Choosing a software as a medical device (SaMD) company is one of the highest-stakes decisions a MedTech team makes, because the partner you pick shapes not only the software but the regulatory evidence, the timeline, and who owns what at the end. SaMD companies vary widely in how they handle regulation, quality, and ownership, and the differences are not always visible in a sales conversation. This guide lays out the criteria that separate a capable SaMD partner from a risky one, so you can evaluate any company against what actually matters.
The term SaMD company covers a broad range: large consultancies, specialized medical-device software firms, and general software shops that take on medical work. They are not interchangeable. The right choice depends on how well a company handles the specific demands of building software that is itself a regulated medical device, which is a different discipline from building general software. The criteria below are how to tell them apart.
1. Regulatory Pathway Experience
The first thing to assess in a SaMD company is whether it understands the regulatory pathway your product will take. SaMD is regulated by class (FDA Class I, II, or III in the US), and the development approach differs at each level. A capable SaMD company can speak clearly about classification, the relevant pathway (510(k), De Novo, or PMA), and how the software’s intended use drives that classification. A company that treats regulation as an afterthought, or promises to sort it out later, is a warning sign, because the pathway shapes the entire build.
Ask how the company has supported submissions before, and how it frames its own role. The strongest partners are clear that the sponsor owns the regulatory submission and classification, while the software company provides the engineering and the supporting evidence. A company that claims to own or guarantee regulatory outcomes is overstating what any software vendor can do.
2. Quality Management System (QMS) and IEC 62304
A serious SaMD company develops under a certified quality management system, most commonly ISO 13485, and builds software in conformance with IEC 62304, the standard for medical device software lifecycle processes. These are not paperwork exercises. They are the framework that makes the software’s development record trustworthy to regulators, hospitals, and acquirers. Ask whether the company’s QMS is certified, and whether IEC 62304 and ISO 14971 (risk management) are part of how it actually builds, not just claims it follows.
The tell is whether quality is embedded or bolted on. A company that produces documentation, traceability, and risk controls alongside code is delivering software ready for its next milestone. A company that writes code first and reconstructs the evidence later is setting up a remediation project that will cost time and money to unwind.
3. Verification, Validation, and Traceability
A SaMD company should be able to show how it verifies and validates software, and how it maintains traceability from requirements through risk controls to tests. This is what turns working software into software that can pass regulatory review. When evaluating a company, ask how it links requirements to tests, how it manages change across releases, and how it demonstrates that the software does what its intended use claims. Vague answers here are a meaningful risk, because verification and validation evidence is exactly what a submission depends on.
4. Ownership of the Software, Code, and Platform
One of the most overlooked criteria in choosing a SaMD company is what you own at the end. Arrangements vary widely. Some companies retain ownership of the underlying platform or license it back to you; others deliver the source code and full ownership to the sponsor. For a medical device that a company must maintain, support, and defend for years, owning the code and the platform it runs on is often decisive. Ask directly: at the end of the engagement, who owns the source code, the platform, and the derivative work, and can the software be deployed into infrastructure you control?
5. Cybersecurity and Data Handling
Because SaMD handles sensitive data and connects to other systems, a SaMD company must treat cybersecurity and data handling as core, not optional. That means designing software that is HIPAA-ready, meeting the FDA’s cybersecurity expectations for medical devices, and building the technical safeguards, access controls, encryption, and audit logging that protect patient data. A company that cannot describe its approach to medical device cybersecurity is a poor fit for a regulated product.
6. Speed Without Shortcuts
Finally, a strong SaMD company moves quickly without cutting corners that create rework. The fastest path to market is not the one that skips documentation and evidence; it is the one that captures them as the software is built, so the next milestone is a forward step rather than a remediation effort. When evaluating a company, look for a development approach where evidence and code move together, sometimes described as continuous delivery paired with continuous compliance. That is what lets a SaMD product reach clinical, regulatory, and commercial milestones with fewer detours.
The SaMD Company Evaluation Checklist
A short version of the criteria above, to use when comparing SaMD companies:
Criterion | What to ask |
Regulatory pathway | Can they explain your classification and pathway, and scope their role correctly? |
QMS and IEC 62304 | Is their QMS certified? Is IEC 62304 and ISO 14971 how they build? |
Verification and validation | How do they trace requirements to tests and manage change? |
Ownership | Who owns the code, platform, and derivative work at the end? |
Cybersecurity | Is the software HIPAA-ready and built to FDA cybersecurity expectations? |
Speed without shortcuts | Do evidence and code move together, or is documentation reconstructed later? |
Frequently Asked Questions
What is a software as a medical device (SaMD) company?
A software as a medical device (SaMD) company develops software that is itself a regulated medical device, meaning the software performs a medical function on its own rather than running a hardware device. These companies build under medical-device regulations and quality standards such as IEC 62304 and ISO 13485, which distinguishes them from general software firms.
What should I look for in a SaMD company?
Look for regulatory pathway experience, a certified quality management system, IEC 62304 and ISO 14971 discipline, clear verification and validation practices, a transparent ownership model, strong cybersecurity, and a development approach where evidence is built alongside the code rather than reconstructed later.
Are SaMD companies and medical device software companies the same?
They overlap but are not identical. All SaMD companies build medical device software, but medical device software companies also include firms that build software inside hardware devices (sometimes called SiMD). A SaMD company specifically builds software that functions as a medical device on its own.
The right software as a medical device company is the one whose approach to regulation, quality, ownership, and evidence matches the demands of your product and its stage. Sequenex is a SaMD company built around exactly these criteria: development under an ISO 13485-certified quality management system, conformance with IEC 62304 and ISO 14971, a sponsor-ownership model, and a software as a medical device practice where evidence and code move together. To discuss your product, get in touch.

