
IT Infrastructure Qualification - From Data Center to Cloud.
IT infrastructure qualification demonstrates that the infrastructure your GxP systems run on is built to specification and operated under control, from your own data center to the cloud. The evidence is not a one-off protocol. It comes from a controlled state, established according to risk and maintained through tools and monitoring.
The foundation beneath every GxP system.
EU GMP Annex 11 states the principle in a single sentence: "The application should be validated; IT infrastructure should be qualified." The regulation does not say how deep that has to go. The depth follows the risk of the GxP processes the infrastructure supports. In scope are hardware and networks, virtual environments, operating systems and databases.
Paper evidence for a single day
Paper-based evidence confirms the state of one day. It says little about ongoing operation.
A controlled state in operation
The qualified state is maintained within the IT quality management system, and service management, automation and monitoring produce the evidence. The records behind it are build reports, the configuration management database and monitoring logs. These records are subject to the data integrity requirements per ALCOA++.
Risk-based from need to controlled state.
There is no rigid phase model. Every step derives from the risk of the processes the infrastructure supports. Where the risk is higher, the evidence goes deeper.
- 1
Planning & risk assessment
The risk of the processes the infrastructure supports is assessed. The scope and depth of qualification per component derive from it.
- 2
Requirements & specification
The infrastructure requirements are captured and documented. Then the planned design is checked against them.
- 3
Build & verification
Documented evidence that hardware, virtual infrastructure and infrastructure software are installed and configured to specification. Automated build reports and Infrastructure as Code (IaC) deliver it reproducibly. Supplier documentation is used as far as the risk of the component allows.
- 4
Acceptance & release
Functional evidence is produced to the depth that the risk assessment in step 1 defined for each component. The qualification report closes the work, and the infrastructure is released for GxP use.
- 5
Controlled state in operation
Change, configuration and security management, patching and periodic review maintain the state. The configuration management database (CMDB) and monitoring logs keep the evidence current.
How do you qualify cloud infrastructure you don't own?
With cloud infrastructure, the regulated company demonstrates control over the provider, because the hardware is not its own. Qualifying the provider takes the place of qualifying the company's own hardware. EU GMP Annex 11 requires the qualified state of IT infrastructure regardless of who operates it, and accountability stays with the regulated company. The 2011 text already requires formal agreements with clear responsibilities and makes the need for an audit dependent on a risk assessment. The 2025 draft of the Annex 11 revision spells this out in more detail. It additionally provides for ongoing oversight against agreed service levels and key performance indicators, plus reporting duties and access to the documentation from the company's own site. The GAMP Good Practice Guide "Enabling Innovation" classifies the IaaS and PaaS service models according to shared responsibility. Cloud infrastructure also changes constantly, because capacity grows and shrinks with demand. Patches arrive on the provider's schedule. A one-off assessment therefore describes a state that the next patch overtakes. Control is demonstrated in three ways:
Two service models are relevant for outsourced infrastructure. Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) differ in how far the provider's responsibility extends:
| Model | What the provider covers | Your evidence focus |
|---|---|---|
| IaaS | Data center, hardware and virtualization as a controlled service, without you having visibility into the physical environment | Verify your own software layer (operating systems, databases, middleware) and reconcile delivered instances with the order, with the provider's build reports as evidence |
| PaaS | Additionally operating systems, middleware, database services and the development environment, up to the runtime platform | Assess the provider's controls, monitor the platform as it continues to evolve, and keep your own applications and deployments under control |
Software as a Service is deliberately out of scope here. A rented application directly performs business processes and belongs to the validation of the computerized system as a whole, in the process and against the Intended Use.
Operating infrastructure is the core competency of the major providers, and their controls are evidenced by certifications such as ISO 27001 and attestations such as SOC 2. What must be demonstrated is controlled operation at the provider in question.
Another driver of cloud use is compute. Training and scaling large AI models often exceed the capacity of company-owned data centers, and the demand arrives in bursts. AI applications in the GxP environment built on such models draw their compute from the cloud, and evidence of controlled cloud use then becomes a prerequisite for their GxP use.
Risk-based scope by infrastructure component.
The qualification scope depends on component type and risk. Standard components need only lean evidence, while configured and outsourced building blocks receive the depth of control their risk demands. For systems that sit directly in production, process evidence is added on top of that, described under Qualification and Validation of Production Systems.
| Infrastructure component | Classification | Qualification focus (risk-based) |
|---|---|---|
| Operating systems, databases, infrastructure software | standard infrastructure software | Inventory, version and configuration, recorded in the configuration management database, kept deliberately lean where risk is low |
| Hardware, network, servers | physical infrastructure | Acceptance against the specification, with functional evidence whose depth depends on how close the supported processes sit to the batch decision |
| Virtual infrastructure, Infrastructure as Code (IaC) | configured | The code is the specification. Verified once, it provisions every environment identically, and every run is documented in the build report |
| Cloud services (IaaS, PaaS) | outsourced operation | Provider assessed according to risk, responsibilities allocated by contract, service levels monitored continuously |
| Backup & restore, disaster recovery | process on the infrastructure | What matters is recovery actually tested under real operating conditions |
| Change, configuration & security management | operational process | The operational processes sustain the qualified state and carry its evidence forward in day-to-day operation |
Does qualification end at the edge of the shop floor?
No, it follows the data. EU GMP Annex 11 applies to all computerized systems used in GMP activities. Process control systems are among them, and so are the sensors and edge devices whose data support GxP decisions. The production level (operational technology, OT) was long a world of its own. Process control systems and sensors followed the automation pyramid per ISA-95 and stayed separated from the corporate network. That separation is dissolving. An ISPE concept paper on Pharma 4.0 from 2024 describes an IT/OT architecture based on the NAMUR Open Architecture. In it, smart sensors deliver their condition data through a second channel parallel to the pyramid, to edge devices and on to the cloud. The architecture was tested on a GMP bioreactor. IT controls thus reach the shop floor, and the depth of qualification follows the intended use of the process the data feed into. A condition signal for maintenance is treated differently from a process value that enters batch release.
Qualification, implemented risk-based.
We support you from strategy through to the qualification report, and then in the operation in which the qualified state is maintained. Along the way we work with IT operations, quality assurance and the providers. The first three points show where the work starts, depending on who initiates the qualification.
We know the guide for this path from the inside.
QFINITY contributed to the GAMP Good Practice Guide "Enabling Innovation". The guide describes how the qualified state of IT infrastructure is maintained through tools, automation and monitoring, from your own data center to IaaS and PaaS.
GAMP 5 Second Edition follows the same approach of risk-based control instead of blanket documentation. QFINITY served on its Core Team. Infrastructure cannot be partitioned into GxP and non-GxP. It is controlled as a whole, with uniform IT practices and evidence drawn from the tools.
Frequently asked questions on IT infrastructure in the GxP environment.
Yes. No regulation prohibits cloud operation. What is required is demonstrable control over the provider. The regulated company remains accountable. It exercises that accountability through its assessment of the provider, its agreements with the provider and ongoing monitoring. That is how it evidences control. The cloud is then open to GxP-critical applications as well.
No. The DQ/IQ/OQ/PQ phase model comes from qualifying stable equipment. IT infrastructure is qualified according to risk. Standard components need only lean evidence, configured building blocks more, and the qualified state is maintained in operation. The evidence comes from the tools' records, from build report to monitoring log.
Not necessarily. What level of assessment is appropriate depends on the risk. The range runs from certificates and standard reports through postal audits to on-site or joint audits where risk is high. An audit only evidences the point in time it was held, so the service and quality agreements and ongoing monitoring of performance have to sustain control continuously.
No. Such a separation is neither practicable nor required. The same infrastructure runs regulated and non-regulated applications alike and is controlled as a whole, to the same IT standards. The differentiation happens one level up, because the intended use of the supported processes determines how deep the evidence for individual components goes.
Annex 11 has regulated suppliers and service providers in a dedicated section since 2011: formal agreements with clear responsibilities, the need for an audit based on a risk assessment, and audit information available to inspectors. The 2025 draft expands this section considerably. It makes clear that the regulated company retains full responsibility. In addition it provides for ongoing oversight against agreed service levels and key performance indicators, regular and ad hoc reporting, agreed support during inspections and access to the documentation from the company's own site. Until adoption, the 2011 version of Annex 11 applies. A company that already runs its controlled state this way is prepared for both versions.
Last updated:
Bring your infrastructure into a controlled state.
In an initial consultation, we classify your infrastructure, data center and cloud alike, by risk and identify today's gaps in responsibilities and evidence. The consultation is free of charge and takes about 30 minutes.
Schedule a consultation


