Compliance
FDA 21 CFR Part 11: a practical guide to electronic records and signatures
What 21 CFR Part 11 requires — electronic records, electronic signatures, audit trails, validation, and access controls — how the QMSR transition affects it, and what "Part 11 compliant" software really means.
21 CFR Part 11 is the FDA regulation that defines when electronic records and electronic signatures are considered as trustworthy and reliable as paper records and handwritten signatures. Issued in 1997, it applies to any FDA-regulated organization — drug and biologics makers, medical device manufacturers, contract research organizations — that creates, modifies, maintains, archives, retrieves, or transmits regulated records electronically.
If your quality system, design history, or clinical data lives in software rather than paper, Part 11 is almost certainly in scope. This guide explains what it actually requires, how the recent QMSR transition affects it, and — importantly — what it means when a vendor calls its software “Part 11 compliant.”
The predicate rule: when Part 11 applies
Part 11 doesn’t stand alone. It applies whenever you use electronic records or signatures to satisfy some other FDA regulation — what the agency calls a predicate rule. Common predicate rules include 21 CFR Part 820 (now the QMSR) for medical devices, Part 211 for pharmaceutical cGMP, Part 58 for good laboratory practice, and Parts 312 and 314 for investigational and new drug applications.
The test is straightforward. If a predicate rule requires you to keep a record, and you choose to keep that record electronically, Part 11 governs how you do it. That’s why a design history file in an eQMS, a batch record in a LIMS, or training records in an LMS all fall squarely within Part 11.
The core technical requirements
Part 11 sets out controls that a compliant electronic system must support. The ones inspectors cite most often are:
- Validated systems. You must demonstrate that the system does what it’s supposed to, reliably and consistently. The FDA’s 2025 Computer Software Assurance (CSA) guidance encourages a risk-based approach — heavier validation for high-risk functions, lighter for low-risk ones.
- Secure, time-stamped audit trails. The system must independently record who did what, when — for every action that creates, modifies, or deletes a record. Crucially, changes must not obscure previously recorded information, and the trail must be retained as long as the record itself.
- Electronic signature controls. Signatures must be uniquely linked to one individual and to the specific record signed, in a way they cannot be excised, copied, or transferred to falsify a record. A scanned image of a signature does not qualify.
- Access and authority checks. Only authorized individuals may use the system, sign records, or alter data — with individual credentials, not shared logins.
- Record retention and accurate copies. The system must produce complete, human-readable and electronic copies suitable for FDA inspection throughout the retention period.
Audit-trail and electronic-signature deficiencies, along with missing validation, are among the most frequently cited findings in FDA warning letters — and data-integrity enforcement has been intensifying, not easing.
Part 11 and the QMSR transition
Effective February 2, 2026, the FDA replaced the old Quality System Regulation (21 CFR Part 820) with the Quality Management System Regulation (QMSR), which incorporates ISO 13485:2016 by reference. This matters for Part 11, but not in the way some teams assume: the QMSR does not replace or relax Part 11. The two coexist. The QMSR sets the quality-system expectations (including software validation under ISO 13485 clause 4.1.6); Part 11 continues to govern the electronic records and signatures those quality processes produce.
In practice, organizations already aligned to ISO 13485 will find the quality-system side familiar, but their electronic-records obligations are unchanged.
What “Part 11 compliant software” really means
Here’s the part that trips up buyers: no vendor can sell you turnkey Part 11 compliance. Compliance is a combination of technical controls — which software provides — and procedural controls — which only your organization can implement, through SOPs, validation, training, and audit-trail reviews.
What a system can do is provide the technical foundation: a tamper-evident audit trail, compliant electronic signatures, individual access controls, and the ability to generate inspection-ready copies. What it cannot do is operate your quality program for you. When you evaluate tools, the right question isn’t “are you compliant?” — it’s “which Part 11 controls do you provide natively, and how do you support our validation?”
Where traceability fits
Part 11 is fundamentally about trust in your records — and traceability is a large part of what makes records trustworthy under audit. A complete requirements traceability matrix, backed by a tamper-evident history, lets you show an inspector not just what a record says but how it connects to the design and verification around it, and exactly how it changed over time.
This is the foundation TraceUnified is built on. Requirements, architecture, tests, and risk live as governed records in one system with a versioned, tamper-evident audit trail and Part 11 electronic signatures throughout — so the technical controls Part 11 expects are intrinsic to the record, not bolted on. The compliance program is still yours to run; the system is engineered to enable it. You can see how that maps to specific frameworks on the compliance overview.
See traceability work as one connected system.
Requirements, architecture, tests, risk, and SBOM on a single thread — audit-ready by default.