoretically build giant internal teams to actively and continuously vet every merchant and advertiser in a regulated category. But that is expensive, slow, and not their core business. So instead they delegate those reviews to a third-party vendor whose entire job is compliance. That vendor is LegitScript. The platform gets a compliance shield and someone else to point to. LegitScript gets a recurring revenue stream. And the merchant, meaning you, pays for it and does the work. Everybody in the chain has a rational reason to want this to exist, which is exactly why it is not going away.
So when you hear "you need LegitScript to run on Stripe" or "you need LegitScript to advertise on Meta," what is really happening is that those companies have outsourced the question of "is this merchant safe to work with" to a specialist, and the certification is the specialist's answer.
When you actually need it (and who this applies to)
You do not need LegitScript to sell t-shirts. This is specifically for regulated and high-risk categories where there is real legal exposure. In practice that means industries like:
- Online pharmacies and telemedicine
- Broader healthcare and health-adjacent services
- Addiction treatment and recovery
- CBD and cannabis-related products
- Supplements, nutraceuticals, peptides, and similar products
If you are in one of these lanes, certification tends to become a prerequisite the moment you try to do one of two things: advertise, or process payments at scale.
On the advertising side, platforms including Google, Meta, Microsoft, LinkedIn, and TikTok require LegitScript certification before they will let you run paid ads in these categories in the markets where they enforce it. Without it, your ads get disapproved and your accounts can get flagged.
On the payments side, the card networks are the pressure point. Visa and Mastercard recognize LegitScript certification as part of their high-risk merchant registration process, specifically for merchant category codes like 5122 (drugs and pharmaceuticals) and 5912 (drug stores and pharmacies). Mastercard has been tightening its merchant monitoring program standards heading into 2026. Payment processors and acquiring banks live and die by their standing with the card networks, so they push those requirements down onto you. That is why a processor will condition your account on getting certified, and why they may drop you if you do not.
The short version: if a platform or a processor has told you that you need it, it is because their own liability rules require it, and that requirement usually traces back to state and federal law. LegitScript's job is to confirm you comply with guidelines that are, in many cases, downstream of actual statutes and regulator expectations.
Certification versus monitoring, because people mix these up constantly
This distinction matters, so I am giving it its own section.
Certification is the one-time (well, annually renewed) review that gets you the seal. You apply, you get vetted, you pass, you display the badge, and now the platforms and processors that trust LegitScript will trust you.
Monitoring is the continuous part. Once you are certified, LegitScript keeps watching. If your website changes, if your checkout flow starts doing something it should not, if your marketing claims drift out of bounds, that can generate a monitoring flag even though you were already certified. And here is the twist a lot of people miss: you can be monitored without ever being certified. Processors and platforms run LegitScript monitoring across whole portfolios of merchants who never applied for anything. Certification is you opting in and proving yourself. Monitoring is the surveillance layer that never turns off.
So passing the audit is not the finish line. It is the beginning of an ongoing relationship where you are expected to stay compliant, not just look compliant on the day you applied.
Common misconceptions worth clearing up
"LegitScript certification means I am fully compliant." No. It means you passed LegitScript's specific standards. It is not a substitute for your state medical board registration, your DEA registration, your board of pharmacy licensing, or anything else a real regulator requires. It is one compliance layer sitting on top of the actual legal ones, not a replacement for them.
"It is a HIPAA certification or a clinical accreditation." Also no. It is not HIPAA certification, and it is not a clinical accreditation like the Joint Commission or CARF. Different things entirely. LegitScript may want to see that you handle data responsibly, but the seal is not a HIPAA stamp.
"Once I am certified, my ads will run automatically." Getting certified clears one prerequisite. It does not guarantee your Google or Meta ads go live cleanly. You still need the platform's own ad approvals and compliant landing pages. Certification opens the door; it does not walk you through it.
"It is a government thing." It is a private company. Trusted and widely adopted, yes, but private and for-profit. Understanding that helps you approach the process like what it is: a vendor review with a paying-customer relationship, governed by clear published standards.
"If I pass once I am done." Covered above, but worth repeating: monitoring is continuous, and renewal is annual and per-domain.
What the process actually entails
Here is the meat of it, since this is what people really want to know before they start.
At a high level you create an account on LegitScript's certification portal, choose your certification type, pay the application fee, fill out a detailed questionnaire, upload supporting documents, and then go through analyst review. That review is where the real work happens, and it is genuinely an audit.
They look at your website. All of it. And you are required to disclose every website you operate as part of the application. Do not try to hide a domain. They look at your checkout flow, your product and service descriptions, your claims, your policies, and your disclosures. A surprising number of applications stumble on checkout ambiguity and on health claims that go further than what the FDA allows for a given product type.
They look at your social media and marketing. Your public presence is part of the picture. The claims you make in ads and on social are fair game, because that is exactly the behavior the platforms are worried about.
They look at your partners and business affiliations. Who you work with matters. Your relationships, affiliates, and downstream or upstream partners get scrutinized, because risk travels through those connections. This is one of the standards people underestimate.
They evaluate you against a defined set of standards. LegitScript's healthcare certification, for example, is built around nine standards covering things like legal compliance, privacy and security, business transparency, patient safety, prescription and controlled-substance practices, business affiliations, marketing claims, and having real ongoing compliance systems in place. Many of these map directly back to state and federal law, which is the point. LegitScript is checking that you comply with rules that exist to keep people safe.
They ask follow-up questions. Expect this. Most applications require at least one round of back-and-forth. An analyst will come back with questions, ask for clarification, and request more documentation. This is normal and it is not a sign you are failing. Vague answers, though, are one of the biggest causes of delays and denials, so treat every follow-up as a chance to be specific and complete rather than something to brush off.
Cost and timeline, so there are no surprises
The pricing is public. As of now the application fee is around $975, non-refundable, charged per website. Annual certification runs roughly $2,150 per domain per year. There is an expedited review option (in the ballpark of a few hundred dollars extra) that can compress a multi-month timeline down to weeks.
On timeline: LegitScript does not promise a fixed turnaround. How long it takes depends on the order your application came in, how complex your business is, how fast you respond to follow-ups, and how clear and sufficient your answers are. Two of those four factors are entirely within your control, which is the whole argument for preparing well.
The per-domain pricing is also a reason to audit your own footprint before you apply. If you are running five domains that could be consolidated, you are looking at five sets of fees. Know what you actually need certified.
How to prepare (the part that saves you the most pain)
Everything about this process rewards being organized and honest up front, and punishes vagueness. Here is how I would approach it.
Get your documents together before you start. That typically means business registration, any professional licenses and credentials, sample intake or patient forms if you are in healthcare, clear product and service descriptions, your privacy policy and terms, and evidence of how you handle sensitive data. Having these ready turns a multi-week scramble into a smooth submission.
Read your own website like an auditor would. Walk your checkout flow end to end. Look for anywhere a customer could be confused about what they are buying, especially on anything prescription-related. Read every health claim on your site and in your ads and ask whether you can actually back it up, because claims that exceed what is allowed for your product category are a top reason applications fail.
Disclose everything. Every domain, every relevant affiliation. The process is built to find what you leave out, and leaving something out reads as a red flag even when the thing itself was harmless.
Answer follow-ups fully and specifically. When an analyst asks a question, give them a complete, concrete answer with documentation rather than a one-line reply. Applicant responsiveness and answer quality directly drive how fast you get through, and how you get through at all.
Treat it as ongoing, not one-and-done. Since monitoring continues after you pass, build the habit of keeping your site, your claims, and your partnerships compliant going forward. The goal is not to look clean on submission day. It is to actually be clean, so that a monitoring flag never has anything to catch.
The bottom line
LegitScript certification is not a hoop for the sake of a hoop. It exists because the platforms and processors you want to work with, Meta and Stripe and the card networks behind them, are liable for the merchants they enable, and rather than monitor everyone themselves they delegate that vetting to a specialist vendor. Certification is that vendor's way of saying you are safe to do business with, checked against standards that largely trace back to real state and federal law.
Once you see it that way, the whole thing gets less mysterious. You are not trying to satisfy an arbitrary gatekeeper. You are proving, to a professional reviewer, that your business genuinely complies with the rules that keep customers safe. Prepare like that is true, because it is, and the process is far more manageable than it looks from the outside.
How Camino helps: We prep merchants for LegitScript certification end to end — auditing your site, marketing claims, and checkout against the standards; assembling the documentation package; and staying on as your monitoring backstop after you pass. Book a free 15-minute call if you want a second set of eyes before you submit.

