The Regulatory Position on Wireless in GMP
Neither EU GMP Annex 11 nor 21 CFR Part 11 prohibits wireless networks. Annex 11 §12 requires that computerised systems are protected from unauthorised access — it does not specify that the connection medium must be copper or fibre. What it does require is that the security controls are appropriate for the risk. And wireless, by its physical nature, presents a different risk profile than a wired network: the signal extends beyond the physical boundary of the facility, any device with the correct credentials can attempt to join, and traffic can potentially be intercepted without physical access to the cabling.
The regulatory expectation is therefore not "do not use wireless" but "if you use wireless, demonstrate that the security controls are commensurate with the risks, documented in the HDS, and verified at IQ." A wireless network that uses WPA2-Enterprise authentication, is on a dedicated SSID assigned to the OT supervision VLAN, and is documented in the HDS with its access point locations, SSID, authentication method, and encryption standard is a defensible design. A wireless network that uses a shared PSK with no documentation is not.
With a wired network, physical access to the cabling is a prerequisite for unauthorised connection. With wireless, proximity to the facility is sufficient — which means the threat boundary extends to the car park, neighbouring buildings, and anyone within radio range. This does not make wireless unacceptable — it makes enterprise-grade authentication mandatory. WPA2-Personal (shared passphrase) is not appropriate for a GMP OT network. WPA2-Enterprise or WPA3-Enterprise with certificate-based or 802.1X authentication is the minimum standard. The HDS must document which standard is implemented, and the IQ must verify it.
Common Wireless Use Cases in Pharma OT
The wireless use cases most commonly encountered on pharma projects fall into three categories, each with a different risk profile and documentation approach.
Wireless HMI / operator panel tablets. A tablet running a thin-client HMI application, connected via Wi-Fi to the SCADA server. Common in large process areas where a fixed panel would require long cable runs or where operators need mobility. The tablet is a validated system component — it appears in the HDS component register, its OS version is documented, and the SCADA user session it runs is subject to the same access control and audit trail requirements as a fixed HMI station. The Wi-Fi connection is to the OT supervision VLAN only; the tablet cannot reach the corporate network or internet.
Wireless field instruments. Temperature, humidity, or pressure transmitters using WirelessHART or ISA100.11a to communicate to a gateway. Common in EMS systems covering large warehouse or cold-store areas where running conduit is expensive. The wireless gateway is the OT component — it sits on the OT control or supervision network and translates wireless sensor data to a wired protocol. The field instruments themselves are Category 3 hardware under GAMP 5. The URS must include wireless reliability requirements (packet delivery rate, redundancy on link loss).
Handheld barcode scanners and mobile devices. Used in warehouse or dispensing areas for material tracking, connected to a LIMS or ERP system. These typically operate on the corporate IT network rather than the OT network, which means they do not affect the OT validation boundary — but their WLAN still needs to be segregated from the OT SSID, and any barcode scan data that flows into a GMP record is in scope for Part 11 or Annex 11.
Authentication and Encryption Requirements
The authentication and encryption standard for a GMP OT wireless network must be documented in the HDS and verified at IQ. WPA2-Enterprise using 802.1X with a RADIUS server is the established standard for industrial Wi-Fi in regulated environments. Each device connecting to the OT wireless network authenticates individually — there is no shared passphrase that can be leaked, guessed, or retained by a former employee. WPA3-Enterprise provides stronger protection and should be used where the access points and client devices support it.
The encryption standard matters too. TKIP (used in older WPA implementations) is deprecated and should not be present in any GMP OT network. AES-CCMP (WPA2) or GCMP-256 (WPA3) are the required encryption ciphers. The IQ verifier will connect to the access point management interface and confirm the authentication method, the cipher suite, and the SSID-to-VLAN mapping are as documented in the HDS. A wireless network running WPA2-Personal with TKIP is an immediate finding.
URS Requirements for Wireless Systems
If wireless connectivity is part of the validated system, the URS must include explicit requirements that drive the design. The requirements need to cover: authentication method (enterprise authentication required, shared PSK prohibited); encryption standard (AES minimum); network availability (wireless link loss must not result in data loss — specify buffer or redundancy behaviour); and cybersecurity (wireless zone is treated as a conduit between zones under IEC 62443, with the same zone boundary controls as a wired conduit).
For wireless field instruments using WirelessHART or ISA100.11a, the URS must also address: packet delivery rate (typically ≥99% as required by the instrument standard); latency requirements (WirelessHART targets ≤1 second per hop — if your process has faster alarm response requirements, document whether wireless meets them or whether wired is required for those signals); and battery life and maintenance interval for battery-powered sensors, which becomes an IQ-verifiable item in the component register.
IQ Documentation for Wireless Infrastructure
Wireless IQ documentation follows the same logic as wired OT network IQ documentation — every component documented in the HDS, every configuration specification verifiable on-site — with additional wireless-specific verification steps.
- Access point model, firmware version, and physical location recorded in HDS component register — verified on-site by physical inspection and management interface screenshot
- SSID name matches HDS — verified by scanning for SSIDs from the production area (the OT SSID should be visible; no undocumented SSIDs should be broadcasting on the OT frequency)
- Authentication method confirmed as WPA2/WPA3-Enterprise — verified from AP management interface configuration export
- SSID-to-VLAN mapping confirmed — OT SSID maps to OT supervision VLAN only, not corporate VLAN
- Corporate SSID and OT SSID are on different channels or frequency bands to minimise interference (documented and verified)
- Signal strength coverage survey conducted and recorded — confirms adequate coverage across all areas where wireless HMI tablets or instruments operate
- Rogue AP detection enabled or documented as N/A with justification
- For WirelessHART: gateway model and firmware in component register; network manager configuration archived; mesh network topology diagram produced and filed as IQ evidence
A rogue access point is an unauthorised wireless AP connected to the OT network — planted by an attacker, set up by a well-meaning engineer, or left behind from a commissioning activity. A rogue AP broadcasting on the OT SSID credentials can give unauthorised devices access to the OT VLAN, completely bypassing the firewall architecture. For pharma OT networks with wireless infrastructure, the IQ should include a scan for rogue APs, and the site security policy should define how rogue AP detection is maintained after go-live. Many enterprise wireless controllers include built-in rogue detection — if your site uses one, document it in the HDS and verify it is enabled at IQ.
Wireless and the Zone-and-Conduit Model
Under the IEC 62443 zone-and-conduit model, a wireless network is a conduit between zones — not a zone itself. The wireless medium connects devices in the OT supervision zone (via an access point that is wired to the OT supervision VLAN) to other devices. Because the conduit is inherently less physically controlled than a wired conduit, the security controls on the conduit must be stronger to compensate. WPA2/WPA3-Enterprise authentication, a dedicated SSID, VLAN enforcement at the AP, and rogue AP monitoring are the controls that make a wireless conduit acceptable within a GMP OT zone architecture.
The zone boundary at the access point is enforced by the VLAN assignment — a device that authenticates successfully to the OT SSID is placed on the OT supervision VLAN by the AP, and from that point it is subject to the same switch-level and firewall controls as a wired device on that VLAN. The wireless authentication is the gate; once through the gate, the zone controls apply identically to wired and wireless devices. This is the argument the HDS must make, and it must be supported by the AP configuration documentation and the IQ verification evidence.
For projects with wireless infrastructure, HDS-SYS-001 Section 7.1 includes a wireless network subsection covering SSID definitions, authentication methods, VLAN assignments, and AP locations. The component register (Section 1.3) includes access points as validated components with firmware versions. The IQ protocol includes a wireless verification section with steps for AP configuration, SSID survey, authentication method confirmation, and VLAN mapping. For WirelessHART systems, the field instrument list in EL-SYS-001 includes battery-powered sensors with their battery change intervals as a maintenance requirement that flows into the Periodic Review SOP.