A simplified explanation of how Annex 11 and ISA/IEC 62443 define safe, compliant remote access for industrial automation systems.
Secure remote access has become a standard part of GMP manufacturing as facilities rely more heavily on automation vendors, equipment suppliers, OT integrators, and cloud-connected support tools. While these connections improve efficiency and speed, they also introduce one of the most common entry points into an Industrial Automation and Control System (IACS). For that reason, GMP and industrial cybersecurity standards require manufacturers to manage remote access through validation, governance, and clearly defined supplier responsibilities.
Annex 11 and ISA/IEC 62443 outline how these responsibilities are shared between manufacturers, who own the assets, and the vendors, service providers, integrators, and product suppliers who support them. Together, these standards establish the controls needed to keep remote access secure, traceable, and compliant.
1. Annex 11 Requirements for Vendor Remote Access (Simplified)
GMP Annex 11 states that when third-party suppliers or service providers access computerized GMP systems, including through remote connections, manufacturers must have formal agreements that define each party’s responsibilities and security expectations.
Specifically, Annex 11 requires documented agreements whenever a third party installs, configures, integrates, validates, maintains (including remote support), modifies, or retains a computerized system. These agreements should clearly identify who is responsible for each activity and the controls that apply.
The manufacturer also remains responsible for several key areas.
Risk management includes evaluating how remote access could affect data integrity, patient safety, or product quality before access is granted.
Identity and access management requires remote users to be uniquely identified, properly authenticated, and authorized for only the work they are expected to perform.
System security and auditability must also be maintained. Remote sessions should not weaken system security, and enough information must be captured so activities can be reconstructed if necessary.
Manufacturers are also expected to oversee supplier performance, confirming that vendors follow approved procedures and maintain system integrity while providing remote support.
Together, these expectations establish the GMP foundation for validating remote access.
2. How ISA/IEC 62443 Defines Responsibilities for Secure Remote Access
ISA/IEC 62443 is the internationally recognized standard for securing Industrial Automation and Control Systems. Rather than placing responsibility on a single organization, it uses a shared responsibility model that identifies four primary stakeholder groups:
- Asset Owners (manufacturers)
- System Integrators
- Product Suppliers
- Service Providers, including remote support vendors
This approach recognizes that secure remote access depends on both the manufacturer and the vendor. Neither group can fully protect remote connectivity without the other meeting its responsibilities.
For remote access, the standard emphasizes several core security controls.
Identification and Authentication Controls (FR1) require strong authentication for every remote user, including vendor technicians.
Use Control (FR2) limits vendor access through role-based permissions, least-privilege principles, and time-restricted access rather than permanent accounts.
Session security focuses on protecting communication channels through encryption and safeguards against protocol-level attacks.
Logging and monitoring ensure that remote sessions can be reviewed after the fact, including connection history, session termination, and significant events.
ISA/IEC 62443-2-4 also places expectations on service providers. Vendors offering remote support should maintain internal cybersecurity programs that align with the standard rather than relying solely on customer controls.
These requirements reinforce Annex 11 by strengthening supplier oversight, accountability, and traceability.
3. A Simple, GMP-Aligned Model for Validated Secure Remote Access
The following framework provides a practical approach that life science manufacturers can use when implementing secure remote access.
Step 1 — Validate Remote Access as Part of the Computerized System
Remote access should be included in user requirements, risk assessments, and validation documentation rather than treated as a separate activity.
Tools such as secure remote access gateways, jump hosts, and vendor portals should also be validated because they become part of the computerized system supporting GMP operations. Annex 11 expects computerized systems, including the mechanisms used for remote access, to be validated appropriately.
Step 2 — Use Time-Bound, Role-Based Access
Vendor access should only be available when it is needed. Permanent access creates unnecessary risk.
Permissions should be tied to defined job roles and limited to the specific systems or equipment required for the work being performed. This reflects the Use Control requirements described in IEC 62443 FR2.
Step 3 — Require Strong Authentication for Vendors
Each vendor should have an individual account. Shared usernames and passwords should be avoided.
Whenever practical, multifactor authentication should be implemented to strengthen identity verification in accordance with IEC 62443 FR1.
Step 4 — Maintain Full Auditability of Remote Sessions
Every remote connection should be logged and reviewed as part of normal system oversight. At a minimum, records should capture who accessed the system, when access occurred, what actions were taken, and how long the session remained active.
For higher-risk systems, organizations may choose to implement additional monitoring measures such as video session recording or command-level logging. These records can provide valuable evidence during investigations, audits, or deviation reviews. Maintaining this level of visibility supports Annex 11 expectations for audit trails and demonstrates appropriate control over remote activities.
Step 5 — Control Changes Through the Supplier Responsibility Model
Remote access should never bypass established GMP processes. Before support work begins, manufacturers and vendors should have clear agreements describing what changes may be performed, what approvals are required, and how activities will be documented.
Any modification made during a remote session must follow the site’s change control procedures. This applies whether the work involves software updates, configuration adjustments, troubleshooting activities, or system enhancements.
Clearly defining responsibilities helps prevent unauthorized changes and ensures that vendor activities remain aligned with GMP requirements. Annex 11 specifically emphasizes the importance of supplier and service provider oversight in maintaining computerized system compliance.
Step 6 — Protect Connections with Secure Architecture
The technical design of remote access is just as important as the policies that govern it. Organizations should implement architectures that reduce exposure to critical production systems and limit the potential impact of a security event.
Common approaches include using demilitarized zones (DMZs), OT-specific remote access solutions, session brokers, and protocol isolation technologies. These controls create separation between external connections and the production environment while still allowing vendors to perform necessary support activities.
Direct vendor VPN connections into production networks should generally be avoided. Instead, access should be routed through controlled and monitored pathways that provide visibility, authentication, and oversight. This approach aligns with IEC 62443 recommendations for protecting communication pathways and isolating critical IACS assets.
Summary
Annex 11 and ISA/IEC 62443 both recognize that secure remote access is a shared responsibility. Manufacturers and vendors each play a role in protecting GMP systems while maintaining the operational support needed to keep facilities running effectively.
For life science manufacturers, this means treating remote access as part of the validated computerized system. Access should be controlled through strong authentication, appropriate authorization, documented oversight, and reliable audit trails. Formal supplier agreements are equally important because they establish expectations, define responsibilities, and support compliance efforts.
Vendors also have obligations. Remote support should be delivered through secure and accountable processes that protect system security and data integrity. Service providers are expected to maintain cybersecurity practices that align with IEC 62443 requirements and support the controls implemented by the asset owner.
When these responsibilities are clearly defined and consistently applied, remote access becomes easier to manage and defend during inspections, audits, and regulatory reviews. The result is a more secure environment that supports both operational efficiency and GMP compliance.
About PSC Biotech®
Founded in 1996, PSC Biotech® has spent three decades supporting the life sciences industry with services that help healthcare products be developed, manufactured, and distributed in compliance with applicable regulatory requirements. Our mission is simple: help clients achieve success by providing practical solutions and specialized expertise where it matters most.
PSC Biotech® supports organizations throughout the product lifecycle, from early project planning and validation activities to manufacturing operations, asset management, and ongoing compliance initiatives. By combining technical knowledge with industry experience, we help both emerging and established life science companies navigate complex challenges and bring critical products to market.
Today, PSC Biotech® operates in 52 countries and has supported thousands of clients worldwide. Our global team includes experienced professionals located across North America, Europe, Asia, Australia, and the Middle East. We take pride in serving as a trusted partner and contributing to the success of organizations that develop and manufacture life-changing therapies and healthcare products.
Explore PSC Biotech’s full range of services at biotech.com, and follow PSC Biotech on LinkedIn to stay informed about industry insights, regulatory developments, and company updates.