Minimum viable company (MVC)

Minimum viable company (MVC)
  • Insight
  • 08 Oct 2026

For decades, optimising was awarded. Slick balance sheets, supply chains that were just in time, sole source technology frameworks and worldwide models for delivery. The theory behind this was when disruption would come, all the operating processes remained stable and usable. 

That was yesterday. Disruption is not an if question anymore but when. Cyber-attacks take down whole enterprises. Cloud usage and software elements malfunction without prior notice. Geopolitically sensitive supply chains. Unpredictable weather and energy disturbance can disrupt electricity, fuel supplies, and operational facilities on a large scale.

These conjoining blowouts arrive faster and hit harder than organisations can endure. Looking at the ability to respond to a major incident, six per cent of organisations claim to be ‘very capable’ across all substantial aspects.

Your organisation depends on a core set of services and processes to keep running when disruption hits. Our minimum viable company (MVC) approach strengthens your business resilience by helping you identify the capabilities, processes and dependencies that are essential to delivering your most critical services. It connects business continuity, cyber resilience, operational resilience, technology, data and third-party dependencies into one practical framework. By defining what must remain operational and designing recovery options in advance, you can limit disruption, protect stakeholder trust and recover within agreed outage tolerances.

Minimum viable company is the smallest set of capabilities that must remain operational to keep the organisation running through severe disruptions. This model has three components, which allows organisations to deliver critical strategic outcomes during a crisis.

  1. Vital outward-facing solutions and services
  2. Vital behind-the-scenes activities and procedures
  3. Essential underlying components

Define the minimum viable company

Managers prefer to know wether the organisation is resillient enough to withstand a disruption when it appears. Additionally, this means questioning if spending on resilience can generate tangible returns instead of being viewed solely as a cost. Through revenue protection, capital preservation, reduced regulatory risk, maintained trust, and accelerated recovery, resilience investments demonstrate their value. The concept of a MVC plays a crucial role in addressing these challenges during the most severe disruptions.

Your leadership faces a clear question: what does ‘viable’ really mean for your organisation when you focus on any type of crises that matter most. This starts with deciding what must stay up and running, instead of treating every system and service as critical.

Together, we map out a clear timeline of your essentials: the most important services, customer commitments, internal workflows, technology and third-party connections, regulatory requirements, acceptable impact levels, and recovery priorities. This gives you a clear understanding of how your MVC functions within the Dutch and broader European landscape, and highlights the areas where you should focus your efforts first.

‘Deciding what is truly essential to keep delivering value, protect trust, and remain resilient when disruption strikes is at the heart of defining a Minimal Viable Company and a C-suite priority.’

Mimoent Haddouti,partner cyber, data, technology & risk, PwC Netherlands

Design solutions for delivering your MVC

Designing solutions for your MVC turns business resilience ambitions into practical capabilities. This means bringing together your existing strengths across business continuity, disaster recovery, cyber security, supply chain, physical security and wider operational resilience, and aligning them with the dependencies that support your most critical services. The result is an integrated resilience approach that enables the organisation to absorb disruption, adapt its operations and continue delivering what matters most.

The right answer for you might be a manual workaround, a substitution, an alternative supplier, or a trusted ‘technology lifeline’ you can switch to when your primary environment is at risk or cannot be trusted. Every design choice should bring together business, technology, data, third-party, and operational requirements so they act as a cohesive whole.

Different parts of your business may require different MVC setups. That could include a minimum viable factory for asset-heavy operations, or a minimum viable business for specific lines of service. We’ll work with you to develop and test these options, ensuring they are practical, resilient, and ready to support you when it counts most.

Digital sovereignty and third party risk management

Defining your MVC is only the starting point. To determine whether it will hold up in practice, it is essential to assess your MVC against the scenarios that are most relevant and impactful for your organisation. These may include digital sovereignty challenges, cyber incidents, third party risk management failures, or other disruptions specific to your operating environment and risk profile. Applying these scenarios helps reveal vulnerabilities, dependencies and difficult choices before a crisis occurs, enabling you to strengthen the capabilities needed to keep critical operations running under pressure.

A resilient MVC also depends on how effectively you manage technology and third-party dependencies. Digital sovereignty helps clarify where control lies over critical data, infrastructure and access, while Third Party Risk Management provides insight into the suppliers, service providers and digital platforms your essential operations depend on. By identifying concentration risks, strengthening oversight and developing viable alternatives and contingency plans, you can help keep your organisation operational when a critical provider or technology environment becomes unavailable or can no longer be trusted.

'Resilience is not about protecting everything; it's about knowing what matters most. A Minimum Viable Company turns uncertainty into clarity and crisis into confident action.'

Bram van Tiel,partner cyber, data, technology & risk, PwC Netherlands

Digital sovereignty and strategy 

What do digital sovereignty, cloud strategy, data ownership and technological resilience mean for your organisation? 

Read more about digital sovereignty and cloud strategy 

Third party risk management 

How well do you understand and manage the suppliers, service providers and digital platforms your critical operations depend on?

Explore more about third party risk management

Deploy and test your MVC solutions

You want to be confident that your MVC’s cyber and resilience setup can withstand serious, real-world threats. Together, we’ll put your plan to the test against tough but realistic scenarios that match today’s threat landscape.

Through these tests, you’ll see clearly how all parts of your organisation, people, systems, data, locations, and partners, depend on each other in practice. At the same time, your leadership team gets the chance to rehearse real decision-making, so when it matters most, you’re ready and united.

These tests also help validate critical dependencies, including third-party providers and key technology services, refine MVC playbooks and recovery sequencing, and identify improvement opportunities before a real disruption occurs. This helps ensure your recovery approach is practical, coordinated, and effective when it matters most.

Drive, monitor, and improve the MVC

Your MVC framework sits at the centre of how you govern and continuously strengthen Business Resilience across your organisation. Clear ownership, regular scenario testing, executive oversight and a fixed update cycle keep the MVC aligned with changes in your business, operating model and risk profile. Key Resilience Indicators give your board a concrete view of whether critical capabilities remain current, tested and understood, and whether the organisation can continue operating within agreed tolerances and risk appetites.

Questions and answers

A minimum viable company (MVC) is the smallest combination of business services, processes, people, technology, data and external dependencies needed to keep an organisation financially, operationally and strategically viable during a major disruption. Its purpose is to determine what absolutely must continue to operate for the organisation to survive, thereby safeguarding continuity efficiently.

Organisations today depend on complex chains of technology, data, suppliers and critical customer services. When a cyber attack, technology platform outage or third-party disruption occurs, an organisation must be able to determine quickly which services should be protected or restored first. A minimum viable company helps leaders make these decisions in advance, enabling faster recovery while preserving customer trust.

Operational resilience focuses on protecting and restoring important business services during disruptions. A minimum viable company goes a step further by considering the smallest set of services, internal processes and dependencies needed to keep the organisation as a whole viable. Operational resilience asks: which services must continue to function? MVC asks: what must continue to operate for the organisation to survive?

A minimum viable company comprises three components:

  1. Critical external services for customers and stakeholders.
  2. Critical internal processes, such as crisis management, compliance, communications and financial processes.
  3. Fundamental dependencies, including technology, data, employees, suppliers and infrastructure.

Together, these three elements form the foundation that enables an organisation to continue operating during a crisis.

An increasing body of legislation and regulation requires organisations to strengthen their digital operational resilience and identify critical services and dependencies. A minimum viable company provides a governance framework that helps organisations set priorities and direct investment towards the processes and technology essential to continuity and recovery. This not only supports compliance with DORA and NIS2, but also provides a clearer view of what is needed to keep the organisation operationally and financially viable during a major disruption.

An organisation depends on cloud providers, software suppliers, payment infrastructure and other external parties. If one of these parties becomes unavailable, critical services may be affected immediately. Third-party dependencies should therefore form part of the minimum viable company and be actively incorporated into resilience and recovery strategies.

AI can help organisations map dependencies between processes, systems and suppliers more quickly. Technologies such as digital twins and continuous monitoring can also support organisations in testing, maintaining and updating their minimum viable company. This makes their resilience less dependent on static plans and turns it into a capability that can be managed continuously.

Board members should ask themselves at least five questions:

  1. Do we know which services must continue to operate for us to remain viable in the event of a major crisis?
  2. Have we tested these priorities in a realistic crisis scenario?
  3. Can we demonstrate the value of investments in resilience?
  4. Are we using AI, monitoring and other technologies to improve our resilience continuously?
  5. Do we have sufficient visibility of our critical dependencies on suppliers, regulators and infrastructure?

Organisations that answer these questions in advance are better prepared for future disruptions and can recover more quickly.

Download the publication

The survival core: your minimum viable company for enterprise resilience

Questions? Feel free to reach out to us:

Mimoent Haddouti
Mimoent Haddouti

Partner cyber, data, technology & risk, PwC Netherlands

Bram van Tiel
Bram van Tiel

Partner cyber, data, technology & risk, PwC Netherlands

Peter Avamale
Peter Avamale

Partner cyber, data, technology & risk, PwC Netherlands

Ewout Stoops
Ewout Stoops

Partner cyber, data, technology & risk, PwC Netherlands

Follow us