Operations Excellence

What Are CQAs? Understanding the FDA’s Critical Quality Attributes

9 min read
Share

The FDA defines a critical quality attribute, or CQA, as a physical, chemical, biological, or microbiological property or characteristic that should be within an appropriate limit, range, or distribution to ensure the desired product quality. For biologics manufacturers, and particularly for cell and gene therapy developers, identifying and controlling the right CQAs is one of...

The FDA defines a critical quality attribute, or CQA, as a physical, chemical, biological, or microbiological property or characteristic that should be within an appropriate limit, range, or distribution to ensure the desired product quality. For biologics manufacturers, and particularly for cell and gene therapy developers, identifying and controlling the right CQAs is one of the most consequential — and least standardized — challenges in the entire development process. The CGT development pathway exists specifically to document and establish these CQAs for regulators, aligning them with how a therapeutic actually progresses from early proof-of-concept work through verification, optimization, and qualification.

How Do CQA Expectations Change Across Development Stages?

The FDA advises that acceptable limits for a given CQA may be broader during a product’s early development than they are at the late stage, reflecting the reality that manufacturers are still actively gathering information about the product’s behavior and the relationship between process parameters and quality outcomes. This means CQA limits are not fixed at the outset of development — they tighten over time as a manufacturer accumulates more process and product knowledge, eventually converging on the well-defined specifications expected for a commercial product. Despite this general principle, standardized guidelines for which specific CQAs must be submitted with each new cell and gene therapy do not yet exist, which leaves considerable judgment in the hands of individual development teams and their regulatory advisors regarding which attributes to prioritize at each stage.

What Are the Common Categories of CQAs?

Despite the absence of a single standardized list, common CQA categories have emerged across cell and gene therapy development: safety, identity, sterility, purity, and potency. Regulators expect that each of these categories will have associated assays demonstrating the therapy’s performance and safety, even where the specific assay methodology may differ across product types and modalities.

Critically, none of these five categories stands alone — each is interdependent with the others in ways that shape how testing programs are actually designed. Confirming identity, for instance, can surface an impurity that must be separately characterized, which in turn affects the product’s overall purity profile; that same characterization process may also reveal unwanted microorganisms that bear directly on both sterility and the broader safety profile. A 2024 Phacilitate Pharma industry survey of cell and gene therapy manufacturers, examining which CQAs are actually measured today versus which are considered essential for regulatory submission, found a meaningful gap specifically around potency: while the majority of manufacturers already measure immunogenicity and recognize its importance, a considerably larger share of respondents recognized potency as essential than were currently measuring it — a real, documented gap between what the field knows it should be testing for and what it has actually built the assay infrastructure to test.

Safety functions as an underlying parameter relevant to every other CQA category. It is defined in 21 CFR 600.3 as relative freedom from a harmful effect to persons affected, directly or indirectly, by a product when prudently administered, taking into consideration the condition of the recipient and the character of the product in relation to the recipient’s condition.

How Do Identity and Purity Differ as CQA Categories?

Identity testing exists to distinguish one product from another produced at the same facility, using physical, chemical, cultural, and in vitro or in vivo immunological testing methods. Developers typically use a quantitative test — a phenotype or biochemical assay — to confirm the number of target cells present in the product. During this same process, when non-target cells or other impurities are identified, researchers characterize them further to understand their role, function, and potential impact on product safety or efficacy.

Autologous products introduce a distinctive identity challenge that doesn’t have a clean equivalent elsewhere in biologics manufacturing: because each lot is manufactured from a single patient’s own cells, different lots cannot be differentiated from one another using standard product-identity testing the way different lots of a standardized product could be. This makes dedicated identity tracking protocols — confirming that a given manufactured product is correctly matched to the specific patient it came from — a critical safeguard against mix-ups between patient-specific products, a risk category that simply doesn’t exist for therapies manufactured at standardized scale from a common source material.

For the purposes of distinguishing identity from purity specifically: identity strictly refers to characterization of the target cell population itself, while purity refers to the presence and characterization of non-target cells and other non-biological impurities — including endotoxins, residual solvents, antibiotics, animal-derived products, and unintended cell types such as off-target lymphocyte subsets. Proof of product purity requires either validating that these impurities have been removed during manufacturing, or final product testing confirming that residual levels fall within acceptable limits. Because both identity and purity testing are derived from closely related testing processes, and because non-target material identified during an identity assay often feeds directly into purity characterization, the two CQAs are frequently discussed together even though they answer distinct regulatory questions.

What Does Sterility Mean as a CQA, and Why Is It Especially Hard for CGT?

Sterility is defined by the FDA as the absence of viable contaminating microorganisms in the final product. For cell and gene therapies, sterility testing carries a structural complication most traditional biologics don’t face: conventional sterility testing requires a 14-day culture period to confirm a product meets the FDA’s sterility threshold, and traditional drug products can fall back on terminal sterilization — a technique that removes adventitious agents from the finished product — when culture-based confirmation isn’t practical. CGT products generally cannot tolerate terminal sterilization, since the technique would destroy the living cellular components that constitute the therapy itself, and a living, patient-specific product frequently cannot wait 14 days for sterility confirmation before it needs to reach the patient.

The FDA’s practical answer to this constraint is twofold. First, aseptic manufacturing processes — closed-system processing, sterile manufacturing equipment, and sterilized raw materials wherever feasible — are recommended to maintain sterility throughout production rather than relying solely on end-product testing to catch contamination after the fact. Second, for products that must be administered before a full 14-day culture can complete, FDA guidance calls for a rapid gram-negative stain performed prior to administration, paired with a predefined action plan for managing a positive result that only emerges after the patient has already received the product. For allogeneic therapies specifically, sterility assurance extends further upstream to donor screening, with required testing for HIV types 1 and 2, hepatitis B, hepatitis C, human transmissible spongiform encephalopathy, and syphilis before donor material ever enters the manufacturing process.

What Does Potency Actually Measure, and How Is It Tested?

Potency is defined by the FDA in 21 CFR 600.3(s) as the specific ability or capacity of a product, as demonstrated through appropriate laboratory tests or adequately controlled clinical data, to produce a given result when administered as intended. For CGT specifically, potency is best understood as the therapy’s ability to perform its intended biological modification in target cells or tissues — conceptually analogous to efficacy, though measured through laboratory assay rather than clinical outcome alone.

Potency assays have to be designed specifically for the product being tested, using either in vivo or in vitro methods, and potency testing functions as a subset of broader conformance, comparability, and stability testing performed ahead of lot release. In practice, potency is measured through assays of biological activity, which can take several distinct forms: a mixed lymphocyte reaction assay, which determines whether T cells are active against a target cell or measures cytokine secretion as a marker of biological activity; an indirect assay correlating a measurable cell phenotype with a known function, such as using elevated CD86 expression on dendritic cells as an indirect marker of dendritic cell activation; or a matrix assay, which evaluates several distinct product characteristics and combines them into a cumulative measure of potency. Whichever approach is used, the FDA expects the assay to be fully validated to demonstrate product activity, provide a quantitative readout, indicate product stability, and demonstrate consistency from lot to lot. Some researchers have proposed standardizing on cell viability as a baseline potency measure, given how widely viability assays are already used across CGT generally — though this hasn’t yet become a formal regulatory standard.

How Are CQAs Prioritized Through Risk Assessment?

Not every CQA carries equal weight, and manufacturers do not control every quality attribute with the same intensity. CQA prioritization is formally governed by quality risk management principles, most notably the framework established in ICH Q9, which provides a structured methodology for assessing and ranking quality risks based on their potential impact on patient safety and product efficacy. Under this approach, manufacturers use formal risk assessment tools — failure mode and effects analysis being among the most common — to evaluate each candidate CQA against its severity if it fails to meet specification, the probability that it could fail, and the likelihood that a failure would be detected before reaching the patient.

Attributes that score high on severity and probability, and low on detectability — meaning a failure would be serious, plausible, and hard to catch through existing controls — receive the most rigorous monitoring, the tightest specification limits, and the most resource investment in assay development. This risk-based prioritization is what allows manufacturers to allocate genuinely finite assay development, validation, and ongoing monitoring resources toward the quality attributes that matter most to patient safety, rather than attempting uniform rigor across every conceivable characteristic of a complex biologic or cell and gene therapy product.

How Should Manufacturers Approach CQA Identification?

Because standardized CQA guidelines for cell and gene therapies remain incomplete, manufacturers benefit from approaching CQA identification as an evolving, risk-based exercise rather than a fixed checklist. This typically begins with a thorough understanding of the product’s mechanism of action — since the attributes most critical to safety and efficacy will differ depending on whether a therapy works through gene insertion, cell engraftment, immune modulation, or another mechanism entirely.

Manufacturers who treat CQA identification as a one-time exercise completed early in development often find themselves revisiting the question repeatedly as new process or product knowledge emerges — sometimes after a regulatory interaction surfaces a gap the original CQA assessment did not anticipate. Building CQA strategy as an iterative, well-documented process from the outset, rather than a static early-stage deliverable, tends to produce a more defensible regulatory position as the product advances toward commercial approval.