The pharmaceutical supply chain is no longer just a chain of physical materials, but rather a complex series of data, data-based decisions, and delegated responsibilities for that data. FDA’s CDER FY2024 Site Catalog reported 4,619 manufacturing sites globally, reflecting the broad scale of the regulated manufacturing network supporting the U.S. drug supply. Within that network, CDMOs represent a major and growing component: A Nice Insight Publication, “Our Update on, and Opinion of, the CDMO Landscape” (2026 Edition), identified 1,934 CDMO manufacturing sites globally. This information shows the scale of the CDMO presence compared with the total number of FDA-registered manufacturers.
CDMOs are now deeply embedded in the global pharmaceutical supply chain. They develop processes and materials for clinical trials, manufacture intermediate and finished products, perform analytical testing, maintain batch records, support regulatory filings, and increasingly operate the digital systems that generate the data used to make release, stability, deviation, validation, and regulatory decisions. In practical terms, a sponsor’s product quality decision is increasingly dependent on data generated, reviewed, stored, and transferred across multiple companies, platforms, laboratories, and jurisdictions.
Branded companies are increasingly dependent on this portfolio of services, creating convergence of risks. Although commercial agreements are in place, these entities are producing the data for which the market authorization holder (MAH) remains accountable. In practical terms, the MAH retains ultimate accountability for ensuring the integrity of this data by confirming that third-party companies have appropriate data integrity programs and controls in place for all data they generate. During PAI audits, the MAH may likely be challenged to demonstrate the integrity of all related data, even if that data was generated by a third-party CDMO.
This risk does not end with the contractual agreement for the commercial product. Data integrity is reaching deep into development. Where CDMOs operate in a manufacturing science and technology (MSAT) style environment, it is common for these organizations to have been historically set up with flexible processes and methods and research-and-development-oriented cultures. As a result, building robust data integrity programs can require significant shifts in operating principles and culture and can pose significant adoption challenges. Well-documented cases have shown that MSAT programs can create doubt about the integrity of development data.
A Lachman scan of FDA Form 483s and warning letters estimated that data integrity citations at CDMOs increased by approximately 120% from 2024 through 2025. Even if the exact CDMO-specific citation rate varies based on methodology and citation-tagging practices, the direction of travel is clear: as outsourced manufacturing grows, the amount of regulated data crossing company boundaries will grow with it.
FDA and HHS have already warned that pharmaceutical supply chains are difficult to fully understand. HHS/ASPR states that the U.S. Government has limited visibility into the supply chain for most pharmaceuticals, that not all approved sites are continuously active, and that available data are not collected in a way that clearly describes current end-to-end production. This is evidenced by the FDA’s Drug Supply Chain Integrity page (here), which similarly notes that the drug supply chain has become increasingly complex as it extends beyond U.S. borders and that threats such as counterfeiting, diversion, theft, and falsified or unsafe drugs can affect the integrity of the U.S. drug supply.
While the physical supply chain may be hard to trace, the data supply chain may be even harder to verify. FDA’s 2022 draft guidance on Risk Management Plans to Mitigate the Potential for Drug Shortages (here) encourages stakeholders to proactively identify, prioritize, and mitigate hazards that can cause supply disruptions and states that the guidance is relevant to stakeholders with oversight and control responsibilities for drug quality and contract establishments. That logic should be extended to data integrity: if data from a CDMO supports batch release, stability, process validation, or regulatory submissions, then data governance is part of supply-chain risk management.
The future pharmaceutical supply chain will be judged not only by whether the product can be traced, but also by whether the data supporting that product can be trusted. Are you incorporating robust data integrity assessments into your vendor audits and/or assessments? Lachman works with global CDMOs to prepare them for their own data integrity audits and to create holistic DI programs. We enhance not only the compliance profile of CDMOs, but also the commercial value for outsourcing organizations by helping them see what may have been missed. Interested? Contact us now!

