Dec 4, 2024·FDA · Final GuidanceActiveHigh impact
FDA finalizes Predetermined Change Control Plans (PCCP) guidance
Final PCCP guidance lets manufacturers pre-authorize specified modifications to AI/ML-enabled device software functions without a new submission, provided cybersecurity impacts are scoped up front.
What changed
- PCCP must define the modification protocol, impact assessment, and the cybersecurity assumptions that bound each planned change.
- Any change that breaks the cybersecurity envelope falls outside the PCCP.
Action for manufacturers
Cross-reference PCCPs against your threat model and SBOM/VEX cadence so cybersecurity-impacting changes are explicit (or explicitly out of scope).