It Got Worse Than Expected: Lessons from Three Years of FDA CBER Requests on SDTM, ADaM, and TFLs


August 20, 2026

Submitting clinical study data to the FDA’s Center for Biologics Evaluation and Research (CBER) can appear straightforward on paper. In addition to established CDISC standards and the FDA Study Data Technical Conformance Guide, vaccine submissions are subject to additional expectations described in CBER “Submitting Study Datasets for Vaccines to the Office of Vaccines Research and Review” (OVRR) guidance and “CDISC Vaccines Therapeutic Area User Guide” v1.1 (TAUG-Vax). These expectations include the use of specific SDTM domains for reactogenicity, safety, efficacy, and immunogenicity data.

However, many teams have discovered that the real challenge begins when standards, reviewer expectations, and evolving regulatory feedback intersect.

At the CDISC Europe Interchange 2026, Mark Malayas shared Cytel experience from three years of retrospective CBER requests on SDTM, ADaM, and TFLs for a vaccine submission package. The title of the presentation, “It Got Worse Than Expected,” captured the central lesson: what initially appears to be a contained SDTM remapping exercise can rapidly expand into a full package remediation effort affecting analysis datasets, outputs, documentation, validation strategy, and submission planning.

 

CBER expectations are specific, and not always fully aligned with current standards

CBER regulates biologic products, including vaccines, gene therapies, and blood products, while the FDA’s Center for Drug Evaluation and Research (CDER), primarily regulates prescription drugs, generic drugs, biosimilars, and over-the-counter products. For vaccine submissions, CBER expectations are shaped not only by CDISC standards, but also by vaccine specific guidance, including the CBER OVRR and the CDISC Vaccines Therapeutic Area User Guide.

While these documents provide valuable direction, they can also introduce practical challenges. Some vaccine-specific guidance was published several years ago, whereas CDISC standards and FDA technical guidance continue to evolve. As a result, sponsors may face situations where CBER preferences do not align completely with the current SDTM model or standard validation expectations.

For example, CBER may request additional variables in SDTM domains to aid review, even when those variables are not part of the standard SDTM structure for that domain. CBER may also request derived information, such as event duration, to be included directly in SDTM, despite SDTM’s general principle of representing collected data with minimal derivation. While such additions may enhance review efficiency, they frequently generate validation findings that require clear justification within the reviewer’s guide.

 

The initial request is often only the beginning

One of the strongest messages from the case study was that the initial scope was underestimated! The team originally assessed the CBER feedback as primarily affecting SDTM mapping. In practice, changes to SDTM had downstream consequences across the full submission package.

When data were remapped from one SDTM domain to another, corresponding ADaM datasets required reassessment. Updates to ADaM datasets led to TFL regenerations. When datasets and outputs changed, define.xml, reviewer guides, aCRF annotations, validation explanations, and the Study Data Standardization Plan (SDSP) also needed revision.

This created a chain reaction. What started as a domain-level mapping change request quickly affected analysis traceability, output reproducibility, package structure, and documentation strategy.

The challenge was even greater because several studies had already been completed, often by other vendors, with Clinical Stuy Reports (CSRs) finalized. In these situations, retrospective remediation introduced additional complexity and posed potential risks to traceability back to the original CSR package.

As a result, collaboration among programmers, statisticians, clinicians, and regulatory stakeholders became critical. Robust cross-functional impact assessments were needed to evaluate the consequences of each requested change across datasets, analyses, outputs, and submission documentation. Close coordination across functions was essential to manage the remediation effort efficiently while maintaining full traceability from source data through analysis results and regulatory deliverables.

 

SDTM carried the largest burden

Most CBER requests impacted SDTM packages. Some were expected. For example, for vaccine studies, reactogenicity and clinical disease efficacy endpoints data may need to be represented in Clinical Events (CE) and Findings About Clinical Events (FACE) domains rather than Adverse Events (AE) or supplemental qualifiers.

Other requests were less expected and more challenging to implement.

As an example, findings data had to be split across the FACE domain for solicited events and the FAEF domain for efficacy endpoints. Certain unsolicited events that were also clinical endpoints needed to be mapped in both CE and AE. CBER requested additional variables across domains, including reference date and timepoint-related variables, to support review. In CE, additional variables were introduced to identify the clinical events included in the primary efficacy analysis, information that would traditionally be traceable through ADaM rather than directly available in SDTM. Event duration was derived within CE for solicited events. SV (Subject Visits) was used for scheduled and unscheduled visit data, including the use of variables associated with a more recent SDTM IG version than the rest of the package.

These requests were not simply technical edits. They required interpretation, derivation decisions, source-to-target traceability, reviewer-guide justification, and careful management of validation findings.

 

ADaM and TFLs were affected through dependency

Although fewer direct requests were made to ADaM, the analysis layer was still significantly affected. When clinical disease efficacy endpoint records were removed from ADAE and represented separately, analysis structures needed to change. Reactogenicity and efficacy analyses required clearer separation, including creation of a dedicated ADaM efficacy (ADEFF) dataset for clinical disease efficacy endpoints.

Additional timing and reference variables were also carried into ADaM to support review. More importantly, any SDTM domain affected by remapping or derivation had to be evaluated for downstream ADaM impact.

The TFLs (Tables, Figures and Listings) impact followed naturally. Outputs based on updated ADaM datasets had to be regenerated. Additional post-hoc outputs were also produced to support the CSR addendum and complement FDA requests.

In some cases, the team had to manage multiple submission packages: one supporting the original completed CSR and another containing updated datasets in response to CBER feedback. Maintaining a clear distinction between these packages was essential. When completed studies undergo retrospective remediation, sponsors must be able to demonstrate which deliverables support the original CSR and which reflect subsequent regulatory requests, while preserving traceability between the two.

The remediation effort also highlighted challenges related to reproducibility. In certain cases, datasets were updated to address CBER requests, but SAS output programs were not necessarily revised. As a result, some analyses could no longer be reproduced directly from the remediated datasets. This created additional complexity in establishing traceability.

 

Documentation became a core deliverable, not an afterthought

A recurring theme was the importance of documentation. Every CBER interaction (Figure 1), information request, response, mapping decision, and implemented change had to be carefully tracked.

 

Figure 1: Sponsor-FDA CBER Interactions

 

This was especially important where CBER requests created apparent non-conformance with supported standards. In one example, a study had 166 Pinnacle 21 validation issues, with 45 attributable to CBER-requested additions, mainly variables not expected in the relevant SDTM domain. Those issues could not simply be ignored. They had to be explained clearly in the compliance section of the reviewer’s guide.

The SDSP also required updates, including updates to the CBER appendix, and documentation of non-conformance to supported standards. define-xml, reviewer guides, and aCRF annotations all needed to remain synchronized with the implemented data strategy.

In this kind of submission, documentation is not an administrative cleanup. It is part of the regulatory argument.

 

Three lessons for future CBER submissions

The Cytel case study shows that CBER submission preparation is not only about creating technically compliant datasets. It involves managing a connected ecosystem of standards, reviewer expectations, analysis dependencies, and documentation.

 

Lesson 1: Engage early and design with CBER expectations in mind!

For vaccine programs, CBER and OVRR expectations should be considered from data collection onward, not only at submission time. Early review of the annotated CRF, early preparation of the CBER SDSP appendix, and early alignment on SDTM mapping strategies can significantly reduce the risk of extensive retrospective remediation.

 

Lesson 2: Expect gaps between standards and reviewer expectations

Current CDISC standards and guidance may not fully address all CBER review needs.  Teams should be prepared to discuss, challenge when appropriate, and document rationale for chosen approach.

 

Lesson 3: Treat remediation as a cross-functional submission effort

Retrospective remediation is rarely limited to SDTM. Changes can cascade across ADaM datasets, TFLs and submission documentation. Successful impact assessment and remediation require close collaboration among programmers, statisticians, clinicians, data managers, and regulatory stakeholders. Maintaining complete traceability of requests, decisions, implementations, and downstream impacts is essential to preserving confidence in the submission package.

 

In short: doing it right from the beginning will avoid extensive downstream rework at submission.

 

Interested in learning more?

In you’re interested in learning more, or have questions, register today for the authors’ upcoming webinar, “FDA CBER Requests in Vaccine Submissions: Lessons from a Recent Submission Preparation” on Sept. 3:

Register today!
Subscribe to our newsletter

Mark Malayas

Principal Statistical Programmer

Mark Malayas is Principal Statistical Programmer at Cytel. Mark has more than 15 years of experience in the pharmaceutical industry working as a statistical programmer for both sponsors and CROs. He has been working for Cytel for the last 5+ years.

He has a bachelor’s degree in statistics and has been using SAS for more than 22 years.

Read full employee bio

Florence Le Maulf

Director, Biostatistics

Florence Le Maulf is a Director, Biostatistics in the Cytel PBS Biostatistics team since 2019 and has extensive experience with all statistical tasks related to the planning, conduct, analysis and reporting of clinical trials. Florence brings more than 20 years of experience as a Trial or Program Statistician in large pharma and CRO organizations in several therapeutic areas mainly in respiratory, oncology, CNS and cardiovascular. Florence was the lead statistician for several submission projects, overseeing integrated analyses (ISS/ISE) and statistical regulatory strategy. She also represented statistics in interactions with regulatory authorities (inc. FDA, EMA, PMDA). Florence is a stats submission SME, providing stats support, acting as stats lead or providing expert stats input to over 25 submission projects.

Read full employee bio

Virginie Jego

Director, Biostatistics

Virginie Jego is Director, Biostatistics at Cytel. Virginie is a biostatistics leader with over 20 years of experience in the pharmaceutical industry, having worked in both sponsor organizations and CROs. Her expertise spans multiple therapeutic areas, including vaccines. Throughout her career, she has contributed to numerous regulatory submissions to major health authorities, including the EMA, FDA, and PMDA.

Read full employee bio

Angelo Tinazzi

Senior Director, Statistical Programming

Angelo Tinazzi is Senior Director, Statistical Programming at Cytel. Angelo is a well-published and recognized expert in statistical programming, with over 25 years’ experience in clinical research. In particular, his core expertise lies in the application of CDISC standards across ​different therapeutic areas, such as data submission to health authorities like the ​FDA and PMDA.

As well as being an authorized CDISC instructor, Angelo is former member of the CDISC European Committee, and co-lead of the Italian-speaking CDISC User Network. Angelo is also conference co-chair for PHUSE EU Connect 2026 and conference chair for PHUSE EU Connect 2027.

Prior to joining Cytel, Angelo worked at Merck Serono, SENDO Foundation, Phamarcia & Upjohn, Simbologica SAS Quality Partner, the UK Medical Research Council, and the Institute for Pharmacological Research “Mario Negri.”

Read full employee bio

Claim your free 30-minute strategy session

Book a free, no-obligation strategy session with a Cytel expert to get advice on how to improve your drug’s probability of success and plot a clearer route to market.

glow-ring
glow-ring-second