Skip to content
complianceofficer

21 CFR Part 11 compliant software, GxP compliance software and computer system validation

21 CFR Part 11 compliant software is software that implements the electronic record and electronic signature controls the FDA regulation requires: validation, secure and computer-generated audit trails, authority checks, readable record copies, and signatures built from two distinct identification components. The phrase describes what a product can do. It is not a status any authority confers, because FDA does not certify software, so the useful question at a demo is never whether a vendor claims compliance but which paragraph of Part 11 each control answers and whether you can watch it work.

That distinction decides how the purchase goes. Compliance attaches to a specific system, as configured and validated and used at a specific company, under a specific predicate rule. A vendor supplies capability and evidence. You supply intended use, configuration, procedures, training and the validation record. Software that ships without the underlying controls cannot be made compliant by writing procedures around it, and software that has every control can still fail an inspection if nobody validated it for the way you actually use it.

Last updated August 2026. Every regulation quote on this page was pulled from the current codified text of 21 CFR Part 11 and checked against the Federal Register in August 2026. Where a claim in wide circulation no longer matches the source, this page says so and gives the citation that changed it.

Scan your Part 11 and GxP obligations

Pick your industry and size, then choose the regimes you report against. The scan returns the obligations that apply to an organization like yours, what moved in the last 12 months, and the primary source behind each line. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 139 The claim

There is no such thing as FDA certified Part 11 software

FDA runs no certification, accreditation or approval scheme for Part 11 software, and no third party is authorized to run one on the agency's behalf. Every "Part 11 compliant" badge in this market is a vendor asserting something about its own product. That is not automatically dishonest. It is just a claim with no external check behind it, which is why an inspector will never ask to see your vendor's certificate. They will ask to see your validation record and your audit trail.

The practical consequence is that responsibility splits, and buyers routinely misjudge where the line falls. The table below is the split that holds up in an inspection.

Split of Part 11 responsibility between software vendor and regulated company
The vendor owes you You owe the inspector
Technical controls that exist in the product, not on a roadmap A written statement of intended use, which is what scopes everything else
A control map from product feature to Part 11 paragraph Validation of the configured system for that intended use
Development and testing evidence you may leverage Your own risk assessment and testing of high-risk functions
An audit trail that is on by default and cannot be switched off by users Procedures, role-based SOPs and training records for real users
A documented change and release process you can assess Periodic review, and revalidation when a change warrants it
Export of records in human readable and electronic form The one-time certification letter to FDA under 11.100(c)

Read the right-hand column again. Not one of those items is something a vendor can do for you, and the last one is the item most often missed entirely. A supplier assessment is genuine work, and it belongs in the same discipline as the rest of your vendor risk management program, not in a separate one-off spreadsheet that nobody revisits at renewal.

§ 140 Does it apply

Part 11 never applies on its own, and it has carve-outs almost nobody quotes

Section 11.1(b) is the sentence that decides scope. Part 11 "applies to records in electronic form that are created, modified, maintained, archived, retrieved, or transmitted, under any records requirements set forth in agency regulations." The operative words are the last seven. Part 11 attaches to a record only because some other regulation, the predicate rule, requires that record to exist. There is no such thing as a Part 11 record in the abstract.

So the first question in any scoping exercise is not "is this system validated" but "which regulation requires this record, and does it require it at all?" A spreadsheet of internal metrics that no FDA regulation asks for is outside Part 11, however important it is to the business. A batch record required by Part 211 is inside it the moment you keep it electronically. Getting this wrong in the generous direction is expensive: teams routinely validate systems that were never in scope, then carry that cost forever.

The same section then carves several record sets straight back out. These paragraphs were added over the years and rarely appear in vendor checklists.

Records excluded from 21 CFR Part 11 by section 11.1
Paragraph What it excludes
11.1(b) Paper records that are, or have been, transmitted by electronic means
11.1(f) Records required by 21 CFR 1.326 through 1.368, the food records access rules
11.1(g) Electronic signatures obtained under 21 CFR 101.11(d)
11.1(h) Electronic signatures obtained under 21 CFR 101.8(d)
11.1(i) Records required by Part 117, the preventive controls rule for human food
11.1(j) Records required by Part 507, preventive controls for animal food

Each of those carve-outs carries the same rider: a record that satisfies the excluded rule but is also required under another statutory or regulatory provision stays subject to Part 11. So a food manufacturer does not get a blanket exemption. It gets an exemption for records whose only source is Part 117 or Part 1 subpart J. That is a narrower thing, and the difference is worth an hour with your quality lead before you scope a system. The mechanics of each control are broken down further in our walkthrough of the 21 CFR Part 11 compliance requirements.

§ 141 Closed or open

Closed versus open turns on who controls access, not cloud versus on-premise

This is the most common technical error in Part 11 conversations, and it has survived two decades of repetition. The regulation does not mention hosting. Section 11.3(b)(4) defines a closed system as "an environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system." Section 11.3(b)(9) defines an open system as one "in which system access is not controlled" by those persons. The whole test is access control.

That matters commercially because the open-system path in 11.30 adds obligations on top of everything in 11.10, specifically document encryption and appropriate digital signature standards, as necessary to ensure record authenticity, integrity and confidentiality from creation to receipt. Teams who assume "cloud means open" buy controls they do not need. Teams who assume "our server means closed" sometimes miss that a managed service provider holds the administrator credentials.

Usually closed

  • A SaaS quality system where your administrators create, entitle and revoke every account
  • An on-premise LIMS administered by your own IT team
  • A validated cloud eTMF where the vendor cannot read or alter record content

Often open

  • A portal where an outside CRO or partner controls who gets in
  • Records exchanged with a third party who administers the exchange
  • An on-premise server whose privileged accounts sit with an outsourced provider

Notice that the deciding factor in every one of those rows is entitlement ownership. That makes the closed-system question a direct descendant of ordinary access governance, and it is answered with the same evidence you would produce for IT general controls: who can grant access, who reviews it, and how removals are proven.

§ 142 The control list

The eleven controls in 11.10, and the question to ask about each in a demo

Section 11.10 is the operative list for closed systems, and it is short enough that you can evaluate a product against it in a single session. The left column is the regulation. The right column is what to make the vendor show you rather than describe, because the gap between "we support that" and a working demonstration is where most of the risk in this purchase lives.

21 CFR 11.10 controls mapped to vendor demonstration requests
11.10 What the regulation requires Make them show you
(a) Validation for accuracy, reliability, consistent intended performance, and ability to discern invalid or altered records The validation package they hand customers, and what it leaves to you
(b) Accurate and complete copies in human readable and electronic form for agency inspection A live export of one record in both forms, including its audit trail
(c) Protection of records for accurate and ready retrieval across the retention period Retrieval of a record older than your longest retention obligation
(d) Limiting system access to authorized individuals The entitlement model, and who at the vendor can reach production data
(e) Secure, computer-generated, time-stamped audit trails that do not obscure prior entries and outlive the record An edit made live, then the before value still visible in the trail
(f) Operational system checks enforcing permitted sequencing of steps and events An attempt to sign step three before step two, and the refusal
(g) Authority checks so only authorized individuals use the system, sign, access devices or alter records A user without the role being blocked from signing, not just hidden from the button
(h) Device checks to determine validity of the source of data input or operational instruction How instrument or interface sources are authenticated, if you integrate any
(i) Determination that people who develop, maintain or use the system have the education, training and experience for their tasks Where training records live and how they gate access
(j) Written policies holding individuals accountable for actions under their signatures, to deter falsification Nothing: this one is yours, and it is a policy, not a feature
(k) Controls over systems documentation, including distribution and revision and change control of that documentation Version history of the operating documentation itself

Two rows in that table are worth pausing on. Paragraph (g), authority checks, is the one that fails most often in practice, because hiding a button is not the same as refusing the action, and an inspector who asks a viewer-role account to sign something will find out which you have. It is the same control problem as segregation of duties in a financial system, and it fails for the same reason: the interface is enforced, the underlying permission is not. Paragraph (j) is the reminder that Part 11 is not purely technical. A written accountability policy is a requirement of the regulation, and no product can supply it, though a policy management system is where most teams keep it and prove attestation.

§ 143 Signatures

Electronic signatures, and the one-time letter to FDA that almost no checklist mentions

Subpart C sets three requirements that shape product selection. Under 11.100(a) a signature must be unique to one individual and never reused or reassigned, which quietly rules out shared or generic accounts anywhere near a signed record. Under 11.100(b) the organization must verify the individual's identity before it establishes, assigns or certifies that signature. And 11.200(a)(1) requires non-biometric signatures to use at least two distinct identification components, typically an identification code and a password.

Here is the part that surprises buyers, and that vendors sometimes get wrong in the conservative direction. Part 11 does not demand full credentials on every single signature. Under 11.200(a)(1)(i), when an individual executes a series of signings during one continuous period of controlled system access, the first signing uses all components and later signings in that session need only one component, provided it is executable solely by that individual. Signings outside a continuous session each need the full set under 11.200(a)(1)(ii). A batch reviewer signing forty results in one sitting does not have to retype a password forty times for the regulation's sake, and a product that forces it is making a design choice, not obeying a rule.

Then there is 11.100(c), which is an obligation on your organization and not on any software. Persons using electronic signatures must, prior to or at the time of use, certify to FDA that the electronic signatures in their system are intended to be the legally binding equivalent of traditional handwritten signatures. The certification has to be signed with a traditional handwritten signature. It is one letter, filed once for the organization rather than per system, and a great many companies running signed electronic records have never sent it.

The submission detail changed recently enough that older guides are wrong. An amendment published 2 March 2023 at 88 FR 13018 removed the fixed mailing address from the rule text. The paragraph now says information on where to submit the certification can be found on FDA's web page on Letters of Non-Repudiation Agreement. If your SOP names a street address copied from a pre-2023 template, it is pointing at something the regulation no longer says.

§ 144 Validation in 2026

Computer system validation changed twice in eighteen months, and most published guidance predates both

If you are buying validated software in 2026, two developments matter more than anything a vendor will put in a deck, and a large share of the material online was written before either landed.

1. Computer Software Assurance is final guidance, not draft

FDA finalized Computer Software Assurance for Production and Quality System Software on 24 September 2025, published at 90 FR 45945. The draft had been open since 13 September 2022, so it took three years and eleven days, and an enormous amount of content still calls CSA a draft or a proposal. It is neither. The guidance reframes validation around intended use and risk: scripted testing where the risk warrants it, and unscripted or exploratory testing, continuous monitoring and leveraged supplier evidence where it does not. For a buyer, the immediate effect is that a vendor's development and testing evidence became more useful, not less, and that "we script every test case" is no longer automatically the safest answer.

2. The regulation CSA points to was superseded four months later

For device manufacturers, the software validation duty lived for decades at 21 CFR 820.70(i), which required that when computers or automated data processing systems are used as part of production or the quality system, the manufacturer validate the software for its intended use according to an established protocol. Nearly every validation SOP, vendor page and consultancy article in this field cites it.

It is no longer in the CFR. The Quality Management System Regulation, published 2 February 2024 and effective 2 February 2026, retitled Part 820 and incorporated ISO 13485 by reference. In the agency's own words in that rulemaking, Part 820 now "includes Subpart A, General Provisions, and Subpart B, Supplemental Provisions. Subparts C through O of the QS regulation have been removed and reserved." Section 820.70 sat in Subpart G, Production and Process Controls. So the standalone paragraph at 820.70(i) went with it, and the software validation duty now reaches device manufacturers through ISO 13485 as incorporated, where validation of software used in the quality management system falls under clause 4.1.6 and validation of production and service processes under clause 7.5.6.

Worth knowing before you cite a source: on 24 August 2026, nearly seven months after the QMSR took effect, a widely used free CFR mirror still served the pre-QMSR text of 820.70 complete with paragraph (i). We checked. If your validation SOP or a vendor's white paper cites 820.70(i) as current law, that is where the citation probably came from. The requirement to validate did not disappear. The provision people quote for it did.

Note also what the CSA guidance says about the relationship to Part 11: the enforcement discretion FDA has long exercised over parts of Part 11 does not relieve a manufacturer of the underlying validation obligation for software used in production or the quality system. The two regimes are not alternatives. Keeping track of shifts like these is the entire job of regulatory change management, and a two-year gap between a rule being published and taking effect is exactly the interval where organizations lose the thread.

§ 145 GxP scope

What GxP compliance software has to cover, by predicate rule

GxP is a collective label, not a regulation. It covers good manufacturing, laboratory and clinical practice, and each has its own predicate rules, its own inspectorate and its own record set. A platform sold as GxP compliance software is really being asked to hold records from several of these at once, which is why scoping by predicate rule beats scoping by department.

GxP disciplines mapped to predicate rules and typical records
Discipline Primary predicate rules Records that pull Part 11 in
GMP, drugs 21 CFR Parts 210 and 211 Batch production and control records, lab test data, deviations, CAPA, change control
Devices 21 CFR Part 820, the QMSR, incorporating ISO 13485 Design history, device master and history records, complaints, nonconformances
GLP, nonclinical 21 CFR Part 58 Study protocols, raw data, final reports, QA unit inspection records
GCP, clinical 21 CFR Parts 312, 812 and 11 alongside Part 50 and Part 56 Case report forms, informed consent, trial master file, monitoring reports
Pharmacovigilance 21 CFR Parts 314 and 600 reporting provisions Adverse event case files, submission records, signal assessments

A useful buying test falls out of this table. If a vendor cannot tell you which predicate rule each record type in their product answers to, they have built features rather than a compliance system, and the mapping work lands on you during validation at the worst possible moment. The same logic applies to audit management for internal and third-party inspections, and to the healthcare compliance obligations that sit alongside GxP for organizations that also touch patient data.

On budget: recorded buyer data across compliance and quality platforms puts most contracts between roughly $20,000 and $54,000 a year at the median, with the full recorded range running from about $7,500 to over $150,000. Validated life sciences systems cluster toward the upper half because the vendor is shipping validation documentation and holding a change process you can assess. Validation effort is the line that surprises people, commonly adding 30 to 100 percent of first-year license in year one. Our breakdown of compliance software pricing has the per-vendor medians and the negotiation spread.

§ 146 Questions buyers ask

21 CFR Part 11 software questions

What is 21 CFR Part 11 compliant software?

It is software built with the technical controls Part 11 requires: validated behavior, secure computer-generated time-stamped audit trails, authority checks, record copies in human readable and electronic form, and electronic signatures with two distinct identification components. The phrase describes capability, not status. Compliance is a property of how your organization configures, validates and uses the system, so the same product can be compliant at one company and not at another.

Is there FDA certified 21 CFR Part 11 software?

No. FDA does not certify, approve, accredit or endorse software as Part 11 compliant, and no FDA-authorized certification program exists. Every vendor claim of Part 11 compliance is a self-assertion. What a credible vendor can give you is a documented control mapping to the regulation, validation support material and an audit trail you can watch generate live. Ask for those instead of a certificate.

Does 21 CFR Part 11 apply to my system?

Only if a predicate rule requires the record. Section 11.1(b) applies Part 11 to electronic records kept under any records requirement set forth in agency regulations, so Part 11 never switches on by itself. Find the underlying requirement first, in Part 211 for drugs, Part 820 for devices, Part 58 for nonclinical studies or Part 312 and Part 812 for clinical work. If no predicate rule requires the record, Part 11 does not reach it.

What is the difference between a closed system and an open system under Part 11?

It turns on who controls access, not on where the software runs. Section 11.3(b)(4) defines a closed system as one where system access is controlled by persons responsible for the content of the records. Section 11.3(b)(9) defines an open system as one where it is not. A cloud application whose accounts you provision and revoke is closed. An on-premise server administered by an outside party can be open.

What are the audit trail requirements for 21 CFR Part 11?

Section 11.10(e) requires secure, computer-generated, time-stamped audit trails that independently record the date and time of operator entries and actions that create, modify or delete electronic records. Record changes must not obscure previously recorded information, and the audit trail must be retained at least as long as the underlying records and be available for agency review and copying.

Does every electronic signature need a username and password?

Not every one. Under 11.200(a)(1)(i), when someone executes a series of signings during a single continuous period of controlled system access, only the first signing needs all components. Subsequent signings in that session need at least one component that only that individual can execute. Signings outside a continuous session each need the full set under 11.200(a)(1)(ii).

Do I have to send FDA a letter to use electronic signatures?

Yes, once. Section 11.100(c) requires persons using electronic signatures to certify to the agency, before or at the time of use, that the electronic signatures in their system are intended to be the legally binding equivalent of handwritten signatures. The certification must carry a traditional handwritten signature. Since an amendment published 2 March 2023 at 88 FR 13018, the rule points to FDA's web page on Letters of Non-Repudiation Agreement for where to submit it rather than naming an address.

Is the FDA Computer Software Assurance guidance final?

Yes. FDA finalized Computer Software Assurance for Production and Quality System Software on 24 September 2025 at 90 FR 45945, three years after the draft published 13 September 2022. It endorses a risk-based approach that can use unscripted and exploratory testing, continuous monitoring and supplier evidence rather than uniform scripted testing for every function.

Is 21 CFR 820.70(i) still the software validation requirement?

Not since 2 February 2026. The Quality Management System Regulation, published 2 February 2024 and effective two years later, incorporates ISO 13485 by reference and removed and reserved Subparts C through O of the former Quality System regulation. Section 820.70 sat in Subpart G, so the standalone software validation paragraph at 820.70(i) is no longer in the CFR. The duty now reaches device makers through ISO 13485 as incorporated.

How much does GxP compliance software cost?

Recorded buyer data puts most compliance and quality platforms between roughly $20,000 and $54,000 a year at the median, with individual contracts from about $7,500 to over $150,000. Validated life sciences systems sit at the upper end because the vendor ships validation documentation. Budget separately for validation effort, which commonly adds 30 to 100 percent of first-year license in the first year.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.

§ 90

Related registers