Information security has quietly become a GMP concern. As pharmaceutical operations move to cloud platforms, connected instruments and AI-assisted systems, the confidentiality and integrity of regulated data is now squarely in the inspector’s sights — and the forthcoming revision of EU GMP Annex 11 makes cybersecurity a core requirement for the first time. For companies certified, or seeking certification, to ISO/IEC 27001, the two worlds are converging fast.
Where information security meets GxP
GxP data integrity rests on the ALCOA+ principles — data should be attributable, legible, contemporaneous, original and accurate, as well as complete, consistent, enduring and available. EU GMP Annex 11 and the FDA’s 21 CFR Part 11 translate these into concrete controls: access management, strong user authentication, audit trails and record retention. ISO/IEC 27001 provides an information security management system (ISMS) whose Annex A controls map directly onto many of the same expectations, which is why the two frameworks are increasingly discussed together.
The Annex 11 revision raises the bar
The European Commission published a draft revision of Annex 11 in July 2025, with the public consultation closing in October 2025 and a final version expected around mid-2026. The change is substantial — the guidance expands from roughly five pages to nearly twenty and, for the first time, treats cybersecurity as a core GMP requirement. Notable additions include:
- strengthened audit-trail requirements, with explicit immutability and periodic review, aligned to ALCOA++;
- enhanced electronic-signature expectations, including multi-factor authentication and eIDAS alignment;
- clearer oversight of cloud and SaaS suppliers holding regulated data;
- explicit reference to international standards such as ISO/IEC 27001, and a companion draft Annex 22 covering artificial intelligence.
ISO 27001:2022 — mind the transition
The 2022 revision of ISO/IEC 27001 restructured its controls, consolidating the previous 114 into 93 arranged under four themes. Crucially, the transition deadline for legacy certificates has now passed: certificates still referencing the 2013 version became invalid after 31 October 2025. Any organisation relying on ISO 27001 as evidence of security maturity should confirm it holds a current 2022 certificate.
Managing the audit risks
Where the two frameworks meet, inspectors and auditors tend to find the same recurring weaknesses:
- weak identity and access management, including shared or generic logins;
- audit trails that can be disabled or edited, or that are never reviewed;
- inadequate oversight of cloud and SaaS providers that hold GxP data;
- backup, restore and business-continuity arrangements that have never been validated.
A key point is often missed: ISO 27001 certification is not the same as GxP compliance. The ISMS must be explicitly mapped to data-integrity expectations before it can be relied upon in a regulated context.
How PQRA helps
PQRA supports pharmaceutical and healthcare companies with quality assurance and data integrity, computerised system validation, Annex 11 gap assessments, supplier qualification and audit readiness — bridging the gap between an ISO 27001 information security programme and GxP compliance so that both stand up to inspection.
Contact PQRA to assess your data integrity and computerised system compliance.


No responses yet