MedTech Launch Guide · Worksheet
FDA Cybersecurity Budget
Series A · Connected Class II device
Prepared July 27, 2026
medtechlaunchguide.com
Typical raise
$8M to $20M
Planning band
$200K to $500K
Share of round
2 to 3% of the round
What this money buys
A submission-ready Section 524B package that survives review without a cyber deficiency letter.
Connected Class II device: Baseline. The bands in this worksheet were built around this profile.
Line items to fund now
- Complete eSTAR-ready cybersecurity documentation set
- Manual, exploit-driven penetration test across device, app, cloud and wireless
- Coordinated vulnerability disclosure policy, published and staffed
- Cybersecurity labeling and MDS2 preparation for hospital procurement
- Reviewer-letter response support held in reserve
Defer to the next round
- Full-time CISO
- Certifications no customer has asked for
What drives your cost
- Firmware, wireless interface, companion app and cloud all in scope
- Field update mechanism must be authenticated and recoverable
- Hospital procurement will ask for an MDS2 form before purchase
Evidence a reviewer will look for on this device type
- Threat model covering device, radio, app and backend
- Hardware and firmware penetration test alongside app and cloud
- Secure boot and signed-update evidence
- Cybersecurity labeling and MDS2
Regulatory anchors
- FD&C Act Section 524B · Cyber devices must submit a plan to monitor and address postmarket vulnerabilities, processes providing reasonable assurance the device is cybersecure, and a software bill of materials. FDA may refuse to accept a submission that lacks them.
- FDA premarket cybersecurity guidance · Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (issued 3 Feb 2026, superseding the 27 Jun 2025 edition). Defines the documentation FDA expects in the submission itself.
- Q-Submission program · Free written FDA feedback before you submit. Scope cybersecurity into the Pre-Sub question list.
- AAMI TIR57 · Principles for medical device security risk management. The bridge between ISO 14971 and your threat model.