A team that has shipped three consumer products successfully will still be blindsided by their first medical device. Not because the engineering is harder — a blood pressure monitor is mechanically simpler than a power tool — but because the deliverable is different. In a consumer product, the deliverable is a working product. In a medical device, the deliverable is a working product plus documented objective evidence that it was developed under control and does what you claim. If the evidence does not exist, the device does not exist, however well it works.

That single shift reorganizes everything: the schedule, the cost, who is on the team, how changes are made, and what happens after launch. Here is what actually changes.

The process itself becomes a regulated artifact

Consumer development is judged by outcome. Medical development is judged by process. Under 21 CFR 820.30, an FDA-regulated device manufacturer must run a defined design control system: design and development planning, design inputs, design outputs, design reviews, verification, validation, design transfer, design changes, and a design history file. Each of those is a required record with signatures and dates.

Practically, this means you cannot iterate first and document later. An FDA inspector reading your file must see requirements that existed before the design, reviews that happened at the right moments, and test results traceable back to specific requirements. Reconstructing that after the fact is both obvious and a serious finding. The full structure is laid out in how FDA design controls work, and everything they generate is compiled into the design history file.

Around that sits a quality management system — ISO 13485 in practice, harmonized with FDA expectations — covering document control, supplier controls, CAPA, training records, and internal audits. A consumer startup can run on shared drives and group chat. A device company cannot.

Risk management is a formal, continuous discipline

Consumer products handle risk with a safety review, a few standards tests, and good judgment. Medical devices run ISO 14971 risk management as a living process across the whole lifecycle: identify hazards, estimate risk, implement controls, verify each control actually works, and evaluate residual risk against defined criteria. Every design decision that touches a hazard is traceable back to the risk file, and every post-market complaint feeds back into it.

The consequence engineers feel most: you cannot mitigate a risk with a warning label if a design change could eliminate it. The hierarchy is inherent safety by design first, protective measures second, information for safety last. That constrains architecture choices in ways consumer work never does.

Classification decides how much of this applies

Not every device carries the same weight. The FDA class sets the pathway and most of the cost:

Class IClass IIClass III
Typical pathwayMostly exempt, register and list510(k) clearancePMA approval
Design controlsOften exemptRequiredRequired
Clinical dataRareSometimesAlmost always
Typical regulatory spend$5,000–$40,000$150,000–$600,000$5M–$50M+
Time to market3–9 months12–30 months4–8 years

The first question is not "how do we get cleared" but "is this even a device." A fitness tracker that counts steps is a consumer product; the same hardware claiming to detect atrial fibrillation is a regulated device. The claim, not the technology, draws the line — which is why marketing copy has to be reviewed by the regulatory side before it is published.

Materials and electrical safety are pre-decided

A consumer designer picks a plastic on cost, appearance, and mechanical properties. A device designer starts from patient contact: anything touching skin, mucosa, blood, or tissue must satisfy ISO 10993 biocompatibility. Testing runs roughly $20,000 to $150,000 depending on contact duration and type, and takes two to six months. Change a colorant or switch resin suppliers and you may be re-testing.

Electrically powered devices with patient contact face IEC 60601 electrical safety and EMC testing rather than the ordinary consumer safety and FCC path. Creepage and clearance distances, leakage current limits, and isolation requirements are far stricter, and they change the board layout and the enclosure. Discovering this after the industrial design is frozen means starting the mechanical design again.

Verification, validation, and the word "done"

Consumer teams test until the product feels right. Device teams distinguish two activities precisely: verification asks whether you built the product to the specification, validation asks whether the specification produces a device that meets user needs in real use. Both need protocols written and approved before execution, defined acceptance criteria, and formal reports signed before anyone declares a phase complete.

Human factors is where consumer teams are most often surprised. Under IEC 62366 and FDA's human factors expectations, use-related risk is analyzed, and a summative usability study with representative users under realistic conditions may be required before submission. A consumer usability session is qualitative research; a summative study is regulatory evidence with a protocol, a sample size, and defined critical tasks. Budget $40,000 to $150,000 and several months when one is needed.

Change control changes the pace of everything

This is the difference that most frustrates good engineers. In consumer work, a supplier substitution or a small tolerance change is a Tuesday afternoon decision. In a device, every post-release change goes through a documented change control process: assess the impact on risk, on verification, on the submission itself, then decide whether it requires a new 510(k). Swapping a screen, a battery cell, or a molding house are all decisions with regulatory consequences.

The knock-on effect is that you cannot design around a component shortage in a week. Second-sourcing has to be planned into the original submission, or you will be filing paperwork while your line is stopped.

Cost and timeline multipliers

Roughly, for a comparable piece of hardware:

  • Engineering effort: 1.5× to 2.5× a consumer equivalent, mostly documentation, traceability, and formal testing.
  • Schedule: 2× to 3×, driven by test lab queues, submission review cycles, and clinical work.
  • Team: add regulatory affairs, quality, and often clinical and human factors specialists.
  • Manufacturing: validated processes, IQ/OQ/PQ, controlled environments, and supplier audits.
  • Cost of goods: higher, since design changes to save pennies later are expensive to requalify.

Detailed ranges by device type are in what it costs to develop a medical device. The important planning point is that regulatory and quality spend is not a percentage added at the end — it is a parallel workstream from day one.

Launch is not the finish line

Consumer products go quiet after launch except for support and reviews. Devices enter a permanent obligation: complaint handling with defined timelines, adverse event reporting through MDR, CAPA investigations, periodic risk file updates, UDI labeling and database submissions, and for connected devices an ongoing cybersecurity posture with patching commitments. This is real, budgeted headcount, described in post-market surveillance duties after launch.

What transfers, and what does not

Consumer product skill is genuinely valuable here — devices designed by people with consumer instincts tend to be more usable, better looking, and cheaper to build, and the market increasingly rewards that, especially for home-use products. What does not transfer is the working rhythm. Ship-and-iterate becomes plan-verify-document. Founders who accept that early and staff for it succeed; founders who treat the quality system as bureaucracy to be minimized fail an audit or, worse, a submission, after the money is gone.

The practical advice: decide your regulatory pathway before detailed design starts, put the quality system in place before the first design output, and bring regulatory expertise in at the concept stage rather than at submission time. Projects House develops regulated and unregulated hardware through a global engineering and manufacturing network, with design controls built into the project structure from the definition phase. If you are trying to work out how much of this applies to your product, describe it through our contact form.