Cryogenic Monitoring System: One View of Every Tank and Site

A centralised cryogenic monitoring system continuously records liquid nitrogen level, vapour-phase temperature and events for every storage tank, brings all sites into one view and routes any deviation through a defined alarm escalation chain. The result: a fault is caught hours before samples warm up, and every reading is documented to GMP standards.

With one tank in one room, a local alarm by the door may be enough. Growth changes that. Tanks end up in different rooms, buildings or cities, samples belong to different studies or clients, and at 3 a.m. on a Sunday nobody is on site. At that point sample safety depends less on any individual sensor and more on the system behind it.

Why a cryogenic monitoring system should be centralised

A cryogenic tank holds its cold passively. If refilling fails, the LN₂ level drops slowly and the vapour-phase temperature rises first at the top storage positions. Between the start of a fault and actual sample loss there are usually hours to days. That margin is only useful if someone finds out in time.

Centralisation closes three gaps that are typical of stand-alone alarms:

  • Visibility: quality assurance sees the status of every tank at a glance instead of collecting printouts room by room.
  • Reliable escalation: an alarm always reaches a person who can act, not just a buzzer in an empty lab.
  • Consistent records: every tank follows the same thresholds, logging intervals and approval rules, which makes ISO 20387 or EU GMP audits far simpler.

For how monitoring fits into a wider redundancy strategy, see our article on cryogenic safety concepts, redundancy and alarm systems.

What should a cryogenic monitoring system measure?

A dependable system records far more than a single temperature. Six signals have proven their value in biobanks, cell therapy manufacturing and pharmaceutical research:

  • Liquid nitrogen level: level monitoring is the early-warning signal. It exposes a refill failure long before the temperature moves.
  • Vapour-phase temperature: measured at a representative worst-case position, usually just below the lid. Which position that is should come from temperature mapping of the storage tank.
  • Lid and access events: who opened the tank, when, and for how long. These records explain short temperature spikes and prove access control.
  • LN₂ supply: level or pressure of the supply vessel and the status of automatic filling.
  • Room oxygen: one litre of liquid nitrogen expands to roughly 700 litres of gas. Normal air contains 20.9 % oxygen by volume; alarm thresholds are commonly set at 19 % and 18 %. Our guide to liquid nitrogen safety in the laboratory covers the details.
  • System health: mains power, sensor faults and loss of communication. A monitoring system that fails silently is worse than none at all.

Temperature limits are anchored to the glass transition of water at about –135 °C, below which biological activity effectively stops. Many facilities therefore set the temperature alarm with a safety margin, often around –150 °C. The sensor side of this topic is covered in more depth in our article on temperature monitoring for cryogenic storage.

Which alarms does an LN₂ storage tank need?

Every tank needs at least a level alarm, a temperature alarm and a system alarm, each with a warning stage and an action stage. The warning buys time; the action alarm demands an immediate response.

Thresholds and delays

Each time the lid opens, the top position warms briefly. Without a delay, the system would alarm on every access and staff would soon learn to ignore it. A short, documented delay on temperature alarms prevents this alarm fatigue. Level and system alarms get no delay: they must fire instantly.

The escalation chain

Remote alarm forwarding follows a fixed order. A proven pattern:

Level 1: notify the responsible lab contact by app, SMS or phone call.

Level 2: if nobody acknowledges within a defined window, notify a deputy and the lab manager.

Level 3: forward to site security, facilities or the building management system, which are staffed around the clock.

Every alarm must be acknowledged, and the acknowledgement goes into the audit trail with name, time and comment. Two independent transmission paths, such as network and cellular, plus an uninterruptible power supply protect the chain. Scheduled alarm tests prove that it actually works.

Multi-site monitoring: how the architecture works

Multi-site monitoring works when every layer can keep running on its own. A three-tier design has become the norm:

  • At the tank: sensors and a local controller that measure level and temperature, manage filling and raise a local alarm if needed.
  • At the site: software that collects data from every tank on site, stores it and forwards alarms. If the external connection drops, it keeps recording.
  • Centrally: one dashboard for quality assurance and operations with a site overview, trends and reports.

The key principle is data ownership at site level. The central dashboard is a window, not a single point of failure. Clocks are synchronised so that events can be compared across sites, and a link to building management ensures alarms reach people who are on duty 24/7 anyway.

A structured risk assessment of cryogenic storage using FMEA shows which failure scenarios the design has to cover.

What must a GMP-compliant audit trail contain?

A GMP-compliant audit trail records who changed what, when and why, automatically, with a timestamp and without any way to edit it afterwards. The reference points are EU GMP Annex 11 for computerised systems and, in the US, FDA 21 CFR Part 11. Both expect data to meet ALCOA+ principles: attributable, legible, contemporaneous, original and accurate, plus complete, consistent, enduring and available.

For cryogenic monitoring, that means:

  • continuous readings with timestamp and tank ID
  • every alarm with trigger, acknowledgement, responsible person and comment
  • every change to thresholds, delays or recipient lists, with old and new values
  • individual user accounts, never shared logins
  • routine backups and a verified export for inspections

The monitoring system is itself a computerised system and has to be validated. In practice it is qualified during the facility's IQ/OQ and requalified after changes.

How Consarctic® monitors cryogenic storage

Consarctic® is a market-leading German manufacturer of cryogenic systems for the life sciences, delivering storage, LN₂ supply and monitoring as one integrated system. The Consarctic® Monitoring-System combines three components:

  • Biolog®: Consarctic's own monitoring software, which logs temperature, event and fill data for each container on a local PC.
  • NRT3010: the automatic refill unit that keeps the LN₂ level constant in each storage container.
  • FMCS Touch: the central control layer for automatic liquid nitrogen supply, coordinating several tanks.

Alarm forwarding, remote access and building-technology interfaces complete the system; the right connection for your sites is defined during planning. Tanks from the ABV+, ABS+, BSD+ and BSF+ series in our cryogenic storage systems can all be brought into one monitoring concept.

Through Consarctic's services, certified technicians install the monitoring and qualify it with IQ/OQ. The 24/7 emergency service is available 365 days a year and on site within hours. Consarctic® works to ISO 9001:2015 and EN ISO 13485:2016 and serves more than 1,500 customers in over 30 countries, including biobanks such as Qatar Biobank and hospitals such as Charité Universitätsmedizin Berlin.

Frequently Asked Questions (FAQ)

Can multiple cryogenic storage sites be monitored centrally?

Yes. Each site records its own tank data locally and forwards alarms independently, while a central dashboard brings all sites together. Each site must keep logging and alarming if the network fails, so the central layer never becomes a single point of failure.

What alarms does a liquid nitrogen tank need?

At minimum a liquid nitrogen level alarm, a vapour-phase temperature alarm and a system alarm for power, sensor or communication faults, each with a warning and an action stage. The room also needs an oxygen depletion alarm. All alarms run through an escalation chain that requires acknowledgement.

What must a GMP-compliant audit trail include?

Every reading with a timestamp, every alarm with its acknowledgement and responsible person, and every change to thresholds or recipients with old and new values. It must be automatic, tamper-proof and tied to individual users, as EU GMP Annex 11 and 21 CFR Part 11 require.

How often should the alarm chain be tested?

There is no fixed legal interval. Many facilities test the full chain, right up to the last escalation level, at least quarterly and after any change to recipients or hardware. Each test is documented.

Protection that never sleeps

A centralised cryogenic monitoring system turns scattered sensors into one system that detects faults early, escalates them reliably and documents every step. The hardware is only half the job: thresholds, escalation rules and regular testing decide whether an alarm reaches someone when it matters.

If an alarm fired at 3 a.m. tonight, would it reach someone who can act? Talk to the Consarctic® team. We plan, install and qualify your monitoring, from a single tank to a multi-site cryogenic storage network.