Industry guide · ERP

Pharma Manufacturing Software: Problems, Solutions, and What It Costs to Build

The short answer

Build if your batch release is slow because of paperwork rather than testing, and if your process has anything the vendor's recipe model cannot hold. A focused first release, one product family's electronic batch record or the deviation evidence layer, runs $60k to $130k and ships in 12 to 16 weeks; a full execution and quality platform across sites runs $150k to $400k phased over 6 to 12 months, with validation and master data reconciliation, not code, driving most of the variance. If you are a single site with one dosage form and under roughly 150 batches a year, configure MasterControl or Veeva and stop reading.

Why batch record software makes or breaks a pharmaceutical manufacturer

A pharma site does not sell tablets. It sells documented evidence that tablets were made correctly. The product is physically finished the day the last carton is packed. It ships two or three weeks later, when a QA reviewer finally signs the executed batch record. Everything between those two dates is working capital sitting in a quarantine cage.

The stack at a typical mid-size site: SAP or NetSuite for materials and financials, a paper or hybrid batch record printed from a Word master, LabWare or STARLIMS for lab results, TrackWise or MasterControl for deviations and change control, AVEVA PI or Ignition for equipment data, ValGenesis or Kneat for the validation packages, and about forty Excel files doing the actual coordination. None of it talks. The sites that call us are usually already paying somewhere between $180k and $400k a year in licenses and validation services across that stack, and still run release off a whiteboard.

Here is what that looks like on a Wednesday at 4pm. Batch 24-0417, a 1.2 million tablet compression run, roughly $2.4M of finished goods. The record arrives at QA as 186 printed pages. The reviewer notices an operator initialed line clearance at 06:12, but the room logbook shows the previous product still on the line at 06:30. That is a data integrity finding, and it opens a deviation. Closing it means pulling the balance printout from the weigh room, the compression force trend out of the historian, the blend uniformity result out of LabWare, and eight years of prior similar events out of TrackWise. Four systems, no shared batch identifier. The batch releases 19 days later. Nothing was ever wrong with the tablets.

Problem 1: QA batch review is a hunt for missing ink, not a quality decision

In the sites we have worked in, a reviewer spends 6 to 9 hours on a solid-dose record, and roughly three in ten go back to production for good documentation practice corrections: a missing initial, a correction without a date, a wrong date format, a yield calculation transcribed one digit off. At 200 batches a year that is about 1,500 QA hours spent proofreading, by people you hired to make quality judgments.

MasterControl and Werum PAS-X both do electronic batch records, and they do them well when your process resembles the process their other customers run. The wall shows up when it does not. If your granulation hold-time rule depends on the previous campaign's product, or you are a CDMO where each client demands a different in-process data set, you configure until you cannot, then you file a change request, then you wait for the vendor's release cycle to give you a field.

A custom build models the process as it actually runs. Entries are captured at execution on a floor tablet: badge login, scanned equipment ID, value range-checked before it can be saved, timestamps from a trusted source. GDP errors become structurally impossible rather than something you catch three weeks later. Then review by exception: QA sees the 11 entries that hit a limit, not all 3,000. That is a 7-hour review turning into about 40 minutes in our builds. Where a site must keep paper for a while, on legacy products or contract lines, an OCR and model pass over the scanned record before QA opens it flags blanks, out-of-sequence timestamps, uninitialed corrections, and calculations that do not recompute. It produces a reviewer worksheet, not a decision. The human stays the recorded signer and the model output goes in as a versioned attachment. That distinction is what keeps it defensible under Part 11.

Problem 2: The deviation investigation is 40 hours of copy and paste

Major deviation on a sterile fill. The investigator opens TrackWise, then spends the week screenshotting a PI trend into Word, printing the LabWare certificate, chasing the environmental monitoring result, and typing a "similar events" section from memory. Thirty to forty-five hours per major, every time we have sat with a client and timed it. A site with 400 deviations a year and 60 majors burns over 2,000 hours on assembly work.

TrackWise and Veeva Vault QMS are excellent records of decision. They are not evidence aggregation systems. They hold what a human types into them. The historian integration is a professional services project quoted separately, and it usually lands as a hyperlink rather than data you can query.

Build it so that entering a batch, an asset ID, and a date range pulls the tag history through OPC UA or the PI Web API, the LIMS results, the EM data, the maintenance work orders on that asset, and eight years of deviations on that product or equipment, into one timeline. Then a model drafts the narrative and the 5-why starting points and returns a ranked similar-event list using semantic search over the historical text, not keyword matching. QA edits and signs. Major deviation cycle time drops from around 35 hours to 10 or 12. The real value is not the drafting. It is that "has this happened before," the question that turns a 483 observation into a warning letter when you answer it wrong, now has an actual answer instead of an anecdote.

Problem 3: Validation makes every change cost more than the change

Adding one field to capture a new in-process check: two hours of work, twelve weeks of calendar. URS revision, risk assessment, design spec, IQ/OQ/PQ authoring, witnessed execution, a deviation on the test script because a screenshot has the wrong date, then approval routing. So the site stops asking. The software freezes while the process keeps moving, and people start running the real process in a spreadsheet beside the validated system. That spreadsheet is the data integrity risk the validated system existed to remove.

ValGenesis and Kneat manage validation documents. They do not reduce validation. And a vendor MES upgrade forces revalidation on the vendor's schedule, not yours.

Build the evidence into the pipeline instead. Requirements live as traceable IDs in the repository, each with automated tests that run on every commit and emit a timestamped, signed execution record tied to the code version. Split by risk, the way GAMP 5 second edition and FDA's Computer Software Assurance thinking allow: release decisions, e-signature, audit trail, and dose calculations get scripted witnessed testing; a report filter or a label gets automated evidence and a written rationale. In our pharma work this turns a 12-week change into a 2-week change and drops validation from roughly 40% of program cost to around 20%. The auditor gets more evidence than before, not less.

Problem 4: The annual product review is three weeks of Excel archaeology

211.180(e) in the US, the PQR in Europe. Forty SKUs, each needing twelve months of batches, yields, OOS results, deviations, complaints, returns, stability, and change controls. Someone in QA exports SAP, LabWare, and TrackWise into three workbooks and VLOOKUPs on a batch number that is formatted differently in all three, then builds control charts by hand. Three weeks per product family. Two people, permanently. And because nothing trends in between, the first time anyone notices dissolution drifting is at review time, eleven months late.

No packaged tool fixes this, because the blocker is that the batch number is a different string in every system and the only mapping lives in the head of the person who has done it for nine years.

The build establishes a canonical batch identity: one master record every system's identifier resolves to, mapped once at ingestion. After that the review is a query, not a project. Cpk and Ppk trends run nightly instead of annually, alerting when a parameter drifts inside spec but outside its historical distribution, which is where you actually catch problems. The model drafts the narrative sections, QA reviews the statistics and signs. Three weeks becomes two days.

Problem 5: Nobody can answer "what does this change touch"

You want to qualify a second filter supplier, or move a product to line 3. Change control asks for an impact assessment. The honest answer is that no one knows which of your 2,800 SOPs, 400 specifications, 60 validated systems, and filed dossier sections reference that supplier or that line. So the QA manager emails eight department heads and waits six weeks for something that should take an afternoon. Occasionally one gets missed, and the miss surfaces as a filed-versus-actual discrepancy during a pre-approval inspection.

Documentum and MasterControl store documents. They do not store a dependency graph between an equipment ID, an SOP, a method, a validated system, and a dossier section, because that relationship only exists inside the prose.

So build the graph. Every SOP, spec, method, asset, material, and dossier section becomes a node, and references become edges, extracted once from the legacy document set with document parsing and a model, verified by SMEs, then maintained at approval. Impact assessment becomes a traversal that generates the affected list with the responsible owner for each node. The extraction pass is usually where clients get their first surprise: a couple hundred live SOPs referencing equipment decommissioned in 2019.

What this costs and how long it takes

Across 2,000-plus projects, our delivery experience: a focused first release lands at $60k to $130k and ships in 12 to 16 weeks. In pharma that first release is one thing done properly, an electronic batch record for one product family on one line, or the deviation evidence layer, or the change control graph. Not three. A full platform runs $150k to $400k phased over 6 to 12 months.

What pushes price up in this category specifically: validation scope, because custom software is GAMP 5 Category 5, so budget 20% to 30% of the program for traceability, risk assessment, evidence, and a CSV lead. If your quality unit refuses a risk-based split and insists on fully scripted testing for every function, add another 15%. Part 11 depth costs 3 to 5 weeks of engineering that has nothing to do with your process and is not optional: audit trail on every table, no hard deletes, signature meaning and manifestation, trusted time, and the audit trail review tooling. Integrations are real work, roughly 2 to 4 weeks for SAP via IDoc or OData, 2 to 3 for a historian, more for LabWare or STARLIMS if the vendor controls the schema. Direct equipment or serialization line integration is where estimates die: get the vendor's interface specification in writing before you sign. Aseptic and Annex 1 scope adds 30% to 40% over solid dose. Two sites with a European QP release model plus US release means two release workflows and a data residency conversation.

The largest overrun we see is never code. It is master data. If equipment IDs, material codes, and batch numbers do not reconcile across systems, that reconciliation is its own project, typically 4 to 8 weeks, and it has to happen first.

Build versus buy: when MasterControl or PAS-X is the right answer

Buy if you are one site, one dosage form, under roughly 150 batches a year, and your process looks like the vendor's model. And buy document control and training records regardless of your size. Nobody should build an SOP repository or a training matrix. Veeva Vault QualityDocs and MasterControl solve that better than you will, and it is not where your margin lives.

Build when three or more of these are true: you are running the real process in Excel next to the validated system; you have paid a vendor for a change request twice in 18 months just to add a field; your differentiator has nowhere to live in the vendor's data model (CDMO with a per-client data set, cell therapy with a patient-linked batch of one, continuous manufacturing); your release cycle exceeds five days after the last operation for paperwork reasons rather than testing reasons; or you have multiple sites that each configured the same vendor system differently, so you cannot compare them.

The clearest signal is competitive. If your position depends on how the process runs, the vendor's roadmap serves 400 other customers before it serves you. A CDMO that onboards a new client in six weeks instead of six months wins contracts, and no amount of configuring a packaged MES gets you there. Note that hybrid is the normal end state, not a compromise: most of our pharma clients keep Vault or MasterControl for documents and training, keep LabWare for the lab, and build the layer that is theirs, which is execution, evidence, and release.

How to choose a developer for pharma manufacturing software

Make them draw your data model on a whiteboard before you sign. Batch, lot, sublot, campaign, phase, equipment, material, and the difference between a specification, a limit, and an alert level. If you have to explain those terms, they will learn on your budget, and the mistakes will be structural rather than cosmetic.

Ask what validation evidence they hand you, and who writes it. A real answer names deliverables: a URS with a traceability matrix, a functional risk assessment, IQ/OQ/PQ or a documented automated equivalent with rationale, and a CSV lead who has sat across a table from an investigator. "We will support your QA team with the documents" means you pay twice, once for the build and again for a validation firm. The firms our clients bring in bill $180 to $250 an hour.

Demand a specific integration story, not a logo slide. Not "we integrate with SAP." Ask which interface, what the batch confirmation payload looked like, what broke, and how long reconciliation took. Anyone who has actually shipped a pharma integration has a story about a two-week argument over a unit of measure or a batch number with a leading zero.

Settle the exit on day one. Source code, database schema, infrastructure definitions, and the validation package should sit in your repository and your cloud account from the first sprint, not get handed over at completion. In a category where your software is inspected evidence, whoever holds the code holds your release. Get it in the contract.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. In PMI's 2014 Pulse of the Profession report on requirements management, inaccurate requirements management is cited as a leading cause of project failure, with 47% of unsuccessful projects failing to meet goals due to poor requirements management. Source: Project Management Institute (PMI) (2014) →
  2. Standish's 2015 CHAOS research found roughly a third of software projects (about 36% by the Modern definition) fully succeed on time, on budget, and on scope, with top success drivers including executive support, user involvement, and clear requirements/business objectives. Source: Standish Group (CHAOS Report) (2015) →
  3. Gallup reports global employee engagement fell to 20% in 2025 (its lowest since 2020, down from a 2022-2023 peak of 23%), and estimates low engagement costs the world economy an estimated $10 trillion in lost productivity, or 9% of global GDP. (Note: this figure appears in Gallup's evergreen State of the Global Workplace page, currently reflecting the 2026 edition reporting on 2025 data.). Source: Gallup (2025) →
  4. Qualtrics research (Q3 2023 survey of ~28,400 consumers across 26 countries) estimated bad customer experiences put roughly $3.7 trillion in global revenue at risk annually, a 19% jump from the prior year's $3.1 trillion; 64% of customers say they will switch companies over poor service regardless of how much they like the product. Source: Qualtrics XM Institute (via Forbes) (2024) →
Rohan Malhotra · Enterprise Software Consultant

Rohan advises mid-market and enterprise teams on ERP, CRM and custom software, and has led delivery on dozens of business-software builds.

Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom pharma manufacturing software cost for a site running 200 batches a year?
A focused first release, such as an electronic batch record for one product family plus review by exception, typically runs $60k to $130k and ships in 12 to 16 weeks. A full execution and quality platform covering batch records, deviations, and annual product review runs $150k to $400k phased over 6 to 12 months. Validation adds 20% to 30% of program cost because custom software is treated as GAMP 5 Category 5, and master data reconciliation across SAP, LabWare, and TrackWise is usually another 4 to 8 weeks before build work starts.
Is custom electronic batch record software better than MasterControl or Werum PAS-X?
Not automatically. MasterControl and PAS-X are strong when your process resembles the process their other customers run, and they carry a validation history you would otherwise fund yourself. Custom wins when your process has something the vendor's recipe model cannot hold, such as a CDMO's per-client data sets, patient-linked batches in cell therapy, or hold-time rules that depend on the previous campaign. The practical test: if you have paid for a vendor change request twice in 18 months just to add a field, you have outgrown configuration.
Can custom software be 21 CFR Part 11 compliant?
Yes, and often more provably than a configured commercial system, because you control the audit trail design. Part 11 requires audit trails on every record, no hard deletes, signature meaning and manifestation, a trusted time source, and tooling to review audit trails. Budget 3 to 5 weeks of engineering for this alone. Compliance comes from your validation evidence and controls, not from the vendor's logo, and no software is Part 11 compliant out of the box.
How long does it take to validate custom pharma manufacturing software?
With a risk-based approach aligned to GAMP 5 second edition and FDA's Computer Software Assurance thinking, validation runs in parallel with the build rather than after it, and adds roughly 20% to 30% to the timeline. High-risk functions such as release decisions, e-signatures, and audit trails get scripted witnessed testing; low-risk functions get automated test evidence with a documented rationale. If your quality unit requires fully scripted testing for every function, expect the program to run 15% longer and cost proportionally more.
How do we move off paper batch records without stopping production?
Do it one product family on one line at a time, and run the electronic record in parallel with paper for two to three batches before paper retires. Never convert every SKU at once. The sequencing that works is master data first (equipment IDs, material codes, batch identity), then one recipe fully electronic, then rollout by line. A site with 40 SKUs typically takes 6 to 12 months to fully convert, with the first line live in 12 to 16 weeks.
Who owns the source code and validation package if we hire an agency?
You should, and it should live in your repository and your cloud account from the first sprint rather than being handed over at project close. That means source code, database schema, infrastructure definitions, test scripts, and the full validation package including the traceability matrix. In pharma this matters more than in other industries, because your software is inspected evidence and a vendor holding the code effectively holds your batch release. Write it into the contract before work starts.
Can AI be used in a GMP batch release process?
Use it for the work around the decision, not the decision. Pre-reviewing scanned batch records for blanks, uninitialed corrections, and out-of-sequence timestamps, drafting deviation narratives from historian and LIMS data, and searching eight years of prior events for similar cases are all defensible, because a qualified human remains the recorded reviewer and signer. The model output goes in as a versioned attachment with its inputs traceable. Anything that makes or implies the disposition decision is a fight with your inspector you do not need.
How do we integrate custom software with SAP, LabWare, and our historian?
SAP via IDoc or OData for batch confirmations and material movements is typically 2 to 4 weeks. A historian through OPC UA or the PI Web API is 2 to 3 weeks. LabWare or STARLIMS depends on whether you or the vendor controls the schema, and can double if you do not. The hidden work is not the connection, it is reconciling batch and material identifiers that are formatted differently in each system, which is why canonical batch identity should be the first thing built.
Should a CDMO build its own manufacturing execution system?
Usually yes, once you are onboarding more than a handful of clients a year, because client onboarding speed is the product you sell. Packaged MES platforms assume one process owner with one data model, so every new client becomes a configuration project measured in months. Custom lets a new client's parameters, in-process checks, and reporting format become data rather than a change request, which is the difference between a six-week and a six-month onboard. Keep buying document control and training records; build execution and release.
How much does a custom ERP cost for a small business?
A small-business ERP covering two or three core modules typically runs $40,000 to $120,000, with inventory, ordering, and accounting sync being the usual starting set. Across 2,000+ Digital Heroes projects, integration count and user roles drive cost far more than screen count. A full mid-market ERP with six or more modules usually lands between $150,000 and $400,000.
Will an app built for 10 users survive growing to 500?
Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.
How many developers does it take to build an ERP?
A typical Digital Heroes ERP pod is five to seven people: two or three backend engineers, one frontend engineer, a QA engineer, a project manager, and a part-time architect and designer. Bigger teams rarely go faster on ERP because the bottleneck is decisions about your business rules, not typing speed. What you need on your side is one empowered internal owner who can answer process questions within a day.
How do I vet an agency for an ERP project?
Ask to speak with two clients who have been running an ERP the agency built for at least two years, because ERP quality shows up in year two, not at launch. Then ask for their data migration plan, their module rollout sequence, and the named senior engineers who will be on your project. An agency that leads with screen designs instead of process mapping is a red flag for ERP work.
How long does it take to build a custom web or mobile app from scratch?
Plan on 8 to 16 weeks for a focused first version and 4 to 9 months for a larger platform, which is the typical spread across Digital Heroes builds. The first 2 to 3 weeks go to discovery and design before any production code ships. The two things that stretch timelines most are integrations with legacy systems and slow feedback from your side, not developer speed.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
How many SaaS seats do we need before building custom becomes cheaper?
The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.
Can a freelancer build an ERP, or do I need an agency?
An ERP is too wide for one person: it needs backend, frontend, database design, integrations, QA, and someone mapping your business processes. A solo freelancer can extend an existing ERP or ship one small internal tool, but full ERP builds by single developers are the most common rescue scenario Digital Heroes takes on. If budget is tight, shrink the scope to one module rather than shrinking the team below three or four people.
Should I pick Microsoft Dynamics 365 Business Central or build a custom ERP?
Pick Business Central if you already live in the Microsoft stack, your processes are close to standard, and around $80 per user per month for Business Central Essentials stays affordable at your headcount. Build custom when your revenue-driving workflow, such as custom manufacturing steps or unusual pricing logic, would need heavy extension work anyway. In our experience, once Dynamics customization quotes pass about $100,000 the custom option deserves a serious side-by-side.
What should I prepare before contacting an ERP development agency?
Bring a list of your current tools and spreadsheets, a rough map of how an order or job moves through the company today, your user count by role, and the three problems costing you the most hours. You do not need a formal specification; a good agency writes that with you during discovery. Companies that arrive with those four things typically cut two to three weeks off scoping in our experience.
Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?