Skip to content
    MedTech Launch Guide
    Education Hub for Founders
    Cybersecurity stage
    Worksheet

    Your one-page cyber budget worksheet.

    Choose your stage and device type. The sheet below rebuilds itself, then prints to a single page you can drop into a board deck or a diligence folder.

    Funding stage
    Device type

    Opens your browser print dialog. Choose "Save as PDF" as the destination.

    MedTech Launch Guide · Worksheet

    FDA Cybersecurity Budget

    Series A · Connected Class II device
    Prepared July 27, 2026
    medtechlaunchguide.com
    Typical raise
    $8M to $20M
    Planning band
    $200K to $500K
    Share of round
    2 to 3% of the round
    What this money buys

    A submission-ready Section 524B package that survives review without a cyber deficiency letter.

    Connected Class II device: Baseline. The bands in this worksheet were built around this profile.

    Line items to fund now
    • Complete eSTAR-ready cybersecurity documentation set
    • Manual, exploit-driven penetration test across device, app, cloud and wireless
    • Coordinated vulnerability disclosure policy, published and staffed
    • Cybersecurity labeling and MDS2 preparation for hospital procurement
    • Reviewer-letter response support held in reserve
    Defer to the next round
    • Full-time CISO
    • Certifications no customer has asked for
    What drives your cost
    • Firmware, wireless interface, companion app and cloud all in scope
    • Field update mechanism must be authenticated and recoverable
    • Hospital procurement will ask for an MDS2 form before purchase
    Evidence a reviewer will look for on this device type
    • Threat model covering device, radio, app and backend
    • Hardware and firmware penetration test alongside app and cloud
    • Secure boot and signed-update evidence
    • Cybersecurity labeling and MDS2
    Regulatory anchors
    • FD&C Act Section 524B · Cyber devices must submit a plan to monitor and address postmarket vulnerabilities, processes providing reasonable assurance the device is cybersecure, and a software bill of materials. FDA may refuse to accept a submission that lacks them.
    • FDA premarket cybersecurity guidance · Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (issued 3 Feb 2026, superseding the 27 Jun 2025 edition). Defines the documentation FDA expects in the submission itself.
    • Q-Submission program · Free written FDA feedback before you submit. Scope cybersecurity into the Pre-Sub question list.
    • AAMI TIR57 · Principles for medical device security risk management. The bridge between ISO 14971 and your threat model.
    Budget bands are planning ranges for scoping conversations, not quotes, and not regulatory advice. Regulatory citations link to the primary source. Confirm current FDA guidance before you submit. Cybersecurity content sponsored by Blue Goat Cyber.
    FD&C Act Section 524B FDA premarket cybersecurity guidance Q-Submission program AAMI TIR57