• Newsroom
  • Join us!
  • Newsletter
  • Kontakt
  • English English English en
  • Deutsch Deutsch German de
Experts Institut
  • Business Consulting
    • Business Solutions
      • Digitization
      • Sustainability Corporate strategy
      • Management systems
      • Project management
      • Strategy & Performance
      • Transformation & Leadership
  • GXP Consulting
    • GMP Beratung
      • Audits & inspections
      • GMP/GXP training courses
      • GMP Aircheck4
      • Continuous Manufacturing
  • Industries
    • Pharma
    • Service providers & trade
    • Automotive
    • FOOD & BEVERAGES
    • Financial service providers & insurances
    • Informationstechnik (IT)
    • Aerospace
  • Academy
    • Individuelle Inhouse-Schulungen
      • GMP/GXP training courses
    • Experts Institut Events
      • Academy
    • Direkt buchen
      • Live-Events
      • On-Demand Webinar
  • Kunden
  • Über uns
    • Über uns
      • Guideline
      • Portrait
      • Team
      • Geschäftsführung
      • Vision
      • Events
      • History Experts Institute
      • Sustainability at the Experts Institute
      • Social responsibility
    • Wissen
      • GMP Glossary
      • FAQ – Frequently asked questions in the GMP environment
      • Videos
    • Blog
      • Newsroom
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Link to LinkedIn
  • Link to Xing

Tag Archive for: Annex 11

GMP, GXP

NIS2, Business Continuity, ISO 27001 & Annex 11: Why the Pharmaceutical Industry Needs to Place Greater Emphasis on Cyber Resilience

The pharmaceutical industry has been under intense regulatory pressure for years. Quality, patient safety, validation, supply reliability, and documentation are firmly embedded in processes. However, what was often less visible in the past is now inevitably taking center stage: information security and business continuity are also increasingly becoming critical success factors.

This is because modern pharmaceutical companies are no longer merely manufacturing or research organizations. They are digital ecosystems. Research, clinical data, manufacturing facilities, laboratory information systems, supply chains, quality management, cloud services, and external service providers are all interconnected. If any of these systems is disrupted, the consequences can go far beyond a typical IT outage and have a direct impact on data integrity (ALCOA+) and, ultimately, patient safety.

This paradigm shift is underscored by the upcoming revision of EU GMP Annex 11. The new draft makes it unmistakably clear that cybersecurity, identity management, audit trails, and backup strategies are no longer isolated IT tasks, but are becoming fundamental components of GMP compliance. It is precisely at this intersection of IT operations, quality management, and legal obligations that NIS2, Business Continuity, ISO 27001, and the new Annex 11 work together to ensure the resilience of the entire ecosystem in a systematic and audit-proof manner.

Cyber

Why NIS2 Is Relevant to the Pharmaceutical Industry

The NIS2 Directive has significantly expanded the scope of regulated organizations. Of particular relevance to the pharmaceutical industry is the fact that the healthcare sector and related fields are explicitly addressed. These include, among others, institutions engaged in research and development activities related to medicinal products, manufacturers of pharmaceutical products, and certain manufacturers of medical devices.

This shifts the focus: Cybersecurity is no longer just a technical task for the IT department. It is becoming a matter of organizational resilience, business continuity, and ultimately, supply security.

For affected companies, this means that simply implementing individual protective measures is not enough. What is required is a systematic approach that identifies, assesses, addresses, and regularly reviews risks. This includes technical, organizational, and operational measures—ranging from access controls and backup strategies to incident response, supply chain management, and crisis management.

Business Continuity: More Than Just “Restarting IT”

In the pharmaceutical industry in particular, business continuity is more than just traditional IT disaster recovery. It is not just a matter of restoring servers or restoring data from a backup. The crucial question is: Which processes must continue to run so that research, production, quality assurance, approval processes, or delivery capabilities do not come to a standstill?

A cyberattack on a production system, an outage of a validated laboratory information system, or a disruption at a critical IT service provider can have a direct impact on deadlines, batch releases, documentation requirements, and supply chains.

Business continuity must therefore be approached from a technical perspective. Which processes are critical? What dependencies exist with regard to IT, OT, cloud services, or external partners? How long can a process be down? Which manual alternative processes are realistic? And have these scenarios actually been tested?

NIS2 makes this point particularly clear by explicitly including business continuity, backup management, disaster recovery, and crisis management among the relevant risk management measures.

ISO 27001 as a structured framework

While NIS2 sets out regulatory requirements, ISO 27001 provides a proven management framework for systematically managing information security. The standard requires an information security management system ( ISMS) that addresses risks not on an ad hoc basis, but on an ongoing basis.

This is particularly valuable for pharmaceutical companies because ISO 27001 integrates well with existing management systems. Many companies already have established structures in place for quality, compliance, auditing, and documented processes. An ISMS can build on these and integrate information security into the existing governance framework.

ISO 27001 is particularly helpful in clarifying responsibilities, assessing risks in a transparent manner, prioritizing measures, verifying their effectiveness, and continuously improving them. It is precisely this traceability that is crucial in regulated industries: it is not only the measure itself that counts, but also the rationale, documentation, and regular review.

Annex 11: Cybersecurity Becomes a GMP Requirement

The new draft of Annex 11 (published in July 2025) marks a clear shift away from purely project-based system validation toward a continuous lifecycle and governance approach. The guideline explicitly aligns GMP systems with European cybersecurity expectations such as the NIS2 Directive and ISO 27001. This means that a cyber incident (e.g., ransomware) is no longer just an IT problem, but a direct GMP violation, as it compromises data integrity (ALCOA+).

Seamless alignment with NIS2 and BCM requirements

The new Annex 11 requirements specify exactly the same measures for computer-based systems in a GMP environment as those required by NIS2 and BCM:

  • Business Continuity and Backups: Annex 11 now explicitly and in detail requires backup, archiving, and disaster recovery plans. Testing recovery processes becomes a mandatory requirement, which aligns with the BCM focus of NIS2.
  • Supply Chain Security and the Cloud: While NIS2 requires the management of supply chain risks, Annex 11 specifically mandates this for software and cloud providers. The pharmaceutical company remains fully responsible for compliance and must establish formal service level agreements (SLAs), risk audits, and exit strategies for IT service providers.
  • Identity and Access Management: Modern standards such as multi-factor authentication (MFA), the principle of least privilege (granting only the necessary permissions), and strict segregation of duties are also required in the GMP environment.

The Blind Spot: Supply Chain and Service Providers

A key risk factor in the pharmaceutical industry lies in its interconnections with third parties. Research partners, CROs, CDMOs, cloud providers, software vendors, logistics partners, and external IT service providers are often deeply integrated into critical processes. Therefore, a security incident does not have to originate within one’s own company to impact one’s own organization. If a service provider goes down, data becomes unavailable, or external access is compromised, this can directly impair one’s own operational capabilities.

Therefore, supplier relationships should be evaluated not only from the perspective of quality and procurement, but also from the perspective of information security and business continuity. This includes clear security requirements, defined reporting channels, emergency contacts, recovery times, and regular reviews.

What Matters Most for Pharmaceutical Companies Right Now

Companies should assess whether they are subject to NIS2 or the relevant national implementing legislation, identify which processes are truly critical, and determine how well these processes are protected against cyber incidents, system failures, and service provider disruptions.

Five questions are particularly important in this context:

  1. Which business processes are critical to research, production, quality, and delivery capability?
  1. What IT, OT, and service provider dependencies exist in these processes?
  1. Have risk analysis, incident response, backup, recovery, and crisis management been documented and tested?
  1. Are responsibilities clearly defined all the way up to management?
  1. Is there a management system in place that regularly reviews and improves information security?

Being able to answer these questions with confidence does not automatically mean that an organization is fully compliant. However, it lays the groundwork for a mature and verifiable approach to managing cyber risks.

Conclusion

NIS2, business continuity, ISO 27001, and the revised Annex 11 should not be viewed in isolation within the pharmaceutical industry. They take different approaches but share the same goal: to sustainably strengthen companies’ resilience to cyber risks, system failures, and supply chain disruptions.

While NIS2 establishes the regulatory framework for cybersecurity and organizational resilience, ISO 27001 provides a well-established methodology for the structured management of information security. Business continuity ensures that critical business processes can be maintained even in the event of a crisis. The new Annex 11 also makes it clear that topics such as cybersecurity, backup and recovery concepts, supplier management, and identity and access management will be an integral part of GMP compliance in the future.

The key to regulatory compliance and risk mitigation lies precisely in this integration of IT security, operational resilience, and corporate compliance.

We help companies take a holistic approach to cyber resilience and regulatory requirements—from assessing their current status and conducting risk analyses to establishing management systems and implementing business continuity and information security measures. Get in touch with us – info@expertsinstitut.de

References:

  1. Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022 — NIS 2 Directive
    Basis for NIS 2 compliance, in particular scope, affected sectors, risk management measures, reporting obligations, and business continuity requirements.
    https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32022L2555
  1. DIN EN ISO/IEC 27001:2024-01 — Information security, cybersecurity, and data protection; Information Security Management Systems — Requirements
    Basis for the ISO 27001 reference, in particular ISMS, risk assessment, risk treatment, governance, documented information, and continuous improvement.
  1. Federal Office for Information Security (BSI): NIS 2 Starter Pack / Information for NIS 2-regulated companies
    Supplementary resource for the German context, particularly regarding the classification of affected companies, registration, reporting requirements, and risk management measures.
    https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/NIS-2-Starterpaket/nis-2-start_node.html
  1. European Commission: Stakeholder Consultation on the Revision of EU-GMP Annex 11, Annex 22, and Chapter 4
    Reference for the revision of EU-GMP Annex 11, particularly regarding the expanded cybersecurity requirements. https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en

Read our entire blog here: https://experts-institut.de/newsroom/
And feel free to follow us on LinkedIn: https://de.linkedin.com/company/expertsinstitut

1 month /by Lirim Smajli
https://experts-institut.com/wp-content/uploads/2026/06/LinkedIn-Kopie.jpg 1080 1920 Lirim Smajli https://experts-institut.de/wp-content/uploads/2023/02/GEMI_Logo_Slogan_color_RGB.webp Lirim Smajli2026-06-15 17:56:042026-06-15 17:56:27NIS2, Business Continuity, ISO 27001 & Annex 11: Why the Pharmaceutical Industry Needs to Place Greater Emphasis on Cyber Resilience
GMP, News

GMP Guidance for Artificial Intelligence (AI), Machine Learning (ML) and Digital Transformation: How it Finally Begins to Enter the EU GMP Guide

The Now: Gaping Holes

When sifting through today’s status of the EU GMP Guide, it does not take an expert to see that there are gaping holes on topics of engineering, management of computerized systems, data integrity, digitalization and application of artificial intelligence.

Not that the guide has nothing to say to some of these areas. At least by means of implication the guide says lots of things between the lines. This very “in-between” is what gives pharmaceutical manufacturers quite a headache when facing governmental inspections.

The issue is that what it has to say does not cover what’s actually out there. And “by implication” is simply not a good advisor for the industry. It may be good enough for an inspector to set up interpretive requirements and for giving industry a hard time. But for a company it is simply not practicable when a text is elusive.

Although we have best practices like ISPE GAMP5 or other guidance somewhere out in the GxP universe, we would like to know from our most relevant guide-the EU GMP Guide-what is required. And this very guide has been doing a rather horrible job to provide the input industry needs (it seems not surprising that some EU countries struggle massively to keep life sciences and pharmaceuticals on their territory).

A New Hope

A new hope may be on the horizon as we have been expecting a revised version of Annex 11. There-so the concept paper tells us-we will receive a text that will address words such as artificial intelligence, clouds, and even digital transformation. One might wonder whether it is worth holding our breath for the release of the new Annex 11, as high hopes have been shown to greatly disappoint before. One might remember Annex 21 or interpretive documents from local supervizing authorities, that in the end have not been helpful for real life at all.

However, in this case it may be different. Can we guess some consequences from this next generation Annex 11?

GMP

GMP Data Integrity Finally Takes Center Stage

Although some would passionately disagree with me on this, the EU GMP guide has virtually lacked clarity on data integrity for decades. It was the US FDA who had to essentially teach us in Europe what Data Integrity is and why this is important. Without them we would still think that Good Documentation Practices and Validation of Spreadsheets is all it takes.

I love how every EU member state GMP inspector knows exactly what is necessary in terms of data integrity-only with next to no express textual basis for it in the EU GMP guide. I mean sure: evey company has by now heard of data integrity, letalone has received inspections that dealt with it. And yes, we were told after the fact that the GMP guide has “always meant” data integrity in various little phrases of the guide. But that seemed a bit of a crutch to assure the colleagues from US FDA that in Europe data integrity is something we “totally want and require!”

Point taken, it is true that in the Annex 11 we had such wording in some spots. And now the EU guide will finally take into consideration the fuller importance of data integrity-at least for computerized systems. One can tell that the EU grows more towards considering guidance from for example WHO or PIC/S.

The consequences will be that audit trails and audit trail review requirements will be clarified and likely deepend. More work. The bar for what is “basic” will be raised.

The same will happen for archiving, backups, and retrieval requirements for archived data. Companies will unlikely be able to keep playing the low-key game in the archiving area.

Management of Clouds will be a Topic

This will be upgraded, or actually decently considered in the new Annex 11. And here I must say that this is positive improvement. The GMP guide has been pretty much blind to this for quite some time now. It will be a reasonable change. It will be interesting to see how block-chain systems will be treated under the new Annex 11.

And I certainly will be interested to see how cloud hosts seriously validate and qualify their systems, software, and infrastructure. The hunsh is: this is going to cause trouble for some service providers. My recommendation to cloud providers who have pharma-clients: Get ready for it now, or You will be out of business before You know it.

If this enters Annex 11 it could mean:

– cloud services must qualify their infrastructure according to GMP.

– they must validate their software fully in line with GMP as well.

This essentially would require a quality-oriented quality management system (and no, ISO9001 would not suffice, not the slightest chance for anyone who wants to take this seriously).

GMP for Artificial Intelligence (AI) and Machine Learning (ML) will Hatch

We must be honest here: it might not be a whole lot of guidance what we will receive from the revised Annex 11:

The primary focus should be on the relevance, adequacy and integrity of the data used to test these models with, and on the results (metrics) from such testing, rather that on the process of selecting, training and optimizing the models.

https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/concept-paper-revision-annex-11-guidelines-good-manufacturing-practice-medicinal-products-computerised-systems_en.pdf

Though this quote from the concept paper is as elusive as sand running through one’s fingers, it does give us a tiny insight into what will be important to a regulator or a GMP-inspector: data (and their quality) used to feed AI models.

One of the biggest questions is: How in the world do we validate AI and ML? Will AI or ML need to be validated according to the typical V-model? In reality this seems almost impssible, since any software code change would required re-validation. And code changes might have to be expected, especially with machine learning. My assupmtion is that we will not receive much help here form the new Annex 11. Industry will be thrown back on non-governmental best practice guidance-as is often the case.

“No New Requirements”

It must be acknowledged that some of what we will find in the revised Annex 11 will likely be clarification and nailing down of requirements that were logical consequences from what is in the current version of the Annex. Yet, we will also find more work, new requirements.

For each company a careful gap assessment will be in order, and for those who have gotten away with mediocre management of electronic systems it will be time to act and invest in modernization.

Needless to say, that I am already looking forward to the next years at Experts Institut, when those projects will continue to fill our work schedules. It is a great challenge!

GMP Challenges for Small Pharmaceutical Businesses

I encourage representatives of small businesses – smaller pharmaceutical entities – to comment and to give feedback once the draft to the new Annex 11 is out. Often it is the larger pharmaceutical businesses that drive or influence what best practice is or what those texts may contain. A consequence can be that the requirements push smaller companies off the cliff of financial and infrastructural fesability. This does not need to be so. But small businesses must take a bit of a stand here. Take the chances You get, that is my recommendation. Digitalization and the use of AI and ML are unstoppable because neither society and nor the economy will not stop it. This is coming at the industry real fast. And it will likely make or break smaller business in the near future. So – get ahead with it!

Experts Institute can help!

Need help with GMP-Digitalization projects and AI-validation concepts? Contact us. Management consultancy GMP, GXP & Business Solutions | Experts Institut (experts-institut.com).

Read our full blog: https://experts-institut.de/newsroom/

And feel free to follow us on LinkedIn: https://de.linkedin.com/company/expertsinstitut

23. October 2024/by Dr. rer. nat. Dietmar Gross
https://experts-institut.com/wp-content/uploads/2024/10/blogbeitrag-1.jpg 349 918 Dr. rer. nat. Dietmar Gross https://experts-institut.de/wp-content/uploads/2023/02/GEMI_Logo_Slogan_color_RGB.webp Dr. rer. nat. Dietmar Gross2024-10-23 11:29:122026-02-11 13:11:43GMP Guidance for Artificial Intelligence (AI), Machine Learning (ML) and Digital Transformation: How it Finally Begins to Enter the EU GMP Guide
Recent
  • Cyber
    NIS2, Business Continuity, ISO 27001 & Annex 11: Why...1 month 
  • Audit
    Too many audits, too little effect? Solving audit fatigue...23. April 2026 - 21:43
  • Lieferantenmanagement
    Supplier management in the GMP industry: regulatory framework...23. February 2026 - 15:36
  • AI
    Pharmaceutical-grade use of generative AI: regulations,...4. February 2026 - 15:19
Popular
  • Qualitätsmanagement
    How to create an effective quality management system (QMS)...31. July 2025 - 10:39
  • Informationssicherheit
    ISMS 2024: What companies need to know now about NIS2, DORA,...3. July 2025 - 12:32
  • Deviation Management
    Enhancing Process Stability through Effective Deviation...27. March 2025 - 11:07
  • Supplier-Audit Reports
    Untrue Supplier-Audit-Reports: The Danger of Ethnocentric...9. January 2025 - 11:29

Tags

AI AI Annex Annex 11 Annex 22 Artificial Intelligence Audit audits Business Continuity Management Cannabis Certification Clean room Computerized systems Continuous Manufacturing CRA Cultures Cytostatics Data Integrity DORA Draft EU AI Act Germ count Germ count monitoring GMP GXP Health insurance Information security inspections ISMS ISO/IEC 42001 ISO 9001 ISO 27001 ISO standard Laboratory Machine Learning NIS-2 NIS2 Pharmacy QMS Quality management system Reagents Regulations Retaxation Sustainability Transformation

Kategorien

  • AI
  • Business Solutions
  • GMP
  • GXP
  • News
  • Retaxation
  • Sustainability
  • Uncategorized

Archiv

  • June 2026 (1)
  • April 2026 (1)
  • February 2026 (2)
  • January 2026 (2)
  • December 2025 (1)
  • November 2025 (1)
  • October 2025 (1)
  • September 2025 (1)
  • July 2025 (2)
  • March 2025 (1)
  • January 2025 (1)
  • December 2024 (1)
  • November 2024 (1)
  • October 2024 (3)
  • September 2024 (2)
  • August 2024 (2)
  • July 2024 (2)
  • May 2024 (1)
  • April 2024 (2)
  • March 2024 (2)
  • February 2023 (10)
Logo Experts Institute

Webpräsenz der Allianz für Cyber- Sicherheit
kununu widget

Business Solutions

  • Digitization
  • Sustainability
  • Management systems
  • Project management
  • Strategy & Performance
  • Transformation & Leadership

GMP / GXP Consulting

  • GMP Consulting
  • GMP audits & inspections
  • GMP/GDP training courses
  • GMP/pharmaceutical engineering
  • Continuous Manufacturing

EI Academy

  • GMP / GxP
  • Academy
  • Live events
  • On-demand webinar

New town

Experts Institut Beratungs GmbH
Weinstraße 85

D-67434 Neustadt a. d. Weinstraße

Phone: +49 (0)6321 969210
E-mail: info@expertsinstitut.de

Fax: +49 (0)6321 9692199

Bamberg

Experts Institut Beratungs GmbH
Untere Sandstraße 53

D-96049 Bamberg

Phone: +49 (0)951 51939330
E-mail: info@expertsinstitut.de

St. Gilgen (Austria)

Experts Institut Beratungs GmbH
Helenenstraße 16

A-5340 St. Gilgen, Austria

Tel.: +43 (0)6227 21068
E-Mail: info@expertsinstitut.de

  • Link to LinkedIn
  • Link to Xing

© 2024 Experts Institut Beratungs GmbH
  • Imprint
  • Data protection
  • AGBs
  • Cookie Directive (EU)
Scroll to top Scroll to top Scroll to top