GB/T 22275.8-2026Requirements of conduct for good laboratory practice - Part 8: The application of cloud computing in GLP laboratories (English PDF)
良好实验室规范实施要求 第8部分:云计算在良好实验室规范试验机构中的应用
Open the GB/T 22275.8-2026 preview as PDF
This is a limited preview
Buy now to download the full PDF (44 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
May 25, 2026
Implementation date
September 1, 2026
Scope
GB/T 22275.8-2026 is the English-translated version of 良好实验室规范实施要求 第8部分:云计算在良好实验室规范试验机构中的应用.
GB/T 22275.8-2026 is the Chinese national standard covering GLP in a laboratory whose data lives in someone else's data centre - the validation of the system, the control and integrity of the records, the audit trail, the archiving obligation that outlives the contract with the provider and the inspector's right of access. Part 8 of the GLP series, first edition, in force since 1 September 2026. It was issued on 25 May 2026 and has been in force since 1 September 2026, as a first edition. The document is under the responsibility of the Standardization Administration of China. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.
Document preview — GB/T 22275.8-2026
National Standard of the People's Republic of China
- ICS
- 03.120.20
- Classification
- A 00
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 2 Cloud computing deployment mode
- 4 Overview of Cloud Computing
- 4.1 Concept
- 5.1 Responsibilities of the Testing Organization
- 5.2 Requirements
- 5.3 Implementation of Cloud Computing Solutions in the GLP Framework
- 5.3.2 Risk Assessment and Selection of Cloud Computing Services
- 5.3.3 Cloud Service Provider Evaluation
- 5.3.4 Service Level Agreement (SLA)
- 8 The application of cloud computing used in GLP laboratory ICS
Foreword
GB/T 22275.8-2026 | Requirements of conduct for good laboratory practice - Part 8: The application of cloud computing used in GLP laboratory
GB/T 22275.8-2026 English version. Requirements of conduct for good laboratory practice - Part
2 Cloud computing deployment mode
4.4 Service Model The cloud computing service models of GLP pilot organizations are mainly divided into the following types according to the types of computing resources provided.
a) Infrastructure as a Service (IaaS). For GLP pilot sites, IaaS solutions provide hardware and network (including physical and virtual) It provides hosting and maintenance services for components and ensures the availability of storage space, computing power and resources.
b) Platform as a Service (PaaS). In GLP testing facilities, the hardware and environment are provided by the platform. The platform provides data and document management capabilities. Functionality typically integrates migration, sorting, and storage services. GLP pilot facilities are still responsible for system configuration and software management. responsibility. Example
1.Cloud service providers support the deployment and implementation of Laboratory Information Management Systems (LIMS) by providing application servers and databases.
c) Software as a Service (SaaS). Under the GLP framework, the SaaS model provides experimental organizations with data generation/analysis and document management capabilities. Applications with functions such as [list of functions] are developed, installed, maintained, and updated by cloud service providers. The hardware is typically deployed on [platform name]. Data centers (often using public cloud models to support multi-user access). These data center hosting services are typically provided by software vendors. Subcontracting implementation to third parties. All security design is guaranteed by the cloud service provider (typically through other subcontractors). GLP Testing facilities need to connect to the system via a general or shared platform with specific access permissions to use the software. Training is usually provided. As part of the service. GLP pilot facilities have limited computational intervention permissions to internally defined user access rights. This also includes root access. Configure the application according to the intended use by the testing facility (including security settings during implementation). SaaS usage includes identity verification. Verify the connection to the system and enter data. Example 2.A laboratory electronic recording system can be hosted in a public cloud and can collect raw data via electronic devices. This data is transmitted directly from [the cloud] through a secure network. The device is transferred to a private (secure) zone also hosted in the public cloud for storage. Depending on the selected cloud computing service model, the management responsibility for the main components of the cloud computing solution lies between the testing organization and the cloud service provider. The overall framework for dividing the space is shown in Figure 3. Figure
3.Division of Management Responsibilities for Key Components of Cloud Computing Services between GLP Pilot Organizations and Cloud Service Providers. Cloud computing in a 5GLP environment
4.1 Concept
4.1.1 Cloud computing can be defined as a network model that supports on-demand access to shared, configurable pools of computing resources. For example, cloud computing can be defined as "a..." This enables ubiquitous, convenient, and on-demand access to shared configurable computing resources (such as networks, servers, storage, applications, and services) via a network. This model allows for rapid deployment and release of resources by minimizing management input or service interactions. (Related terms. network, server, etc.) See Appendix A for details.
4.1.2 Cloud computing has five basic characteristics, four deployment modes and three service modes, as shown in Figure 1.
4.2 Basic Features The basic characteristics of cloud computing include the following.
a) On-demand self-service allows users to access computing resources independently without needing to interact manually with service providers;
b) Network access. Computing resources can be accessed via the network and support various heterogeneous client platforms (such as mobile devices and workstations);
c) Resource pooling. The supplier's computing resources are centrally managed through a single-tenant or multi-tenant model to provide services to multiple users. Physical and virtual resources (such as storage, processing power, memory, and network bandwidth) can be dynamically allocated and reallocated according to user needs;
d) Rapid elasticity (scalability). Resources can be rapidly expanded or contracted according to demand, and can be automatically allocated and released elastically;
e) Measurable services. Cloud systems optimize resource usage by reasonably metering capabilities based on service type (e.g., active user accounts). The system can be monitored, measured, controlled, and reported, providing transparency for both suppliers and users (pay-as-you-go).
4.3 Deployment Mode Cloud computing can be deployed in different models depending on the type of use. The main difference lies in the availability of cloud infrastructure, which includes the following four types. Deployment mode. See Figure 2 for cloud computing deployment mode.
a) Private Cloud. In the GLP framework, a private cloud refers to computing resources deployed exclusively for the exclusive use of the contracted pilot institution or its affiliated organization. Managed services. These clouds are built on private internal networks or employ fully isolated access architectures to ensure that the infrastructure is dedicated to... Contracted trial institutions, regardless of whether the cloud service is provided by an external cloud service provider or internally.
b) Community Cloud. In the GLP framework, a community cloud refers to a cloud consisting of multiple testbeds with similar needs (such as security and compliance requirements). This is a shared cloud infrastructure. Access is not public; it is limited to specific user groups with shared needs. The cloud environment can be operated by member organizations or third-party organizations.
c) Public Cloud. In the GLP framework, public cloud refers to computing resources available for use by the public or large groups (such as entire industry sectors). Managed services, which are provided by the respective cloud service providers in their own facilities/data centers.
d) Hybrid Cloud. In the GLP framework, hybrid cloud refers to a combination of public and private clouds. The experimental organization uses both public and private cloud services. It has its own private cloud and can establish a two-way connection to enable the two to work together to form a unified system. Figure
5.1 Responsibilities of the Testing Organization
5.1.1 Test Facility Management (TFM) The testing facility manager is responsible for ensuring that the GLP testing facility and the systems supporting GLP activities comply with GLP specifications. When IT operations originate from this... When migrating locally controlled servers to a cloud solution, regardless of whether an internally managed cloud platform is used (as part of a pilot facility or its affiliated organization)... Whether implemented through external cloud service providers or in separate units, the testing organization should maintain appropriate understanding, awareness, and oversight of the system and its operation. Implement effective control.
5.1.2 Cloud Service Delegated Management Due to the complexity of cloud services, administrators of experimental institutions can delegate the signing and management of such service contracts to entities responsible for supplier selection and contract fulfillment. Package and oversight by professionals or specialized internal departments. Therefore, transparency of agreements and obligations among all relevant parties is a key element, allowing for [further details regarding the implementation]. The different services offered allow for scalable hierarchical management of details. It is important to emphasize that even when outsourced, TFM should still be responsible for the testing machine. The system is responsible for GLP compliance.
5.1.3 System Administrator Access Control System administrators have access to both real-time and archived data and documents. When data is hosted by a cloud service provider, data access should be clearly defined. Inquire about the context and operational procedures. Granting administrator privileges to personnel with a potential interest in the data and/or documents is prohibited. Clear guidelines should be established and implemented. Risk mitigation strategies and controlled procedures are implemented to ensure data integrity, quality, and availability, regardless of whether the system administrator is located at the testing facility or elsewhere. Supplier's office.
5.1.4 Verification of Cloud Services The project leader should ensure that all computerized systems used in the research (including virtual components that may be hosted locally or in the cloud) are properly configured. Verified.
5.1.5 Archivist The archivist is responsible for archival management. If GLP archives are stored in a cloud solution, the archivist may need to consult with experts. To assist in handling technical issues. Nevertheless, the archivist remains responsible for ensuring.
a) The archiving conditions ensure the integrity of the archived electronic records;
b) Controlled management of access to archives;
c) Establish an indexing system to achieve ordered storage and retrieval of records;
d) The migration process of archived electronic records shall be effectively controlled and documented;
e) Establish a process for regular readability and data integrity checks;
f) Develop a process (exit strategy) to ensure that data remains readable after it has been migrated from the cloud environment to the test facility.
5.1.6 Quality Assurance A quality assurance (QA) program should ensure that GLP compliance is maintained. This applies to cloud computing used in GLP studies. The solution, like any other computerized system, should be verified through quality assurance to ensure compliance with GLP specifications.
5.2 Requirements
5.2.1 GLP requirements for cloud services GLP requirements for computerized systems and managed services (or cloud services) are mainly outlined in GB/T 22278-2008 and GB/T 22272. The description is provided in GB/T 22275.6.Under different cloud computing service models, GLP-related provisions as specified in GB/T 22278-2008 apply. The requirements are shown in Table 1.
5.2.2 Requirements for cloud service providers The cloud service provider of the testing institution shall meet all the requirements for suppliers in GB/T 22275.6.
5.2.3 Requirements for the Division of Responsibilities in Cloud Services Cloud services or managed services (such as platforms, software, data storage, archiving, backup, or processes as a service) should be integrated with services from any other vendor. They should be treated equally, and a written agreement should be signed to clarify the roles and responsibilities of each party.
5.2.4 TFM's responsibility for risk assessment and control of cloud services TFM is responsible for evaluating related services and assessing risks to data quality, integrity, and availability. TFM should... Recognizing the potential risks arising from uncontrolled use of cloud services, and taking steps to identify these risks and their impact on GLP compliance. Meanwhile... Appropriate risk control measures should be developed and documented.
5.2.5 Transparency and Protocol Control of Cloud Service Subcontracting Model Cloud service providers can provide services directly or participate as subcontractors to other vendors. TFM handles all supply chain matters related to GLP. Subcontractors should be appropriately managed, and their activities must be transparent to TFM. The written agreement between the trial organization and the cloud service provider should clearly state... Determine whether service subcontracting is permitted (see 5.3.4).
5.3 Implementation of Cloud Computing Solutions in the GLP Framework
5.3.1 Key Elements When using cloud services to provide, install, configure, integrate, verify, maintain, modify, or retain computerized systems, the following four key points should be considered. The criteria will determine whether a GLP testing organization can prove its compliance with GLP principles.
a) A detailed risk assessment (based on a description of the cloud solution);
b) A comprehensive evaluation of cloud service providers, including relevant pre-use audits and periodic reviews;
c) Define the Service Level Agreement (SLA) that is directly related to the operational activities and services to be provided;
d) Validation of computerized systems hosted in cloud services.
Note. The above requirements also apply to physical servers and virtual servers.
5.3.2 Risk Assessment and Selection of Cloud Computing Services
5.3.2.1 Risk management should be integrated throughout the entire lifecycle of all computerized systems, taking into account data quality, data integrity, and data reliability. Use sex.
5.3.2.2 Before adopting a cloud computing solution, TFM should identify and describe potential failure modes and assess their relevance to GLP compliance. Risks (including likelihood and extent of impact) should be identified, and effective mitigation measures should be developed where applicable. The development, deployment, and management of cloud computing services should... Ensure data quality, data integrity, and data availability without compromising the GLP compliance of the testing facility.
5.3.2.3 Before making any choice, a detailed description of the expected use of the cloud solution and its related impacts should be clearly documented. Risk Assessment Step The steps include, but are not limited to, the following.
a) Expected goals and functions, including system requirements, user requirements, and system limitations.
b) Infrastructure and Applications. The scope of the infrastructure, network/platform, and applications expected to be provided.
c) The impact of using cloud computing-based systems on GLP compliance, particularly regarding data migration and storage (not an exhaustive list). 1) The existing system anticipates the processing and modification of new data. The data migration steps need to be carefully identified and described; 2) New risks related to data quality. Risks associated with newly provided applications used for collecting, generating, or analyzing data. (System and data reliability, availability, and backup solutions for system failures); 3) New risks related to data integrity and data availability. control level of remote data access, data protection level, and data... The secure location of physical storage (physical infrastructure access permissions, disaster recovery strategy, recovery time target, and recovery point target) (Regarding the geographical location of the data hosting server and the long-term integrity of electronically archived data), for SaaS, due to the pilot institutions The software itself is typically inaccessible at the time of release, and end users need to develop business continuity plans for GLP testing facilities. When developing disaster recovery plans and exit strategies, their potential impact on data integrity and data availability should be carefully assessed. 4) Regarding the system architecture (including the system architecture of the testing facility and the system architecture of the cloud service provider), organizational structure, and operating model. Influence; 5) Impact on data ownership protection; 6) Impact on the capabilities of researchers, project leaders, quality assurance personnel, and record keepers, particularly training needs.
d) Expected identified risk control measures, including (not an exhaustive list). 1) Implement appropriate controls to maintain or verify data quality, data integrity, and data availability, and meet data audit requirements. Require; 2) Effective audit trail functionality when appropriate.
e) Establish cloud service provider selection criteria, including requirements for compliance with specific quality specifications and supplier failure contingency plans (such as disaster recovery plans). The completeness of solutions for difficult recovery, security measures of cloud service providers, etc. (see 5.3.3).
f) Service migration plan developed in response to service termination.
5.3.2.4 When selecting a cloud solution, a clear and complete description and implementation plan should be developed, including the following.
a) Cloud service provider. company name and address (if known, the address of the data center), contact person, contract number.
b) Details of cloud service provider subcontractors related to GLP compliance. technical role, name and address, contract number.
c) Overview of the selected solution. including a detailed functional description, the difference between expected and actual functions provided, and the selected services/products. Relevant parties and delivery locations.
d) Detailed specifications for cloud service provider execution activities (see Table 1), particularly between cloud service providers, their subcontractors, and pilot organizations. The division of technical tasks, roles, and responsibilities (see 5.3.4).
5.3.3 Cloud Service Provider Evaluation
5.3.3.1 The management of cloud service providers is crucial to ensuring service quality and compliance. The trial organization's assessment of cloud service providers... The expectation, namely ensuring that the service reaches a suitable level for GLP purposes, should be specified in the Service Level Agreement (SLA) (see 5.3.4).
5.3.3.2 Documented regulations for selecting cloud service providers should be established.
5.3.3.3 The capabilities and reliability of cloud service providers are key factors when selecting a product or service provider. It may be necessary to assess the cloud service provider's capabilities and reliability. Suppliers should be audited, and the decision to audit cloud service providers should be based on a documented risk assessment. The audit team may include... Users, quality assurance personnel, IT experts and/or external experts.
5.3.3.4 Cloud service providers may subcontract some activities to other vendors. In any case of subcontracting, the testing organization has the final say. The assessment and verification of the responsibility for these cloud services will ensure that they do not affect the GLP compliance of the pilot facility. During the cloud service provider assessment, the cloud services should be verified. What quality system (if any) does the cloud service provider (including relevant subcontractors) actually operate? The cloud service provider (and subcontractors) may hold [certificates of authority/reputation]. Certified quality systems. Testing organizations may consider systems that contribute to their GLP compliance.
Note. If the cloud service provider has the capability to provide a certain level of security before deciding to host specific data (such as personal data, medical data, health data), then this applies. Specific certifications. TFM's responsibility is limited to GLP compliance matters.
5.3.3.5 The testing organization may also choose to outsource the evaluation of cloud service providers to external experts; the suitability of such evaluation should be determined by TFM in terms of quality. The assessment was conducted with the support of the quality assurance department.
5.3.3.6 The following routine items (not an exhaustive list) may be involved in the evaluation process.
a) The cloud service provider's quality system (if any) (including subcontractor and standard operating procedure management);
b) Document recording process;
c) Personnel management (including training);
d) Confidentiality and security;
e) Data access control;
f) Location and technology used;
g) Confirmation of equipment involved within the system scope;
5.3.4 Service Level Agreement (SLA)
5.3.4.1 Documents describing the terms of cloud service operation may use different names. contracts, quality (assurance) agreements, technical specifications, etc. This document... Use the term Service Level Agreement (SLA) consistently.
5.3.4.2 Risk assessments, system verifications, cloud service provider assessments, and service level agreements should all clearly state that when the testing organization implements cloud computing... The calculation already covers the relevant requirements for data quality, data integrity, and data availability. GLP pilot organizations and cloud service providers should... Sign formal agreements. These agreements should clearly define the responsibilities of cloud service provider subcontractors and stipulate the rights of any third parties involved in the service to the data. The responsibilities undertaken.
5.3.4.3 The SLA is the core document defining all aspects of the collaboration between the GLP pilot organization and the cloud service provider. The SLA should cover all... Related aspects include, but are not limited to. division of responsibilities, subcontractor usage, documentation, performance, archiving, training, communication, reporting channels, auditing, and verification.
5.3.4.4 The use of subcontractors by cloud service providers should not affect the data quality, data integrity, data availability, or overall performance of the testing institution. GLP compliance. Appropriate arrangements should be made to ensure the orderly transfer of activities, data, or services from the contractor to subcontractors. Subcontracting should be carried out in accordance with testing standards. The authorization is explicitly stated in the service level agreement between the provider and the cloud service provider.
5.3.4.5 Cloud service providers themselves are generally not required to fully comply with GLP specifications; all they must do is ensure data quality, data integrity, and data availability. All sex-related requirements should be included in the SLA. The SLA should enable cloud service providers to understand and assume responsibility for their data and subcontracted services. The responsibility for commercial data. The testing organization should conduct an investigation to ensure that the services provided do not compromise data integrity and generally support [the data]. GLP compliance requirements.
5.3.4.6 The roles and responsibilities of the testing institutions and cloud service providers are required to be as follows:
a) The roles and responsibilities of the testing organization and the cloud service provider should be described.
b) TFM bears full responsibility for the GLP compliance of its computerized systems lifecycle and IT support services, even if cloud services provide... Suppliers provide these services.
c) The cloud service provider is responsible for delivering cloud-based services that enable the testing facility to meet all applicable GLPs specified in the SLA. Require.
d) If the cloud service provider subcontracts activities to other vendors, this should be specified in the SLA. The subcontractor and subcontracted activities should be listed in the SLA. A list of actions and related responsibilities.
e) The draft SLA should be reviewed by the Quality Assurance Department to ensure that all aspects of GLP compliance are met; however, the SLA approval... Ultimately, the responsibility for the accuracy of the results still lies with TFM.
f) The SLA should specify the model for periodic review of the SLA. The SLA should also specify the possibility of auditing the cloud service provider. Sexuality, and incorporate it into the quality assurance plan of the testing institution.
g) All documentation from both parties (standard operating procedures, personnel records, reports, change control documents) should reflect the relevant information in the SLA. All parties shall maintain the specific documents required by the SLA.
5.3.4.7 The SLA should describe the respective responsibilities of the cloud service provider (and any subcontractors) and the testing organization throughout the entire lifecycle of the supported system. This may include the installation, configuration, integration, verification, maintenance (e.g., via remote access), modification, retention, or decommissioning of the system. At a minimum, It covers the following points.
8 The application of cloud computing used in GLP laboratory ICS
03.120.20 CCSA
00 National Standards of the People's Republic of China Good Laboratory Practice Implementation Requirements Part
8.Cloud Computing in a Good Lab Application in standard testing institutions Published on 2026-05-
25 Implemented on 2026-09-
01 State Administration for Market Regulation The State Administration for Standardization issued a statement.
1.Scope This document specifies the application requirements for cloud computing in Good Laboratory Practice (GLP) testing facilities, including an overview of cloud computing and its application in GLP environments. Expectations and summaries of cloud solutions inspections by cloud computing and GLP compliance monitoring bodies. This document applies to all cloud-based solutions in testing facilities that comply with Good Laboratory Practices, including systems already in use. Cloud services can be services provided internally by the testing organization or its affiliated company, or services outsourced by a contracted service provider. When through... The contract stipulates that the service may be provided directly by the cloud service provider or indirectly through a supplier. The cloud service provider may also provide the entire service. Some or all services may be subcontracted to third parties. This document applies to all types of cloud services.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 44 pages — is available in the English PDF.
How to Buy GB/T 22275.8-2026
- 1Add to cart. Click the "Buy GB/T 22275.8-2026" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 22275.8-2026
$365.00