CAHIR Solutions

Interactive guide

Predetermined Change Control Plans (PCCP) for AI-enabled devices

FDA issued its final PCCP guidance for AI-enabled device software functions in December 2024 and reissued it in August 2025. This guide explains what a plan has to contain, then gives you three tools: an eligibility checker, an outline builder, and a readiness checklist you can work through with your team.

What a PCCP actually is

A predetermined change control plan is a part of a marketing submission that describes modifications you intend to make to an AI-enabled device after it is authorised, and the process you will follow to make them safely. If FDA authorises the plan, changes made within it can be implemented without going back for a new submission each time.

The legal basis is section 515C of the Federal Food, Drug, and Cosmetic Act, added by FDORA in December 2022. The final guidance followed on 4 December 2024 and was reissued on 18 August 2025, with the scope broadened from machine learning specifically to AI-enabled device software functions generally.

A PCCP is optional. Filing without one is entirely normal; you simply handle each future change through the usual change assessment. The plan earns its keep when you already know you will retrain, recalibrate or extend the device on a regular cadence.

Lifecycle diagram: authorisation, in-protocol change, verification, version log, labelling update
The loop a PCCP authorises: authorisation, an in-protocol change, verification against pre-specified criteria, a version record, and a labelling update.

The three required parts

Every PCCP has the same anatomy. Reviewers read them in this order, and a weak section undermines the ones around it.

01

Description of modifications

What will change, stated specifically and bounded. General statements of intent to improve the model are not modifications.

  • Named, individually described changes
  • The limits each change stays within
  • Automatic or manual release, and cadence
02

Modification protocol

How each change will be developed, verified, validated and released — written so a reviewer can tell whether a given release followed it.

  • Data management and set independence
  • Pre-specified acceptance criteria
  • Update, rollout and rollback procedures
03

Impact assessment

The benefits and risks of each modification, individually and in combination, and how the protocol keeps them controlled.

  • Per-change and cumulative analysis
  • Traceability to the risk management file
  • Effects on other functions and interoperability
Three panels representing the description of modifications, modification protocol and impact assessment

Inside the plan, or a new submission?

The line is drawn by the authorised plan, not by how large the change feels internally.

ChangeCovered by an authorised PCCPNeeds a new submission
Retraining on more data of the same typeYes, if the protocol specifies itNo
Operating point moved within a stated rangeYesNo
Operating point moved outside the stated rangeNoYes
New compatible scanner listed in the planYes, after qualification testingNo
New clinical indicationNoYes
New patient population outside the indicationsNoYes
Model architecture replaced, in protocolYes, with full V&VNo
Change not described in the plan at allNoYes

FDA and EU MDR handle change differently

FDA (PCCP)EU MDR
Pre-authorised change mechanismYes, via an authorised PCCPNo direct equivalent
Who agrees the changeFDA, at the time of the original submissionNotified body, at the time of the change
Trigger for reviewFalling outside the protocolSubstantial change to design or intended purpose
DocumentationProtocol and impact assessment in the submissionChange assessment and updated technical documentation

A US PCCP does not carry over to Europe. See the EU MDR and UKCA guide for how the same change is handled there.

Work it through

Three tools that run entirely in your browser. Nothing you enter is stored or sent anywhere.

Eligibility checker

0 of 6 answered

Answer six questions about the modification you have in mind. Nothing is stored or sent anywhere.

  1. 1.Is the change to an AI-enabled device software function?

    FDA's final guidance covers AI-enabled device software functions. Other software changes may still use a PCCP, but this guidance is written for AI.

  2. 2.Can you describe the change specifically and in advance?

    A PCCP covers named, bounded modifications — not a general licence to improve the device.

  3. 3.Would the change alter the device's intended use?

    Intended use and indications for use as written in the authorised labelling.

  4. 4.Would the change extend the device to a new patient population?

    For example, adding paediatric use to an adult-only indication.

  5. 5.Can performance after the change be verified before release?

    You need pre-specified acceptance criteria and a test method you can run every time.

  6. 6.Can the residual risk of the change be controlled by your protocol?

    The impact assessment has to show that the protocol keeps the benefit-risk profile acceptable.

PCCP outline builder

Choose your submission type, the modifications you expect to make, and the risk profile of the output. The outline updates as you go.

Submission type

Planned modifications

Risk profile of the output

Your outline

PREDETERMINED CHANGE CONTROL PLAN — DRAFT OUTLINE
Submission type: 510(k)
Risk profile: moderate

0. PCCP summary
   - One paragraph stating the device, the authorised intended use, and the fact that this plan does not change it.
   - A table listing each planned modification and where it is described below.

1. Description of modifications
   - Select at least one modification type to generate this section.

2. Modification protocol
   2.1 Data management
   2.2 Re-training practices
   2.3 Performance evaluation
   2.4 Update procedures
        - Include post-release performance monitoring with a defined review period after each modification.

3. Impact assessment
   - Benefit and risk of each modification, individually and cumulatively.
   - How the verification and validation activities in section 2 control each identified risk.
   - Effect on other device functions and on any interoperable systems.
   - Traceability from each modification to the risk management file.

4. Labelling and transparency
   - How users learn that a modification has been released and what changed.
   - Version identification visible to the user.
   - Where the change log lives and how long versions are retained.

5. Documentation and records
   - Records retained for each release: test results, approvals, and release decision.
   - Design control and quality system procedures the protocol runs under.

Reference: FDA, Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions (final, December 2024; reissued August 2025).
This outline is an educational starting point, not regulatory advice.

Readiness checklist

Eighteen items a reviewer will look for. Tick them off as your draft covers them.

0 of 18 complete (0%)

Description of modifications

Modification protocol

Impact assessment

Transparency and records

These tools are educational. They do not constitute regulatory advice and do not replace review by your regulatory affairs team or FDA feedback through the Q-Submission programme.

What a PCCP will not buy you

  • A new intended use. If the claim changes, the plan does not apply.
  • A new patient population outside the authorised indications.
  • Changes that were not described in the plan, however small they seem.
  • Relief from labelling and version transparency. Users still have to know what changed.
  • Automatic acceptance in other jurisdictions. EU MDR and UKCA handle change on their own terms.
Share thisLinkedInXEmail

Running the plan after authorisation

A PCCP is only as good as the records behind it. Every release under the plan needs its test results, its approval, its version identifier and its change-log entry, kept in a form a reviewer can follow years later. MedTech Copilot handles that side: total product lifecycle document drafting, change logging, device project tracking and versioning, so each in-protocol release leaves an audit trail without anyone assembling it by hand.

Frequently asked questions

What is a predetermined change control plan?
A PCCP is a section of a marketing submission that describes planned future modifications to a device, the protocol that will be followed to develop, validate and implement them, and an assessment of their impact. Once FDA authorises the PCCP, changes made within it can be implemented without a new marketing submission.
Which FDA guidance applies to PCCPs for AI-enabled devices?
FDA's guidance 'Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions' was issued in final form on 4 December 2024 and reissued on 18 August 2025. The statutory basis is section 515C of the Federal Food, Drug, and Cosmetic Act, added by FDORA in December 2022.
Do I need a PCCP for a 510(k) or a De Novo?
A PCCP is optional. It is included in a 510(k), De Novo request or PMA when a manufacturer expects to modify an AI-enabled device software function after authorisation and wants to avoid a new submission for each change. Filing without one is perfectly valid; you simply handle each future change through the normal change assessment route.
What are the three required parts of a PCCP?
A description of modifications, a modification protocol, and an impact assessment. The description says what will change and how the change will be presented to users; the protocol says how each change will be developed, verified, validated and released; the impact assessment analyses the benefits and risks of each modification and how the protocol controls them.
What changes cannot be covered by a PCCP?
Anything that alters the device's intended use, extends it to a new patient population outside the authorised indications, or falls outside the specified modification protocol. Those changes still need a new marketing submission.
How does a PCCP interact with EU MDR?
There is no direct EU MDR equivalent. Under MDR, substantial changes to a certified device are handled through the notified body change assessment process, so a US PCCP does not remove the need to notify and, where relevant, obtain notified body agreement for the same change in Europe.
Does a PCCP remove the need for version transparency?
No. Labelling must make clear which version of the device the user has and what changed. FDA expects the PCCP to describe how modifications are communicated to users, and a change log remains part of good lifecycle practice regardless of the PCCP.