Devices & Software

Software Verification & Validation

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

Verification confirms that software was built correctly against its specified requirements ("did we build the thing right?"), while validation confirms the software meets user needs and intended use in its operational environment ("did we build the right thing?"). Both are required across the software lifecycle, at increasing depth with risk.

For device software, verification spans reviews, static analysis, and unit/integration/system testing traced to requirements, while validation confirms the software performs its intended clinical/functional purpose. FDA’s general principles of software validation frame this as a lifecycle activity with documented evidence proportional to risk.

The modern Computer Software Assurance (CSA) emphasis shifts effort toward critical-thinking about intended use and unscripted/exploratory testing for lower-risk features, reserving exhaustive scripted testing for high-risk functions — reducing documentation-for-its-own-sake while strengthening assurance where it matters.

KEY POINTS
  • Verification = built right; validation = built the right thing.
  • Traced to requirements; depth scales with risk.
  • Lifecycle activity, not a one-time test event.
  • CSA focuses rigor on high-risk functions.
REGULATORY BASIS

FDA General Principles of Software Validation (2002); FDA guidance, Computer Software Assurance for Production and Quality System Software; IEC 62304.

Frequently asked questions

What is Software Verification & Validation?

Verification confirms that software was built correctly against its specified requirements ("did we build the thing right?"), while validation confirms the software meets user needs and intended use in its operational environment ("did we build the right thing?"). Both are required across the software lifecycle, at increasing depth with risk.

Which regulations cover Software Verification & Validation?

FDA General Principles of Software Validation (2002); FDA guidance, Computer Software Assurance for Production and Quality System Software; IEC 62304.