Doxis Blog  ECM & Archive

21 CFR Part 11 Requirements for Manufacturers

| Bärbel Heuser-Roth

Two women discussing 21 CFR Part 11 in a cozy setting with a document labeled E-Record.

If your company keeps GMP or quality records electronically, 21 CFR Part 11 decides whether the FDA accepts them. You have to prove who created or changed each record, when, and under whose signature, using controls you have validated. Gaps in those controls show up in inspections as data integrity findings.

Those findings are a regular cause of FDA warning letters. A Pharmaceutical Online (2025) review of 85 warning letters to drug manufacturers found that 15% cited data integrity concerns.

This guide explains what 21 CFR Part 11 requires for electronic records and electronic signatures, who it applies to, and which parts your software covers and which stay with your quality team.

Key takeaways

  • 21 CFR Part 11 sets the conditions under which the FDA accepts electronic records and signatures as equivalent to paper records and handwritten signatures
  • It applies when an FDA predicate rule, such as drug GMP or medical device quality requirements, requires a record and you keep that record electronically
  • The core electronic record controls are validation, secure time-stamped audit trails, access and authority checks, accurate copies, and retention
  • Electronic signatures must show the signer's name, date and time, and meaning, and stay permanently linked to the signed record
  • No software is "Part 11 certified". Your DMS supplies the technical controls, and your company is responsible for using and validating them correctly

What is 21 CFR Part 11?

21 CFR Part 11 is the FDA regulation that defines when electronic records and electronic signatures are trustworthy, reliable, and equivalent to paper records and handwritten signatures. Published in 1997, it sets technical and procedural controls for systems that create, modify, store, or transmit records required by other FDA regulations.

The six requirement areas of 21 CFR Part 11. Each one is explained in the sections below.

Who does 21 CFR Part 11 apply to?

Part 11 never creates a record-keeping obligation on its own. It attaches to records that another FDA regulation, called a predicate rule, already requires you to keep.

For enterprise manufacturers, the main predicate rules are drug current good manufacturing practice (21 CFR Parts 210 and 211), medical device quality requirements (21 CFR Part 820, which incorporates ISO 13485 since the Quality Management System Regulation took effect in February 2026), and food safety rules. If your plant keeps batch records, device production records, complaint files, or training records electronically to meet one of those rules, Part 11 applies to them.

Contract manufacturers carry the same obligations for the records they keep on behalf of their customers, which makes Part 11 one more strand of compliance in manufacturing.

Two distinctions shape how much of the regulation you have to meet:

  • Closed vs. open systems: a closed system is one where access is controlled by the people responsible for the records, such as your validated internal DMS. Open systems, where outside parties control access, need extra measures like encryption and digital signature standards on top of the closed-system controls
  • Enforcement discretion: in its 2003 Part 11 guidance, the FDA said it would use enforcement discretion for four requirements: validation, audit trails, record retention, and record copies. In practice, it does not strictly enforce the Part 11 wording for these. Under certain conditions, the same applies to systems that were already running before Part 11 took effect in 1997

You still need these controls. Other FDA rules often require them, and the FDA expects you to decide how much each system needs based on its risk. Records kept only to meet the FDA's food safety preventive controls rule (Part 117) are exempt from Part 11, but the exemption ends if another rule also requires the same record. Check which rule applies to each type of record before you plan your validation.

 

Automate Work. Accelerate Business.

Bring together AI, ECM, and workflow automation in one powerful enterprise platform.

21 CFR Part 11 requirements for electronic records

Section 11.10 lists the controls for closed systems. Together they let you show an investigator that a record is complete, unaltered, and created by the person named on it.

System validation

You must validate systems to ensure accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records. Validation is your responsibility as the regulated company. A vendor can supply documentation and test evidence, but only you can confirm the system works for your intended use.

Take a risk-based approach. A system holding release decisions for finished product needs deeper validation than one storing meeting notes.

Audit trails

Part 11 requires secure, computer-generated, time-stamped audit trails that independently record operator entries and actions that create, modify, or delete records. A change must never obscure the previous value. The audit trail must be kept as long as the record itself and be available for FDA review.

In practice, an audit trail only helps you if it was switched on for the right record types before the change happened, so audit configuration belongs in your validation scope.

Access controls and authority checks

Only authorized individuals may access the system, and authority checks must confirm that only permitted people can sign a record, change it, or operate a device. Shared logins defeat both controls at once, so investigators look for them.

Map access rights to roles. A QA approver, a production operator, and a system administrator need different permissions, and you should be able to show an investigator who held which rights on a given date.

Record retention and accurate copies

You must be able to produce accurate and complete copies of records in human-readable and electronic form (11.10(b)), and protect records so they stay retrievable throughout the retention period (11.10(c)).

Retention periods in regulated manufacturing run for years, sometimes beyond the life of the system that created the record. Long-term formats such as PDF/A for audit-proof archiving help keep records readable after the original application is retired. Part 11 retention also sits alongside other US obligations covered in our guide to audit-proof archiving in the US.

Operational checks, training, and documentation controls

The remaining controls cover the people and processes around the system. Operational and device checks enforce the correct sequence of steps and confirm valid input sources. Everyone who builds, maintains, or uses the system needs documented education, training, and experience (11.10(i)).

You also need written policies that hold individuals accountable for actions taken under their electronic signatures (11.10(j)), and change control over system documentation (11.10(k)). These controls are mostly procedural, so an investigator will mainly ask to see documents and records here.

21 CFR Part 11 electronic signature requirements

Subparts B and C set the rules for electronic signatures. Together they make sure a signer cannot later deny having signed a record.

Signature manifestation and record linking

Every signed electronic record must display the signer's printed name, the date and time of signing, and the meaning of the signature, such as review, approval, responsibility, or authorship. That information must appear wherever the record is shown or printed.

Signatures must also be linked to their records so they cannot be removed, copied, or transferred to falsify another record by ordinary means. In practice, this means a signature belongs to one specific version of one document.

Signature components and password controls (11.100, 11.200, 11.300)

Each electronic signature must be unique to one person and never reused or reassigned. Before you issue one, you must verify the person's identity, and you must certify to the FDA that your electronic signatures are the legally binding equivalent of handwritten signatures. The certification must be signed by hand, and since 2023 it can be submitted electronically or on paper.

Non-biometric signatures need at least two distinct components, such as a user ID and password. The first signing in a continuous session requires both; later signings in the same session require at least one. Section 11.300 adds controls for those credentials:

  • Uniqueness: no two people share the same combination of ID and password
  • Periodic review: credentials are checked, recalled, or revised on a schedule
  • Loss management: lost or compromised tokens and cards are deactivated promptly
  • Unauthorized use detection: attempts at unauthorized use are detected and reported urgently to your security unit and, where appropriate, to management

What the October 2024 FDA guidance adds

In October 2024 the FDA finalized guidance on electronic systems, records, and signatures in clinical investigations. It is written for sponsors, clinical investigators, and CROs, not for GMP manufacturing, but it is the FDA's most recent statement on Part 11 and a useful reference by analogy. It reconfirms the risk-based approach to validation and says the regulated company stays responsible when it relies on IT service providers, including cloud services.

It also addresses signatures drawn with a finger or stylus on a tablet. The FDA treats these as handwritten signatures executed to electronic records, which Part 11 also covers: they still have to be linked to the record they sign.

What software can and can't do for Part 11 compliance

Part 11 is a shared responsibility. Software supplies technical controls, and your procedures, training, and validation turn those controls into compliance. The FDA does not certify software for Part 11, so ask what sits behind any "compliant out of the box" claim.

The table below shows how that split works for the requirements a DMS touches most:

Part 11 requirement

What your DMS provides

What you own

Validation

Stable, documented software and release notes

Risk assessment, test plans, execution, and the validation report

Audit trails

Configurable, time-stamped logging of user actions

Choosing which record types to log, switching logging on, reviewing trails

Access and authority checks

Role-based and attribute-based access rights, password policies

Role definitions, access reviews, joiner and leaver processes

Retention and copies

Retention rules, write protection, archive formats

Retention schedules mapped to each predicate rule

Electronic signatures

Signature functions or connectors to signing services

Signature policies, identity checks, FDA certification letter

Training and accountability

User and administrator documentation

Training records, written accountability policies

The right-hand column is what an investigator will ask your team to show. No software can write your SOPs or sign your validation report for you.

How to choose a document management system for a Part 11 environment

Start with the questions an investigator would ask about your records, then ask the vendor how its platform answers each one. These five questions give you a good starting point.

Which events does the audit trail capture, and how is logging configured?

Ask whether previous values are preserved when a record changes and whether audit records are protected against editing.

How do signatures display and link to records?

Confirm that the signed record shows the signer's name, the date and time, and the meaning, and that the signature is bound to one document version.

What validation documentation and support do you supply?

Ask what the vendor provides and what you will need to produce yourself or through a services partner.

How are records protected over the full retention period?

Look for write protection, retention rules per document type, and long-term archive formats.

How do access rights map to your roles?

Check that you can restrict access at document-type and individual-document level, and that you can report who held which rights on a given date.

Ask the vendor to show each answer in a live demo, using a signed record and its audit trail. If they can't show it to you, they won't be able to show it to an investigator either.

Beyond Part 11: managing the full GxP document lifecycle

Part 11 covers how a record is created, changed, and signed. Most of the rules for the rest of a record's life come from the predicate rules and your own quality system.

SOPs need controlled revisions and periodic review, which is the core of document control. Released versions must stay locked while earlier revisions remain traceable through document version control. Approvals need a documented route, and records need retention rules that match each predicate rule.

Every system that holds GxP records needs its own validation, access model, and audit trail. Running document control, approvals, and archiving on one platform keeps that number low and makes it easier to connect your ERP and the other systems that generate GxP records.

How Doxis supports Part 11 requirements

Doxis provides building blocks that support requirements related to Part 11. It is not a "Part 11 compliant" system out of the box: your team configures the controls, writes the procedures, and validates the system for its intended use, with support from Doxis.

  • Audit trail: the audit trail service logs the date, operation, user, and role for each recorded action. Logging is configured per category of operations, and nothing is logged until an administrator enables it. Keeping previous values is also a configuration choice, so include both in your validation scope.
  • Access control: access rights work at class and instance level, with configurable password policies. Attribute-based access control is also available.
  • Retention and protection: retention rules and SoftWORM write protection through Doxis safeLock keep records protected for their retention period. Retention of audit entries is configured separately from the record.
  • Electronic signatures: a signature is bound to one specific document version. Signing can run through integrations with external signing providers or a local certificate store. Signed records show the signer's name, the date and time, and the meaning of the signature, and signing uses two components.
  • Validation: Doxis supports the validation of your system. Your company stays responsible for approving the validation, writing SOPs, training users, and submitting the FDA certification of your electronic signatures.

Those controls sit inside a wider document management system. The same platform runs approval workflows with process automation and long-term records management, so the SOP, its approval, and its archived record are managed in one system.

  • Audit trails you configure: choose which categories of operations are logged and review the entries
  • Granular access control: restrict rights by document class or individual document
  • Version-bound signatures: each signature attaches to one document version and shows who signed, when, and why
  • Retention with SoftWORM protection: retention rules plus audit-proof archiving with SoftWORM protection
  • One platform for the lifecycle: document control, approval workflows, and archiving run on the same platform

See how Doxis supports regulated manufacturers on the pharma and life sciences page. Doxis is a Leader in the Gartner® Magic Quadrant™ for Document Management 2026. Request a free demo to walk through a signed record and its audit trail with our team.

Automate Work. Accelerate Business.

Bring together AI, ECM, and workflow automation in one powerful enterprise platform.

FAQs on 21 CFR Part 11 requirements

What is the difference between 21 CFR Part 11 and EU GMP Annex 11?

Part 11 is a US FDA regulation for electronic records and signatures. EU GMP Annex 11 is part of the European GMP guidelines and covers computerized systems. It puts risk at the center, stating that. Annex 11 is being revised: a draft was published for consultation in July 2025, together with a new Annex 22 on artificial intelligence, and it was still in draft as of October 2026.

Can software be "21 CFR Part 11 certified"?

No. The FDA does not certify software for Part 11, because compliance rests on how you configure, validate, and operate the system as much as on its technical controls.

Does 21 CFR Part 11 apply to scanned paper records?

It applies when you rely on the electronic copy to meet a predicate rule. If the paper original remains your official record, Part 11 does not apply to the scan. If the scan replaces the paper and becomes the record you rely on, Part 11 applies.

Are electronic signatures legally binding under 21 CFR Part 11?

Yes, once you meet the Part 11 controls and submit a hand-signed certification to the FDA stating that your electronic signatures are the legally binding equivalent of handwritten signatures. That certification is your company's declaration to the FDA. The wider legal effect of electronic signatures in the US also rests on laws such as the ESIGN Act and UETA.

What are the 21 CFR Part 11 electronic signature requirements?

Each signature must be unique to one person, show the signer's name, date and time, and meaning, and stay linked to its record. Non-biometric signatures need at least two components, such as a user ID and password.

Do signatures drawn on a tablet count as handwritten signatures?

Yes. Part 11 defines a handwritten signature to include one captured on an electronic device, and the FDA's October 2024 guidance for clinical investigations confirms that signatures drawn with a finger or stylus count as handwritten signatures. They must still be linked to the electronic record they sign.

What are the 21 CFR Part 11 audit trail requirements?

Audit trails must be secure, computer-generated, and time-stamped, record actions that create, modify, or delete records, and preserve previous values. You must keep them as long as the records and make them available to the FDA.

Who is responsible for 21 CFR Part 11 compliance when using cloud software?

You are. Part 11 obligations stay with the regulated company, and the FDA's October 2024 guidance for clinical investigations confirms this applies to systems run by IT service providers.

Bärbel Heuser-Roth

Bärbel Heuser-Roth has specialized in a wide range of Enterprise Content Management (ECM) disciplines, including information logistics, process management, compliance, and AI-based intelligent content automation. Her professional work has been complemented by in-depth research and extensive publications on the planning, implementation, and optimization of ECM initiatives across enterprises and organizations.

You might also be interested in

How can we help you?

+49 (0) 30 498582-0
What is the sum of 7 and 5?

Your message has reached us!

We appreciate your interest and will get back to you shortly.

Contact us

Table of contents