FDA's Shift from CSV to CSA: What GAMP5 Users Need to Know Now
FDA's Computer Software Assurance draft guidance reshapes GMP software validation. Here's what GAMP5 second-edition users must update before their next FDA audit.
Most validation teams are still writing IQ/OQ/PQ protocols the same way they did in 2005. The documentation binders are thicker than ever. The test scripts cover hundreds of fields. And FDA is increasingly frustrated by all of it.
In September 2022, FDA released its draft guidance titled Computer Software Assurance for Production and Quality System Software — a document that explicitly signals the agency’s intent to move away from documentation-heavy Computer System Validation (CSV) and toward a risk-based, thinking-first model called Computer Software Assurance (CSA). Months earlier, ISPE had published the second edition of GAMP5 in April 2022, quietly aligning with the same principles.
Together, these two documents represent the most significant shift in GxP software validation philosophy in two decades. Most regulated manufacturers and labs are still catching up.
What FDA Actually Said — And What It Means
The September 2022 CSA draft guidance is surprisingly direct. FDA’s stated concern is that the industry has developed a culture of “over-testing and under-thinking” — generating enormous volumes of test scripts and approval signatures to demonstrate compliance, while missing the actual risk-based questions that matter for product quality and patient safety.
The guidance applies to production and quality system software governed under 21 CFR Parts 211, 820, and related GxP regulations. It doesn’t replace 21 CFR Part 11, which still governs electronic records and electronic signatures in full force. But it fundamentally changes how you should justify your validation scope.
Under CSA, the core obligation is no longer “document everything you tested.” It’s “apply critical thinking to determine what needs testing, then document that thinking.” FDA uses the phrase “critical thinking” eight times in the draft guidance. That’s not an accident — it’s a signal about what the agency expects to see during an inspection.
Three practical consequences flow directly from this:
Intended use drives everything. Your validation scope should be anchored to the intended use of the system in your specific GxP context — not to a vendor’s installation qualification template that ships with every copy of the software.
COTS software gets proportional treatment. Commercial off-the-shelf software (your LIMS, your ERP, your chromatography data system) carries different residual risk than a custom-built data aggregation module written by an intern three years ago. FDA expects your testing effort to reflect that distinction.
Low-value documentation activities should be eliminated. Re-testing standard operating system features, capturing screenshots of generic UI elements, running scripted checks on vendor-pre-tested functionality — the CSA guidance specifically identifies these as examples of effort that consumes resources without improving patient safety or product quality outcomes.
That last point tends to generate internal resistance. Compliance teams that have spent years equating documentation volume with regulatory safety find it genuinely unsettling when FDA says “do less, but think more.” But that’s precisely what the agency is asking.
GAMP5 Second Edition — The Category Change That Changes Everything
ISPE published the second edition of GAMP5 in April 2022, and the most immediately actionable change is the restructuring of software categories. If your validation SOPs still reference five categories including “Category 2” — which historically covered spreadsheets and macros — they’re now outdated against the current standard.
The second edition uses four categories:
- Category 1: Infrastructure software (operating systems, database engines, middleware, virtualization layers)
- Category 3: Non-configured products (off-the-shelf software used without modification or configuration)
- Category 4: Configured products (COTS software that requires configuration, scripting, or parameter-setting for your GxP environment)
- Category 5: Custom software (applications built, heavily modified, or scripted specifically for your organization)
Category 2 was intentionally removed. Spreadsheets and macro-driven tools now fall into Category 3, 4, or 5 depending on their complexity and intended use — a recognition that a simple reference lookup table and a macro-driven stability trending calculation carry fundamentally different risk profiles and shouldn’t share a validation template.
The second edition also places substantially greater weight on data integrity as a core validation concern. An audit trail isn’t just a Part 11 checkbox in this framework. Under GAMP5 2nd edition, evaluating data integrity controls — access permissions, modification logs, backup and recovery validation — is part of the risk assessment for any Category 4 or 5 system. Given that data integrity violations have consistently ranked among the most cited deficiencies in FDA warning letters to pharmaceutical manufacturers over the past several years, this shift in emphasis reflects real-world enforcement patterns, not theory.
Three Places Most Organizations Are Still Getting This Wrong
Working with regulated manufacturers and contract labs on software validation programs, we see the same structural gaps appearing repeatedly. These aren’t obscure edge cases — they’re systemic misalignments between legacy CSV programs and the CSA/GAMP5 2nd edition framework.
1. Applying uniform test script density across all systems
Under the old model, a commercial LIMS and a custom-built data aggregation tool might receive nearly identical validation documentation packages — just with different system names on the cover page. Under CSA and GAMP5 2nd edition, that approach is exactly backwards. A widely-deployed, vendor-supplied LIMS that has been validated thousands of times across the industry (Category 4) carries far lower residual risk than a custom-built reporting tool that only your lab uses (Category 5). Your testing effort should reflect that asymmetry.
The fix is structural: build a formal risk tiering step at the start of every validation project. Before drafting a single test case, answer three questions — what is the intended GxP use, what is the system’s complexity and customization level, and what is the consequence of a failure on product quality or patient safety? Let those answers drive scope, not a default template that gets reused regardless of system type.
2. Treating GAMP5 categories as permanent labels rather than dynamic risk assessments
Category assignment isn’t a one-time activity performed at system implementation and then filed away. When your system configuration changes significantly, when you upgrade across major versions, when you integrate a previously standalone system with other GxP data sources — those events can meaningfully change the risk profile and should trigger a formal reassessment.
We’ve encountered audit findings where a LIMS that started as a Category 4 implementation had been progressively extended with custom calculation modules over several years, effectively converting portions of it into Category 5 functionality — but the validation master record still reflected the original classification from the initial deployment. FDA investigators aren’t impressed by that kind of documentation staleness, and “we didn’t think it required requalification” isn’t a satisfying response when the investigator is looking at a custom formula driving batch release decisions.
3. Failing to update the Validation Master Plan
Your VMP is the document that explains your overall strategy to an auditor before they look at anything else. If it still describes your approach as “IQ/OQ/PQ protocols covering all system functions,” it’s signaling a framework that predates both FDA’s CSA draft guidance and GAMP5 2nd edition. That misalignment shapes the auditor’s impression before the inspection is even underway.
Updating the VMP doesn’t mean starting over from scratch. It means adding explicit language about how your program applies critical thinking to scope determination, how intended use anchors each validation project, and how your category framework aligns with GAMP5 2nd edition. That update typically takes two to three days of focused effort from your quality systems lead — and it’s among the highest-return-on-time investments available before an audit cycle.
Practical Next Steps for Your Validation Program
CSA and GAMP5 2nd edition don’t require re-validating systems that were properly validated under prior CSV approaches. FDA has been clear on this point. But for new systems, major upgrades, and periodic reviews going forward, your program should reflect the current framework.
A workable starting sequence looks like this:
- Review your Validation Master Plan language against CSA principles. Add explicit statements about critical thinking, intended use as the primary scope anchor, and proportional testing effort relative to risk classification.
- Audit your active GAMP5 category assignments for all GxP systems. Flag any Category 2 designations (which no longer exist in the 2nd edition) and any systems that may have evolved in scope since their initial classification.
- Assess data integrity controls for all Category 4 and 5 systems. At minimum: confirm audit trail functionality is enabled and tested, access controls are validated, and backup/recovery procedures have been through a validation exercise.
- Run your next validation project as a CSA pilot. Use an upcoming system upgrade or new implementation as the first project executed under the new framework — build internal experience with proportional scoping before those decisions are examined in an inspection.
Regulatory compliance consulting services that specialize in GxP software systems can accelerate steps 1 through 3 considerably, particularly for organizations with lean quality teams carrying multiple priorities. The objective isn’t to produce a new documentation mountain — it’s to build a validation program that a senior FDA investigator would read and conclude: these people understand what they’re doing.
That’s exactly what CSA is asking for.
Pull your Validation Master Plan today. Search for the phrase “IQ/OQ/PQ” and count how many times it appears without any surrounding language about risk-based scoping, intended use, or critical thinking. That count is a reasonably accurate proxy for how much alignment work lies ahead.
Written by Sam Sammane, Founder & CEO, Aurora TIC | Founder, Qalitex Group. Learn more about our team
Reserve early access to our AI audit tools — built for exactly this kind of validation program assessment. Contact us
Related from our network
- ISO 17025 Accredited Laboratory Testing Services — Qalitex Laboratories provides accredited testing for supplements, cosmetics, and food products with full GMP documentation support.
- GMP-Compliant Lab Testing for Canadian NHP Manufacturers — Androxa supports Health Canada compliance programs including computer system validation requirements for regulated Canadian facilities.
Hulp nodig bij het kiezen van het juiste laboratorium?
Aurora TIC koppelt fabrikanten en merken aan geaccrediteerde testlaboratoria — snel, gratis en afgestemd op uw product.
Offerte aanvragen