Where CGT BLAs Actually Get Stuck: A Taxonomy

The Center for Biologics Evaluation and Research (CBER) does not publish CRLs. But sponsors, investors, and reviewers now have enough public and post-hoc information (SEC 8-K filings, press releases, systematic literature reviews of CRLs, and CBER conference remarks) to build a reliable taxonomy of where CGT BLAs get stuck. A recent systematic review of CGT CRLs found that CMC deficiencies dominate the picture, and within CMC, six subdomains recur: manufacturing design and control, process validation, materials, product characterization, analytical procedures, and facility inspection.1

Sitting under those six subdomains, however, is a more useful cut for practitioners. The recurring data-standards problems that generate CRL language, informational requests, and mid-cycle meetings tend to fall into five categories.

10+ Currently approved CGT products that received at least one CRL before approval, all citing CMC concerns2
5-10% Share of new CGT INDs placed on clinical hold by CBER, most commonly for CMC deficiencies including inadequate product characterization or potency assays3
3 CRLs CGT programs delayed by FDA in a single month (July 2025): CAP-1002, UX111, Kresladi, primarily on CMC and manufacturing data grounds4

The Five Recurring Data-Standard Failure Modes

Across the CRL corpus, the recurring failure modes cluster in a way that makes them tractable if you look at them upstream. This taxonomy is what late-stage sponsors should be scoring themselves against roughly nine months before submission.

FAILURE MODE 1

Product characterization gaps

Insufficient granularity on cell subset composition, transduction efficiency distributions, or vector genome integrity data such that FDA cannot confirm the clinical lots and commercial lots are the same product.

FAILURE MODE 2

Potency assay data package

A single potency test that does not reflect mechanism of action, or a matrix that lacks bridging data across process changes. Perennial driver of CRLs and informational requests.

FAILURE MODE 3

Chain-of-identity and traceability

Patient-specific manufacturing where the digital thread from apheresis to infusion is not reconstructable end-to-end, or where the systems tracking chain-of-custody are not tied into the quality record.

FAILURE MODE 4

Process validation and comparability

Insufficient bridging data across sites, scales, or process changes. Very common as sponsors move from clinical to commercial facilities or add decentralized manufacturing.

FAILURE MODE 5

Facility, analytical, and materials data

Facility readiness (recent Pre-License Inspection observations), analytical procedure validation status, or raw material qualification data that fails to demonstrate consistent, controlled sourcing.

CROSS-CUTTING

Data integrity and 21 CFR Part 11

The data may exist. But if it lives in spreadsheets, disconnected LIMS, or systems without audit trails and electronic signatures, FDA reviewers cannot rely on it to support the submission. Cross-cuts every category.

None of these categories are new. What is new is the volume of programs now hitting BLA review with all five simultaneously unresolved. The industry has scaled clinical activity faster than it has scaled the data infrastructure required to make a CGT BLA reviewable in one cycle.

Chain of Identity and Chain of Custody as a Data Problem

Chain of identity (COI) and chain of custody (COC) are usually framed as logistics problems. That framing is the first mistake. For an autologous CGT, COI and COC are data problems that touch logistics. FDA and EMA reviewers do not care that a courier moved a bag from Boston to Frederick. They care that the patient identifier on the apheresis product at collection matches the patient identifier on the drug product at infusion, and that every intermediate state was logged, timestamped, and attributable.5

In practice, most sponsors run their COI and COC across six or more organizations: the treatment center’s apheresis unit, the courier, the cryostorage vendor, the drug substance manufacturing site, the drug product fill-finish site, and the infusion center. Each has its own quality system, its own SOPs, its own data platform, and frequently its own way of writing timestamps. There is often no single system that can produce a real-time record from collection to infusion.6

What CBER reviewers look for. Traceability between the patient’s autologous apheresis and the CAR T-cell product must comply with the applicable regulations, with records supporting full traceability retained for at least 30 years. That timeline outlives most sponsors’ current data platforms. The infrastructure question is not just whether you can reconstruct the record today. It is whether you can reconstruct it in 2056.5

The Data Standards Problems Hiding in Plain Sight

The COI/COC failure modes we see in reviewer feedback tend to look like this:

  • Timestamp inconsistency across systems. Treatment center EHR is UTC-local. Courier system is UTC. MES is site-local. Reconciliation is manual and does not scale.
  • Identifier collisions or handoff drops. Patient ID at apheresis is a treatment-center MRN. Manufacturer assigns a lot number. Somewhere in between, a “batch number” gets typed by hand. When the reviewer asks to trace a single patient’s product, three people spend a week finding the linkage.
  • Missing environmental data. Temperature excursions during transit are captured by the courier but never make it into the batch record in a queryable way. FDA asks about an excursion, and the sponsor cannot produce a definitive answer.
  • Deviation records that do not tie back to specific COI-related events. An intermediate storage step fails a check. The batch record notes it. The COI system does not. On review, the two records tell different stories.

What “Reviewable” COI/COC Data Looks Like

A reviewable COI/COC data package treats the patient-to-product chain the way pharma has learned to treat batch records: as an immutable, auditable, queryable object. Modern implementations increasingly use dedicated cell orchestration platforms integrated with Manufacturing Execution Systems (MES) to enforce COI/COC through barcoding, dialogue-driven checks, and automatic linkage between courier events and batch record events.7

Signals that COI/COC data is reviewable. A single system can produce the full chain for any patient in under an hour. Timestamps across systems share a common time authority and are stored in a canonical format. Every handoff between organizations is logged as a discrete event with attribution. Environmental data (temperature, orientation, transit time) is captured continuously and joined to the batch record. Deviation and CAPA records reference specific COI-linked events by ID, not by narrative.

Cell Characterization Data Granularity

Cell characterization gaps are the failure mode that quietly kills BLAs. Sponsors often assume that identity, sterility, and viability testing constitute characterization. FDA does not. Characterization is what tells the reviewer that the clinical lots (which demonstrated efficacy in Phase 1 and Phase 2) and the commercial lots (which will be released under the BLA specifications) are functionally the same product.8

For CAR-T products, the characterization package should include, at minimum, cell subset composition (naive, central memory, effector memory, terminally differentiated), CAR expression distribution (not just percent-positive but distribution across cells), transduction efficiency, cell health markers (activation, exhaustion, apoptosis), and cytokine secretion profiles under stimulation. For AAV-based products, characterization now includes empty/full/partial capsid distribution using orthogonal methods, aggregation, and vector genome integrity by long-read sequencing or mass spectrometry.9

The empty/full capsid data standard has moved. As of mid-2025, USP recognized mass photometry in draft General Chapter <1067> as a key orthogonal method for AAV characterization. Sponsors who validated a single ELISA-based method three years ago are now expected to run at least two orthogonal techniques (Analytical Ultracentrifugation, Mass Photometry, or Charge-Detection Mass Spectrometry alongside SEC-MALS) and to distinguish partially filled capsids, not just empties versus fulls.10

Where Characterization Data Fails Review

The characterization data failures we see are rarely about missing tests. They are about missing granularity and missing statistical context. A CRL rarely says “you did not characterize your product.” It says something closer to “the sponsor should provide additional data supporting the comparability of the pre-change and post-change process” or “the sponsor should further characterize the distribution of [attribute] across lots to establish acceptance criteria.”

Both statements sound like requests for more data. What they actually mean: the sponsor built acceptance criteria from a handful of lots without describing the statistical distribution, and now cannot demonstrate that commercial lots will consistently fall within the clinical range.

Potency Assay Data: The Perennial CRL Driver

Potency has been the single most consistent CRL driver in CGT for a decade, and 2025 did not break the pattern. FDA’s expectation is straightforward on paper. The potency assay must reflect the product’s mechanism of action. For CAR-T, that typically means demonstrating cytotoxicity against antigen-expressing targets, T-cell activation, or both. Surrogate markers like CAR surface expression by flow cytometry are generally insufficient unless thoroughly justified.11

A recent systematic analysis of the potency tests used across the 31 FDA-approved cell therapy products found that no single assay dominates. Approved products use combinations of functional bioassays, biochemical assays, and matrix approaches, and the acceptable approach depends heavily on product class, mechanism, and clinical evidence. This variability is often misread by sponsors as regulatory ambiguity. It is not. It is a signal that FDA wants a defensible, product-specific, MOA-linked potency strategy, not a copy of what worked for someone else.12

The Potency Data Standards Failure Modes

MOA MISMATCH

Assay does not reflect mechanism

A CAR-T program uses interferon-gamma release as the sole potency measure. FDA asks: does IFN-gamma predict clinical response? Most sponsors cannot answer definitively because they never designed the study to.

MATRIX GAPS

Matrix without bridging data

Sponsor proposes a two-assay matrix. Assay A ran on clinical lots. Assay B was introduced later. There is no bridging data connecting Assay B results to clinical outcomes.

SPEC-SETTING

Acceptance criteria too narrow or too wide

Criteria set on 6 clinical lots, tightened without justification for commercial launch, or widened after post-approval OOS results. Either invites additional review cycles.

METHOD DRIFT

Method drift not tracked

Potency method was modified during Phase 3. No formal bridging exercise. FDA cannot connect the pre-modification and post-modification data, forcing a resubmission cycle.

The potency trap for late-stage sponsors. The most damaging pattern is a sponsor who selects a “simple” potency measure early (transduction percentage, viability, IFN-gamma), builds Phase 3 around it, and only develops a functional cytotoxicity or killing assay in the year before BLA. FDA sees two disconnected data packages: the clinical evidence (linked to the surrogate) and the release criterion (linked to a newer functional assay). Bridging one to the other consumes a review cycle.

Batch-of-One Release Testing and Concurrent Release

For autologous CGT, every patient is a batch. This breaks assumptions baked into decades of pharmaceutical batch release architecture: three PPQ lots, retain samples, sterility hold periods, formal review of the full batch record before release. FDA has now formalized flexibility on many of these expectations. But sponsors continue to treat “batch of one” as a logistical inconvenience rather than a fundamental redesign of the release testing data model.13

The flexibility guidance is important. CBER has stated it will consider flexibility on product release specifications for CGT BLAs and will consider requests to revise specifications based on post-approval manufacturing experience. There is no fixed requirement of three PPQ lots. CBER will consider a lower number, justified by process understanding and controls. Process Performance Qualification protocols can be designed to allow release of a PPQ batch for distribution before all protocol activities are completed (concurrent release), when PPQ production limitations exist.14

Flexibility is not looseness. FDA’s January 2026 formalization of CMC flexibility for CGT should be read as an invitation to bring proposals, not as permission to defer. The flexibility guidance rests on demonstrated process understanding and analytical rigor. Sponsors with weak characterization data and immature potency programs cannot invoke it. Sponsors with strong process understanding and comprehensive analytical data can use it to shorten review cycles.15

The Data Standards Required to Justify Flexibility

To actually use the flexibility that CBER has formalized, sponsors need data infrastructure that few late-stage programs currently have. The threshold looks something like this:

1

Continuous manufacturing data across all lots, not sampled

Every batch’s process parameters, in-process controls, and release data are collected and analyzed together. Statistical process control is real, not a slide in an internal review. This is what justifies fewer PPQ lots.

2

Analytical methods with orthogonal confirmation

Every critical quality attribute is measured by at least two orthogonal methods, at least during development. This is what justifies a leaner release specification.

3

Concurrent release procedures with documented risk-based decisions

The sponsor has written and tested procedures for releasing product before final results are available, with defined re-review actions if later results are out of specification. FDA wants to see the procedure, not just the concept.

4

Post-approval commitments with data feedback loops

Sponsors invoke flexibility with clear commitments: expanded characterization on the next 20 lots, tightened specifications after N additional lots, updated potency correlations as clinical experience accumulates. Commitments require infrastructure to fulfill.

Apheresis-to-Infusion Data Linkage

The end-to-end data linkage from apheresis collection through drug substance manufacture, drug product fill-finish, cryostorage, thaw, and patient infusion is the most technically complex part of a CGT data architecture, and it is where most sponsors have the biggest gaps. The gap is not usually a single missing data element. It is that the systems capturing the data are not talking to each other, and there is no authoritative source of truth for any given patient’s journey.16

Practical reality: apheresis data lives in the treatment center’s cell processing system. Courier data lives in the courier’s platform. Cryostorage data lives in the vendor’s LIMS. Manufacturing data lives in the sponsor’s MES and LIMS. Fill-finish data lives in a different site’s MES. Infusion data lives back in the treatment center’s EHR. Long-term follow-up data lives in the sponsor’s clinical database.

6+ Distinct organizations typically involved in a single autologous CGT patient’s chain, each with its own data platform6
30 years Minimum retention period for CAR-T traceability data linking apheresis to the drug product5
21 CFR 11 Applicable to all electronic records supporting COI/COC across every organization in the chain, plus HIPAA and GDPR where applicable17

The Three Integration Patterns That Work

Sponsors approaching the apheresis-to-infusion data linkage problem tend to converge on one of three architectural patterns. None of them is trivial. All of them are workable if started early enough.

PATTERN A

Cell orchestration platform as the system of record

A dedicated platform (TrakCel, Vineti/Marken, Trace Therapeutics, others) sits at the center and holds the canonical COI/COC record. All other systems feed into it. Strong for chain-of-identity questions, weaker for deep manufacturing integration.

PATTERN B

MES-centric with orchestration overlay

A CGT-adapted MES (Körber PAS-X, MasterControl Manufacturing Excellence, Werum) holds the manufacturing data spine. An orchestration overlay handles cross-organization events. Strong for manufacturing depth, requires careful design of the orchestration boundary.

PATTERN C

Data platform / data mesh as the source of truth

Individual operational systems remain. A data platform ingests events from all of them, curates a canonical patient-to-product view, and serves it to quality, regulatory, and analytics teams. Most flexible, most demanding on data engineering.

CROSS-PATTERN

What all three require

Standardized identifiers across organizations. A shared event vocabulary. Common time authority. Documented interface control between every system pair. A quality-approved data flow diagram that is actually up to date.

A CGT Data Standards Maturity Model

Late-stage CGT sponsors benefit from a scored, comparable view of where they stand on data standards. The following maturity model draws from the failure modes above and maps to the categories FDA reviewers actually probe. It is not a certification. It is a tool for sponsors to self-assess where they are nine to twelve months before submission, when there is still time to close gaps.

Dimension Level 1: Reactive Level 3: Managed Level 5: BLA-Ready
Chain of Identity / Custody Manual reconciliation across systems. Can reconstruct a patient chain in days with effort. Cell orchestration platform in place. Chain reconstructable in hours. Some environmental data still manual. Single system of record. Chain reconstructable in minutes with automated environmental data joining.
Cell Characterization Identity + viability + sterility. Ad hoc subset composition. Comprehensive panel run on Phase 3 lots. Some historical gaps. Full panel across all clinical lots, with statistical distribution documented and comparability to commercial process established.
Potency Single surrogate (transduction %, viability). No MOA-linked functional assay. Functional assay developed. Some bridging data. Method drift not fully documented. MOA-linked potency matrix, bridging data across all method versions, correlations with clinical outcome, defensible acceptance criteria.
Batch Release Data Paper-based batch records. Manual reconciliation of in-process and release data. Electronic batch records in most steps. Some data still transcribed. SPC in slides, not systems. Fully electronic. In-process, release, and stability data continuously analyzed in an SPC system. Trends flagged in real time.
Comparability / Bridging Comparability studies at process changes, but data lives in study reports, not queryable systems. Comparability data structured. Some pre/post-change comparisons automated. Every process change linked to structured comparability data. FDA can be shown the linkage in a query, not a slide.
Data Integrity / 21 CFR 11 Spreadsheets and disconnected systems in the critical path. Audit trails inconsistent. Critical systems compliant. Some peripheral tools still weak. Every system in the GxP data path is validated, audit-trailed, and access-controlled. Documented cross-system data flow with interface controls.

Level 4 and Level 2 sit between the described levels; sponsors should score themselves honestly and target Level 4 or 5 across every dimension before submission. Uneven maturity (Level 5 on characterization, Level 2 on comparability) is a common failure pattern and is what generates the “additional data required” language in CRLs.

Preparedness Checklist for Late-Stage Sponsors

The following checklist reflects what late-stage CGT sponsors should be able to answer yes to before they file. Every item corresponds to a common CRL driver. Any “no” is worth an internal review before submission.

The one-year-before-BLA checklist. Use this list to structure a formal internal review roughly a year before the target submission date. Not to determine whether to file, but to determine what to fix while there is still time.

Chain of Identity and Chain of Custody

  • Can we reconstruct the full COI/COC chain for any patient in under an hour, including environmental data during transit?
  • Do timestamps across the treatment center, courier, storage, and manufacturing systems share a common time authority and canonical format?
  • Are all organizations in our chain covered by executed quality agreements that specify data retention, data integrity, and audit rights?
  • Have we tested our COI/COC data extraction against an FDA-style query on ten random historical patients?

Product Characterization

  • Do we have a documented characterization panel that captures subset composition, mechanistic markers, and process-relevant impurities across all clinical lots?
  • Are we running orthogonal methods for critical CQAs (e.g., empty/full/partial capsid for AAV, cell composition for CAR-T)?
  • Do we have statistical distributions, not just means, for every characterization attribute?
  • Is our commercial-scale characterization data comparable to the clinical characterization data by a documented, reviewable analysis?

Potency

  • Is our potency assay clearly linked to product mechanism of action, with justification a reviewer can accept?
  • Do we have bridging data across every version of the assay used during clinical development?
  • Are our acceptance criteria justified by clinical data and by statistical analysis of clinical lot results?
  • Have we assessed correlation between potency results and clinical outcomes, at least descriptively?

Batch Release and Concurrent Release

  • Is our electronic batch record system validated end-to-end?
  • Do we have documented concurrent release procedures with defined re-review triggers?
  • Are our in-process control data and release data available in a common analytical environment for real-time SPC?
  • Have we mapped which flexibility provisions we intend to invoke, and prepared the data to justify each one?

Data Infrastructure

  • Is every system in the GxP data path validated, audit-trailed, and 21 CFR Part 11 compliant?
  • Do we have a documented, current data flow diagram from apheresis to infusion?
  • Are the interface controls between every system pair documented and tested?
  • Can our data infrastructure be maintained (and reconstructed if needed) for the 30-year retention window?

Where late-stage sponsors most often lose time. The item that most often surprises sponsors is not on this checklist explicitly. It is the cumulative effect of technical debt across all the categories. Any single gap is fixable. The characteristic CRL pattern is three or four gaps simultaneously, which multiplies review complexity and forces the reviewer toward a Complete Response. Score honestly, and fix the whole picture before submission.

Lessons from the 2025 CRL Cluster

The July 2025 CRL cluster (Capricor’s CAP-1002, Ultragenyx’s UX111, Rocket’s Kresladi) each tell a slightly different story, but reading them side by side sharpens the pattern late-stage CGT sponsors should be watching for.

UX111: When Facility and Process Data Cannot Be Separated

Ultragenyx received its CRL for UX111 (an AAV-based gene therapy for Sanfilippo Syndrome Type A) citing additional CMC information and observations from recent manufacturing facility inspections. The sponsor publicly framed the concerns as facility-and-process focused rather than as questions about the therapy itself, and characterized the observations as readily addressable.19

The lesson for other sponsors is not the specific observation. It is that the FDA does not, in practice, separate “facility issues” from “product issues” the way sponsors sometimes try to. A facility with recent inspection observations casts doubt on the manufacturing data generated at that facility, which casts doubt on the release data supporting the BLA. The data integrity question travels up the chain even when the underlying product is well-characterized. Sponsors who address facility observations without also demonstrating the impact analysis on data integrity leave the reviewer holding an open question.

Kresladi: The “Limited Additional CMC Information” Trap

Rocket’s Kresladi (an ex vivo lentiviral gene therapy for severe Leukocyte Adhesion Deficiency-I) received a CRL that Rocket described as requesting “limited additional CMC information.” The BLA was resubmitted, accepted for review, and given a PDUFA date of March 28, 2026.21

“Limited additional CMC information” is language sponsors sometimes use to signal to investors that the CRL is manageable. That framing is defensible. But it obscures a hard fact: any CMC-driven CRL costs at least six months of review clock, plus the additional time to generate and validate the requested data. For a small-population indication where reimbursement, capacity, and patient identification all take time to build, the resubmission cycle is expensive even when the data itself is tractable.

CAP-1002: The Clinical/CMC Boundary

Capricor’s CAP-1002 received a CRL citing that substantial evidence of effectiveness was not met and that more clinical data would be needed, alongside CMC and non-clinical elements. The clinical piece is not the focus of this article, but the CMC-adjacent pattern is instructive.4

In an allogeneic cell therapy, clinical evidence and manufacturing data are more intertwined than in a small-molecule review. If clinical lots were manufactured under a process that has since evolved, the reviewer needs comparability data connecting the earlier clinical lots to the current (and future commercial) process. When clinical evidence is questioned, sponsors sometimes discover that the underlying comparability data is not organized in a way that supports rapid reanalysis. The data infrastructure question shows up as a clinical development question.

Platform Justifications, Decentralized Manufacturing, and the Standards Question

Two structural shifts are compounding the data standards challenge for CGT sponsors: FDA’s move away from generic platform justifications for AAV programs, and the industry’s move toward decentralized (multi-site, point-of-care, closer-to-patient) manufacturing. Both shifts require new data infrastructure, and both are running ahead of most sponsors’ internal capabilities.

The End of Generic Platform Justification

Through 2023 and 2024, some AAV sponsors leaned on “platform” arguments: the vector construct is well-characterized in Program X, therefore the same characterization should support Programs Y and Z with lighter data packages. FDA has now shifted decisively away from that framing. The expectation is product-specific resolution of each critical quality attribute, using product-specific analytical methods, with product-specific acceptance criteria.20

Practically, this means sponsors carrying multiple AAV programs need multiple, product-specific data packages rather than a shared characterization foundation. It also means that method validation costs and analytical infrastructure requirements are higher than sponsors modeled two years ago. Sponsors whose CMC plan still assumes platform-level acceptance will need to revisit that assumption before submission.

Decentralized and Point-of-Care Manufacturing

Decentralized manufacturing (multi-site production, in-hospital point-of-care processing, closed-system automated production placed near the patient) is emerging as a serious answer to the scaling problem for autologous CGT. It also multiplies the data standards problem. EMA’s Quality and Innovation Group is currently working on Q&A guidance addressing how to demonstrate comparability between all decentralized sites in a manner equivalent to a centralized manufacturing model. That work is still in progress, and sponsors moving to decentralized models are effectively operating ahead of settled guidance.18

The decentralized data standards challenge. Every additional manufacturing site adds a full copy of the data infrastructure problem: identifier standards, timestamp reconciliation, MES integration, analytical method transfer, deviation management, and comparability data generation. Sponsors piloting decentralized manufacturing without a documented data standards architecture across sites are building CRL surface area. The right time to standardize is before site number two goes live, not after site number five.

The ICH and USP Standards Landscape Shifting Under Sponsors

The technical standards landscape for CGT is moving faster than most sponsors’ internal reference architectures. Three shifts deserve specific attention from any team preparing a BLA in the next twelve to eighteen months.

USP General Chapter <1067> and AAV Analytics

USP’s draft General Chapter <1067>, “Best Practices for the Manufacture and Quality Control of Recombinant Adeno-Associated Virus Gene Therapy Products,” is open for public comment and formalizes expectations around AAV characterization that many sponsors’ existing analytical methods do not meet. Mass photometry is explicitly recognized alongside Analytical Ultracentrifugation and Transmission Electron Microscopy as an orthogonal method capable of distinguishing empty, full, and partially filled capsids.10

Sponsors relying on ELISA and OD ratios alone are operating below the standard the chapter formalizes. The remediation is not trivial: adopting mass photometry or an equivalent method requires equipment, method development, method validation, comparability with the existing method, and updated release specifications. Sponsors who scope the remediation as “buy an instrument” underestimate the timeline.

Standards Coordinating Body and Reference Materials

USP has released AAV8 empty capsid and full capsid reference standards, characterized using orthogonal methods, that sponsors can now use to calibrate their internal methods. The Standards Coordinating Body (SCB) continues to convene stakeholders on CGT-specific standards, and the ISCT is active on the potency and characterization side. The landscape of available and expected reference materials is broader than it was even eighteen months ago, and sponsors who have not refreshed their reference material strategy in that window should do so.10

ICH Q Guidelines and Their CGT Interpretation

ICH Q5A, Q5D, Q6B, Q8, Q9, Q10, and Q11 all apply, in adapted form, to CGT programs. The adaptation is not always obvious, and sponsors sometimes miss that quality risk management (ICH Q9) and pharmaceutical quality system (ICH Q10) expectations apply just as fully to a CGT program as to a monoclonal antibody, even though the practical implementation differs.

The most useful ICH-derived expectation, for CGT specifically, is the emphasis on quality risk management as an integrating framework. Sponsors who can show that every CMC decision (specification setting, method selection, sampling plan, comparability protocol) traces back to a documented risk assessment give reviewers a defensible framework for interpreting individual data packages, even when the data itself has known limitations.

Building an Internal Review Cadence That Catches Problems Early

The strongest CGT sponsors we see all have one operational practice in common: a scheduled, structured, cross-functional CMC review cadence that runs from Phase 2 through submission and continues past approval. It is a boring intervention. It works.

The purpose of the cadence is not to produce slides. It is to force a shared view of the data across CMC, quality, regulatory, clinical, manufacturing, and IT, at a cadence tight enough that gaps become visible while there is still time to close them. The characteristic failure mode of struggling CGT programs is that each function knows about its own gaps, and no forum exists in which the full picture is assembled and pressure-tested.

1

Monthly integrated CMC review

CMC, quality, regulatory, manufacturing, and analytical development in one room. Agenda covers process performance, method performance, characterization progress, comparability status, and open FDA feedback. Not a status readout. A working session where gaps are identified and owned.

2

Quarterly BLA readiness assessment

Score the maturity model dimensions honestly. Identify the two or three dimensions most at risk. Assign a workstream lead and a target date for each. Report to program leadership.

3

Semi-annual mock CRL exercise

An external or internal team reviews the current data package as if writing a CRL. What are the three most likely deficiencies? What data would close them? The exercise is uncomfortable and highly productive.

4

Annual data infrastructure review

IT, quality, and CMC review the underlying systems: MES, LIMS, cell orchestration, data platform. Are the interface controls documented and current? Is every system in the GxP path validated? Is the retention plan credible for 30 years?

Who owns the review cadence. The single most common failure of internal review cadence is unclear ownership. CMC assumes quality owns it. Quality assumes regulatory owns it. Regulatory assumes CMC owns it. The result is a series of ad hoc status meetings that never surface the cross-functional problems that actually drive CRLs. Assign a named owner (typically a senior CMC leader or an integrated CMC/quality director), give that owner authority to convene the cross-functional room, and hold that owner accountable for the outcome.

Conclusion

Cell and gene therapy manufacturing sits at the collision of biological complexity, patient-specific logistics, and pharmaceutical regulatory expectation. FDA’s shift toward formalized CMC flexibility for CGT reflects an accurate reading of that complexity, and it is a genuine opportunity for sponsors who can demonstrate process understanding backed by structured data. But flexibility is not a shortcut. It is a higher bar dressed as a lower one, because it makes the data infrastructure question inescapable. Sponsors who invoke flexibility need the data to justify it. The ones who miss that read produce the BLAs that get stuck.

The 2025 CRL pattern is a signal, not a coincidence. It says that the industry has scaled clinical activity faster than it has scaled data infrastructure, and that late-stage CGT sponsors need to treat data standards as a strategic capability rather than a QA cleanup task. The taxonomy of stuck points, the maturity model, and the preparedness checklist above are tools for having that internal conversation earlier than a CRL forces it.

Sakara Digital works with pharma and biotech organizations building the data foundations that make regulatory submissions defensible in a single cycle. If you are approaching a CGT BLA, working through a resubmission, or building the data infrastructure that will support one, and want an independent perspective on where the gaps are and where to invest first, we are happy to have that conversation.