The hidden cost of building your own QMS

August 24, 2026 ░░░░░░

Software bill of materials (SBOM) for medical devices what FDA expects in 2026 (2)

Most early-stage medical device companies never decide to skip a quality management system (QMS). They just never decide to buy one. The founding team opens a shared drive, builds a spreadsheet for design inputs and outputs, starts a document register in another tab, and agrees to sort out the real system closer to submission. On the invoice, that approach costs nothing. But that zero is exactly why it ends up being so expensive.

Building your own QMS in spreadsheets and folders is one of the most common ways medical device companies experience the “cost of doing nothing.” The tools feel free because the price never lands in one place. It shows up later, spread across rework, lost traceability, and audit risk. And by the time you add it up, it dwarfs the subscription you were avoiding.

BONUS RESOURCE: Download the Content Toolkit for Product Developers

Where the cost actually hides

A QMS is not one document. It is the connected set of processes a medtech company runs to prove its device is safe and effective: document control, training records, design controls and the design and development file (DDF), risk management, corrective and preventive action (CAPA), complaint handling, supplier management, audit management, and change control. On a build-your-own setup, each of these starts life as a tab or a folder. Each one looks manageable in isolation. The expense is not in any single sheet. It lives in keeping all of them current, consistent, and connected to each other, by hand, forever.

The trouble with running one process this way is already well documented. Managing design controls on spreadsheets always results in broken revision control and missing links to risk management. But that’s just a single function. A whole-QMS build takes the same failure and repeats it across nine process areas at once, then adds a tenth problem no individual spreadsheet has on its own. The connections (or lack thereof) between them.

The manual tasks are where it gets expensive

In a purpose-built system, a change to a design input ripples automatically to the outputs it drives, the verification tests that cover it, the risks it affects, and any CAPA tied to those risks. In a spreadsheet build, none of those references are live. Update one cell and the related records in five other files fall out of date. The system does not fail spectacularly. It drifts, and the gap stays invisible until an auditor pulls one thread and finds the other end no longer matches.

Adding up the bill

The hidden cost of doing nothing tends to build in four places.

  1. The first is maintenance labor. Every sheet needs an owner, and that owner spends hours on version control that dedicated QMS software would handle on its own: renaming files, reconciling two people's edits, re-sending the current copy, rebuilding a tracker after someone sorted a column the wrong way. None of that work moves the device closer to market, and it exists purely to keep a fragile workaround from collapsing.

  2. The second is broken traceability, which is where compliance risk concentrates. FDA's design control requirements under 21 CFR 820 expect a traceable DDF, and the Quality Management System Regulation (QMSR), in effect since Feb. 2, 2026, folds ISO 13485:2016 and its documented-information requirements into U.S. law. Traceability that depends on a person remembering to update six files is not traceability you can count on. Gaps turn into findings, and findings turn into delays.

  3. The third is audit and submission prep. When evidence lives scattered across folders and tabs, getting ready for an audit or assembling a 510(k) means rebuilding the record from scratch, hunting for the current revision, screenshotting spreadsheets, and chasing signatures that were never captured in a controlled way.

  4. The fourth is data integrity, and it is the one auditors probe hardest. A general-purpose spreadsheet does not provide the time-stamped, computer-generated audit trail or the controlled electronic signatures that 21 CFR Part 11 requires for electronic records. An editable Excel file with no record of who changed what, and when, hands a reviewer a reason to question the numbers in it. Layer key-person risk on top, where the logic of the entire system lives in one employee's head, and a single resignation can turn a passable setup into a map nobody else can read.

Underneath all four sits the biggest cost of the build-your-own approach. The hours your founders and engineers pour into maintaining a quality system are hours they are not spending on the product. For a pre-market team racing a submission window, that trade can be the whole ballgame.

The bill also grows with the company. A spreadsheet system that can hold together at five people quickly becomes unworkable at 30, when there are more devices in flight, more design changes, more suppliers to qualify, and more hands editing the same files with no controlled way to see who touched what. The workaround does not break on a schedule you get to choose. It breaks when a new hire cannot find the current procedure, or when a notified body asks for a change history that the folders simply cannot produce.

Deferral is the most expensive option

The standard answer to all of this is to fix it later, closer to submission, when there is budget and time to spare. But cleanup always costs more than setup. A record that was never captured correctly cannot be rebuilt cleanly a year after the fact, and remediating twelve months of untraceable design decisions under submission pressure is far harder than doing it right the first time. Six months of delay is rarely bad luck. More often it is the bill for a build-your-own QMS finally coming due.

BONUS RESOURCE: Download the Content Toolkit for Product Developers

A right-sized QMS from Greenlight Guru eliminates the hidden costs of paper

None of this argues for a sprawling, enterprise-grade quality system that takes a year to stand up. Early teams are right to resist that. The real alternative to the spreadsheet build is a right-sized system: enough structure to hold the foundational processes without the bloat a startup has no use for yet. A pre-market team needs document control, design controls, risk management, and a handful of core records working together from day one, not a hundred modules it will never touch.

Greenlight Guru's eQMS is built for exactly that. It gives early medtech teams design controls, risk management, document control, CAPA, and supplier and audit management in one place, with traceability built into the records as the work happens instead of reconstructed the night before an audit. It maps to ISO 13485 and the QMSR out of the box, and because it connects to the tools engineers already use, like Jira and GitHub, the work they do gets captured without anyone

See how Greenlight Guru's pre-market eQMS gives early medtech teams a quality system that is audit-ready from day one. Get your free demo today.

Etienne Nichols is the Head of Industry Insights & Education at Greenlight Guru. As a Mechanical Engineer and Medical Device Guru, he specializes in simplifying complex ideas, teaching system integration, and connecting industry leaders. While hosting the Global Medical Device Podcast, Etienne has led over 200...

Content Toolkit for Product Development
Download Now →
content toolkit - Product Development
Search Results for:
    Load More Results