Computer Software Assurance (CSA) Test Strategy
A CSA test strategy that assigns assurance effort to each software feature by its impact on product quality or the quality system, then matches the testing activity — unscripted, ad-hoc, or scripted — to that risk, leveraging supplier evidence to keep documentation least-burdensome. Aligned to the FDA CSA guidance (2025) and GAMP 5 (2nd ed.).
What a template is not
A template is a document baseline to adapt inside your own quality system. SPEQ does not approve, validate, or take responsibility for what you issue from it, and using one is not evidence of compliance.
The strategy that decides, feature by feature, how much assurance a piece of software actually needs — and then commits to the lightest activity that establishes confidence. It goes wrong in two opposite ways: a blanket scripted approach that documents everything and proves little, or an unscripted approach applied to a feature whose failure reaches the patient. The intended use and risk determination behind each choice belongs to your organisation.
What's Inside
How to Use It
The full section structure of this template — every section and sub-section, so you can use it as a baseline for your own site document.
The FDA CSA guidance (2025) shifts effort from exhaustive documentation toward risk-based assurance driven by critical thinking, and GAMP 5 (2nd ed.) supplies the lifecycle and the supplier-leverage model behind it; EU GMP Annex 11 sets the validated-state expectation the strategy has to satisfy. None of them classifies your features, sets your escalation thresholds, or decides which vendor evidence is good enough to rely on. Those determinations are yours, and the matrix here is SPEQ synthesis for recording them consistently.