Electronic Records; Electronic Signatures
Sets the criteria under which FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and equivalent to paper records and handwritten signatures executed on paper.
All persons required to maintain records or submit information to FDA under statutes enforced by the Agency. Applies to any electronic records that are created, modified, maintained, archived, retrieved, or transmitted under applicable FDA requirements.
- 01Audit trails for all operator entries, computer-generated data, and changes
- 02System access controls — unique user IDs, passwords, biometrics
- 03Electronic signatures include printed name, date/time, and meaning of signature
- 04Software validation — installation qualification, operational qualification, performance qualification
- 05Copies of records in readable form (human-readable and electronic output)
- 06Protection of records throughout retention period
No amendments since the rule took effect in 1997. FDA issued Guidance for Industry on Scope and Application (2003) as primary interpretive reference. Data Integrity guidance (2018) significantly expanded practical requirements.
21 CFR Part 11: frequently asked questions
Quick answers to common questions about 21 CFR Part 11.
What is 21 CFR Part 11?
21 CFR Part 11 — Electronic Records; Electronic Signatures — is a regulation issued by the Food and Drug Administration (United States). Sets the criteria under which FDA considers electronic records, electronic signatures, and handwritten signatures executed to electronic records to be trustworthy, reliable, and equivalent to paper records and handwritten signatures executed on paper.
Who does 21 CFR Part 11 apply to?
All persons required to maintain records or submit information to FDA under statutes enforced by the Agency. Applies to any electronic records that are created, modified, maintained, archived, retrieved, or transmitted under applicable FDA requirements.
What are the key requirements of 21 CFR Part 11?
FDA 21 CFR Part 11 requires, among other things: Audit trails for all operator entries, computer-generated data, and changes; System access controls — unique user IDs, passwords, biometrics; Electronic signatures include printed name, date/time, and meaning of signature; Software validation — installation qualification, operational qualification, performance qualification.
When was 21 CFR Part 11 last updated?
The current version of 21 CFR Part 11 dates from August 1997. No amendments since the rule took effect in 1997. FDA issued Guidance for Industry on Scope and Application (2003) as primary interpretive reference. Data Integrity guidance (2018) significantly expanded practical requirements.
Live openFDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.
Track the standards that move
When 21 CFR Part 11 — or any GxP requirement — is revised, recalled against, or clarified by new guidance, the Weekly GxP Briefing surfaces it. Free, one email a week.