V5 Ultimate
Ultimate
PricingResourcesCompany
Start free trial
HomeGlossaryCSA
Compliance · The complete guide

CSAComputer Software Assurance

In short

Computer Software Assurance (CSA) is FDA's risk-based approach to confirming that software used in medical device production or quality systems is fit for its intended use. FDA issued the final guidance on 3 February 2026; it contains nonbinding recommendations and is not a certification.

Sources checked 2026-10-04 · AI editorial check against the FDA final guidance PDF; no human expert review recorded
On this page
  1. 01What CSA means
  2. 02Scope: which software
  3. 03The four steps the guidance describes
  4. 04Worked example: one system, two risk levels
  5. 05Common failure modes and checks
  6. 06Where V5 fits
On this page · 6 sections
  1. 1What CSA means
  2. 2Scope: which software
  3. 3The four steps the guidance describes
  4. 4Worked example: one system, two risk levels
  5. 5Common failure modes and checks
  6. 6Where V5 fits
AI · Explain it for MY operation

How does CSA apply to your shop floor?

Pick your industry and scale — Ask V5 rewrites the definition in your context, gives a worked example, and shows what V5 does on day one.

Your scale

01What CSA means

CSA asks a manufacturer to decide what a piece of software is used for, how badly a failure could affect product quality or patient safety, and then apply assurance activities proportionate to that risk. The aim is confidence that the software works as intended — not a stack of scripted test evidence for every feature.

The guidance is labelled 'Contains Nonbinding Recommendations'. The binding requirement it supports is the validation of software used as part of production or the quality system under 21 CFR Part 820. Nobody is 'CSA certified'; a vendor can only supply evidence a manufacturer may choose to use.

02Scope: which software

In scopeOut of scope
Software used directly in production (e.g. controlling or recording a manufacturing step)Software that is itself a medical device or part of one
Software supporting the quality system (e.g. CAPA, complaint, training, document tools)General business software with no production or quality use

Drug manufacturers sometimes borrow the thinking, but this guidance is written for medical device production and QMS software. EU GMP sites still need to meet Annex 11 expectations.

03The four steps the guidance describes

  1. Identify the intended use of the software, feature or function.
  2. Decide whether a failure poses high process risk — that is, could foreseeably compromise safety by leading to a quality problem.
  3. Select assurance activities that fit the risk: scripted testing for high-risk functions; unscripted, exploratory or ad hoc testing and supplier evidence where risk is lower.
  4. Keep a record that captures intended use, risk determination, what was tested, issues found, the conclusion and who reviewed it.

04Worked example: one system, two risk levels

A device maker configures a production system. The feature that checks a component lot against the bill of materials before assembly could let a wrong component through if it fails — high process risk, so the team writes scripted tests with expected results and boundary cases. The feature that automatically logs CAPA routing notifications is supporting functionality; the team runs unscripted testing, records what was exercised and the result, and relies on the supplier's release testing for the rest.

The guidance lists CAPA routing and automated logging among examples generally not high process risk, but the intended use in context decides — not a category label.

05Common failure modes and checks

  • Calling CSA a standard, certification or exemption from validation.
  • Downgrading risk without writing down the intended use that justifies it.
  • Using supplier evidence without assessing the supplier or checking your own configuration.
  • Producing screenshots of every step for low-risk functions while high-risk functions get thin testing.

06Where V5 fits

V5 is production and quality software, so a device customer would assess it under its own CSA or validation approach. Enterprise may include IQ/OQ documentation and validation support that a customer can evaluate as supplier evidence. Intended-use definition, risk decisions, any PQ, and approval of the validated state stay with the customer.

Frequently asked questions

Q.Is CSA mandatory?+

The guidance is nonbinding. Validating production and quality system software for its intended use is required under Part 820; CSA is FDA's recommended way to approach it.

Q.When was the final CSA guidance issued?+

3 February 2026.

Q.Does CSA replace computer system validation?+

It describes a risk-based way to achieve software assurance; the underlying obligation to show fitness for intended use remains.

Q.Can software be 'CSA certified'?+

No. There is no CSA certification; manufacturers decide what assurance is adequate.

Q.Does CSA cover device software?+

No. Software that is a device or part of a device is outside this guidance.

Primary sources

  • FDA — Computer Software Assurance for Production and Quality Management System Software (final guidance PDF, 3 Feb 2026)
  • 21 CFR Part 820 as amended (final rule, govinfo)

Further reading

  • Computer system validation
    The broader validation discipline.
  • GAMP 5
    Industry good-practice framework.
  • QMSR
    The device quality rule CSA software supports.
  • 21 CFR Part 11
    Electronic records rules still apply.
  • GAMP 5 and CSA guide
    Planning guide.
Software that covers CSA
V5 Ultimate for CSV / CSA
Requirements traceability, test evidence, change impact and periodic review in one place. Your QA approves the validation; IQ/OQ…
V5 Ultimate (21 CFR Part 11)
V5 Ultimate gives FDA-regulated manufacturers bound e-signatures, an audit trail, authority checks and printed-copy controls. An…
V5 Ultimate eQMS Software
Document control, CAPA, deviations, change control, training and audits in one platform, with a rollout plan agreed with you.
V5 Ultimate QMS for Manufacturing
V5 keeps deviations, corrective actions, controlled documents and training on the same platform as your batches and equipment.…

Explore this topic

CSA sits inside 2 overlapping topic clusters in our glossary. Every neighbour is one click away.

Part 11 & data integrity
24 related entries

Electronic records, signatures, audit trail and ALCOA+ data-integrity principles.

21 CFR Part 11EU Annex 11E-signatureTwo-person e-signatureAudit trailALCOA+Data integrityCSVGAMP 5IQ / OQ / PQURSFSDSDQPPQVMPAnnex 15Traceability MatrixSSO / SAMLRBACSOC 2HIPAAChange controlDocument control
Validation & qualification
16 related entries

URS-through-PQ lifecycle, GAMP 5 categorisation and CSA's modern alternative.

URSFSDSDQIQ / OQ / PQPPQCPVVMPAnnex 15Traceability MatrixGAMP 5CSVICH Q9ICH Q2Design verificationChange control
Talk to us about CSA

Want to see how CSA could fit into your own records and workflows? Explore the related V5 pages or talk to our team about what applies to your operation.

Start free
Back to glossary
Inside V5
  • → Score your compliance gap — then download the validation pack.
  • → Document control — one version in force, every change signed and explained.
  • → QMS — quality records next to the work they concern.
Related terms
  • → CSV
  • → GAMP 5
  • → 21 CFR Part 11
  • → EU Annex 11
  • → E-signature
  • → Two-person e-signature
  • → Audit trail
  • → ALCOA+
  • → Data integrity
  • → IQ / OQ / PQ
  • → URS
  • → FS
  • → DS
  • → DQ
  • → PPQ
  • → VMP

Next step

Try V5 with your own records, or ask a question first. Ask V5 opens with an editable question; nothing is sent until you choose to.

Start your free trial Browse all features
V5 Ultimate
Ultimate

Warehouse, quality and manufacturing software for regulated operations.

ProductIndustriesPricingResourcesSecurity & TrustCompanyLegal centre

© V5 Ultimate