Pharma Engineering Insights

Monitoring Sterilization Cycles: Temperature, Pressure, Time, Lethality and Process Evidence

Move from measurements to a documented decision through critical parameters, data quality, alarms and complete cycle review.

A Aldo Xhango 9 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Temperature recorder and measurement leads for monitoring a sterilization cycle

The report shows "cycle complete," but an independent probe indicates a delay, the recorder clock does not match the PLC's, and the operator notes an alarm that has disappeared from the screen. The question to be resolved is not whether the machine finished the sequence: it is whether reliable evidence exists that the load received the validated process and remained in the required conditions until unloading.

1. Separate control, recording, and verification

Control regulates the process; recording preserves what happened; verification assesses whether the data meets the applicable criteria. These functions may share components, but the dependencies must be understood. Two identical values on the screen do not necessarily constitute two independent measurements: they could stem from the same sensor, the same conversion, or the same channel.

[QRM] Define the function performed and the effect of failure for each parameter. Evaluate what happens if the sensor remains stuck on a plausible value, if recording is interrupted, or if the connection returns the last valid value. The responses must be designed and tested, without relying solely on the presence of a generic alarm.

A useful matrix links parameter, measurement point, instrument, role in control, role in the record, and acceptance criteria. It allows for identifying hidden dependencies and choosing validation tools. The necessary independence must be consistent with criticality and architecture, not with the number of printed curves.

2. Measure temperature where it answers the question

Chamber temperature describes a condition of the medium; temperature in the load describes the thermal response of the measured object. In the case of liquids, the position of the measurement in the container influences the interpretation of penetration. For porous materials and parts, media contact and difficult geometries must be considered. No single position can be declared representative without evidence.

During validation, distribution and penetration studies identify significant points and variability. These results support the choice of routine measurements. This does not mean installing a permanent probe at every studied point: it means demonstrating the link between routine control, load configuration, and validated performance.

[REGULATORY REQUIREMENT] EU GMP Annex 1, § 8.51, requires justification of the positions of probes used for control and recording, and verification during validation with an independent probe in the same position. The requirement supports the comparability of measurements; it does not prescribe a universal quantity of sensors for every sterilizer.

3. Interpret pressure in the correct context

In steam cycles, temperature and pressure can provide complementary information on the conditions of the medium. Their correlation requires reliable measurements, clear conventions, and understanding of the process. Distinguish absolute pressure from relative pressure: comparing data based on different references can generate a false deviation or hide a real inconsistency.

Chamber pressure alone does not demonstrate the absence of air in the load. A system can reach the expected value while local conditions unfavorable to steam contact persist. The air removal strategy and pertinent tests must therefore remain part of the process demonstration.

For liquid cycles with overpressure, the meaning of pressure differs from that of a saturated steam cycle for porous loads. Container protection and heat transfer must be evaluated according to the specific architecture. Do not automatically apply a correlation check designed for a different technology.

4. Measure time as part of the sequence

Exposure time must begin when the conditions expected by the validated cycle are met. The control sensor reaching the setpoint does not necessarily prove that the entire load has reached the required condition. The phase logic must reflect the developed and verified strategy.

Document the temporal origin of events, the unit of measurement, and the synchronization between the PLC, recorder, historian, and batch management system. Small misalignments can become important when one must determine whether an alarm preceded or followed the end of exposure. The record must preserve sufficient information to reconstruct the sequence.

Sampling interval and archiving frequency are not necessarily the same. A system might acquire data frequently and save only more spaced-out averages. Assess whether this transformation hides significant variations. The choice must derive from the process dynamics and the intended use of the data, with documented criteria.

5. Calculate lethality without losing the assumptions

Equivalent lethality is derived from the integration of the thermal history according to a stated model. For each calculation, preserve the reference temperature, z-value, time unit, data used, and rules applied to missing points. A final number lacking these elements is neither fully interpretable nor comparable with other calculations.

F0 is associated with specific conventions for moist heat; it is not equivalent to the simple time during which the chamber remains at the setpoint. The 2019 EMA guide defines F0 relative to 121 °C and z equal to 10 °C. If a system or method adopts a different reference convention, it must be stated and reconciled before comparing results.

[GUIDEGXP RECOMMENDATION] Verify the calculation with controlled data sets: constant temperature, variable profile, missing point, different time unit, and acquisition interruption. Compare the implementation with an approved independent calculation. Software verification does not replace the scientific justification of the model or the process target.

A target reached on one sensor does not automatically demonstrate performance at all load positions. Furthermore, a calculated lethality does not render media contact conditions, container integrity, or subsequent protection irrelevant. The assessment must include all criteria applicable to the cycle.

6. Distinguish parameters, indicators, and results

Evidence What it supports What it does not prove alone
Recorded temperature Thermal history at the measured point Exposure of every load position
Recorded pressure Pressure trend in the system Absence of air in every geometry
Chemical indicator Response to the conditions for which it is designed Sterility of the material
Biological indicator Response of the selected microbiological challenge Adequacy of the entire physical characterization
«Completed» status Outcome of the implemented logic Automatic acceptance of every GMP requirement
Endotoxin test Analytical result in the defined sample and method Control of all possible pyrogens

The strength of the evidence depends on the consistency of the whole. A satisfactory biological indicator does not nullify a critical deviation of physical parameters. A changed chemical indicator does not authorize release as sterile material. Interpretation rules must be defined before execution and understood by operators.

7. Design alarms that support a decision

Separate operational warnings, machine anomalies, and process failures. A maintenance warning may not compromise the current cycle; a loss of critical measurement may make it impossible to demonstrate compliance even if the machine continues. Classification must derive from the effect, not from the color chosen in the interface.

For each event, specify threshold, delay, applicable phase, automatic action, recording, acknowledgment, and reset condition. Evaluate the consequences of modifiable thresholds or disabled alarms. Critical settings must be controlled and changes traceable.

Test the response under realistic conditions. Simulating a failure does not just mean forcing a message onto the screen: one must verify sequence status, valve or belt behavior, data persistence, and outcome indication. Include post-event recovery, as this is often when traceability is lost.

8. Build a reviewable cycle record

The record must identify the equipment, cycle, recipe and version, date, operators, and load. It must report actual parameters, relevant events, outcome, and references to any deviations. If some data resides in separate systems, the link must be stable and usable during the review.

A graphic representation facilitates reading but does not replace the original data and necessary metadata. Preserve the information with which the graph was built and document filters, averages, or rounding. PDF export does not, by itself, prove that the electronic record is complete.

Define who performs the operational review and who evaluates exceptions. The process must also intercept events not summarized in the final message. A review-by-exception requires reliable, validated, and maintained rules; it cannot consist of just reading a green indicator.

9. Example: discrepancy between two probes

In an illustrative example, the control sensor regularly reaches the exposure phase while the recording channel shows a slower trend. The team keeps both sets of data and verifies identification, position, configuration, calibration, and synchronization. It does not choose the most favorable curve to declare the cycle compliant.

If the discrepancy stems from a channel configured with a different filter, its effect on cycles already performed must be evaluated and the configuration corrected via change control. If, instead, a physical problem emerges, the repair must be accompanied by the necessary checks. In both cases, the decision on the material remains separate from the technical repair.

The conclusion documents which data is reliable, based on what evidence, and with what limitations. If the available information does not allow for demonstrating the required process, the absence of an alarm does not fill the gap. The investigation must recognize uncertainty instead of transforming it into presumed compliance.

10. Calibration and management of out-of-tolerance measurements

Calibration must cover the intended use of the instrument, including the relevant points of the operating range and the pertinent measurement chain. Checking only the sensor may not include errors introduced by the transmitter, conversion, or configuration. Establish what is verified and what remains excluded.

Frequency derives from criticality, stability, conditions of use, history, and applicable requirements. Do not use a fixed interval as a substitute for assessment. An unexpected drift requires an investigation that considers the last known reliable state, the extent of the error, and the decisions based on that measurement.

Retrospective assessment must identify potentially involved cycles and available complementary information. A second measurement can be useful only if its independence and reliability are demonstrated. Preserve the reasoning and the data: correcting the sensor resolves the future, it does not automatically clarify the past.

11. Monitor performance over time

Trending can compare heating times, exposure stability, vacuum behavior, drying, cooling, and alarm frequency. Compare homogeneous loads and recipes, distinguishing planned changes from anomalies. An overall average of different configurations can hide a specific deterioration.

Define warning signals before acceptance criteria are exceeded, when process knowledge allows. These signals support investigation and maintenance, but they must not be confused with new, unapproved release limits. Any change to operating criteria requires the established document path.

Routine control and requalification meet complementary needs. Routine data shows daily behavior; studies performed periodically or following changes verify aspects that routine measurement does not observe directly. A good historical series does not authorize ignoring a verification required by the validated strategy.

12. Technical review checklist

Before approving the monitoring system, verify the relationship between measured points and load performance, instrument traceability, dependencies between channels, and record completeness. Also check units, clocks, acquisition, archiving, and behavior in the event of power loss. Each element must contribute to a concrete decision.

The main red flags are curves without identification, average values without source data, lethality without model parameters, deleted alarms, and recipes without a version. Effective monitoring makes the cycle reconstructible and clarifies the limitations of the available evidence. It is this capability, in addition to the quality of the instrumentation, that supports a reliable review.

To make the review sustainable, prepare an approved example of a complete record and one with representative deviations. Training must show which elements to check and when to stop the evaluation to request an in-depth analysis. Verify that the operator knows how to distinguish the acknowledgment of an alarm from its resolution and from the acceptance of the material.

Also maintain a matrix of responsibilities between production, engineering, microbiology, automation, and quality. Anomalies often cross multiple disciplines: an inconsistent curve can stem from a measurement, a data transformation, or the real process. Clear responsibility reduces the risk that each group considers the problem already assessed by another.

References and pathways

Sources verified September 23, 2026: EU GMP Annex 1 and Annex 11; EMA, guideline on sterilization, 2019; ISO 11140-1:2014, official catalog. Original operational indications must be adapted to the validated process.

Consult Sterilization & Depyrogenation Systems, moist heat cycle development, automation and data integrity, and Critical Utilities Systems.

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →