Blog › ICP guides

Biomedical engineer on retainer: FDA 510(k) advisory, design V&V, ISO 14971 risk management, and ISO 13485 QMS support on monthly retainer

July 25, 2026 · ~21 min read

A Class II medical device company files a 510(k) submission with FDA. The submission is prepared by an internal regulatory affairs team with support from a biomedical engineering consultant who reviews the substantial equivalence argument, the performance testing protocol, and the predicate comparison data. The 510(k) receives a first-cycle clearance in 97 days. The engagement with the biomedical engineering consultant ends when the clearance letter arrives. The product enters the commercial market.

Eighteen months later, the same company is preparing a second-generation design with three modifications: a new electrode material that reduces sensor drift, a revised housing geometry that improves ergonomics, and a firmware change that adjusts the glucose reading algorithm. The regulatory affairs team submits a design change assessment and concludes that the three modifications collectively do not significantly change the device’s safety or effectiveness, making a new 510(k) unnecessary. FDA disagrees and issues a 513(g) classification request, then a Warning Letter, noting that the electrode material change introduces a new material biocompatibility profile that requires biocompatibility testing not conducted for the original device, and that the algorithm change introduces new performance characteristics not covered by the original 510(k)’s substantial equivalence argument. The company faces a Class I recall, a mandatory 510(k) for the modified device, and $2.1 million in remediation costs.

The Warning Letter review identifies two things that went wrong. First, the design change assessment was conducted without biomedical engineering input — the regulatory affairs team applied the FDA design change guidance without the engineering expertise to evaluate whether the electrode material change constituted a new material contact requiring ISO 10993 biocompatibility evaluation. Second, there was no ongoing risk management advisory that would have flagged the firmware algorithm change as a new performance characteristic requiring V&V testing scope expansion. Both problems were identifiable at the design change proposal stage, before engineering resources were committed to prototyping. The biomedical engineering advisory that would have caught both issues would have cost approximately 14 hours. The remediation cost $2.1 million.

FDA 510(k) submission support advisory

510(k) submission support advisory is the biomedical engineer retainer function that shapes regulatory outcomes before the submission window opens. The 510(k) clearance decision depends on the quality of the predicate device selection, the rigor of the substantial equivalence argument, the defensibility of the performance testing acceptance criteria, and the completeness of the special controls documentation — all of which are established in the design and development phase, months before the submission is prepared.

Predicate device selection strategy and substantial equivalence argument development

Predicate device selection is the foundational decision in a 510(k) strategy. A predicate device is a legally marketed device to which the new device is compared to establish substantial equivalence — same intended use, and same technological characteristics, or different technological characteristics that do not raise new safety or effectiveness questions. The choice of predicate determines which performance characteristics FDA will expect to see compared, which special controls apply, and whether the submission requires performance testing, clinical data, or both.

In one predicate selection advisory, a biomedical engineering consultant reviewed the 510(k) strategy for a transcutaneous oxygen monitoring device intended for neonatal care. The regulatory affairs team had identified two predicate candidates from the FDA 510(k) database: K190847, a pulse oximetry device with the same intended use population (neonatal patients) but measuring oxygen saturation rather than transcutaneous oxygen tension; and K211439, a transcutaneous oxygen monitor with the same measurement technology but intended for adult patients in a chronic wound healing context. Neither predicate was ideal: K190847 had the intended use match but a different measurement technology requiring a technological characteristics comparison that would need to demonstrate equivalent performance through a head-to-head accuracy study; K211439 had the measurement technology match but a different intended use population requiring a clinical performance comparison that would need to demonstrate equivalent accuracy in neonatal versus adult skin.

The consultant reviewed the 510(k) database for a third predicate candidate that had both neonatal population and transcutaneous oxygen measurement technology, and identified K031822, a transcutaneous oxygen monitor for neonatal use cleared in 2003, as a split-predicate candidate. Split-predicate strategies allow a submitter to use different predicates for different aspects of the substantial equivalence argument — one predicate for intended use and a different predicate for technological characteristics. The FDA split-predicate guidance requires that the combination of predicates does not create a device that is substantially different from any single marketed device, and that both predicates are used to establish all aspects of substantial equivalence.

The consultant developed a split-predicate framework using K031822 for intended use and measurement technology, and K211439 for the specific sensor design and electrode characteristics, with a performance comparison table showing that the new device’s accuracy specification (±3 mmHg across the 10–150 mmHg measurement range) was equivalent to or exceeded both predicates. The predicate analysis and substantial equivalence argument framework development took 22 hours over three sessions. The 510(k) submission using the split-predicate strategy received a first-cycle clearance in 86 days. A submission using K190847 alone, which the regulatory affairs team had been preparing before the consultant’s involvement, would have required a clinical accuracy study that the company estimated at $380,000 and 14 months.

Performance testing protocol review and acceptance criteria defensibility

Performance testing is the empirical basis for the substantial equivalence argument. FDA reviewers evaluate not only whether the performance data demonstrates equivalence but whether the test method and acceptance criteria are appropriate — whether the tests measure what they claim to measure, whether the test conditions reflect the device’s intended use environment, and whether the acceptance criteria are consistent with industry standards, FDA guidance, and predicate device labeling.

In one performance testing protocol review, a biomedical engineering consultant reviewed the draft V&V test protocols for a Class II implantable cardiac monitor prior to the test lab engagement. The protocols included an electromagnetic compatibility (EMC) test per IEC 60601-1-2, a biocompatibility evaluation per ISO 10993-1, and an electrical safety test per IEC 60601-1. The consultant identified three protocol issues that would have produced test data FDA would reject during 510(k) review. First, the EMC test plan specified testing to the 2014 edition of IEC 60601-1-2 rather than the 2014+AMD1:2020 edition, which FDA had adopted as the current edition in a 2022 guidance update; data collected under the superseded edition would require retesting. Second, the biocompatibility evaluation did not include cytotoxicity testing for a new polymer coating applied to the device housing, which constituted prolonged skin contact (greater than 30 days) requiring cytotoxicity, sensitization, and implantation testing under ISO 10993-1 for that contact duration. Third, the electrical safety test included a leakage current test but used the B-type applied part classification rather than the BF-type classification appropriate for an implantable device with conductive connections near the heart; the wrong classification applied a leakage current limit 10 times higher than the correct limit. The consultant’s protocol review took 8 hours and identified $47,000 in retesting costs that would have been incurred after submission rather than before.

Design verification and validation advisory

Design verification and validation (V&V) advisory is the biomedical engineer retainer function that ensures design outputs are evaluated against design inputs in a manner defensible to FDA reviewers and ISO 13485 auditors. Verification confirms that the device design outputs meet the design inputs (the device was built right); validation confirms that the device meets user needs and intended uses (the right device was built). Both functions require that test methods be validated, that sample sizes be statistically justified, and that acceptance criteria be traceable to the design input requirements they are intended to verify or validate.

Test method validation and measurement system analysis

Test method validation establishes that a measurement procedure produces accurate, repeatable, and reproducible results when applied to the device characteristic being measured. An unvalidated test method produces data that FDA reviewers cannot accept as evidence of design output conformance: if the test itself cannot be shown to measure what it claims to measure with sufficient precision, the data collected with that test cannot establish that the device meets the design input requirement.

Measurement system analysis (MSA) is the statistical framework for evaluating test method performance. An MSA quantifies the contribution of the measurement system (operator, equipment, and environmental factors) to the total observed variation in the measured characteristic. The key MSA metrics are gauge repeatability and reproducibility (Gauge R&R), which partitions measurement variation into repeatability (same operator, same equipment, same conditions) and reproducibility (different operators, or different equipment). A Gauge R&R study result above 30% contribution of measurement variation to total observed variation indicates that the test method is measuring the test itself rather than the device characteristic.

In one test method validation advisory, a biomedical engineering consultant reviewed the measurement system for a force-displacement test used to verify the deployment force specification for a percutaneous catheter. The specification required that deployment force not exceed 8 Newtons at 25°C. The test was conducted using a digital force gauge on a test fixture that simulated the deployment geometry. The consultant conducted a Gauge R&R study using two operators and three test fixtures across 10 catheter samples, each measured three times. The Gauge R&R result showed 38.4% total measurement variation attributable to the measurement system, well above the 30% acceptance threshold. Analysis of the variance components identified the test fixture geometry as the dominant source of reproducibility variation: slight differences in the angle at which the catheter was loaded into the three fixtures produced force measurements that varied by ±1.4 Newtons between fixtures at the same load level — a 17.5% variation against an 8 Newton specification. The consultant recommended redesigning the test fixture to standardize the loading angle with a mechanical registration feature. After the fixture redesign, the Gauge R&R result improved to 11.2% total measurement variation. The MSA work took 12 hours and prevented FDA from rejecting the verification data on the basis of measurement system inadequacy.

Sample size justification under ASTM and ISO standards

Sample size justification is a recurring FDA 510(k) review issue for medical device V&V testing. FDA reviewers evaluating a 510(k) submission regularly identify performance test reports where the sample size was selected by convention (“we tested 30 units because that’s what we always do”) rather than by statistical justification linked to the design input requirement. A sample size that is not statistically justified cannot establish the performance claim: if the sample size was not calculated to detect a specified defect rate with a specified confidence level, the test result does not demonstrate that the device population meets the requirement.

The standard statistical framework for attribute data (pass/fail tests) in medical device V&V uses reliability and confidence levels. A common acceptance criterion is 95% reliability with 95% confidence (C=95, R=95), which requires a sample of 59 units with zero failures to demonstrate that at least 95% of the device population meets the requirement with 95% confidence. Some FDA guidance documents and voluntary consensus standards specify different reliability and confidence targets; the choice should be traceable to the design input requirement and the risk analysis for the failure mode being tested.

In one sample size advisory, a biomedical engineering consultant reviewed the verification test plan for a single-use surgical retractor’s maximum load capacity specification. The specification required that the retractor support a minimum of 25 Newtons of sustained load for 60 seconds without structural failure. The test plan specified a sample of 20 units. The consultant evaluated the sample size against the risk classification of the failure mode: retractor structural failure during a surgical procedure is a Severity 4 hazard (serious injury) under the risk management file, and the acceptable probability of failure had been set at <1 in 10,000 uses in the FMEA. The sample of 20 units with zero failures demonstrates 90% reliability with 95% confidence under binomial statistics — which means that up to 10% of the device population could fail the load test and the data collected from 20 units would still show zero failures 95% of the time. For a Severity 4 hazard with a <1 in 10,000 acceptable probability target, a sample of 20 units was statistically inadequate to support the risk management file’s risk acceptability finding. The consultant recommended increasing the sample to 46 units (demonstrating <10% failure rate with 99% confidence) as a minimum, with a recommended target of 300 units to approach the 1-in-10,000 threshold at 95% confidence. The sample size advisory took 4 hours and prevented a 510(k) deficiency letter that would have required a test repeat.

ISO 14971 risk management advisory

ISO 14971 risk management advisory is the biomedical engineer retainer function that maintains the risk management file’s integrity between design reviews and submission milestones. The risk management file must cover the entire product life cycle, including post-market surveillance data that may require risk management updates after the device is on the market. An incomplete or inadequately scoped FMEA, a severity classification that does not reflect the actual injury potential, or risk acceptability criteria that are not linked to the device’s benefit-risk analysis all represent vulnerabilities that FDA reviewers and ISO 13485 auditors will identify.

FMEA scope definition and hazard severity classification

FMEA scope definition determines which failure modes are analyzed and which are excluded. A FMEA that covers only the device’s primary functional subsystems may exclude failure modes associated with the device-patient interface, the user-device interaction, or the use environment that represent the highest-severity hazard scenarios. ISO 14971 requires that the risk management process consider hazards associated with reasonably foreseeable misuse as well as intended use, and that the analysis include hardware failure modes, software anomalies, and use error scenarios.

In one FMEA scope advisory, a biomedical engineering consultant reviewed the FMEA for a powered wheelchair intended for users with spinal cord injuries. The FMEA covered eight subsystems: motor drive, battery and power management, joystick control interface, tilt and recline mechanism, seating system, frame, wheels and tires, and electronics enclosure. The consultant reviewed the scope against ISO 14971 Annex C’s guidance on hazard identification and identified three scope gaps. First, the electromagnetic interference susceptibility of the joystick control signal was not analyzed: a reasonably foreseeable use scenario involved the chair operating near common hospital EMI sources (MRI rooms, electrosurgical units, portable radios), and EMI-induced joystick signal corruption could produce an unintended drive command, a Severity 5 hazard (fatality or serious permanent injury). Second, the software anomaly analysis did not include the motor speed governor firmware, which constrained maximum motor current and provided the primary protection against runaway speed; a firmware failure in the governor that allowed unconstrained motor acceleration had no corresponding FMEA failure mode or risk control. Third, the tilt mechanism FMEA analyzed failure of the tilt mechanism to hold position (Severity 3, discomfort and possible fall) but did not analyze failure of the tilt mechanism position sensor that provided feedback to the tilt control algorithm; a sensor failure in the seated position could produce erroneous tilt position data that caused the controller to command rearward tilt from a fully upright position without user input, a Severity 5 hazard. The scope gap analysis took 9 hours.

Risk acceptability criteria and post-market surveillance risk review

Risk acceptability criteria define the boundary between acceptable and unacceptable risk, and they must be established before the risk analysis is conducted — not after, to prevent post-hoc adjustment of criteria to make identified risks acceptable. The criteria are typically defined in the risk management plan using a risk matrix that maps severity and probability combinations to risk levels (acceptable, as low as reasonably practicable (ALARP), or unacceptable). The benefit-risk analysis required under ISO 14971 and FDA guidance requires that unacceptable risks be reduced to an acceptable level through risk controls, and that the residual risk after risk controls be acceptable in the context of the device’s clinical benefit.

Post-market surveillance (PMS) data creates ongoing risk management obligations after 510(k) clearance. Complaint data, MDR (Medical Device Report) data, literature search results, and clinical outcome data must be reviewed against the risk management file to determine whether the post-market experience is consistent with the risk analysis conducted during design and development. A change in the observed frequency of a failure mode in post-market data may require a probability rating update in the FMEA, a new risk control, or a design change. In one post-market risk review advisory, a biomedical engineering consultant reviewed 18 months of complaint data for a cleared Class II wound vacuum therapy device. The complaint data included 7 reports of pressure alarm failures in which the device continued applying negative pressure after the alarm condition should have triggered pump shut-off. The FMEA probability rating for the pressure alarm failure mode was P2 (probability 1 in 1,000 to 1 in 10,000 uses). The 7 reports over 18 months against an estimated installed base of 14,000 units implied an observed rate of approximately 1 in 36,000 uses annually — consistent with the P2 probability rating. However, 3 of the 7 reports included patient injury data (tissue maceration and delayed wound healing attributed to over-application of negative pressure), elevating the hazard severity classification from S3 (significant injury requiring medical intervention) to S4 (serious injury with long-term consequence) in those cases. The revised severity classification with the P2 probability rating placed the risk in the ALARP region under the device’s risk matrix rather than the acceptable region. The consultant recommended implementing a risk control in the form of a firmware update that added a secondary hardware interrupt to the pressure alarm circuit and provided a field safety corrective action for in-service units. The post-market risk review took 11 hours.

ISO 13485 QMS and design change advisory

ISO 13485 quality management system advisory covers the design control documentation requirements, nonconforming product procedures, and CAPA system effectiveness that determine surveillance audit outcomes. ISO 13485 requires that the QMS be maintained continuously, not only in preparation for scheduled audits. A Notified Body or FDA Quality System Regulation inspection that finds design control documentation gaps, inadequate nonconforming product disposition procedures, or CAPA records that are open without evidence of effectiveness verification can result in major nonconformance findings that put the CE mark or FDA registration at risk.

Design control documentation and CAPA system effectiveness

Design control documentation under ISO 13485 and 21 CFR Part 820 requires that design inputs, design outputs, design verification, design validation, design review records, and design transfer records be maintained in a Design History File (DHF) that allows FDA investigators and Notified Body auditors to trace how the device design was developed and how each design requirement was verified or validated. A DHF that is incomplete at the time of a surveillance audit — with design review minutes that do not document the participants, the design inputs reviewed, the open items identified, and the closure criteria — represents a major nonconformance under ISO 13485 Section 7.3 (Design and Development).

CAPA (Corrective Action and Preventive Action) system effectiveness is one of the most common major nonconformance findings in ISO 13485 surveillance audits. The CAPA system must demonstrate that root causes are identified through rigorous analysis (not symptom identification), that corrective actions address root causes rather than symptoms, and that effectiveness verification confirms that the corrective action prevented recurrence. A CAPA record that identifies “operator training” as the root cause and “training completed” as the corrective action, without evidence of root cause analysis, is a pattern that experienced Notified Body auditors recognize as a systemic CAPA deficiency.

In one CAPA advisory, a biomedical engineering consultant reviewed the open CAPA records for a Class II in vitro diagnostic device manufacturer preparing for an ISO 13485 surveillance audit scheduled in 11 weeks. The consultant reviewed 23 open CAPAs and identified 7 that had evidence of inadequate root cause analysis: 5 had root causes identified as “operator error” or “inadequate training” without analysis of why the process allowed the operator error to occur; 2 had root causes identified but corrective actions that addressed the symptom (re-inspection of the specific nonconforming lot) rather than the systemic root cause (the incoming inspection procedure that failed to detect the nonconformance). The consultant also identified 4 CAPAs where effectiveness verification records showed that the corrective action was verified by the same individual who implemented it, creating an independence concern that auditors would likely note. The consultant recommended root cause re-analysis for 7 CAPAs, corrective action revision for 2, and effectiveness verification protocol updates for 4. The CAPA review and recommendation took 14 hours. The surveillance audit resulted in zero major nonconformances and two minor observations unrelated to the CAPA system.

Design change assessment for existing cleared devices

Design change assessment is the regulatory determination of whether a modification to a cleared medical device requires a new 510(k) submission or can be implemented without a new submission under FDA’s design change guidance (FDA’s “Deciding When to Submit a 510(k) for a Change to an Existing Device” guidance). The assessment is one of the highest-stakes determinations a medical device company makes, because an incorrect determination that a change does not require a new 510(k) — and the subsequent marketing of a modified device without clearance — is a Class I recall trigger and a Warning Letter basis.

The FDA design change guidance establishes a flowchart-based decision tree that evaluates whether a change affects safety or effectiveness. The decision tree is not self-applying: it requires engineering judgment to determine whether a change to a material, a dimensional specification, a performance characteristic, a software algorithm, or a sterilization method “could significantly affect the safety or effectiveness of the device.” That determination requires both regulatory knowledge of how FDA has applied the guidance in prior enforcement actions and 510(k) decisions, and engineering knowledge of how the change affects the device’s technical function and failure mode profile.

In one design change assessment advisory, a biomedical engineering consultant reviewed three simultaneous design changes proposed for a cleared Class II electrosurgical generator: a software update that modified the power delivery algorithm to improve coagulation consistency, a change to the foot pedal material from thermoplastic elastomer to silicone rubber for improved chemical resistance, and a dimensional change to the front panel display mounting that altered the display viewing angle from 15 to 20 degrees from vertical. The consultant evaluated each change against the FDA design change decision tree. The software algorithm change was identified as requiring a new 510(k): the power delivery algorithm modification changed the device’s output power waveform characteristics in a way that affected the clinical performance of the coagulation function, constituting a “new technology or a new intended use” under the guidance. The foot pedal material change required a biocompatibility evaluation for the silicone rubber formulation (prolonged skin contact) but did not require a new 510(k) if the biocompatibility testing demonstrated equivalence to the prior material. The display viewing angle change did not require a new 510(k) or additional testing. The assessment, which correctly separated the three changes’ regulatory requirements, took 7 hours and directed the engineering team’s V&V and submission resources appropriately rather than treating all three changes uniformly.

Frequently asked questions

What does a biomedical engineer on retainer typically do?

A biomedical engineer on monthly retainer typically provides ongoing advisory across FDA 510(k) submission strategy, design verification and validation (V&V) protocol development and review, ISO 14971 risk management documentation, ISO 13485 quality management system maintenance, and design change assessment for existing cleared devices. In 510(k) advisory, this includes predicate device selection strategy, substantial equivalence argument development, performance testing protocol review, and FDA pre-submission meeting preparation. In V&V advisory, it covers test method validation, measurement system analysis, sample size justification under ASTM and ISO standards, and acceptance criteria defensibility review. In ISO 14971 risk management, it means FMEA scope definition, hazard severity and probability classification, risk acceptability criteria review, and post-market surveillance risk review. In ISO 13485 QMS advisory, it covers design control documentation review, nonconforming product disposition, CAPA system effectiveness, and surveillance audit preparation. In design change assessment, it addresses substantial equivalence impact analysis for design modifications to existing cleared devices. The retainer scope should specify which FDA product codes are in scope and whether engagement covers Class II or Class III device programs.

What biomedical engineering work is most commonly underlogged?

The most systematically underlogged categories in biomedical engineer retainers are: predicate device landscape monitoring (reviewing FDA 510(k) clearance databases quarterly to identify new predicates takes 4 to 6 hours per review cycle but produces no submission document); design review participation advisory (attending an internal design review to evaluate design input-output traceability gaps takes 3 to 5 hours but does not advance any regulatory filing); risk management file updates triggered by post-market surveillance data (reviewing field complaint data for new failure modes requiring FMEA updates takes 4 to 8 hours per review); test report review for V&V completeness (reviewing a contract test laboratory’s report for protocol compliance, acceptance criteria application, and deviation documentation takes 3 to 5 hours per report); and FDA Q-submission preparation (drafting questions and supporting rationale for an FDA pre-submission meeting request takes 8 to 14 hours and determines the substantive content of the meeting but precedes it by 90 days).

What should a biomedical engineer retainer agreement include?

Biomedical engineer retainer agreements should specify: the device product codes and FDA device classes in scope (Class I exempt, Class II 510(k), Class II De Novo, Class III PMA); the regulatory pathway currently active (pre-submission, 510(k) in preparation, cleared device in post-market, design change under assessment); the quality system standard applicable (ISO 13485, 21 CFR Part 820, or both); the FMEA and risk management scope (which systems and subsystems are covered under ISO 14971); how project-scope work (a full 510(k) submission, a complete DHF compilation, or an EU MDR gap assessment) is distinguished from retainer advisory; the design review participation expectation; access to design documentation (DHF, DMR, risk management file, complaint data); and hours visibility access so the VP of Engineering and regulatory affairs lead can see the 510(k) strategy, V&V review, risk management, and QMS advisory hours accumulated between submission and audit milestones.

What are typical retainer rates for biomedical engineers?

Retainer rates for biomedical engineers vary significantly by experience level, regulatory expertise, and the complexity of the device class in scope. Entry-level biomedical engineers (2 to 5 years of experience, primarily design support or test execution roles) typically charge $80 to $130 per hour. Mid-level biomedical engineers (5 to 10 years, with V&V lead or risk management ownership experience) typically charge $130 to $200 per hour. Senior biomedical engineers with FDA 510(k) submission experience and ISO 14971 ownership typically charge $175 to $280 per hour. Biomedical engineers with Class III PMA experience, EU MDR technical documentation expertise, or combination product regulatory experience typically command $220 to $380 per hour. Consultants who also hold Regulatory Affairs Certification (RAC) from RAPS typically charge a 15 to 25% premium for engagements that include regulatory strategy work. Most biomedical engineer retainers run 15 to 35 hours per month, with spikes during 510(k) submission preparation windows, pre-audit periods, and design freeze milestones.

How should biomedical engineer retainer hours be logged?

Biomedical engineer retainer work log entries should capture the device or system in scope, the specific regulatory or engineering task, and the outcome, finding, or decision reached. A useful format is: [Device/System] + [Specific task] + [Finding or decision]. For example: “Glucose monitor Gen 2: 510(k) predicate analysis — reviewed 3 candidate predicates from FDA 510(k) database; K221847 has identical intended use but different measurement technology requiring comparative performance testing to demonstrate equivalent accuracy — documented predicate selection rationale and testing gap: 5 hours.” Or: “Infusion pump: V&V protocol review — identified acceptance criteria of ±5% at 0.1 mL/hr rate that test equipment cannot measure at that accuracy; recommended ±10% at rates below 1 mL/hr consistent with predicate device labeling: 4 hours.” Or: “Surgical stapler: ISO 14971 FMEA update — reviewed 3 Q2 field complaints for FMEA alignment; 1 complaint describing proximal pin shear not in current scope — added new failure mode FM-41, severity S3, probability P2, risk level acceptable with existing controls: 6 hours.” Entries that name the device, regulatory standard, and specific finding make the work log legible as a concrete medical device advisory history.


Tracking biomedical engineer retainer hours with HourTab

Biomedical engineers on monthly retainer face the same billing visibility problem that affects most technical advisory retainers: the visible outcomes of the engagement (the 510(k) clearance, the ISO 13485 surveillance audit passing, the design change correctly classified) occur months after the advisory work that determined those outcomes. The predicate analysis that identified the split-predicate strategy, the protocol review that caught three test method errors before the test lab ran them, the FMEA scope review that identified two missing failure modes, the CAPA review that prevented major nonconformance findings — none of those produce a clearance letter or an audit report. They produce an accurate clearance letter and a clean audit report, months later.

When the monthly invoice arrives, VPs of Engineering and regulatory affairs leads who evaluate the retainer against visible milestones apply a calculation that systematically undervalues ongoing regulatory advisory: “what did we receive this month?” If the answer is “a predicate landscape review, a test protocol review, and an FMEA scope analysis,” the invoice may feel disconnected from the submission calendar — even though the predicate landscape review identified a new competitor clearance that changed the substantial equivalence strategy, the protocol review identified $47,000 in retesting costs, and the FMEA scope analysis identified two Severity 5 failure modes that were not in the risk management file. The prevention advisory is the majority of the retainer value; the work logs are the documentation of that analysis.

HourTab is built for exactly this billing challenge. Import your time-tracker CSV, and HourTab generates a public retainer-hours URL that your VP of Engineering or regulatory affairs lead can bookmark. The URL shows a live view of hours logged against the monthly retainer allocation, with the work log entries visible in chronological order — predicate analysis session, protocol review session, FMEA update, CAPA advisory. The client does not need a login or a portal to see where the retainer hours stand. When the invoice arrives, the client has already seen the 510(k) strategy work, the V&V protocol review, and the risk management file update. The hours are not a surprise; they are a record of the ongoing regulatory advisory the client has been following in real time.

The Free plan handles one active retainer: a public share URL, CSV import, and a work log with a progress bar showing hours consumed against the monthly allocation. The Solo plan at $9 per month supports up to 10 active retainers with a custom URL slug, no HourTab branding, CSV export, and email-a-summary for month-end reporting. The Studio plan at $19 per month supports unlimited retainers, a branded subdomain, two team seats, per-client headers, and rollover rules for engagements where unused hours carry forward.

Try HourTab free →