FDA 21 CFR Part 11: Electronic Records and Signatures Guide
21 CFR Part 11 is the FDA regulation that defines the criteria under which electronic records and electronic signatures are considered trustworthy, reliable, and equivalent to paper records and handwritten signatures. For pharmaceutical companies, medical device manufacturers, biotechnology firms, and clinical research organizations, Part 11 compliance is essential for any system that creates, modifies, maintains, archives, retrieves, or transmits regulated records. A failed FDA inspection tied to Part 11 deficiencies can result in Warning Letters, import alerts, and costly remediation programs — making this regulation one of the highest-stakes technical requirements in the life sciences.
What Part 11 Is and Who Issues It
21 CFR Part 11 was published by the United States Food and Drug Administration on March 20, 1997 and took effect on August 20, 1997. The regulation appears in Title 21 of the Code of Federal Regulations, Chapter I (FDA), Part 11. It was issued in response to industry's transition away from paper-based records toward electronic systems and the growing need for regulatory clarity on the trustworthiness of electronic data.
The FDA's Center for Drug Evaluation and Research (CDER), Center for Biologics Evaluation and Research (CBER), Center for Devices and Radiological Health (CDRH), and Center for Veterinary Medicine (CVM) all enforce Part 11 requirements within their respective domains. Inspectors from these centers will review electronic records systems during establishment inspections, pre-approval inspections (PAIs), and for-cause inspections.
In 2003, the FDA issued a Guidance for Industry on Scope and Application, which significantly narrowed the agency's enforcement focus. The 2003 guidance indicated that the FDA would apply a risk-based approach to Part 11 enforcement and would exercise enforcement discretion for certain legacy systems. Critically, the guidance made clear that the FDA considers Part 11 requirements to be predicate rule requirements — meaning the underlying records requirement comes from the relevant predicate rule (such as 21 CFR Part 211 for pharmaceutical manufacturing), and Part 11 applies when an organization elects to use electronic systems to meet those record-keeping obligations.
Since 2003, the FDA has issued additional guidance covering specific topics including electronic source data in clinical investigations (2013), data integrity and compliance with CGMP (2018), and computer software assurance (CSA) for production and quality system software (2022). The 2022 CSA guidance introduced a risk-based approach to software assurance activities, moving away from prescriptive documentation requirements toward evidence-based testing.
Who Must Comply
Part 11 applies to any organization that:
- Maintains electronic records required by FDA regulations (predicate rules) as an alternative to paper records, or
- Uses electronic signatures in lieu of traditional handwritten signatures in connection with FDA-regulated activities.
The practical scope is broad and encompasses:
Pharmaceutical manufacturers operating under 21 CFR Parts 210 and 211 (Current Good Manufacturing Practice for Finished Pharmaceuticals). Electronic batch records, laboratory information management systems (LIMS), manufacturing execution systems (MES), and quality management systems (QMS) all fall within scope.
Medical device manufacturers subject to 21 CFR Part 820 (Quality System Regulation, now replaced by 21 CFR Part 820 aligned with ISO 13485). Electronic Device History Records, Complaint Handling systems, and CAPA tracking systems must meet Part 11 requirements.
Clinical investigators and sponsors managing electronic clinical data under 21 CFR Parts 11, 312, and 812. Electronic Data Capture (EDC) systems used in clinical trials, including patient-reported outcome (PRO) systems, are subject to Part 11.
Biotech and biologics manufacturers under 21 CFR Parts 600-680. Electronic records supporting lot release, stability testing, and manufacturing must comply.
SaaS vendors and technology providers supplying systems to FDA-regulated organizations bear shared responsibility. When a SaaS vendor hosts a system used to create or manage FDA-required records, the vendor's platform must support Part 11 compliance. Contracts between regulated organizations and SaaS vendors should clearly allocate Part 11 responsibilities.
Key Requirements in Depth
System Validation
Validation is the cornerstone of Part 11 compliance. Section 11.10(a) requires that closed systems used to create, modify, maintain, or transmit electronic records have the ability to generate accurate and complete copies, protect records throughout their required retention period, and use computer-generated, time-stamped audit trails.
The FDA's Computer Software Assurance (CSA) guidance (2022) introduced a risk-based approach to validation, emphasizing that the level of validation effort should be proportionate to the risk of the software to product quality and patient safety. Under CSA:
- Category 1 software (infrastructure tools like operating systems) requires minimal documentation.
- Category 2 software (non-configurable commercial off-the-shelf tools) requires basic records of configuration decisions.
- Category 3 software (configurable or custom systems used to create regulated records) requires the most rigorous validation, including Installation Qualification (IQ), Operational Qualification (OQ), and Performance Qualification (PQ) protocols.
The GAMP 5 framework (Good Automated Manufacturing Practice, 2nd edition 2022) remains widely used in the industry to structure validation activities. GAMP 5 aligns well with the FDA's risk-based approach and provides practical guidance for different software categories.
Validation documentation must be maintained throughout the lifecycle of the system and updated whenever significant changes occur. A change control process must govern modifications to validated systems.
Audit Trails
Section 11.10(e) requires computer-generated, time-stamped audit trails to independently record the date and time of operator entries and actions that create, modify, or delete electronic records. Audit trails must:
- Be created by the system, not the user.
- Include the original value before any modification, the new value, the date and time of change, and the identity of the person making the change.
- Be retained for a period at least as long as the records they support.
- Be available for FDA inspection.
- Not be editable by users, including system administrators.
Audit trail reviews are a frequent inspection focus. The FDA expects that organizations actively review audit trails as part of their quality oversight — not merely that the trails exist. Organizations should establish documented procedures for periodic audit trail review.
Electronic Signatures
Part 11, Subpart C, establishes requirements for electronic signatures used to sign FDA-required records. Electronic signatures must be:
- Unique to one individual and not reused by or reassigned to anyone else.
- Verified before being established or used.
- Bound to their respective electronic records so that the signature cannot be excised, copied, or otherwise transferred to falsify an electronic record.
Non-biometric electronic signatures (by far the most common type) must employ at least two distinct identification components such as an identification code and password. When signing during a continuous session, the system may require only the first component for subsequent signings. When signing outside a continuous session, both components must be used each time.
Individuals who use electronic signatures must certify to the FDA (via written notice submitted to the relevant center) that their electronic signatures are the legally binding equivalent of their handwritten signatures. This is a one-time certification per individual.
Signatories must, at the time of signing, display information associating the signature with its meaning — including the printed name, date and time, and meaning of the signature (such as review, approval, responsibility, or authorship).
Access Controls
Section 11.10(d) requires procedures and controls to limit system access to authorized individuals. These controls include:
- Unique user identification codes (usernames must be unique and not reused).
- Password management procedures including complexity requirements, expiration policies, and prohibition on sharing.
- Authority checks to ensure only authorized individuals can use the system, access operating documentation, and operate specific functions.
- Device checks to determine the validity of the source of data input or operational instruction.
The FDA's data integrity guidance (2018) reinforced that access controls must prevent unauthorized modification of records and that shared login credentials are a significant data integrity vulnerability.
Record Retention and Availability
Organizations must be able to generate accurate and complete copies of electronic records in both human-readable and electronic form suitable for inspection, review, and copying by the FDA. Records must be protected throughout their required retention period against degradation, obsolescence of media or software, and unauthorized alteration.
For pharmaceutical manufacturing, batch production records must be retained for at least one year after the expiry date of each batch produced. For drug applications, records must typically be retained for the life of the application plus two years. System retirement must include a documented strategy for migrating or preserving records.
The Compliance and Inspection Process
FDA Part 11 compliance is not demonstrated through a standalone certification or third-party audit in the same manner as ISO 27001 or SOC 2. Instead, compliance is evaluated during FDA inspections as part of a broader review of CGMP or QSR compliance.
During an inspection, FDA investigators may:
- Review the organization's system inventory and Part 11 assessment for each regulated system.
- Request access to audit trails for specific records reviewed during the inspection.
- Review validation documentation (protocols, test records, final reports) for regulated systems.
- Review SOPs governing electronic record management, access control, and system changes.
- Test the system's electronic signature functionality.
- Review training records for personnel using regulated systems.
The frequency of FDA inspections depends on the organization's product type and risk classification. Drug manufacturers are typically inspected every two to three years under CGMP surveillance programs; medical device manufacturers are on similar cycles. Pre-approval inspections occur before new drug applications are approved. For-cause inspections may occur at any time following complaints, adverse events, or other signals.
Costs and Timeline
| Scope | Typical Timeline | Estimated Cost Range |
|---|---|---|
| Single-system validation (commercial software) | 3–6 months | $50,000–$100,000 |
| Small company, 3–5 regulated systems | 6–12 months | $150,000–$250,000 |
| Mid-size pharma/device, 10+ systems | 9–18 months | $250,000–$500,000 |
| Enterprise-wide program (50+ systems) | 12–18 months | $500,000+ |
The largest cost drivers are validation activities (protocol writing, testing, documentation), remediation of gaps identified during the initial Part 11 assessment, and ongoing change control and periodic review. Cloud-based and SaaS systems have reduced infrastructure costs but introduce vendor qualification responsibilities that must be managed through audit and contractual controls.
Organizations that defer Part 11 compliance often face significantly higher remediation costs when deficiencies are identified during an FDA inspection — Warning Letters can trigger consent decrees and import alerts that far exceed the cost of proactive compliance.
Comparison with Related Frameworks
Part 11 does not exist in isolation. Organizations operating across multiple regulatory jurisdictions will encounter overlapping and complementary requirements:
- HIPAA Security Rule (approximately 30% overlap): Both frameworks require access controls, audit logging, and protection of electronic records. Health tech companies building platforms for pharmaceutical and healthcare clients may need to address both simultaneously. See HIPAA for full coverage.
- ISO 27001 (approximately 35% overlap): ISO 27001's controls for access management, audit logging, change management, and asset inventory align with Part 11's technical requirements. Many pharmaceutical companies pursue ISO 27001 as a foundation for their information security program, finding it complements rather than duplicates Part 11.
- EU Annex 11: The European counterpart to Part 11 for computerized systems in GMP environments. Pharmaceutical companies operating in both the US and EU must satisfy both Part 11 and Annex 11. The two share similar objectives but differ in specific requirements — Annex 11 places stronger emphasis on supplier qualification and data migration.
- 21 CFR Part 820 / ISO 13485: Medical device quality system requirements that mandate records management practices to which Part 11 applies when those records are maintained electronically.
- GDPR Health: Organizations conducting clinical trials involving EU data subjects must align their electronic data systems with both Part 11 and GDPR's data protection requirements.
How Automation Helps
Part 11 compliance is documentation-intensive, system-specific, and requires ongoing maintenance as systems change and new systems are deployed. Compliance automation delivers measurable value across the Part 11 program:
- Automated evidence collection supports audit trail review, access control monitoring, and change management documentation.
- Policy and procedure management platforms maintain current versions of validation SOPs, access control procedures, and electronic signature policies.
- Vendor risk workflows help manage third-party system qualifications and SaaS vendor assessments.
- Training management systems deliver and document required training for staff using regulated electronic systems.
- Risk registers track identified Part 11 gaps, remediation status, and periodic review outcomes.
LowerPlane supports Part 11 compliance programs as part of its AI-powered compliance automation platform covering 50-plus frameworks including HIPAA, ISO 27001, and SOC 2. At $4,000 per year starting price with a free tier available, and rated 9.4/10 on AuditXYZ, LowerPlane enables pharmaceutical and medical device companies to manage validation documentation, evidence collection, and audit readiness without the manual overhead of spreadsheet-based programs. For health technology companies building Part 11-compliant platforms, see /for/healthtech and /tools/compliance-automation/lowerplane.
Frequently Asked Questions
Does Part 11 apply to SaaS platforms used by FDA-regulated companies?
Yes. When a SaaS vendor hosts a system that an FDA-regulated organization uses to create, maintain, or transmit records required by a predicate rule, the system must meet Part 11 requirements. Regulated organizations remain responsible for ensuring their SaaS vendors' systems are compliant, typically through vendor qualification activities including supplier audits and review of the vendor's validation documentation. SaaS vendors should maintain their own Part 11 assessments and be prepared to provide documentation packages to regulated customers.
What is the difference between an open system and a closed system under Part 11?
A closed system is one where access is controlled by persons who are responsible for the content of the electronic records. A cloud-hosted system accessible only to the regulated organization and its authorized users with authentication controls is generally a closed system. An open system involves communication of data over unprotected networks where the organization cannot control who may intercept or alter data in transit. Open systems require additional controls including encryption and digital signatures to verify record integrity.
How does the 2022 Computer Software Assurance guidance change validation requirements?
The FDA's CSA guidance shifts focus from documentation volume to evidence-based testing and critical thinking. Under CSA, the level of assurance activities should be proportionate to the risk of the software to product quality and patient safety. Organizations are encouraged to leverage vendor test documentation (IQ/OQ protocols and results) rather than repeating identical tests. Testing effort should focus on the specific ways the organization uses the system and on the highest-risk functions. This approach reduces unnecessary documentation burden without relaxing the fundamental requirement that systems be fit for intended use.
What happens if an FDA investigator finds Part 11 deficiencies during an inspection?
Part 11 deficiencies are typically documented in an FDA Form 483 (Inspectional Observations) and may be escalated to Warning Letters if they are significant or if the organization fails to respond adequately. Warning Letters are publicly posted on the FDA's website and can affect drug approval timelines, import status, and business relationships. Serious data integrity violations — which often overlap with Part 11 requirements — can result in consent decrees that impose costly remediation programs under FDA oversight. Organizations should respond promptly to 483 observations with substantive corrective action plans.
How long must electronic records be retained under Part 11?
Part 11 itself does not specify retention periods — those are determined by the applicable predicate rules. For pharmaceutical manufacturing under 21 CFR Part 211, batch production records must be retained for at least one year after the expiry date of the batch (and at least three years after the batch distribution date). Drug application records are typically retained for the life of the application. Medical device records under 21 CFR Part 820 are retained for two years from the date of device manufacture or the life of the device, whichever is longer. Organizations must identify the applicable predicate rule retention requirement for each record type.