Regulations and Standards
TL;DR
21 CFR Part 11 is the FDA regulation that sets out when electronic records and electronic signatures can be trusted as generally equivalent to paper records and handwritten signatures. It applies when records that other FDA regulations require, under GLP or GMP rules for example, are kept or submitted electronically.
21 CFR Part 11 is the section of Title 21 of the US Code of Federal Regulations that sets the criteria under which FDA considers electronic records and electronic signatures trustworthy, reliable, and generally equivalent to paper records and handwritten signatures. FDA published the rule on March 20, 1997, and it took effect on August 20, 1997.
It is a short regulation, and it does not decide which records you keep. Those obligations come from the predicate rules, such as 21 CFR Part 58 for GLP nonclinical studies and Parts 210 and 211 for drug CGMP. Part 11 governs how those records are handled once they are electronic. EU GMP Annex 11 is the closest European equivalent, and the two overlap heavily.
Records a predicate rule requires, and records submitted to FDA. A nonclinical study run under GLP brings Part 11 in, and so does GMP manufacturing. An academic group doing basic research has no Part 11 obligation.
Inside a regulated lab the question gets answered system by system. Any electronic system holding records a predicate rule requires, from the ELN to the freezer inventory used in a GLP study, has to meet the Part 11 controls, or the lab has to treat a signed paper printout as the official record. FDA's 2003 guidance says that when a printout is the record relied on for regulated activities, Part 11 generally does not apply to the electronic version. So which copy you rely on changes your scope a great deal.
The rule has three subparts:
Most of the day-to-day weight sits in section 11.10, the controls for closed systems, meaning systems where access is controlled by the people responsible for the records on them. Section 11.10 asks for validation, accurate copies for inspection, record protection through the retention period, limited system access, audit trails, operational and authority checks, device checks, trained staff, a written policy holding people accountable for their electronic signatures, and control over system documentation.
At the bench it looks ordinary. A scientist logs in with her own account, and the plate reader PC has no shared "LabUser1" login. She records a protocol deviation in the notebook entry, attaches the raw export from the instrument run, and signs with her user ID and password. The signed record shows her printed name, the date and time, and the meaning of the signature, and the signature is linked to that entry so it cannot be copied onto another one. If she corrects a concentration the next morning, the change lands in the audit trail beside the original value.
FDA narrowed how it enforces the rule without changing the rule itself. Its August 2003 guidance, "Part 11, Electronic Records; Electronic Signatures: Scope and Application," said FDA would exercise enforcement discretion on validation, audit trails, legacy systems, copies of records, and record retention, and asked firms to base those decisions on risk.
FDA kept enforcing the other provisions, including limited system access, operational and authority checks, and every electronic signature requirement in sections 11.50, 11.70, 11.100, 11.200, and 11.300. And predicate rules still apply in full, so the discretion is narrower than it sounds. For clinical investigations, FDA's October 2024 final guidance answers Part 11 questions specific to that setting.
Quite a lot, because several requirements are procedural. Section 11.10(i) expects evidence that users are trained, 11.10(j) requires a written policy that people are accountable for what they sign, and 11.100(c) requires organizations to certify to FDA, in a letter with a handwritten signature, that their electronic signatures are intended to be legally binding. A vendor supplies technical controls. Validation for your intended use, the SOPs and the training records stay with the lab.
A workable order is to list the records your predicate rules require and where each one lives today, then run a gap assessment against sections 11.10, 11.50, 11.70, 11.100, 11.200, and 11.300, one system at a time. Note which controls the software provides and which need an SOP, such as deactivating accounts when someone leaves, periodic password checks, and the certification letter to FDA. Then scale validation to risk. A system holding GLP raw data needs more evidence than one holding meeting notes.
IGOR is compliant with 21 CFR Part 11. The controls involved are a time-stamped audit trail, electronic signatures applied with initials and account password, role-based access control enforced in the application and at the database level through row-level security, and a Document Version History on every notebook entry, and they are described on IGOR's security and compliance page. Compliance for your own studies also depends on your team's SOPs and validation.
No. FDA does not certify software or vendors for 21 CFR Part 11. A vendor can state that its system is compliant with Part 11 and supply validation documentation, but compliance is assessed for each regulated use inside each organization, so a "Part 11 certificate" from a vendor is the vendor's own claim and not an FDA document.
Usually not. 21 CFR Part 11 applies only to records required by FDA regulations or submitted to FDA, so most academic labs doing basic research are outside its scope. That changes when an academic group runs a nonclinical study under GLP, takes part in an FDA-regulated clinical investigation, or generates data meant for a regulatory submission.
It narrowed the records FDA treats as subject to Part 11 and announced enforcement discretion for validation, audit trails, legacy systems, copies of records, and record retention. FDA kept enforcing the other controls, including all electronic signature provisions, and predicate rule requirements for documenting changes still apply.
21 CFR Part 11 is a US regulation on electronic records and signatures, while EU GMP Annex 11 is part of the EU GMP guidelines and covers the whole lifecycle of computerised systems. Annex 11 says more about risk management, suppliers, and periodic evaluation. Part 11 says more about signature mechanics. A revised draft of Annex 11 went out for public consultation in 2025.
This page is a general overview for lab scientists. It is not formal compliance or legal advice, and the requirements that apply to your lab depend on your regulated activities, your predicate rules, and your own validated processes.