Lessons from Both Sides of MedTech: What Start-ups and Established Companies Can Learn from Each Other
by Thais Sala
MedTech insights
Achieving CE Mark certification is a defining moment for any MedTech company. Following CergenX's recent milestone, Head of Quality & Regulatory Affairs Thaís Sala shares insights from the MDR/IVDR 2.0 Summit in Nice on building scalable quality systems, navigating regulatory complexity, and why start-ups and established medtech companies have more to learn from each other than they may realise.
I recently represented CergenX at the invitation-only MDR/IVDR 2.0 Summit in Nice. It was an incredibly valuable, intimate gathering of Senior Regulatory Leaders. Rather than navigating standard, massive conference halls, we sat at collaborative roundtables and even shared a catamaran reception. This type of event enabled participants to openly contrast how we are navigating today’s complex regulatory environment.
Throughout these discussions, a core theme stood out to me: MedTech start-ups and huge global companies have more in common than they think, and the best innovation often happens when both ends of the industry actively learn from one another.
I spent much of the summit looking at the structural and operational challenges faced by both sides of our industry. My biggest takeaways focused on how our operational foundations, resource constraints, and collaborative experiences dictate our long-term success.
1. M&A, Silos, and Designing for the Future
Many global giants grow primarily through mergers and acquisitions (M&A). Over years or decades, they acquire numerous smaller organizations and inherit their respective Quality Management Systems. Trying to maintain, align, or merge these disparate systems into a unified enterprise QMS is incredibly difficult.
Because start-up systems are frequently pieced together quickly to meet immediate commercialization goals, they can be highly "imperfect." When a giant tries to absorb an imperfect QMS, the integration can go terribly wrong, leading to compliance bottlenecks, delayed product lines, and massive regulatory remediation costs.
On the flip side, massive organizations naturally tend to develop internal silos, resulting in multiple sources of truth and disjointed documentation across different departments. Altogether, this can lead to multiple difficulties in investigating CAPAs, introducing lean methodologies or ensuring efficiency and cost saving.
For a growing organization like CergenX, understanding these enterprise-level pain points is a strategic superpower. Whether a start-up aims to be acquired or grow organically, building a clean, robust, and digitized compliance foundation early is a critical operational strategy.
For future acquisitions: A pristine QMS removes a massive barrier to integration, reduces the risk profile of the acquisition, and significantly increases the start-up's value in the eyes of the buyer.
For organic growth: It sets the tone for an exceptionally robust operational structure from day one, preventing those dreaded internal silos and multiple sources of truth from forming as you scale.
2. Learning in Both Directions
Perhaps the most striking contrast between small and large MedTech companies is the disparity in resources.
Smaller organizations must comply with the exact same stringent regulations (like MDR and IVDR) as multi-billion-dollar giants, but with a fraction of the budget, headcount, and infrastructure. However, this resource constraint is also a start-up's secret weapon. It forces an increased level of creativity and out-of-the-box problem-solving to overcome complex compliance hurdles. Large organizations, with their vast resources, can learn a great deal from these lean, agile methodologies to strip out internal bureaucracy, reduce complexity, and become more adaptable.
Conversely, the structured frameworks that global companies use to navigate massive, complex challenges are a great source of creative inspiration for smaller players. Understanding how a large corporation successfully manages risk, organizes its regulatory pipelines, and maintains compliance across dozens of markets serves as a proven blueprint. Start-ups can adapt these robust structures to build their own scalable systems before they experience severe growing pains.
3. A Win-Win Networking Ecosystem
Ultimately, it is a true win-win scenario when both sides of the coin share their experiences in valuable networking settings. By stepping out of our day-to-day silos and discussing our hurdles openly, we find that we can help solve each other's problems. Start-ups learn how to build for scale, while enterprises learn how to regain their agility.
This collaborative exchange is more critical than ever given the broader regulatory shifts discussed at the Nice summit:
Proposed Revisions (COM(2025) 1023): There is cautious optimism around proposals to reduce administrative burdens, but the regulatory environment remains highly complex.
The Cyber Resilience Act (CRA): Compliance can no longer exist in a silo. Both small and large manufacturers must aggressively integrate CRA secure-by-design and vulnerability handling obligations directly into their standard QMS to prepare for overlapping reporting timelines hitting between late 2026 and 2027.
Notified Body Headwinds: With Notified Body internal headcount dropping by 8% and subcontractor availability falling by 21% in 2025, capacity constraints are a very real threat. The cleaner and more structured our technical documentation is, the faster we can clear these congested queues.
Building the Future of MedTech
By combining the scalable, robust compliance structures of global giants with the lean, creative resourcefulness of start-ups, the MedTech industry can turn regulatory changes into what Bassil Akra noted during the opening session: "an invitation to lead."
Thank you to the organizers and my fellow regulatory leaders at the summit for such an open, insightful, and transparent exchange of perspectives!