Skip to content
The RND Group, a Gener8 company
Menu
Shipping custom regulated software since 1997

Medical device software, built end to end.

IVD platforms, Software as a Medical Device, LIS connectivity, and custom solutions, built to the regulatory standards that apply and backed by a real quality system, designed to your use case in an audit-ready manner.

Deep expertise in medical device software, from first requirement to FDA submission. Backed by a fully integrated device shop: instruments, consumables, and manufacturing, under one roof.

One team, the full depth of the stack.

What we do
Cybersecurity Aligned with the FDA's 2026 final premarket guidance

Device cybersecurity is now a condition of FDA clearance.

Under FDA Section 524B, in force since March 2023, the agency can refuse to even review a premarket submission for a connected "cyber device" on cybersecurity grounds alone. We build threat modeling, SBOMs, penetration testing, and eSTAR-ready premarket documentation into the software lifecycle, aligned to the FDA's 2026 final premarket cybersecurity guidance, so 510(k), De Novo, and PMA submissions hold up on first-pass review instead of being assembled in the last six weeks before filing.

Encrypted padlocks on a circuit board, connected device security

How we build it in, architecture through postmarket

01 Secure architecture & risk management Trust boundaries, update signing, and credential handling, aligned to your ISO 14971 risk file.
02 Threat modeling & risk assessment STRIDE-based analysis tied to the risk file, not run beside it, with AAMI TIR57 alignment.
03 Software inventory & security testing A machine-readable SBOM generated at build time, plus security testing of what it produces.
04 Premarket documentation The security section of the submission, written to FDA's current premarket cybersecurity guidance.
05 Postmarket vulnerability response Monitoring, legacy-device assessment, and remediation for products already on the market.
AI-assisted engineering

The speed of AI, with the quality of human engineers.

We build AI into our design and development workflow to shorten time to market and lower development cost. Every AI-assisted artifact, and the IEC 62304 and 21 CFR Part 11 records behind it, is reviewed by a seasoned engineer, traced into the design history file (DHF), and verified by our independent V&V team.

Engineers reviewing AI-assisted code and traceability on screen

A human in the loop, start to finish

01 Draft with AI Starting from your inputs, a PRD, architecture, existing specs, or current code, AI generates first-pass requirements, code, and tests inside the IEC 62304 lifecycle.
02 Human reviews every artifact A seasoned engineer reviews and approves everything generated (code, documentation, and diagrams) through pull requests. Nothing merges without human review.
03 Traceability & DHF Requirements, design, code, and tests stay linked in the design history file (DHF), with the 21 CFR Part 11 account of who did what.
04 Independent V&V A separate team verifies the result, the same way it does on any regulated project.
05 Regulatory-ready delivery The evidence a submission needs is generated by the work, not assembled at the end.
We work to
ISO 13485IEC 62304ISO 14971IEC 6236621 CFR 82021 CFR Part 11CLIA / CAP

Software your device can depend on.

Whether you're starting from scratch or catching up before a submission, bring us your device details. We'll pair you with a senior medical device software expert to review your lifecycle needs and agree on a clear roadmap.

Book a call
How we engage A full program team, or specialists working alongside yours
Where it starts A review of your device and where it sits in its lifecycle
What you get A scoped plan with a defined artifact list before work begins
Talk to a medical device software expert