PROCESS  ·  17th September 2026  ·  14 min read

How to Choose a Medical Device Development Partner: 9 Questions to Ask Before You Sign

Nine questions to ask a medical device development partner before you sign: experience, quality system, firmware, cybersecurity, manufacturing, IP, cost.

Bhairav Shankar
How to Choose a Medical Device Development Partner: 9 Questions to Ask Before You Sign

SHARE

LINKEDINX

You have funding, a clinical problem you understand better than almost anyone, and a bench prototype that works on a good day. What you do not have is a full hardware team, a firmware team, a quality system and a production line. So you start looking for a development partner, and within a week you are holding six proposals that all say roughly the same thing.

This guide is for that moment. It is written for founders, product heads and R&D leads at companies building connected medical devices: wearables, monitoring and diagnostic products, rehabilitation and assistive equipment. The nine questions below are the ones that separate firms in practice. Some of them are uncomfortable for a partner to answer, which is the point. We have put our own answers at the end.

Why this decision deserves more time than it usually gets

A typical medical product takes around two years to get from concept to regulatory approval, going by the figure Medical Design & Outsourcing reports for the industry. Your partner will be inside your company for most of that stretch. They will make architecture decisions you live with for a decade, and they will write a large share of the records a regulator later reads.

Switching firms halfway is possible. You pay for it twice, though: once in money, and once in a design history that has to be reconstructed by people who were not in the room when the decisions were made. An extra two weeks spent choosing well is cheap by comparison.

First, know which kind of firm you are talking to

Three kinds of company will answer your enquiry, and they are good at different things.

  • Design and development firms are strong on complex, novel products and on the early, uncertain phases. The common weakness is distance from the factory. If nobody on the team has lived through a production ramp, design for manufacturing and design for test tend to arrive late, and late means redesign.

  • Contract manufacturers are built for volume, supply chain and repeatability. Many offer design services, but their instinct is to steer you towards what their line already does well.

  • Integrated partners cover requirements through prototyping to production handoff. You get one accountable team. In return, you need to check that each discipline is truly strong and not just present on the website.

None of these is wrong. The mistake is hiring one and expecting it to behave like another.

Idea, specification, quality and risk documentation, manufacturing, and packaging — the stretch a development partner has to cover, in whole or in part.
Idea, specification, quality and risk documentation, manufacturing, and packaging — the stretch a development partner has to cover, in whole or in part.

The nine questions

1. Have you solved the hard part of my device before?

Not "have you built my device". Nobody has, which is why you are building it. Ask about the hard part. For a cardiac patch, that may be pulling a clean signal from a body that will not stay still. For a ring, it is fitting sensing, battery and antenna into a few cubic centimetres that sit against skin all day. For a rehabilitation device, it may be motor control that fails safely.

A ring, a patch, a wristband, a phone — each sensing modality poses a different hard engineering problem.
A ring, a patch, a wristband, a phone — each sensing modality poses a different hard engineering problem.

A team with the right background can sketch a believable system architecture after two or three conversations, and can tell you where they expect trouble. Be wary of "we can develop anything". The honest version sounds more like: we are strong at most of this, here is the piece we would bring a specialist in for, and here is who that is.

2. Who, by name, will work on my project?

You are not hiring a logo. Ask who the lead engineers are, how senior they are, and whether they are employees or subcontractors. Then ask the awkward follow-up: if your RF engineer is pulled onto another client, or resigns, who is number two? A firm with one expert in the skill you need most is a firm with a single point of failure on your schedule.

Meet the people, in person if you can. A few hours with the team tells you more than any proposal will.

3. What quality system will the work sit under, and who holds the design history?

This question became simpler to ask in 2026. On 2 February the FDA's Quality Management System Regulation replaced the old Quality System Regulation, and it incorporates ISO 13485:2016 by reference. For most companies that means one quality language for the United States and nearly every other market, instead of two. Device classification and the 510(k), De Novo and PMA routes did not change.

What it means for your partner search: design and development work has to be planned, reviewed, verified and recorded in a way that fits ISO 13485, and risk management under ISO 14971 has to start with the first architecture decision, not the month before submission. You are the legal manufacturer, so the design history must end up complete and in your hands.

Ask whether the firm holds its own ISO 13485 certificate or works inside the client's system as a controlled supplier. Either can work. Then ask to see a redacted example of how they trace a requirement to a design output to a test result. If they cannot show you one, the paperwork will become your problem later.

4. How do you develop firmware and software?

In a connected device, most of the behaviour and most of the risk lives in code. The reference standard is IEC 62304, which asks you to assign a software safety class and then scale your rigour to it. Listen for the basics: requirements linked to code and to tests, version control and code review as habit, a register of third-party and open-source components, and a release process someone can explain without notes.

If your device uses machine learning, go one level deeper. Where does the training data come from and who has rights to it? Is the model locked at release or will it change in the field? How will performance be checked on people who were not in the training set?

5. What is your plan for cybersecurity?

If your device contains software and can reach the internet, even indirectly through a phone app, the FDA is likely to treat it as a "cyber device" under section 524B of the FD&C Act. The obligations are specific: a plan to monitor and fix vulnerabilities after launch, a device that can actually be updated and patched, and a machine-readable software bill of materials covering commercial, open-source and off-the-shelf components. Since 1 October 2023 the FDA has been able to refuse to accept a submission that lacks this material.

Patchability is a hardware decision. Secure boot, enough flash for a fallback firmware image, a radio stack that can be updated over the air. These get fixed when the board is designed.

Here is why it belongs in a partner interview and not a regulatory appendix: patchability is a hardware decision. Secure boot, enough flash for a fallback firmware image, a radio stack that can be updated over the air. These get fixed when the board is designed. A partner who talks about security as a document to write before submission has already got the board wrong.

6. When does manufacturing enter the conversation?

The right answer is "at the first layout". Ask how they choose components with availability and lifecycle in mind, how the device will be tested on the line and who designs those fixtures, and what a manufacturing transfer package from them contains. Ask which manufacturers they have handed designs to, and whether you can speak to one.

A pattern that comes up again and again in this industry: a company believes it has a manufacturable product, approaches a manufacturer, and discovers there is still a long road ahead. Clearing regulatory review and then finding the device cannot be built at volume without redesign is the most expensive version of that story.

7. What exactly do I own at the end?

For a startup, the intellectual property is most of the company's value. The contract should assign you everything created for your project. In practice, check the list of deliverables: schematics and layout files in native format, mechanical CAD, firmware source with its build environment, test scripts, the bill of materials with approved alternates, and the full design history. Look for it in the contract, not the pitch deck.

Also ask what the firm brings that is theirs, such as reusable libraries or reference designs, and on what terms you may keep using it if you part ways.

8. How is the work priced, and what is the first milestone?

Be suspicious of a fixed price for an entire programme quoted before the architecture exists. Nobody knows enough yet, so the number is either padded or wrong. A healthier structure is phased: a small, paid feasibility or architecture phase with clear deliverables, then estimates that firm up as unknowns are retired.

Ask how much visibility you get into hours and costs, what triggers a change order, and what happens commercially if a phase shows that the concept needs to change. Openness about money should run in both directions. Tell them your runway and your funding milestones so the plan fits reality.

9. What would make you turn this project down?

Watch how the firm behaves while quoting. Are they listening to where you really are, or fitting you into a standard template? Do they ask about intended use, the user, the care setting and the likely classification? A good partner asks hard questions early and tells you things you may not want to hear, including that your timeline is unrealistic or that part of the project is outside their strength.

Then ask about a project that went badly. Development is messy and mistakes happen everywhere. What you are buying is how a team behaves when they do.

Red flags worth walking away from

  • A fixed price and date for the whole programme before anyone has drawn the architecture.

  • No questions about intended use, users or classification in the first two meetings.

  • One named expert carrying the skill your device depends on.

  • Regulatory and quality work described as something to "handle later".

  • Vague or hedged language on IP assignment and source files.

  • No example of a design they have transferred to a manufacturer.

When to bring a partner in

There is no single right moment, but the architecture stage is where an experienced partner saves you the most. Decisions about sensing method, processor, radio, power and enclosure cast a long shadow, and getting them wrong means doing them again. If you are earlier than that and simply need to prove feasibility quickly, that is a perfectly good time too. The costly moment to start looking is after the second prototype, when the design already carries choices nobody wrote down.

How we answer these questions at Avantari

Avantari is a development partner. We do not sell devices of our own into your market; we engineer them for clients, from PCB and circuit design through embedded firmware, embedded AI and device interfaces to prototyping and manufacturing handoff. You can read how that applies to regulated products on our medical device development page.

The hard parts we have worked on. Continuous cardiac sensing in a wearable, for the Ein cardiac wearable. Heart rate variability sensing inside a ring, for the Dhyana 2 smart ring, a Red Dot Award winner. Both are client projects we cite as engineering proof.

Who does the work. Hardware, embedded systems, firmware, AI and UX engineers in one team in Hyderabad.

Frequently Asked Questions About Choosing a Medical Device Development Partner

How much does it cost to develop a medical device with an outside partner?

There is no honest single figure. Cost depends on device class, how novel the technology is, how much clinical evidence you need and how much of the quality system you already have. Ask each firm for a phased estimate with a fixed price for the first phase only, and compare what each phase delivers, not just the totals.

How long does medical device development take?

Around two years from concept to regulatory approval is a commonly cited industry average. A Class II device with a clear predicate and no clinical study can move faster. Anything needing new clinical evidence will take longer. Your partner should be able to show you which activities sit on the critical path.

Does my development partner need to be ISO 13485 certified?

Not always. As the legal manufacturer you can bring a partner into your own quality system as a controlled supplier. What is not optional is that their work fits the design and development requirements of ISO 13485, which the FDA now incorporates through the QMSR, and that the records end up with you.

Can a partner outside the United States work on an FDA-bound device?

Yes. The FDA regulates the manufacturer and its quality system, not where the engineers sit. What matters is that design controls are followed, suppliers are qualified and the records are complete and accessible. Many US and European device companies work with engineering teams abroad on exactly this basis.

Should I use one firm for both design and manufacturing?

It reduces handover risk and gives you one accountable party. The trade-off is less freedom to move production later. A workable middle path is a development partner that designs for manufacturing from day one and hands over to a manufacturer you choose together.

Who owns the IP when I outsource development?

You should own everything created for your project, and the contract should say so in plain words. Check the deliverables list for native design files, source code and the build environment, because owning IP you cannot open or rebuild is not worth much.

Send us the hard part

If you are weighing up partners for a connected medical device, tell us what it has to measure or do, who will use it and where you are today. We will come back with how we would approach the architecture and what we would want to find out first. Talk to Avantari.

KEEP READING

How HIPAA Relates to Healthcare Laws and Regulations Across Canada, the UK, Australia, and MENA

PROCESS

How HIPAA Relates to Healthcare Laws and Regulations Across Canada, the UK, Australia, and MENA

A practical compliance guide for medical device builders, health app founders, and digital health teams expanding into global markets

IoT Testing Guide

PROCESS

IoT Testing Guide

A practical IoT testing guide covering firmware testing, BLE protocol validation, OTA update testing, security testing, and performance testing for connected devices. Written by hardware engineers with 12+ years of IoT product experience.

Product Development: The Complete Guide for Hardware Founders & Product Teams

PROCESS

Product Development: The Complete Guide for Hardware Founders & Product Teams

From first idea to factory floor — a practical, end-to-end guide built for founders, PMs, and entrepreneurs navigating the complexity of physical product development.

NEWSLETTER

We write when we’ve actually built something.