Few phrases appear on clinical research software marketing pages more often than "21 CFR Part 11 compliant." Few phrases are more routinely misunderstood. This article explains what Part 11 actually is, when it applies, what it requires in plain language, and how to evaluate what a vendor is really claiming.

What Part 11 is

Part 11 is the section of Title 21 of the Code of Federal Regulations in which FDA sets the conditions under which electronic records and electronic signatures are considered trustworthy, reliable, and generally equivalent to paper records and handwritten signatures [1]. Issued in 1997, it grew out of industry's own request: regulated companies wanted to move from paper to electronic systems, and FDA needed criteria for accepting electronic records in place of the paper the regulations had assumed.

The structure matters. Part 11 does not, by itself, require anyone to keep any record. Other FDA regulations — the so-called predicate rules, such as the IND regulations (21 CFR Part 312), the IDE regulations (21 CFR Part 812), and the informed consent and IRB regulations — establish which records must be created and retained. Part 11 then governs how those records may be kept electronically [2].

When Part 11 applies — and when it doesn't

Part 11 applies to records that are created, modified, maintained, archived, retrieved, or transmitted in electronic form under records requirements in FDA regulations, and to electronic records submitted to FDA [1] [2]. In practice, that means:

  • It applies to FDA-regulated clinical investigations — studies conducted under an IND or IDE, and studies of FDA-regulated products intended to support marketing applications. Case report form data, eConsent records, and electronic signatures on regulated documents in these studies fall within scope.
  • It generally does not apply to research that no FDA predicate rule reaches. A great deal of academic research — observational studies, registries, behavioral research, and much investigator-initiated work that involves no FDA-regulated product and no intent to submit to FDA — sits outside Part 11 entirely.

As with most regulatory boundaries, "Part 11 doesn't apply to us" is the beginning of an analysis, not the end. Studies outside Part 11 still answer to the Common Rule and IRB requirements, to good clinical practice expectations where ICH E6 has been adopted or contractually imposed [4], to institutional policy, and to the ordinary scientific obligation to keep data trustworthy. Many academic institutions apply Part 11-like controls — audit trails, access controls, validation — as a matter of data integrity even when the regulation itself is not triggered.

The core requirements, in plain language

For closed systems (systems where access is controlled by the people responsible for the records — which describes most EDC systems), Part 11's requirements include [1]:

  • Validation. The system must be validated to ensure accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records. (See validation documentation.)
  • Audit trails. Secure, computer-generated, time-stamped audit trails must record the creation, modification, and deletion of records — without obscuring previously recorded information. (See audit trails.)
  • Record protection and retrieval. Records must be protected so they remain accurate and retrievable throughout the retention period, and the system must be able to produce accurate and complete copies for FDA inspection.
  • Access and authority controls. System access limited to authorized individuals, with checks that only authorized people can use the system, sign records, or perform specific operations. (See security controls and role-based permissions.)
  • Training and accountability. People who develop, maintain, or use the system must have the education, training, and experience to do their tasks, and written policies must hold individuals accountable for actions taken under their electronic signatures.
  • Electronic signatures. Signatures must be unique to one individual and never reused or reassigned; signed records must display the signer's name, the date and time, and the meaning of the signature (such as review or approval); and signatures must be linked to their records so they cannot be excised or copied to falsify anything. Organizations using electronic signatures must certify to FDA that those signatures are intended as the legally binding equivalent of handwritten ones [1]. (See electronic signatures.)

Notice how much of that list is about people, procedures, and documentation rather than software features. That observation is the key to the rest of this article.

The 2003 guidance: enforcement discretion

In the years after 1997, industry argued that broad readings of Part 11 were discouraging the very modernization the rule was meant to enable. FDA responded in 2003 with the Part 11 Scope and Application guidance, which announced a narrower interpretation and stated that the agency would exercise enforcement discretion — that is, would generally not take enforcement action — regarding certain Part 11 requirements, including validation, audit trails, record retention, and record copying, while it reexamined the rule [2]. Two things are worth understanding:

  1. The guidance narrowed Part 11-specific enforcement; it did not waive the predicate rules. Records still must be trustworthy and retained, and FDA continued to expect controls justified by a documented, risk-based assessment.
  2. The reexamination never produced a rewritten rule. Part 11 remains on the books as written, read through the lens of the 2003 guidance and the more recent guidance below.

The 2023 guidance: electronic systems in clinical investigations

In 2024 FDA finalized "Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers," which supersedes earlier 2017-era draft material and updates the agency's thinking for how trials actually run now [3]. In question-and-answer form, it addresses topics the 1997 rule could not have anticipated: electronic records drawn from EHRs and other real-world sources, cloud-hosted systems and the sponsor's responsibility for overseeing IT service providers, digital health technologies used to capture data remotely, risk-based approaches to validation, and acceptable methods of electronic signature. The consistent theme is that responsibility follows the regulated party — sponsors and investigators cannot outsource accountability for their records to a hosting provider or software vendor [3].

Why "Part 11 compliant software" is not a thing you can buy

Part 11 regulates records and the organizations that keep them, not products. Software can be compliant-capable — built with audit trails, access controls, signature manifestations, validation documentation, and export functions that make compliance achievable. But compliance itself also depends on things no vendor ships: your validation of the system for your intended use, your SOPs, your account management and training, your signature certification to FDA, and how your users actually behave. The same system can sit inside a fully compliant operation at one site and an inspection finding at another that shares logins and never wrote a procedure.

So when a vendor says "Part 11 compliant," the useful translation is: "ask us specific questions." The phrase alone tells you almost nothing about where the vendor's responsibilities end and yours begin.

Questions to ask a vendor

These are reasonable due diligence for any system holding regulated study data — and most are worth asking even when Part 11 does not technically apply.

  1. Which Part 11 requirements does the system support, specifically — and which controls remain procedural obligations on our side?
  2. Is there a complete, computer-generated audit trail covering creation, modification, and deletion, with prior values preserved — and can we review and export it? (See audit trails.)
  3. How do electronic signatures work — signer identity, date/time, meaning, and linkage to the record? Are signature components enforced? (See electronic signatures.)
  4. What validation documentation exists for the platform, and what is the customer's validation responsibility for study-specific configuration? (See validation documentation.)
  5. How is access controlled — unique accounts, role-based permissions, authentication requirements, and deprovisioning? (See security controls and role-based permissions.)
  6. How are records protected and retrieved across the retention period, and can we produce accurate and complete copies — including audit trails — for an inspection? (See data export and archiving and retention.)
  7. How are software releases and mid-study changes managed, and what revalidation documentation accompanies them?
  8. Who hosts the system, and how is vendor and subprocessor oversight handled — the specific concern the 2023 guidance raises about IT service providers [3]?

The bottom line

Part 11 is narrower than the marketing suggests — it may not apply to your study at all — and broader than a feature checklist: where it applies, it governs your validation, procedures, training, and signatures, not just your software. Establish whether a predicate rule reaches your records, read the 2003 and 2023 guidances rather than vendor summaries of them, buy systems that are genuinely compliant-capable, and remember that the best audit trail in the world does not compensate for a site where everyone knows the coordinator's password.