Introduction
Digital therapeutics, software-based interventions intended to prevent, manage, or treat a medical condition, sit in an unusual regulatory position. They are not drugs, though some are prescribed alongside them or intended to reduce reliance on them. They are not traditional hardware devices, though many are regulated as Software as a Medical Device. And they carry a clinical evidence burden closer to a pharmaceutical product than most consumer health apps, since a genuine digital therapeutic has to demonstrate it actually changes a clinical outcome, not just user engagement. That combination is producing a specific, growing hiring niche within regulatory affairs, one that does not map cleanly onto the traditional drug or device tracks that most regulatory professionals trained on.
This piece is about what that niche actually involves, why it has become distinct enough to hire for specifically, and what it takes to be a credible candidate for it, whether you are coming from a traditional device background, a clinical research background, or software.
What Makes Digital Therapeutics Regulatorily Distinct
A conventional medical device regulatory pathway assumes a physical product with a relatively stable design once cleared or approved. A conventional pharmaceutical pathway assumes a fixed chemical entity studied through defined clinical trial phases. Digital therapeutics inherit expectations from both worlds while breaking some of the assumptions each one relies on. The software itself can be updated far more frequently than a device's physical design or a drug's formulation, which raises real questions about how much a given update constitutes a new version requiring fresh regulatory attention versus a maintenance change that does not.
At the same time, regulators including FDA have made clear that digital therapeutics claiming a genuine therapeutic effect need to support that claim with clinical evidence, generally through randomized controlled trials or comparable rigorous study designs, not simply user satisfaction data or engagement metrics. That puts digital therapeutics regulatory work at a genuine intersection: it requires comfort with software development practices, including how a company documents version control and change management, alongside comfort with clinical trial design and evidence standards more typical of pharmaceutical development. Few people come into the field having built deep expertise in both halves of that equation, which is exactly why companies are hiring for it specifically rather than assuming a traditional device or drug regulatory background transfers cleanly.
The Cybersecurity and Data Layer
Digital therapeutics regulatory work also carries a layer that most traditional device or drug regulatory roles touch only lightly: cybersecurity and data handling. Because these products run as software, often connected to a phone, a cloud backend, or both, regulatory submissions increasingly need to address how the product handles cybersecurity risk, data privacy, and interoperability with other systems a patient or provider might use. FDA's premarket cybersecurity guidance for connected devices applies here, and regulatory professionals working on digital therapeutics need at least a working fluency in how their company's quality and engineering teams manage that risk, even if they are not writing the technical documentation themselves.
This is a meaningfully different skill demand than a traditional device regulatory role, where physical safety testing and biocompatibility might dominate the technical file instead. A regulatory professional moving into this space benefits from being comfortable asking pointed, informed questions of a software engineering team, and from understanding enough about how software risk management frameworks work to evaluate whether a submission's cybersecurity section actually holds up, rather than treating it as a section to simply collect from another department and pass along.
Where This Work Actually Sits Organizationally
Digital therapeutics regulatory roles show up in a few different organizational settings, and the shape of the work differs depending on where you land. Dedicated digital therapeutics companies, smaller and mid-sized organizations built specifically around a software intervention, tend to need regulatory professionals who can operate broadly across strategy, submissions, and quality system oversight with less internal specialization to lean on, since the regulatory team itself is often small. Larger pharmaceutical and device companies building digital therapeutics as an adjunct to an existing drug or device franchise tend to fold this work into an existing regulatory team, where a specialist or manager may own the digital therapeutic components alongside more traditional regulatory responsibilities for the same product line, working closely with a separate core regulatory team.
There is also a growing presence of digital therapeutics regulatory expertise inside consulting firms, since many companies entering this space, especially smaller ones, do not have in-house depth in the software-plus-clinical-evidence intersection this work requires and bring in specialized regulatory consultants for pivotal submissions or agency interactions. For someone building a career in this niche, consulting experience can be a legitimate way to see a wider range of digital therapeutic products and submission strategies faster than staying inside a single company would allow.
What Makes a Strong Candidate for This Niche
Companies hiring into digital therapeutics regulatory roles are generally looking for some combination of traditional regulatory grounding plus specific comfort with software and evidence generation that goes beyond a standard device or drug background. A background in Software as a Medical Device regulatory work is a natural entry point, since it already builds familiarity with how FDA evaluates software function and risk. A background in clinical operations or clinical regulatory affairs is another reasonable entry point, since it builds the evidence-generation fluency that digital therapeutics claims require, with software and cybersecurity literacy then layered on through direct exposure or targeted learning.
What tends to matter less than people expect is a formal computer science or engineering credential. Regulatory professionals in this space generally are not writing code or architecting systems; they need to understand software development and risk management well enough to evaluate what engineering and quality teams bring to them, ask the right questions, and represent that work accurately in a submission. Curiosity about how software actually gets built and tested, willingness to sit in on engineering and quality risk discussions rather than staying purely on the regulatory side of the table, and comfort reading clinical trial protocols and results are a more realistic and attainable combination than trying to become a software engineer on top of a regulatory career.
Realistic Expectations About the Space
It is worth being honest that the digital therapeutics sector has gone through real volatility, with some well-funded companies scaling back or restructuring as reimbursement and adoption proved harder to secure than initial enthusiasm suggested. That does not mean the regulatory niche itself is going away; the underlying regulatory challenge, evaluating software interventions that make genuine clinical claims, is not disappearing, and it is increasingly relevant beyond dedicated digital therapeutics companies as more traditional pharmaceutical and device companies build software components into their broader product strategies. But it does mean candidates should evaluate individual employers in this space with the same scrutiny they would apply to any smaller or earlier-stage company, looking at funding, regulatory milestones already achieved, and reimbursement strategy, rather than assuming the sector label alone guarantees stability.
How to Start Building This Expertise
If you are a regulatory professional interested in moving toward this niche rather than already in it, a few concrete steps tend to help more than general study. Read actual FDA guidance documents relevant to software function and Software as a Medical Device classification directly, rather than only secondary summaries, since the primary source gives you a more precise sense of how the agency actually frames these questions and where genuine ambiguity remains. Look for opportunities, even informally, to sit in on discussions with your company's software engineering, data science, or quality risk teams if you have access to them, since the fastest way to build fluency in how software risk actually gets assessed is repeated exposure to how the people building the product talk about it.
If you are earlier in your career or between roles, consider whether a company building a digital therapeutic, even in a general regulatory or quality role rather than one titled specifically for this niche, would give you meaningful exposure to these questions. Professional organizations including RAPS have increasingly built out programming on digital health and software regulatory topics, and attending sessions specific to this area, rather than general regulatory affairs content, is a reasonable way to build both knowledge and a network of people already working in the space. As with most regulatory specializations, the credibility that actually matters to employers comes from demonstrated exposure to real submissions or real cross-functional work in the space, not from certificates or self-study alone, so look for any way to get your hands on real work in this area even before you have a title that says so.
Conclusion
Digital therapeutics regulatory work is a genuine hiring niche because it demands a blend of skills, software risk fluency and clinical evidence rigor, that most traditional regulatory career tracks do not build together. For regulatory professionals willing to develop comfort on both sides of that intersection, whether coming from a Software as a Medical Device background, a clinical regulatory background, or general device or pharma experience with a genuine interest in the space, it offers a distinct and still-developing career lane. As with any emerging niche, it rewards people who invest in understanding the underlying technical and evidentiary challenges deeply, rather than treating the space as a simple relabeling of skills they already have.

