Industries
Pharma and life sciences — GxP, 21 CFR Part 11 and data-integrity security
Manufacturers, CROs and life-sciences firms must keep computerised systems validated and data-integrity intact under CDSCO and US FDA 21 CFR Part 11, while protecting patient and trial data under DPDP.
Applicable regulations
- US FDA 21 CFR Part 11 and GxP data-integrity expectations
- CDSCO requirements for computerised systems in regulated operations
- DPDP Act 2023 for patient, trial and employee personal data
- ISO 27001 ISMS and SOC 2 for enterprise and partner assurance
Common cybersecurity risks
- Data-integrity failures in GxP computerised systems (ALCOA+)
- Unvalidated changes to manufacturing and LIMS/QMS platforms
- Exposure of clinical-trial and patient personal data
- Insecure interfaces between IT, lab instruments and OT
- IP theft of formulations and research data
Audit findings we typically see
- Incomplete audit trails and access controls in GxP systems
- Weak segregation between IT, lab and manufacturing networks
- No DPDP-aligned handling of patient and trial data
- Untested backup and recovery for validated systems
- No incident-response process spanning quality and security
Services required
- VAPT across enterprise, lab and OT systems
- ISO 27001 ISMS
- SOC 2 readiness
- DPDP compliance for patient and trial data
- Security architecture review
Our engagement approach
- Discovery. Inventory GxP and enterprise systems, data flows and interfaces; confirm 21 CFR Part 11, CDSCO and DPDP obligations.
- Assessment. Security testing and control-gap review mapped to data-integrity (ALCOA+), ISO 27001 and DPDP, without disrupting validated systems.
- Remediation. A prioritised, validation-aware roadmap for access, audit-trail and segmentation fixes.
- Assurance. Retest, audit-grade reporting and inspection-ready evidence.
Expected evidence
- System and data-flow inventory across GxP and enterprise IT
- Access-control and audit-trail review results
- VAPT reports with closure evidence
- DPDP and data-integrity control evidence
Indicative timeline
A typical assessment runs 6 to 12 weeks, depending on validated-system scope.
Deliverables
- Gap assessment mapped to 21 CFR Part 11, ISO 27001 and DPDP
- Validation-aware remediation roadmap
- VAPT reports with closure evidence
- Inspection-ready control evidence pack
Related case study
Free tool
Try it free →DPDP Readiness Checker
Check your readiness for India’s DPDP Act and see your priority gaps — free.

QSA Authorised
CEMEA · Asia Pacific · USA
Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne — see all locations & addresses →
