Skip to main content

21 CFR Part 11 Software Requirements: Vendor Evaluation Guide

Ready to modernize?

See GoVal in Action

Book a 30-minute walkthrough with our validation specialists. No slides — just your questions, answered live.

Contact Us
Summary

21 CFR Part 11 software requirements fall into two categories: electronic records controls under Section 11.10 — validation, accurate copies, record protection, limiting access, secure time-stamped audit trails, and operational and authority checks — and electronic signature controls under Sections 11.50 through 11.300, covering unique signature identity, signature-to-record linking, and two distinct components for every signing event. There is no FDA certification for 'Part 11 compliant' software; compliance depends on how a specific vendor's system is built and configured, not a label the vendor applies to itself. Evaluating a vendor means asking to see the audit trail generate live, confirming whether it captures old and new values, and checking whether an administrator can disable it without that action itself being logged. GoVal ships with 21 CFR Part 11 compliant audit trails and e-signatures built into its architecture, scaled to each system's GAMP 5 risk classification rather than applied as a marketing label.

What are the 21 CFR Part 11 software requirements, and how do you evaluate a vendor against them?

Part 11 requires two categories of controls: electronic record controls — validation, accurate copies, record protection, limited access, and secure time-stamped audit trails — and electronic signature controls, covering unique signature identity and tamper-evident signature-to-record linking. There's no FDA certification for "Part 11 compliant" software, so evaluating a vendor means verifying these controls directly — asking to see the audit trail generate live, not just described in a slide.

There is no FDA certificate for "21 CFR Part 11 compliant" software. Any vendor who tells you otherwise just failed the first question you should be asking them.

What "Part 11 Compliant" Actually Means

Part 11 is a regulation defining controls for electronic records and electronic signatures used in FDA-regulated processes — it isn't a certification program, and the FDA doesn't audit or approve software vendors against it directly. When a vendor's website says "21 CFR Part 11 compliant," that's a description of the product's built-in capabilities, not a regulatory seal of approval. Whether the software is actually compliant depends on how it's configured and used at your specific company, validated against your specific intended use. The label is a starting point for evaluation, not the finished answer.

Electronic Records Requirements to Verify

Section 11.10 sets the controls for electronic records themselves. These are the specific capabilities to confirm, not just ask about in general terms.

RequirementWhat to Verify in a Demo
System validationAsk for the vendor's own validation documentation for the software itself, not just a security certificate
Accurate and complete copiesAsk them to export a record and confirm it matches the system's live version exactly, including metadata
Record protection and retentionAsk how records are protected from deletion or overwrite, and what retention period the architecture enforces
Limited, controlled system accessAsk how role-based access is enforced, and whether it's structurally prevented or just a policy recommendation
Secure, computer-generated, time-stamped audit trailsAsk to see a field changed live, and confirm the audit trail captures the old value, the new value, who, and when
Operational system checksAsk whether the system enforces the correct sequence of steps, or allows steps to be skipped or reordered
Authority checksAsk what stops a user without the right permission level from performing a restricted action

Electronic Signature Requirements to Verify

Sections 11.50 through 11.300 govern electronic signatures specifically — a separate set of controls from records, and one that's just as commonly under-verified in a vendor demo.

  • Unique to one individual. Confirm the system structurally prevents shared logins for any account used to sign records — not just a policy telling people not to share passwords.
  • Identity verified before assignment. Ask what process confirms a person's identity before they're issued signing credentials in the first place.
  • Signature manifestation. Confirm a completed signature displays the signer's printed name, the date and time, and the meaning of the signature (approval, review, authorship).
  • Signature-to-record linking. Ask what prevents a signature from being copied, transferred, or reattached to a different record version than the one actually signed.
  • Two distinct components per signing. Confirm each signing event requires two identification components — typically a user ID plus a password re-entered at the moment of signing, not a session that stays open indefinitely.

Red Flags: "Part 11 Compliant" Claims That Don't Hold Up

  • Encryption and hosting security get conflated with Part 11 compliance. TLS encryption and SOC 2 hosting certifications are good security practice, but they say nothing about audit trail integrity or signature-to-record linking.
  • The audit trail can be disabled by an administrator without that action being logged. If turning off the audit trail isn't itself an audit-trailed event, the control has a hole in it.
  • Electronic signature is just a confirmation click, with no password re-entry. A single sign-on session that stays authenticated doesn't meet the two-component requirement for each individual signing event.
  • The vendor can't produce their own system's validation documentation. If they can't show how their own software was validated, that's worth taking seriously before you build your validation package on top of theirs.

How GoVal Meets Part 11 Requirements

GoVal is built with 21 CFR Part 11 controls in its architecture from the start, not layered on as a configuration afterthought.

Native, tamper-evident audit trails
Every change captures old value, new value, user, and timestamp — and disabling the audit trail is itself an audit-trailed event.
Enforced unique signature identity
Shared logins for signing accounts are structurally prevented, not left to policy alone.
Signature-to-record linking
Signatures are tied to the specific record version signed, with manifestation of name, meaning, and timestamp displayed.
GAMP 5-scaled validation
Documentation and testing scope scale to each system's risk classification, generating defensible evidence rather than a marketing claim.

Related Topics

Frequently Asked Questions

What software features are required for 21 CFR Part 11 compliance? +
Part 11 requires two categories of controls: electronic record controls under Section 11.10, including system validation, the ability to generate accurate and complete copies, record protection and retention, limited and controlled access, and secure, computer-generated, time-stamped audit trails; and electronic signature controls under Sections 11.50 through 11.300, covering unique signature identity, verified identity before assignment, signature-to-record linking, and two distinct components for every signing event.
Is there an official FDA certification for Part 11 compliant software? +
No. The FDA does not certify, approve, or endorse software as "21 CFR Part 11 compliant." Compliance is a property of how a specific system is configured, validated, and used at a specific regulated company, not a label a vendor can earn once and apply universally. Treat a vendor's compliance claim as a starting point for verification, not a finished answer.
What questions should I ask a vendor to verify Part 11 compliance? +
Ask them to generate an audit trail entry live during the demo, and confirm whether it captures both the old and new value for a changed field, not just that a change occurred. Ask whether an administrator can disable the audit trail, and if so, whether that action is itself logged. Ask how electronic signatures are cryptographically linked to a specific record version, and what prevents two people from sharing a single login.
Does 21 CFR Part 11 require specific software, or can any system be made compliant? +
Part 11 doesn't mandate specific products; it defines controls any system handling GxP electronic records or signatures must meet. In principle, many systems can be configured to meet these controls, but some architectures make requirements like tamper-evident audit trails far easier to implement correctly than others. A system built around these controls from the start typically needs less custom configuration than one retrofitted afterward.
What's the difference between Part 11 electronic records and electronic signature requirements? +
Electronic record requirements govern how GxP data itself is created, changed, and protected — validation, audit trails, access control, and retention. Electronic signature requirements govern how a person's approval is captured and tied to a specific record — unique identity, verified assignment, and tamper-evident linkage between the signature and what was signed. A system can pass one and fail the other, so both need separate verification.
Can two people share a login in Part 11 compliant software? +
No. Part 11 requires that electronic signatures be unique to one individual and never reused or reassigned, which rules out shared logins for any account used to sign or approve GxP records. Shared credentials break the attribution the entire framework depends on — if two people can act under one identity, no signature or audit trail entry can be reliably tied to who actually performed the action.
How does GoVal meet 21 CFR Part 11 requirements? +
GoVal ships with 21 CFR Part 11 compliant audit trails and e-signatures built into its architecture rather than added as a configuration layer afterward — unique user identity, tamper-evident audit trails capturing old and new values, and signature-to-record linkage are native. Validation and documentation scope scale to each system's GAMP 5 risk classification, so Part 11 controls are demonstrably in place rather than asserted as a marketing claim.

See Part 11 controls demonstrated live, not described

Native audit trails, enforced signature identity, and GAMP 5-scaled validation evidence — in GoVal.

Book a Free Demo →