FDARegulatory IntelligenceGuidanceHIGH INSPECTION RISK
FDA GPSV (2002)

General Principles of Software Validation

FDA's foundational guidance on software validation for the medical-device world, final since 11 January 2002. It sets out general validation principles — software is different from hardware, validation confidence comes from the whole life cycle, not just testing — and typical life-cycle activities and tasks. Still in effect, with one critical exception: Section 6, on validating automated process equipment and quality-system software, was superseded by the 2025 Computer Software Assurance (CSA) guidance.

LAST REVISED
January 2002
PRODUCT AREAS
Devices

What this does not cover

stated in the document's own scope
  • Scoped to the medical-device domain — device software and software used in device production or the quality system; it does not govern computerised systems in pharmaceutical manufacturing, clinical trials, or pharmacovigilance.
  • Section 6 is superseded: validation of automated process equipment and quality-system software now follows the Computer Software Assurance guidance, while Sections 1–5 remain in effect.
  • Guidance, not regulation: the enforceable validation obligations come from the quality-system regulation itself.
SOURCE & PROVENANCE
ISSUING BODY
Food and Drug Administration
JURISDICTION
United States
DOCUMENT ID
FDA GPSV (2002)
Official site — Food and Drug Administration

Always verify against the current published text before relying on it for a submission or inspection.

Overview

"General Principles of Software Validation" is FDA's foundational statement of how software in the medical-device world is validated. Final since 11 January 2002, it explains why software demands a different validation approach from hardware — most software defects are design defects, so confidence must be built across the whole life cycle rather than inspected in at the end — and walks through validation principles and the typical life-cycle activities and tasks: requirements, design, construction, testing, and maintenance. One structural fact now defines how the document is used: its Section 6, which applied the framework to automated process equipment and quality-system software, was superseded by FDA's Computer Software Assurance guidance; the rest of the document remains in effect for device software.

Scope & applicability

Software within the medical-device domain: software used as a component of or as a medical device, and software used in device production or the quality system. It does not govern pharma manufacturing CSV, where EU Annex 11, 21 CFR Part 11, and GAMP 5 remain the anchors.

Legal basis & how it acquires force

A final guidance for industry and FDA staff, published 11 January 2002 (announced in the Federal Register the same day), interpreting the software validation obligations that flow from the device quality-system regulation — 21 CFR Part 820, whose provisions require validation of device software and of software used in production and the quality system. As guidance it describes FDA's thinking rather than creating requirements; the binding obligations sit in the regulation.

Document structure

PartCovers
Section 1 — PurposeWhat the guidance is for and how FDA intends it to be used
Section 2 — ScopeThe software populations addressed and the regulatory context under the quality-system regulation
Section 3 — Context for software validationDefinitions, why software is different from hardware, and how validation relates to verification and testing
Section 4 — Principles of software validationRequirements as the foundation, defect prevention over defect detection, life-cycle coverage, independence of review, and validation after change
Section 5 — Activities and tasksTypical validation tasks across quality planning, requirements, design, construction, testing, and maintenance
Section 6 — Automated process equipment and quality system softwareSuperseded: this application of the framework was replaced by the Computer Software Assurance guidance

Key requirements

  • Validation planned across the software life cycle, with requirements established before verification of them
  • Software requirements that are complete, unambiguous, and testable as the foundation of validation
  • Verification and testing effort commensurate with the software's complexity and safety risk
  • Validation of changes: regression analysis and re-verification when software is modified
  • Independence of review appropriate to risk

Implementation tips

  • Apply Sections 1–5 for device software; for production and quality-system software, work from the CSA guidance instead of Section 6 — citing §6 as current is the classic stale-SOP finding

Revision notes

Final 11 January 2002 and unrevised since; the 2025 CSA guidance superseded Section 6 (automated process equipment and quality system software) while the rest of the document remains in effect.

CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

International alignment

The guidance operationalises the software-validation obligations of the device quality system (21 CFR Part 820, now the QMSR incorporating ISO 13485). For device software engineering it is complemented by IEC 62304's life-cycle processes; for production and quality-system software its Section 6 role passed to the risk-based Computer Software Assurance guidance. It is a medical-device document: pharmaceutical manufacturing CSV rests on EU GMP Annex 11, 21 CFR Part 11, and the GAMP 5 methodology instead.

FDA GPSV (2002): frequently asked questions

Quick answers to common questions about FDA GPSV (2002).

Is the 2002 GPSV guidance still in effect?

Yes, with one exception. The guidance remains FDA's statement of general software-validation principles for device software, but its Section 6 — validation of automated process equipment and quality-system software — was superseded by the Computer Software Assurance guidance. Citing Section 6 as current is citing a replaced text.

What replaced Section 6 of the GPSV?

FDA's Computer Software Assurance guidance for production and quality-system software, which substitutes a risk-based assurance model — effort proportionate to a feature's impact on quality, with unscripted testing where risk is low — for Section 6's validation framing.

Does the GPSV apply to pharmaceutical computer system validation?

No. It is scoped to the medical-device domain under the quality-system regulation. Computerised systems in pharma manufacturing are governed by EU GMP Annex 11 and 21 CFR Part 11, with GAMP 5 as the accepted methodology.

What is the central validation principle of the GPSV?

That software quality comes from the life cycle, not from final testing alone: most software failures trace to design and requirements defects, so the guidance builds validation on documented requirements, defect prevention through the development process, and re-validation whenever the software changes.