The Regulatory Position on Wireless in GMP

Neither EU GMP Annex 11 nor 21 CFR Part 11 prohibits wireless networks. Annex 11 §12 requires that computerised systems are protected from unauthorised access — it does not specify that the connection medium must be copper or fibre. What it does require is that the security controls are appropriate for the risk. And wireless, by its physical nature, presents a different risk profile than a wired network: the signal extends beyond the physical boundary of the facility, any device with the correct credentials can attempt to join, and traffic can potentially be intercepted without physical access to the cabling.

The regulatory expectation is therefore not "do not use wireless" but "if you use wireless, demonstrate that the security controls are commensurate with the risks, documented in the HDS, and verified at IQ." A wireless network that uses WPA2-Enterprise authentication, is on a dedicated SSID assigned to the OT supervision VLAN, and is documented in the HDS with its access point locations, SSID, authentication method, and encryption standard is a defensible design. A wireless network that uses a shared PSK with no documentation is not.

The Key Risk Distinction

With a wired network, physical access to the cabling is a prerequisite for unauthorised connection. With wireless, proximity to the facility is sufficient — which means the threat boundary extends to the car park, neighbouring buildings, and anyone within radio range. This does not make wireless unacceptable — it makes enterprise-grade authentication mandatory. WPA2-Personal (shared passphrase) is not appropriate for a GMP OT network. WPA2-Enterprise or WPA3-Enterprise with certificate-based or 802.1X authentication is the minimum standard. The HDS must document which standard is implemented, and the IQ must verify it.

Common Wireless Use Cases in Pharma OT

The wireless use cases most commonly encountered on pharma projects fall into three categories, each with a different risk profile and documentation approach.

Wireless HMI / operator panel tablets. A tablet running a thin-client HMI application, connected via Wi-Fi to the SCADA server. Common in large process areas where a fixed panel would require long cable runs or where operators need mobility. The tablet is a validated system component — it appears in the HDS component register, its OS version is documented, and the SCADA user session it runs is subject to the same access control and audit trail requirements as a fixed HMI station. The Wi-Fi connection is to the OT supervision VLAN only; the tablet cannot reach the corporate network or internet.

Wireless field instruments. Temperature, humidity, or pressure transmitters using WirelessHART or ISA100.11a to communicate to a gateway. Common in EMS systems covering large warehouse or cold-store areas where running conduit is expensive. The wireless gateway is the OT component — it sits on the OT control or supervision network and translates wireless sensor data to a wired protocol. The field instruments themselves are Category 3 hardware under GAMP 5. The URS must include wireless reliability requirements (packet delivery rate, redundancy on link loss).

Handheld barcode scanners and mobile devices. Used in warehouse or dispensing areas for material tracking, connected to a LIMS or ERP system. These typically operate on the corporate IT network rather than the OT network, which means they do not affect the OT validation boundary — but their WLAN still needs to be segregated from the OT SSID, and any barcode scan data that flows into a GMP record is in scope for Part 11 or Annex 11.

WIRELESS NETWORK ARCHITECTURE — PHARMA GMP FACILITY OT ZONE — WIRED BACKBONE SCADA SERVER 192.168.20.10 HISTORIAN 192.168.20.20 MANAGED SWITCH ACCESS POINT WPA3-Ent / VLAN 20 WIRELESSHART GW Wired to OT-CTRL VLAN HMI TABLET SENSORS CORPORATE NETWORK / SEPARATE SSID CORP AP SSID: CORP-WIFI BARCODE SCANNER Corp VLAN only FIREWALL CRITICAL REQUIREMENTS → OT SSID physically separate from Corp SSID → WPA2/WPA3-Enterprise (no shared PSK) → OT SSID assigned to OT VLAN only
WIRELESS ARCHITECTURE — PHARMA GMP FACILITY · OT wireless (HMI tablets, WirelessHART sensors) on a dedicated SSID assigned to the OT VLAN, separated from the corporate wireless network by firewall and VLAN policy

Authentication and Encryption Requirements

The authentication and encryption standard for a GMP OT wireless network must be documented in the HDS and verified at IQ. WPA2-Enterprise using 802.1X with a RADIUS server is the established standard for industrial Wi-Fi in regulated environments. Each device connecting to the OT wireless network authenticates individually — there is no shared passphrase that can be leaked, guessed, or retained by a former employee. WPA3-Enterprise provides stronger protection and should be used where the access points and client devices support it.

The encryption standard matters too. TKIP (used in older WPA implementations) is deprecated and should not be present in any GMP OT network. AES-CCMP (WPA2) or GCMP-256 (WPA3) are the required encryption ciphers. The IQ verifier will connect to the access point management interface and confirm the authentication method, the cipher suite, and the SSID-to-VLAN mapping are as documented in the HDS. A wireless network running WPA2-Personal with TKIP is an immediate finding.

URS Requirements for Wireless Systems

If wireless connectivity is part of the validated system, the URS must include explicit requirements that drive the design. The requirements need to cover: authentication method (enterprise authentication required, shared PSK prohibited); encryption standard (AES minimum); network availability (wireless link loss must not result in data loss — specify buffer or redundancy behaviour); and cybersecurity (wireless zone is treated as a conduit between zones under IEC 62443, with the same zone boundary controls as a wired conduit).

For wireless field instruments using WirelessHART or ISA100.11a, the URS must also address: packet delivery rate (typically ≥99% as required by the instrument standard); latency requirements (WirelessHART targets ≤1 second per hop — if your process has faster alarm response requirements, document whether wireless meets them or whether wired is required for those signals); and battery life and maintenance interval for battery-powered sensors, which becomes an IQ-verifiable item in the component register.

IQ Documentation for Wireless Infrastructure

Wireless IQ documentation follows the same logic as wired OT network IQ documentation — every component documented in the HDS, every configuration specification verifiable on-site — with additional wireless-specific verification steps.

The Rogue AP Problem

A rogue access point is an unauthorised wireless AP connected to the OT network — planted by an attacker, set up by a well-meaning engineer, or left behind from a commissioning activity. A rogue AP broadcasting on the OT SSID credentials can give unauthorised devices access to the OT VLAN, completely bypassing the firewall architecture. For pharma OT networks with wireless infrastructure, the IQ should include a scan for rogue APs, and the site security policy should define how rogue AP detection is maintained after go-live. Many enterprise wireless controllers include built-in rogue detection — if your site uses one, document it in the HDS and verify it is enabled at IQ.

Wireless and the Zone-and-Conduit Model

Under the IEC 62443 zone-and-conduit model, a wireless network is a conduit between zones — not a zone itself. The wireless medium connects devices in the OT supervision zone (via an access point that is wired to the OT supervision VLAN) to other devices. Because the conduit is inherently less physically controlled than a wired conduit, the security controls on the conduit must be stronger to compensate. WPA2/WPA3-Enterprise authentication, a dedicated SSID, VLAN enforcement at the AP, and rogue AP monitoring are the controls that make a wireless conduit acceptable within a GMP OT zone architecture.

The zone boundary at the access point is enforced by the VLAN assignment — a device that authenticates successfully to the OT SSID is placed on the OT supervision VLAN by the AP, and from that point it is subject to the same switch-level and firewall controls as a wired device on that VLAN. The wireless authentication is the gate; once through the gate, the zone controls apply identically to wired and wireless devices. This is the argument the HDS must make, and it must be supported by the AP configuration documentation and the IQ verification evidence.

In the QLean Framework

For projects with wireless infrastructure, HDS-SYS-001 Section 7.1 includes a wireless network subsection covering SSID definitions, authentication methods, VLAN assignments, and AP locations. The component register (Section 1.3) includes access points as validated components with firmware versions. The IQ protocol includes a wireless verification section with steps for AP configuration, SSID survey, authentication method confirmation, and VLAN mapping. For WirelessHART systems, the field instrument list in EL-SYS-001 includes battery-powered sensors with their battery change intervals as a maintenance requirement that flows into the Periodic Review SOP.