Industry guide · Custom Software

Professional Licensing Board Software: Why Renewal Season Breaks a Legacy System

Occupational Licensing Board software visual showing id card, inspection checklist, and folder lock.
The short answer

$90,000 to $200,000 for a first release in 14 to 20 weeks, and $250,000 to $600,000 for a full board platform phased over 9 to 18 months is the honest range we see for a state licensing board that has outgrown its legacy system. A custom build is justified when your statute changes every session and every change is a paid configuration ticket, when investigative records must stay legally walled off from licensing staff, when compact participation forces real time outbound reporting, and when renewal season creates a queue you cannot staff your way out of. It is not justified for a board with one or two license types, fewer than roughly 15,000 licensees and a handful of disciplinary cases a year. At that size Thentia or System Automation MyLicense will serve you better and cost less than the discovery phase of a build.

Why a licensing board is not a CRM (Customer Relationship Management) with a renewal date bolted on

Picture the second week of your biennial renewal window. The phone queue is 40 deep. A licensee who moved out of state wants to know whether her multistate privilege still covered the telehealth shifts she worked last month. An applicant approved for exam eligibility in March has a fingerprint result that came back in April with a hit on it, and that result is sitting in a shared email folder because the licensing system has nowhere to put a criminal history response. Your enforcement analyst needs the list of licensees with an open complaint so the renewals that should not auto issue get held, and the only way to produce it is to export two spreadsheets and match them on name, which fails because a third of your practitioners changed a surname or an address since the last cycle.

None of that is a technology gap in the ordinary sense. It is a modelling gap. A licensing board is four different systems wearing one name: an eligibility determination engine, a recurring billing and renewal operation, a regulatory enforcement case system, and a public transparency service that employers and other states query all day long. Products sold into this market usually do one of those well and treat the other three as modules. The board absorbs the difference in staff time, and the absorption is invisible until a legislative session adds a requirement and the vendor quotes six months and a change order to add one field with a date rule attached to it.

The cost of that gap shows up in three places. Renewal season overtime. Applications that sit in a queue while a profession waits for staff, which is the thing legislators hear about. And the enforcement side, where an early warning signal exists in the data but nobody can see it because the complaint record and the license record were never designed to talk to each other.

Problem 1: intake is a statutory eligibility engine, not a web form

An application to your board is not a form with attachments. It is a decision tree written in statute and rule, and it has several entry pathways that do not share requirements. An initial applicant by examination needs an approved program transcript, supervised practice hours signed by a qualifying supervisor, exam results transmitted from the testing vendor, and a criminal history response. An applicant by endorsement needs primary source verification of an active license in another state, plus a discipline check, plus whatever equivalency your rule allows for a program that does not match your state's curriculum. A military spouse applying under your expedited statute needs a different, shorter set with a statutory clock attached to it. Each of those pathways has its own definition of complete.

Packaged licensing products model an application as a form plus a document checklist plus a reviewer queue. That works until the rule changes and you need the old requirement set to keep applying to the 900 applications already in flight while the new one applies to anything submitted after the effective date. In a checklist model there is no clean way to say that, so staff either reprocess everything by hand or the board applies a rule to people it should not have applied to, which is the kind of thing that surfaces at an appeal.

A custom build treats requirements as first class objects with effective dates. A pathway is a versioned set of requirements. Each requirement has its own evidence type, its own verifier, its own expiry, and its own satisfaction logic. When the legislature amends the supervised hours rule, you publish a new version with an effective date, and the engine keeps evaluating in flight applications against the version that was live when they were filed. That single design decision is what makes the difference between a system your rules analyst can change and a system that needs the vendor's roadmap.

Problem 2: renewal season is a queue you cannot staff your way out of

Renewals compress into weeks. Most licensees renew in the last few days, which is human nature and will not change. The work is not the payment, it is the hold logic sitting in front of the payment. Before a license reissues you have to know whether there is an open complaint, an unpaid civil penalty, a delinquent continuing education audit, a probationary condition with a reporting requirement, and in many states a hold from the child support enforcement agency or the department of revenue for delinquency. Those signals live in five places and one of them is another agency.

Legacy board systems evaluate holds at the moment the licensee clicks renew, serially, against whatever integrations happen to respond. So the site slows to a crawl in the exact week it matters, and the failure mode is either a licensee who cannot renew because a partner agency timed out, or a renewal that issues when it should have been held.

The build pattern that works is to precompute. A nightly job evaluates every active license against the hold rules and writes a status with a reason code and a timestamp. Renewal at 11:50pm on the deadline then reads a precomputed answer rather than making six network calls. Anything that changes intraday, a complaint filed that afternoon, publishes an event that recomputes just that licensee. The same status object feeds the public license lookup and the primary source verification endpoint that hospital credentialing offices and other states hit, which means employers stop calling your staff to ask whether a license is really active.

Problem 3: continuing education audits collapse into a pile of PDFs

Your rule says you audit a random sample of renewals for continuing education compliance. In practice that means selecting a sample, emailing those licensees, receiving a folder of scanned certificates in wildly different layouts, and having staff check each one against the approved provider list and the subject matter requirements, including the mandated hours in specific topics your legislature added. The audit takes months, the sample is smaller than your rule intends because you cannot process more, and a licensee who fails contests it on the grounds that the course was approved, which nobody can quickly disprove.

The structural fix is to stop collecting evidence from the licensee and start collecting it from the provider. A custom build gives approved providers a portal or an API to submit completion rosters, which posts hours directly to a licensee CE ledger with the approval number and the topic categories already attached. The licensee's compliance status becomes a running balance rather than a year end investigation. For the courses that will always arrive as a scan, document extraction reads the provider number, date, hours and topic off the certificate and matches it to the provider registry, flagging only the ones it cannot resolve. That is a narrow, honest use of a model: it reduces a queue of hundreds to a queue of dozens, and a human still decides the failures.

Problem 4: the wall between licensing and enforcement is a legal requirement, not a permission checkbox

In most states a complaint and the investigation that follows are confidential until formal charges are filed. Licensing staff who process renewals should not be reading investigative files. Board members who will sit as adjudicators on a case should not see the investigative record before the hearing, because that is the separation of investigative and adjudicative functions that keeps a disciplinary order from being overturned. Your assistant attorney general needs full access. Your investigator needs full access to their own cases and nothing on cases assigned elsewhere.

Packaged systems implement this as role based permissions on a shared record, which is the correct answer for a sales CRM and the wrong answer here. Roles drift, an administrator grants an exception during a busy week, and a year later a respondent's counsel asks in discovery who viewed the file and when. If the honest answer is a permission matrix rather than an access log, you have a problem in front of an administrative law judge.

The build should separate the domains, not just the views. Enforcement data lives with its own access model and its own immutable read log. The bridge between licensing and enforcement carries only the facts licensing is entitled to: there is a hold, here is the reason code, here is the case number. The board packet is generated as a redacted view built for the hearing stage the case is actually in. Every read of an investigative record is written to an append only log that survives independently of the application, because that log is the thing you will one day have to produce.

Problem 5: compacts and reciprocity turn one license into a network obligation

If your profession participates in an interstate compact, and nursing, medicine, psychology, counseling and physical therapy all have one, your board no longer owns its licensees in isolation. Determining a practitioner's primary state of residence, recognising privilege to practise granted by another state, and pushing adverse actions to the compact's coordinated database in something close to real time are now operational duties. Separately, disciplinary actions against health practitioners are reportable to the National Practitioner Data Bank, and that submission has its own format, its own deadlines and its own correction process.

These outbound obligations are exactly where legacy systems are weakest, because they were built when a license was a row in a state database that nobody outside the state read. A build should treat every reportable event as a durable outbound message with retries, a delivery receipt, and a visible queue an analyst can inspect. When a compact partner asks why an action took nine days to appear, you want a timestamped transmission record, not a staff member's recollection.

What this costs and how long it takes

Across the public sector work Digital Heroes has delivered, a first release for a licensing board covering one profession end to end, meaning intake with a versioned rules engine, renewal with hold logic, payments, and the public lookup, runs $90,000 to $200,000 and ships in 14 to 20 weeks. A full platform adding continuing education with a provider registry, complaint intake, investigation and hearing management, compact and data bank reporting, and legacy conversion runs $250,000 to $600,000 phased over 9 to 18 months.

What pushes the number up is specific to this environment. The count of license types and pathways, because each one is a distinct requirement set that has to be captured from your rules and confirmed by your counsel. Legacy data conversion, which is almost always the ugliest part: 20 or 30 years of license history with duplicate person records, name changes, merged boards, and disciplinary actions recorded as free text. Payment handling, because reconciling to the state treasury's cash receipting is not the same as taking a card. State identity provider integration if your agency mandates single sign on. Accessibility conformance to WCAG 2.1 AA, which most state policies now require and which is cheap if designed in and expensive if retrofitted. And the hearing side, because a discipline module with orders, stipulations, probation conditions and monitoring is close to a second product.

What keeps it down is sequencing. Ship one profession, one pathway, one renewal cycle. You learn more from watching your own staff use a real renewal than from any amount of requirements gathering, and you learn it before you have paid to build the other eleven license types the same wrong way.

Build versus buy: when Thentia, MyLicense, Versa or Tyler is the right answer

Buy if you are a single board with one or two license types, a licensee population in the low thousands, a stable statute, and a disciplinary caseload you could describe in a meeting. Thentia and System Automation MyLicense are built for exactly that shape and their configuration is genuinely deep. Versa Regulation is a reasonable fit for a mid size regulator that wants a packaged enforcement workflow. Tyler Technologies is worth taking seriously if your board already sits inside a Tyler estate and integration cost dominates your decision. Buying is not a failure. Buying is the right call more often than agencies like us admit.

Build when several of these are true at once. You are an umbrella agency running many boards with genuinely different statutes and the packaged product forces them into one model. Your legislature amends your practice act most sessions and you are quoting those changes as vendor work rather than staff work. You have received a change order for something you consider maintenance. You participate in a compact and the outbound reporting is manual. Your investigative wall is currently a permissions setting and your counsel is uncomfortable about it. Or you want your own licensee data in your own warehouse for legislative reporting without asking a vendor to run a report.

The threshold is not features. It is whether the rate of statutory change in your profession exceeds the rate at which your vendor will move, because when it does, every session you fall further behind and your staff absorbs the gap in spreadsheets that nobody audits.

How to choose a developer for a regulatory licensing system

Ask them to whiteboard effective dated rules before you talk price. Give them a real scenario: the legislature shortens the supervised hours requirement effective January 1, there are 900 applications in flight, and 40 of them were filed by military spouses under the expedited pathway. A team that has done regulatory work will immediately talk about rule versions, evaluation date and replay. A team that has not will talk about a config screen.

Ask how they will implement the separation between licensing and enforcement, and reject an answer that is only about roles. You want to hear about separate stores, a narrow bridge, and an immutable access log.

Ask what they have actually integrated in this space. A testing vendor's exam result feed, a state criminal history response, a payment gateway that reconciles to state cash receipting, a compact database, and the National Practitioner Data Bank are five different problems with five different failure modes. General integration experience is not the same thing.

Ask about records retention and public records exposure on day one, not at launch. Your system will hold records with different retention schedules and different disclosure rules in the same database, and that has to be designed rather than discovered.

Ask who owns the code, the repository and the cloud accounts, and get it in the contract before kickoff. At Digital Heroes the client owns all three from the first commit, and any developer who wants to hold your repository is selling you a dependency, not a system. Start with a paid discovery on one profession and one pathway, and make the deliverable a written rules specification your own counsel signs off on.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. In PMI's 2014 Pulse of the Profession report on requirements management, inaccurate requirements management is cited as a leading cause of project failure, with 47% of unsuccessful projects failing to meet goals due to poor requirements management. Source: Project Management Institute (PMI) (2014) →
  2. Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
  3. SHRM's 2025 benchmarking data puts the average cost-per-hire at $5,475 for nonexecutive roles and $35,879 for executive roles - executive hires are on average nearly 7x more expensive than nonexecutive hires. Source: SHRM (Society for Human Resource Management) (2025) →
  4. The EY survey of 508 payroll professionals at U.S. companies with 250-10,000 employees quantifies the direct and indirect cost of payroll inaccuracy, reinforcing the ROI case for payroll automation; the study is the original source of the frequently cited $291-per-error figure. Source: BusinessWire / EY (Ernst & Young) (2022) →
Priyanka S. · Senior UX Designer · UK · London

Priyanka designs the flows inside business software, the screens that staff will sit in for years rather than admire once. Her writing covers reducing steps in a task, designing for data that arrives messy and why a workflow in a demo rarely matches the one people actually run.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does it cost to replace a state licensing board's legacy system?
A first release covering one profession end to end, with a versioned rules engine for intake, renewal with hold logic, payments and the public lookup, runs $90,000 to $200,000 and ships in 14 to 20 weeks in our delivery experience. A full platform adding continuing education, complaint and investigation management, hearings, compact reporting and legacy conversion runs $250,000 to $600,000 over 9 to 18 months. The variables that move the number most are the count of license types, the state of your historic data, and whether a disciplinary hearing module is in scope.
Is Thentia or MyLicense good enough, or should we build?
They are strong products for a single board with one or two license types, a few thousand licensees and a modest disciplinary caseload, and buying is the right answer more often than an agency will tell you. They struggle when an umbrella agency has to run many boards with genuinely different statutes, when your practice act is amended most legislative sessions, and when the separation between licensing and investigative records has to be structural rather than a permissions setting. If you are quoting routine statutory changes as vendor change orders, that is the signal to price a build.
How do we keep investigation records legally separated from licensing staff?
Do not implement it as role based permissions on a shared record, because roles drift and exceptions get granted during busy weeks. Keep enforcement data in its own store with its own access model, and let only reason codes and case numbers cross into the licensing side. Every read of an investigative record should write to an append only log that survives independently of the application, because that log is what you produce when a respondent's counsel asks who saw the file and when.
How long does it take to build licensing board software?
Fourteen to 20 weeks for a first working release covering one profession, and 9 to 18 months for a full platform. The schedule risk is almost never engineering. It is getting your rules written down: pathways, requirement sets, equivalency provisions and hold conditions usually exist as staff knowledge plus a practice act, and turning that into a specification your counsel will sign takes real weeks. Boards that already maintain written procedure manuals move noticeably faster.
Can we migrate 20 years of license history without losing the disciplinary record?
Yes, but treat conversion as its own project with its own budget rather than a line item. The hard parts are duplicate person records created before you had a unique identifier, name changes that were recorded as new licensees, boards that merged, and disciplinary actions stored as free text in a notes field. Plan for a reconciliation period where the legacy system stays readable, and have staff verify a sample of high risk records, meaning anyone with an action, a probation condition or an open case.
What does compact participation require from our licensing system?
Compacts in nursing, medicine, psychology, counseling and physical therapy make your board part of a network rather than a standalone registry. You have to determine and maintain primary state of residence, recognise privilege granted elsewhere, and push adverse actions to the compact's coordinated database quickly and reliably. Build these as durable outbound messages with retries and delivery receipts so that when a partner state asks why an action took days to appear, you can answer with a transmission log.
Does the system have to report discipline to the National Practitioner Data Bank automatically?
For health professions the reporting obligation exists regardless of your software, so the question is whether the submission is generated by the case record or retyped by a staff member from a signed order. Generating it from the case is both faster and safer, because the format, the deadlines and the correction process are unforgiving and a retyped field is where errors enter. Confirm the specific reportable event definitions with your counsel, since they are narrower than most people assume.
What actually breaks first when the legislature changes our practice act?
In flight applications. A rule takes effect on a date, but you have hundreds of applications filed under the old requirements, and a system that stores requirements as a static checklist has no honest way to evaluate both populations correctly. The second thing to break is renewal hold logic, because new statutory holds get added by other agencies and a serial, at click evaluation cannot absorb them. Both are design problems you solve once with versioned rules and precomputed status.
Who owns the code if we hire a firm to build our board's system?
You should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm to continue the work, and it belongs in the contract before kickoff rather than at handover. At Digital Heroes the client owns all of it from the first commit. For a public agency this matters more than for a private buyer, because your successor administration will inherit the decision and a procurement that leaves the code with the vendor guarantees a sole source renewal five years from now.
Will an app built for 10 users survive growing to 500?
Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.
What is a discovery phase, and is it worth paying for separately?
Pay for it, and treat the output as yours. A discovery phase runs two to three weeks, typically 5 to 10% of the eventual build budget, and produces a written scope, wireframes, and a fixed quote you can take to any vendor, including a competitor of the agency that wrote it. Skipping it is how projects end up quoted from a two-paragraph email and delivered at twice the price.
Should we build an MVP first or go straight to the full system?
MVP first, for almost everyone: ship the single workflow that carries the business value in 10 to 16 weeks, learn from real users, then fund phase two from evidence instead of guesses. The caveat is that an MVP is a small version of a well-built system, not a badly built version of a big one; the data model must already support what comes next. An agency that cannot tell you what they deliberately left out of your MVP has not designed one.
How do I vet a software development agency before signing a contract?
Ask to speak with two past clients whose projects resemble yours in size and industry, and ask exactly who will write your code, since some agencies sell senior faces and deliver junior or subcontracted hands. Demand a written specification with acceptance criteria before any fixed price, and check that their portfolio links to products that are actually live. An instant quote given without questions about your workflows is the clearest warning sign there is.
What does it cost to keep custom software running after launch?
Budget 15-20% of the original build cost per year, which on a $100,000 system means $15,000 to $20,000 for security patches, dependency updates, bug fixes, and small improvements as real usage reveals what the spec missed. Cloud hosting for a typical business application adds $50 to $300 a month on top. Skipping maintenance does not save the money; in Digital Heroes rescue work, unmaintained systems typically need a far more expensive rebuild within about three years.
Should I hire a freelancer or an agency for my software project?
A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.
How do I work out whether custom software will pay for itself?
Do the arithmetic on hours before anything else: if the system saves three staff eight hours a week at a $35 loaded hourly cost, that is about $43,700 a year against, say, a $70,000 build plus 15 to 20% annual maintenance, a payback around two years. Add revenue effects only if you can name them specifically, like faster quotes or fewer abandoned orders, not as vague growth. In our delivery experience the businesses that see payback inside 24 months are the ones automating a process they already measure.
Will custom software work with the tools we already use, like QuickBooks and Stripe?
Yes, and this is one of custom software's genuine advantages: QuickBooks, Stripe, Shopify, and most mainstream business tools publish documented APIs built for exactly this. Expect each standard integration to add one to two weeks of build time, and be suspicious of any quote that lists five integrations without asking what data flows in which direction. The hard cases are legacy systems with no API, which is a question to raise in discovery, not in week nine.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
Is it cheaper to customize Salesforce than to build a custom CRM from scratch?
If you use less than a third of what Salesforce does, a custom CRM is often cheaper by year three. Salesforce Enterprise lists at $165 per user per month, so 25 seats cost about $49,500 a year before admin and consultant fees, while a focused custom CRM runs $60,000 to $100,000 once plus 15 to 20% a year in maintenance. If you genuinely need Salesforce's ecosystem, reporting, and app marketplace, customizing it beats rebuilding it; the mistake is paying enterprise prices to use it as a glorified contact list.
Who can build a custom software system?

Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?