The U.S. Food and Drug Administration (FDA) has issued a comprehensive guidance titled “Computer Software Assurance for Production and Quality System Software” on September 23, 2025, which presents nonbinding recommendations for validating computers and automated data processing systems used in medical device production or within the quality system. Prepared by the Center for Devices and Radiological Health (CDRH) and the Center for Biologics Evaluation and Research (CBER), this document establishes a risk-based framework for Computer Software Assurance (CSA) — one that specifically integrates modern concepts, including cybersecurity requirements, directly into quality assurance activities.

The guidance is intended to supplement the FDA’s existing “General Principles of Software Validation” guidance, though it supersedes the section concerning validation of automated process equipment and quality system software. The core principle of CSA is to use a risk-based approach to maintain confidence that software is fit for its intended use. This approach follows a “least-burdensome” philosophy, meaning the validation effort should be scaled to the identified risk.

Cybersecurity as a component of high process risk

A key step in the CSA Risk Framework is determining whether a software feature, function, or operation poses a high process risk. A failure is deemed high process risk if it results in a quality problem that foreseeably compromises safety, thus posing a medical device risk. Crucially, the guidance identifies specific scenarios where cybersecurity considerations elevate the risk level: software functions that automate surveillance, trending, or tracking of data identified by the manufacturer as essential to device safety and quality are generally considered examples of high process risk. This linkage ensures that systems monitoring or protecting critical device safety attributes — such as cybersecurity defenses — are subjected to the highest level of assurance rigor.

Assurance activities and security testing

When determining the appropriate assurance activities (like testing) necessary to establish confidence in the software, the guidance explicitly recognizes the importance of security testing methods.

  • Experience-based testing — the framework promotes the use of unscripted testing methods, defined as techniques based on using the experience of testers to generate test cases. This can include concepts like test attacks and error taxonomies that specifically target potential problems such as security and performance, closely aligned to how penetration testing is performed.
  • Leveraging existing cybersecurity guidance — the guidance refers manufacturers to the FDA’s “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submission” guidance, encouraging manufacturers to use the cybersecurity testing methods described there when conducting CSA assurance activities.
  • Process controls for exposure reduction — manufacturers should consider leveraging additional process controls, including activities to reduce cybersecurity exposure already incorporated throughout production, which can reduce the assurance effort needed for a given software component.

Integrating cybersecurity into vendor management

Given the widespread adoption of commercial off-the-shelf (COTS) and cloud computing solutions (IaaS, PaaS, and SaaS), the guidance places significant emphasis on evaluating external software vendors, with cybersecurity practices as an integral part of that assessment:

  • Reviewing vendor documentation — manufacturers are recommended to review a vendor’s cybersecurity practices and documentation, citing SOC 2 and ISO 27001 as example accreditations to review, alongside security risk assessments, threat modeling, security design reviews, SBOMs, and testing/risk mitigation evidence.
  • Data integrity and security — vendor assessment should also cover data integrity controls, such as securing data at rest and in transit, maintaining secure time-stamped audit trails, and encryption.
  • Service agreements — for cloud vendors (e.g. SaaS), manufacturers may establish service agreements that specifically address security, data integrity, privacy, availability, change management, and business continuity.

The examples the guidance provides — including a Nonconformance Management System, a Business Intelligence application, and a SaaS Product Life Cycle Management system — consistently show that a thorough vendor assessment includes reviewing the vendor’s cybersecurity documentation and lifecycle management plans as a foundational assurance activity.

By incorporating robust cybersecurity review — from initial risk analysis and vendor assessment to the selection of appropriate testing methods — the FDA’s CSA guidance encourages a holistic approach where device safety and quality are inherently protected against software failure and external threats throughout the entire life cycle.