FDA Computer Software Assurance (CSA) Training — The Final Guidance and What Your Validation Programme Must Address

FDA finalised the Computer Software Assurance (CSA) guidance on September 24, 2025. Three years after the 2022 draft introduced the CSA framework to the pharmaceutical and medical device industry, the final guidance — updated in February 2026 to align with the Quality Management System Regulation and ISO 13485:2016 — is the current FDA expectation for how computerised systems used in GxP activities should be assured.

For validation engineers, QA professionals and IT teams responsible for GxP systems, understanding CSA is no longer optional. Inspectors have been evaluating validation programmes against CSA principles since the 2022 draft. With the final guidance in force, validation programmes still applying uniform scripted testing to every GxP system regardless of risk are operating behind the current expectation.

What CSA changes from legacy CSV

Legacy Computer System Validation (CSV), developed in the 1990s for static, on-premise software, generated documentation as the primary evidence of compliance. Validation binders measured in inches became the proxy for quality. The documentation approach worked for the environment it was designed for — but that environment no longer describes most pharmaceutical IT.

Cloud-hosted systems, SaaS applications, agile development with continuous updates, and AI and machine learning tools have fundamentally changed the software landscape in pharmaceutical manufacturing. A validation approach that requires a full IQ/OQ/PQ cycle every time a cloud vendor pushes an update is both impractical and, under CSA, unnecessary.

CSA replaces the documentation-driven model with a critical thinking-driven model. The fundamental question shifts from "what documentation do we need to generate?" to "what assurance activities are appropriate for the risk this system presents?"

The core CSA principles every validation professional must understand

Intended use determines the scope of assurance activities. Not all GxP system functions carry the same patient safety risk. A laboratory information management system function that calculates and records a critical test result carries higher risk than a function that generates a formatted report. Under CSA, assurance activities are focused on the functions with the highest patient safety risk — not applied uniformly across all system features.

Unscripted testing is explicitly accepted. The final guidance explicitly acknowledges that unscripted, exploratory testing — where a tester exercises the system based on their knowledge of how it will be used without following a pre-written test script — is appropriate for lower-risk functions. This is a direct departure from legacy CSV practice where scripted testing was considered the only defensible approach.

Vendor testing evidence can be leveraged. For commercial off-the-shelf software, the vendor's own testing — including regression testing, release notes and defect logs — can be leveraged to reduce on-site testing for lower-risk functions. The site must evaluate the vendor's testing sufficiency, not replicate it.

21 CFR Part 11 requirements are unchanged. CSA does not reduce electronic records and signature obligations. Systems that generate CGMP records must still meet Part 11 requirements for audit trails, electronic signatures and record protection. CSA and Part 11 operate in parallel — CSA governs the assurance approach, Part 11 governs the electronic records requirements.

What the final guidance added from the 2022 draft

The September 2025 final guidance made six substantive additions and clarifications to the 2022 draft. Validation programmes must address all of them.

Formal definitions for cloud models — Cloud, IaaS, PaaS and SaaS — are now included, making the scope of CSA for cloud-hosted GxP systems unambiguous.

AI and machine learning systems are explicitly included within CSA scope. This is directly relevant given the April 2026 Purolea Pharmaceuticals warning letter — the first FDA enforcement action citing AI misuse in pharmaceutical manufacturing — which cited failure to validate an AI system under 21 CFR 211.68.

Expanded practical examples in Appendix A now include a SaaS PLM case that explicitly addresses vendor service agreements as part of the assurance approach for cloud deployments.

Cybersecurity expectations are now formalised, with vendor cybersecurity posture, SOC reports, software bill of materials and accreditation reviews explicitly recommended as part of supplier assessment for cloud and SaaS systems.

Digital records supported as assurance evidence — system logs, audit trails and software-generated data can be used as objective evidence of assurance activities, reducing the need for parallel paper documentation.

February 2026 QMSR update aligned references from the legacy QSR (21 CFR Part 820) to the new Quality Management System Regulation and ISO 13485:2016.

The most urgent action item

If your computer system validation SOP still references the 2002 General Principles of Software Validation as the controlling document, update it now. Section 6 of that guidance has been formally superseded by the CSA final guidance. An SOP referencing superseded guidance is a finding waiting to happen.

GMPify CSA and GAMP 5 training

GMPify's Computer Software Assurance (CSA) and GAMP 5 course covers the FDA CSA final guidance in full — including the September 2025 finalisation, the February 2026 QMSR update, the transition from legacy CSV, GAMP 5 Second Edition alignment, scripted versus unscripted testing, cloud and SaaS system assurance and the validation programme updates required.

The course includes five knowledge check questions and issues a completion certificate on passing. It is included in the GMPify subscription at $69/month alongside 29 additional courses.

Who this training is for

Validation engineers and scientists, QA professionals responsible for computerised system validation, IT teams managing GxP systems, laboratory systems administrators, and QA directors reviewing the organisation's validation programme against current FDA expectations.

GMPify's Computer Software Assurance (CSA) and GAMP 5 course

FDA CSA final guidance September 2025, GAMP 5 Second Edition, cloud and SaaS systems. Certificate on completion.

View course →