Computer Software Assurance (CSA)
Computer Software Assurance is the FDA’s risk-based approach for establishing and maintaining confidence that software is fit for its Intended Use – in the guidance’s own wording, the Intended Use of the software as part of production or the quality management system, explicitly distinguished from the intended use of the medical device itself. The effort follows the Least Burdensome principle: no more validation burden than needed to address the risk. (QFINITY working convention: we place the Intended Use at the process level – the system is fit for purpose for it; see the entries Intended Use and Fit for Purpose.) For high process risk, more rigor comes into consideration – such as scripted or hybrid testing; for lower process risk, unscripted methods such as scenario testing, error guessing, or exploratory testing are often sufficient. The guidance makes this mapping explicitly non-exclusive: chosen is whatever demonstrates fitness most effectively – unscripted testing can be the better choice even at high risk, and the level of detail and evidence per test case follows the risk. The basis for the CSA approach is a thorough understanding of the process and the function, and of the associated risks to the patient or the product. The CSA approach can be applied across the entire lifecycle of computerized systems, including software development, as long as the risks are understood and documented.
The CSA principles should be applied to all computer systems involved in the manufacture of a medical device or in the associated quality systems (e.g., ERP, LIMS, etc.). Software that is itself part of a medical device is expressly excluded.
The key steps of the CSA approach are:
- Defining the Intended Use (at the system and/or function level)
- Defining the risk-based approach to assuring software quality
- Determining the appropriate testing activities
In all of these steps, the CSA approach underscores the need for Critical Thinking in developing the lifecycle strategy of a computerized system, particularly regarding the scope and depth of the associated testing and documentation activities.
Formally, the guidance applies to software in production and the quality management system of medical device manufacturers – the validation obligation follows from ISO 13485 as incorporated into Part 820 (QMSR). Carrying it over to pharmaceutical GxP systems is a matter of methodology, not of scope.


