medical Device Manufacturing Software: Plm, Qms, Mes and Erp
A practical map of the medical device manufacturing software stack: what each system does, where they overlap, validation effort and typical annual cost.
November 18, 20195 min read

Written by Konstantin Dolgan, Ph.D., NPDP
Founder & CEO, Product Development Engineer
Published November 18, 2019Updated September 2, 2026
In a regulated plant, the software stack is part of the quality system. Auditors do not only ask what you built; they ask how you can prove it. Medical device manufacturing software exists to make design history, device history records and traceability reproducible on demand — and each system you add carries a validation burden of its own.

What each system owns
System | Owns | Regulatory artefact | Typical annual cost |
|---|---|---|---|
PLM | CAD data, BOMs, change control | Design history file | $15k-$120k |
QMS | CAPA, complaints, audits, training | Quality system records | $10k-$90k |
MES | Work instructions, e-records on the floor | Device history record | $25k-$250k |
ERP | Lots, inventory, purchasing, finance | Supplier and lot traceability | $20k-$200k |
LIMS | Test data, sample results, CoA | Verification evidence | $10k-$80k |
Validation is the real cost
- Computer system validation. IQ, OQ and PQ protocols with signed evidence for every GxP-relevant function.
- 21 CFR Part 11. Unique logins, audit trails, and electronic signatures that cannot be repudiated.
- Change control. Every vendor update to a validated system needs an impact assessment.
- Data integrity. ALCOA+ principles applied to anything a reviewer could rely on.
- Supplier qualification. Your SaaS vendor becomes part of your audit scope.
How to sequence adoption
Most device companies start with an eQMS because it is the system an auditor asks for first, then add PLM once the BOM and change traffic outgrow spreadsheets. MES arrives when production volume makes paper travellers a bottleneck, and ERP when lot traceability and purchasing cannot be run from accounting software. Adding all four at once tends to stall: validation effort scales with the number of interfaces, not the number of licences.
Related reading: medical device design process and documentation.
Budget and timeline by system
System | Typical annual license | Implementation | Validation effort | Time to live |
|---|---|---|---|---|
eQMS | $15k-$60k | $20k-$80k | IQ/OQ/PQ, 4-8 weeks | 3-6 months |
PLM | $25k-$120k | $50k-$250k | Config validation, 6-10 weeks | 6-12 months |
MES | $40k-$200k | $100k-$500k | Line-by-line, 8-16 weeks | 9-18 months |
ERP | $30k-$150k | $80k-$400k | Financial and inventory scope | 9-18 months |
Integration points that decide success
- PLM to ERP item master. One source for part numbers and revisions, or you will ship the wrong revision.
- QMS to PLM change control. A design change should open the CAPA or ECO record automatically.
- MES to QMS nonconformance. Line rejects must create records without retyping.
- Device history record assembly. Decide early which system is the DHR system of record.
- Part 11 controls. Audit trails, e-signatures and access control must be validated, not just enabled.
Frequently asked questions
The four-system stack and where each one earns its keep
What software do medical device manufacturers use?
Medical device manufacturers rarely buy one system. They assemble a stack: PLM owns the design history and bill of materials, QMS owns documents, CAPA and training, MES owns the electronic device history record on the floor, and ERP owns purchasing, inventory and finance. Failures come from the seams between them, not from any single tool.
A typical stack is PLM for design data and change control, an eQMS for CAPA and document control, MES for electronic device history records on the floor, ERP for lots, inventory and purchasing, and LIMS where laboratory testing is involved. Smaller manufacturers often combine PLM and QMS in a single validated platform.
System | Owns | Key regulatory artefact | Typical annual cost (SMB) |
|---|---|---|---|
PLM | BOM, revisions, change orders | Design history file, DMR | $18,000-$90,000 |
QMS | SOPs, CAPA, training, complaints | Quality system records per 21 CFR 820 | $12,000-$70,000 |
MES | Work instructions, traceability, genealogy | Device history record (DHR) | $40,000-$200,000 |
ERP | Purchasing, lots, inventory, costing | Lot traceability and recall reporting | $25,000-$150,000 |
Does medical device manufacturing software need validation?
Validation: the cost line buyers forget
Yes. Any system used for a GxP-relevant function requires computer system validation with documented IQ, OQ and PQ, plus 21 CFR Part 11 controls for audit trails and electronic signatures. Validation effort routinely costs as much as the first year of licences.
Any software that touches a quality record must be validated under computer software assurance principles. Budget 40-80% of first-year licence cost for validation on a first implementation - user requirements, risk assessment, IQ/OQ/PQ protocols, traceability matrix and a validation summary report.
Cloud vendors that supply a validation accelerator package can cut that to 20-35%, but you still own the intended-use risk assessment. Every upgrade triggers a regression assessment, so favour vendors with predictable, documented release cycles.
How much does the stack cost per year?
Integration seams that cause audit findings
A small manufacturer running a combined PLM/QMS platform can operate for $25,000 to $60,000 a year. A mid-size plant running PLM, QMS, MES and ERP together typically spends $150,000 to $500,000 annually once licences, validation and integration support are counted.
- PLM-to-ERP BOM sync: an unsynchronised revision means building to a superseded drawing.
- QMS-to-MES nonconformance: floor rejects must open a record automatically or they go unreported.
- MES-to-ERP lot genealogy: without it, a recall becomes a manual paper reconstruction.
- Training records to work instructions: an operator running an unauthorised revision is a classic 483 observation.
- Audit trail completeness across systems - Part 11 requires attributable, contemporaneous, unalterable records.
Validation scope: decide it before you buy
Selection checklist and implementation timeline
The licence fee is rarely the expensive part of medical device manufacturing software. Validation is. And validation effort is not a property of the tool — it is a property of how you intend to use it. A risk-based scope, written before procurement, is the single strongest cost control available: functions that touch product quality or records get full protocols, functions that do not get a documented rationale for lighter treatment.
Phase | Duration | Deliverable |
|---|---|---|
Requirements and risk classification | 3-5 weeks | URS, GxP impact assessment |
Vendor demo against your scripts | 4-6 weeks | Scored comparison, reference calls |
Configuration and data migration | 8-16 weeks | Configured system, migrated master data |
Validation execution | 6-12 weeks | IQ/OQ/PQ executed, summary report |
Go-live and hypercare | 4-8 weeks | SOPs live, training complete, legacy retired |
Intended use | Risk level | Validation approach | Typical effort |
|---|---|---|---|
Document control and approvals | High | IQ/OQ/PQ with signed evidence per workflow | 4-8 weeks |
Electronic signatures and audit trail | High | Part 11 assessment plus record integrity testing | 2-4 weeks |
Production routing and traceability | High | OQ per transaction type, PQ on real builds | 6-10 weeks |
Planning and forecasting | Low | Supplier evidence plus targeted testing | 1-2 weeks |
Analytics and dashboards | Low | Documented rationale, no formal protocols | Days |
Two decisions reduce the number the most: keep configuration in place of customisation wherever the process can bend, and reuse the vendor's validation package rather than rewriting protocols from scratch. Customised code is validated by you, every release, forever.
Supplier qualification and the vendor audit
A software supplier feeding a regulated process is a supplier like any other, and auditors will ask for the qualification evidence. Do it before signature, when the vendor is motivated to answer, rather than during an inspection when they are not.
- Request the vendor's own quality certifications and their software development lifecycle documentation.
- Ask for the validation package: installation qualification scripts, functional test evidence, and a traceability matrix to their requirements.
- Confirm how releases are handled — forced auto-updates on a validated system are a compliance problem, not a convenience.
- Establish data ownership and export: full record export in an open format, on demand, including audit trails.
- Get the hosting and backup story in writing: locations, retention, restore testing frequency, and breach notification terms.
- Agree change notification lead times so you can revalidate before, not after, a change lands.
Data Integrity: the Alcoa+ Checklist Auditors Actually Run
Most software-related findings are data integrity findings, and they are predictable. Walk your configured system against these attributes with a real record before an inspector does.
Attribute | What it means in the system | Common gap |
|---|---|---|
Attributable | Every action tied to a unique named user | Shared logins on shop-floor terminals |
Legible | Records readable and exportable for the retention period | Proprietary format with no export |
Contemporaneous | Recorded at the time the work happened | Batch data typed in at end of shift |
Original | Source record retained, not just a printed copy | Paper print signed, electronic record edited later |
Accurate | Validated calculations and controlled units | Spreadsheet doing a GxP calculation outside the system |
Complete | Including repeats, failures and reprocessing | Failed test deleted rather than annotated |
Consistent | Time-stamped in sequence, one clock | Local time zones on distributed servers |
Enduring | Retained for device lifetime plus regulatory period | Retention shorter than the device's service life |
Available | Retrievable during inspection | Archive restorable only by the vendor |
Integration points where regulated stacks break
Individually validated systems can still produce a non-compliant plant if the joins between them are manual. The recurring failure is a part revision that is current in one system and superseded in another, which surfaces as product built to an obsolete drawing.
Interface | What must flow | Failure symptom | Control |
|---|---|---|---|
PLM → ERP | Item master, revision, effectivity | Building to superseded revision | One source of truth, automated release |
PLM → MES | Approved work instructions | Operators using printed obsolete copies | Instructions rendered from PLM at run time |
MES → QMS | Nonconformances, deviations | NCs tracked in email and spreadsheets | Automatic NC creation from failed steps |
QMS → PLM | CAPA-driven design changes | CAPA closed with no design update | Change record linked to CAPA closure |
MES → ERP | Consumption, WIP, lot genealogy | Inventory and traceability drift | Transaction-level posting, reconciled daily |
A phased rollout that does not stall
Phase | Scope | Duration | Success criterion |
|---|---|---|---|
0 | Process mapping and risk assessment | 3-4 weeks | Written intended-use and validation scope |
1 | eQMS: documents, training, CAPA | 2-4 months | Audit-ready document control |
2 | PLM: CAD, BOM, change control | 3-5 months | Single item master, released revisions |
3 | ERP or MRP: purchasing, inventory, lots | 4-6 months | Lot traceability end to end |
4 | MES: electronic DHR and shop-floor execution | 6-9 months | Paperless device history record |
5 | Analytics and continuous improvement | Ongoing | Trend data feeding management review |
Resist the temptation to run phases in parallel to save calendar time. Each phase changes how people work, and the validation evidence for phase two is usually built on master data created in phase one.
More questions teams ask
Frequently asked questions
Can a small manufacturer run a compliant stack on one platform?
Yes. Combined PLM/QMS platforms aimed at small device companies cover design control, document control, CAPA and change control adequately, and pair with a modest ERP. The trade-off is less depth in each module, which matters once production volume or product count grows.
Do spreadsheets have any place in a regulated plant?
Only when they are controlled like any other GxP tool: locked calculations, version control, access restrictions and validation evidence. An uncontrolled spreadsheet performing a quality-relevant calculation is one of the most common inspection findings.
How often does a validated system need revalidation?
On change, and on a periodic review cycle — typically annually for high-risk systems. Revalidation should be scoped to what changed, using the same risk-based logic as the original effort, rather than re-running every protocol.
Who should own the software stack internally?
Quality owns intended use and validation, IT owns infrastructure and security, and operations owns the process configuration. Assigning the whole thing to IT is the usual reason validation evidence ends up thin. Work with LA NPDT: if you are moving from here to execution, start with our medical device development or talk to us about medical device prototyping .
Filed under:Tech Talk Podcast
Tagged:AndroidElectronicsHaptic TechnologiesLatest DevicesLatest GadgetsNew GadgetsNew MaterialsNew ProductsPaypalScience UpdatesTechnology UpdatesVerizon
Related articles
All articlesFDA QMSR 2026: What Medical Device Founders Should Change Before the Next Prototype
For founders and product teams building Class I/II hardware: what actually changed when FDA's QMSR replaced the old QS framework, and how to keep early prototypes from becoming regulatory debt.

Medical Device Design Companies: Who Fits Which Device Class
Which medical device design companies fit Class I, Class II and Class III programs, what design controls and ISO 13485 actually cost, and when a general product firm is the wrong call.

Medical device prototyping: the steps, the cost and the paperwork
What it takes to prototype a Class I or Class II device, how design controls change the work, and realistic cost and timing before you spend anything.
Services related to this guide
- Product design servicesIndustrial design and CAD taken all the way to manufacturable files.
- Rapid prototypingWorking prototypes in days, from 3D printing to vacuum casting.
- Electronic design servicesSchematic, PCB layout, firmware and bring-up, through to production handoff.
- Product development examplesReal projects we designed, prototyped and shipped.
