Five Key Recommendations for Building a Predetermined Change Control Plan
The Predetermined Change Control Plan (PCCP) allows medical device manufacturers to pre-declare anticipated post-market changes to the FDA, addressing regulatory challenges posed by frequent AI software updates. Although the framework has been recognized by the FDA, many companies still do not adopt it due to unfamiliarity or a lack of long-term planning. Based on expert interviews with MedTech Dive, this article distills five practical recommendations regarding PCCP.

As more medical devices incorporate artificial intelligence technology, regulators are exploring how to effectively manage frequent software updates.
A new regulatory framework—the Predetermined Change Control Plan (PCCP)—has emerged. This framework allows companies to specify in advance the changes they plan to make before a product goes to market. This is a stark departure from the traditional model: previously, if a change could affect a device's safety or effectiveness, companies typically had to submit an application to the U.S. Food and Drug Administration (FDA). After the FDA releaseda draft guidance in 2023, it published in Decembera final guidance, clarifying its expectations for PCCPs and approving related plans.
In interviews with MedTech Dive, experts said PCCPs could serve as a bridge to more automated software updates. However, many manufacturers have yet to adopt the framework, due to a lack of familiarity or failure to plan far enough ahead for their products.
Here are five recommendations on how to use PCCPs:
1. PCCPs are likely to survive regulatory uncertainty
It remains unclear how the FDA will regulate artificial intelligence in medical devices under President Donald Trump. Early in his presidency, Trump signed an executive orderrevoking Biden-era efforts around AIand calling to "maintain and enhance America's global dominance in AI."
Experts believe this administration may roll back someFDA requirements, but given the positive reception from the medical technology industry, they expect the PCCP concept to endure.
Michele Buenafe, a lawyer who leads the FDA and healthcare practice at Morgan Lewis, noted that the framework was formally established after Congressgranted the FDA authorityin its 2022 omnibus spending bill.
Megan Robertson, a lawyer at Epstein Becker Green, also expects PCCPs to be long-lasting.
"Given that the core purpose of PCCPs is to streamline the process for developers," Robertson said, "I would be surprised if the new administration severely curtailed PCCPs or limited their use."
2. Is a PCCP the right approach?
Beacon Biosignals, a company that makes devices to measure brain activity and sleep, has had two PCCPs approved by the FDA. One is for in-clinic sleep scoring software, and the other is for its wearable headband device, Dreem 3S, used for home sleep monitoring.
Alexander Chan, vice president of analytics and machine learning at Beacon Biosignals, said these plans allow the company to retrain its algorithms to improve performance as it gains more data.
Chan said the company took this approach to ensure its devices perform well in the subgroups targeted by their indications and to keep pace with changes in clinical practice.
"If we don't continuously update our algorithms, we risk optimizing for a population that might be what clinicians were treating in the 80s but is no longer relevant," Chan said. "That's critical for us."
When considering a PCCP, companies must keep several factors in mind. The FDA requires that changes be necessary to maintain or improve the safety and effectiveness of the product, and that updates cannot alter the device's intended use. Robertson said companies must also submit their change plans to the FDA and follow the same procedures each time.
Robertson believes the framework is suitable for devices that require regular changes or modifications, such as calibrations to adapt to new operating systems.
"Given the nature of AI," Robertson added, "for most, if not all, AI- or machine-learning-driven device functions, this should be part of the discussion."
3. Develop a roadmap
Experts say companies considering a PCCP should plan their updates in advance.
"You shouldn't go to the FDA unless you know where the product is going," said LaDale George, a partner at Perkins Coie, adding that companies should be able to explain why the device is heading in that direction.
Ashkon Rasooli, founder and CEO of medical device consulting firm EnGenius Solutions, said companies should first ask themselves whether they have a roadmap.
Rasooli noted that the PCCP framework allows companies to essentially front-load FDA review of device changes, but "in the industry, companies often only plan for the next upcoming release."
As a result, Rasooli said he has seen some adoption of PCCPs as a regulatory strategy, but it has not been widespread.
4. Details matter
Beacon Biosignals' Chan, drawing on his experience with two FDA-approved PCCPs, said his main advice to other developers is to thoroughly think through all the details of the proposed changes. For example, Beacon Biosignals developed a validation plan to demonstrate how the team would ensure the safety and effectiveness of updates, and used representative datasets to prove the results could generalize to real-world populations.
Similarly, Rasooli said the main concern he has heard from the FDA is a lack of detail. Early communication with the FDA can mitigate these criticisms. In the final guidance, the FDA also recommended that developers use its Q-submission program to obtain feedback before submitting a PCCP.
"It's hard for manufacturers to disclose the core secrets of their algorithms, if they know them," said Perkins Coie's George, but providing the FDA with "some basic level of transparency" is crucial for evaluating changes later.
5. Plan the rollout of changes
Erez Kaminski, founder and CEO of software development company Ketryx, said PCCPs can be challenging for medical device companies because they are not accustomed to this type of change management.
"Years ago, the medical community discovered that no one wanted to release updates on a daily, weekly, or monthly basis, but now we hear many companies wanting to do so," said Kaminski, who develops software for regulatory compliance.
Kaminski added that developers must be able to answer what they plan to change, how they will manage the data lifecycle, how they will implement the change, and how they will assess whether the change was successful. All of this should be documented.
Morgan Lewis's Buenafe said companies should also have a plan for notifying customers of changes after the product is on the market. For example, they may need to update the device's labeling to reflect that the algorithm is faster or has improved sensitivity or specificity.
Buenafe also cautioned that the guidance does not guarantee the FDA will be satisfied with every submission involving automated changes, which could raise more complex issues. However, she said, "I do think they intended for this framework to open the door to automated changes."