Evidence explainer

Health policy, systems, and equity

What a Regulatory Submission Contains

A regulatory submission is an evidence argument and an electronic record. It has to let a reviewer follow every claim back to its data.

Fully reviewed by Jasaman (Jasmin) Tojjar, MD, PhD

On this page
  1. Key takeaways
  2. Start with the requested decision
  3. The five CTD modules
  4. Module 1: regional and administrative content
  5. Module 2: the integrated account
  6. Module 3: identity, manufacturing, and quality control
  7. Module 4: nonclinical evidence
  8. Module 5: clinical evidence and study data
  9. CTD and eCTD are different layers
  10. Technical validation is necessary but not scientific review
  11. Traceability and consistency hold the package together
  12. A submission is a lifecycle, not a delivery event
  13. References

A regulatory submission is a structured package of evidence, explanations, proposed product information, and administrative records sent to a health authority for a defined decision. For a medicine marketing application, it usually connects quality, nonclinical, and clinical evidence to a proposed indication. It connects that evidence to population, dose, labeling, and benefit-risk conclusion. Its electronic structure also lets the authority navigate, validate, compare, and maintain the record over time.

There is no universal “regulatory submission.” A clinical-trial application is different from a marketing application. A generic application differs from one for a new active substance. Vaccines, cell and gene therapies, and combination products can follow different frameworks. So can medical devices, manufacturing changes, safety reports, and post-authorization variations. The submission type, authority, legal basis, product, and requested decision therefore define what belongs in the package.

Key takeaways#

Start with the requested decision#

The first question is not which documents exist. It is what you are asking the authority to decide. An early development submission may ask permission to begin or modify a clinical trial. A marketing application may ask for authorization of a defined product for a defined use. A post-authorization submission may ask to add a manufacturing site, change a formulation, expand an indication, or update safety information.

That requested action determines the legal basis, forms, and fees. It determines timelines, data requirements, and review disciplines. It also determines the claims you have to support: a dossier for treatment of adults with a specific condition cannot rely on evidence for a broader population without explaining whether it transports. A new strength or route can require bridging evidence even when the active ingredient is familiar.

The proposed product information serves as an organizing target. Each indication, dose, and contraindication should trace to evidence. So should each warning, interaction, population statement, and storage condition. Unsupported wording is not repaired by placing more reports elsewhere in the package.

The five CTD modules#

The International Council for Harmonisation created the Common Technical Document, or CTD, to give quality, safety, and efficacy information a common organization. Module 1 is regional. Modules 2 through 5 are intended to be common across ICH regions, although region-specific implementation and product requirements still matter.[1]

The five modules are:

  1. Regional administrative information. Application forms, cover letters, legal and administrative documents, proposed labeling, patent or exclusivity information where applicable, environmental material, certifications, and other jurisdiction-specific content.
  2. CTD summaries and overviews. A high-level introduction, quality overall summary, nonclinical overview and summaries, and clinical overview and summaries.
  3. Quality. Information on the drug substance and drug product, manufacturing, controls, specifications, analytical methods, validation, reference standards, container closure, and stability.
  4. Nonclinical study reports. Pharmacology, pharmacokinetics, and toxicology reports and related information.
  5. Clinical study reports. Biopharmaceutic studies, clinical pharmacology, efficacy and safety studies, postmarketing experience where applicable, case report forms or listings in defined circumstances, and related references.

The modules are not five separate arguments. Module 2 should integrate what Modules 3 through 5 establish, identify important uncertainties, and explain benefit-risk in relation to the proposed use. Inconsistency between a summary and its source report creates review risk.

Module 1: regional and administrative content#

Module 1 varies because legal and procedural requirements vary. Common components can include the application form, cover letter, table of contents, and applicant and manufacturer information. They can include fee material, meetings or correspondence, user-fee forms, and proposed prescribing information. They can include patient information, carton and container labels, and region-specific declarations.

The proposed labeling is not decoration added after the science. It expresses the decision requested from the authority. The indication defines who would receive the product and for what use. Dosage instructions must match the studied regimen and formulation. Warnings, adverse reactions, and interaction language should align with the safety database. Storage and handling depend on quality evidence.

Risk-management plans, pharmacovigilance-system information, pediatric plans, and orphan documentation may be required depending on region and product. So may environmental assessments, financial disclosures, debarment certifications, or other records. An experienced team maintains a jurisdictional content matrix instead of assuming the harmonized modules removed regional differences.

Administrative accuracy matters. A mismatched manufacturer name, site address, dosage form, application number, or legal representative can delay your intake or create ambiguity. Current forms and controlled terms should be checked near submission because technical requirements change.

Module 2: the integrated account#

Module 2 helps a reviewer understand the program before descending into individual reports. The quality overall summary presents the manufacturing and control strategy. Nonclinical summaries organize pharmacology and toxicology findings. Clinical summaries group study results by pharmacology, efficacy, and safety.

The clinical overview should do more than repeat conclusions. It explains development rationale, pivotal evidence, limitations, and dose selection. It explains population relevance, consistency, missing information, and benefit-risk. It should distinguish prespecified evidence from analyses developed after results were known.

Good summaries are traceable. Tables identify study, population, dose, and comparator. They identify duration, outcome, and source location. Numbers reconcile with study reports and datasets. Important discrepancies are explained rather than hidden by averaging across programs.

The overview also connects disciplines. A manufacturing impurity can require toxicologic qualification, organ-function findings can affect clinical dose recommendations, and a delivery device can change usability and dose reliability, and the summary should make those dependencies visible.

Module 3: identity, manufacturing, and quality control#

Module 3 explains what the product is and how each batch will consistently meet its intended quality. For the drug substance, it can cover nomenclature, structure, and properties. It can cover manufacturer, process, materials, and process controls. Characterization, impurities, specifications, and analytical procedures belong there too. So do method validation, batch results, reference standards, container system, and stability.

For the finished product, the module can cover composition, pharmaceutical development, and manufacturing process. It can cover critical controls, excipient controls, and specifications. It can cover analytical procedures, validation, and batch analyses. It can cover impurity characterization, container closure, and stability. Biologics can require extensive characterization of cell banks, biological activity, process-related impurities, comparability, and adventitious-agent controls.

The control strategy connects material attributes and process parameters to product quality. A specification should have a method, acceptance criterion, rationale, and supporting validation. Stability data should support shelf life, storage, shipping, in-use periods, and container claims.

Changes during development must be assessed. If pivotal clinical batches differ from the proposed commercial process, your submission needs a comparability argument and supporting studies, because the question is whether the evidence generated with earlier material remains applicable to the product that will be marketed.

Module 4: nonclinical evidence#

Module 4 contains full nonclinical study reports and organizes them across pharmacology, pharmacokinetics, and toxicology. Pharmacology can include the intended mechanism, secondary activity, and safety pharmacology. Pharmacokinetics can address absorption, distribution, metabolism, excretion, and interactions in the studied systems. Toxicology can include single- and repeat-dose studies, genetic toxicity, and carcinogenicity where needed. It can include reproductive and developmental toxicity, local tolerance, immunotoxicity, and other product-specific work.

Study design should support the human context. Species or model relevance, dose selection, and route matter. So do duration, achieved concentrations, and recovery. So do endpoints, pathology, and toxicokinetic findings. A no-observed-adverse-effect level is not a universal safety boundary. Reviewers consider the nature, reversibility, severity, and human relevance of findings.

Good Laboratory Practice status, deviations, data integrity, and specimen or archive controls belong in the record. Literature can complement reports but does not erase the need to establish relevance and ownership of conclusions. Nonclinical evidence changes across product types. Some biologics have limited species relevance, and gene therapies can require distribution and shedding studies. Excipients, impurities, combination components, or novel delivery materials can create their own qualification questions.

Module 5: clinical evidence and study data#

Module 5 contains the clinical study reports and supporting clinical information. Depending on the application, it can include bioavailability and bioequivalence studies, studies using human biomaterials, and pharmacokinetic and pharmacodynamic studies. It can include efficacy and safety trials, uncontrolled experience, integrated analyses, and published reports.

A complete clinical study report links protocol, amendments, and statistical analysis plan. It links participant flow, conduct, results, and deviations. It links efficacy, safety, and appendices. The article on what a clinical study report contains examines that structure.

Standardized study datasets let reviewers reproduce analyses, explore safety, and combine studies. Dataset specifications, define files, and annotated case-report forms improve usability. So do data reviewer guides, analysis programs or metadata where requested, and clear links between analysis results and source variables. Technical conformance does not guarantee that a dataset is scientifically coherent, but poor conformance can prevent efficient review.

Clinical evidence must support the exact population, dose, comparator, endpoint, and duration in the proposed claim. Subgroup evidence, missing data, and intercurrent events should be addressed. So should multiplicity, protocol changes, and regional differences. Safety integration should examine common events, serious events, discontinuations, and deaths. It should examine laboratory patterns, special topics, dose or duration patterns, and uncertainty from database size. Patient narratives and case details can be required for selected serious events or deaths. They should preserve chronology, relevant history, and treatment timing. They should preserve alternative explanations, action taken, and outcome without substituting an advocacy conclusion for the facts.

CTD and eCTD are different layers#

CTD defines how content is organized. The electronic Common Technical Document, or eCTD, adds an XML-based structure. It adds metadata, navigation, file rules, and checksums. It adds controlled terms and lifecycle relationships. It lets a later sequence add, replace, or retire content while preserving the regulatory history.[2][4]

The dossier is therefore not one static PDF. It is a sequence-based record. Reviewers should be able to identify the current document, what changed, and which prior content remains active. Poor lifecycle operations can leave conflicting versions visible or remove context that should remain.

Specifications are region- and version-dependent. As of July 2026, FDA supports eCTD v4.0 for new CDER and CBER application types while also publishing current v3.2.2 standards. Its v4.0 technical materials were updated on 9 July 2026.[2][3] The EMA eSubmission project page identifies eCTD v3.2.2 as the current specification for CTD Modules 2 through 5 while European v4.0 work continues.[4] Your team has to check the receiving authority's current implementation rather than infer one standard from another region.

Technical validation is necessary but not scientific review#

Before transmission, publishing teams validate XML, metadata, and file formats. They validate naming, paths, and hyperlinks. They validate bookmarks, checksums, and document granularity. They validate study tagging and controlled vocabulary. They also verify virus scanning, page orientation, legibility, and that every referenced file is present.

Study data can have separate validation criteria. A dataset may need required domains, metadata, terminology, identifiers, and a study-data reviewer guide. FDA publishes technical rejection criteria and current conformance guidance for relevant submissions.[2]

A package can pass every machine check and still fail scientifically. Validation cannot determine whether the pivotal trial is biased, the dose is justified, the manufacturing process is controlled, an impurity is qualified, or the labeling matches the evidence. Conversely, excellent science in an unreadable or invalid sequence can be delayed before reviewers can use it. The best submission treats technical and scientific readiness as one connected quality system.

Traceability and consistency hold the package together#

Key facts should agree across forms, summaries, and reports. They should agree across datasets, labeling, and metadata. Those facts include product name, strength, manufacturer, and indication. They include study identifiers, analysis populations, and participant counts. They include endpoint definitions, dates, and result values.

Traceability means a reviewer can move from a label claim to a summary table, from the table to a study report, from the report to an analysis dataset, and from the derived result to documented source variables and methods. Broken links and unexplained differences consume review time and weaken confidence.

Quality control should be risk-based but cross-functional. Medical writing, statistics, and data management each see different failure modes. So do clinical, safety, and quality. So do manufacturing, nonclinical, regulatory operations, and labeling. A single “final review” at the end is too late to repair program-level inconsistencies.

Documented data standards, authoring conventions, and source-of-truth tables reduce late surprises. So do issue logs, reference checks, and reconciliation plans. The site's research approach uses the same principle of linking conclusions to auditable sources.

A submission is a lifecycle, not a delivery event#

After intake, the authority may conduct filing or validation review, assign disciplines, and request clarification. It may inspect sites, analyze data, consult advisory bodies, and negotiate labeling or risk controls. Responses become new sequences in the same record.

New safety information can require rapid updates while review continues. Manufacturing changes can require amended evidence. A regulator may ask for an analysis using a different population or missing-data assumption. Each response should answer the question directly, identify changed documents, reconcile affected sections, and avoid introducing unrelated inconsistency.

After authorization, the lifecycle can include safety reports, periodic updates, and commitments. It can include variations, supplements, and annual reports. It can include manufacturing changes, new indications, and labeling revisions. It can include renewals and withdrawals. The active dossier should remain clear across years of sequences.

Readiness is therefore not “all documents uploaded.” A package is ready when the requested decision is stated, the evidence is sufficient and internally consistent, the technical standards are current, and the known gaps are declared rather than buried. Reviewers should be able to follow the argument, and the team should be able to maintain the dossier after day one.

References#

  1. ICH: The Common Technical Document
  2. FDA: Electronic Common Technical Document
  3. FDA: eCTD Version 4.0 and Regional Module 1 Submission Standards
  4. EMA eSubmission: eCTD Project
  5. The Common Technical Document and Regulatory Submission Process
  6. Electronic Common Technical Document Implementation
  7. Global Electronic Regulatory Submission Systems

Questions and answers

Is every regulatory submission a five-module CTD?

No. The CTD mainly structures medicine marketing applications in ICH regions. Trial applications, medical-device submissions, safety reports, master files, and post-authorization changes can use different structures and requirements.

What is the difference between CTD and eCTD?

CTD defines the five-module content organization. eCTD adds electronic metadata, XML structure, navigation, validation, transmission rules, and lifecycle operations that maintain documents across sequences.

Which CTD module contains clinical study reports?

Module 5 contains clinical study reports and related clinical information. Module 2 contains clinical overviews and summaries that integrate those reports into the overall efficacy, safety, dose, and benefit-risk argument.

Can a technically valid eCTD still be scientifically inadequate?

Yes. A validation tool can check file and metadata rules. It cannot establish whether the trials, analyses, safety database, manufacturing controls, nonclinical evidence, or proposed labeling support the requested action.

Does a submission end when the initial dossier is sent?

No. Authority questions, amendments, updated safety information, inspections, labeling revisions, commitments, variations, supplements, and other lifecycle sequences continue and may change the active dossier.