The Complete Guide to 21 CFR Part 11 Compliance FDA-regulated organizations face a persistent challenge: electronic records and signatures must carry the same legal weight as paper — yet the specific requirements that make them trustworthy under 21 CFR Part 11 remain poorly understood across many regulated industries.

The confusion is understandable. Part 11 doesn't operate in isolation. It sits on top of other FDA requirements, applies conditionally based on how records are used, and was later narrowed by a 2003 guidance document that many organizations misread as weakening enforcement. It didn't.

This guide covers what Part 11 actually requires — the definition, scope, the 11 specific controls under §11.10, electronic signature rules, enforcement consequences, and the practical steps to build a compliant system.


Key Takeaways

  • 21 CFR Part 11 governs electronic records and signatures across all FDA-regulated industries, from pharma to cold chain logistics
  • Compliance requires meeting 11 specific controls under §11.10 for electronic records, plus distinct signature requirements
  • Non-compliance can trigger FDA Form 483 observations, warning letters, and product submission delays
  • Part 11 applies to hardware and software when electronic output substitutes for required paper records
  • Compliant systems need validation, audit trails, access controls, and documented training records in place

What Is 21 CFR Part 11?

The Regulation and Its Purpose

21 CFR Part 11 is Part 11 of Title 21 of the U.S. Code of Federal Regulations. The FDA published the final rule on March 20, 1997 (62 FR 13430), effective August 20, 1997. Its purpose: establish criteria under which electronic records, electronic signatures, and handwritten signatures on electronic records are considered trustworthy, reliable, and legally equivalent to their paper counterparts.

The regulation uses precise definitions. An electronic record is "any combination of text, graphics, data, audio, pictorial, or other information representation in digital form that is created, modified, maintained, archived, retrieved, or distributed by a computer system." An electronic signature is "a computer data compilation of any symbol or series of symbols executed, adopted, or authorized by an individual to be the legally binding equivalent of the individual's handwritten signature."

The Predicate Rule Concept

Part 11 doesn't apply to every digital file in a regulated facility. It applies when organizations choose to use electronic records or signatures to fulfill underlying FDA regulatory requirements — these underlying requirements are called predicate rules. Common examples include:

  • 21 CFR Part 211 — CGMP for finished pharmaceuticals
  • 21 CFR Part 820 — Quality System Regulation for medical devices
  • 21 CFR Part 58 — Good Laboratory Practice for nonclinical studies

If paper hard copies remain the authoritative record and electronic versions aren't relied upon for regulated activities, Part 11 may not apply to that specific system. That said, process-control computers may still require validation under the predicate rules themselves, regardless of whether paper remains the authoritative record.

The 2003 Enforcement Guidance

Understanding Part 11's scope matters even more in light of a key regulatory shift. In August 2003, the FDA issued guidance narrowing Part 11's scope and announcing enforcement discretion for certain provisions (including audit trail granularity, record copying, and legacy system validation) for systems operational before August 20, 1997. This did not suspend predicate rule enforcement. Organizations that misread the 2003 guidance as a general reduction in data integrity obligations discovered the error through FDA warning letters.

Part 11 is organized into three subparts:

Subpart Sections Contents
A — General Provisions 11.1–11.3 Scope, implementation, definitions
B — Electronic Records 11.10–11.70 Closed/open system controls, signature manifestation, record linking
C — Electronic Signatures 11.100–11.300 Identity, authentication components, credential controls

21 CFR Part 11 three-subpart structure overview infographic with sections

Who Needs to Comply with 21 CFR Part 11?

Part 11 coverage is determined by the record, not the industry category. The following organization types commonly generate records that fall under its requirements:

  • Pharmaceutical and biopharmaceutical manufacturers
  • Medical device manufacturers
  • Biologics, vaccine, and biosimilar producers
  • Contract research organizations (CROs) — explicitly named in FDA's 2024 clinical investigations guidance
  • Contract manufacturers (CMOs/CDMOs)
  • Clinical and testing laboratories
  • Food and beverage companies maintaining required electronic records (HACCP)
  • Cold chain and logistics operators handling FDA-regulated products

The triggering condition: Part 11 applies when an organization uses electronic records or signatures in place of paper to satisfy a predicate rule requirement. The key question isn't "Are we a regulated industry?" — it's "Is this electronic output the official record that satisfies the underlying regulation?"


The 11 Key Requirements for Electronic Records Under §11.10

§11.10 governs closed systems (environments where system access is controlled by those responsible for the electronic record content). It's the most operationally demanding section of Part 11, and it contains 11 distinct controls.

Controls 1–4: Foundation Controls

System Validation (§11.10(a)) Systems must be validated to ensure accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records. Validation requires documented evidence — test protocols, scripts, and results — and must be repeated after significant system changes. FDA's 2003 guidance recommends a risk-based approach to validation rather than a specific template.

Record Accessibility and Retention (§11.10(b) and (c)) Systems must produce accurate, human-readable copies of records for inspection. Records must remain protected and retrievable throughout the entire legally required retention period — not just while the system is active.

Access Controls and Authority Checks (§11.10(d) and (g)) Only authorized individuals may access the system or sign records. This requires:

  • Unique user IDs and role-based permissions
  • Authority-level checks before record creation, modification, or deletion
  • Controls preventing unauthorized access to connected input/output devices

Controls 5–11: Integrity and Accountability Controls

Audit Trails (§11.10(e)) This is where most compliance failures occur. The regulation requires secure, computer-generated, time-stamped audit trails that independently record the date, time, and identity of operator actions that create, modify, or delete electronic records.

Critical requirements:

  • Record changes must never obscure previously recorded information
  • Audit trail data must be retained at least as long as the records themselves
  • Audit trail data must be available for FDA inspection and copying

21 CFR Part 11 section 11.10 eleven electronic records controls compliance infographic

Operational and Device Checks (§11.10(f) and (h)) Workflow sequence checks must enforce that process steps occur in correct order. Device checks must verify that data input sources are valid and functioning. For automated monitoring equipment like temperature data loggers in pharmaceutical storage or cold chain applications, this means the device itself must demonstrate that its data input is reliable.

Realogview's TempTrail data loggers address this directly. Integrated internal sensors eliminate external probe variability, ±0.2°C measurement accuracy ensures reliable readings, and DO-160G certification confirms device integrity under extreme environmental conditions. Automatic PDF and CSV report generation (no external software required) produces tamper-evident records with complete time-stamped measurement histories, satisfying audit trail requirements out of the box.

Training, Accountability, and Document Control (§11.10(i), (j), and (k)) Three separate but related controls cover the human side of compliance:

  • §11.10(i): Personnel who develop, maintain, or use electronic record systems must have documented education, training, and experience
  • §11.10(j): Written policies must hold individuals accountable for actions taken under their electronic signatures
  • §11.10(k): System documentation must be version-controlled, with change history maintained as an audit trail

Electronic Signature Requirements Under 21 CFR Part 11

An electronic signature is legally binding only when it meets all regulatory controls. Having a signature feature in your system isn't enough — the controls governing how signatures are captured, displayed, and protected determine actual compliance.

Signature Manifestation Requirements (§11.50)

Every signed electronic record must display three elements in any human-readable version:

  1. The printed name of the signer
  2. The exact date and time the signature was executed
  3. The meaning or intent of the signature — such as review, approval, authorship, or responsibility

Signatures must also be cryptographically or technically linked to their corresponding records so they cannot be excised, copied, or transferred to falsify another document (§11.70).

Signature Components and Controls (§11.200 and §11.300)

For non-biometric signatures, at least two distinct identification components are required — typically a unique user ID plus a password. The rules for how these components are used:

  • First signing in a continuous session: All components required
  • Subsequent signings in the same session: At least one component usable only by that individual
  • Each new, separate session: All components required again

These session rules only work when the underlying credentials are properly controlled. Each electronic signature must be unique to one individual and never reassigned — §11.300 governs how organizations enforce that through:

  • Unique ID/password combinations
  • Scheduled password updates or recalls
  • Loss management procedures for compromised credentials
  • Transaction safeguards to detect and report unauthorized access attempts
  • Regular testing of token- or card-based authentication devices

Consequences of Non-Compliance with 21 CFR Part 11

FDA Enforcement Mechanisms

The FDA uses several tools to address Part 11 and data integrity failures:

  • FDA Form 483: Formal written notice of inspectional observations — not a final determination, but a serious signal requiring a response
  • Warning Letters: Public citations that can damage reputation, trigger market delays, and require corrective action commitments
  • Submission consequences: When FDA cannot rely on supporting data, product approvals stall or are rejected
  • Import alerts: Allowing detention of products without physical examination
  • Civil injunctions: To stop ongoing FD&C Act violations

FDA enforcement mechanisms for Part 11 non-compliance five-tier escalation infographic

How FDA Actually Cites These Violations

Recent enforcement actions are instructive. Warning letters to Intas Pharmaceuticals, Lupin Limited, MMC Healthcare, NWL Netherlands Services, and Wisconsin Pharmacal Company addressed electronic data failures — missing raw records, unauthorized reprocessing of chromatography data, inadequate audit trail review, and OpenLab system privileges that permitted modification or deletion of records.

Most of these were cited under 21 CFR 211.68(b) — the predicate rule governing computerized systems in drug manufacturing — rather than Part 11 expressly.

FDA's 2025 action addressing data integrity concerns with Chinese third-party testing firms extends that scrutiny across the supply chain. Predicate rule violations carry the same enforcement weight regardless of Part 11 enforcement discretion — the 2003 guidance narrowed Part 11 interpretation, not predicate rule obligations.


Building a 21 CFR Part 11 Compliant System: Practical Steps

Step 1: Conduct a Gap Assessment

Map every electronic record-keeping and signature workflow against the §11.10 controls. For each system:

  • Is this system in scope (does it create, modify, or store records required by a predicate rule)?
  • Which records are "Part 11 records" by design versus supporting documentation?
  • Where do gaps exist against the 11 controls?

Document findings. The gap assessment itself becomes part of your compliance evidence.

Step 2: Select Validated Systems and Hardware

Any tool used to create, capture, or store regulated electronic records must meet Part 11 requirements — including physical monitoring hardware. When evaluating data capture devices for pharmaceutical storage, vaccine cold chain, or clinical laboratory settings, look for:

  • Automatically generated, tamper-evident records without reliance on external software
  • Time-stamped, complete measurement histories
  • Tamper-proof physical design (IP67/IP68 rated)
  • "Stop when full" logging behavior that preserves complete data rather than overwriting records

Realogview's TempTrail line meets all four criteria above. Models span cryogenic pharmaceutical and vaccine storage (TempTrail Glacial, –85°C to +70°C) through autoclave validation (TempTrail HiTemp, +5°C to +140°C). Each device generates PDF and CSV reports automatically on USB connection — no external software needed — and ships with FDA 21 CFR Part 11 compliance built in.

Step 3: Establish Ongoing Compliance Infrastructure

Compliance is not a one-time event. Sustain it through:

  • Written SOPs covering access control, user training, and change control
  • Training records that document personnel qualifications for each system role
  • Scheduled audit trail reviews — retaining trails is not enough; they must be actively reviewed
  • Re-validation triggered by significant system changes (hardware, software, or configuration)
  • Periodic personnel competency checks on a defined schedule

21 CFR Part 11 ongoing compliance infrastructure five-component maintenance cycle infographic

Frequently Asked Questions

What does 21 CFR Part 11 stand for?

It stands for Part 11 of Title 21 of the U.S. Code of Federal Regulations, issued by the FDA. It governs the use of electronic records and electronic signatures in FDA-regulated industries, defining when they are legally equivalent to paper records and handwritten signatures.

What should a 21 CFR Part 11 compliance checklist cover?

A Part 11 compliance checklist should document your organization's status across two areas: all 11 controls under §11.10 (covering system validation, access controls, audit trails, training, and document control, among others) and electronic signature requirements under §§11.50, 11.70, 11.100, 11.200, and 11.300.

What is the difference between 21 CFR Part 11 and GMP?

GMP regulations (such as 21 CFR Part 211 for drugs or Part 820 for devices) are the predicate rules that govern how regulated products must be manufactured and documented. 21 CFR Part 11 is the specific overlay that governs how electronic records and signatures used to meet those GMP requirements must be controlled — it only applies when electronic records substitute for paper to satisfy a predicate rule.

What are the penalties for non-compliance with 21 CFR Part 11?

Enforcement can include FDA Form 483 inspectional observations, Warning Letters, rejection or delay of product submissions, import alerts, and civil injunctions. Predicate rule violations (which underpin most data integrity enforcement) carry the same penalties regardless of Part 11 enforcement discretion.

Does 21 CFR Part 11 apply to temperature data loggers and monitoring hardware?

Yes, conditionally. When a data logger's electronic output substitutes for a required paper record in a regulated activity — such as temperature monitoring in pharmaceutical storage or vaccine cold chain — Part 11 applies to that record system. If paper remains the authoritative record, Part 11 may not apply, though predicate rule requirements for device qualification and calibration can still apply.

What is an audit trail under 21 CFR Part 11?

An audit trail is a secure, computer-generated, time-stamped record that logs the date, time, and identity of every operator action that creates, modifies, or deletes an electronic record. It must be retained at least as long as the records it covers, remain available for FDA inspection, and never allow changes to obscure previously recorded information.