Skip to main content
Blog

Decoding 21 CFR Pt. 11: Your Compliance Checklist for Electronic Records and Signatures


00:0000:00
9 min read

Under 21 CFR Part 11, the Food and Drug Administration (FDA) mandates rigorous standards for electronic records and signatures. Discover how FDA-regulated organizations can maintain strict compliance while accelerating digital transformation and operational efficiency with Docusign.

en-US

In 21 CFR Part 11, the Food and Drug Administration (FDA) establishes its requirements for electronic records and signatures. The regulation is intended to permit the widest possible use of the technology, while ensuring the integrity and security of electronic records and signatures, ultimately supporting the Food and Drug Administration’s responsibility to protect the public health opens in a new tab.

Docusign eSignature is used by pharmaceutical and medical device companies to meet a range of compliance requirements, including those set forth in the Code of Federal Regulations Title 21 Part 11.

We have a complete guide to CFR Part 11 and electronic signatures with examples of how eSignature satisfies the requirements.

Here we’ll summarize key concepts from 21 CFR Part 11, including how the regulation addresses electronic signatures and electronic records, with a closer look at Subpart C requirements related to signatures.

Key takeaways

  • Title 21 CFR Part 11 establishes the FDA's regulatory standards for ensuring that electronic records and signatures are as trustworthy and reliable as paper equivalents.

  • These compliance guidelines apply to organizations operating within FDA-regulated industries, such as pharmaceutical companies and medical device manufacturers.

  • Compliant electronic signatures must include specific identifying information, while the systems supporting them require rigorous validation, secure audit trails, and reliable record retention protocols.

  • Docusign offers a specialized Part 11 module designed to help life science organizations meet these regulatory standards while confidently streamlining their digital agreement processes.

What does 21 CFR Part 11 stand for?

Title 21 CFR Part 11 opens in a new tab establishes the United States Food and Drug Administration (FDA) regulations on electronic records and electronic signatures. It is a portion of Title 21 of the Code of Federal Regulations.

Part 11 of the code applies to records in electronic form that are created, modified, maintained, archived, retrieved, transmitted, or submitted under any records requirements set forth by FDA regulations or predicate rules.

Who is required to be compliant with 21 CFR Part 11?

Organizations that are subject to 21 CFR Part 11 are those regulated by the FDA and/or engage in activities related to FDA-regulated products. They typically include the following industries:

  • Pharmaceutical companies

  • Biotechnology companies

  • Medical device manufacturers

  • Contract research organizations (CROs)

  • Contract manufacturing organizations (CMOs)

  • Clinical laboratories

  • Food and beverage manufacturers

  • Cosmetics manufacturers

Although not all activities within these industries are regulated, it’s likely that some common activities do require compliance, and that the tools they use are compatible with requirements.

Why 21 CFR Part 11 compliance matters for regulated organizations

Adhering to 21 CFR Part 11 requirements serves a vital role beyond core regulatory alignment.

Compliance ensures the integrity and reliability of the data submitted to the FDA. When these standards are maintained, they build a foundation of trust in an organization’s electronic records, which is critical for patient safety and product quality. Moreover, non-compliance can expose businesses to significant operational risks, including costly delays, warning letters opens in a new tab, or compromised product approvals. 

By maintaining a part 11 compliant system, organizations keep their operations ready for FDA inspections. This readiness helps teams focus on innovation rather than scrambling to verify document histories during an audit.

Ultimately, understanding and applying these guidelines helps companies transition smoothly from paper-based processes to efficient, secure digital workflows.

What 21 CFR Part 11 says about electronic records

The FDA defines an electronic record as any combination of text, graphics, data, or audio created, modified, maintained, or transmitted in digital form. While signatures receive significant focus, CFR Part 11 compliance applies equally to these electronic records themselves. 

To meet the standards of 21 CFR 11, electronic records need to be as trustworthy and reliable as traditional paper records. 

The regulation states that systems used to process these records should employ procedures and controls to protect data authenticity opens in a new tab. This typically involves limiting system access to authorized individuals and ensuring that records can be readily retrieved throughout their required retention period.

Additionally, the FDA expects organizations to implement operational system checks. These checks help ensure that only valid data is entered into the system and that records cannot be altered without authorization.

What are the key requirements of Part 11 for electronic signatures?

The FDA allows electronic signatures to be used in place of pen and ink signatures on paper documents so that business can be conducted digitally. In order to be compliant opens in a new tab, electronic signatures must include: 

  • The printed name of the signer

  • The date and time the signature was executed

  • A unique user ID

  • Digital adopted signature 

  • The meaning of the signature (labeled “signing reason”) 

The FDA also issued a guidance paper, “Part 11, Electronic Records; Electronic Signatures — Scope and Application opens in a new tab,” to provide further clarification on electronic records and electronic signatures.

What are the other requirements for electronic signatures?

Below are the requirements as outlined in subpart C on electronic signatures:

  • Each electronic signature must be unique to one individual and not reused by, or reassigned to, anyone else. Subsection 11.100(a)

  • The identity of the individual must be verified before establishing, assigning, certifying, or otherwise sanctioning the individual’s electronic signature, or any element of such electronic signature. Subsection 11.100(b)

  • Persons using electronic signatures shall, prior to or at the time of such use, certify to the agency that the electronic signatures in their system, used on or after August 20, 1997, are intended to be a legally binding equivalent of traditional handwritten signatures. Subsection 11.100(c)

  • Persons using electronic signatures must, upon agency request, provide additional certification or testimony that a specific electronic signature is the legally binding equivalent of the signer’s handwritten signature. Subsection 11.100(c.2)

  • Electronic signatures that are not based upon biometrics opens in a new tab must employ at least two distinct identification components, such as an identification code and a password. Subsection 11.200 (a)(1) 

  • When an individual executes a series of signings during a single, continuous period of controlled system access, the first signing must be executed using all electronic signature components. Subsequent signings must be executed using at least one electronic signature component that is only executable by, and designed to be used only by, the individual. Subsection 11.200 (a)(1)(i)

  • When an individual executes one or more signings not performed during a single period of controlled system access, each signing must be executed using all of the electronic signature components. Subsection 11.200 (a)(1)(ii)

  • The uniqueness of each combined identification code and password must be maintained such that no two individuals have the same combination of identification code and password. Subsection 11.300(a)

  • Identification code and password issuances must be periodically checked, recalled, or revised (e.g., to cover such events as password aging). Subsection 11.300(b)

  • Loss management procedures must be followed to electronically deauthorize lost, stolen, missing, or otherwise potentially compromised tokens, cards, and other devices that bear or generate identification code or password information. The system must issue temporary or permanent replacements using suitable, rigorous controls. Subsection 11.300(c)

  • The system must use transaction safeguards to prevent unauthorized use of passwords and/or identification codes, and to detect and report in an immediate and urgent manner any attempts at their unauthorized use. Subsection 11.300(d)

  • A procedure must be in place for initial and periodic testing of devices such as tokens or cards that bear or generate identification code or password information to ensure that they function properly and have not been altered in an unauthorized manner. Subsection 11.300(e)

How validation, audit trails, and record retention support 21 CFR Part 11 compliance

Establishing a compliant electronic signature is a critical step, but it operates within a broader framework. To fully align with 21 CFR Part 11, organizations often rely on robust system controls, including validation, audit trails, and strict record retention policies. 

These elements work together to protect the lifecycle of digital agreements.

  • System validation: The FDA expects systems used to create or manage electronic records to be validated to ensure accuracy opens in a new tab, reliability, and consistent intended performance. Validation helps confirm that the software being used works exactly as it should, minimizing the risk of data corruption.

  • Audit trails: Secure, computer-generated, and time-stamped audit trails are a core component. An effective audit trail independently records the date and time of operator entries and actions that create, modify, or delete electronic records. This provides a clear, transparent history of exactly who did what and when.

  • Record retention: Businesses need to protect records to enable their accurate and ready retrieval throughout the required retention period. Proper retention policies ensure that documents remain available for FDA review long after the initial signature is captured.

Docusign’s modules for 21 CFR Part 11 compliance

The Docusign Part 11 module is a product enhancement available for Docusign’s life science customers who may be impacted by the requirements in 21 CFR Part 11. It features capabilities designed for documents and approvals regulated by 21 CFR Part 11, including:

  • Prepackaged account configuration

  • Signature-level credentialing

  • Signature-level meaning (signing reason)

  • Signature manifestation (printed name, date/time, and signing reason)

For more examples of how Docusign solutions help businesses stay compliant, read our complete guide to CFR Part 11 and electronic signatures.

Ready to get therapies and devices to market faster? Read our comprehensive guide to simplifying 21 CFR Part 11 compliance

Related posts

  • Insights for Leaders

    Sensata and Salesforce: Why Agreement Modernization Has to Come Before AI

Docusign IAM is the agreement platform your business needs

Start for FreeExplore Docusign IAM
Person smiling while presenting