Our services for GxP IT administration
In the pharmaceutical and chemical industry, IT infrastructure is not just an operational necessity: it is a regulatory requirement. Every system that collects, processes, or stores GxP-relevant data must be administered, qualified, and validated in accordance with applicable guidelines. cube one GmbH provides comprehensive IT administration services tailored specifically to GxP-regulated environments.
Our team of experienced IT administrators and GxP specialists supports you in operating your laboratory and production IT reliably, securely, and in compliance with FDA 21 CFR Part 11, EU-GMP Annex 11, and GAMP 5 requirements. For orientation on NIS 2, the BSIG and further IT security requirements, see the Regulatory Expertise Center.
Reference: Central Chromeleon administration across six servers and 300 users, including expansion to Mexico. Read case story
BSI IT-Grundschutz Check
For information security and IT operations, the public BSI IT-Grundschutz Check is available: eight questions on the ISMS, protection needs, modules, risk analysis, emergency management, authorisations, logging and the supply chain according to the BSI IT-Grundschutz publications.
Start the Grundschutz CheckNIS 2 Check
For scope, registration, incident reporting and risk management, the public NIS 2 Check is available: eight questions according to Directive (EU) 2022/2555, the BSI Act and the BSI guidance for NIS 2-regulated entities.
Start the NIS 2 CheckIT pathfinder
Which IT landscape is your focus?
Choose your starting point. You get a focused entry with relevant deep links and a direct contact path.
Instrument PCs and lab clients
Wir härten Geräte-PCs mit Kiosk-Modus, Gruppenrichtlinien und Zugriffssperren, betreiben Autologon-Konzepte sicher und dokumentieren jede Änderung für QA und Audit.
Servers, Active Directory and backup
On-Premise, hybrid oder Cloud: wir administrieren Infrastruktur mit RBAC, Patch-Management, Backup-Strategie und Wiederherstellungstests inklusive IQ/OQ-Nachweisen.
Monitoring, change and continuity
Proaktive Überwachung, dokumentiertes Change Management und belastbare Betriebsprozesse halten qualifizierte Systeme audit-ready. Für Zugriffsrechte empfehlen wir RADAR.
The most common cause of failure in GxP labs is not hardware but undocumented change: a patch, user account or configuration without change control. We apply changes only with impact assessment, testing and evidence, keeping the qualified state traceable in operation.
What you get
Five building blocks cover operations and evidence. Each step ends with a result you can present in audit.
Infrastructure & network
Wir administrieren Server und Netzwerk On-Premise, hybrid oder in der Cloud mit GxP-konformer Konfiguration, Patch-Management und Need-to-Know-Zugriff.
Dokumentierte Basiskonfiguration und Betriebsverfahren für Server und Netzwerk.
Identity & access
Active Directory, RBAC, Passwortrichtlinien und SSO werden so administriert, dass Data Integrity und Part 11-Anforderungen im Alltag eingehalten werden.
Rollenmodell mit nachvollziehbaren Berechtigungen und Provisioning-Prozess.
Backup & recovery
Backup-Strategien mit regelmäßigen Wiederherstellungstests und vollständiger Dokumentation, weil Datenverlust im GxP-Umfeld nicht tolerierbar ist.
Getestete Backup- und Restore-Nachweise für GxP-relevante Systeme.
Monitoring & stability
Proaktive Überwachung erkennt Probleme, bevor sie die Produktionskontinuität gefährden. Für regulierte Umgebungen setzen wir auf RADAR.
Alarmierung, Eskalation und Betriebsprotokolle für kritische Systeme.
Change & qualification
Änderungen an qualifizierten Systemen laufen über dokumentiertes Change Management mit Impact Assessment und Test. Infrastrukturkomponenten qualifizieren wir nach IQ/OQ.
Change-Control-Fälle und Qualifizierungsnachweise für Infrastruktur und Betrieb.
IT-Landschaft und Betriebsumfang klären?
Book an initial callOur IT administration expertise
Standard IT
- Patch ohne Change Record
- Backup ohne Restore-Test
- Monitoring ohne Audit Trail
GxP-integrated
- Change Control vor jeder Änderung
- Getestete Wiederherstellung mit Protokoll
- Betriebsnachweise für Inspektionen
GxP-specific focus areas
Access rights under control
Mit RADAR überwachen Sie Dateizugriffsrechte in regulierten Umgebungen und erkennen Abweichungen, bevor sie zu Findings werden.
AI agents & workflows
Wiederkehrende IT-Aufgaben automatisieren wir mit dokumentierten Workflows und KI-Agenten, ohne den GxP-Nachweis aus dem Blick zu verlieren. Mehr unter AI agents & workflows.
Knowledge base
Lab11: proven solutions on the shelf
In our internal software Lab11 we maintain a knowledge base for every system we administer. Incidents, release notes, operating guides and settings required for compliant operation under EU GMP Annex 11 and 21 CFR Part 11 live in one place, versioned and audit-ready.
For existing and new customers that means: when a fault pattern has been solved before, the fix is often already on the shelf across customers, instead of starting from scratch on every ticket.
Regulatory framework: Annex 11, Part 11 and GAMP 5
IT-Administration in GxP-Umgebungen folgt diesen Regelwerken:
- EU-GMP Annex 11: regelt computergestützte Systeme über den gesamten Lebenszyklus inklusive Betrieb und Change Control.
- FDA 21 CFR Part 11: definiert Anforderungen an elektronische Aufzeichnungen, Signaturen und Zugriffskontrolle.
- ISPE GAMP 5, 2nd Edition: liefert den risikobasierten Rahmen für Kategorisierung, Qualifizierung und laufenden Betrieb.
FAQ: IT administration in GxP environments
IT reference projects at a glance
Chromeleon landscape, lab IT hardening and LIMS rollout from our programme.
IT-Administration
Chromeleon global
Zentrale Chromeleon-Administration über Insellabore hinweg, inklusive Expansion nach Mexiko.
View case story
IT-Administration
Spektralphotometer Lab IT
Härtung und Qualifizierung eines Spektralphotometers: Kiosk, PowerShell-Audit-Trail, Backup und Virtualisierung.
View case story
IT-Administration
LabWare LIMS-Rollout
Globaler LabWare-LIMS-Rollout plus SAP-Update: PMO, Change Management und IT-Betrieb.
View case story