Skip to main content
search

August 26, 2026

SDTM 3.2, ADaM 3.2, SEND 4.2, and a controlled terminology update every six months. In a recent webinar, Rajesh Saha, senior CDISC consultant at Certara, made the case that this particular CDISC standards update is a harder problem than the industry’s usual pace of change, and walked through the mechanics of why, along with a concrete process for managing it.

Version fragmentation is a mapping problem, not just a scheduling one

The timeline alone explains part of the pressure. Studies that started on or after March 15, 2023 must follow SDTM IG 3.3 for FDA submission. Studies starting on or after March 15, 2025 follow IG 3.4. That’s a two-year gap between mandates, and IG 4.0, SEND 4.0, and ADaM 3.3.0 are already in the pipeline behind it.

What makes this operationally difficult isn’t just tracking which version applies to which study. It’s that each version changes real mapping and programming decisions. Rajesh pointed to the LC domain, which several sponsors are already implementing alongside LB to better handle demographic data for subjects with multiple enrollments, using a subject-level submission ID to distinguish enrollment records.

That’s a data model change that ripples into define.xml, ADaM derivations, and validation logic, not a cosmetic update. Sponsors running trials that started under IG 3.3 alongside newer trials on IG 3.4 are, in effect, maintaining two different mapping standards in

parallel, which is where bridging strategies become a permanent fixture of the data management function rather than a one-time transition task.

Layered on top of the SDTM and ADaM lineage is USDM, the unified study definition model. Version 4.2 went stable in 2025 and is gaining adoption alongside CDASH and ICH M11 protocol standards, as the industry moves toward digitizing the protocol itself rather than just the data collected under it.

USDM’s promise is real efficiency gains in downstream standardization, but Rajesh was clear that teams need to build fluency in a new data model while still maintaining every deliverable they’re already responsible for. That’s additive workload, not a replacement for existing processes, at least during the transition window.

Where the operational risk actually shows up

Rajesh named three specific risk areas, each with a different failure mode.

  • Validation instability. Controlled terminology and conformance rules update roughly every six months, independent of the major IG releases. A submission package that passes Pinnacle 21 Enterprise validation today can fail six months from now purely because the rule set caught up to a newer standard, not because anything in the package changed.
  • Resource burnout. Moving from SDTM IG 3.x to 4.0, adopting USDM, and integrating ICH M11 protocol standards all require deep, cross-functional retraining. That pulls senior programmers and data managers off active study delivery, and the cost shows up as schedule slippage as much as direct spend.
  • Compliance gaps. Public review periods for one standard frequently overlap with active releases of another. Rajesh gave the example of an ADaM package for anti-drug antibody data moving through review at the same time as a major IG update. That overlap raises the odds that a team treats a still-in-review version as production ready, or the reverse, simply because the review calendars aren’t synchronized.

None of these risks is new in isolation. What changed in the 2025 to 2026 window, in Rajesh’s framing, is that they’re compounding at the same time, which is what turns a manageable cadence of updates into genuine volatility. He was direct that organizations without a documented change management process should expect submission delays and data quality issues to surface during this stretch, not as a hypothetical but as a likely outcome.

A five-step CDISC change management process

The framework Rajesh recommends has five steps, and the discipline is in running all five for every release rather than reacting ad hoc to whichever update feels most urgent.

  1. Monitor. Track new metadata releases, controlled terminology updates, and guidance documents continuously rather than periodically.
  2. Assess impact. Evaluate the real implications for active studies, including rework scope, resource needs, process changes, and timeline impact.
  3. Decide and document. Classify each change as mandatory, recommended, strategic, or not currently applicable, and document the rationale regardless of outcome, including changes the organization decides to reject or defer.
  4. Implement. Define clear requirements, then update metadata standards to reflect the changes that were approved.
  5. Approve and publish. Release the updates as the next official, versioned iteration of the organization’s metadata standards.

Pinnacle 21 Enterprise supports each step directly. New CDISC and controlled terminology releases surface in the enterprise metadata module shortly after publication. The compare function in Define Designer lets teams check sponsor or study level metadata against a newly released standard and returns a report showing exactly what was added, removed, or changed, which is what impact assessment runs on in practice.

The change request module documents the decision itself, capturing rationale, review, and approval history for both approved and rejected changes, so the record holds up under audit even years later. Once changes are approved, the standards module handles implementation and publication of the updated version.

When should you adopt a new CDISC standard?

This was the most pointed question from the audience, and Rajesh’s answer rejected both easy extremes. Adopting every standard the day it publishes is unnecessary and expensive. Waiting for a regulatory mandate before assessing impact is riskier than it looks, because by the time a standard is mandatory, the assessment work should already be done.

His recommended approach is risk based. Check whether a regulatory authority is already signaling the change, the way FDA has with the LC domain. Weigh the actual efficiency or quality gain against the organization’s current bandwidth to absorb it. Assess organizational readiness honestly rather than optimistically. Then document the adopt, defer, or reject decision either way, with enough specificity that the same discussion doesn’t have to happen again in six months, and that an auditor reviewing the study years later can see exactly why the organization made the call it did.

Author

Wendy Young

Content Strategist

Wendy Young is a strategic content leader specializing in UX writing, product content strategy, and customer education for SaaS organizations. She helps companies bridge the gap between complex technology and exceptional user experiences by developing content frameworks that drive product adoption, strengthen brand consistency, and support business growth. Collaborating across product, engineering, design, marketing, and customer success, Wendy builds scalable content strategies that enable users to get the most from the products they use.