MHRA published the draft statutory instrument for the future UK pre-market framework in May 2026. It moves UK essential requirements toward EU MDR and IVDR concepts, adds explicit cybersecurity standards for software medical devices, and introduces a Predetermined Change Control Plan pathway, the same idea gaining ground at FDA and IMDRF: pre-authorize a class of software and security updates so you are not filing a new submission for each patch.

A stakeholder survey closed in June, with adoption expected around December 2026 and entry into force roughly six months later, plus transition periods. If you sell into Great Britain, start building technical documentation that demonstrates cybersecurity against the new essential requirements, and design the PCCP route into your release process now, because it changes how fast you can ship a fix.