CSAComputer Software Assurance
Computer Software Assurance (CSA) is FDA's risk-based approach to confirming that software used in medical device production or quality systems is fit for its intended use. FDA issued the final guidance on 3 February 2026; it contains nonbinding recommendations and is not a certification.
On this page · 6 sections
How does CSA apply to your shop floor?
Pick your industry and scale — Ask V5 rewrites the definition in your context, gives a worked example, and shows what V5 does on day one.
01What CSA means
CSA asks a manufacturer to decide what a piece of software is used for, how badly a failure could affect product quality or patient safety, and then apply assurance activities proportionate to that risk. The aim is confidence that the software works as intended — not a stack of scripted test evidence for every feature.
The guidance is labelled 'Contains Nonbinding Recommendations'. The binding requirement it supports is the validation of software used as part of production or the quality system under 21 CFR Part 820. Nobody is 'CSA certified'; a vendor can only supply evidence a manufacturer may choose to use.
02Scope: which software
| In scope | Out of scope |
|---|---|
| Software used directly in production (e.g. controlling or recording a manufacturing step) | Software that is itself a medical device or part of one |
| Software supporting the quality system (e.g. CAPA, complaint, training, document tools) | General business software with no production or quality use |
Drug manufacturers sometimes borrow the thinking, but this guidance is written for medical device production and QMS software. EU GMP sites still need to meet Annex 11 expectations.
03The four steps the guidance describes
- Identify the intended use of the software, feature or function.
- Decide whether a failure poses high process risk — that is, could foreseeably compromise safety by leading to a quality problem.
- Select assurance activities that fit the risk: scripted testing for high-risk functions; unscripted, exploratory or ad hoc testing and supplier evidence where risk is lower.
- Keep a record that captures intended use, risk determination, what was tested, issues found, the conclusion and who reviewed it.
04Worked example: one system, two risk levels
A device maker configures a production system. The feature that checks a component lot against the bill of materials before assembly could let a wrong component through if it fails — high process risk, so the team writes scripted tests with expected results and boundary cases. The feature that automatically logs CAPA routing notifications is supporting functionality; the team runs unscripted testing, records what was exercised and the result, and relies on the supplier's release testing for the rest.
05Common failure modes and checks
- Calling CSA a standard, certification or exemption from validation.
- Downgrading risk without writing down the intended use that justifies it.
- Using supplier evidence without assessing the supplier or checking your own configuration.
- Producing screenshots of every step for low-risk functions while high-risk functions get thin testing.
06Where V5 fits
V5 is production and quality software, so a device customer would assess it under its own CSA or validation approach. Enterprise may include IQ/OQ documentation and validation support that a customer can evaluate as supplier evidence. Intended-use definition, risk decisions, any PQ, and approval of the validated state stay with the customer.
Frequently asked questions
Q.Is CSA mandatory?+
The guidance is nonbinding. Validating production and quality system software for its intended use is required under Part 820; CSA is FDA's recommended way to approach it.
Q.When was the final CSA guidance issued?+
3 February 2026.
Q.Does CSA replace computer system validation?+
It describes a risk-based way to achieve software assurance; the underlying obligation to show fitness for intended use remains.
Q.Can software be 'CSA certified'?+
No. There is no CSA certification; manufacturers decide what assurance is adequate.
Q.Does CSA cover device software?+
No. Software that is a device or part of a device is outside this guidance.
Primary sources
Further reading
Explore this topic
CSA sits inside 2 overlapping topic clusters in our glossary. Every neighbour is one click away.
Electronic records, signatures, audit trail and ALCOA+ data-integrity principles.
URS-through-PQ lifecycle, GAMP 5 categorisation and CSA's modern alternative.
Want to see how CSA could fit into your own records and workflows? Explore the related V5 pages or talk to our team about what applies to your operation.
