← Back to blog

Avoid FDA Deficiency Letters: U.S. 5 Step PCCP for SaMD Checklist

September 25, 2026
Avoid FDA Deficiency Letters: U.S. 5 Step PCCP for SaMD Checklist

A Predetermined Change Control Plan (PCCP) lets a manufacturer implement specified future modifications to a Software as a Medical Device without filing a new marketing submission for each one, as long as the changes match what FDA authorized. The plan documents three things: the modifications you intend to make, the protocol you'll use to verify them, and the impact assessment showing they remain safe and effective. Get it authorized, and it belongs front and center in your submission, not buried as an afterthought.


TL;DR:

  • Most modifications eligible for a PCCP are constrained to scope, similar input sources, or model retraining within defined parameters, avoiding fundamental clinical changes.
  • The modification protocol must include specific numeric acceptance criteria, clear stop or revert rules, and testing methods to meet FDA expectations.
  • Impact assessments should evaluate individual and cumulative risk, bias, and cybersecurity effects, with special attention to demographic performance and downstream interoperability.
  • PCCPs are authorized through PMA, 510(k), or De Novo pathways, and the plan should be a standalone section in the submission with explicit scope and clear references.
  • Postmarket, companies must monitor device performance within the authorized scope and update or withdraw modifications if real-world results deviate from approved parameters.

The StartupMD
Navigate Healthcare SaaS Growth Challenges
The StartUp MD brings medical and business expertise to healthcare SaaS companies navigating product-market fit, fundraising, and growth.
Explore The StartUp MD

Table of Contents

What Is a PCCP for SaMD, and Why Does It Matter for Total Product Lifecycle?

A PCCP shifts SaMD regulation from single-shot approval toward a lifecycle model. Instead of treating your device as fixed at clearance and filing a new submission every time you retrain a model or expand a compatible input type, you negotiate the boundaries of future change up front, then operate inside them under your existing quality management plan.

This only works within your Quality System Regulation (21 CFR 820) and IEC 62304 software lifecycle processes, which is why design controls under 21 CFR 820.30 and IEC 62304 matter as much as the PCCP document itself. A PCCP is not the right tool for every change. Routine bug fixes and minor label corrections still go through ordinary document-to-file change control. A PCCP is for changes that would otherwise trigger a new 510(k) or PMA supplement. It does not lower FDA's safety bar; it requires you to prove, in advance, that you can manage change within a defined Total Product Lifecycle framework.

Section 515C of the Food, Drug, and Cosmetic Act, added by the Food and Drug Omnibus Reform Act (FDORA), gives FDA explicit statutory authority to authorize PCCPs and specifies that they can be established through PMA, 510(k), or De Novo submissions, according to the Federal Register notice on PCCP marketing submissions. Two FDA documents translate that statute into practice: the guidance on marketing submission recommendations for AI-enabled device software functions, and the guiding principles document developed with international regulatory partners for machine learning-enabled devices.

Once FDA authorizes your PCCP, you can implement the specified modifications without a new marketing submission, provided you follow the plan exactly as written, per FDA's guidance on PCCP marketing submissions. That authorization is bounded. Deviate from the protocol, exceed the described scope, or skip an acceptance criterion, and you're back to filing a traditional submission.

What Legal Authority Governs PCCP for SaMD? — overview diagram

What Are the Three Required Components of a PCCP?

Every PCCP rests on three interrelated components. FDA expects each one detailed enough that a reviewer unfamiliar with your product could understand exactly what you plan to change and how you'll prove it's safe.

  • Description of Modifications: Define the type of change (a retraining update, an added input source, a new compatible imaging format) rather than listing every conceivable future tweak. Specify what's in scope and what's explicitly excluded, since ambiguity here is one of the fastest ways to draw review questions.
  • Modification Protocol: Lay out the verification and validation activities, predefined acceptance criteria, test methods, and stop or revert criteria tied to each modification type.
  • Impact Assessment: Evaluate the risk and benefit of each modification individually and cumulatively, addressing bias, representativeness of the intended use population, and downstream effects on labeling or interoperability.

FDA's guiding principles emphasize that a workable PCCP stays focused and bounded, risk-based, evidence-based, and transparent, all viewed through a Total Product Lifecycle lens rather than a single approval snapshot.

Which Modifications Belong in a PCCP for SaMD?

Good candidates share a common trait: they're bounded enough that FDA can evaluate the type of change now, even though the specific change hasn't happened yet. Think performance specification updates within a defined range, expanded compatibility with additional but similar input devices, or model retraining constrained to a defined dataset and parameter set.

Poor candidates include anything that introduces a new intended use, meaningfully raises risk classification, or changes the fundamental clinical claim. Those need a fresh submission, full stop. Minor administrative changes, meanwhile, don't need a PCCP at all. They belong in your existing document-to-file change control process, and trying to route them through a PCCP just adds unnecessary review burden.

FDA's draft guidance on PCCPs for medical devices recommends focusing on changes that would otherwise require a new 510(k), then writing explicit in-scope and out-of-scope examples for each. That specificity is what separates a PCCP that sails through review from one that generates round after round of deficiency letters.

How Do You Build a Modification Protocol That FDA Will Accept?

The Modification Protocol is where vague intentions become testable commitments. FDA wants numeric acceptance criteria, not aspirational language. If your modification affects diagnostic performance, define the minimum acceptable sensitivity, specificity, or AUC, along with the statistical analysis plan you'll use to confirm the updated model meets it.

  • Set acceptance thresholds before you know the result, not after.
  • Define stop or revert criteria tied to specific monitored metrics, so a failing update gets pulled automatically rather than debated in a meeting.
  • Describe whether implementation is manual or automatic, and global or local. FDA notes that automatic implementation carries added complexity that your protocol needs to address directly.
  • Plan staged rollouts with human oversight and telemetry so you can validate real-world performance before full deployment.

Pro Tip: Reviewers rely on FDA's appendices of example scenarios and modification protocol questions as an informal template. Draft your protocol section by mirroring that structure, and you'll answer most reviewer questions before they're asked.

Verification and validation rigor here should mirror what you'd already apply under FDA software validation expectations, just scoped to the specific modification type rather than the whole device.

How Should You Handle Risk, Bias, and Cybersecurity in the Impact Assessment?

The Impact Assessment is where benefit-risk analysis meets your existing risk management file. Every modification type needs its own risk evaluation, plus a look at cumulative effect: three individually low-risk changes stacked over eighteen months can add up to something FDA would want reviewed differently than any single one.

Algorithmic bias deserves explicit treatment. If your retraining protocol touches a model that performs diagnostic or triage functions, document how you'll confirm performance holds across the demographic and clinical subgroups in your intended use population, not just in aggregate. Cybersecurity and interoperability effects belong here too. A change that alters data formats or expands network-connected inputs needs its patch management and interoperability implications folded into the same assessment, not treated as a separate afterthought.

Where Does the PCCP Go in Your FDA Marketing Submission?

Section 515C permits PCCPs to be authorized through PMA, 510(k), or De Novo submissions, so pathway choice usually depends on your device's underlying classification rather than the PCCP itself. If you're still deciding between pathways, comparing De Novo and 510(k) strategy before drafting your PCCP saves rework later.

FDA recommends the PCCP appear as a standalone section in your submission, referenced clearly in the cover letter and table of contents, with labeling cross-references noted explicitly. Expect interactive review. Vague scope language and undefined acceptance criteria are the two fastest ways to trigger additional information requests.

What Happens After PCCP Authorization: Labeling and Monitoring?

FDA recommends labeling state plainly that the device operates under an authorized PCCP, describing how modifications might affect the user experience. That's a transparency requirement, not a suggestion you can quietly skip.

Postmarket, you need a defined monitoring cadence: how often you check for performance drift, how you detect it, and how you notify users when a modification goes live. If a real-world change falls outside your authorized scope, or performance drifts beyond what your Modification Protocol anticipated, you need a PCCP revision or an entirely new marketing submission. There's no gray zone here your labeling can paper over.

Postmarket monitoring and escalation loop

What Should Be on Your PCCP Preparation Checklist?

Before you touch the submission draft, work through these steps in order:

  1. Finalize the scope of each modification type, with explicit in-scope and out-of-scope examples.
  2. Build the Modification Protocol, including V&V plans, numeric acceptance criteria, and stop or revert rules.
  3. Draft the Impact Assessment covering per-change and cumulative risk, bias, and cybersecurity effects.
  4. Establish your postmarket monitoring plan and QMS traceability linking PCCP changes back to your quality records.
  5. Request a pre-submission meeting with FDA to pressure-test scope and protocol language before formal filing.

The most common reasons FDA sends deficiency letters trace back to steps one and two: scope written too broadly, or acceptance criteria left undefined. A gap analysis against common SaMD submission pitfalls before you file catches most of these issues early.

How Do You Operationalize PCCP Readiness Across Your Organization?

The technical content of a PCCP is only half the battle. The other half is organizational: clinical, regulatory, QA, and data science teams have to align on scope decisions before the document reaches FDA, not after a deficiency letter forces the conversation. Instrument your monitoring metrics before submission, not after authorization arrives and you scramble to build dashboards you should have had running for months.

Outside advisory help earns its cost fastest at two points: translating clinical risk into FDA's bounded-scope language, and structuring the governance that shows a reviewer exactly how your teams will make scope decisions once the plan is live.

— Paul Bergeron MD, MBA

Get PCCP Support From Experienced Fractional Medical Leadership

Most SaMD teams don't lack technical talent. They lack a clinical voice sitting inside the regulatory conversation who can translate what "bounded and risk-based" actually means for your specific model, dataset, and patient population, before FDA asks the hard question. The StartupMD closes that gap directly.

The StartupMD

Paul Bergeron, MD, MBA brings clinical and business judgment to PCCP drafting, Modification Protocol design, and the FDA interactions that follow. That's a different kind of support than a pure regulatory consultancy offers, because the same advisor who helps you write acceptance criteria can also speak to how a retraining update affects real clinical workflows. Whether you're structuring your first PCCP for a pre-submission meeting or building the postmarket monitoring plan that keeps an authorized plan compliant, The StartupMD's Fractional Chief Medical Officer and Advisory Services exist for exactly this stage of a healthcare SaaS company's growth. If your team is heading into a PCCP conversation with FDA, reach out through the services page to scope an engagement before your next submission deadline.

Sources

FAQ

What Is a PCCP for SaMD?

A PCCP is a plan submitted with your marketing submission that describes specific future modifications to your software, the protocol for verifying them, and an assessment of their impact. Once FDA authorizes it, you can implement those specified changes without filing a new marketing submission, as long as you follow the plan exactly.

Which FDA Submission Pathways Allow a PCCP?

PMA, 510(k), and De Novo submissions can all establish an authorized PCCP under Section 515C. Your device's existing classification, not the PCCP itself, generally determines which pathway applies.

What Modifications Should Be Excluded From a PCCP?

Exclude changes that introduce a new intended use, materially increase risk, or alter the core clinical claim. Minor administrative or bug-fix changes also don't belong in a PCCP. They stay in your ordinary document-to-file change control process instead.

Why Do FDA Reviewers Reject or Question PCCPs?

The most common issues are vague modification scope and undefined acceptance criteria in the Modification Protocol. Missing stop or revert rules and inadequate postmarket monitoring plans also generate deficiency requests.

When Should a Healthcare SaaS Company Bring in Outside Regulatory Help?

Engaging outside advisory support before your pre-submission meeting typically saves the most time, since scope and protocol language are hardest to fix after FDA has already raised questions. The StartupMD's Fractional Chief Medical Officer and Advisory Services are structured for exactly this stage of PCCP and marketing submission preparation.