Our services for computer system validation (CSV)
Many providers validate software only. We deliver the complete CSV system: procurement consulting, infrastructure, vendor validation, bespoke development for interfaces and equipment qualification – coordinated through our six service areas and, where needed, an external Validation Manager.
Phase 1 · before purchase
Vendor selection & procurement consulting
Before you invest, we structure requirements, shortlists and evaluation criteria. We compare vendors on GxP suitability, supplier documentation and integration effort – so CSV does not start on the wrong system.
Outcome: robust procurement recommendation with documented vendor assessment
- URS draft and requirements workshops with business units and QA
- Vendor shortlist, demo and reference review
- Supplier qualification and audit preparation
Phase 2 · before purchase
Data integrity assessment & GAP analysis
We assess the planned system against Annex 11, Part 11 and ALCOA+ before the contract is signed. Open points are expressed as concrete implementation measures for configuration, process or interface.
Outcome: risk-based investment decision instead of costly rework during rollout
- DI GAP analysis against regulatory requirements
- Assessment of audit trail, signatures and access concept
- Recommendations for configuration, process or customisation
Phase 3 · infrastructure
Servers, network & three environments
We set up the platform for your CSV programme: physical or virtualised, with clearly separated environments EVAL (evaluation), VAL (validation) and PROD (production). Backup, monitoring, hardening and access concepts are part of the deliverable.
Outcome: clearly separated, documented environments for risk-free qualification and controlled go-live
- Server and network design including firewall and backup
- EVAL · VAL · PROD with documented separation
- User, role and permission concept
Phase 4 · vendor software
CSV per GAMP 5 Category 4
We validate LIMS, CDS, ERP, MES and laboratory IT on a risk-based basis: using supplier evidence, closing gaps, and verifying configuration and customer-specific workflows. IQ, OQ and PQ are executed in VAL and released in PROD.
Outcome: audit-ready validation package with traceability through to the validation report
- Validation plan, risk analysis and traceability matrix
- GAP analysis against URS and supplier documentation
- IQ/OQ/PQ, deviation management and validation report
Phase 5 · interfaces
Develop interfaces & validate per GAMP 5 Category 5
When LIMS, ERP, CDS or instruments need to exchange data, we develop the interface and validate it with full SDLC evidence. Bespoke developments and major customisations are covered on the page Software Validation GAMP 5 Category 5.
Outcome: production-ready integration with robust specification and test evidence
- URS, FS, DS and risk-based test strategy
- Development, code review and automated tests
- IQ/OQ/PQ of the interface in the system context
Phase 6 · equipment
Qualify & connect instruments
Chromatographs, balances, spectrometers or plate readers are part of the computer system. We qualify the equipment for operation, verify data transfer and close the evidence chain through to archiving.
Outcome: end-to-end qualification from instrument through interface to archive
- IQ/OQ of instruments and peripherals
- Verification of data integrity along the transfer chain
- Alignment with vendor CSV and overall validation plan
Phase 7 · release
Release, operation & Validation Manager
The validation report consolidates all evidence. After QA release we support change control, periodic review and re-validation. On request, an external Validation Manager takes overall control across facilities, processes and CSV.
Outcome: released system with a sustainable operating and change model
- Validation report and formal system release
- Change control and impact assessment
- Periodic review and inspection preparation
What sets us apart: you do not need to coordinate vendor, IT, validation, development and equipment qualification separately. We connect all building blocks into a turnkey CSV programme – from the first requirement through to audit-ready operation.
Planning a CSV project – clarify scope and start?
Book an intro callCSV guide
Where is your CSV project?
Choose your starting point. You receive the right entry point – including references and a direct route to contact.
Choose a vendor before you commit
We support requirements, vendor assessment and DI assessment – so budget and timeline stay realistic and CSV starts on the right system.
Rollout with EVAL, VAL and PROD
Set up servers, separate environments, validate vendor software per GAMP 5 Cat. 4 and release – from a single source, with one validation plan.
LIMS, CDS and connected instruments
From LabWare through Chromeleon to LabX: vendor CSV, equipment qualification and interfaces in one evidence chain – typically our strongest project profile.
ERP and MES validation
GAP analysis, test scope and release for ERP and MES systems in regulated sites – including interfaces to production and quality.
Risk-based CSA approach
Where supplier evidence is strong, CSA reduces redundant documentation effort at the same test depth – without regulatory compromise.
CSV from a single source means no ping-pong between IT service provider, software house and validation consultant. One team takes on vendor selection, infrastructure, vendor validation, interface development and equipment qualification – aligned to your validation plan.
Reference: SYSPRO CSV at a pharmaceutical manufacturer: from 1,200 planned to 500 delivered hours. Read the case story
Three environments: EVAL, VAL and PROD
Professional CSV separates evaluation, qualification and production operation physically or logically. You test in VAL without putting PROD at risk – and go live only after release.
Evaluation
Vendor demo, prototype and early configuration. No GxP data, no production release – but documented findings for URS and procurement.
Validation
IQ, OQ and PQ run here. Deviations are closed, test protocols signed – the environment mirrors PROD but remains separate from live operation.
Production operation
Released system for GxP-relevant data. Change control, backup and monitoring apply – every change is assessed and tracked.
Six service areas – one CSV programme
CSV projects are interface projects between QA, business units, IT and vendors. That is why we bring all six cube one GmbH service areas into one programme where needed – without handover gaps.
Data integrity consulting
Pre-purchase DI assessment, ALCOA+ checks and gap analyses across the data lifecycle.
View data integrity ›Equipment and facility qualification
Qualification of connected instruments and peripherals as part of the overall system.
View equipment qualification ›Software validation (CSV)
Vendor software per GAMP 5 Cat. 3 and 4 – the core of this page.
View services above ›IT administration
Servers, network, EVAL/VAL/PROD, backup and operation for validated systems.
View IT administration ›Project management
Schedules, vendors, milestones and reporting – from kick-off through go-live.
View project management ›Software development
Interfaces, data converters and extensions per GAMP 5 Cat. 5.
View software development ›Our approach in GxP projects: from planning through release – each step delivers evidence you can present in QA review and audit. View GxP consulting in five steps
What is computer system validation (CSV)?
CSV is the documented process that demonstrates a computerised system – software and associated hardware – consistently and reliably performs its intended functions while meeting GxP requirements. Data integrity and traceability are central requirements.
This page covers purchased systems in GAMP Category 3 and 4 and the overall programme around them: infrastructure, interfaces (Cat. 5) and equipment. Evidence draws on supplier documentation, GAP analysis against your requirements and qualification in the target environment.
Regulatory foundations: EU GMP Annex 11, FDA 21 CFR Part 11 and GAMP 5. You will also find IT security requirements in the Regulatory Expertise Center.
A complete CSV programme protects against audit findings, safeguards data integrity and shortens time to compliance – because procurement, IT, validation and equipment are delivered in alignment, not in sequence.
GAMP 5: Category 3 and 4 on this page
| Category | Description | Examples | Our contribution |
|---|---|---|---|
| Cat. 1 | Infrastructure | Operating system, database, virtualisation | IT administration & environment separation |
| Cat. 3 | Non-configurable COTS | Fixed instrument software | Evidence of intended use |
| Cat. 4 | Configurable COTS | LIMS, CDS, ERP, MES, LabX | Vendor CSV with IQ/OQ/PQ |
| Cat. 5 | Bespoke / individually developed | Interfaces, code-level customisation | Dedicated page GAMP 5 Cat. 5 |
Self-assessment: where does your system stand?
Both frameworks ask their own questions of a computerised system. Use eight questions each to see where your system stands today, before we go into the actual system context together.
Annex 11 Check
Start with our public Annex 11 Check: eight questions identify initial action areas covering risk management, validation, suppliers, audit trails and access controls.
Start the Annex 11 Check21 CFR Part 11 Check
For the FDA frame, the public 21 CFR Part 11 Check is available: eight questions on validation, audit trails, electronic signatures and operational checks.
Start the Part 11 CheckScope: which approach fits your system?
Not every system is validated the same way. What matters is origin, configuration depth and GxP risk. Bespoke developments and interfaces in source code are validated per GAMP 5 Category 5 on the page Software Validation GAMP 5 Category 5.
The CSV process using the V-model
Every specification on the left is verified by a qualification stage on the right. For purchased systems (GAMP Cat. 3/4) we use supplier evidence where it is robust – and close gaps with our own testing in VAL.
Audit takeaway: on the left you define what the system must deliver – on the right you prove it in VAL. The validation report closes the chain and authorises PROD operation.
After release: securing operation
Release is not an endpoint. Two pillars keep the system audit-ready long term – data integrity in daily use and controlled change.
Data integrity & audit trail
- Tamper-evident audit trail for security-relevant actions
- Roles, signatures and access per Part 11 / Annex 11
- ALCOA+ compliance in ongoing operation
Change control & periodic review
- Impact assessment for software, configuration and infrastructure
- Re-validation and re-test only where needed – risk-based
- Periodic review and inspection preparation