Minimum Acceptance Criteria

Mandatory baseline conditions set by a business unit. These conditions are included in the acceptance criteria for every user story from that unit, and any functionality delivered must meet them for the Product Owner to accept the work.

Key Points

  • Defined by the business unit, not by the delivery team.
  • Applied to every user story from that unit as part of its acceptance criteria.
  • They are the minimum bar; story-specific criteria can be added but cannot weaken them.
  • Product Owner acceptance depends on meeting these conditions; unmet items block acceptance.

Example

A finance business unit sets minimum acceptance criteria such as audit logging, encryption of sensitive data, and role-based access. A user story like "Export monthly statements" must implement logging of all exports, encrypt files at rest and in transit, and restrict access to authorized roles; otherwise the Product Owner will not accept the story.

PMP Example Question

In an agile project, what best describes Minimum Acceptance Criteria for a business unit?

  1. The team's Definition of Done for all backlog items across the program.
  2. Baseline conditions set by the business unit that every one of its user stories must satisfy to be accepted.
  3. Optional stretch goals the team pursues if there is extra capacity.
  4. The Product Owner's personal preferences for the current sprint only.

Correct Answer: B — Baseline conditions set by the business unit that apply to all of its user stories

Explanation: Minimum Acceptance Criteria are mandatory, unit-defined conditions included in each user story's acceptance criteria and used by the Product Owner for acceptance; they are not optional, not the team's Definition of Done, and not ad hoc preferences.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Advance your Lean Six Sigma expertise!

HK School of Management helps you take Lean Six Sigma to the next level—without the overwhelm. Master advanced statistical tools, Excel-based analysis, and real-world improvement techniques to solve complex problems with confidence. For the price of lunch, you get practical templates, guided examples, and hands-on project experience you can use immediately at work. Backed by our 30-day money-back guarantee—zero risk, real impact.

Learn More