The stability rulebook is being rewritten
For about two decades, the core ICH stability framework has been spread across Q1A(R2) for study design, Q1B for photostability, Q1C for new dosage forms, Q1D for bracketing and matrixing, Q1E for evaluation of stability data, and Q5C for biotechnological products. Q1F was withdrawn in 2006.
In April 2025, ICH published a Step 2 draft that consolidates the Q1 stability guidelines and Q5C into one guideline: eighteen sections and three annexes covering the arc from development and formal stability studies through commitments and post-approval changes. Notably, this is the first structural overhaul of the ICH stability framework in roughly two decades.
The consultation window closed in September 2025, all the resulting comments are considered as part of the ongoing ICH process. As of August 2026, the ICH Q1 work plan, last updated in February 2026, has Step 3 sign-off and Step 4 adoption targeted for November 2026. Step 4 is the ICH adoption step, subsequent regional implementation follows under Step 5. Until the new guideline is implemented in a given region, the currently applicable regional requirements remain the basis for regulatory submissions and assessments.
The interesting part is the transition
A software team reading this might be tempted to ask the wrong question first: which version do we implement? I think there is a better question: how long do we need to account for more than one regulatory state?
A submission prepared under the current framework may be assessed during a transition to the new one. Two products in the same portfolio can therefore sit on different sides of the change, depending on their development, submission and regional implementation timelines.
Data generated under an earlier framework also does not become irrelevant when the guideline changes. Its provenance, the rules applied to it, and the resulting regulatory decisions need to remain traceable and reconstructable for as long as the applicable record-retention and compliance framework require them.
This is a versioning problem which shows up whenever regulatory logic gets encoded: guidelines are not constants. They are controlled documents with revisions, applicability, jurisdictions and effective dates.
Rule bases instead of magic numbers
AssayVault treats the guideline as versioned data. The Q1E evaluation chain (per-batch regression, the extrapolation decision process, poolability testing) runs against a rule base that can represent both the established framework and the 2025 consolidated draft. Every result also records which rule set produced it. Specifications get the same treatment: Your spec is a slowly changing dimension describes how every result is evaluated against the limit in force on its measurement date.
Switching between rule versions needs to be a controlled configuration change whenever possible. At the same time, the new Q1 should not be treated merely as a collection of changed constants: revisions can alter definitions, decision logic, applicability conditions and analytical approaches as well as numerical parameters.
That distinction matters. A robust regulatory system tracks versions of numbers, rules, algorithms, assumptions, applicability and jurisdiction, independently of the software release.
Where these elements are baked directly into formulas instead (a typical evaluation spreadsheet) the next revision turns into a major project and reproducing an older answer requires reconstructing which version of the logic produced it.
In my opinion, the consolidation itself should be considered as very good news. One coherent guideline instead of a collection of overlapping documents will be easier to read, maintain and implement. An additional takeaway: regulatory logic changes and systems should expect it.