The pharmaceutical industry has been under intense regulatory pressure for years. Quality, patient safety, validation, supply reliability, and documentation are firmly embedded in processes. However, what was often less visible in the past is now inevitably taking center stage: information security and business continuity are also increasingly becoming critical success factors.
This is because modern pharmaceutical companies are no longer merely manufacturing or research organizations. They are digital ecosystems. Research, clinical data, manufacturing facilities, laboratory information systems, supply chains, quality management, cloud services, and external service providers are all interconnected. If any of these systems is disrupted, the consequences can go far beyond a typical IT outage and have a direct impact on data integrity (ALCOA+) and, ultimately, patient safety.
This paradigm shift is underscored by the upcoming revision of EU GMP Annex 11. The new draft makes it unmistakably clear that cybersecurity, identity management, audit trails, and backup strategies are no longer isolated IT tasks, but are becoming fundamental components of GMP compliance. It is precisely at this intersection of IT operations, quality management, and legal obligations that NIS2, Business Continuity, ISO 27001, and the new Annex 11 work together to ensure the resilience of the entire ecosystem in a systematic and audit-proof manner.

Why NIS2 Is Relevant to the Pharmaceutical Industry
The NIS2 Directive has significantly expanded the scope of regulated organizations. Of particular relevance to the pharmaceutical industry is the fact that the healthcare sector and related fields are explicitly addressed. These include, among others, institutions engaged in research and development activities related to medicinal products, manufacturers of pharmaceutical products, and certain manufacturers of medical devices.
This shifts the focus: Cybersecurity is no longer just a technical task for the IT department. It is becoming a matter of organizational resilience, business continuity, and ultimately, supply security.
For affected companies, this means that simply implementing individual protective measures is not enough. What is required is a systematic approach that identifies, assesses, addresses, and regularly reviews risks. This includes technical, organizational, and operational measures—ranging from access controls and backup strategies to incident response, supply chain management, and crisis management.
Business Continuity: More Than Just “Restarting IT”
In the pharmaceutical industry in particular, business continuity is more than just traditional IT disaster recovery. It is not just a matter of restoring servers or restoring data from a backup. The crucial question is: Which processes must continue to run so that research, production, quality assurance, approval processes, or delivery capabilities do not come to a standstill?
A cyberattack on a production system, an outage of a validated laboratory information system, or a disruption at a critical IT service provider can have a direct impact on deadlines, batch releases, documentation requirements, and supply chains.
Business continuity must therefore be approached from a technical perspective. Which processes are critical? What dependencies exist with regard to IT, OT, cloud services, or external partners? How long can a process be down? Which manual alternative processes are realistic? And have these scenarios actually been tested?
NIS2 makes this point particularly clear by explicitly including business continuity, backup management, disaster recovery, and crisis management among the relevant risk management measures.
ISO 27001 as a structured framework
While NIS2 sets out regulatory requirements, ISO 27001 provides a proven management framework for systematically managing information security. The standard requires an information security management system ( ISMS) that addresses risks not on an ad hoc basis, but on an ongoing basis.
This is particularly valuable for pharmaceutical companies because ISO 27001 integrates well with existing management systems. Many companies already have established structures in place for quality, compliance, auditing, and documented processes. An ISMS can build on these and integrate information security into the existing governance framework.
ISO 27001 is particularly helpful in clarifying responsibilities, assessing risks in a transparent manner, prioritizing measures, verifying their effectiveness, and continuously improving them. It is precisely this traceability that is crucial in regulated industries: it is not only the measure itself that counts, but also the rationale, documentation, and regular review.
Annex 11: Cybersecurity Becomes a GMP Requirement
The new draft of Annex 11 (published in July 2025) marks a clear shift away from purely project-based system validation toward a continuous lifecycle and governance approach. The guideline explicitly aligns GMP systems with European cybersecurity expectations such as the NIS2 Directive and ISO 27001. This means that a cyber incident (e.g., ransomware) is no longer just an IT problem, but a direct GMP violation, as it compromises data integrity (ALCOA+).
Seamless alignment with NIS2 and BCM requirements
The new Annex 11 requirements specify exactly the same measures for computer-based systems in a GMP environment as those required by NIS2 and BCM:
- Business Continuity and Backups: Annex 11 now explicitly and in detail requires backup, archiving, and disaster recovery plans. Testing recovery processes becomes a mandatory requirement, which aligns with the BCM focus of NIS2.
- Supply Chain Security and the Cloud: While NIS2 requires the management of supply chain risks, Annex 11 specifically mandates this for software and cloud providers. The pharmaceutical company remains fully responsible for compliance and must establish formal service level agreements (SLAs), risk audits, and exit strategies for IT service providers.
- Identity and Access Management: Modern standards such as multi-factor authentication (MFA), the principle of least privilege (granting only the necessary permissions), and strict segregation of duties are also required in the GMP environment.
The Blind Spot: Supply Chain and Service Providers
A key risk factor in the pharmaceutical industry lies in its interconnections with third parties. Research partners, CROs, CDMOs, cloud providers, software vendors, logistics partners, and external IT service providers are often deeply integrated into critical processes. Therefore, a security incident does not have to originate within one’s own company to impact one’s own organization. If a service provider goes down, data becomes unavailable, or external access is compromised, this can directly impair one’s own operational capabilities.
Therefore, supplier relationships should be evaluated not only from the perspective of quality and procurement, but also from the perspective of information security and business continuity. This includes clear security requirements, defined reporting channels, emergency contacts, recovery times, and regular reviews.
What Matters Most for Pharmaceutical Companies Right Now
Companies should assess whether they are subject to NIS2 or the relevant national implementing legislation, identify which processes are truly critical, and determine how well these processes are protected against cyber incidents, system failures, and service provider disruptions.
Five questions are particularly important in this context:
- Which business processes are critical to research, production, quality, and delivery capability?
- What IT, OT, and service provider dependencies exist in these processes?
- Have risk analysis, incident response, backup, recovery, and crisis management been documented and tested?
- Are responsibilities clearly defined all the way up to management?
- Is there a management system in place that regularly reviews and improves information security?
Being able to answer these questions with confidence does not automatically mean that an organization is fully compliant. However, it lays the groundwork for a mature and verifiable approach to managing cyber risks.
Conclusion
NIS2, business continuity, ISO 27001, and the revised Annex 11 should not be viewed in isolation within the pharmaceutical industry. They take different approaches but share the same goal: to sustainably strengthen companies’ resilience to cyber risks, system failures, and supply chain disruptions.
While NIS2 establishes the regulatory framework for cybersecurity and organizational resilience, ISO 27001 provides a well-established methodology for the structured management of information security. Business continuity ensures that critical business processes can be maintained even in the event of a crisis. The new Annex 11 also makes it clear that topics such as cybersecurity, backup and recovery concepts, supplier management, and identity and access management will be an integral part of GMP compliance in the future.
The key to regulatory compliance and risk mitigation lies precisely in this integration of IT security, operational resilience, and corporate compliance.
We help companies take a holistic approach to cyber resilience and regulatory requirements—from assessing their current status and conducting risk analyses to establishing management systems and implementing business continuity and information security measures. Get in touch with us – info@expertsinstitut.de
References:
- Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14, 2022 — NIS 2 Directive
Basis for NIS 2 compliance, in particular scope, affected sectors, risk management measures, reporting obligations, and business continuity requirements.
https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32022L2555
- DIN EN ISO/IEC 27001:2024-01 — Information security, cybersecurity, and data protection; Information Security Management Systems — Requirements
Basis for the ISO 27001 reference, in particular ISMS, risk assessment, risk treatment, governance, documented information, and continuous improvement.
- Federal Office for Information Security (BSI): NIS 2 Starter Pack / Information for NIS 2-regulated companies
Supplementary resource for the German context, particularly regarding the classification of affected companies, registration, reporting requirements, and risk management measures.
https://www.bsi.bund.de/DE/Themen/Regulierte-Wirtschaft/NIS-2-regulierte-Unternehmen/NIS-2-Starterpaket/nis-2-start_node.html
- European Commission: Stakeholder Consultation on the Revision of EU-GMP Annex 11, Annex 22, and Chapter 4
Reference for the revision of EU-GMP Annex 11, particularly regarding the expanded cybersecurity requirements. https://health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en
Read our entire blog here: https://experts-institut.de/newsroom/
And feel free to follow us on LinkedIn: https://de.linkedin.com/company/expertsinstitut



