Cybersecurity in GxP systems is no longer just an IT concern.
The draft revision of EMA Annex 11 marks an important evolution in GxP compliance. Information security and cybersecurity are no longer viewed solely as technology concerns. They are becoming essential elements of data integrity, product quality, operational resilience, and ultimately patient safety.
What is particularly significant is that the draft does not introduce an entirely new information security approach for GxP systems. Instead, it brings pharmaceutical and medical device regulations closer to established cybersecurity and risk management practices reflected in frameworks such asGAMP® 5 (Second Edition), and FDA Computer Software Assurance (CSA).
The message is clear: GxP expectations are converging with modern cybersecurity practices.
How does the draft align with modern frameworks?
Several areas in the draft reflect established information security and cybersecurity principles.
Information Security Management System (ISMS) principles
A structured approach for managing information security risks through governance, policies, risk management, continuous improvement and accountability.
Information security governance and cybersecurity accountability
Clear collaboration between IT Information Security , Quality, System Owners, Process Owners, Engineering, and suppliers. Cybersecurity ownership remains with the security function, while GxP stakeholders ensure that risks affecting product quality, patient safety, and data integrity are appropriately managed.
Security by Design
Information security and cybersecurity considerations should be integrated throughout the computerized system lifecycle, from design and implementation to operation, maintenance and retirement.
Risk-based information security management
Organizations should identify, assess, mitigate, and continuously monitor information security risks, including cybersecurity risks, based on business, product and patient impact.
Supplier and cloud security oversight
The draft also strengthens the focus on managing risks associated with outsourced services, cloud platforms and third-party providers.
Security incident management and business resilience
This includes establishing capabilities for security monitoring, vulnerability management, incident response, backup and recovery.
What should pharmaceutical companies do?
The EMA Annex 11 draft should not be viewed as a requirement to create a separate cybersecurity model for GxP systems. Instead, it provides an opportunity to strengthen information security governance and integrate cybersecurity into computerized system lifecycle management.
For organizations considering where to start, practical steps include:
Establish clear information security governance and accountability
Define responsibilities across IT Information Security / ISRM, System Owners, Process Owners, Quality, Engineering and suppliers.
Build or enhance Organizations with mature cybersecurity programs should align existing practices with GxP expectations. Small and medium-sized companies can start with fundamentals such as security policies, risk assessment, asset inventory, access management, incident management and continuous improvement.
Embed information security into the system lifecycle
Include security considerations in computerized system implementation, change management, supplier management, operation and retirement.
Strengthen third-party and operational resilience
Assess cloud providers, suppliers, vulnerability management, patching, backup, recovery, and incident response capabilities based on business and patient impact.
The Bigger Picture
The EMA Annex 11 draft does not require every organization to immediately implement a mature enterprise cybersecurity program. Instead, it reinforces a clear direction of travel: GxP computerized systems must become secure, resilient, and actively managed throughout their lifecycle.
Whether an organization is beginning its information security journey or enhancing an existing security framework, the objective is the same: align cybersecurity with the fundamentals of GxP—patient safety, product quality, and data integrity—while strengthening overall business resilience.
How KVALITO Can Help
For organizations reviewing what the draft Annex 11 requirements could mean for their computerized systems, KVALITO can help assess how existing information security governance, lifecycle processes and controls align with these expectations.
This can help identify where current practices may need to be strengthened and how cybersecurity can be integrated into the wider GxP computerized system lifecycle.
[RG1]Shall we consider a IT Security standards ((ISO 27002: 2013 , CIS, ISO 27701 and NIST) vs GMP Annex 11



