---
title: "Cybersecurity Budget Worksheet: Series A Connected Class II device"
description: "A one-page, printable FDA cybersecurity budget worksheet. Pick your funding stage and device type to get the line items, the deferrals, and the Section 524B evidence your submission needs."
lang: en
json-ld:
---

[Skip to content](#main)

[

MedTech Launch Guide

Education Hub for Founders



](/)

[Roadmap](/roadmap)

[Topics](/topics)

Tools

[Pulse](/pulse)Search ⌘K[Start Here](/start)

Search ⌘K

[Cybersecurity stage](/roadmap/cybersecurity)

Worksheet

# Your one-page _cyber budget_ worksheet.

Choose your stage and device type. The sheet below rebuilds itself, then prints to a single page you can drop into a board deck or a diligence folder.

Funding stage

Pre-SeedSeedSeries ASeries BSeries C and beyond

Device type

Software as a Medical DeviceConnected Class II deviceImplantable or life-sustaining deviceDiagnostics or laboratory deviceMulti-product platform

Company name (optional, prints on the sheet)  Download PDF

Opens your browser print dialog. Choose "Save as PDF" as the destination.

MedTech Launch Guide · Worksheet

## FDA Cybersecurity Budget

Series A · Connected Class II device

Prepared September 8, 2026

medtechlaunchguide.com

Typical raise

$8M to $20M

Planning band

$200K to $500K

Share of round

2 to 3% of the round

What this money buys

A submission-ready Section 524B package that survives review without a cyber deficiency letter.

**Connected Class II device:** Baseline. The bands in this worksheet were built around this profile.

Line items to fund now

-   Complete eSTAR-ready cybersecurity documentation set 
-   Manual, exploit-driven penetration test across device, app, cloud and wireless 
-   Coordinated vulnerability disclosure policy, published and staffed 
-   Cybersecurity labeling and MDS2 preparation for hospital procurement 
-   Reviewer-letter response support held in reserve 

Defer to the next round

-   Full-time CISO
-   Certifications no customer has asked for

What drives your cost

-   Firmware, wireless interface, companion app and cloud all in scope
-   Field update mechanism must be authenticated and recoverable
-   Hospital procurement will ask for an MDS2 form before purchase

Evidence a reviewer will look for on this device type

-   Threat model covering device, radio, app and backend 
-   Hardware and firmware penetration test alongside app and cloud 
-   Secure boot and signed-update evidence 
-   Cybersecurity labeling and MDS2 

Regulatory anchors

-   [FD&C Act Section 524B](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity) · Cyber devices must submit a plan to monitor and address postmarket vulnerabilities, processes providing reasonable assurance the device is cybersecure, and a software bill of materials. FDA may refuse to accept a submission that lacks them. 
-   [FDA premarket cybersecurity guidance](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions) · Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (issued 3 Feb 2026, superseding the 27 Jun 2025 edition). Defines the documentation FDA expects in the submission itself. 
-   [Q-Submission program](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/requests-feedback-and-meetings-medical-device-submissions-q-submission-program) · Free written FDA feedback before you submit. Scope cybersecurity into the Pre-Sub question list. 
-   [AAMI TIR57](https://www.aami.org/) · Principles for medical device security risk management. The bridge between ISO 14971 and your threat model. 

Budget bands are planning ranges for scoping conversations, not quotes, and not regulatory advice. Regulatory citations link to the primary source. Confirm current FDA guidance before you submit. Cybersecurity content sponsored by Blue Goat Cyber.

[FD&C Act Section 524B](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity) [FDA premarket cybersecurity guidance](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions) [Q-Submission program](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/requests-feedback-and-meetings-medical-device-submissions-q-submission-program) [AAMI TIR57](https://www.aami.org/)

MedTech Launch Guide

The independent education hub for medtech innovators bringing devices to the US market - paired with a live pulse of what FDA, CMS, CISA and investors are doing right now.

Sponsored by Blue Goat Cyber 

Pulse

-   [Live Pulse](/pulse)
-   [Funding Tape](/pulse#funding)
-   [Pitch Decks](/pulse#pitch)
-   [Cybersecurity](/pulse#cyber)
-   [Post-mortems](/pulse#failure)

Learn

-   [Founder Roadmap](/roadmap)
-   [Start here: build my plan](/start)
-   [Regulatory & Quality](/roadmap/regulatory-pathway)
-   [Funding & Grants](/pulse#funding)
-   [Clinical evidence](/roadmap/clinical-evidence)
-   [Reimbursement](/roadmap/reimbursement)
-   [Topics & tools](/topics)
-   [Funding quiz](/quiz)
-   [Investor Directory](/investors)
-   [FDA user fees & calculator](/mdufa-fees)
-   [Cyber budget worksheet](/worksheets/cyber-budget)
-   [Glossary](/glossary)
-   [Weekly Brief](/#newsletter)

Company

-   [About](/about)
-   [Editorial policy](/editorial)
-   [Tip line · Contact](/contact)
-   [Privacy](/privacy)
-   [Terms](/terms)

Sister sites

[MedTech Terms ↗](https://medtechterms.com)

medtechterms.com

The full MedTech dictionary. Sourced definitions with a page per term, A-Z and category indexes, learning paths, and side-by-side comparisons.

[A-Z index →](https://medtechterms.com/a-z)[Categories →](https://medtechterms.com/categories)[Learning paths →](https://medtechterms.com/paths)[Compare terms →](https://medtechterms.com/compare)

[Blue Goat Cyber ↗](https://bluegoatcyber.com)

bluegoatcyber.com

Medical device cybersecurity practice. Threat modeling, SBOMs, penetration testing, and FDA premarket and postmarket submission support.

[FDA premarket cyber →](https://bluegoatcyber.com/services/medical-device-cybersecurity/fda-premarket-cybersecurity/)[Penetration testing →](https://bluegoatcyber.com/services/medical-device-cybersecurity/penetration-testing/)[Threat modeling →](https://bluegoatcyber.com/services/medical-device-cybersecurity/threat-modeling/)[Site index →](https://bluegoatcyber.com/site-index)

© 2026 MedTech Launch Guide. Editorial independence is non-negotiable.

Sponsored content is clearly labelled.