GAMP 5 second edition (2022) defines four active software categories that determine how much validation a GxP system requires — from configuration documentation only (Category 1) to full software development lifecycle (Category 5). Your category assignment is the starting point for every CSA-based validation programme.
GAMP 5 Categories — Quick Reference
| Category | Type | Validation Required | Risk Level |
|---|---|---|---|
| Category 1 | Infrastructure Software | Configuration documentation + change control only | Low |
| Category 2 | Removed in 2022 | No longer applicable — update any SOPs referencing this | N/A |
| Category 3 | Non-Configured Standard | Functional testing for intended use | Low–Med |
| Category 4 | Configured Standard | Full IQ/OQ/PQ on your configuration | Med–High |
| Category 5 | Custom Software | Full SDLC lifecycle validation | High |
Each Category — What It Means in Practice
OS, databases, and virtualisation platforms used as supplied. No IQ/OQ/PQ needed. Document version, patch level, and config baseline. Every infrastructure change needs a downstream GxP impact assessment.
- Windows Server / Red Hat Linux
- Oracle DB / MS SQL Server
- VMware vSphere / Hyper-V
- Active Directory / Azure AD
Commercial software used exactly as supplied — no custom workflows or fields. Validation focuses on whether it does what you need it to do in your environment, not the vendor's software quality.
- Excel (for read-only reference data)
- Standard PDF readers/viewers
- Fixed-function lab instrument firmware
- Standard network monitoring tools
The most common category in pharma. Validate your configuration — workflows, approval chains, reports — not the base platform. Leverage vendor test evidence; FDA CSA explicitly endorses this approach to minimize re-testing.
- SAP ERP (QM/MM/PM modules)
- Veeva Vault QMS / eTMF
- Waters Empower LIMS
- MasterControl / GoVal VLMS
Built specifically for you — including any custom script that processes GxP data, regardless of code length. Full Software Development Life Cycle (SDLC) required. Avoid Category 5 where a Category 4 commercial alternative exists.
- Custom SCADA / DCS systems
- Bespoke MES / lab automation
- Python/R/VBA scripts on GxP data
- Custom GxP system integrations
How to Classify Your Software — 4 Steps
1. Determine software origin
Was it developed specifically for your organisation? If yes, it is Category 5, regardless of anything else.
2. Check the configuration level
Can it be configured with your workflows, fields, and approval chains? If yes, it is Category 4. If it is used exactly as the vendor ships it, it is Category 3.
3. Identify infrastructure software
Is it an OS, database engine, virtualisation platform, or directory service? If yes, it is Category 1. No IQ/OQ/PQ is needed — just configuration documentation and change control.
4. Apply the correct validation requirement
Category 1: Configuration baseline only. Category 3: Functional testing for intended use. Category 4: Full IQ/OQ/PQ on your configuration. Category 5: Full SDLC documentation.
GAMP 5 + FDA CSA — How They Work Together
GAMP 5 provides the category-based triage. FDA CSA endorses the exact same risk-based approach to validation effort.
| Category | GAMP 5 Requirement | FDA CSA Approach |
|---|---|---|
| Category 1 | Config documentation + change control | No change — same lightweight approach |
| Category 3 | Functional testing for intended use | Leverage vendor testing where available |
| Category 4 | Full IQ/OQ/PQ on your configuration | Use vendor evidence for base platform; focus testing entirely on your configuration |
| Category 5 | Full SDLC lifecycle validation | No vendor evidence to leverage — full testing rigor and unscripted documentation required |
Related Topics
Frequently Asked Questions
What are the GAMP 5 software categories? +
What GAMP category is SAP, a LIMS, or a QMS? +
Does a custom Excel macro or Python script need GAMP 5 validation? +
Why was Category 2 removed from GAMP 5? +
What validation is required for GAMP 5 Category 4 systems? +
How do GAMP 5 categories and FDA CSA work together? +
Stop Guessing Your GAMP 5 Categories
GoVal classifies every system in your portfolio, configures the right validation workflow, and keeps your entire portfolio audit-ready — without inconsistency from manual classification.
