EU GMP Annex 11 and Cloud Computing: Why “No” Is No Longer a SustainableAnswer

By Paolo Alzalamira
C.T.O. Dos&Donts

30 July 2026

For years, conversations about cloud computing in pharmaceutical companies always seemed to end the same way. A Quality Manager would look up from a stack of documents, shake their head, and say something like, “No, that’s not possible here. We’re regulated.” And that was the end of the discussion. Annex 11 was treated as an impenetrable barrier—a regulatory shield behind which companies could comfortably continue relying on physical servers housed in their own facilities.

Today, that conversation no longer holds up. Companies that continue to dismiss cloud adoption in this way are quietly accumulating technical debt that will cost far more to address in a few years than it would today.

What Annex 11 Actually Says

The interesting part is that Annex 11—the guideline governing computerized systems under EU GMP—does not prohibit cloud computing. In fact, it never even mentions the cloud.

Instead, it establishes a fundamental principle: the manufacturing authorization holder remains responsible for data integrity, system validation, traceability, and maintaining control over computerized systems.

Whether a server sits in a rack inside the production facility or in a hyperscale data center in Ireland is, from a regulatory perspective, an architectural decision—not a compliance issue.

What changes is not whether cloud computing is allowed, but how you demonstrate to inspectors that control has been maintained. That means contractual Service Level Agreements (SLAs), validated deployment pipelines with complete audit trails, controlled privilege management within the cloud environment, and supplier qualification aligned with GAMP® 5 principles.

The confusion stems from the fact that, for nearly two decades, the pharmaceutical industry translated “the system must remain under control” into “the system must be physically located on-site.” That interpretation may have been convenient when cloud computing was still emerging, but it was never a regulatory requirement.

What Has Changed in the Last Three Years

The pressure to move toward cloud architectures is not coming from regulators. It is coming from business realities.

The first driver is complexity.

A modern cleanroom automation platform integrates access control, door interlocking, environmental monitoring, batch management, audit reporting, and interfaces with MES and LIMS systems. Maintaining such an ecosystem on-premises means managing hardware infrastructure, redundancy, backups, disaster recovery, cybersecurity patches, operating system upgrades, and proactive monitoring.

Eventually, the IT team required to maintain the infrastructure becomes larger than the engineering team developing the actual business solution. For many pharmaceutical SMEs—and for the solution providers serving them—this is simply not sustainable.

The second driver is cybersecurity.

As the NIS2 Directive began to reshape cybersecurity expectations across Europe, many pharmaceutical IT departments realized that maintaining an adequate level of security internally requires investments that few organizations can justify: 24/7 Security Operations Centers, threat intelligence capabilities, continuous vulnerability management, network segmentation, and specialized cybersecurity expertise.

Major cloud providers are certainly not immune to cyber threats—no platform is—but they offer a depth of security expertise and investment that individual organizations simply cannot replicate. The cost-risk equation, which often favored on-premises infrastructure before 2020 largely out of organizational inertia, is increasingly shifting in the opposite direction.

The third driver receives less attention but is becoming increasingly relevant: energy consumption.

Cleanrooms are inherently energy-intensive environments. Continuous HVAC operation, HEPA filtration, and controlled pressure differentials already consume significant amounts of power. Adding a redundant on-site server infrastructure only increases that burden.

In several recently commissioned facilities, IT energy consumption has become a measurable component of overall operating costs. Large cloud data centers, by contrast, are typically designed with Power Usage Effectiveness (PUE) values that most corporate server rooms will never achieve, making cloud infrastructure considerably more efficient per unit of computing power.

The Concerns That Still Matter

None of this means that migrating GMP systems to the cloud is straightforward.

Several concerns remain entirely legitimate and deserve careful consideration.

The first is data sovereignty.

For many pharmaceutical manufacturers—particularly those developing sensitive products or operating in heavily regulated international markets—the physical location of data is often a contractual requirement before it becomes a regulatory one.

Fortunately, all major cloud providers now offer European regions with guaranteed data residency. Achieving compliance requires appropriate contractual agreements, but it is entirely feasible.

The second concern is vendor dependency.

If your entire cleanroom automation platform relies on a single cloud provider and that provider experiences a six-hour outage, the operational consequences can be significant.

This risk must be mitigated through multi-zone architectures, local failover mechanisms for real-time critical functions, and thoroughly documented business continuity strategies. These are not trivial challenges, but they represent well-established engineering practices rather than unexplored territory.

The third—and arguably the most important—is supplier qualification under GAMP® 5.

GAMP® 5 requires critical suppliers to undergo structured qualification, but applying the same supplier assessment process used for a small system integrator to organizations such as AWS or Microsoft Azure is only partially practical.

Organizations cannot realistically audit hyperscale providers in the traditional sense. Instead, they rely on internationally recognized certifications such as ISO 27001, ISO 27017, and SOC 2 reports, together with independent audit documentation and contractual agreements defining documentation review and inspection rights.

It is a different qualification model—one that requires careful explanation during inspections—but it is already being successfully implemented by many leading pharmaceutical companies.

The Real Challenge Is Not Technical

Having worked on GMP automation projects with pharmaceutical manufacturers of different sizes, I have consistently observed one recurring pattern.

In nine cases out of ten, the greatest obstacle to cloud adoption is neither technical nor regulatory.

It is cultural.

Many Quality Managers built their careers around the belief that physical proximity equals control.

“If the server is here, I control it. If it is somewhere else, I don’t.”

While understandable from a psychological perspective, this has never been technically accurate.

Control is achieved through governance, validated processes, access management, audit trails, and data integrity—not through the geographical location of a server.

Changing this mindset takes time.

It requires cloud advocates to speak the language of Quality as fluently as they speak the language of IT. It requires qualification documentation developed with a level of rigor that organizations accustomed to traditional on-premises systems sometimes underestimate. Above all, it requires patience during inspections, recognizing that the first audit of a cloud-based GMP system will inevitably involve more questions, closer scrutiny, and a greater need for evidence.

But it is a transition that can be accomplished.

And it is already happening.

Where the Industry Is Heading

Over the next three to four years, the discussion will no longer revolve around whether pharmaceutical companies should adopt the cloud.

That question is already becoming obsolete.

The real discussion will focus on how to implement cloud architectures correctly: determining which hybrid architectures best support different manufacturing processes, integrating artificial intelligence and machine learning while maintaining ALCOA+ data integrity principles, and migrating validated legacy systems without compromising decades of valuable historical data.

Organizations postponing this transition today will eventually face the same journey—but under greater time pressure, with more accumulated technical debt, and with fewer opportunities to negotiate favorable terms with technology providers.

The pharmaceutical industry’s transition from paper-based batch records to electronic batch records between 2010 and 2018 offers a familiar lesson: companies that delayed paid more and gained less.

Annex 11 is not the obstacle.

On the contrary, it remains a well-designed guideline built on clear, technology-neutral principles that are likely to remain relevant for many years to come.

The real obstacle lies in the overly conservative interpretation that has surrounded it for far too long.

Whether you are developing GMP automation solutions or implementing them within a pharmaceutical manufacturing facility, it is time to stop using regulation as a reason to avoid change and start having the conversations that the regulation itself has always allowed.

Share the Innovation Insights

Go back to innovation insights

Interested in our solutions?
Ask our expert!

Ask for more information