Clinical Trial Site Software: Buy the Management System, and Build Only the Operational Layer Above It
Three or more sites, or one site past roughly fifteen concurrent protocols, is the line. Below it, one senior coordinator can still hold the whole portfolio in their head and a packaged clinical trial management system plus disciplined paper source is genuinely enough.
On this page
Three or more sites, or one site past roughly fifteen concurrent protocols, is the line. Below it, one senior coordinator can still hold the whole portfolio in their head and a packaged clinical trial management system plus disciplined paper source is genuinely enough. Above it nobody can, and the operation quietly hires a person whose real job is to be a human integration layer between a whiteboard, a management system and nine sponsor portals. Most sites reading this sit below the line and should buy.
When is off the shelf genuinely the right call here?
Clinical Conductor and RealTime CTMS are the two clinical trial management systems most independent research sites end up on, and for a large share of sites they are the correct and final answer. They hold the clinical trial agreement, the budget, the per visit payment terms and the invoicing, and they hold them properly. Rebuilding any of that is money spent to arrive back where you started.
Buy, and stop there, if this describes your operation:
- One site running under about eight concurrent protocols.
- Two or three coordinators who can each name every active subject without looking.
- A deviation log dominated by clinical judgement calls rather than missed visit windows.
- One therapeutic area, or one or two sponsors whose own tooling already covers most of your day.
- Paper source that your monitors have never raised a finding against.
At that shape, the arithmetic a build automates is arithmetic a person can still do reliably. Eight protocols is a whiteboard someone reads across in thirty seconds. The subscription costs less than the discovery phase of a custom project, and the difference buys a second coordinator.
There is a second thing you should not build at any size, and it is worth saying before anything else. Do not build electronic data capture. Medidata Rave, Veeva CDMS, Oracle Clinical One and Medrio belong to the sponsor and are mandated study by study. Your system sits upstream of them by design, and any proposal that includes replacing them is a proposal to enter a fight nobody asked you to have.
When does a custom build actually pay off?
The threshold is not revenue, it is cognitive load. Five signals tend to arrive together, and two or more of them makes a build case:
- More than a third of your deviations are visit window, missing source or missing signature, which means the problem is operational rather than clinical.
- Coordinators lose six to nine hours a week to transcription, chasing signatures and reconciling paper against the sponsor system.
- Monitoring preparation takes two days of binder pulling before every visit, four times a year, across every active protocol.
- You lost a study at feasibility because you could not evidence your enrolment history with anything better than an anecdote.
- Your best coordinator maintains a personal spreadsheet the whole site depends on.
That last one is the tell that ends the argument. The spreadsheet is your requirements document, and the fact that somebody had to write it means the packaged tool already failed at the thing you needed most. Open it and you will usually find two things: a versioned schedule of assessments, and a days to window close calculation across every protocol at once. Those are precisely what a build formalises, and precisely what the packaged tools do not attempt.
Check your own deviation log first. If fewer than a third of your deviations are window or source related, fix process before writing a cheque.
How do they compare on the things that matter in this industry?
Schedule versioning. A packaged system carries the visit schedule that existed at study startup. When an amendment moves the Week 12 window from plus or minus seven days to plus or minus three and adds an unscheduled draw, most sites re-enter it by hand or rely on the lead coordinator remembering. Ask a vendor how a subject who re-consented on a specific date gets forward windows recomputed while subjects still on the prior version do not. A configuration screen cannot express that. Dated protocol versions can.
Cross protocol ordering. The question a coordinator has at 7:40am is not what is happening today, it is what closes soonest across everything. Packaged tools sort by date and by study because they were built one study at a time. Sorting by days to window close across all protocols at once is the single screen that changes a working day.
Source verification burden. Generic electronic source products exist, and sites abandon them around protocol four because every worksheet is rebuilt as a form from scratch. Ask what happens when you hand over a sponsor's Word source worksheet. If the answer is a two week build per protocol, your operation will drift back to paper by the third study.
Capacity in hours rather than names. Staff assignment as a name field cannot tell you that a Day 1 oncology dosing visit is five and a half hours with a timed series while a device follow up is forty minutes. No packaged tool models procedure time, because it varies per protocol and per site.
Data portability under audit. Ask how the complete record leaves whatever you run, including the audit trail with reason for change capture rather than only current values. A regulated record you cannot export intact is a finding waiting for a date.
What does total cost of ownership look like at your scale?
On the build side, from Digital Heroes delivery experience, three shapes recur. A window engine alone, meaning protocol and schedule of assessments with versioning, a subject roster with consent version pointers and the cross protocol coordinator dashboard, runs $35,000 to $65,000 in seven to ten weeks. A focused first release adding electronic source for two or three protocols with typed fields, ranges, an append only audit trail and compliant electronic signature on the principal investigator review step runs $60,000 to $130,000 over twelve to sixteen weeks. A full platform adding the enrolment funnel and forecasting, coordinator capacity, agreement linked per visit invoicing, health record cohort integration and the retention engine runs $150,000 to $400,000 phased over six to twelve months.
Validation under 21 CFR Part 11 sits inside those bands rather than on top, and it adds 15 to 25 percent to the engineering line. Whether you land at 15 or 25 is decided in week two, because an append only audit trail designed into the data model is cheap and the same requirement retrofitted onto tables that have been overwriting rows is expensive. Health record integration is typically $20,000 to $45,000 of engineering, and engineering is not the constraint. Approval through a vendor partner programme can take months before code starts, while a nightly extract negotiated with your own health system information technology group often produces the same pre-screening list a quarter earlier.
After go live, budget 18 to 22 percent of build cost per year. Hosting for a three site network runs $400 to $1,200 a month. Each new protocol takes two to four weeks to onboard once the extraction pipeline exists, which at twenty concurrent protocols is a standing line. Change control is the recurring cost unregulated software does not carry: every material change needs impact assessment, testing evidence and a documentation update, so a change request that would be trivial elsewhere has a paperwork tail here.
On the buy side, the honest comparison is not the subscription, because you are keeping the management system either way. Price the gap instead. Take twelve months of deviations, count the share that are window, source or signature rather than clinical, and attach principal investigator time on each memo to file and coordinator time on each corrective action. Add monitoring preparation days. Then add the line everybody leaves out: replacing a certified coordinator lands around $40,000 to $60,000 once recruiting, ramp and the deviations during ramp are counted.
What does the hybrid look like, and when is it the honest answer?
For nearly every site that builds, this is the answer, and we give it whether or not it wins us work. Keep the management system. Build the operational layer above it.
In practice that is three pieces:
- The window engine, $35,000 to $65,000. Protocol versions with anchor events, day offsets, windows and required procedures. Subjects carry a consent version pointer, and the dashboard sorts by days to close across every protocol at once.
- Electronic source for your two or three worst protocols, inside the $60,000 to $130,000 release. Choose the ones that generate the most deviations rather than the ones that are easiest to model, because the extraction pipeline built for those makes every later protocol a two to four week job.
- Reconciliation against the sponsor system rather than push into it. Compare your source against what has been entered and surface the differences to a coordinator. That captures most of the operational benefit without a connector estate the next protocol will invalidate.
The split keeps your finance team out of the migration entirely, which matters more than it sounds. Contracts, budgets and payments stay where your controller already trusts them, the custom system becomes the daily driver, and nobody has to argue about which system is the record. It also keeps the number near $126,000 rather than near $400,000, because the expensive half of a full platform is the half you are deliberately not rebuilding.
Which should you choose, by operator size and stage?
- Single site, under eight concurrent protocols, two or three coordinators. Buy Clinical Conductor or RealTime CTMS and run disciplined paper source. Do not build.
- Single site, eight to fifteen protocols. Still buy, but start counting. Categorise every deviation for two quarters as window, source, signature or clinical. That count is the only evidence that makes the next decision cheap instead of theoretical.
- One site past fifteen protocols, or two sites. The decision point. Build the window engine alone at $35,000 to $65,000 and see whether the deviation category you were worried about actually falls before funding anything else.
- Three or more sites, or a network with mixed sponsors and therapeutic areas. Build the focused first release: window engine plus electronic source with audit trail and signatures for your two worst protocols, $60,000 to $130,000 over twelve to sixteen weeks.
- Network competing for sponsor selection on enrolment performance. Build the full platform, sequenced. Window engine and source first, then the pre-screening funnel with coded screen failure reasons, then capacity and invoicing. Twelve months of funnel history is what wins the next feasibility, and history is the one thing you cannot buy.
Two conditions apply to every build row. Design the append only audit trail in week two rather than month four, because that decision alone separates validation at 15 percent from validation at 25 percent. And do not migrate paper. Run new protocols on the new system and let existing binders age out with their studies, since digitising closed subject records creates a reconciliation question you will answer to a monitor for no benefit.
If you would rather someone argued with your brief than agreed with it, Digital Heroes starts every engagement with a signed specification covering the data model, permissions and acceptance criteria, which is what keeps a fixed price fixed. The document is yours whichever way you go.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Per the Standish Group CHAOS 2020 report (reviewed at this URL), across tens of thousands of software projects roughly 31% end successfully, about 50% are 'challenged', and roughly 19% fail outright; small projects succeed far more often than large ones, and Agile approaches succeed at markedly higher rates than Waterfall. Source: The Standish Group (2020) →
- Only about 30% of digital transformations succeed at meeting their objectives, but getting six critical success factors in place (leadership commitment, talent, agile culture, progress monitoring, clear strategy, and a modernized platform) raises the odds of success from 30% to 80%. Source: Boston Consulting Group (BCG) (2020) →
- Across ten outpatient clinics the mean no-show rate was 18.8%, and the marginal cost of no-shows reached $14.58 million per year for those clinics, at roughly $196 per missed appointment (2008 figures). Source: BMC Health Services Research / PubMed Central (Kheirkhah et al.) (2015) →
- 88% of organizations are concerned about employee retention, and providing learning opportunities is respondents' #1 retention strategy; career progress is cited as people's top motivation to learn, yet only 36% of organizations qualify as 'career development champions.'. Source: LinkedIn Learning (2025) →
Frequently asked questions
Should we replace Clinical Conductor or RealTime CTMS?
No, and this is where sites most often get the decision wrong. Contracts, budgets, per visit payment terms and invoicing already work in those products, and rebuilding them adds cost while creating an argument about which system your finance team treats as the record.
Build the operational layer instead: versioned schedules of assessments, live window tracking across every protocol at once, electronic source, and coordinator capacity in hours rather than names. Most sites that build end up running both, with the custom system as the daily driver.
What does it cost to switch site management systems later?
The licence side is modest. The expensive part is that a regulated record does not travel cleanly, and you need the audit trail with reason for change capture, not just current values, for years after the visit. Before signing anything, ask how the complete record leaves the system and get the answer into the contract.
The same question applies to a developer. Your repository, infrastructure accounts, validation plan and traceability matrix should be yours from the first commit, because a sponsor auditor may ask to see documentation years later.
What if our CTMS vendor raises prices at renewal?
Work out now what the fee looks like at double your protocol count and double your coordinator headcount, because per seat and per study pricing rises exactly as the site grows. Do that arithmetic before renewal rather than during it.
The structural answer is not to leave. It is to own the layer that determines whether your operation runs on time, so that the packaged system is providing contracts and payments you can price and compare rather than a service that nothing else is measured against.
How long before coordinators are actually off paper?
Twelve to sixteen weeks to a live first release covering two or three protocols, then roughly two to four weeks per additional protocol once the worksheet extraction pipeline exists. A window engine alone lands faster, at seven to ten weeks.
Budget real coordinator time in the final three weeks. A tablet form a coordinator does not trust gets abandoned in week three and the binder comes back out, which is the most common way this category fails after a technically successful build.
Can we push our data into Medidata Rave or Veeva CDMS?
Technically yes, and in a first release you almost certainly should not. Sponsors mandate the system per study and change it between studies, so every connector becomes a maintenance obligation for a relationship that may not survive the next protocol.
Reconciliation is the better first step. Compare your source against what has been entered and surface the differences to a coordinator. That delivers most of the operational value without signing up for a connector estate you maintain forever.
What does 21 CFR Part 11 validation add to the build cost?
15 to 25 percent on the engineering line, covering the validation plan, installation, operational and performance qualification documentation, and a requirements traceability matrix. It is inside our quoted bands rather than added on top.
Where you land in that range is decided in week two. An append only audit trail with reason for change capture designed into the data model is cheap. The same requirement retrofitted onto tables that have been overwriting rows is expensive and less defensible under audit.
Does Epic or Cerner integration change the build or buy answer?
It changes the schedule more than the decision. Engineering is typically $20,000 to $45,000, but a read only cohort query through a vendor partner programme can take months of approval before code starts, and that timeline belongs to your health system information technology group rather than to any developer.
A nightly flat file extract negotiated directly with the same team frequently produces the same pre-screening list a quarter earlier for less money. Decide the path before scoping, because it swings the schedule either way.
We are one site running six protocols. What should we do?
Buy a management system, keep disciplined paper source, and spend nothing on custom software. At that scale the arithmetic a build automates is arithmetic your coordinators can still do reliably, and your constraint is staff hours rather than system architecture.
Do one cheap thing now that makes the next decision easy: categorise every deviation for two quarters as window, source, signature or clinical. If the operational share climbs past a third as you take on more protocols, you will have evidence instead of a theory.
Will an app built for 10 users survive growing to 500?
Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.
We run everything on Airtable and spreadsheets. When is it time to go custom?
The switch usually makes sense when you hit one of two walls: Airtable's record caps (125,000 records per base on the Business plan) or logic the tool cannot express, like multi-step approvals with conditional pricing. There is also a simple cost signal: 25 people on Business at roughly $45 per seat per month is about $13,500 a year, forever, for a tool you are already fighting. Custom is worth it when the workflow is core to how you make money; for peripheral processes, staying on Airtable is the right call.
If an agency builds my software, who actually owns the code?
You should own everything, assigned in writing: the contract transfers full IP to you on final payment, the code lives in your GitHub organization, and hosting runs in cloud accounts you control. The red flag is a proposal that mentions the agency's proprietary platform or framework, which usually means you are renting, not buying. Digital Heroes structures every build this way precisely so a client can fire us and lose nothing but the relationship.
How do we get years of data out of our old system and into the new one?
Treat migration as a planned sub-project: a field-mapping document, at least one dry run on a copy of your data, then a cutover with the old system kept read-only for 30 days as a safety net. On Digital Heroes projects it consumes 10 to 15% of the budget when the old system has an export, and more when data must be pulled out screen by screen. Ask any vendor to walk you through their last migration before you sign.
How do I make sure custom software is secure and compliant with rules like HIPAA?
Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.
Is it cheaper to customize Salesforce than to build a custom CRM from scratch?
If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.
Couldn't I just build my app in Bubble or another no-code tool instead of hiring an agency?
For validating an idea with real users, yes, and we tell clients that honestly. The walls come later: Bubble apps cannot be exported as code to run anywhere else, performance drops on complex data operations, and usage-based pricing climbs as you grow. A meaningful share of Digital Heroes custom builds are rebuilds of no-code MVPs that proved the business worked, which is the system operating as intended: validate cheap, then build the version that scales.
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .