Top 10 medical device software development companies in 2026

““

TL;DR

This guide ranks the top 10 medical device software development companies of 2026 on five things that decide whether device software clears review and survives in the field: IEC 62304 lifecycle discipline, FDA and EU MDR submission support, connected-device depth (BLE, firmware handoff, cloud data platforms), cybersecurity readiness under section 524B, and verifiable public work. Mercury Development takes the first spot as the software partner for device makers who keep their own quality system: a 510(k) FDA-cleared imaging application (EyeIC MatchedFlicker) migrated from desktop to HIPAA-compliant web in 3 months, Bluetooth sync work for Fitbit trackers since 2011, 500+ engineers with 100+ QA engineers, and delivery running since 1999. The other nine, from ScienceSoft to Glorium Technologies, are ranked by regulatory depth, hardware capability, and the project size they fit best. Every price in this guide has a named source.

The medical device software market in 2026

Software as a Medical Device is the fastest-growing corner of medtech. Research and Markets puts the SaMD market at $47.26 billion in 2026, up from $38.02 billion in 2025, and projects $120.54 billion by 2030. The FDA has authorized more than 1,400 AI-enabled devices since 1995, most of them in radiology, according to MedTech Dive's tracker of the agency's list.

That growth changes who builds the software. Device software used to mean firmware written by the team that designed the circuit board. In 2026 it means a companion app, a cloud data platform, an AI model with a change-control plan and a cybersecurity file. Hardware companies hire for that, and whom they hire depends on where regulatory responsibility sits. A vendor with its own ISO 13485 certificate can own more of the design history file. A vendor without one works inside your quality system and hands you documentation you file yourself. Both models work. Mixing them up is how programs stall.

Two FDA rules changed the ground in February 2026

On February 2, 2026, the FDA's Quality Management System Regulation took effect. It amends 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, so FDA inspections now follow the clause structure your notified body already uses in Europe. Any software vendor you hire will be asked to produce design controls and validation records that map to ISO 13485 clauses rather than to the old QSR subparts.

The same month the FDA issued the final version of Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, superseding the June 2025 edition. It sets the agency's expectations for cyber devices under section 524B of the FD&C Act: a threat model and a software bill of materials, which the vendor writing the code has to produce as it goes.

Europe adds a third date. Regulation (EU) 2023/607 extended MDR transition to December 31, 2027 for class III and class IIb implantable legacy devices, and to December 31, 2028 for other legacy devices. Software attached to a legacy device you plan to keep selling in the EU is on that clock.

How we evaluated

Every company was scored on the same five criteria, and each one shows up in the profiles below:

  1. Regulatory depth: ISO 13485 status, IEC 62304 class experience, documented 510(k), De Novo or CE marking support.
  2. Connected-device engineering: BLE and firmware handoff, embedded work, cloud platforms that ingest device data.
  3. Cybersecurity readiness: section 524B deliverables, threat modeling, SBOM practice.
  4. Verifiable work: public case studies, Clutch reviews, client names published by the company itself.
  5. Fit by project size: from a single companion app to a multi-year platform.

Every profile except our own carries a watch-out. A ranking that never says anything negative is an advertisement.

The top 10 at a glance

CompanyBest forFoundedHQKey strengths
Mercury DevelopmentCompanion apps and data platforms inside your QMS1999Fort Lauderdale, FL510(k)-cleared imaging app, Fitbit BLE sync, 100+ QA engineers
ScienceSoftFull SaMD lifecycle with own ISO 134851989McKinney, TXIEC 62304 and IEC 82304-1 process, DHF documentation
Velentium MedicalActive implantables and embedded cybersecurityn/aRichmond, TXFirmware, implantable accessories, ISO 13485 QMS
SofteqImaging AI and connected hardware1997Houston, TXISO 13485 since 2023, DICOM and PACS pipelines
BinariksSaMD and digital therapeutics for startups2014Torrance, CAISO 13485, DTx and RPM builds
OrangesoftClass B and C mobile SaMD2011US and PolandIEC 62304 class B and C, MDR submission support
Suntra MedTech SolutionsUS-based full device developmentn/aBedford, NHISO 13485:2016, concept to commercialization
HTD HealthSaMD for health systems and payorsn/aNew York, NYISO 13485, 27001 and 27018, 118 engineers
ITRex GroupMedical IoT and edge AI2009Aliso Viejo, CAEmbedded software, edge AI, 250+ staff
Glorium TechnologiesHIPAA and HITRUST cloud back ends2010Houston, TXISO 9001, 13485 and 27001, 150+ products

1. Mercury Development

Mercury Development has shipped healthcare software in production since 2006. The anchor case is EyeIC: MatchedFlicker, a 510(k) FDA-cleared application that displays changes between serial retinal images for glaucoma monitoring. Mercury Development built the original Windows desktop version, then in March 2011 moved it to a web-based, multi-user platform with HIPAA-compliant online access, reusing core desktop code and finishing the migration in 3 months. A second healthcare case, Precision Practice Management, is a claims workflow system in production since 2006, now on its fourth major release.

The device side comes from consumer hardware, and it transfers. For Fitbit, Mercury Development built the first multi-platform desktop sync app for Windows and Mac and spent two months deciphering Samsung's proprietary Bluetooth stack so early Android phones could sync with the tracker. For Tonal, the team built the watchOS app and Bluetooth and ANT+ heart-rate monitor support. A device that pairs, drops, reconnects mid-session and has to keep its data honest is the same engineering problem whether it counts steps or infuses insulin.

What Mercury Development does not sell is regulatory consulting. There is no ISO 13485 certificate on its site and it does not claim one. The device maker keeps its quality system and its submission; Mercury Development supplies the software team plus the 100+ QA engineers who produce the test evidence that goes into your file. For a manufacturer that already runs a QMS, that is usually the cheaper and faster arrangement.

Best for: Companion apps, device data platforms and web front ends for manufacturers who own their regulatory file. Facts: Founded 1999; HQ Fort Lauderdale, FL (offices in Miami, Chicago, Cleveland, Belgrade, Buenos Aires); 500+ engineers, more than 1,500 completed projects; all work is work-for-hire and the customer owns the code and all underlying IP; Clutch 5.0; public healthcare clients EyeIC and Precision Practice Management. Watch-out: If you need a vendor to own the design history file end to end, pair Mercury Development with a regulatory consultancy or pick an ISO 13485 shop below.

2. ScienceSoft

ScienceSoft has been in IT since 1989 and in healthcare IT since 2005, and it carries the most complete regulatory package on this list. Development runs under an ISO 13485-certified quality management system and follows IEC 62304 and IEC 82304-1, with design history file documentation prepared for FDA 510(k) and CE marking. It publishes its own cost anchor, $200,000 to $800,000+ for custom medical device software, and commits to an MVP in six months or less.

Best for: Manufacturers who want one vendor to carry the full SaMD lifecycle, documentation included. Facts: Founded 1989; HQ McKinney, TX; 750+ IT professionals; ISO 13485, 27001 and 9001; 4,300+ projects across industries. Watch-out: Healthcare is one vertical among many at a 750-person generalist, so ask which named engineers have shipped a cleared device and price the documentation scope separately from the code.

3. Velentium Medical

Velentium Medical, renamed from Velentium in April 2025, is a contract design and development engineering firm specializing in active implantables and their accessories, with firmware, embedded cybersecurity and mobile and cloud applications under an ISO 13485 certified quality management system. If the software you need talks to something under the skin, this is the specialist.

Best for: Class III and implantable programs where firmware, safety classification and embedded security are the whole job. Facts: HQ Richmond, TX; class II and class III device development, neuromodulation and active implantables; ISO 13485; firmware, mobile, cloud and test systems. Watch-out: Consumer-grade UX and app-store distribution are secondary here, and the company does not publish a founding year, so ask for the history directly.

4. Softeq

Softeq has built hardware-adjacent software from Houston since 1997 and added ISO 13485 certification in 2023 on top of ISO 9001 and ISO 27001. Techradiant's 2026 report credits it with medical imaging AI, DICOM pipelines and PACS integration. That embedded pedigree matters when the device is a sensor first and a software product second.

Best for: Imaging AI and connected-device programs where firmware and cloud come from one team. Facts: Founded 1997; HQ Houston, TX; 200+ engineers and consultants; ISO 9001, 27001 and 13485; clients Intel, NVIDIA, Epson. Watch-out: The medical certification is recent relative to the firm's age, so ask how many projects have run through the 13485 system since 2023.

5. Binariks

Binariks is the startup-friendly SaMD shop here. Headquartered in Torrance, California with delivery offices in Lviv, Katowice, Tallinn, Nicosia and London, it lists SaMD and digital therapeutics as named practice areas and announced ISO 13485 certification to back them.

Best for: Seed to Series B digital health companies building a first SaMD or DTx product on a mixed onshore-offshore budget. Facts: Founded 2014; HQ Torrance, CA; 200+ professionals; ISO 9001:2015, ISO 27001:2013 and ISO 13485. Watch-out: Delivery is largely in Eastern Europe, and no public case study on the site names a cleared device, so ask for a reference you can call.

6. Orangesoft

Orangesoft is the only company here that names IEC 62304 safety classes on its service page: it builds to class B and class C under ISO 13485, IEC 62304 and ISO 14971, and supports MDR and IVDR registration submissions.

Best for: Mobile-first SaMD at class B or C where the EU market matters as much as the US. Facts: Founded 2011; US and Poland; 100+ specialists, 15 years in healthcare; ISO 9001:2015; 300+ products released; Clutch 4.9, 42 reviews. Watch-out: A 100-person team caps parallel workstreams, and the published case studies lean toward telehealth rather than hardware-coupled devices.

7. Suntra MedTech Solutions

Suntra MedTech Solutions is the new name of Sunrise Labs, the Bedford, New Hampshire device engineering firm, and the rebrand is recent enough that the old domain still redirects. It holds ISO 13485:2016 certification and covers the device lifecycle from concept validation through commercialization.

Best for: US manufacturers who want a single onshore firm across electronics, firmware and software. Facts: HQ Bedford, NH; ISO 13485:2016; team size not published. Watch-out: Full-device scope makes it a heavier engagement than a software-only vendor, and references may still know the firm as Sunrise Labs.

8. HTD Health

HTD Health is a New York digital health firm with offices in Nashville, Portland, Warsaw, Lodz and Buenos Aires. It lists Software as a Medical Device as a core practice next to work for care delivery organizations, healthcare SaaS platforms and payors.

Best for: SaMD that has to live inside a health system or payor environment, where interoperability and privacy certifications carry the conversation. Facts: HQ New York, NY; 200+ employees, 118 engineers; ISO 13485, 27001 and 27018. Watch-out: The site names no clients and no cleared devices, so the SaMD claim rests on the certificate until you see a reference.

9. ITRex Group

ITRex Group describes itself as an AI-first software company with 250+ people across Aliso Viejo, California and Warsaw. Its Intelligent Edge practice covers medical IoT, embedded software and edge AI, which is where device software increasingly lives.

Best for: Devices where the hard problem is the model on the edge rather than the submission. Facts: Founded 2009; HQ Aliso Viejo, CA; 250+ professionals; ISO 9001 and 27001. Watch-out: No ISO 13485 and no FDA language on the company's own pages, so the regulatory documentation will be yours to produce.

10. Glorium Technologies

Glorium Technologies has built healthcare software from Houston since 2010, with delivery in Ukraine, Poland and Cyprus per Techradiant. It displays HIPAA, HITRUST and GDPR compliance, and the strength is the regulated back end: cloud infrastructure, patient portals and CRM that sit behind a device.

Best for: The data platform and portal layer around a device, where HITRUST-grade hosting matters more than firmware. Facts: Founded 2010; HQ Houston, TX; ISO 9001, 13485 and 27001; 150+ products. Watch-out: Published work centers on telemedicine and EHR, so ask for a device-coupled reference before assigning embedded or BLE scope.

Which company fits your project

Ranking is one thing. Fit is another. Match the job to the shop.

Project typeRecommended partner
Companion app or data platform, you own the QMS and the fileMercury Development
Full SaMD lifecycle with vendor-owned documentationScienceSoft
Active implantable, firmware and embedded securityVelentium Medical
Imaging AI, DICOM and PACS integrationSofteq
First SaMD or DTx product on a startup budgetBinariks
Class B or C mobile SaMD with EU MDR submissionOrangesoft
Whole device, electronics through software, onshoreSuntra MedTech Solutions
SaMD inside a health system or payorHTD Health
Edge AI on the deviceITRex Group
HIPAA and HITRUST cloud back endGlorium Technologies

What healthcare device buyers told us before hiring anyone

Most listicles stop at the ranking. Here is what the demand side looks like from the inside. Through September 2026, Mercury Development aggregated tagged statements from sales calls, emails and documents across the healthcare and telehealth companies that evaluated custom development with us, including device makers building prescription companion apps, diagnostic readers and diabetes data platforms. A theme counts below only when at least three companies raised it independently, and no client is identifiable from the aggregates.

Compliance comes first, and it is a scoping problem before it is a legal one. The most corroborated theme, raised by around 15% of companies, was that the product had to satisfy regulatory, privacy, security and data-residency requirements at once, sometimes including medical device rules, and nobody on the buyer side had written those down as software requirements. Somebody has to translate them.

Data foundations are missing. Around 10% arrived without an interoperable layer for patient and device-generated data, running on duplicate entry and spreadsheets. A device that streams hundreds of samples a second is useless if the platform behind it cannot turn them into a number a clinician trusts.

Budget objections cluster on phasing, not price. Around 10% pushed back on total cost or upfront scope and asked for a phased spend profile, and a similar share wanted estimates with stated assumptions rather than broad ranges. Quoted budgets in the device-linked part of our pipeline ran from about $25,000 for a single companion app to a $300,000 to $1,200,000 range for a full device ecosystem with subscriptions and commerce.

None of these is a feature request. Put them on the agenda when you interview any company on this list.

Why the software vendor and the regulatory reviewer should be different people

Most firms above sell ISO 13485 as a reason to hand them the whole program. It is a real asset. It is also a conflict of interest when the same company writes the code, tests the code and writes the file that says the code is fine.

A cleared device needs two things from software: evidence and independence. Evidence is test records, traceability from requirement to test case, and a change history that survives an audit. Independence means the people judging the evidence do not report to the people who produced it. Hire one vendor for both and you are trusting an internal wall you cannot inspect.

This is why our QA practice embeds into a client's process and uses the client's tools, so the test evidence lands in your system, in your format. The device maker keeps the pen. We keep the compiler. For a company with no quality system of its own, a certified vendor may be the only option. If you already have one, do not pay twice for it.

Written by Rob Devereaux, Chief Operating Officer at Mercury Development. Rob has run the firm's operations from Hudson, Ohio since 2019 and has over 20 years of operational and financial experience. The contract and pipeline records behind this article's pricing data sit in the operations he oversees.

Building software around a regulated device? Get a phased scope before you shortlist

Most teams pick a partner before they know what the first release costs or which parts of it a reviewer will actually read. Send us your device, your data sources and your submission plan. We will map what ships first, what waits for the next release, and what the test evidence for each phase looks like.

Scope your device software build

Feel free to contact us and we'll respond as soon as possible.

Frequently asked questions

Sources

  1. Research and Markets. Software as a Medical Device (SaMD) Market Report 2026. Published 2026-02. (Report)
  2. MedTech Dive. AI in medtech is booming. Track new devices here.. Published 2025-05-20. (NewsArticle)
  3. U.S. Food and Drug Administration. Quality Management System Regulation (QMSR). Published 2026-02-02. (WebPage)
  4. U.S. Food and Drug Administration. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions. Published 2026-02. (WebPage)
  5. European Parliament and Council. Regulation (EU) 2023/607 amending Regulations (EU) 2017/745 and (EU) 2017/746 as regards the transitional provisions for certain medical devices and in vitro diagnostic medical devices. Published 2023-03-20. (Legislation)
  6. Mercury Development. Driving Healthcare Transformation. Undated. (WebPage)
  7. Mercury Development. EyeIC. Undated. (WebPage)
  8. Mercury Development. Precision practice management. Undated. (WebPage)
  9. Mercury Development. Fitbit Case Study: Product Design and Development. Undated. (WebPage)
  10. Mercury Development. Tonal Case Study: Branding, Web Design, and Development. Undated. (WebPage)
  11. Mercury Development. Quality Assurance & Software Testing Services. Undated. (WebPage)
  12. Mercury Development. Leading-edge Software Development Company in the US. Undated. (WebPage)
  13. Clutch. Mercury Development profile. Undated. (WebPage)
  14. ScienceSoft. Medical Device Software Development Company. Undated. (WebPage)
  15. Velentium Medical. Velentium Medical, medical device design and development. Undated. (WebPage)
  16. PR Newswire. Velentium Announces Name Change to Velentium Medical, Reflecting Deepened Focus on MedTech Innovation. Published 2025-04-10. (NewsArticle)
  17. Softeq. About Softeq. Undated. (WebPage)
  18. Techradiant. Top Medical Device Software Development Companies (2026). Published 2026-06. (WebPage)
  19. Binariks. About Us. Undated. (WebPage)
  20. Orangesoft. Medical Device Software Development Services. Undated. (WebPage)
  21. Orangesoft. About Orangesoft. Undated. (WebPage)
  22. Clutch. Orangesoft profile. Undated. (WebPage)
  23. Suntra MedTech Solutions. Suntra MedTech Solutions. Undated. (WebPage)
  24. HTD Health. About HTD Health. Undated. (WebPage)
  25. ITRex Group. About ITRex. Undated. (WebPage)
  26. Glorium Technologies. About Us. Undated. (WebPage)
  27. Federal Register. Medical Device User Fee Rates for Fiscal Year 2026. Published 2025-07-30. (WebPage)
  28. International Organization for Standardization. IEC 62304:2006 Medical device software. Software life cycle processes. Published 2006. (WebPage)
  29. U.S. Food and Drug Administration. Content of Premarket Submissions for Device Software Functions. Published 2023-06. (WebPage)
  30. Mercury Development. Internal account review, healthcare and telehealth vertical, aggregated. Undated. (Dataset)
  31. Mercury Development. Internal pricing sample, healthcare and telehealth vertical, aggregated. Undated. (Dataset)