
GAMP 5 Categories Guide
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
ExploreThe industry framework regulators and QA teams use to scope computerized system validation.
GAMP 5 is the shared vocabulary of computerized system validation — when a vendor says 'Category 4' or an auditor asks for your lifecycle approach, this is the framework behind the words.

GAMP 5 — A Risk-Based Approach to Compliant GxP Computerized Systems — is the industry guide published by ISPE (International Society for Pharmaceutical Engineering) that defines how regulated companies specify, validate, and maintain computerized systems. The current version is the second edition, published in July 2022; the first edition dates to 2008, and the GAMP framework itself goes back to the early 1990s.
Its core ideas: scale validation effort to risk, complexity, and novelty; leverage supplier activities and documentation instead of repeating them; apply critical thinking rather than templated test volume; and manage systems across their whole lifecycle — concept, project, operation, retirement — not just at go-live. The guide is supported by a family of GAMP Good Practice Guides on topics like data integrity, testing, and IT infrastructure.
Its best-known tool is the software category classification: Category 1 (infrastructure software), Category 3 (non-configured products), Category 4 (configured products), and Category 5 (custom applications) — Category 2 was retired with the first edition's hardware focus. The category signals how much specification and verification work the regulated company owes on top of what the supplier already did. A configured multi-tenant eQMS is typically assessed as Category 4.
GAMP 5 is not a regulation — no authority enforces it directly. It is the industry's consensus method for meeting the validation expectations that ARE law (21 CFR Part 11 §11.10(a), EU GMP Annex 11). Auditors use its vocabulary because everyone else does; a vendor claiming to be 'GAMP certified' is waving a flag that does not exist.
When a quality team qualifies an eQMS, LIMS, or MES supplier, the assessment is almost always GAMP-shaped: what category is the system, what does the supplier's quality system cover, which lifecycle deliverables exist (URS, risk assessment, configuration specification, test evidence, traceability), and what residual work belongs to the regulated company. The framework gives both sides a shared map of who owes which evidence — which is why supplier assessments, audit agendas, and validation plans all speak its language.
The second edition (2022) matters because it modernized the framework for how software is actually built and run now: it embraces agile and incremental delivery, cloud services and SaaS, automated testing and tool-supported traceability, and gives explicit attention to data integrity, IT service management, and emerging tools. It aligns with the critical-thinking direction FDA later formalized in its Computer Software Assurance guidance. Validation positions written against the 2008 first edition tend to over-document and under-think — exactly what the second edition argues against.
For buyers, GAMP 5 fluency is also a vendor-quality signal: a supplier who can state their category honestly, show their lifecycle deliverables, and explain which V-model activities they perform versus which remain with the customer has done this before. One who answers "we are fully GAMP compliant" has not understood the question.
GAMP 5 is the how behind several regulatory whats:
The practical failure mode with GAMP 5 is treating it as a template library: generating maximum documentation for every system regardless of risk. The framework itself says the opposite — a Category 4 configured product with a qualified supplier should lean on supplier evidence, focus testing on the regulated company's configuration and intended use, and document decisions rather than boilerplate.
A workable pattern for an eQMS or similar Category 4 system: classify honestly (configured product — unless you have commissioned custom code, which moves those parts to Category 5); assess the supplier once and deeply — their quality system, lifecycle deliverables, testing and release discipline, change management — and record what you will leverage; write a URS that reflects your intended use, not the vendor's feature list; risk-assess per requirement so high-impact functions (e-signatures, audit trail, record lifecycle) get scripted depth and low-impact configuration gets lighter verification; and keep the lifecycle alive — supplier releases, configuration changes, and periodic review all feed back into the validated state.
The second edition's additions matter most in operation: for SaaS, the supplier releases on their cadence, so your change-evaluation and regression-evidence process is the real control; tool-supported traceability (requirements-to-test linkage in systems rather than spreadsheets) is explicitly endorsed; and critical thinking is expected to show up as documented rationale — why this depth, why this sample, why this residual risk is acceptable.
Whether you are the regulated company or assessing a vendor, these are the concrete artifacts a GAMP-shaped review looks for:
The most consequential classification call is Category 4 versus 5. Configuration uses the product's intended mechanisms (settings, workflows, fields); customization is new code. Custom scripts, bespoke integrations, and modified vendor code are Category 5 work hiding inside a Category 4 system — and inspectors know to ask.
Complere is assessed as a GAMP 5 Category 4 configured product, and the validation pack exists so that a GAMP-shaped supplier assessment finds what it is looking for without a negotiation.
The lifecycle deliverables ship per module, generated against the customer tenant: Validation Master Plan, User Requirements Specification, Risk Assessment with per-requirement tiers, Traceability Matrix linking requirements to risk to test cases, IQ/OQ/PQ protocols, a 21 CFR Part 11 checklist, and an Audit Trail Specification. Validation depth is scoped per requirement risk in line with FDA's CSA guidance — high-risk requirements carry scripted test depth, lower-risk configuration carries lighter qualification, and the rationale is recorded the way GAMP's critical-thinking principle expects.
The leverage model is explicit: Complere performs and documents the product-level lifecycle work — requirements, testing, release discipline, change management — and the customer's residual work concentrates on intended use: their configuration, their workflows, their PQ in their tenant. On releases that affect validated functionality, release notes map changes to affected requirements and only the affected evidence regenerates, which is the SaaS lifecycle behaviour the second edition asks suppliers to support.
What stays with your team is the regulated company's share of the framework: your system inventory and classification decision, your supplier assessment of us (we expect it — the artifacts above are its inputs), your intended-use URS choices, and your periodic review. The category model is explained further in the GAMP 5 categories guide, the methodology in the validation approach, and the artifact list on the validation pack page.
Common questions about GAMP 5 sourced from regulatory references and inspection patterns.
No — GAMP 5 is industry guidance from ISPE, not a regulation. What is mandatory is validation itself (21 CFR Part 11 §11.10(a), EU GMP Annex 11). GAMP 5 is the consensus method most regulated companies and auditors use to meet those requirements, which is why supplier assessments speak its vocabulary.
A configured commercial eQMS is typically Category 4 (configured products): the supplier builds and tests the product, and the regulated company specifies, configures, and verifies its own intended use on top. Custom-developed extensions would be assessed as Category 5.
The 2022 second edition modernized the framework for current software practice: agile and incremental delivery, cloud and SaaS, automated testing and tool-based traceability, stronger emphasis on critical thinking over document volume, and closer alignment with the risk-based direction FDA formalized in its Computer Software Assurance guidance.
They point the same way. GAMP 5 (second edition) and FDA's CSA Final Guidance (February 3, 2026) both argue for scaling assurance effort to risk and intended use rather than generating uniform documentation. GAMP 5 covers the full lifecycle method; CSA is FDA's position on assurance for production and quality system software.
Category 4 is configured products - you use the product's intended configuration mechanisms (settings, workflows, fields, roles). Category 5 is custom applications - new code written for you. Custom scripts, bespoke integrations, and modified vendor code are Category 5 work that often hides inside an otherwise Category 4 system, and they carry more validation responsibility. Classify honestly: inspectors know to ask where the custom code is.
Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

Explore this topic in more depth to build a complete picture of your quality and compliance operations.
Explore
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
Explore
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
ExploreWalk through the modules and workflows that address this area inside a controlled, validation-ready quality system.