Regulatory

CTD Dossier Structure: What Goes Into Modules 1 Through 5

Ask five regulatory affairs staff what a CTD dossier "looks like" and you will get five gestures at the same shape: a stack of five modules, one of them fat, one of them oddly bureaucratic, and one that quietly runs the whole show. That shape is ICH M4, the Common Technical Document, and it has been the working structure for marketing authorization dossiers for long enough now that most people learned it on the job rather than from the guideline itself.

We work on the systems side of this, the platforms holding the stability data, specifications, and method records that land in a dossier, so this guide leans practical: less "here is the ICH text," more what actually has to exist, where it comes from, and what keeps it usable after approval.

What the CTD actually is

ICH M4 defines a common way to organize the quality, safety, and efficacy information that supports a marketing authorization application. Before it existed, a company filing the same product in three regions wrote three differently structured dossiers, even though most of the underlying data was identical. The CTD fixed the structure so the same core content, the science, could be reused, with only the administrative wrapper changing per region.

That structure is usually drawn as a triangle sitting on top of a rectangle. The triangle is Module 1: regional, not harmonized, and technically not part of the CTD at all. The rectangle underneath is Modules 2 through 5, the part that is genuinely common across regions. That distinction matters more than it sounds: it is the reason a company can build one quality and clinical data package and refile it, with adjustments, in multiple markets instead of rebuilding it from scratch each time.

Module 1: the region-specific administrative module

Module 1 holds everything the CTD itself does not standardize: the application form, prescribing information and labeling text, certificates (GMP, free-sale, pharmaceutical product), letters of authorization, patent and exclusivity statements, and environmental risk information where a region requires it. Every national regulatory authority defines its own Module 1 checklist, which is exactly why two dossiers built on identical Module 2-5 content can still look completely different at first glance depending on where they are being filed.

This is also where a lot of avoidable submission delay lives. Module 1 documents expire, change owners, or go missing at the worst moment — a GMP certificate that lapsed between assembly and submission, a power of attorney signed by someone who left the company. None of that is a science problem. It is a document-tracking problem, and it is the first thing worth putting under some kind of system rather than a shared folder.

Module 2: the summaries

Module 2 is where an assessor actually starts reading. It contains the overall table of contents, the introduction, the Quality Overall Summary (2.3), the nonclinical overview and written/tabulated summaries (2.4 and 2.6), and the clinical overview and summary (2.5 and 2.7). Each of these is a distilled, assessor-facing version of the detailed data sitting one module down.

The discipline this section demands is consistency, not creativity. The Quality Overall Summary has to say, in condensed form, exactly what Module 3 says in detail — not a rounder, friendlier version of it. When those two do not match, the mismatch itself becomes the question in a deficiency letter, independent of whether the underlying data was ever a problem.

Module 3: quality — where the lab's work lives

Module 3 is the one most of our own work touches directly. It is organized around the drug substance (3.2.S) and the drug product (3.2.P), each broken into sections covering manufacture, characterization, control of materials, control of the substance or product, reference standards, container closure system, and stability. If Module 1 is administrative and Module 2 is narrative, Module 3 is evidentiary: every claim in it has to trace back to a real study, a real batch, a real instrument run.

3.2.P.8 stability data

Section 3.2.P.8 is the stability data package, and it is one of the parts of a dossier that keeps generating work long after approval. Under ICH Q1A(R2), a shelf-life claim has to be supported by long-term, intermediate (where the climatic zone requires it), and accelerated stability data, run against a defined protocol, on batches that represent the commercial manufacturing process. The storage statement on the label is not a marketing choice; it is a direct consequence of what the stability data actually showed.

What makes 3.2.P.8 different from the rest of Module 3 is that it does not stop at approval. Post-approval stability commitments, ongoing batches, annual or bracketed testing, extended pull points to support a longer shelf life later, are exactly the kind of program that is easy to file correctly and then quietly under-execute over several years, which is why a stability study needs to run on a system built for scheduling, chamber tracking, and trending rather than a calendar reminder. Our stability LIMS exists for that reason: it manages the ongoing stability program the dossier commits to, so the study that gets filed is the study that actually keeps running.

Specifications and analytical methods

Sections 3.2.S.4 and 3.2.P.5 cover specifications and the analytical procedures used to test against them. A specification is not just a list of numbers; it is a justified set of acceptance criteria, tied to the test methods that generate the results and to the pharmacopoeial or in-house limits that support each one. Method descriptions here need to be detailed enough that a competent analyst in another lab could run the same test and land on a comparable result.

Method validation and transfer

Sections 3.2.S.4.3 and 3.2.P.5.3 hold the validation summaries: specificity, accuracy, precision, linearity, range, and robustness, run against ICH Q2(R2), which replaced Q2(R1) in November 2023 alongside the new ICH Q14 on analytical procedure development. Older dossiers will still cite Q2(R1), and that is fine for methods validated before the change. When a method moves from the R&D bench where it was developed to the QC lab where it will run for years, that move needs its own documented transfer, not an assumption that a validated method behaves identically on a different instrument, with a different analyst, on a different day. A dossier is only as strong as the weakest link in that chain from development to routine testing.

Modules 4 and 5: nonclinical and clinical

Module 4 holds the nonclinical study reports (pharmacology, pharmacokinetics, and toxicology, organized per ICH M3), and Module 5 holds the clinical study reports, organized per ICH E3, plus case report forms and literature references where relevant. For a new molecule these are often the largest part of the submission. For a generic or well-established product, they usually shrink: a bioequivalence study substitutes for a full clinical program, and nonclinical data is referenced from the originator rather than repeated. That substitution is defined by the receiving authority's own pathway, not by ICH M4, so it is worth confirming locally rather than assuming.

Dossier lifecycle: variations, renewals, and staying inspection-ready

A dossier is not a document you file once and forget. It is a live record of what the authority approved, and it has to stay synchronized with what the site actually does.

Variations

Any change that touches what was filed, a new manufacturing site, a tightened specification, a revalidated method, a different container closure, has to go through a formal variation before, or in some cases shortly after, it takes effect commercially, depending on the risk classification the change carries. The mistake we see most often is a change that starts and finishes on the shop floor, gets filed as a variation months later as an afterthought, and creates a gap where the dossier and reality briefly disagreed. Tracking which sections a given change touches, and whether the corresponding variation was actually submitted and approved, is exactly the kind of registration and correspondence tracking that belongs in CTD dossier management software rather than in someone's memory of what they meant to file.

Renewals

Periodic renewal reuses most of Modules 2 through 5 as-is, updated for anything that changed since the last submission, with a refreshed Module 1. The practical risk at renewal time is administrative drift — expired certificates, a labeling text updated locally but never fed back into the master dossier, a commitment from the original approval that nobody closed out.

Staying inspection-ready between submissions

Inspectors and assessors both work from the same underlying question: does what is actually happening at the site match what was approved. That means the specifications in 3.2.P.5, the stability protocol in 3.2.P.8, and the validated method in 3.2.P.5.3 all need to be the same documents the QC lab is using today, not the versions that were current when the dossier was first compiled. Keeping that alignment is less about any single module and more about how R&D, quality, and regulatory affairs share data across the product's life — which is the problem our broader R&D and regulatory solutions are built around.

CTD dossiers in Egypt and the wider MENA region

As general background: national regulatory authorities across Egypt and the wider MENA region, including Egypt's own authority and Saudi Arabia's SFDA, have moved their submission requirements onto the CTD structure, accepting Modules 2 through 5 largely as harmonized while defining their own regional Module 1 — local agent appointment documents, GMP evidence, and labeling requirements among them. The scientific core of the dossier does not need to be rebuilt market by market; the administrative wrapper does. We are deliberately not quoting specific fees, review timelines, portal names, or form numbers here, since those details change and are set directly by each authority rather than by ICH M4.

Frequently asked questions

What is the difference between the CTD and the eCTD?

The CTD is the content and structure defined by ICH M4: five modules, arranged in a set order, with an agreed table of contents. The eCTD is the electronic publishing format built on top of that structure, an XML backbone that turns the same modules into a navigable electronic submission and manages lifecycle sequences such as new applications, variations, and renewals. You can have a CTD-format dossier on paper or as a set of PDFs; the eCTD is how you file that same content electronically with a defined technical envelope.

Does every submission need every module filled in?

No. A full new molecular entity dossier uses all five modules in depth. A generic or abbreviated application typically leans on bioequivalence data in Module 5 instead of a full clinical program, and often references the innovator's nonclinical data rather than repeating Module 4 in full. Which sections can be abbreviated, and how, is defined by the receiving authority's own guidance, not by ICH M4 itself.

Who inside a company actually owns Module 3?

In practice it is a joint effort between quality control, analytical R&D, and regulatory affairs. QC and analytical R&D generate and own the underlying data (specifications, validation reports, stability results); regulatory affairs is responsible for compiling it into the module structure, writing the Quality Overall Summary, and making sure what is filed matches what the lab actually does.

What is the most common reason Module 3 draws questions from an assessor?

Two patterns come up repeatedly: the Quality Overall Summary in Module 2.3 says something the detailed data in Module 3 does not quite support, and a stability commitment on file is not being executed exactly as written, whether that is a missed pull point, a substituted condition, or a container closure that changed without the dossier being updated.

How does a post-approval change affect a dossier that is already approved?

A change to the formulation, manufacturing site, specification, or analytical method that touches what was filed has to go through a formal variation, updating the relevant CTD sections and, depending on the risk classification the authority assigns, either a notification or a full review before the change can be implemented commercially. This is why the change should start as a documented change control record, not as something the plant just does and files later.

CORPEX Informatics

Enterprise software solutions for pharmaceutical, food, chemical, and manufacturing industries. Headquartered in Egypt, serving regulated industries across the MENA region since 2006.

Keeping a dossier and the lab that supports it in sync?

See how RENOVA-RDX tracks registrations, submissions, and stability commitments alongside the R&D data behind them.

See RENOVA-RDX for Regulatory Affairs