FDA Finalised CSA Guidance September 2025 - What Changed from the Draft

On September 24, 2025, FDA published the final guidance "Computer Software Assurance for Production and Quality System Software" — three years after the September 2022 draft first introduced the CSA framework to the pharmaceutical and medical device industry. A further update was issued on February 3, 2026, aligning the guidance with the Quality Management System Regulation (QMSR) and ISO 13485:2016 references.

The finalisation matters for a precise reason. Inspectors were already evaluating validation programmes against CSA principles before the guidance was finalised. With the final version now in force, a validation programme still applying uniform scripted testing to every GxP system regardless of risk is operating behind the current FDA expectation — even if technically compliant with the letter of 21 CFR Part 211.

Timeline

September 13, 2022: CSA draft guidance published. September 24, 2025: Final guidance published — formally superseding Section 6 of the 2002 General Principles of Software Validation guidance. February 3, 2026: Updated version published — QMSR and ISO 13485:2016 alignment added.

What the final guidance changes from the 2022 draft

The final guidance clarifies rather than replaces the 2022 draft. The philosophical foundation — risk-based, critical-thinking-led assurance proportionate to intended use — is unchanged. What changed is the level of specificity, the addition of formal definitions and the expansion of practical examples.

Change 1

Formal definitions section added

The draft did not include a definitions section. The final guidance adds formal definitions for cloud computing models — Cloud, IaaS, PaaS and SaaS — recognising that the majority of GxP software is now delivered as cloud-hosted or SaaS solutions. This removes ambiguity about whether and how cloud systems fall within CSA scope. They do, unambiguously, when they affect the quality system, product quality or patient safety.

Change 2

Explicit AI and ML systems inclusion

The final guidance explicitly includes AI and machine learning systems within CSA scope. This is directly relevant given the April 2026 Purolea warning letter — the first FDA enforcement action citing AI misuse in pharmaceutical manufacturing. The guidance makes clear that AI systems used in production or quality processes require the same intended-use and risk assessment as any other GxP software, with assurance activities proportionate to the risk of failure.

Change 3

Expanded practical examples — including a SaaS PLM case

Appendix A in the final guidance now includes detailed stepwise examples covering a Nonconformance Management System, a Learning Management System, a Business Intelligence application and a SaaS-based Product Lifecycle Management system. The SaaS PLM example explicitly describes establishing service agreements with the vendor as part of the assurance approach — making cloud deployments and supplier quality agreements unmistakably part of the CSA framework.

Change 4

Cybersecurity expectations formalised

The final guidance adds a dedicated vendor evaluation subsection covering cybersecurity. It recommends assessing vendor cybersecurity posture, development practices, certifications and documentation — including SOC reports, SBOMs (software bill of materials) and accreditation reviews. Remote assessments are explicitly encouraged where direct audit access is limited. This formalises an expectation that was implied but not stated in the 2022 draft.

Change 5

Stronger push for digital records and audit trails

The final guidance explicitly supports using native digital records — system logs, audit trails and data generated and maintained by the software — as objective assurance evidence. This reduces the need for manual paper-based documentation or screenshots duplicating what the system already captures electronically. The guidance clarifies that when electronic records constitute required CGMP evidence, Part 11 controls apply. When they are routine operational logs, Part 11 may not apply.

Change 6 — February 2026 update

QMSR and ISO 13485:2016 alignment

The February 2026 update to the final guidance updates references from the legacy QSR (21 CFR Part 820) to the new Quality Management System Regulation (QMSR) which aligns with ISO 13485:2016. This is primarily a reference update rather than a substantive change — the CSA principles themselves are unchanged — but it ensures the guidance remains current as QMSR replaces QSR for medical device manufacturers.

What did not change

The core principles that made the 2022 draft controversial among traditional CSV practitioners are unchanged and strengthened in the final version:

  • Assurance activities are determined by intended use and patient safety risk — not by software category, complexity or the size of the validation binder
  • Unscripted testing remains explicitly accepted for software features and functions that are not high process risk
  • Vendor testing evidence can be leveraged to reduce on-site testing for lower-risk software functions
  • 21 CFR Part 11 requirements are unchanged — CSA does not reduce electronic records and signature obligations
  • GAMP 5 Second Edition remains fully aligned — the final guidance explicitly references GAMP 5 as a recognised industry guidance document

What your validation programme must address now

The finalisation of the CSA guidance is a signal to act — not to wait. Here is what a validation programme needs to address:

  • Update SOPs. If your computer system validation or software assurance SOP still references the 2002 General Principles of Software Validation as the controlling document, update it. The final CSA guidance has formally superseded Section 6 of that document.
  • Define intended use assessment as the first step. Every GxP system should have a documented intended use assessment as the starting point for determining the scope of assurance activities required.
  • Review vendor controls for cloud and SaaS systems. If you have SaaS GxP systems without quality agreements that address cybersecurity, update notifications, data integrity and inspection access — address them now. The final guidance makes supplier quality agreements for cloud systems a clear expectation.
  • Establish a risk-based change assessment process. For cloud and SaaS systems that receive automatic updates, have a documented process for assessing each release for GxP impact before allowing the update to proceed.
  • Train your validation team. An ISPE survey in early 2024 found that 31% of pharmaceutical professionals had never heard of CSA. Your validation engineers, QA reviewers and system owners all need to understand CSA principles before they can implement them.
The bottom line

The FDA CSA final guidance is not new law. It is a clarification and modernisation of existing 21 CFR requirements — applying them to the software landscape that pharmaceutical manufacturing actually operates in today. Cloud systems, SaaS platforms, AI tools and agile development are not edge cases in pharmaceutical manufacturing any more. They are the norm. The CSA framework provides the regulatory language for how to assure them. Validation programmes that have not yet adopted its principles are running behind both FDA expectations and current industry practice.

Key regulatory references

  • FDA CSA Final Guidance — Computer Software Assurance for Production and Quality System Software, September 24, 2025
  • FDA CSA Updated Guidance, February 3, 2026 — QMSR and ISO 13485:2016 alignment
  • Federal Register 2025-18468, September 24, 2025
  • GAMP 5 Second Edition, July 2022
  • 21 CFR Part 11 — Electronic Records and Electronic Signatures
  • EU GMP Annex 11 — Computerised Systems

Our CSA and GAMP 5 course covers the final guidance in full

FDA CSA final guidance September 2025, the February 2026 QMSR update, GAMP 5 Second Edition, scripted vs unscripted testing, cloud and SaaS systems and the transition from legacy CSV. Certificate on completion.

View course →