GAMP 5: Software Categories and the Second Edition
GAMP 5 is ISPE's guide to validating computerised systems in regulated life sciences. It is not a regulation and no authority requires it. It is the framework most of the industry uses to satisfy requirements that regulations state without explaining how to meet.
Software categories
The categories set expectations for how much validation effort a system warrants.
- Category 1: infrastructure software. Operating systems, databases, middleware. Recorded and version-controlled; not validated in their own right.
- Category 3: non-configured products. Used as supplied, default configuration. Testing focuses on the intended use.
- Category 4: configured products. Configured to your process without custom code. Most commercial LIMS, MES and EDMS deployments. Testing covers the configuration you actually rely on.
- Category 5: custom applications. Bespoke code. The full lifecycle applies, including design review and code review.
Category 2 was retired. A system is frequently a mix: a Category 4 platform with Category 5 extensions, and the extensions carry the heavier expectation.
What the second edition changed
The 2022 second edition is a meaningful update rather than a refresh.
Critical thinking as a stated expectation. Effort should follow risk and system understanding, not a fixed template. This is the same correction FDA's Computer Software Assurance guidance makes.
Agile and iterative development. The first edition assumed waterfall. The second accommodates iterative delivery, which is how software is actually built now.
Software tools and automation. Explicit acceptance that test automation and tooling can produce validation evidence, rather than requiring manual execution with screenshots.
Supplier leverage. Stronger endorsement of relying on a supplier's own development and testing where their quality system justifies it, assessed through supplier assessment rather than repeated from scratch.
Data integrity by design, aligned with ALCOA expectations.
GAMP 5 and CSA
They agree, and it is worth being clear that they are different kinds of document.
CSA is FDA guidance describing a risk-based approach to assuring software used in medical device production and quality systems. GAMP 5 is an industry guide covering computerised systems in regulated life sciences broadly.
Both push the same direction: less effort on documenting low-risk functionality, more on analysing what could actually go wrong. An organisation applying GAMP 5 second edition properly is already doing what CSA asks.
Neither removes the underlying requirement. The predicate rules and 21 CFR Part 11 are unchanged.
Frequently asked questions
Is GAMP 5 a regulation?
No. It is an ISPE industry guide. No regulator requires it, and most inspectors recognise it.
What are the GAMP software categories?
1 infrastructure, 3 non-configured, 4 configured, 5 custom. Category 2 was retired.
Which category is a configured commercial system?
Category 4. Custom extensions to it are Category 5 and carry the heavier expectation.
What did the second edition change?
Critical thinking, support for agile and iterative development, acceptance of automated testing as evidence, stronger supplier leverage, and data integrity by design.
Is GAMP 5 the same as CSA?
No, but they point the same way. CSA is FDA guidance; GAMP 5 is an industry guide. Applying either properly satisfies much of the other.
Does following GAMP 5 make me Part 11 compliant?
No. It is a means of demonstrating control. The requirements come from the predicate rules and Part 11 itself.