SECURE DEV ENVIRONMENT CHECKLIST · MAY 2026
Field Checklist · v1.0

Securing the medical device development environment

A practical checklist for AI-era development in regulated MedTech.

Why this exists

In May 2026, a poisoned VS Code extension (Nx Console) exposed approximately 3,800 internal GitHub repositories. It was live for 18 minutes. Auto-update did the rest.

This is one of several supply chain attacks in 2026 targeting developer workstations, AI coding tools, and MCP servers. For medical device manufacturers, the development environment is part of your evidence chain. If a tool can touch code, credentials, or build workflows, it needs to be governed like any other supplier.

How to use this checklist. Items are grouped by where the control lives. Each section maps to a specific regulatory or industry framework. Use it as a self-assessment or a gap analysis input.

Contents

  1. Workstation & IDE hardeningCorporate Cybersecurity / IT Security
  2. AI coding tools & MCP governanceQMS Supplier Management
  3. Build & release integrityEngineering / DevSecOps · QMS oversight
  4. Detection, response & vulnerability managementProduct Security · Corporate IR
  5. Team training & awarenessQuality / HR · Product Security input
Prepared by CyberMed. Aligned to FDA Cybersecurity in Medical Devices (June 2025), IEC 81001-5-1:2021, AAMI SW96:2023, AAMI SW91, JSP v2, ISO 13485, ISO/IEC 29147. 01 / 07
Section 01 · Workstation & IDE
01
Section one

Workstation & IDE hardening

Owner
Corporate Cybersecurity / IT Security
Reference
IEC 81001-5-1 §5.1.2 · Development environment security
Example tools Microsoft Defender for Endpoint · CrowdStrike Falcon · SentinelOne · Aikido Endpoint · Snyk Developer Security · Intune / Jamf for policy enforcement.
Securing the Medical Device Development Environment · CyberMed Checklist v1.0 02 / 07
Section 02 · AI Coding Tools & MCP
02
Section two

AI coding tools & MCP governance

Owner
QMS Supplier Management
Reference
ISO 13485 §7.4 (Purchasing) · JSP v2 §C (Supplier Management) · FDA Premarket Guidance §V
Example tools GitHub Copilot Enterprise · Claude Code · Cursor · Checkmarx One Assist · Snyk Code · Lasso Security (agent inventory) · Arcade.dev (MCP governance).
Securing the Medical Device Development Environment · CyberMed Checklist v1.0 03 / 07
Section 03 · Build & Release Integrity
03
Section three

Build & release integrity

Owner
Engineering / DevSecOps, with QMS oversight
Reference
IEC 81001-5-1 §7.2 · AAMI SW96 Annex D.3.1 (Supply chain threat scenario) · AAMI SW91 §6.4 (Build and release tools) · FDA Premarket Guidance §V.B (Security Architecture)
Example tools GitHub Actions with OIDC · GitLab CI · Sigstore / cosign · in-toto · Anchore · Syft / Grype · Dependency-Track · AWS Signer · HashiCorp Vault.
Securing the Medical Device Development Environment · CyberMed Checklist v1.0 04 / 07
Section 04 · Detection, Response & Vuln Mgmt
04
Section four

Detection, response & vulnerability management

Owner
Product Security, with Corporate IR support
Reference
FDA Postmarket Cybersecurity Guidance · JSP v2 §F (Maintenance) · AAMI TIR97 (Postmarket Risk Management)
Example tools GitHub Advanced Security · GitGuardian · Wiz · Datadog Cloud SIEM · Splunk · CISA KEV feed · NVD API · OSV.dev.
Securing the Medical Device Development Environment · CyberMed Checklist v1.0 05 / 07
Section 05 · Team Training & Awareness
05
Section five

Team training & awareness

Owner
Quality / HR, with Product Security input
Reference
ISO 13485 §6.2 (Human resources / competence) · FDA QMSR (2026) · IEC 81001-5-1 §6.1
Example tools & programs SANS Secure Coding · Secure Code Warrior · AppSec Engineer · Anthropic and OpenAI usage policy training · internal lunch-and-learns on recent incidents.
Securing the Medical Device Development Environment · CyberMed Checklist v1.0 06 / 07
FDA eSTAR Submission Mapping
06
Appendix

Mapping to FDA submission documentation

The controls in this checklist directly support the cybersecurity attachments in an eSTAR submission. Use this table during pre-submission planning to confirm each attachment has supporting evidence from the relevant section.

Checklist section eSTAR attachment
1, 5 Secure Product Development Framework (SPDF) documentation
2 Cybersecurity Risk Management Plan · Supplier Management Records
3 Security Architecture Views · SBOM · VEX
3, 4 Threat Model · Security Risk Assessment
4 Postmarket Cybersecurity Management Plan · Vulnerability Communication Plan
5 Personnel competence records (QMS)

Self-assessment

Walk the list with the owner named in each section. Tick boxes that are fully implemented; flag partials for a follow-up gap analysis.

Pre-submission readiness

Pair each ticked control with the eSTAR attachment it supports. Unticked rows become the cybersecurity work plan for your next submission.