Environmental monitoring programmes: building a CQA/CPP register
The EU's 2025 GACP rewrite expects each site to define and justify its own critical parameters. How to build a register that holds up at audit.
On this page
Ask an EU regulator's auditor what humidity you should be running in late flower and they will not give you a number. That is not evasion. The EU's rewritten guideline on good agricultural and collection practice, EMA/HMPC/246816/2005 Rev.1, adopted by the HMPC on 9 July 2025 and published on 12 August 2025, asks a harder question instead: can you show that you identified the parameters that matter to your product, set a defensible range for each, and proved you stayed inside it [1][2]. This is the first substantive revision since the guideline's 2006 original [1][3], and for the first time it gives indoor and other controlled-environment cultivation its own annex, Annex 1 [1][4]. That annex is where the Critical Quality Attribute (CQA) and Critical Process Parameter (CPP) register lives, and this guide walks through building one.
A quick scope note before the detail: this is an EU scientific guideline, not a statute, and it applies most directly to cannabis flower moving through the medicinal supply chain. It is not law in the way a plant-count limit is law, and it does not bind a Maltese ARUC-model association or a purely recreational-market licence the way it binds a facility supplying a pharmacy. But EU medicines regulators and the auditors who work for them already treat it as the working compliance bar for herbal starting materials, cannabis flower included [1][4]. If you are not yet supplying that chain, the register is still worth building, for reasons the closing section covers. If you are, EU-GACP is one jurisdiction's rulebook among several this library covers; check the law section for the rules that actually bind your licence before you act on anything here.
What a CQA and a CPP actually are
Strip away the acronyms and the idea is ordinary quality engineering, borrowed into agriculture.
A Critical Quality Attribute is a measurable property of the harvested or dried material that defines whether it is fit for use: a moisture range, a contaminant threshold, freedom from a specific defect such as botrytis damage. It is the thing you are accountable for. You cannot control a CQA directly: you cannot reach into a flower and turn a dial marked "moisture", so the guideline asks you to identify the levers that do control it.
A Critical Process Parameter is one of those levers: a controllable input, such as temperature, relative humidity, light intensity or irrigation water quality, that measurably affects a CQA. A CPP earns the word "critical" because you can show a link between moving it and moving the CQA it protects. Each CPP in a working register carries an acceptance band, a monitoring method, and an alarm threshold that fires before the band is breached, not after.
This band and threshold are this site’s own, set from its own incident history — see the worked example in the article. Nothing here is a regulatory or manufacturer limit.
A CQA is often protected by more than one CPP: airflow uniformity and plant spacing can bear on the same botrytis outcome, and one CPP can sit against more than one CQA.
Source: worked example for this guide, 2026-09. EMA GACP Rev.1 publishes no setpoints to copy [1].
The relationship is one CPP protecting one CQA, though in practice several CPPs often protect the same CQA (late-flower RH, airflow uniformity and plant spacing can all bear on the same botrytis outcome), and the same CPP can appear against more than one CQA in a full register.
| CQA | CPP | |
|---|---|---|
| What it is | A property of the material | A controllable process input |
| Where it's measured | On the harvested or dried product | Continuously, during cultivation |
| Can you set it directly? | No — it's an outcome | Yes — it's a lever |
| What the register records | The target range and the test | The acceptance band, sensor, alarm threshold |
Why there is no number to copy
This is the part worth stating plainly, because vendor marketing around the 2025 rewrite tends to skip it: Annex 1 names the systems it expects you to control (air and climate, humidity, light, water treatment, ventilation and filtration) and does not publish setpoints for any of them [1][4]. There is no EU-mandated late-flower RH number, no EMA-sanctioned PPFD ceiling, no official airflow tolerance. Each site is expected to identify its own CQAs and CPPs and justify its own acceptance ranges from its own product, its own building, and its own history of what has gone wrong [1].
That is a genuine design implication, not a technicality. A commentary you'll see repeated in vendor guides suggests figures such as air-handling-unit airflow held within 10% of design, or RH held within 3 percentage points of setpoint for a full hour — useful as a starting sketch, but those are one consultancy's own engineering benchmarks for one archetype of indoor flower room, not a number the guideline states, and treating them as an EU standard would misrepresent both the guideline and the vendor's own framing of its advice [4]. The deliverable this article can actually hand you is not a table of numbers. It's the register itself, and the reasoning that has to sit behind every cell in it.
What the guideline actually asks you to keep
Two obligations in the text are specific enough to build a system around, and worth separating from what commentary has read into them.
The main guideline, in the section on traceability, expects batches to be unambiguously and unmistakeably traceable to their sources, a requirement that applies to all cultivation covered by the guideline, not only indoor sites [1]. Annex 1 adds a sharper requirement for controlled-environment cultivation specifically: daily (digital) records of critical process parameters must be kept and reviewed [1]. Read those two clauses together and the shape of the obligation is clear: a CPP reading that exists but was never looked at does not satisfy "reviewed", and a batch record that cannot be traced back to which room, which sensor and which reading applied to it does not satisfy "traceable".
Equipment qualification gets the same specific-but-not-prescriptive treatment. Annex 1 states that qualification of critical equipment and ancillary systems should be completed, and that cultivation equipment must be calibrated to a schedule. It does not name IQ/OQ/PQ or any other named methodology; that framework is a consultancy's own recommended way of meeting the requirement, not EMA text [1][4]. In practice this means every CPP in your register needs a named instrument with a named calibration interval sitting behind it, which is exactly the asset and calibration record this library's guide on preventive maintenance programmes covers in full. Build that register alongside this one, because an uncalibrated sensor makes every reading it produced retroactively unusable as evidence.
Building your first register entry
The clearest way to see how a register actually gets built is to build one row of it, from a real incident pattern rather than an industry chart.
Take a licensed flower room that has logged three botrytis-related rejections in eighteen months. Reviewing the environmental logs behind each event finds a common pattern: in every case, RH at lights-off in the final two weeks of flower had drifted above roughly 68% and stayed there for more than an hour before anyone intervened, in a dense, poorly-thinned canopy — the same RH-driven failure mode this library's HVAC redundancy guide models minute by minute for a different trigger (a failed dehumidifier rather than a missed setpoint). That history, not a published table, is what justifies the numbers below.
- Name the CQA the incident actually threatensreview, not a task
Not "humidity problems" — a checkable outcome: flower free of botrytis-related rejection at harvest. If a lab or a visual inspection can pass or fail a batch against it, it's specific enough to be a CQA.
- Name the CPP that drives it
Late-flower relative humidity at lights-off, because that's what the three rejection events had in common. A different site's incident history might point to airflow dead zones or plant spacing instead; the method is the same, the parameter isn't guaranteed to be.
Warning Pick the parameter your own incident data actually implicates, not the one a generic guide names first. - Set the acceptance band below your own failure point, not at it
The incidents cluster above 68% RH sustained for over an hour. Setting the acceptance band at under 65% RH, rather than right up against 68%, leaves margin for sensor drift and for the time it takes anyone to respond.
- Set an alarm threshold that fires before the band is breached
68% RH sustained for 15 minutes triggers an alert — chosen well inside the roughly hour-long window the incident history suggests you actually have, so a night-shift response still arrives in time.
- Name the sensor and its calibration schedulelink to the maintenance register
A fixed capacitive RH/temperature probe at canopy height, logged every five minutes, two-point checked monthly, sent for accredited calibration annually — entered once in the equipment register linked above, referenced here rather than duplicated.
- Set a review cadence
Quarterly as standard, plus an immediate review after any alarm or any rejection event, so the register updates from real incidents rather than sitting static between audits.
| Attribute | This entry |
|---|---|
| CQA protected | Flower free of botrytis-related rejection at harvest |
| CPP (the lever) | Late-flower relative humidity at lights-off |
| Acceptance band | Under 65% RH |
| Alarm threshold | 68% RH sustained 15 min |
| Monitoring method | Canopy-height capacitive RH/T probe, logged every 5 min |
| Calibration schedule | 2-point check monthly; accredited calibration annually |
| Review cadence | Quarterly, plus after any alarm or rejection event |
Two mistakes show up repeatedly once sites start doing this for real, and both are worth checking for before you call a first register "done".
The first is copying a benchmark number from a vendor guide or a peer's system into the acceptance-band field without ever pulling your own incident logs. It looks identical to a justified entry until an auditor asks where the number came from, and "a consultancy's website" is not traceability. The second is setting the alarm threshold too close to the acceptance band, so it fires constantly on ordinary variation; staff learn to ignore it within a few weeks, and the one alarm that mattered gets dismissed with the rest. A threshold that has fired more than a handful of times in a quarter without a real excursion behind it needs widening, not silencing.
Where GACP ends and GMP begins
A register built this way stops at the GACP boundary, and it's worth knowing roughly where that sits before you extend it. Cultivation, harvesting and the early handling steps generally stay under GACP; the closer a step gets to the finished product, the stricter the requirement gets, and manufacturing-adjacent steps such as drying commonly move toward GMP in practice, though sources describing this boundary do not all draw the line at exactly the same step, and the classification of an individual stage like sorting or cutting can depend on how your specific licence and supply chain are structured [5]. If you plan to supply into a medicinal or export-grade chain, that ambiguity is exactly why the GACP/GMP handoff needs its own explicit, documented step in your workflow rather than an assumption — see the GACP and GMP explainer for the fuller picture, and treat any specific boundary claim for your own product form as something to confirm with your regulator before you rely on it.
Building the register before someone makes you
Everything above assumes a licence context where GACP conformance is already the goal. Most cultivation sites reading this are not there yet, and it is worth saying plainly why the exercise is still worth doing.
A CQA/CPP register is the same structured thinking an insurer's risk questionnaire eventually asks for, the same thing a regulatory auditor will ask for the day your licence changes tier, and the same due-diligence document a future buyer or investor in a GMP-regulated supply chain will want to see before they commit. None of those audiences care whether you called the document a "CQA/CPP register" or something else; they care whether you can show, for any environmental claim you make about your product, which parameter you were controlling, what range you accepted, what alarmed you when it drifted, and who reviewed it. Building that discipline once, while it's still optional, costs a few hours per CPP. Retrofitting it after an inspection finding, a rejected batch, or a due-diligence request has already happened costs a great deal more, and it costs it under a deadline you don't control.
Start with the CPP your own incident history already points to — a rejected batch, a near-miss, an alarm you silenced instead of investigating. That row will teach you the method faster than any blank template, and it links directly into the traceability and seed-to-sale records that turn a register from a standalone document into part of your batch record.
Sources
- European Medicines Agency, HMPC (2025). Guideline on good agricultural and collection practice (GACP) for starting materials of herbal origin, Revision 1 (EMA/HMPC/246816/2005 Rev.1) Accessed 2026-09-26.
- European Medicines Agency (2025). Good agricultural and collection practice for starting materials of herbal origin — Scientific guideline Accessed 2026-09-26.
- GMP-Publishing (2025). EMA: Update of the GACP Guideline Published Accessed 2026-09-26.
- Kannaplan (2025). EMA GACP Revision 1 (2025): Indoor-Cultivation Requirements & Implementation Accessed 2026-09-26.
- ECA Academy / GMP Compliance Association (n.d.). What are the GMP Requirements for Medical Cannabis? Accessed 2026-09-26.