Computer Software Assurance, or CSA, is the FDA’s risk-basedapproach for establishing confidence in software used as part of medical-deviceproduction and quality management systems.
The current FDA guidance, issued in February 2026, describeshow manufacturers can identify software’s intended use, evaluate process risk,select appropriate assurance activities, and create sufficient records. Theguidance is specifically directed at medical-device production and qualitymanagement system software. Its principles may also inform broader GxPcomputerized-system assurance approaches when applied within the relevantregulatory framework.
CSA builds on established risk-based validation principles.It emphasizes critical thinking and encourages organizations to selectassurance activities that are proportionate to the potential impact of softwarefailure.
Functions associated with higher process risk generallyrequire greater rigor. Functions that are not high process risk may beevaluated using methods such as scenario testing, exploratory testing, or otherappropriately documented assurance activities. The selected approach should bejustified based on intended use, process risk, available knowledge, and thenature of the function.
Supplier documentation and evidence may be leveraged whenthey are relevant, reliable, and sufficient. Supplier evidence does notautomatically demonstrate that a configured system fulfills the regulatedcompany’s intended use. CSA is not a lower assurance standard. It directseffort toward activities that establish confidence in the software whilediscouraging unnecessary documentation.
Frequently Asked Questions
Is CSA mandatory?
CSA is FDA guidance rather than a separate regulation.Applicable assurance and validation obligations arise from the relevant qualitysystem requirements, predicate rules, and the intended use of the software.
Does CSA mean less documentation?
CSA can reduce low-value documentation, but it does not remove the need for objective evidence. Records should show what was assessed, which assurance activities were performed, the results, issues identified, and the basis for the conclusion.
What is unscripted testing under CSA?
Unscripted testing is performed without a fully prescribed,step-by-step test script. It should still generate sufficient records to showwhat was tested, who performed the testing, when it was performed, the results,and any issues identified.
How should a company start moving from CSV to CSA?
Begin by reviewing the risk-assessment andsoftware-assurance methodology. Apply the revised approach to a defined system,project, or software change, then use the lessons learned to update procedures,templates, training, and governance before broader adoption.