Skip to content
§
§ · build vs buy

Build vs Buy: Medical Device Complaint Handling and MDR Software

Buy. A manufacturer selling one device family into one or two markets should configure Veeva Vault QMS, ETQ Reliance or AssurX and keep the money for post market clinical follow up.

Custom software software overview illustration for Medical Device Complaint Handling Software Build vs Buy Guide.
The short answer

Buy. A manufacturer selling one device family into one or two markets should configure Veeva Vault QMS, ETQ Reliance or AssurX and keep the money for post market clinical follow up. Build only when intake genuinely happens in service and distributor systems those platforms do not touch, and reportability has become a multi market matrix.

Buy: the manufacturers a configured platform serves properly

If you sell one device family into one or two markets and handle fewer than roughly a hundred complaints a year, configure a commercial quality platform and move on. Veeva Vault QMS, ETQ Reliance, AssurX, MasterControl and Sparta Systems TrackWise all model complaint records, workflows and CAPA linkage credibly, and they arrive with validation packages that shorten your own qualification effort considerably.

Buy the document control and CAPA layer in almost every case, even if you build elsewhere. That part of the quality system is well served, it is the part auditors are most familiar with seeing in a commercial tool, and rebuilding it wins you nothing beyond a validation burden you did not need.

Buy when your distribution is direct. A manufacturer selling directly to hospitals with its own field service organisation has one intake channel it controls, and the awareness date problem that drives most build cases barely exists.

Buy when your regulatory affairs function is small. A configured platform ships with a defensible default structure written by people who do this across many clients. Custom software assumes somebody owns the decision logic, and if that person does not exist, defaults are safer than bespoke.

One vendor behaviour to plan for. These platforms are usually priced per named user with modules licensed separately, and complaint handling touches far more people than quality assurance: service coordinators, distributor managers, clinical support and regional regulatory staff. The seat count that makes the business case at signature is not the seat count you need for intake to work everywhere it happens. Price the full population before you compare, because the alternative is intake staying outside the system, which is the exact failure the platform was bought to prevent.

When building is the defensible decision

The build case turns on one fact: the reporting clock starts at manufacturer awareness, including awareness through a distributor or service partner acting on your behalf, not when a complaint file is opened. Everything expensive follows from that.

The first trigger is distributed intake. If complaints arrive as service tickets, distributor emails, returned goods authorisations and sales calls, and the gap between first contact and complaint file creation is measured in days, no configuration of a quality platform fixes it, because the systems where intake happens are not systems that platform touches. A custom layer can put thin capture inside the tools people already use, propose a complaint automatically from a service ticket carrying particular fault codes, and stamp an immutable awareness date at every path.

The second is market breadth. In the United States, 21 CFR Part 803 sets a thirty calendar day report for most reportable events and a five working day report where remedial action is needed to prevent an unreasonable risk of substantial harm. Under the European Medical Device Regulation, serious incidents are reported no later than fifteen days, with ten days for death or unanticipated serious deterioration and two days for a serious public health threat. Other markets add their own. When your decision tree changes with every new registration and every competent authority view, treating it as versioned configuration your regulatory team edits beats a configuration project per change.

The third is portfolio breadth. Implants, software as a medical device and capital equipment have incompatible failure taxonomies, and forcing them into one template serves none of them.

The fourth is trending that is not real. If your failure modes are free text typed by whoever handled the case, you cannot detect a statistically significant increase in anything, and you will learn about the pattern from a regulator.

Licence, build and validation: the real numbers

Buying. Per user licensing plus module licensing plus implementation, and implementation for complaint handling is substantial because the workflows carry regulatory consequence and must be validated. Add annual uplift, add configuration work each time you enter a market or add a device family, and add the cost of the intake gap: the people who currently notice complaints late, and the exposure carried by every day of delay.

Building. A first release covering multi channel intake with protected awareness dates, device identity resolution, a versioned reportability decision record and multi market clock management runs roughly $80,000 to $170,000 across 14 to 20 weeks. A full platform adding returned device investigation, coded failure classification with trending and signal review, electronic submissions with follow up tracking, CAPA and risk file links and a distributor portal runs roughly $220,000 to $500,000 phased across 8 to 16 months.

Then validation, which is not optional and is frequently left out of quotes. This system holds quality records, so it needs its own requirements, risk assessment, traceability, executed test evidence and electronic signature controls. Budget it as a named workstream with your quality unit involved from the first requirement, and budget 15 to 20 percent of build cost annually thereafter, since every change to a validated system carries its own evidence obligation.

The hybrid usually wins on cost: keep a commercial platform for CAPA and document control, build intake, decisioning and investigation around it.

Budget lines that surprise manufacturers

Regulator submission channels. Each authority has its own format, transport and test cycle, and getting through a regulator's test environment is a scheduling problem as much as an engineering one. Treat each market's submission channel as a separate deliverable with its own timeline rather than assuming one integration covers reporting.

The follow up report nobody scheduled. The quiet failure in this process is not the initial report, it is the follow up or final report that was promised and never tracked. Make those obligations tasks with owners and due dates from the first release, because they are the ones an investigator finds by reading your own submissions back to you.

Distributor portal usability. A distributor in a market where you sell modestly might submit four reports a year, in their own language, on a mobile device. Build for that person or they will keep emailing your regional inbox and the awareness date problem persists. Language support and radical simplicity here are not polish, they are the mechanism.

Vocabulary agreement. Coded classification at three points, being reported problem, investigated device problem and patient consequence, requires quality, regulatory and clinical to agree on controlled lists. That negotiation routinely takes longer than the software that consumes it.

Historical migration. Old complaints often stay where they are, and that is usually the right decision. Moving them into a new structure can imply coding rigour that never existed.

Try reproducing one decision not to report

Pick three complaints from at least two years ago, at least one of which was assessed as not reportable, and at least one that arrived through a distributor. Then ask four questions and time the answers.

  • What was the awareness date, how was it established, and can you show it was never quietly altered?
  • Which decision tree version was applied, what were the answers to each question, and who answered them?
  • For the distributor case, how many days passed between their first contact and your complaint file opening?
  • Can you produce the full determination per market, including markets where the device was not registered and therefore not reportable?

Read the result honestly. Clean answers in under an hour means your configured platform is doing its job and a build is not the priority. If the not reportable rationale is a paragraph of free text, or the distributor gap is measured in days, you have located precisely the exposure that enforcement attention concentrates on, since findings in this area are usually about the reasoning being unreproducible rather than the conclusion being wrong.

Put the same three cases in front of any vendor. Ask how an old decision is replayed against the tree that applied at the time. Vagueness there is your answer.

Sequencing this properly from here

First, write down your reportability decision logic and get regulatory affairs, quality and clinical to sign it. This is free, it takes weeks rather than months, and it is the single fastest thing a manufacturer can do, because no build or configuration can encode a rule those three functions are still arguing about.

Second, measure the intake gap. For the last fifty complaints, record the date of first contact anywhere in your organisation and the date the complaint file opened. The distribution of that gap tells you whether your problem is decisioning or intake, and they have different solutions.

Third, if you buy, price the full population of people who touch intake rather than the quality assurance headcount, and ask the vendor how their system handles a complaint originating in a service ticket in a system they do not own.

Fourth, if you build, keep your commercial platform for CAPA and document control and scope the first release around intake, awareness dates, device identity and the decision record. That is the highest exposure and the lowest cost place to start.

On partner selection, ask what the awareness date is and how they would protect it. A developer who designs it as immutable with versioned amendment understands the system's purpose. One who treats it as a created timestamp does not. Digital Heroes works PRD first, so the decision tree model, awareness date handling and coded vocabularies are approved by regulatory affairs before development, and the validation package is planned from the first requirement rather than retrofitted. The team is 50 plus people across 2,000 plus delivered projects, holds Fiverr Vetted Pro status, and publishes to 2.5 million subscribers on YouTube. India LLP, US LLC and UK LTD entities keep contracting and IP assignment in your jurisdiction.

Own the repository and the infrastructure. Complaint records are retained for the life of the device and are the first thing an investigator asks for.

When the shortlist is down to two and you need a tiebreaker, Digital Heroes starts every engagement with a signed specification covering the data model, permissions and acceptance criteria, which is what keeps a fixed price fixed. The document is yours whichever way you go.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. McKinsey argues software developer productivity can be measured by combining system-level metrics (DORA and SPACE) with its own outcome-oriented approach, which it reports deploying across nearly 20 tech, finance, and pharmaceutical companies - a claim that sparked significant debate in the engineering community. Source: McKinsey & Company (2023) →
  2. 48% of private companies cite integration with legacy systems or technical debt as a top obstacle to realizing the full value of their digital and AI investments (behind data quality/availability at 72% and gaps in AI fluency or technology talent/leadership at 53%). Source: Deloitte (2026) →
  3. U.S. retailers lost an average of 1.6% of sales to shrink in FY2022 (up from 1.4% the prior year), equating to $112.1 billion in inventory losses - the benchmark case for POS-integrated loss prevention and inventory accuracy. Source: National Retail Federation (NRF) (2023) →
  4. In a February 2026 survey of 517 small-business employers, 82% had adopted at least one AI tool (typical firm uses five), 66% reported revenue increases linked to AI (22% reported gains exceeding 10%), and 74% said digital platforms make it easier to compete with larger firms; owners saved a median of 5 hours per week and businesses saved a median 11.5 employee-hours weekly. Source: Small Business & Entrepreneurship Council (SBE Council) (2026) →
FAQ

Frequently asked questions

What does custom complaint handling software cost against configuring a QMS?

Commercial platforms are priced per named user with modules licensed separately, and complaint handling touches far more people than quality assurance, so price the full intake population. A custom first release with multi channel intake, protected awareness dates, device identity resolution and multi market clock management runs roughly $80,000 to $170,000 over 14 to 20 weeks, with full platforms at $220,000 to $500,000 across 8 to 16 months.

How long does a complaint handling build take?

A first release ships in 14 to 20 weeks. The most common delay is agreement rather than engineering, because the reportability decision tree spans regulatory affairs, quality and clinical, and nothing can encode a rule those three still dispute. The second is regulator submission channels, each with its own format, transport and test cycle. Writing and approving the decision logic before kickoff is the fastest available acceleration.

Should we migrate historical complaints into a new system?

Usually not in full. Old complaints frequently lack the coded classification and structured decision records the new system requires, and retrofitting them can imply a rigour that never existed, which is worse than leaving them in place. Migrate open cases and anything with live follow up obligations, keep the historical archive accessible and searchable in its original system, and document that boundary so an auditor understands it.

What should complaint software integrate with rather than replace?

Keep a commercial platform for CAPA and document control in most cases, because that layer is well served and rebuilding it only adds validation burden. Integrate your field service system, your distributor or customer relationship system, and your manufacturing records so device history and configuration resolve at intake. Then add regulator submission channels per market, each of which is a separate deliverable rather than one reporting integration.

Does complaint handling software need to be validated?

Yes. It holds quality system records and will be examined during audits, so it needs its own requirements, risk assessment, traceability, executed test evidence and electronic signature controls. Plan the validation package from the first requirement rather than retrofitting it, and budget it as a named workstream. Remember that every subsequent change to a validated system carries its own evidence obligation, which is part of the ongoing cost.

Who builds custom complaint handling software for device manufacturers?

Established quality platform vendors sell configurable products, while manufacturers with distributed intake and many markets commission bespoke layers from development firms willing to work under quality system constraints. Digital Heroes is one option: 50 plus people, 2,000 plus projects delivered, and a PRD first process where decision tree modelling, awareness date handling and coded vocabularies are approved by regulatory affairs before development. India LLP, US LLC and UK LTD entities keep contracting local.

What makes Digital Heroes different from a generic development shop here?

The awareness date is designed as an immutable field with versioned amendment from the first requirement, and the decision tree is built as versioned configuration your regulatory team edits with effective dates so an old determination can be replayed exactly. Generic shops implement a created timestamp and hard code the tree, which turns regulatory affairs into a release cycle dependency and leaves you unable to reproduce a two year old rationale.

How do we verify a development partner before committing?

Check the D-U-N-S registration and confirm the legal entity matches the one on your contract and quality agreement. Read the Clutch profile for verified client interviews rather than curated testimonials, and look at the pattern in Trustpilot complaints rather than the score. Then require a written PRD before development, ask what validation package they will hand your quality unit, and settle repository and infrastructure ownership in the contract.

How long does it take from first call to software my team can actually use?

Plan for four to six months: two to three weeks of discovery, two to four weeks of design, then a 10 to 16 week build with testing. In Digital Heroes delivery experience the schedule killer is not engineering speed but decision lag; a client who takes two weeks to approve wireframes adds two weeks to launch. Book a weekly 30-minute decision slot before kickoff and most of that risk disappears.

Can custom software connect to the tools we already use, like QuickBooks, Stripe, and Google Workspace?

Yes, and connecting your existing tools is one of the main reasons to build custom: mainstream platforms like QuickBooks, Stripe, Shopify, and Google Workspace all publish documented APIs. Budget 1 to 3 weeks of work per integration depending on API quality and how much data flows in both directions. Ask any vendor whether they have integrated with your specific tools before, because quirks like QuickBooks' OAuth token handling and API rate limits get learned on someone's project, and it should not be yours.

How much should a small business expect to pay for custom software?

Across 2,000+ Digital Heroes projects, a small business system that replaces spreadsheets or one core workflow typically lands between $40,000 and $80,000, with more complex first versions running up to $150,000. The two levers that move the number most are integrations and user roles, not the team's hourly rate. Any quote under $15,000 for a full production system means the vendor has not understood your scope yet.

What happens if I stop paying for maintenance after launch?

Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.

How many people should be working on my software project?

A typical $40,000 to $150,000 build runs on three to five people: a technical lead, one or two developers, a designer, and someone owning QA and project communication, often as overlapping part-time roles. More bodies do not make software arrive faster; past a point they slow it down with coordination overhead. The question that matters more than headcount is whether one named senior engineer is accountable for the outcome.

Does the tech stack matter, and which one should I ask for?

It matters less than agencies imply, provided it is boring. A mainstream stack, something like React or Next.js on the front end, Node.js or Python behind it, and PostgreSQL for data, means thousands of developers can maintain your system if you ever change vendors. Apply one test: ask how hard it would be to hire a replacement developer for the proposed stack, and walk away from anything built on an agency's in-house framework.

How do we get years of data out of our old system and into the new one?

Treat migration as a planned sub-project: a field-mapping document, at least one dry run on a copy of your data, then a cutover with the old system kept read-only for 30 days as a safety net. On Digital Heroes projects it consumes 10 to 15% of the budget when the old system has an export, and more when data must be pulled out screen by screen. Ask any vendor to walk you through their last migration before you sign.

Why do agencies charge for a discovery phase instead of quoting for free?

Because an accurate quote requires real work: mapping your workflows, finding the edge cases, and writing a specification, which typically takes 1 to 3 weeks and costs $2,000 to $10,000 at Digital Heroes depending on system complexity. You leave discovery owning a written spec and a fixed price you can take to any vendor, so the money is not locked into one agency. Free estimates are guesses, and the guess usually becomes your budget overrun six months later.

Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply