Container Closure Integrity Testing
Purpose and scope
Container Closure Integrity Testing (CCIT) evaluates whether a container-closure system can maintain the barrier required to protect a sterile product throughout its intended shelf life.
CCIT may be applied during:
- Container-closure development.
- Packaging-system selection.
- Sealing-process development.
- Equipment and process qualification.
- Product stability studies.
- Transportation and distribution studies.
- Routine manufacturing, where scientifically justified or required.
- Investigations and change assessments.
CCIT is not a replacement for the release sterility test required for applicable sterile drug products. It does not establish that the product was initially sterile. Instead, it provides evidence that the closed container can maintain the required barrier after the sterile product has been manufactured and sealed.
FDA specifically recognizes appropriately validated physical, chemical, or microbiological integrity tests as possible alternatives to sterility testing at applicable stability time points. FDA does not consider CCIT a replacement for required product sterility testing before release. See the FDA guidance on container and closure system integrity testing in stability protocols.
Regulatory and compendial framework
The regulatory basis for container-closure control includes:
- 21 CFR 211.94, which requires drug-product containers and closures to provide adequate protection against foreseeable external factors that could cause deterioration or contamination.
- 21 CFR 211.160, which establishes requirements for scientifically sound laboratory controls.
- 21 CFR 211.166, which requires a written stability-testing program.
- 21 CFR 211.167, which addresses special testing requirements for sterile and pyrogen-free products.
- FDA Guidance for Industry: Container Closure Systems for Packaging Human Drugs and Biologics.
- FDA Guidance for Industry: Sterile Drug Products Produced by Aseptic Processing.
- EU GMP Annex 1, where applicable.
Relevant USP chapters include:
- USP
<1207>Package Integrity Evaluation—Sterile Products. - USP
<1207.1>Package Integrity Testing in the Product Life Cycle. - USP
<1207.2>Package Integrity Leak Test Technologies. - USP
<1207.3>Package Seal Quality Test Technologies. - USP
<382>Elastomeric Component Functional Suitability in Parenteral Product Packaging/Delivery Systems.
USP chapters should be cited by chapter number without linking to paywalled USP content.
EU GMP Annex 1 distinguishes fusion-closed containers from systems such as stoppered vials. It establishes specific 100% integrity-testing expectations for glass ampoules, Blow-Fill-Seal units, and small-volume fusion-closed containers of 100 mL or less. Other closure systems may use a scientifically justified sampling plan and validated method.
This distinction should not be converted into a general statement that every sterile container requires 100% CCIT.
What container closure integrity means
Container closure integrity is the ability of the assembled packaging system to maintain its required barrier against potential ingress or product loss.
Depending on the product and package, integrity may be required to prevent or control:
- Microbial ingress.
- Gas ingress or loss.
- Moisture ingress or loss.
- Product leakage.
- Solvent loss.
- Loss of vacuum.
- Loss of an inert headspace.
- Entry of environmental contaminants.
The necessary barrier is product- and package-specific. A method suitable for detecting liquid leakage may not adequately evaluate microbial-barrier risk, oxygen ingress, moisture transfer, or loss of headspace pressure.
An intact system at the time of filling does not automatically remain intact through shelf life. Closure performance can be affected by component aging, elastomer relaxation, temperature cycling, pressure changes, handling, transportation, and interactions among the product and packaging materials.

CCIT, sterility testing, and seal-quality testing
These evaluations provide different evidence and should not be treated as interchangeable.
| Evaluation | Primary question |
|---|---|
| Sterility testing | Did viable microorganisms grow under the conditions of the test? |
| CCIT | Does the assembled container-closure system maintain the required barrier? |
| Seal-quality testing | Were the closure components assembled with acceptable physical or dimensional characteristics? |
| Visual inspection | Are visible container, closure, or product defects present? |
Crimp diameter, residual seal force, stopper height, cap torque, roll depth, seal appearance, or fusion-seal width can support process control. These measurements do not independently demonstrate container-closure integrity unless an appropriate relationship to integrity performance has been established.
Similarly, passing CCIT does not prove that the product was initially sterile or that every aspect of the sealing process was properly controlled.
Container-closure systems and potential leak paths
CCIT can be applied to:
- Stoppered and capped vials.
- Prefilled syringes.
- Cartridges.
- Ampoules.
- Blow-Fill-Seal containers.
- Form-Fill-Seal containers.
- Flexible bags.
- Bottles with screw-cap or induction-seal systems.
- Combination-product container and delivery systems.
Potential leak paths depend on the package design. For a stoppered vial, potential failure mechanisms include:
- Incomplete stopper seating.
- Stopper tilt or extrusion.
- Channels at the stopper–vial interface.
- Elastomer damage.
- Vial-finish irregularities.
- Glass cracks or chips.
- Inadequate stopper compression.
- Improper cap application.
- Component dimensional incompatibility.

For syringes and cartridges, additional paths may occur at:
- Plunger-stopper interfaces.
- Tip caps.
- Needle shields.
- Staked-needle interfaces.
- Luer connections.
- Access points or administration ports.
Method selection should begin with understanding the package design, required barrier, likely failure mechanisms, product characteristics, and conditions of use.
Maximum allowable leakage limit
The maximum allowable leakage limit, or MALL, represents the greatest leakage that can be tolerated without compromising the product’s critical quality requirements during its lifecycle.
The MALL should be established using scientific evidence appropriate to the product and package. Relevant considerations may include:
- Microbial-barrier requirements.
- Product sensitivity to oxygen or moisture.
- Headspace-gas requirements.
- Product or solvent loss.
- Package dimensions and materials.
- Route of administration.
- Storage conditions.
- Shelf life.
- Transportation exposure.
- Clinical consequences of integrity loss.
A generic leak diameter should not be assigned to every product. A defect size associated with microbial ingress under one test condition does not necessarily represent the applicable MALL for every product, package, or leak geometry.
The method’s validated detection capability should be suitable relative to the justified MALL.
Selecting a CCIT method
Method selection should be based on intended use rather than a general hierarchy of technologies.
Important selection factors include:
- Container material and geometry.
- Rigid, semi-rigid, or flexible construction.
- Product conductivity.
- Product viscosity and surface tension.
- Fill volume and headspace volume.
- Headspace pressure and gas composition.
- Product vapor pressure.
- Package transparency.
- Expected leak path.
- Required detection capability.
- Destructive or nondestructive operation.
- Laboratory, at-line, or automated application.
- Testing speed and sample throughput.
- Compatibility with stability samples.
- Ability to retain the tested unit for other analyses.
CCIT methods are commonly divided into deterministic and probabilistic technologies.

Deterministic methods
Deterministic methods measure a physical or chemical response using controlled test conditions and an objective measurement system.
Potential technologies include:
| Method | General application | Important limitations |
|---|---|---|
| Vacuum decay | Rigid or semi-rigid packages containing gas or headspace | Package volume, product vapor, stabilization time, chamber design, and package deformation can affect the response |
| Pressure decay | Packages that can be internally pressurized or otherwise tested under positive pressure | Test configuration may be intrusive and may not represent the commercial package condition |
| Mass extraction | Air-based leakage measurement under controlled vacuum | Package volume, deformation, fixture design, and stabilization affect performance |
| Helium leak detection | Highly sensitive characterization using helium as a tracer gas | Helium introduction, sample preparation, leak-standard control, and commercial-package representativeness require justification |
| High-voltage leak detection | Liquid-filled, electrically nonconductive containers containing sufficiently conductive product | Product conductivity, container geometry, fill level, wall thickness, and air bubbles can affect sensitivity |
| Laser-based headspace analysis | Packages with a measurable headspace gas or pressure attribute | Requires an optical path and may detect the consequence of leakage over time rather than an instantaneous physical leak |
| Force or mechanical decay methods | Flexible or semi-flexible packages | Package material behavior, creep, temperature, fixture design, and headspace conditions may affect results |
A deterministic method is not automatically suitable merely because it generates a numerical result. Its suitability must be demonstrated for the specific product, container, closure, defect type, and intended application.
Vacuum decay
Vacuum decay places the test package in a chamber and applies a controlled vacuum. Gas escaping from a leaking package can cause a measurable change in chamber pressure or vacuum behavior.

Vacuum-decay performance can be influenced by:
- Chamber dead volume.
- Fixture design.
- Package dimensions.
- Headspace volume.
- Product vapor pressure.
- Package temperature.
- Flexible package movement.
- Stabilization and test time.
- Surface moisture.
- Instrument resolution.
- Background leakage.
Method development should establish evacuation, stabilization, measurement, and venting conditions appropriate to the package.
Probabilistic methods
Probabilistic methods depend on a challenge material passing through a leak path during the test.
Examples include:
- Dye ingress.
- Microbial ingress.
- Tracer-liquid ingress.
- Bubble emission under defined conditions.
These methods may remain useful for development, comparison, specialized package configurations, or situations where a suitable deterministic technology has not been established.
Their limitations may include:
- Dependence on exposure conditions.
- Stochastic penetration behavior.
- Destructive testing.
- Operator interpretation.
- Product interference.
- Difficulty characterizing very small defects.
- Greater uncertainty around negative results.
A probabilistic method should not be rejected solely because of its category. Its appropriateness depends on the scientific question, method capability, validation evidence, and intended use.
Method development before validation
Formal validation should begin only after the test method and its operating conditions have been sufficiently developed.
Development should define:
- Intended use.
- Package configurations.
- Product or surrogate matrix.
- Required detection capability.
- Expected defect mechanisms.
- Test sequence and conditioning.
- Equipment settings.
- Fixture and chamber configuration.
- Environmental conditions.
- Sample preparation.
- Control standards.
- Data analysis.
- Preliminary acceptance threshold.
- Retest and invalid-test rules.
Method development should investigate variables that could shift the response of intact or defective units. Depending on the technology, these may include:
- Product temperature.
- Equilibration time.
- Fill and headspace volume.
- Container orientation.
- Product conductivity.
- Viscosity and surface tension.
- Vapor pressure.
- Package deformation.
- Surface moisture.
- Closure aging.
- Instrument warm-up.
- Operator handling.

A method that performs well with empty containers may not perform equivalently with product-filled units. Surrogates should be used only when their representativeness is supported.
Known defects and control standards
Validation requires suitable positive and negative controls.
Negative controls
Negative controls normally represent intact packages manufactured or assembled under defined conditions. They should be evaluated for:
- Component and assembly history.
- Representativeness of production units.
- Storage and handling.
- Potential damage.
- Baseline signal distribution.
- Reuse limitations, where applicable.
An assumed intact package should not automatically be treated as a qualified negative control without appropriate examination or characterization.
Positive controls
Positive controls represent packages with known or intentionally introduced defects.
Possible approaches include:
- Calibrated capillaries.
- Laser-drilled holes.
- Microtubes.
- Controlled seal channels.
- Misassembled components.
- Reduced closure compression.
- Representative cracks, punctures, or seal defects.
Each type of positive control answers a different question. A calibrated capillary may support leak-rate characterization but may not reproduce the geometry, tortuosity, surface interaction, or flow behavior of an actual closure defect.
Positive controls should have defined:
- Construction method.
- Defect location.
- Nominal leak rate or dimension.
- Characterization method.
- Traceability.
- Storage conditions.
- Use limitations.
- Reverification or replacement interval.
The study may need both calibrated leakage standards and realistic package defects.
CCIT method validation
Method validation should demonstrate that the procedure is suitable for its specified purpose.
The protocol should identify:
- Intended use.
- Product and package configurations.
- Method principle.
- Equipment and software.
- Control standards.
- Operating parameters.
- Validation characteristics.
- Statistical methods.
- Acceptance criteria.
- Deviations and invalid-test rules.
- Data-review requirements.
- Approved report content.
Detection capability
Detection capability should be established using defects that bracket the required performance level.
For deterministic methods, the study may evaluate:
- Signal response across defect levels.
- Separation of intact and defective populations.
- Measurement variation.
- Decision threshold.
- False-accept and false-reject risk.
For probabilistic methods, detection should be evaluated across an appropriate number of replicate units and challenge conditions. Probability of detection may be more informative than reporting a single observed defect size as an absolute detection limit.
The validation claim should be no broader than the evidence. Detection of a laser-drilled hole of a stated nominal diameter does not automatically prove equivalent detection of every natural leak of the same apparent diameter.
Specificity and discrimination
The method should distinguish integrity failures from unrelated sources of signal variation.
Potential interferences include:
- Product vapor.
- Residual surface moisture.
- Temperature differences.
- Container-wall variation.
- Headspace variation.
- Cosmetic defects.
- Electrical conductivity changes.
- Bubbles or foam.
- Fixture leakage.
- Instrument drift.
Precision
Precision testing should address the variability relevant to intended use, including:
- Repeat testing.
- Different operators.
- Different days.
- Different instruments.
- Different fixtures or chambers.
- Different component or product lots.
- Permitted environmental conditions.
Repeatability and intermediate precision should be distinguished where appropriate.
Robustness
Robustness studies should challenge reasonable variations in:
- Sample temperature.
- Conditioning time.
- Instrument settings.
- Chamber or fixture installation.
- Test duration.
- Package orientation.
- Environmental conditions.
- Operator preparation.
Robustness ranges should not exceed the operating ranges supported by development data.
Acceptance threshold
The pass/fail threshold should be supported by:
- Intact-package response distribution.
- Defective-package response distribution.
- Measurement uncertainty.
- Instrument capability.
- Required detection performance.
- False-accept risk.
- False-reject risk.
- Guard bands, where appropriate.
Complete separation of all study populations may be desirable but is not a universal requirement. When distributions approach or overlap, the threshold and associated decision risks require explicit statistical justification.
Bracketing and matrixing
Grouping multiple products or package configurations may be acceptable when scientific equivalence or justified worst-case relationships are demonstrated.
The evaluation should consider:
- Container size and geometry.
- Closure design.
- Component materials.
- Fill volume.
- Headspace volume.
- Product characteristics.
- Sealing process.
- Expected leak path.
- Method sensitivity.
- Storage conditions.
The largest package, smallest headspace, maximum fill volume, or lowest closure force should not automatically be designated worst case. Worst case depends on the test principle and package-failure mechanism.
Equipment qualification and computerized controls
Analytical method validation does not replace qualification of the CCIT equipment.
Equipment qualification should address:
- Instrument installation.
- Utilities and environmental requirements.
- Measurement ranges.
- Pressure, vacuum, electrical, optical, or gas systems.
- Chambers, fixtures, and change parts.
- Calibration.
- Leak or reference standards.
- Alarms and interlocks.
- Operating sequences.
- Access control.
- Recipe control.
- Calculation accuracy.
- Data storage and retrieval.
- Audit trails, where required.
- Interfaces and data transfer.
- Backup and recovery.
- Preventive maintenance.
Operational qualification should challenge failures such as:
- Inability to reach the required vacuum or pressure.
- Chamber leakage.
- Failed reference-standard check.
- Sensor drift.
- Interrupted test cycle.
- Sample misloading.
- Fixture mismatch.
- Communication failure.
- Power interruption.
- Unauthorized method changes.
Performance qualification should demonstrate reliable operation using representative packages, trained analysts, approved procedures, and qualified control standards.
System suitability and routine method control
System suitability verifies that the instrument and method remain capable of performing as intended at the time of use. A system-suitability procedure may include:
- Instrument readiness checks.
- Chamber or fixture leak checks.
- Reference-standard verification.
- Positive-control testing.
- Negative-control testing.
- Blank testing.
- Environmental-condition verification.
- Acceptance of baseline and challenge responses.
- Review of calibration and maintenance status.
The number and frequency of controls should be based on method risk, test duration, instrument stability, and intended application.
Control failure should trigger a predefined response addressing:
- Validity of the current run.
- Results generated since the last acceptable check.
- Instrument condition.
- Control-standard condition.
- Need for retesting.
- Potential impact on previously reported results.
Application and sampling strategy
CCIT sampling should be linked to the purpose of the study. One sampling plan should not be applied indiscriminately to development, qualification, stability, and routine manufacturing.
Container-closure development
Development studies may evaluate:
- Component combinations.
- Dimensional tolerances.
- Closure settings.
- Product effects.
- Storage orientation.
- Temperature and pressure exposure.
- Transportation stress.
- Intentional sealing defects.
- Package aging.
Sealing-process qualification
CCIT may support stoppering and vial capping system qualification by demonstrating closure performance across justified operating conditions.
Samples may represent:
- Multiple sealing heads.
- Component lots.
- Line speeds.
- Beginning, middle, and end of runs.
- Process parameter ranges.
- Changeovers.
- Representative interventions.
- Worst-case component combinations.
- Lyophilized and liquid presentations.
CCIT should be interpreted with seal-quality measurements and equipment data rather than used as a stand-alone substitute for sealing-process qualification.
Release and routine manufacturing
Routine batch CCIT is not universally required for every stoppered sterile product. Its use and frequency should be based on:
- Regulatory commitments.
- Approved specifications.
- Container-closure risk.
- Sealing-process capability.
- Method availability.
- Historical performance.
- Component and equipment controls.
- Applicable regulatory expectations.
Nondestructive technology does not automatically justify 100% inspection. The technical capability, control strategy, validated throughput, false-reject behavior, data handling, and regulatory commitments must be considered.
Stability testing
Stability CCIT should represent the marketed container-closure system and approved storage conditions. Applicable time points may include:
- Initial testing.
- Intermediate intervals.
- Annual intervals.
- Expiration.
- Post-transportation or distribution studies.
- Additional time points established in the approved protocol.
FDA’s 2008 guidance recommends an appropriate CCIT method annually and at expiration when CCIT is used in place of sterility testing within the stability program, unless otherwise required by applicable regulations or the approved protocol.
The samples tested at one stability interval should not automatically be returned to storage for testing at a later interval, even when the method is nondestructive. The effect of test exposure and handling must be considered.
Transportation and distribution
Container-closure validation should consider foreseeable transportation and shipping conditions that could affect integrity, including:
- Vibration.
- Shock.
- Compression.
- Temperature cycling.
- Low-pressure or decompression exposure.
- Frozen storage.
- Cold-chain handling.
- Package orientation.
The study should distinguish transportation simulation, package conditioning, and CCIT. Each requires its own defined method and acceptance criteria.
Integration with aseptic filling and sealing
CCIT should be connected to the process that creates the closure. For vial systems, relevant controls may include:
- Stopper preparation.
- Stopper seating.
- Stopper-height detection.
- Vial-finish dimensions.
- Stopper dimensions and formulation.
- Cap dimensions.
- Capping-head settings.
- Crimp geometry.
- Tool wear.
- Line speed.
- Lyophilizer final stoppering.
- Protection of stoppered but uncapped vials.
These relationships should be coordinated with the aseptic filling line architecture and fill line qualification lifecycle.
A dimensional or mechanical parameter should be treated as a process control rather than a direct CCIT result unless its relationship to integrity has been established.
Investigation of CCIT failures
An initial failing result should be preserved and investigated. Passing a repeat test does not invalidate the original failure. The investigation should evaluate:
- Sample identity and history.
- Instrument status.
- System-suitability results.
- Calibration and maintenance.
- Chamber and fixture condition.
- Method execution.
- Analyst actions.
- Data and audit trails.
- Positive and negative controls.
- Product or surface interference.
- Container and closure defects.
- Sealing-equipment parameters.
- Component lots.
- Related visual-inspection findings.
- Stability or transportation exposure.
- Similar results and trends.
The investigation should distinguish among:
- Confirmed package-integrity failure.
- Instrument or fixture failure.
- Control-standard failure.
- Sample-handling damage.
- Method interference.
- Invalid test execution.
- Unresolved result.
Retesting should follow an approved, scientifically justified procedure. Testing additional units until acceptable results are obtained is not an acceptable investigation strategy.
Lifecycle control and revalidation
The validated state should be maintained through:
- Calibration.
- Preventive maintenance.
- System-suitability review.
- Control-standard management.
- Analyst qualification.
- Data trending.
- Periodic method review.
- Software and configuration control.
- Change control.
- Deviation and CAPA review.
- Instrument replacement planning.
- Method transfer controls.
Potential revalidation triggers include:
- New container or closure.
- Component supplier or manufacturing-site change.
- Elastomer formulation or coating change.
- Container dimensional change.
- Sealing-process change.
- New fill volume or product formulation.
- New package orientation or storage condition.
- Extended shelf life.
- Modified instrument hardware or software.
- New chamber or fixture.
- Revised test parameters.
- Revised acceptance threshold.
- New testing laboratory.
- Adverse result trend.
- Repeated system-suitability failures.
- Change to the established MALL or detection requirement.
The assessment should determine whether the change requires documentation only, targeted verification, partial revalidation, or full revalidation. This decision should follow the site’s change-control impact assessment and risk-based requalification processes.
Common deficiencies
Common CCIT deficiencies include:
- Treating CCIT as proof of initial product sterility.
- Selecting a method without defining its intended use.
- Using a generic leak size without product-specific justification.
- Assuming that every deterministic method is superior for every package.
- Claiming universal submicron sensitivity.
- Validating empty containers without demonstrating applicability to filled units.
- Using uncharacterized positive controls.
- Assuming nominally intact packages are qualified negative controls.
- Confusing method development with method validation.
- Failing to qualify the test instrument and computerized functions.
- Using equipment PQ as a substitute for analytical method validation.
- Assigning worst case without considering the measurement principle.
- Applying one sampling plan to every lifecycle application.
- Assuming nondestructive testing requires 100% inspection.
- Treating a repeat passing result as invalidation of an initial failure.
- Failing to assess transportation and shelf-life effects.
- Failing to evaluate component, process, and equipment changes.
Conclusion
Container Closure Integrity Testing provides evidence that a container-closure system can maintain the barrier required to protect a sterile product throughout its lifecycle.
A defensible CCIT program requires more than selecting sensitive instrumentation. It requires a product-specific barrier requirement, justified method selection, representative defect standards, method validation, equipment qualification, system suitability, scientifically justified sampling, investigation controls, and lifecycle management.
CCIT is strongest when integrated with packaging development, sealing-process qualification, stability testing, transportation studies, and continued process verification.

