The International Medical Device Regulators Forum (IMDRF) has finalized a technical document outlining how regulatory agencies may adopt predetermined change control plans (PCCP). The document lists principles for regulators to consider when developing their own PCCP regulations, as well as key elements to include in manufacturers' PCCPs.
The US Food and Drug Administration (FDA) was explicitly authorized to accept PCCPs under the 2022 Food and Drug Omnibus Reform Act (FDORA), though it allowed sponsors to include them in premarket submissions for some time prior to the law’s adoption. Since then, regulators around the world have taken an interest in the topic, and last year, IMDRF's management committee approved a draft version of the technical document from its Software as a Medical Device Working Group for a 60-day public consultation. (RELATED: IMDRF plans new PCCP guideline, adds new affiliates, Regulatory Focus 30 September 2025)
Typically, if a manufacturer wants to make certain changes to a marketed medical device, they need to submit a supplement or new submission detailing those changes for regulatory review; however, PCCPs allow them to make those changes without the need to file a supplement or new submission if the changes have been predetermined between regulators and the company. While FDA's PCCP guidance could potentially be used for a whole slew of changes to medical devices and their manufacturing processes, IMDRF's finalized technical document, published on 6 August, only applies to medical device software changes.
"PCCPs have the potential to be applied beyond medical device software to other areas of medical technology," said IMDRF. "The evolution of PCCPs could lead to more flexible and responsive regulatory frameworks, better suited to the fast-paced nature of technological innovation in healthcare.
"However, the focus of this document is on medical device software," the group added.
The technical document lists five essential principles that regulators should adhere to when considering PCCPs, including limiting changes to the medical device software's intended use, taking a risk-based approach, using an evidence-based approach where evidence is gathered and constantly evaluated about the medical device software, ensuring transparency, and using a total product lifecycle (TPLC) approach. It also lists three elements that PCCPs should include, including a description of changes, a change plan, and an impact assessment.
IMDRF noted that the description of changes should detail the changes the manufacturer plans to make to its device, with a rationale for each, and that change plans should describe the verification and validation of those changes and explain how those changes will be communicated to users. The group also elaborated that impact assessments are meant to evaluate the impact of the changes and ensure the medical device software continues to meet safety and efficacy requirements.
IMDRF emphasized that PCCP is an optional mechanism that manufacturers can propose in their initial premarket submission or when submitting a supplement to change an already marketed product, allowing them to make changes to their product within prespecified parameters without the need to submit additional authorization requests. The group added that PCCPs may be used to support certain iterative changes but must do so while ensuring the product's continued safety and efficacy.
"The PCCP should be developed and managed within the manufacturer’s existing quality management system, including the risk management process," said IMDRF. "Changes included in a PCCP, which may include planned maintenance activities, are limited to changes within the medical device software’s original intended use or intended purpose.
"A manufacturer’s quality management system, specifically the risk management and change management processes, is critical to ensure that medical device software consistently meets applicable regulatory requirements and pre-defined specifications," the group added. "This is particularly important for medical device software that is authorized with a PCCP, as PCCPs include changes that would otherwise require a new submission."
IMDRF emphasized that PCCP changes should be implemented within the manufacturer's risk management system, with particular consideration of change management and risk management processes, while also complying with existing regulatory requirements and international standards. The group also emphasized that all parties involved should pay particular attention to version control, so regulators and manufacturers know which software version was authorized, enabling them to track it.
"Because PCCPs contain modifications that would otherwise require a new submission, revisions to a previously authorized PCCP are generally considered to be a change that will affect the safety and performance of the medical device software and will therefore likely require reauthorization," said IMDRF. "However, some jurisdictions may allow for some minor changes to PCCPs without re-authorization."
IMDRF suggested that it may be useful for manufacturers to connect the changes in their PCCP description of changes section to the verification or validation plan in the PCCP's change plan, as it may help regulators identify those changes and how they may affect the device safety and performance.
Broadly, IMDRF said that PCCP adoption may help patients access improved products more quickly and enable healthcare systems, manufacturers, and regulators to achieve greater efficiency. The group, however, highlighted that despite the potential for benefits, PCCPs come with certain challenges.
"Regulatory bodies will face increased submission complexity at the time of the initial regulatory review," said IMDRF. "This complexity also applies to manufacturers, who will need to prepare the necessary documentation for PCCPs at the time of submission.
"Clear documentation and communication between manufacturers and regulatory authorities is crucial to ensure traceability and implementation around the acceleration of modifications of medical device software within the context of a robust quality management system," the group added. "Additionally, manufacturers should be cognizant of the differences in jurisdictional adoption of PCCPs as this may complicate their PCCP authorization plans and/or their global reliance strategies."