In pharmaceutical manufacturing, your SCADA system is not just an operations tool - it is a GxP record-generating machine. Cleanroom environmental trends, sterilizer cycles, purified-water loops, and batch process values all become regulated electronic records the moment you rely on them for quality decisions. That pulls the platform under 21 CFR Part 11, EU Annex 11, and the data integrity expectations FDA and European inspectors now enforce aggressively. This guide walks through pharmaceutical SCADA compliance end to end: which rules apply and why, what ALCOA+ actually demands from a SCADA platform, how the GAMP 5 validation process works step by step, what realistic timelines and costs look like, and what to require from any SCADA vendor selling into a GMP facility.
One of 60+ guides in our SCADA security and compliance series.
The regulatory driver is simple: US cGMP regulations (21 CFR Part 210 and Part 211) and EU GMP require manufacturers to keep records proving that product was made under controlled conditions. When those records are created and stored electronically - as every modern SCADA, environmental monitoring, or building management system does - 21 CFR Part 11 governs the electronic records and signatures in the US, and Annex 11 of EudraLex Volume 4 governs the computerised system in the EU. The predicate rule creates the record-keeping duty; Part 11 and Annex 11 define what makes the electronic version trustworthy.
Enforcement is not theoretical. Since the mid-2010s, data integrity has been one of the most cited themes in FDA warning letters and EU non-compliance reports: shared operator logins, disabled or unreviewed audit trails, deleted raw data, and systems where operators could alter results without a trace. Inspectors have learned to sit at the SCADA console and ask three questions: who did this, when, and can anyone change the record afterward? If your platform cannot answer those cleanly, the deficiency writes itself.
Scope matters, though. Not every tag in the plant is GxP. A compressed-air trend used only for maintenance planning is not a quality record; the same trend used to release a sterile batch is. The first real compliance task is a GxP assessment that separates systems and data with product-quality impact from those without - because validation effort should follow risk, not paranoia.
Part 11 is short but demanding. For electronic records that fall in scope, it requires:
For electronic signatures, Part 11 adds that each signature must be unique to one individual and never reused or reassigned; that non-biometric signatures use at least two components (typically user ID plus password); and that signed records display the printed name of the signer, the date and time, and the meaning of the signature (review, approval, responsibility). Crucially, the signature must be linked to its record so it cannot be excised or copied to another record.
Two practical notes. First, FDA's 2003 Scope and Application guidance narrowed enforcement to records required by predicate rules and signaled a risk-based posture - but validation, audit trails, access control, and record retention remain firmly expected. Second, there is no such thing as a Part 11 certificate. Software can be Part 11 capable; only your validated, procedurally controlled system is Part 11 compliant.
Annex 11 covers more ground than Part 11 because it addresses the whole computerised system lifecycle, not just records and signatures. Its clauses expect risk management applied throughout the lifecycle, formal supplier assessment (including audits of vendors for critical systems), validation appropriate to the system's novelty and complexity, checks on accuracy of manually entered critical data, secure storage with backup verification, audit trails for GMP-relevant changes and deletions - with a notable expectation that audit trails be regularly reviewed - plus incident management, business continuity for critical systems, and periodic evaluation to confirm the system remains in a validated state.
In practice, a SCADA deployment engineered to satisfy both regimes looks the same: named accounts, validated functionality, tamper-evident audit trails, controlled change, verified backups, and a paper trail proving you assessed your supplier. If you sell product into both the US and EU, design to the union of the two from day one; retrofitting audit-trail review procedures after an inspection finding is far more expensive.
Regulators - including FDA in its Data Integrity and Compliance With Drug CGMP guidance - summarize data integrity as ALCOA+: data must be Attributable, Legible, Contemporaneous, Original, and Accurate - plus Complete, Consistent, Enduring, and Available. For a SCADA platform, each attribute maps to a concrete technical capability:
This is where platform architecture shows. Merobix, for example, attaches identity to every telemetry sample - sample ID, timestamp, quality flag, device, and site - writes immutable, chained audit records for sensitive events so tampering is evident, and uses store-and-forward buffering at the gateway so a connectivity outage results in delayed data rather than missing data. Those are exactly the properties ALCOA+ asks you to demonstrate. For a deeper treatment of tamper-evident logging, see our guide to SCADA audit trails and operational evidence.
GAMP 5, published by ISPE and now in its Second Edition (2022), is the de facto playbook for validating computerised systems in pharma. It is guidance, not law - but inspectors, quality units, and consultants all speak its language. The core ideas:
FDA's Computer Software Assurance (CSA) guidance pushes the same direction: apply deep scripted testing where failure directly impacts product quality or patient safety, and use lighter, unscripted assurance elsewhere. CSA does not abolish validation - it rebalances the evidence. The practical consequence for buyers: a vendor with strong internal test practices, documented quality processes, and shareable evidence directly reduces your validation bill. When you assess suppliers, ask how they test releases, how they communicate changes, and what independent scrutiny their controls receive - our comparison of SOC 2, ISO 27001 and IEC 62443 explains what vendor attestations actually prove.
A typical path from purchase to a validated, inspection-ready SCADA system:
Ranges vary widely with scope, risk, and how much vendor evidence you can leverage - treat these as planning numbers, not quotes. A monitoring-only environmental system covering a few cleanrooms is often validated in six to twelve weeks. A full process SCADA controlling GMP-critical parameters typically runs three to nine months from URS to validation report. Budget-wise, small monitoring validations commonly land around 15,000 to 50,000 dollars in internal and consultant effort; large configured batch-control systems can reach 100,000 to 500,000 dollars or more. Ongoing costs are real too: periodic reviews (typically annual or biennial), audit-trail review time, and change-control overhead for every meaningful update. A vendor documentation package that your quality unit can leverage under GAMP 5 or CSA principles is often worth tens of thousands of dollars in avoided duplicate testing - which is why it belongs in your RFP scoring.
| Standard / Rule | Issued By | Legal Force | What It Covers for SCADA |
|---|---|---|---|
| 21 CFR Part 11 | US FDA | Binding regulation (US) | Electronic records and signatures: validation, audit trails, access control, signature linkage |
| EU Annex 11 | European Commission (EudraLex Vol 4) | Binding GMP guideline (EU) | Full computerised-system lifecycle: supplier assessment, validation, audit-trail review, continuity |
| GAMP 5 (2nd Ed) | ISPE | Industry guidance | How to validate: categories, V-model, risk-based testing, supplier leverage |
| ALCOA+ / Data integrity guidances | FDA, MHRA, PIC/S, WHO | Guidance backed by enforcement | Attributes trustworthy data must have; the lens inspectors apply to your records |
| CSA guidance | US FDA | Guidance | Risk-proportionate assurance; less scripted testing for lower-risk functions |
| IEC 62443 | IEC / ISA | Voluntary standard | Cybersecurity of the control system itself - increasingly expected alongside GxP controls |
Note the last row: data integrity and cybersecurity have converged. A system whose records can be silently altered by an attacker fails ALCOA+ just as surely as one abused by an insider. That is why supplier assessments increasingly ask security questions, and why the architecture arguments in our secure SCADA for OT networks guide apply squarely to pharma.
Requirements to put in the URS and demand in demos:
On that last point, Merobix is built for exactly this style of scrutiny: TOTP and FIDO2 authentication with brute-force lockout, six permission roles with site-level authorization, step-up authentication for high-risk workflows such as permit signing, immutable chained audit records, and data-retention plus customer-export workflows. On the assurance side, Merobix runs a SOC 2 readiness program, maps its controls to IEC 62443, and treats independent penetration testing as part of its ongoing validation program - framed exactly that way, because honest vendors distinguish readiness from certification. You can review the architecture on our security page or walk through the audit-trail and signing workflows live in a demo.
Key takeaway: No vendor can sell you a "Part 11 compliant" product - compliance belongs to your validated system, procedures, and people. What a vendor can sell you is Part 11 capability (named accounts, audit trails, signatures, retention) plus documentation and test evidence that shrink your validation effort under GAMP 5 and CSA. Score vendors on both, and treat anyone waving a "Part 11 certificate" as disqualified on honesty grounds.
Yes, whenever a SCADA system creates, modifies, stores, or transmits records that a predicate rule (such as the cGMP regulations in 21 CFR Parts 210 and 211) requires you to keep. Cleanroom temperature and humidity trends, sterilizer cycle records, purified-water system data, and batch process values are all common examples. If those records exist electronically and you rely on them for GMP decisions, Part 11 controls apply: validation, secure and computer-generated audit trails, limited system access, record protection and retention, and compliant electronic signatures where signatures are required.
No. There is no FDA certification program for Part 11, and compliance is a property of a validated system in its operating context, not of a software product on its own. A vendor can honestly claim to be Part 11 capable, meaning the software provides the technical controls the rule demands: unique named accounts, computer-generated time-stamped audit trails, e-signature manifestation, record protection and export. It is then the regulated company that achieves compliance by validating the system for its intended use, writing the supporting procedures, and controlling access and change. Treat any vendor claiming a Part 11 certificate as a red flag.
Part 11 is a binding US FDA regulation focused specifically on electronic records and electronic signatures. Annex 11 is part of the EU GMP guidelines (EudraLex Volume 4) and covers the full lifecycle of computerised systems: risk management, supplier assessment, validation, data storage, audit trails and their periodic review, security, incident management, and business continuity. In practice they overlap heavily, and a system built to satisfy both looks the same: named accounts, validated functionality, tamper-evident audit trails, controlled access, and reliable data retention. Companies selling into both markets design to the union of the two.
It varies with system scope and risk. A monitoring-only environmental system covering a handful of cleanrooms can often be validated in six to twelve weeks. A full process SCADA system controlling GMP-critical parameters typically takes three to nine months from user requirements through IQ/OQ/PQ and the validation report. Costs range from roughly fifteen to fifty thousand dollars for small monitoring systems to several hundred thousand for large batch-control projects, depending heavily on how much vendor documentation and testing you can leverage instead of repeating yourself. These are honest planning ranges, not quotes; complexity, internal review cycles, and consultant rates move them significantly.
CSA is the FDA-endorsed shift from documentation-heavy computer system validation toward risk-based critical thinking: spend deep, scripted testing effort on functions that directly impact product quality and patient safety, and use lighter, unscripted or vendor-leveraged assurance for everything else. It does not remove the obligation to validate; it changes how much evidence is proportionate. GAMP 5 Second Edition (2022) embraces the same thinking, including leveraging supplier testing and documentation. For SCADA buyers this makes vendor quality practices, test evidence, and documentation packages directly valuable, because good vendor evidence is effort you do not have to duplicate.
Named accounts, step-up signing, immutable audit chains, and gap-free telemetry - see how Merobix supports GxP-grade evidence, cloud or on-premise.