Data Integrity & CSV

GAMP 5 Categories with Examples: 1, 3, 4 and 5

GAMP 5 categories with examples: how to classify software in categories 1, 3, 4 and 5 and scale validation effort accordingly. Plus what changed in the Second Edition (2022) and how GAMP 5 connects to EU Annex 11 and FDA Computer Software Assurance.

G GuideGxP 4 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Illustrazione editoriale GuideGxP a colori sul tema GMP: GAMP 5 e convalida dei sistemi computerizzati.

GAMP 5 categories with examples: if you need to classify a GxP computerized system and scale your validation effort accordingly, this is the practical reference you were looking for. GAMP 5 is a proprietary guide, published by ISPE in English, and there is no free official download. What matters in practice is understanding what the Second Edition (July 2022) actually asks for, how software categories 1, 3, 4 and 5 work, and how the guide fits together with EU GMP Annex 11 and FDA's Computer Software Assurance (CSA). That is exactly what you will find in this article, with an operational table of the categories and the official references to cite in audits.

GAMP 5 categories in context: what the guide is and where to find the official PDF

GAMP 5 ("A Risk-Based Approach to Compliant GxP Computerized Systems") is the international reference guide for validating computerized systems in GxP environments. It is not law: it is a good-practice guide published by ISPE (International Society for Pharmaceutical Engineering) that inspectors know well and that has become the common language between companies, suppliers and authorities.

The official PDF can only be purchased from ISPE (free for members); any "free GAMP 5 PDF" found online is an unauthorized copy or a third-party summary. The binding requirement in Europe remains Annex 11 of EudraLex Volume 4 (and 21 CFR Part 11 in the US for records and signatures): GAMP 5 is the tool you use to demonstrate, in a structured and risk-proportionate way, that you comply.

What changed in the Second Edition (2022)

The Second Edition, published in July 2022, is the first substantial update since 2008. The framework (lifecycle, quality risk management, software categories) remains, but the philosophy changes: less box-ticking documentation, more critical thinking. The main additions:

  • Critical thinking (Appendix M12): the approach must be calibrated on the system's real risk, not on rigid templates and tick-the-box checklists. This is the heart of the revision.
  • Agile methods (Appendix D8): iterative and incremental development is fully compatible with GxP, without artificially superimposing a waterfall model.
  • Software tools (Appendix D9): risk-based management of supporting tools (e.g. ticketing and testing tools) that have no direct GxP impact.
  • Blockchain (D10) and Artificial Intelligence / Machine Learning (D11): first structured guidance for emerging technologies in regulated processes.
  • Cloud and service providers: more leverage on supplier assessment and monitoring, fewer duplicated in-house tests.
  • From CSV to "assurance": the declared goal is not passing the inspection but protecting patient, product and data integrity across the whole lifecycle, fully converging with FDA's CSA approach.

Topics like GAMP 5, Annex 11 and CSA evolve month by month: to receive a practical, no-fluff analysis of GMP news every week, subscribe to The Pragmatic GMP, the free weekly newsletter from GuideGxP.

GAMP 5 software categories: operational table with examples

The categories remain the most used tool in the guide: they classify software by its nature so you can scale validation effort. Since the first edition in 2008, category 2 (firmware) no longer exists; the current categories are 1, 3, 4 and 5.

CategorySoftware typeExamplesTypical approach
1Infrastructure softwareOperating systems, database engines, middlewareVersion recording, environment control
3Non-configured standard productInstruments with fixed software, COTS applications used as isVerification of user requirements, reduced risk-based testing
4Configured productLIMS, MES, ERP, eQMS, CDS configured to the processSupplier assessment, testing of configuration and critical workflows
5Custom (bespoke) softwareCustom-built applications or modules, critical macros and scriptsFull lifecycle: specifications, code review, extensive testing

Watch out for the most common audit mistake: classifying as category 3 a system that is actually configured (category 4), or forgetting that a single Excel macro used for release decisions is, for all purposes, category 5.

GAMP 5, Annex 11 and FDA CSA: how they fit together

To use GAMP 5 defensibly you need clarity on the regulatory framework:

  1. Annex 11 (EU GMP) is the binding European requirement for computerized systems; a draft revision was published for public consultation in July 2025 and will make requirements far more detailed (audit trail review, security, cloud suppliers).
  2. FDA CSA: in September 2025 FDA finalized the guidance "Computer Software Assurance for Production and Quality System Software", which supersedes Section 6 of the General Principles of Software Validation (2002) and promotes risk-proportionate assurance activities, including unscripted testing.
  3. GAMP 5 Second Edition is the bridge between the two worlds: its emphasis on critical thinking and risk is deliberately aligned with CSA, and its documentation structure covers European expectations.

In practice: a company applying GAMP 5 with judgment is already well positioned both for an EMA/national inspection and for an FDA one.

How to apply GAMP 5 in your company: 5 steps

  1. Inventory and GxP assessment: list all systems and establish which ones have GxP impact. Whatever is not GxP leaves the validation scope.
  2. Category and risk: assign the software category and assess impact on patient, product and data (ICH Q9 as the methodological reference).
  3. Proportionate strategy: define in the validation plan how much you rely on the supplier (audits, test documentation) and what you verify internally.
  4. Targeted testing: focus scripted testing on critical functions; use exploratory and unscripted testing where risk is low, documenting the rationale.
  5. Maintaining the validated state: change control, periodic review and audit trail review must cover the entire lifecycle, cloud updates included.

GuideGxP recommendation

Do not chase a translated or "free" GAMP 5 PDF: invest instead in building a validation rationale an inspector can follow line by line. The document that makes the difference in an audit is not the guide itself, but your system-category-risk-strategy matrix, kept up to date and consistent with your SOPs. Start from the highest-impact systems (those generating data for batch release) and use critical thinking to streamline the rest: less paper on trivial systems, more depth where the risk is real.

If you are validating SaaS or cloud systems under GAMP 5 and Annex 11, the GuideGxP guide Operational Guide to Computer System Validation (CSV) in the GxP Environment gives you method, examples and ready-to-use templates to walk into an audit with a defensible dossier.

Official sources

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →