How to Hire an SDS Authoring and Chemical Compliance Software Company
Judge an SDS software vendor on how they detect a recipe change, not on their authoring screen.
On this page
Judge an SDS software vendor on how they detect a recipe change, not on their authoring screen. A first release with a live feed from your enterprise system, classification for one jurisdiction and a managed phrase library runs $80,000 to $170,000 in 12 to 18 weeks. Under roughly 200 formulations shipping to three jurisdictions, license Chemwatch or a 3E authoring service instead.
A drum leaves your yard on Monday with a label printed from a classification calculated fourteen months ago. The surfactant was substituted in March because the original supplier went on allocation. It went through as a bill of materials revision, technical approved it, production ran it the following week. Nobody told regulatory affairs, because a bill of materials revision is a routine Tuesday.
This category is awkward to buy because the hard part does not look hard. The classification rules are published. Substance data can be licensed from Sphera, Verisk 3E or Chemwatch. What you are paying a developer for is the connection between the system where recipes change and the system where documents are produced, and nobody has a portfolio screenshot of plumbing. So buyers end up comparing authoring interfaces, which is the cheapest quarter of the build, and the vendor who demos the prettiest editor wins a project they will fail at.
What it really costs in 2026
| Scope | Cost | Timeline |
|---|---|---|
| Live recipe feed, classification for your home jurisdiction, phrase library, authoring and generation in one or two languages | $80,000 to $170,000 | 12 to 18 weeks |
| Full platform: further jurisdictions and languages, label generation, transport classification, poison centre output, distribution register | $220,000 to $500,000 | 9 to 18 months, phased |
| Maintenance, rule set updates and regulatory change work | 15 to 20 percent of build per year | Retainer |
Two line items go missing from almost every quote here.
Translation governance. The standardised hazard and precautionary statements have official translations you can pull. The rest of the sheet does not. First aid measures, firefighting measures, handling and storage advice and disposal considerations are your own prose, and each language needs an owner, a review cycle and a change process forever. Vendors price building the library. Almost none price the operational cost of keeping it consistent, which is the reason in-house systems age badly: the same hazard ends up with three different first aid paragraphs written by three people in three different years, and a large customer eventually reads two of your sheets side by side.
The recipe data project. If formulations sit in your enterprise system as free text, or as a percentage typed into a description field, there is nothing to compute a mixture classification from. Structuring that is your chemists and your master data team, not a developer task, and it has to finish before the classification engine has any input. Ask where this sits in the plan. If it is not in the plan, the timeline is fiction.
Licensed substance content is a third cost that continues after delivery. It stays the licensor's property and carries its own subscription, and in year three it usually exceeds your software maintenance line.
Signals of a strong partner
- They ask which system holds the authoritative recipe before they ask anything about the interface, and they want to know whether it emits change events or only supports polling.
- They version the classification, not the document. The correct model stores inputs, rules and result so a historical determination is reproducible under audit.
- They propose licensing substance content. A developer who wants to build your own substance database is proposing to spend your money recreating decades of work.
- They treat the sheet as a rendering. The authoritative object is the product and its versioned classification; the document in a given language is produced from it and archived on issue.
- They ask about label dimensions early. Label space is a hard constraint that forces content decisions, and it is legally sensitive because the label is what a worker on the floor reads.
- They separate supply from transport classification without being prompted, and know the two can legitimately differ for the same product.
- They ask who your competent person is. Software does not make hazard determinations. A vendor who implies it does has not worked in regulatory affairs.
Red flags
- A nightly extract is their change-detection design. Ask what happens to a product that changed and shipped the same day. Watch what they say next.
- They quote a fixed price before seeing your formulation data. The state of that data is the single largest variable in this build and they cannot know it yet.
- They describe one document per product in a folder structure. That is the drift you are hiring them to end, rebuilt at higher cost.
- They have no answer on superseded versions. Retention of withdrawn sheets is not optional and cannot be bolted on after the archive design is set.
- They cannot tell you who received which version. If distribution is a mailing list, a revision is a broadcast into a decayed address book, and you have no evidence of notification.
Questions to ask on the first call
- How will you know that formulation 4471 changed at 14:20 on Tuesday, and what happens to product that shipped the same afternoon?
- Show me how you would reproduce the classification a product carried in March 2024, including the rule set version in force at the time.
- A raw material supplier issues a revised sheet adding a hazard class. What cascades, to how many finished products, and how fast?
- Which substance content do we license, from whom, and what is that subscription in year two and year five?
- A label runs out of room for precautionary statements. What are the rules for which ones are carried, and who signs that off?
- How is the unique formula identifier generated and how does the poison centre submission come out of the same classification data rather than being assembled by hand?
- Where does transport classification live, and can it differ from the supply classification for the same product in your model?
- Show me the distribution register. Who holds version four of the sheet for product X, and when were they sent it?
- Who owns the repository, the phrase library and the translations from the first commit, in writing?
A simple way to decide
Do not buy a build from a slide deck. Buy a paid discovery phase instead, four to six weeks, at the end of which you own a written specification: the formulation event model, the classification and versioning design, the jurisdictions and languages in scope, the label and transport rules, and the content you will license rather than build. That document is portable. Take it to three firms and the quotes finally compare, because they are pricing the same thing.
Digital Heroes is the wrong firm for you if you want a regulatory content vendor. We do not maintain substance databases and will tell you to license that. We are a fit for the workflow, integration and generation layer around it, with PRD-first delivery so the specification exists before anyone writes code, and contracting through an India LLP, a US LLC or a UK LTD so the intellectual property assignment sits under law your own counsel already reads.
Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Deloitte's research found that digitally advanced small businesses experienced revenue growth nearly 4x as high as the prior year, were about 3x as likely to have exported, were nearly 3x as likely to have created new jobs, and were more than 3x as likely to have seen more sales inquiries in the last year. Source: Deloitte (research summarized by Google) (2017) →
- Across 1,471 IT projects the average cost overrun was 27%, but one in six projects was a 'black swan' with an average cost overrun of 200% and a schedule overrun of nearly 70%. Source: Harvard Business Review (Bent Flyvbjerg & Alexander Budzier, University of Oxford) (2011) →
- In an RCT, text-message reminders (11.7% missed) were non-inferior to telephone reminders (10.2% missed; difference not significant, within the 2% non-inferiority margin) but far cheaper - total cost EUR 230 for SMS versus EUR 8,910 for telephone over 6 months - making SMS more cost-effective. Source: BMC Health Services Research / PubMed Central (Junod Perron et al.) (2013) →
- McKinsey emphasizes that most L&D functions still fail to tie training to business outcomes, recommending organizations track 2-3 business-relevant indicators (such as time-to-proficiency, redeployment into priority roles, or frontline productivity) rather than participation metrics to demonstrate training effectiveness. Source: McKinsey & Company (2025) →
Frequently asked questions
How much does it cost to hire an SDS authoring software company?
A first release covering a live recipe feed from your enterprise system, classification for your home jurisdiction, a managed phrase library and generation in one or two languages runs $80,000 to $170,000 over 12 to 18 weeks. A full platform adding more jurisdictions and languages, labels, transport classification and a distribution register runs $220,000 to $500,000 phased across 9 to 18 months. Budget 15 to 20 percent of build cost a year for maintenance.
Should we build an SDS system or license one?
License if you make a modest number of formulations shipping into two or three jurisdictions with a stable recipe set. Chemwatch or an authoring service from Verisk 3E will produce compliant documents for less than a build, and outsourcing authoring entirely is a legitimate answer at that scale. Build when recipes change often enough that document drift is a standing risk and your document matrix has outgrown a folder structure.
What is the single most important question to ask a vendor?
Ask how they will detect that a formulation changed. If the answer is a nightly or weekly extract from your enterprise system, ask what happens to a product that changed and shipped the same day. The right architecture is event driven from the system that holds the authoritative recipe, and a developer who has built this will immediately ask which system that is and whether it emits change events.
Why do SDS software projects run over on timeline?
Usually because the formulation data is not structured. If recipes live as free text or as percentages typed into description fields, there is nothing for a mixture classification engine to compute from, and cleaning that up is a master data project involving your own chemists rather than a developer task. Ask where structuring sits in the plan. A timeline that does not include it is not a real timeline.
Who owns the code and the phrase library when the project ends?
You should own the repository, the infrastructure accounts, the integrations and the phrase library including every translation, from the first commit. The one exception is licensed regulatory and substance content, which stays with its licensor and carries a separate subscription that continues after delivery. Get that distinction written into the contract before kickoff, because it is the part vendors leave deliberately vague.
What are the biggest mistakes first-time software buyers make?
Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
Who owns the code when an agency builds my software?
You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.
What is the biggest mistake first-time software buyers make?
Choosing the lowest quote without asking why it is the lowest. A bid 40% under the field usually gets there by skipping tests, documentation, and code review, which are invisible in a demo and brutal to pay for later; every stalled project Digital Heroes has been asked to rescue tells some version of that story. The second mistake is signing without a written scope, which reliably turns the winning cheap quote into 1.5x to 2x the price by launch.
How much should a small business expect to pay for custom software?
Across 2,000+ Digital Heroes projects, a small business system that replaces spreadsheets or one core workflow typically lands between $40,000 and $80,000, with more complex first versions running up to $150,000. The two levers that move the number most are integrations and user roles, not the team's hourly rate. Any quote under $15,000 for a full production system means the vendor has not understood your scope yet.
Should I ask for a fixed price or pay the agency hourly?
Fixed price for the first version, hourly or retainer for what comes after launch. A fixed-scope, fixed-price V1 puts the estimation risk on the agency, which is exactly where you want it while trust is unproven; hourly billing on an unscoped greenfield build is a blank check. After launch, flip it, because maintenance and small features arrive unpredictably and fixed-pricing every ticket wastes everyone's time.
What happens to my software if the agency shuts down or we stop working together?
Nothing dramatic, if the engagement was set up correctly: the code sits in your repository, hosting runs on your cloud account, and a handover document explains how to deploy and operate the system. Any competent replacement team can then take over in days rather than months. If the agency controls the repo, the servers, or the domain, fix that now, because renegotiating access during a dispute is the most expensive place to discover the problem.
Will an app built for 10 users survive growing to 500?
Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.
Can custom software connect to the tools we already use, like QuickBooks, Stripe, and Google Workspace?
Yes, and connecting your existing tools is one of the main reasons to build custom: mainstream platforms like QuickBooks, Stripe, Shopify, and Google Workspace all publish documented APIs. Budget 1 to 3 weeks of work per integration depending on API quality and how much data flows in both directions. Ask any vendor whether they have integrated with your specific tools before, because quirks like QuickBooks' OAuth token handling and API rate limits get learned on someone's project, and it should not be yours.
What should I have ready before I contact a development agency?
Three things, none of them technical: a one-page description of the problem in your own words, a list of the tools and spreadsheets the new system must replace or connect to, and a must-have versus nice-to-have split of features. Add a budget range, even a wide one, because it changes the conversation from fantasy to engineering. You do not need a formal specification; producing that is what a discovery phase is for.
What happens if I stop paying for maintenance after launch?
Nothing breaks on day one, which is what makes it dangerous. Within 6 to 18 months, unpatched dependencies accumulate known vulnerabilities, an integrated API like Stripe ships a breaking change, and the first fix requires a developer to relearn a stale codebase at full price. Budget 15 to 20% of the build cost per year for upkeep; it is the difference between a $500 patch and a $15,000 emergency.
How do I vet a software development agency before signing a contract?
Ask to speak with two past clients whose projects resemble yours in size and industry, and ask exactly who will write your code, since some agencies sell senior faces and deliver junior or subcontracted hands. Demand a written specification with acceptance criteria before any fixed price, and check that their portfolio links to products that are actually live. An instant quote given without questions about your workflows is the clearest warning sign there is.
How do I make sure custom software is secure and compliant with rules like HIPAA?
Start with the baseline every business system should have: encryption in transit and at rest, role-based access control, and audit logs. If HIPAA applies, the hosting provider must sign a Business Associate Agreement, which AWS, Azure, and Google Cloud all offer, and access controls have to be designed in from day one, not bolted on. SOC 2 certifies a company's operating practices, not a codebase, so ask vendors what they have shipped in your regulated domain rather than which logos are on their website.
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .