Global Community

 View Only

  • 1.  CSA vs CSV - Software Assurance vs Validation

    Posted 20 days ago

    During a recent client interaction a topic of interest came up and I am looking for feedback.  

    Since 2002, software validations (as required by the FDA for software used in or as a medical device or in its production, including document and record control) has required a thorough, document heavy validation for its intended use.  In Feb 2026,  new guidance was published that would lower the burden on medical device manufacturers.  The Software Assurance (instead of software validation) would only focus on parts of the software that were the source of the highest risk to the patient, product quality or compliance to standards (such as ISO13485). 

    My question for the community - has anyone implemented the 2026 Computer Software Assurance (https://www.fda.gov/media/188844/download)  instead of the 2002 Computer Software Validation (https://www.fda.gov/media/73141/download)?  Was the implementation successful? Are there any suggestions?

    Thank you for the feedback.

    Regards,

    Nanda



    ------------------------------
    Nanda Filkin
    QA Scientist
    Arete Biosciences
    ------------------------------


  • 2.  RE: CSA vs CSV - Software Assurance vs Validation

    Posted 16 days ago

    Hi Nanda, I am currently upgrading my software validation processes to reflect impact of the new guidance. I will circle back to you once I have that completed. I have a current client in need of a process assurance/validation that will include software so I will be testing the impact on this project later this month.  



    ------------------------------
    Robert Schmitt
    RA Manager, SIGN Fracture Care International
    RA/QA Consultant, Pearl Technologies QMS Insights
    ------------------------------



  • 3.  RE: CSA vs CSV - Software Assurance vs Validation

    Posted 15 days ago

    Thank you, Robert. I look forward to your response. -Nanda



    ------------------------------
    Nanda Filkin
    QA Scientist
    Arete Biosciences
    ------------------------------



  • 4.  RE: CSA vs CSV - Software Assurance vs Validation

    Posted 13 days ago

    Nanda, in my revised software validation package, following my risk assessment worksheet, I have added the following table due to the new CSA guidance. I find it really helpful and practical in mapping a risk conclusion to the degree of validation rigor.

    Framework for Risk-Based Validation Rigor

    Reference: FDA Guidance – Computer Software Assurance for Production and QMS Software, Feb. 3rd, 2026

    The level of software risk determines the rigor of the assurance activities and the amount of objective evidence necessary to establish confidence that the software is fit for its intended use. This framework provides a consistent methodology for scaling validation activities commensurate with the risk associated with the software's intended use.

    Risk Level

    Validation Confidence Objective

    Validation Rigor

    Low

    Establish confidence that the software performs as intended under normal operating conditions.

    Basic documented testing of intended use, including installation verification and functional testing of normal operating conditions.

    Medium

    Establish confidence that the software consistently performs as intended and that identified risks are effectively controlled.

    Expanded testing to include verification of risk controls, foreseeable user errors, and boundary conditions.

    High

    Establish confidence that the software performs as intended under normal, abnormal, and reasonably foreseeable failure conditions.

    Comprehensive testing as applicable, including challenge testing, verification of data integrity and security, verification of risk controls, and risk-based regression testing following changes.



    ------------------------------
    Robert Schmitt
    ------------------------------



  • 5.  RE: CSA vs CSV - Software Assurance vs Validation

    Posted 12 days ago

    I am not in the device CSV space myself, so treat this as the view from the auditor's chair rather than an implementer's. Under the new assurance approach the part I would watch most is the risk decision itself. When rigour is scaled to risk, that risk rationale becomes the evidence, and if the reasoning is not written down clearly, a lighter round of testing can read as a gap to whoever reviews it later even when the call was perfectly sound.

    So whatever you carry over from the old validation package, I would keep the record that shows why each function landed where it did on risk. Robert's mapping table sounds like exactly that kind of artefact. When I train auditors I tell them a risk based shortcut is only as strong as the documented thinking behind it, and the same holds true here.



    ------------------------------
    Dilawar Laghari
    Auditor, Consultant and Trainer
    AuditWorkshop.com
    ------------------------------