This seems kinda cargo culty. An MVP necessarily meets the security requirements of its customers else it would not be purchased and hence is not an MVP as it is unviable in the market.
If your product is solving a pain point things like SOC compliance will be granted exemptions or an attestation will be provided until an audit is completed, this allows the customer to reap the benefits of the product while the i's are dotted and t's crossed.
agree, but also point out that this argument can be expanded to essentially make all such efforts meaningless - actual security is never captured by these documents, because it is a function of the system itself, and these documents can only by definition point to some aspects of it...
Comments
This seems kinda cargo culty. An MVP necessarily meets the security requirements of its customers else it would not be purchased and hence is not an MVP as it is unviable in the market.
If your product is solving a pain point things like SOC compliance will be granted exemptions or an attestation will be provided until an audit is completed, this allows the customer to reap the benefits of the product while the i's are dotted and t's crossed.
agree, but also point out that this argument can be expanded to essentially make all such efforts meaningless - actual security is never captured by these documents, because it is a function of the system itself, and these documents can only by definition point to some aspects of it...
p =~ np, what can I say.
Putting excess effort into things that your customers don't need isn't MVP.
These efforts aren't meaningless, they are very important when you get into enterprise sales once your product has found market fit and is maturing.