What is computer software assurance?
Teams spend months screenshotting every field of a spreadsheet tool. Then the function that touches product gets the same effort as the one that formats a report.
Computer software assurance
CSA
Computer software assurance (CSA) is a risk-based approach, set out in FDA guidance, for software used in medical device production and quality systems. Test hardest where failure could reach product quality or patient safety. Lighter evidence is accepted elsewhere.
FDA states the aim plainly. The guidance describes computer software assurance as a risk-based approach to establish confidence in the automation used for production or quality management systems. It also identifies where more rigour may be appropriate.
The current document is titled Computer Software Assurance for Production and Quality Management System Software. FDA issued it on 2 February 2026. It replaces the version issued on 24 September 2025.
Note the scope. CSA covers software used to make the product or run the quality system. Software inside the device falls under other guidance. Mixing up the two is a common early mistake.
CSV asked for evidence everywhere; CSA asks where it counts
Older computer system validation, or CSV, grew into a paperwork exercise. Teams wrote scripted test cases with screenshots for every function, and the stack of paper became the deliverable. Effort went where writing was easy rather than where risk was high.
CSA starts from a different question. What does this software do, and what happens if it fails? Where failure would not foreseeably harm safety, the guidance accepts lighter evidence. If it would, the bar goes up.
The guidance names methods that CSV culture treated as unserious. It defines unscripted testing as dynamic testing in which the tester's actions are not prescribed by written instructions in a test case. Scenario testing, also called ad-hoc testing, is named as part of it.
- 01Intended use comes first. You cannot grade risk before you write down what the function is for.
- 02A supplier's own testing counts as evidence you build on, rather than work to repeat.
- 03Records still matter: what was tested, what failed, who tested it, and the date.
- Intended useWhat this function is for.
- RiskCould failure reach a patient?
- MethodScripted or unscripted testing.
- EvidenceEnough to show it works.
- ChangeRe-ask all of the above.
Skip the first station and every later one becomes a guess dressed as a procedure.
Systems built to be checked after the fact
Common questions
01What is the difference between CSA and CSV?
CSA and CSV chase the same obligation by different routes. CSV practice defaulted to scripted testing and heavy paperwork on every function. CSA sizes the evidence to the risk of that one function, and accepts unscripted testing where the guidance allows it. Validation requirements did not go away. How you meet them changed.
02Does CSA replace validation requirements in the regulations?
No. CSA is guidance on how to meet existing duties, not a repeal of them. FDA guidance documents say they contain nonbinding recommendations. The quality system rules are still what you are held to.
03Which software does CSA cover?
CSA covers software used in medical device production and in the quality management system. That takes in automation on the line and the systems running quality processes. Software that is part of the finished device, or that is the device, falls under different guidance.
04Do you help with CSA?
We build the software and the audit trail that a CSA approach depends on. In practice, every action is logged with who did it and when. Roles are enforced rather than assumed. Any result traces back to the evidence behind it. Your quality team makes the risk determinations, and we make sure the system can evidence them.

