What is the difference between CSV and CSA?
Computer System Validation (CSV) is the traditional, documentation-heavy way to prove a system works for its intended use. Computer Software Assurance (CSA) is FDA's risk-based approach that concentrates assurance on software failures that pose high process risk and allows unscripted testing and supplier evidence elsewhere. FDA finalized its CSA guidance for medical device production and quality-system software in September 2025 and updated it February 2026.
What CSV is
CSV grew out of the validation requirement in 21 CFR 11.10(a) and FDA's General Principles of Software Validation guidance. In practice many companies applied it uniformly: written requirements, scripted test protocols with screenshots, and signed reports for every function, whatever its risk.
FDA never required that uniformity. Its 2018 drug data integrity guidance, for example, says the extent of validation should be commensurate with the risk the automated system poses.
What CSA is
FDA published the CSA draft on September 13, 2022, finalized it on September 24, 2025, and issued a revised version on February 3, 2026 to align with the Quality Management System Regulation, which took effect February 2, 2026 and incorporates ISO 13485:2016 by reference. The guidance supersedes Section 6 of General Principles of Software Validation.
The method: identify reasonably foreseeable software failures, decide whether each poses a high process risk, and select assurance activities commensurate with that risk. FDA describes scripted testing alongside unscripted approaches such as scenario and experience-based testing, and lets you leverage validation work by developers, suppliers and cloud service providers, plus continuous monitoring.
Side by side
- Focus: CSV tends to test everything equally; CSA puts effort where a failure would compromise product quality or records.
- Testing: CSV relies on scripted protocols; CSA mixes scripted and unscripted testing by risk.
- Suppliers: CSA explicitly allows leveraging vendor and cloud provider assurance.
- Records: both still require evidence of the risk determination and the assurance performed.
Who CSA applies to
The guidance comes from CDRH and CBER and addresses software used in medical device production or the quality management system. It does not replace drug CGMP or Part 11 obligations. Drug and biologic manufacturers can still apply risk-based thinking under the data integrity guidance, but should confirm their approach with their quality unit rather than citing the device guidance as their authority.
One useful example in the guidance: for cloud storage holding quality records, FDA recommends focusing assurance on record integrity and the applicable Part 11 requirements.
Moving from CSV to CSA
Start with an inventory of systems and their intended uses, then classify each feature by whether a failure would pose a high process risk. Update your validation SOP so the level of testing follows that classification, assess key suppliers so you can rely on their evidence, and pilot the approach on one system before applying it to the rest. Keep the risk rationale with each system's records.
Common follow-up questions
Does CSA replace 21 CFR Part 11?
No. CSA is guidance on how much assurance work a system needs. Part 11 remains a regulation, and systems holding required electronic records still need access controls, audit trails and compliant electronic signatures.
Can pharma and biotech companies use CSA?
The CSA guidance is scoped to medical device production and quality-system software. Drug CGMP guidance already ties validation extent to risk, so similar principles apply, but your quality unit should document the rationale under drug regulations.
Does CSA mean less documentation?
Less documentation for low-risk functions, not none. You still need a record of intended use, the risk determination, the assurance activities performed and their results, so an inspector can see why the effort matched the risk.
LAN Service Group provides GxP-regulated IT for life-science companies, including system inventories, risk classification and the IT controls and records that support a risk-based validation or assurance program.
Talk to LAN Service Group (888) 281-7243Sources
- FDA guidance: Computer Software Assurance for Production and Quality Management System Software (Feb 2026)
- Federal Register: CSA final guidance notice of availability (Sep 24, 2025)
- Federal Register: Medical Devices; Quality System Regulation Amendments (QMSR final rule)
- FDA guidance: Data Integrity and Compliance With Drug CGMP, Questions and Answers (Dec 2018)