A food or beverage plant lives under two audit regimes at once: the FDA enforcing FSMA and HACCP rules, and the GFSI schemes - SQF, BRCGS, FSSC 22000 - that your retail customers demand before they will stock your product. Both regimes ultimately come down to the same question: can you prove, with trustworthy records, that every critical control point was monitored and every deviation was caught and corrected? Your SCADA and monitoring system is where that proof lives or dies. This guide covers which standards actually apply, what each one demands of your monitoring records, the concrete process and honest costs of getting certified, and what to require from any SCADA vendor selling into food and beverage.
One of 60+ guides in our SCADA security and compliance series.
Food and beverage SCADA compliance is driven by four requirement sets: FSMA preventive-controls records, HACCP critical control point monitoring, 21 CFR Part 11 electronic-records rules where they apply, and the GFSI audit schemes (SQF, BRCGS, FSSC 22000) your retail customers demand. Unlike power utilities under NERC CIP or pipelines under TSA directives, there is no single cybersecurity-specific SCADA regulation - instead, a stack of food safety and data integrity requirements quietly dictates what a monitoring system must do:
The regulatory driver differs from other industries in one important way: for most food plants, the strongest enforcement pressure is commercial, not governmental. FDA inspections happen on a cycle of years; the GFSI audit that keeps your product on a retailer's shelf happens every twelve months, and a failed audit can cost a contract within weeks.
FSMA moved US food regulation from reacting to contamination toward preventing it. The preventive controls rule requires covered facilities to run a written food safety plan: a hazard analysis, preventive controls for the hazards identified, and - critically for SCADA buyers - monitoring, corrective action, and verification records that prove the controls actually operated. Under the record-keeping requirements of 21 CFR Part 117, Subpart F, records must be retained for at least two years and be available to FDA within 24 hours of a request.
Nothing in FSMA mandates electronic records or SCADA. Paper is legal. But the practical bar keeps rising: an investigator reviewing a pasteurizer deviation wants to see the continuous temperature record, the alarm, who responded, and what happened to the product in the affected window. A SCADA historian that captures every reading with a timestamp, an instrument identity, and a data-quality flag answers those questions in minutes. A clipboard of hourly manual checks leaves gaps an auditor is trained to find - the 2 AM reading recorded in suspiciously identical handwriting to the 3 AM and 4 AM readings is a cliché of food audits for a reason.
The Intentional Adulteration rule adds a food defense angle: facilities must assess where a bad actor could deliberately contaminate product and mitigate those vulnerabilities. Access control on the control system belongs in that assessment - an unattended HMI logged in with a shared operator account is exactly the kind of vulnerability the rule asks you to think about, and the same named-account and audit trail discipline that satisfies auditors also closes it.
HACCP is the operating system of food safety: identify the critical control points (CCPs) where a hazard can be controlled - pasteurization temperature, metal detection, cook and chill times, pH - set critical limits, monitor them, and document corrective action when a limit is exceeded. Whether HACCP applies to you as law (seafood, juice, meat, poultry) or through your GFSI scheme and FSMA plan, the record-keeping logic is identical.
For each CCP, an auditor expects four things your monitoring system should produce without heroics:
This is where SCADA choice becomes a compliance decision. A platform that treats alarms as transient screen events, or lets anyone edit history, cannot produce defensible CCP records. A platform that stores telemetry with full identity - sample ID, timestamp, quality flag, device, and site, the way Merobix records every point - and keeps an immutable log of every acknowledgment gives your QA team evidence instead of assertions.
Part 11 is the FDA's rule for electronic records and signatures, and it is the most misunderstood standard in food manufacturing. Two facts cut through most of the confusion:
First: FSMA preventive-controls records are exempt. When FDA wrote 21 CFR Part 117, it explicitly exempted records kept solely to satisfy that part from Part 11. Your FSMA monitoring records do not legally require validated Part 11 systems.
Second: Part 11 still applies elsewhere in food. Electronic records kept to satisfy other FDA regulations remain in scope - thermal processing records for low-acid canned foods, seafood and juice HACCP records, and anything a dual-use facility (food plus dietary supplements or pharma) keeps under those regimes. For those records, Part 11 expects controlled system access, computer-generated audit trails, operational checks, and electronic signatures that are unique to one individual and linked to their record - with FDA's current enforcement interpretation laid out in its Part 11 scope and application guidance.
In practice, sophisticated food companies stopped playing scope games and simply run Part 11-style discipline everywhere: named accounts, multi-factor authentication, audit trails on every change, and signature-grade confirmation for critical actions. It satisfies the strictest reading of the rule, it satisfies GFSI auditors, and it is simply good OT security. Merobix supports this posture natively - named roles from viewer to admin, TOTP and passkey MFA, step-up re-authentication for high-risk workflows, and chained, tamper-evident audit records for sensitive events - capabilities described in more depth on our security page. If your operation spans into pharma-grade requirements, our pharma SCADA compliance guide covers the full validation world of GAMP 5 and Annex 11.
The Global Food Safety Initiative benchmarks the private certification schemes that dominate food retail. If you sell to major grocers, club stores, or large foodservice, at least one of these is effectively mandatory. All three cover similar ground - food safety plan, HACCP, good manufacturing practices, traceability, food defense - and all three are audited annually by accredited certification bodies, with unannounced audit options that retailers increasingly prefer.
What GFSI auditors do with your SCADA system is simple and ruthless: they sample. Pick a production date, pull the CCP records, follow one deviation from alarm to disposition, check the calibration certificate on the sensor involved, and verify the records could not have been quietly rewritten. Sites fail findings not because monitoring did not happen, but because they cannot retrieve coherent evidence - the trend data is in one system, alarm history in another, operator actions on paper, and nothing links them. A unified platform where telemetry, alarms, acknowledgments, and user actions share one timeline, with clean export for the audit binder, converts audit week from a scramble into a report run. Merobix includes data-retention and customer-export workflows for exactly this purpose.
| Standard / Scheme | Who Enforces or Audits | Legally Required? | What It Demands of SCADA & Records |
|---|---|---|---|
| FSMA / 21 CFR 117 | FDA inspections | Yes - most US food facilities | Monitoring, corrective action and verification records; 2-year retention; produce within 24 hours |
| HACCP (seafood, juice, USDA meat & poultry) | FDA / USDA FSIS | Yes - in those sectors | CCP monitoring records, deviation and corrective action documentation, calibration evidence |
| 21 CFR Part 11 | FDA | Only for electronic records under FDA rules outside the Part 117 exemption | Access control, computer-generated audit trails, unique e-signatures, system validation |
| SQF / BRCGS / FSSC 22000 | Accredited certification bodies (GFSI) | No - but commercially mandatory for major retail | Evidence sampling across CCPs, traceability, food defense, record integrity; annual audits |
| IEC 62443 / NIST SP 800-82 | Voluntary; customer & insurer questionnaires | No | OT security architecture: segmentation, access control, monitoring - see our NIST 800-82 guide |
For a plant pursuing its first GFSI certification with FSMA obligations in order, the path looks like this:
Total elapsed time for a reasonably prepared single site: 6–12 months. Costs vary too widely for a single number to be honest, but the components are predictable: certification-body audit fees commonly run a few thousand dollars per audit day; consultant support ranges from a few thousand dollars for a tune-up to tens of thousands for a ground-up program; and monitoring-system upgrades range from minor configuration to six figures in an older plant that still runs on chart recorders and clipboards. Budget the internal labor honestly - it usually exceeds every external fee combined.
Key takeaway: In food and beverage, compliance is an evidence problem before it is a technology problem. Every standard on this page - FSMA, HACCP, Part 11, SQF, BRCGS - converges on the same demand: trustworthy, attributable, tamper-evident records of your critical control points, retrievable on demand. Choose a SCADA platform on its ability to produce that evidence automatically, and most of your audit findings disappear before the auditor arrives.
Use this checklist in vendor evaluations - it reflects what audits in this industry actually test:
Finally, weigh deployment model against your IT reality. Most food plants run lean IT, which makes a cloud platform with an outbound-only gateway attractive - no plant-floor servers to patch, no inbound firewall holes - while an on-premise option remains available where policy requires it. You can pressure-test how this works against your own CCP list in a guided demo.
No. FSMA requires monitoring of preventive controls and records that prove the monitoring happened - it does not mandate any particular technology, and paper records remain legal. In practice, plants adopt SCADA and electronic records because manual logs fail audits in predictable ways: missed readings on nights and weekends, transcription errors, and no way to prove a chart was not filled in after the fact. An electronic system that records CCP temperatures, flows, and pressures automatically, with timestamps and named-user attribution, produces the continuous evidence FDA investigators and GFSI auditors increasingly expect.
Sometimes, and the nuance matters. FDA explicitly exempted records kept solely to satisfy the FSMA preventive controls rule (21 CFR Part 117) from Part 11. But Part 11 still applies when electronic records satisfy other FDA regulations - low-acid canned food thermal processing records, seafood and juice HACCP records, and any records a dual-use food and supplement or pharma facility keeps under those rules. Many food companies apply Part 11-style controls - audit trails, access control, electronic signature discipline - across the board anyway, because GFSI auditors and large retail customers expect that level of data integrity regardless of the legal minimum.
GFSI auditors work from your food safety plan: they pick CCPs and preventive controls, then ask for the records that prove continuous monitoring, alarm response, and corrective action. For an electronic system they typically verify that records are complete for the review period, that each entry is attributable to a person or instrument, that alarm events show documented operator response within the required time, that calibration records exist for the instruments feeding the data, and that records cannot be silently edited or deleted. A SCADA platform with an immutable audit trail and easy record export turns this from a two-day paper chase into an hour of report pulling.
For a first GFSI certification (SQF, BRCGS, or FSSC 22000), most single-site plants need 6 to 12 months from gap assessment to certificate, assuming a functioning food safety plan already exists. Direct audit fees commonly run a few thousand dollars per audit day - typically 2 to 4 days - plus annual recertification. The larger cost is internal: consultant support, documentation work, instrument calibration, and any monitoring-system upgrades, which can range from tens of thousands into six figures for larger or older plants. These ranges vary widely by site size, process complexity, and starting maturity, so treat any fixed quote with skepticism until a gap assessment is done.
Prioritize evidence-producing capability: automatic recording of CCP and preventive-control parameters with timestamps and data quality, immutable audit trails attributing every action to a named user, alarm handling with documented acknowledgment, retention that comfortably covers the FSMA two-year record requirement, and clean export for auditors. On the security side, demand multi-factor authentication, role-based access that separates viewing from control, and a vendor that is transparent about its security program - for example, Merobix operates a SOC 2 readiness program and maps its controls to IEC 62443 rather than making vague certification claims. Finally, verify the vendor can support validation documentation if any of your records fall under Part 11.
CCP monitoring with full data identity, immutable audit trails, MFA and role-based access, and export workflows built for audit week - see how Merobix fits your food safety plan.