Draft an 8-section SDS-PCCP outline aligned to FDA's December 2024 PCCP guidance - with per-modification cybersecurity impact and the deficiency flags reviewers actually cite.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
PCCP completion
1/9 requirements complete
Progress saved on this device automatically.
Model class
Determines which monitoring and re-training controls reviewers expect.
Planned modification types
Each choice carries a known FDA disposition and cybersecurity expectation. Out-of-scope items will be flagged.
Verification methods (modification protocol)
Items marked required are flagged in your output if missing.
Transparency / user notification
FDA expects clinicians to know when a model version changes underneath them.
What you'll see after you submit
Common misconceptions
Myth: PCCP is only for continuously-learning AI.
Reality: FDA's guidance applies PCCP to any planned change to a software function - including locked algorithms and deterministic updates. 'Predetermined' is about the plan, not the model class.
Myth: PCCP lets us push any model update without a new submission.
Reality: Only changes inside the documented modification scope are exempt. Hardware expansion, new intended use, new interfaces, and most architecture swaps still require a new 510(k) or supplement.
Myth: We can skip cybersecurity in the PCCP if the device already has §524B docs.
Reality: The FDA's Feb 3, 2026 final cyber guidance requires explicit cybersecurity impact analysis for every modification path (SBOM diff, threat model delta, attack surface review), separate from the baseline §524B package.
Myth: Rollback is a deployment concern, not a regulatory one.
Reality: FDA expects (a) a documented rollback trigger, (b) evidence the rollback is exercised before each release, and (c) a notification plan to clinicians. Documentation alone is rejected.
Myth: Real-world performance monitoring is optional if we have a strong test set.
Reality: RWPM is the most common PCCP deficiency. For any model that retrains or adapts, it's effectively mandatory - and reviewers want named metrics, thresholds, and cadence.
References & further reading
Tracked signals that change what reviewers expect. Items move on as new ones land.
Full SPDF + eSTAR-ready submission aligned to current FDA guidance.
Read FDA premarket cybersecurity servicesSTRIDE-based threat model that satisfies PCCP impact-assessment requirements.
Read Threat modeling servicesSPDX/CycloneDX SBOMs with continuous CVE/VEX maintenance.
Read SBOM services for MedTechReadiness quiz, §524B applicability, SaMD classifier, and more.
Read More free tools