What is 21 CFR Part 11?
21 CFR Part 11 is the US FDA regulation that defines the conditions under which electronic records and electronic signatures are considered as trustworthy and legally binding as paper records with a handwritten signature. It applies to every record a company must keep under other FDA requirements, such as batch records in pharmaceutical manufacturing. Because more and more of those records are created in SCADA, DCS, MES and historian systems, Part 11 is one of the most important points where operational technology meets quality regulation in GxP environments.
π§± Who falls under 21 CFR Part 11?
Part 11 does not create a record-keeping obligation of its own. It hooks into the so-called predicate rules: the underlying FDA regulations that state which records and signatures are required, such as 21 CFR 211 for drug GMP and the quality system requirements for medical devices. As soon as you keep such a required record electronically, or sign it electronically, Part 11 applies.
That covers pharmaceutical companies, biotech, medical device manufacturers, laboratories and contract manufacturers. European companies that export to the United States are also assessed against Part 11 by FDA investigators, usually alongside the European requirements. Software vendors are not bound by Part 11 themselves; responsibility lies with the regulated user, who must show that the configured system meets the rule.
π Since when has 21 CFR Part 11 applied?
| Year | Milestone |
|---|---|
| 1997 | Part 11 published on 20 March, effective on 20 August |
| 2003 | Part 11, Scope and Application guidance: narrow interpretation |
| 2011 | Revised EU GMP Annex 11 (computerised systems) in force |
| 2018 | FDA guidance on data integrity in cGMP (December) |
| 2022 | ISPE publishes GAMP 5, Second Edition (July) |
| 2025 | FDA Computer Software Assurance guidance finalised (September); draft revision of Annex 11 (July) |
| 2026 | CSA guidance updated for the new device QMSR (February) |
Part 11 has been in force since 20 August 1997 and its text has not changed since. In the early years it triggered huge validation programmes, with companies treating almost every system as a Part 11 system. In 2003 the FDA corrected course with a narrow interpretation: Part 11 only applies when the electronic record replaces paper or when you rely on it for regulated activities. The FDA also announced enforcement discretion for validation, audit trails, record copies, record retention and legacy systems that were operational before August 1997. The requirements of the predicate rules, however, remain fully in force.
π Which obligations does 21 CFR Part 11 impose?
The core is in section 11.10 (closed systems) and the sections on signatures:
| Requirement | Section | What it means in practice |
|---|---|---|
| Validation | 11.10(a) | Show that the system is accurate and reliable and can detect altered records |
| Copies | 11.10(b) | Provide records in human-readable and electronic form to an investigator |
| Retention | 11.10(c) | Protect records and keep them retrievable for the whole retention period |
| Access limitation | 11.10(d) | Only authorised individuals can access the system |
| Audit trail | 11.10(e) | Secure, computer-generated, time-stamped audit trail; previous values stay visible |
| Operational checks | 11.10(f) | Enforce the permitted sequence of steps and events |
| Authority checks | 11.10(g) | Only authorised users can sign, alter records or operate the system |
| Device checks | 11.10(h) | Verify that input comes from a valid source or terminal |
| Training | 11.10(i) | Developers, administrators and users are demonstrably qualified |
| Accountability | 11.10(j) and (k) | Written signature policy and controlled system documentation |
| Signature components | 11.50, 11.70, 11.200 | Name, date, time and meaning shown; signature linked to its record; at least two components such as user ID and password |
| Unique and certified | 11.100 | Each signature belongs to one person whose identity has been verified; the company certifies to the FDA in writing that e-signatures are legally binding |
| ID and password | 11.300 | Unique combination of user ID and password, periodically reviewed and protected against misuse |
For open systems (section 11.30), where access is not controlled by those responsible for the record content, additional measures such as encryption and digital signatures apply. During a continuous session, one component is sufficient for subsequent signings after the first full signing.
π How does it differ from EU GMP Annex 11?
In Europe, Annex 11 of EudraLex Volume 4 is the counterpart. In practice, the two together determine how computerised systems in pharma are designed.
| Topic | 21 CFR Part 11 | EU GMP Annex 11 (2011) |
|---|---|---|
| Status | US federal regulation | European GMP guideline, enforced through inspections |
| Approach | Detailed technical requirements | Risk-based, lifecycle-oriented |
| Electronic signature | Extensively regulated, certification to the FDA | Brief: same impact as handwritten, linked to the record with date and time |
| Audit trail | For entries and actions that create, modify or delete records | Based on risk assessment for GMP-relevant changes |
| Suppliers | Not explicit | Supplier assessment and formal agreements required |
| Periodic review | Not explicit | Required |
| Cybersecurity | Implicit through access control | 2025 draft revision makes it a core requirement |
In July 2025 the European Commission and PIC/S published a draft revision of Annex 11, together with a revised Chapter 4 (documentation) and a new Annex 22 on artificial intelligence. The draft grows from about 5 to 19 pages, with expanded requirements for audit trail review, identity and access management, patching and security. The consultation closed on 7 October 2025. Until the final version takes effect, the 2011 Annex 11 remains the applicable text.
π§ How do GAMP 5 and CSA relate to Part 11?
Part 11 says that you must validate, not how. That guidance comes from ISPEβs GAMP 5, whose Second Edition appeared in July 2022. It emphasises critical thinking, risk-based effort, support for iterative development and the reuse of supplier documentation.
The FDA continued along the same line in September 2025 with its final Computer Software Assurance (CSA) guidance, updated in February 2026 to align with the new Quality Management System Regulation (QMSR). CSA is formally written for production and quality system software of medical devices, but pharmaceutical companies apply its principles widely: test thoroughly where the impact on patient safety, product quality and data integrity is high, and keep evidence lean where the risk is low. The FDAβs 2018 data integrity guidance adds the ALCOA principles: data must be attributable, legible, contemporaneous, original and accurate.
π How does 21 CFR Part 11 affect OT environments?
In a pharmaceutical plant, GMP records are not created in an office application but in process automation:
- Batch records β batch control systems based on ISA-88 and the MES record recipes, material consumption and process parameters; with an electronic batch record they replace the paper file entirely.
- Setpoint changes β every change to a critical process parameter on an operator station must appear in the audit trail with who, what, when, old and new value and, where required, the reason.
- Historians β when process data are used for batch release or deviation investigations, they are GMP records subject to retention and copy requirements.
- Time synchronisation β time stamps are only meaningful when all systems use a reliable time source, usually via NTP, and users cannot change the system clock.
- Shared accounts β a common βoperatorβ login on an HMI is the classic inspection finding: actions cannot be attributed to one person, which conflicts with 11.10(d) and 11.100.
This is where Part 11 clashes with OT reality: older controllers and panels often do not support individual accounts or audit trails, and patching or revalidating after every change takes time and production windows.
π οΈ How do you make an OT system Part 11 compliant?
- Determine GxP relevance β which data and actions in the system fall under a predicate rule? Record this in a system inventory and data flow diagram.
- Carry out a risk assessment β for each function, assess the impact on product, patient and data in line with GAMP 5 and choose the depth of testing.
- Set up identities β personal accounts, role-based access control following least privilege and integration with a central directory; retire shared accounts.
- Enable and protect the audit trail β record critical setpoint, recipe and alarm changes, make the audit trail tamper-proof and schedule periodic review.
- Synchronise time β one validated time source for controllers, servers and the historian, with monitored drift.
- Configure e-signatures β two components, the meaning of the signature displayed, and for example a second signer for critical changes.
- Validate and document β user requirements, configuration specification, tests and a validation report.
- Maintain the validated state β change management, backups with restore tests, periodic review and training.
β Frequently asked questions
Does 21 CFR Part 11 apply to European companies?
21 CFR Part 11 applies to every company that keeps FDA-regulated records electronically, even if it manufactures outside the United States. A Dutch plant exporting medicines to the US is therefore assessed against Part 11 during an FDA inspection. In practice, European companies combine Part 11 with EU GMP Annex 11.
What is the difference between a closed and an open system in Part 11?
Under 21 CFR Part 11, a closed system is an environment in which access is controlled by the people responsible for the content of the records. In an open system that is not the case, for example when records are exchanged over the internet. For open systems, Part 11 requires extra measures such as encryption and digital signatures.
Is an audit trail mandatory under 21 CFR Part 11?
21 CFR Part 11 requires in section 11.10(e) a secure, time-stamped audit trail for the creation, modification and deletion of electronic records. Since 2003 the FDA has applied enforcement discretion here, but predicate rules and data integrity expectations make an audit trail necessary in almost every case. Inspectors also expect the audit trail to be reviewed regularly.
Can operators use a shared account on an HMI?
No, a shared account is incompatible with 21 CFR Part 11, because actions and signatures can no longer be attributed to a single person. A read-only overview screen without GMP actions can work without a personal login. Changes to setpoints, recipes or releases require individual accounts.
Does Computer Software Assurance replace validation under Part 11?
No, Computer Software Assurance does not replace the validation requirement of 21 CFR Part 11; it describes a more efficient, risk-based way to meet it. CSA focuses testing effort on high-impact functions and accepts less formal evidence where the risk is low. The FDA guidance is written for medical devices, and pharma mainly adopts its principles.
Does a historian need to comply with 21 CFR Part 11?
A historian falls under 21 CFR Part 11 as soon as the stored process data are used for GMP decisions, such as batch release or deviation investigations. Requirements for access control, audit trail, retention and providing copies then apply. If the historian only serves process optimisation, that is usually not the case.
π In summary
Since 1997, 21 CFR Part 11 has defined when the FDA accepts electronic records and signatures as equivalent to paper, which directly affects the SCADA, DCS, MES and historian systems in pharmaceutical manufacturing. Personal accounts, a tamper-proof audit trail, reliable time and risk-based validation following GAMP 5 form the core of a compliant OT system.
