Medical device software development companies are vendors you hire to build Software as a Medical Device (SaMD) or the software inside a device (SiMD). This page is how to choose one: a capabilities checklist, how to read the team and the method, and the cost / timeline questions. It is not a ranking, and it is not how the software is built.
If you meant how the software is built (IEC 62304 / SaMD vs SiMD) → medical device software development. If you meant software testing → medical device software testing. If you meant software validation → medical device software validation.
If the device is imaging software, PYCAD is the imaging stack (viewer / model), not the 62304 / validation / vendor house.
You are not hiring a generalist shop
Building a Formula 1 car is not building a family sedan. A consumer-app studio can ship features. A MedTech vendor has to ship a file: ISO 13485 records, IEC 62304 lifecycle evidence, ISO 14971 risk, and a cybersecurity story that survives FDA or a Notified Body. The wrong hire shows up as a rejected 510(k), a data incident, or a product clinicians will not use.
Two products sit under the same roof. SaMD is the software itself — a phone app that scores a mole, a desktop tool that measures a lesion on an MRI. SiMD is the firmware or embedded code that makes a pump, scanner, or implant work. The how-to for that distinction is 494. Here it only changes what you ask: has this team shipped your class of software, on your path, in your clinical domain.
Capabilities checklist
| Capability | Why it matters | Ask |
|---|---|---|
| Regulatory path | 510(k) / PMA / EU MDR experience is not a certificate on the wall. It is a file they have survived. | Walk me through a 510(k) or PMA you supported. What did FDA send back? |
| ISO 13485 QMS | Without a real QMS, design controls and change control are theatre. | Show the QMS. Who owns it. Last audit finding. |
| IEC 62304 + ISO 14971 | Class A/B/C and the living risk file decide how much evidence you actually need. | How do you classify software safety. Show a risk control that became a test. |
| Cybersecurity / HIPAA | PHI and a connected device are a patient-safety problem, not an IT add-on. | Threat model, pen-test, encryption. When do you run them. |
| HL7 / FHIR | A device that cannot talk to the EHR is a silo. | Name a hospital integration you shipped and what broke. |
| V&V | Verification and validation have to be documented, not asserted. | What does your V&V pack look like. Who signs it. |
If the product is imaging AI, add one more column: annotation → training data → model monitoring. That is a different skill from “we also do ML.”
How to evaluate the shop
Track record. Case studies that match your class, your stack, and your clinical domain beat a generic sales deck. Class I logging is not Class II imaging and is not Class III life-support. Ask who the manufacturer of record was — vendors write software; they rarely hold the 510(k).
Method. “Agile” in MedTech means sprints that still emit design-control records and a risk update. A shop that documents at the end will document badly. Risk work (ISO 14971) has to move with the code, not after freeze. The lifecycle itself is medical device software development.
Team on the SOW, not the sales deck. You need software engineers plus someone who lives FDA / MDR, plus QA who can run medical-device V&V, plus UX that has sat with clinicians. Ask for names. A bench of contractors with one RA on Slack is not a team.
Three questions that cut the pitch:
- Describe the QMS and the ISO 13485 certificate — whose name is on it.
- How do you handle post-market software maintenance and vigilance. Launch-only shops go quiet here.
- Walk through a regulatory hole you hit for a client, and what you changed in the process after.
FAQ
SaMD or SiMD — does the vendor need both?
Only if your product is both. Most shops lean one way. Match the job. The definitions and the 62304 path are how the software is built.
What does it cost?
Low-risk tools can sit under $100k. Class II / III systems with clinical evidence, AI, and a real cybersecurity programme run into the high six figures or millions. Drivers: safety class, feature surface, the file (FDA or MDR), and security. Anyone quoting a single number before a risk class is selling a website.
Which standards should they actually run?
Four you will hear on every serious call: ISO 13485 (QMS), IEC 62304 (software lifecycle), ISO 14971 (risk), and HIPAA if the software touches PHI in the U.S. 62304 how-to is 494. Testing is 496. Software validation is 498.
How long to market?
Rough bands, not promises: Class I often 6–12 months; Class II with a 510(k) often 12–24 months; Class III with PMA can be years. Review clocks sit with FDA, not the vendor. A good partner writes the file as they build so the wait is the wait, not a rewrite. The class → 510(k) / PMA / De Novo tree is FDA medical device approval process.