The critical installation is not the bed. It is the supply.
German law names the distribution logistics system and blood donation control as critical installations in their own right. And the Annex 11 draft turns "validated, therefore unpatchable" into a duty to isolate. Both are architecture work — we do it along your qualification cycles, not against them.
It is not the hospital bed that appears in the law, it is the supply chain
Annex 5 of the German critical infrastructure regulation lists the distribution logistics system for prescription medicines and the blood or plasma donation control system as critical installations in their own right. Not the building, not the hall — the software that steers supply. Whoever fails there fails for everyone they supply.
The documented incidents bear the pattern out. In 2017 NotPetya brought down active ingredient production at one of the largest pharmaceutical manufacturers. In 2024 data belonging to several manufacturers was exfiltrated from an American pharma wholesaler. In the same year ransomware hit a laboratory network in London, after which more than 800 operations were cancelled. In October 2024 an attack encrypted the systems of a German pharma wholesaler and disrupted supply. In none of these cases was the hospital the target, and in every one it was the hospital that was hit.
What we find
In pharmaceutical development you encounter high standards. Work there is documented, reviewed and released properly, because the environment has enforced it for decades. Anyone who accuses this sector wholesale of negligence has not seen it.
The gradient starts behind that. The further you move from development — into distribution, into smaller production sites, to suppliers and device makers — the less often you find someone who owns the subject as their actual job. Smaller houses have no real administrators, only someone who handles it on the side. Attention sits with the product, and that is reasonable: the product is approved, tested and carries liability. The infrastructure underneath is not a line item in the marketing authorisation.
What follows from that looks the same everywhere. Validated systems run on platform versions without vendor support and are still reachable from the office network, because at some point somebody needed a report. Device software is tied to an operating environment prescribed by the manufacturer that nobody may touch. Remote maintenance by the device maker sits there as standing access, justified by the validated state. And the distribution side hangs on SAP, on EDI to wholesalers and pharmacies, and on the serialisation connection — when that fails, nothing may be dispensed at the end of the chain.
"Validated, so we may not patch" was the answer. It is becoming a condition.
You get that answer in this sector, and have for twenty years, and it was never entirely wrong. The consultation draft for Annex 11 of the EU GMP guidelines, published on 7 July 2025, draws the consequence from it for the first time and writes it down.
Section 15.12 of the draft records that applications on operating systems and platforms no longer supported by vendors, and for which security patches are no longer released, are highly vulnerable and should be isolated from computer networks and the internet. Section 15.14 says the same for systems that are not patched in a timely manner with critical patches, and names them expressly as a significant risk to data integrity. Section 15.11 requires validation on an updated platform to be planned and completed in due time before vendor support expires.
The justification has thereby become a duty. Whoever cannot patch has to separate — and separating is architecture work, not a licence question. The draft is not final. Waiting for the final text loses the rebuild time, not the obligation.
On the medical device side the EU coordination group set this out as early as 2019 in MDCG 2019-16 and confirmed it in the revised version: responsibility for updates is shared between manufacturer, integrator and operator, and the operating environment is prescribed by the manufacturer. That is why the operator may not simply patch and remains responsible anyway. Nobody resolves that contradiction with a tool, only with an architecture that controls the crossing.
How to get out of it
Zones and crossings, before anything is procured. Isolation under Annex 11 is only possible without stopping production if it has first been settled which system has to speak to which. That is architecture work and costs no licence.
No agents on validated systems. We install nothing in a qualified environment. Control sits at the crossing: terminate, inspect, forward or reject.
Remote maintenance gets an end. The device maker's access runs through a PAM path: approval per assignment, a fixed time window, session recording, no permanently stored credentials. The validated state is untouched; the standing access disappears.
One source of truth. Identities, rights and states live in one place and under version control. Without it, every zone architecture stays a drawing and every piece of evidence a reconstruction.
Evidence during operations, not before the audit. Who decided what, and when, accumulates continuously — not in the week before the inspection.
Where it pays to start
A survey of the crossings and the remote access paths, before anything is procured. In this order: which validated systems are reachable from the office network today and why; which device maker holds standing access; which systems lose vendor support within the next two years; and what the ability to dispense at the end of your chain depends on when one interface fails.
Sources: EU GMP Annex 11, consultation draft of 07.07.2025, section 15; MDCG 2019-16 rev. 1; BSI-KritisV § 6 with annex 5; the BSI Act, Annexes 1 and 2, as amended by the German NIS2 implementation act (BGBl. 2025 I no. 301). Incidents per contemporaneous reporting.
What you can hand off
-
Zone and crossing design
Which system has to speak to which — the precondition for isolating anything without stopping.
-
End-of-support survey
Which validated systems lose vendor support when, and what that triggers under Annex 11.
-
Controlled vendor remote maintenance
Approval per assignment, a fixed time window, session recording — without touching the validated state.
-
Control at the crossing, not on the device
Terminate protocols, inspect them, forward them. We install nothing on qualified systems.
-
Protection for distribution interfaces
EDI to wholesalers and pharmacies and the serialisation connection, authenticated and monitored.
-
Evidence for NIS2 and inspection
Decisions, access and changes accumulate in operations — not in the week before the appointment.
The four that actually bite
Four documents decide what actually has to be done in this supply chain, and in which order. Also relevant, depending on the business: the serialisation duty for prescription medicines, ISO 27001, GDPR for health data, and GDP for distribution.
-
NIS2 · two tiersNIS2 implementation · health, pharma and medical devices
Pharmaceutical research, the manufacture of pharmaceutical products under NACE C21, and makers of medical devices listed as critical during a health emergency are essential entities. Regular manufacture under MDR and IVDR is an important entity. Two tiers, two sets of duties — and in both an initial report within 24 hours and personal accountability of the management body.
-
GMP Annex 11 · 15EU GMP Annex 11 · consultation draft of 07.07.2025, security section
Applications on platforms no longer supported should be isolated from networks and the internet; the same applies to systems without timely critical patches, which the draft expressly names as a significant risk to data integrity. Validation on an updated platform must be completed before support expires. What used to be a justification becomes a condition carrying rebuild work.
-
BSI-KritisV · annex 5BSI-KritisV · § 6 health sector, thresholds
Medicine production becomes critical above 4,650,000 packages placed on the market per year, a laboratory or laboratory network above 1,500,000 orders, distribution logistics above 4,650,000 packages handled. The telling part is the structure: the distribution logistics system and blood donation control are installation categories of their own. The software is the critical installation.
-
MDCG 2019-16MDCG 2019-16 rev. 1 · Cybersecurity for medical devices
Responsibility for updates is shared between manufacturer, integrator and operator, and the operating environment is prescribed by the manufacturer. The operator therefore may not patch freely and remains responsible regardless. We resolve that at the crossing rather than on the device, with documented ownership on each side.
Sector facts
| Typical engagements | Pharmaceutical production and distribution · medical device manufacturers · laboratory networks |
|---|---|
| Most common triggers | NIS2 applicability, the Annex 11 draft, an incident at a wholesaler, a customer's supplier audit |
| Core regulation | NIS2 · GMP Annex 11 · BSI-KritisV annex 5 · MDR and IVDR |
| What we touch first | Reachability of validated systems, vendor remote maintenance, crossings into distribution |
| On validated systems | No agents · control sits at the crossing |
| Qualification | Changes run along your qualification cycles, not against them |
| At the end of the chain | The ability to dispense depends on interfaces, not only on stock |
| Operating levels | Manual, automated or by playbook — selectable per area |
Asked before the briefing
-
Our systems are validated. Can you do anything at all there?
Yes, and without touching them. We work at the crossing: who reaches the system, by which route, with which approval. That leaves the validated state untouched and is exactly the compensation the Annex 11 draft foresees for systems that cannot be patched. -
Do we now have to isolate everything?
Not everything and not at once. First it is settled which system has to speak to which — then it becomes clear what can genuinely be separated and what needs a controlled crossing. Isolating without that order stops production. -
Do you install agents on laboratory instruments or plant systems?
No. We install nothing in a qualified environment. Detection sits at the crossing and on the traffic, not on the device. -
How do we handle device makers' remote maintenance?
We allow it, but not permanently. Approval per assignment, a fixed time window, session recording, no stored credentials. The manufacturer works as before, and you can evidence who did what and when.
Which of your validated systems loses support next?
The industry briefing surveys crossings and remote access, orders your validated systems by end of support, and shows what the Annex 11 draft touches — in a sequence that fits your qualification cycles.