What are the 21 CFR Part 11 software requirements, and how do you evaluate a vendor against them?
Part 11 requires two categories of controls: electronic record controls — validation, accurate copies, record protection, limited access, and secure time-stamped audit trails — and electronic signature controls, covering unique signature identity and tamper-evident signature-to-record linking. There's no FDA certification for "Part 11 compliant" software, so evaluating a vendor means verifying these controls directly — asking to see the audit trail generate live, not just described in a slide.
There is no FDA certificate for "21 CFR Part 11 compliant" software. Any vendor who tells you otherwise just failed the first question you should be asking them.
What "Part 11 Compliant" Actually Means
Part 11 is a regulation defining controls for electronic records and electronic signatures used in FDA-regulated processes — it isn't a certification program, and the FDA doesn't audit or approve software vendors against it directly. When a vendor's website says "21 CFR Part 11 compliant," that's a description of the product's built-in capabilities, not a regulatory seal of approval. Whether the software is actually compliant depends on how it's configured and used at your specific company, validated against your specific intended use. The label is a starting point for evaluation, not the finished answer.
Electronic Records Requirements to Verify
Section 11.10 sets the controls for electronic records themselves. These are the specific capabilities to confirm, not just ask about in general terms.
| Requirement | What to Verify in a Demo |
|---|---|
| System validation | Ask for the vendor's own validation documentation for the software itself, not just a security certificate |
| Accurate and complete copies | Ask them to export a record and confirm it matches the system's live version exactly, including metadata |
| Record protection and retention | Ask how records are protected from deletion or overwrite, and what retention period the architecture enforces |
| Limited, controlled system access | Ask how role-based access is enforced, and whether it's structurally prevented or just a policy recommendation |
| Secure, computer-generated, time-stamped audit trails | Ask to see a field changed live, and confirm the audit trail captures the old value, the new value, who, and when |
| Operational system checks | Ask whether the system enforces the correct sequence of steps, or allows steps to be skipped or reordered |
| Authority checks | Ask what stops a user without the right permission level from performing a restricted action |
Electronic Signature Requirements to Verify
Sections 11.50 through 11.300 govern electronic signatures specifically — a separate set of controls from records, and one that's just as commonly under-verified in a vendor demo.
- Unique to one individual. Confirm the system structurally prevents shared logins for any account used to sign records — not just a policy telling people not to share passwords.
- Identity verified before assignment. Ask what process confirms a person's identity before they're issued signing credentials in the first place.
- Signature manifestation. Confirm a completed signature displays the signer's printed name, the date and time, and the meaning of the signature (approval, review, authorship).
- Signature-to-record linking. Ask what prevents a signature from being copied, transferred, or reattached to a different record version than the one actually signed.
- Two distinct components per signing. Confirm each signing event requires two identification components — typically a user ID plus a password re-entered at the moment of signing, not a session that stays open indefinitely.
Red Flags: "Part 11 Compliant" Claims That Don't Hold Up
- Encryption and hosting security get conflated with Part 11 compliance. TLS encryption and SOC 2 hosting certifications are good security practice, but they say nothing about audit trail integrity or signature-to-record linking.
- The audit trail can be disabled by an administrator without that action being logged. If turning off the audit trail isn't itself an audit-trailed event, the control has a hole in it.
- Electronic signature is just a confirmation click, with no password re-entry. A single sign-on session that stays authenticated doesn't meet the two-component requirement for each individual signing event.
- The vendor can't produce their own system's validation documentation. If they can't show how their own software was validated, that's worth taking seriously before you build your validation package on top of theirs.
How GoVal Meets Part 11 Requirements
GoVal is built with 21 CFR Part 11 controls in its architecture from the start, not layered on as a configuration afterthought.
Related Topics
Frequently Asked Questions
What software features are required for 21 CFR Part 11 compliance? +
Is there an official FDA certification for Part 11 compliant software? +
What questions should I ask a vendor to verify Part 11 compliance? +
Does 21 CFR Part 11 require specific software, or can any system be made compliant? +
What's the difference between Part 11 electronic records and electronic signature requirements? +
Can two people share a login in Part 11 compliant software? +
How does GoVal meet 21 CFR Part 11 requirements? +
See Part 11 controls demonstrated live, not described
Native audit trails, enforced signature identity, and GAMP 5-scaled validation evidence — in GoVal.
