Blog · 13 Aug 2026 · 10 min read
21 CFR Part 11 compliance requirements: what the regulation says, and the letter almost every checklist forgets
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
The short answer: 21 CFR Part 11 sets the conditions under which FDA will treat an electronic record or electronic signature as equivalent to paper and a handwritten signature. It requires validated systems, secure computer-generated time-stamped audit trails, access and authority checks, signature manifestations that show the signer's printed name, the date and time and the meaning of the signing, and electronic signatures built from at least two distinct identification components. It also requires something most guides omit entirely: a one-time certification letter to FDA, signed with a traditional handwritten signature.
Part 11 is short, and reading it directly settles most of the arguments that get had about it. What follows quotes the regulation itself. Every citation below was checked against the eCFR on 13 August 2026, and the one paragraph that has changed recently is flagged with the Federal Register document that changed it.
What is 21 CFR Part 11?
Part 11 is the FDA regulation governing electronic records and electronic signatures. Section 11.1(a) states that the rules "set forth the criteria under which the agency considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and generally equivalent to paper records and handwritten signatures executed on paper." It is a rule about trustworthiness of the record, not about what the record must contain.
That distinction matters more than any single control in the regulation, and it is the root of the most expensive mistakes in life sciences software buying.
Who does 21 CFR Part 11 apply to?
It applies to electronic records kept under some other FDA requirement. Section 11.1(b) says the part applies to records "created, modified, maintained, archived, retrieved, or transmitted, under any records requirements set forth in agency regulations," plus records submitted to FDA under the Federal Food, Drug, and Cosmetic Act and the Public Health Service Act. The rule that requires you to keep the record in the first place is called the predicate rule.
So Part 11 never applies on its own. If no FDA regulation requires the record, Part 11 has nothing to attach to. Section 11.1(b) also carries a limit worth knowing: "this part does not apply to paper records that are, or have been, transmitted by electronic means." Faxing a paper batch record does not pull it into Part 11.
The list of explicit exclusions has grown considerably and is rarely reproduced. Sections 11.1(f) through 11.1(p) carve out records required by part 117 (preventive controls for human food), part 507 (animal food), part 112 (produce safety), part 121 (intentional adulteration), subparts J, L, M, O and R of part 1, and sections 1.326 through 1.368. In plain terms, most of the record-keeping created by the Food Safety Modernization Act sits outside Part 11. If a vendor is selling you Part 11 controls for FSMA traceability records, ask them which paragraph they think applies.
What are the requirements of 21 CFR Part 11 for closed systems?
Section 11.10 is the operative list. It opens by requiring procedures and controls "designed to ensure the authenticity, integrity, and, when appropriate, the confidentiality of electronic records, and to ensure that the signer cannot readily repudiate the signed record as not genuine," then sets out eleven specific controls.
| Cite | What 11.10 requires |
|---|---|
| (a) | Validation of systems for accuracy, reliability, consistent intended performance and the ability to discern invalid or altered records |
| (b) | Ability to generate accurate and complete copies in both human readable and electronic form for FDA inspection |
| (c) | Protection of records for accurate and ready retrieval throughout the retention period |
| (d) | Limiting system access to authorized individuals |
| (e) | Secure, computer-generated, time-stamped audit trails recording operator entries and actions that create, modify or delete records |
| (f) | Operational system checks enforcing permitted sequencing of steps and events |
| (g) | Authority checks so only authorized individuals can use the system, sign, access a device or alter a record |
| (h) | Device checks determining validity of the source of data input or operational instruction |
| (i) | Determination that people who develop, maintain or use the systems have the education, training and experience for their tasks |
| (j) | Written policies holding individuals accountable for actions initiated under their electronic signatures |
| (k) | Controls over systems documentation, including distribution control and revision and change control procedures |
Paragraph (i) is the one that quietly turns into an operational program rather than a software setting. Proving that every person who touches a regulated system has the right training means keeping dated, attributable training records, which is why life sciences quality teams usually end up running that evidence through a system that certifies the whole workforce and keeps the completion record rather than a folder of signed sheets.
What is an audit trail under Part 11?
Paragraph 11.10(e) requires "secure, computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records." Two clauses in that paragraph do the real work. First, "record changes shall not obscure previously recorded information," so an audit trail that overwrites is not an audit trail. Second, the documentation "shall be retained for a period at least as long as that required for the subject electronic records," so audit trail retention inherits the predicate rule's retention period rather than a system default.
What is the difference between a closed system and an open system?
It turns on who controls access, not on where the software runs. Section 11.3(b)(4) defines a closed system as "an environment in which system access is controlled by persons who are responsible for the content of electronic records that are on the system." Section 11.3(b)(9) defines an open system as one where access "is not controlled by persons who are responsible for the content."
This is probably the most misunderstood pair of definitions in the regulation. Cloud hosting does not make a system open. A SaaS quality system where your organization administers the user accounts and owns the record content is a closed system, and the additional measures in section 11.30, such as document encryption and digital signature standards, are aimed at genuinely open environments. The practical test is whether the people accountable for the records decide who gets in.
What are the electronic signature requirements?
Four sections carry them. Section 11.50 requires that a signed record show the printed name of the signer, the date and time the signature was executed, and "the meaning (such as review, approval, responsibility, or authorship) associated with the signature," and that these appear in any human readable form of the record. Section 11.70 requires signatures to be linked to their records "to ensure that the signatures cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means."
Section 11.100(a) requires each electronic signature to be "unique to one individual" and never reused or reassigned, and 11.100(b) requires the organization to verify the individual's identity before establishing it. Shared accounts are not a policy weakness under Part 11, they are a direct breach of 11.100(a).
Section 11.200(a)(1) requires non-biometric signatures to "employ at least two distinct identification components such as an identification code and password." The part that is regularly misstated is what happens next. Under 11.200(a)(1)(i), when someone signs a series of records during "a single, continuous period of controlled system access," only the first signing needs all components; subsequent signings need at least one component "that is only executable by, and designed to be used only by, the individual." Under 11.200(a)(1)(ii), signings outside a continuous session each need all components. So the common claim that every single signature requires a full username and password is stricter than the rule.
Do you have to send FDA a certification letter?
Yes, and this is the requirement most often missing from published checklists. Section 11.100(c) requires persons using electronic signatures to "certify to the agency that the electronic signatures in their system, used on or after August 20, 1997, are intended to be the legally binding equivalent of traditional handwritten signatures." It is a one-time, organization-level letter, commonly called a letter of non-repudiation, and it is due prior to or at the time of use.
Section 11.100(c)(1) requires the certification to be "signed with a traditional handwritten signature." That has not changed, which produces a genuine irony: the only document in the whole electronic signature regime that still needs a wet signature is the letter declaring that you use electronic signatures.
What did change is where it goes. A large amount of published Part 11 guidance still instructs readers to mail the letter to the Office of Regional Operations at 5600 Fishers Lane in Rockville, Maryland. That address came out of the regulation on 2 March 2023, when FDA published a technical amendment, Federal Register document 2023-04010, titled "Change of Address; Technical Amendment." The current text of 11.100(c)(1) permits submission "in electronic or paper form" and says "information on where to submit the certification can be found on FDA's web page on Letters of Non-Repudiation Agreement." Check that page rather than any secondary source, including this one.
Is there such a thing as Part 11 certified software?
No. FDA does not certify, approve or validate commercial software, and no vendor can sell you compliance as a property of a product. Part 11 obligations attach to the person using the system: 11.10 begins "persons who use closed systems," and section 11.1(e) makes the systems, controls and "attendant documentation" subject to FDA inspection at your site.
What a vendor can honestly offer is a system with the technical capabilities Part 11 requires, documentation supporting your validation, and configuration that does not force you into a breach. Validation under 11.10(a) is still yours, because it is validation for your intended use. This is the same category error as calling an organization SOC 2 certified when SOC 2 produces an attestation report, and it is worth pushing back on in a demo. If a salesperson says the product is Part 11 certified, ask who issued the certificate.
What about FDA's enforcement discretion?
In August 2003 FDA issued the guidance "Part 11, Electronic Records; Electronic Signatures, Scope and Application," which narrowed the agency's interpretation of the rule's scope and stated it intended to exercise enforcement discretion over certain requirements, including validation, audit trails, record retention and the generation of record copies, while it reconsidered the regulation. That guidance is still the operative statement of FDA's approach and is why Part 11 practice is less maximalist than the text alone suggests.
Two cautions. Enforcement discretion is not repeal, the regulation is unchanged, and predicate rule obligations were explicitly not relaxed. Records you must keep under a predicate rule must still be kept, and must still be available and readable for inspection.
A practical 21 CFR Part 11 checklist
- Identify the predicate rule for each record. If there isn't one, Part 11 does not apply.
- Classify each system as closed or open using the access-control test in 11.3(b)(4) and (9).
- Validate for intended use and keep the validation documentation inspection-ready.
- Confirm the audit trail is computer-generated, time-stamped, non-obscuring, and retained as long as the record.
- Remove shared accounts, and verify identity before issuing any signature credential.
- Check that signature manifestations show name, date and time, and meaning, in printouts as well as on screen.
- Confirm you can export accurate and complete copies in human readable and electronic form.
- Keep dated training records for everyone who develops, maintains or uses the systems.
- Write the accountability policy required by 11.10(j) and have people acknowledge it.
- File the 11.100(c) certification letter if you have not, and keep proof that you did.
Step one is where most programs are weakest, and it is the step no software performs for you. Working out which rules create which obligations, and keeping that mapping current as agencies amend the text, is the job regulatory compliance software exists to do. Part 11 itself is a good illustration of why it needs doing continuously: the address in 11.100(c) moved in 2023 and a great deal of published guidance never caught up.
One adjacent problem worth separating out. Part 11 audit trails cover the validated system that holds the record. Once those values are copied into a warehouse for analysis or reporting, proving where a given number came from is a different discipline with its own tooling, and teams that try to answer it with the quality system's audit trail usually find it cannot reach that far. Tracking where each field in a downstream dataset originated is a separate control, not a Part 11 one.
If your obligations run wider than FDA, the same register logic applies across agencies. Our healthcare compliance software page covers the HHS and OIG side, and policy management software covers keeping the written procedures 11.10(j) and 11.10(k) require current and attested.
General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.