Compliance & Certifications • Food & Beverage

Food & Beverage SCADA Compliance:
FSMA, HACCP & Part 11

Merobix Engineering • • 12 min read

A food or beverage plant lives under two audit regimes at once: the FDA enforcing FSMA and HACCP rules, and the GFSI schemes - SQF, BRCGS, FSSC 22000 - that your retail customers demand before they will stock your product. Both regimes ultimately come down to the same question: can you prove, with trustworthy records, that every critical control point was monitored and every deviation was caught and corrected? Your SCADA and monitoring system is where that proof lives or dies. This guide covers which standards actually apply, what each one demands of your monitoring records, the concrete process and honest costs of getting certified, and what to require from any SCADA vendor selling into food and beverage.

Back to Blog

One of 60+ guides in our SCADA security and compliance series.

2011FSMA Signed Into Law
2 yrFSMA Record Retention Minimum
AnnualGFSI Audit Cycle (SQF / BRCGS)

Which Standards Actually Matter in Food & Beverage

Food and beverage SCADA compliance is driven by four requirement sets: FSMA preventive-controls records, HACCP critical control point monitoring, 21 CFR Part 11 electronic-records rules where they apply, and the GFSI audit schemes (SQF, BRCGS, FSSC 22000) your retail customers demand. Unlike power utilities under NERC CIP or pipelines under TSA directives, there is no single cybersecurity-specific SCADA regulation - instead, a stack of food safety and data integrity requirements quietly dictates what a monitoring system must do:

The regulatory driver differs from other industries in one important way: for most food plants, the strongest enforcement pressure is commercial, not governmental. FDA inspections happen on a cycle of years; the GFSI audit that keeps your product on a retailer's shelf happens every twelve months, and a failed audit can cost a contract within weeks.

FSMA: What the Preventive Controls Rule Demands of Your Records

FSMA moved US food regulation from reacting to contamination toward preventing it. The preventive controls rule requires covered facilities to run a written food safety plan: a hazard analysis, preventive controls for the hazards identified, and - critically for SCADA buyers - monitoring, corrective action, and verification records that prove the controls actually operated. Under the record-keeping requirements of 21 CFR Part 117, Subpart F, records must be retained for at least two years and be available to FDA within 24 hours of a request.

Nothing in FSMA mandates electronic records or SCADA. Paper is legal. But the practical bar keeps rising: an investigator reviewing a pasteurizer deviation wants to see the continuous temperature record, the alarm, who responded, and what happened to the product in the affected window. A SCADA historian that captures every reading with a timestamp, an instrument identity, and a data-quality flag answers those questions in minutes. A clipboard of hourly manual checks leaves gaps an auditor is trained to find - the 2 AM reading recorded in suspiciously identical handwriting to the 3 AM and 4 AM readings is a cliché of food audits for a reason.

The Intentional Adulteration rule adds a food defense angle: facilities must assess where a bad actor could deliberately contaminate product and mitigate those vulnerabilities. Access control on the control system belongs in that assessment - an unattended HMI logged in with a shared operator account is exactly the kind of vulnerability the rule asks you to think about, and the same named-account and audit trail discipline that satisfies auditors also closes it.

HACCP: Turning Critical Control Points Into Defensible Records

HACCP is the operating system of food safety: identify the critical control points (CCPs) where a hazard can be controlled - pasteurization temperature, metal detection, cook and chill times, pH - set critical limits, monitor them, and document corrective action when a limit is exceeded. Whether HACCP applies to you as law (seafood, juice, meat, poultry) or through your GFSI scheme and FSMA plan, the record-keeping logic is identical.

For each CCP, an auditor expects four things your monitoring system should produce without heroics:

This is where SCADA choice becomes a compliance decision. A platform that treats alarms as transient screen events, or lets anyone edit history, cannot produce defensible CCP records. A platform that stores telemetry with full identity - sample ID, timestamp, quality flag, device, and site, the way Merobix records every point - and keeps an immutable log of every acknowledgment gives your QA team evidence instead of assertions.

21 CFR Part 11: When Electronic Records Must Behave

Part 11 is the FDA's rule for electronic records and signatures, and it is the most misunderstood standard in food manufacturing. Two facts cut through most of the confusion:

First: FSMA preventive-controls records are exempt. When FDA wrote 21 CFR Part 117, it explicitly exempted records kept solely to satisfy that part from Part 11. Your FSMA monitoring records do not legally require validated Part 11 systems.

Second: Part 11 still applies elsewhere in food. Electronic records kept to satisfy other FDA regulations remain in scope - thermal processing records for low-acid canned foods, seafood and juice HACCP records, and anything a dual-use facility (food plus dietary supplements or pharma) keeps under those regimes. For those records, Part 11 expects controlled system access, computer-generated audit trails, operational checks, and electronic signatures that are unique to one individual and linked to their record - with FDA's current enforcement interpretation laid out in its Part 11 scope and application guidance.

In practice, sophisticated food companies stopped playing scope games and simply run Part 11-style discipline everywhere: named accounts, multi-factor authentication, audit trails on every change, and signature-grade confirmation for critical actions. It satisfies the strictest reading of the rule, it satisfies GFSI auditors, and it is simply good OT security. Merobix supports this posture natively - named roles from viewer to admin, TOTP and passkey MFA, step-up re-authentication for high-risk workflows, and chained, tamper-evident audit records for sensitive events - capabilities described in more depth on our security page. If your operation spans into pharma-grade requirements, our pharma SCADA compliance guide covers the full validation world of GAMP 5 and Annex 11.

GFSI Audits: SQF, BRCGS and FSSC 22000

The Global Food Safety Initiative benchmarks the private certification schemes that dominate food retail. If you sell to major grocers, club stores, or large foodservice, at least one of these is effectively mandatory. All three cover similar ground - food safety plan, HACCP, good manufacturing practices, traceability, food defense - and all three are audited annually by accredited certification bodies, with unannounced audit options that retailers increasingly prefer.

What GFSI auditors do with your SCADA system is simple and ruthless: they sample. Pick a production date, pull the CCP records, follow one deviation from alarm to disposition, check the calibration certificate on the sensor involved, and verify the records could not have been quietly rewritten. Sites fail findings not because monitoring did not happen, but because they cannot retrieve coherent evidence - the trend data is in one system, alarm history in another, operator actions on paper, and nothing links them. A unified platform where telemetry, alarms, acknowledgments, and user actions share one timeline, with clean export for the audit binder, converts audit week from a scramble into a report run. Merobix includes data-retention and customer-export workflows for exactly this purpose.

Standards Compared: Who Enforces What

Standard / Scheme Who Enforces or Audits Legally Required? What It Demands of SCADA & Records
FSMA / 21 CFR 117FDA inspectionsYes - most US food facilitiesMonitoring, corrective action and verification records; 2-year retention; produce within 24 hours
HACCP (seafood, juice, USDA meat & poultry)FDA / USDA FSISYes - in those sectorsCCP monitoring records, deviation and corrective action documentation, calibration evidence
21 CFR Part 11FDAOnly for electronic records under FDA rules outside the Part 117 exemptionAccess control, computer-generated audit trails, unique e-signatures, system validation
SQF / BRCGS / FSSC 22000Accredited certification bodies (GFSI)No - but commercially mandatory for major retailEvidence sampling across CCPs, traceability, food defense, record integrity; annual audits
IEC 62443 / NIST SP 800-82Voluntary; customer & insurer questionnairesNoOT security architecture: segmentation, access control, monitoring - see our NIST 800-82 guide

The Compliance Process: Concrete Steps, Honest Timelines and Costs

For a plant pursuing its first GFSI certification with FSMA obligations in order, the path looks like this:

  1. Gap assessment (2–6 weeks). Compare current practice to the chosen scheme's code. Most plants discover their monitoring records are the weak point, not their actual food safety.
  2. Food safety plan and hazard analysis (4–8 weeks). Write or refresh the plan with a preventive-controls-qualified individual; identify CCPs and preventive controls with their critical limits.
  3. Map monitoring to instrumentation (2–6 weeks). For every CCP and preventive control, decide what instrument monitors it, at what frequency, where the record lives, and who responds to alarms. This is where SCADA scope is defined.
  4. Close the record gaps (1–4 months). Deploy or reconfigure monitoring, alarming, and record retention; calibrate instruments; establish the corrective-action workflow.
  5. Train and document (ongoing, 1–2 months to baseline). Operators must execute the plan and the system consistently - auditors interview them.
  6. Internal audit and mock audit (2–4 weeks). Sample your own records the way an auditor will. Fix what falls apart.
  7. Certification audit and corrective actions. Typically 2–4 audit days on site, followed by a window (often 30 days) to close findings before the certificate issues. Then annual re-audits.

Total elapsed time for a reasonably prepared single site: 6–12 months. Costs vary too widely for a single number to be honest, but the components are predictable: certification-body audit fees commonly run a few thousand dollars per audit day; consultant support ranges from a few thousand dollars for a tune-up to tens of thousands for a ground-up program; and monitoring-system upgrades range from minor configuration to six figures in an older plant that still runs on chart recorders and clipboards. Budget the internal labor honestly - it usually exceeds every external fee combined.

Key takeaway: In food and beverage, compliance is an evidence problem before it is a technology problem. Every standard on this page - FSMA, HACCP, Part 11, SQF, BRCGS - converges on the same demand: trustworthy, attributable, tamper-evident records of your critical control points, retrievable on demand. Choose a SCADA platform on its ability to produce that evidence automatically, and most of your audit findings disappear before the auditor arrives.

Choosing a SCADA Vendor for Food & Beverage

Use this checklist in vendor evaluations - it reflects what audits in this industry actually test:

Finally, weigh deployment model against your IT reality. Most food plants run lean IT, which makes a cloud platform with an outbound-only gateway attractive - no plant-floor servers to patch, no inbound firewall holes - while an on-premise option remains available where policy requires it. You can pressure-test how this works against your own CCP list in a guided demo.

Frequently Asked Questions

Does FSMA require a SCADA system or electronic records?

No. FSMA requires monitoring of preventive controls and records that prove the monitoring happened - it does not mandate any particular technology, and paper records remain legal. In practice, plants adopt SCADA and electronic records because manual logs fail audits in predictable ways: missed readings on nights and weekends, transcription errors, and no way to prove a chart was not filled in after the fact. An electronic system that records CCP temperatures, flows, and pressures automatically, with timestamps and named-user attribution, produces the continuous evidence FDA investigators and GFSI auditors increasingly expect.

Does 21 CFR Part 11 apply to food and beverage plants?

Sometimes, and the nuance matters. FDA explicitly exempted records kept solely to satisfy the FSMA preventive controls rule (21 CFR Part 117) from Part 11. But Part 11 still applies when electronic records satisfy other FDA regulations - low-acid canned food thermal processing records, seafood and juice HACCP records, and any records a dual-use food and supplement or pharma facility keeps under those rules. Many food companies apply Part 11-style controls - audit trails, access control, electronic signature discipline - across the board anyway, because GFSI auditors and large retail customers expect that level of data integrity regardless of the legal minimum.

What do SQF and BRCGS auditors check in a SCADA or monitoring system?

GFSI auditors work from your food safety plan: they pick CCPs and preventive controls, then ask for the records that prove continuous monitoring, alarm response, and corrective action. For an electronic system they typically verify that records are complete for the review period, that each entry is attributable to a person or instrument, that alarm events show documented operator response within the required time, that calibration records exist for the instruments feeding the data, and that records cannot be silently edited or deleted. A SCADA platform with an immutable audit trail and easy record export turns this from a two-day paper chase into an hour of report pulling.

How long does food and beverage compliance certification take, and what does it cost?

For a first GFSI certification (SQF, BRCGS, or FSSC 22000), most single-site plants need 6 to 12 months from gap assessment to certificate, assuming a functioning food safety plan already exists. Direct audit fees commonly run a few thousand dollars per audit day - typically 2 to 4 days - plus annual recertification. The larger cost is internal: consultant support, documentation work, instrument calibration, and any monitoring-system upgrades, which can range from tens of thousands into six figures for larger or older plants. These ranges vary widely by site size, process complexity, and starting maturity, so treat any fixed quote with skepticism until a gap assessment is done.

What should a food or beverage plant look for in a SCADA vendor?

Prioritize evidence-producing capability: automatic recording of CCP and preventive-control parameters with timestamps and data quality, immutable audit trails attributing every action to a named user, alarm handling with documented acknowledgment, retention that comfortably covers the FSMA two-year record requirement, and clean export for auditors. On the security side, demand multi-factor authentication, role-based access that separates viewing from control, and a vendor that is transparent about its security program - for example, Merobix operates a SOC 2 readiness program and maps its controls to IEC 62443 rather than making vague certification claims. Finally, verify the vendor can support validation documentation if any of your records fall under Part 11.

Sources & Further Reading

Audit-Ready Records, Every Shift

CCP monitoring with full data identity, immutable audit trails, MFA and role-based access, and export workflows built for audit week - see how Merobix fits your food safety plan.

Request a Demo → See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →