Back to Frameworks

FDA 21 CFR Part 11

United States
v2023
7 domains
13 controls

21 CFR Part 11 (62 FR 13430 March 20 1997) establishes the criteria under which the FDA considers electronic records + electronic signatures to be trustworthy + reliable + equivalent to paper records + handwritten signatures. The regulation applies to ALL electronic records + signatures created + modified + maintained + archived + retrieved + transmitted under any records requirement set forth in any FDA regulation or any electronic records submitted to FDA under the Federal Food + Drug + and Cosmetic Act + Public Health Service Act + Tobacco Control Act. STRUCTURE - 3 Subparts: SUBPART A General Provisions (§11.1 scope + §11.2 implementation + §11.3 definitions); SUBPART B Electronic Records (§11.10 controls for closed systems + §11.30 controls for open systems + §11.50 signature manifestations + §11.70 signature / record linking); SUBPART C Electronic Signatures (§11.100 general requirements + §11.200 signature components + controls + §11.300 controls for identification codes + passwords). Risk-based implementation: per the August 2003 FDA Scope and Application Guidance the agency intends to exercise enforcement discretion regarding specific Part 11 requirements + apply Part 11 requirements based on risk + criticality + intended use. Computer System Validation (CSV) under Part 11 + the GAMP 5 framework + ICH Q9 risk + ICH Q10 PQS coordinate to operationalise the regulation. The 2023 FDA Computer Software Assurance (CSA) draft guidance + the related FDA Software Bill of Materials (SBOM) expectations modernise the validation approach for medical device software + production software. Part 11 is the US counterpart to EU GMP Annex 11 (which covers computerised systems in GMP-regulated pharmaceutical manufacturing) + EMA Q&A on Annex 11 + the EU Medical Device Regulation (MDR) + In Vitro Diagnostic Regulation (IVDR) digital records provisions. Part 11 enforcement examples include FDA warning letters citing inadequate audit trails + lack of validation + electronic-signature controls failures + closed-system control deficiencies in pharmaceutical manufacturing sites + clinical trial sponsors + medical device manufacturers + contract research organisations (CROs).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

21 CFR Part 11 - Implementation, Guidance, Risk-Based Approach and Status

1 controls
Controls in the 21 CFR Part 11 - Implementation, Guidance, Risk-Based Approach and Status domain of FDA 21 CFR Part 111 controls
CodeTitle
Part11.Status21 CFR Part 11 - corpus status, FDA enforcement landscape, CSA transition

21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f))

4 controls
Controls in the 21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f)) domain of FDA 21 CFR Part 114 controls
CodeTitle
Part11.AccessAndAuthAccess control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))
Part11.AuditTrailAudit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
Part11.CSVComputer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
Part11.RecordRetentionRecord protection + retention + readiness for inspection (21 CFR §11.10(b) + (c))

21 CFR Part 11 Subpart A - General Provisions (Scope, Implementation, Definitions)

2 controls
Controls in the 21 CFR Part 11 Subpart A - General Provisions (Scope, Implementation, Definitions) domain of FDA 21 CFR Part 112 controls
CodeTitle
Part11.DefinitionsDefinitions (21 CFR §11.3)
Part11.ScopeScope and implementation (21 CFR §§11.1-11.2)

21 CFR Part 11 Subpart B - Electronic Records (§11.10 Closed Systems)

1 controls
Controls in the 21 CFR Part 11 Subpart B - Electronic Records (§11.10 Closed Systems) domain of FDA 21 CFR Part 111 controls
CodeTitle
Part11.10Controls for closed systems (21 CFR §11.10)

21 CFR Part 11 Subpart B - Electronic Records (§11.30 Open Systems, §11.50 + §11.70 Signature Manifestations and Linking)

2 controls
Controls in the 21 CFR Part 11 Subpart B - Electronic Records (§11.30 Open Systems, §11.50 + §11.70 Signature Manifestations and Linking) domain of FDA 21 CFR Part 112 controls
CodeTitle
Part11.30Controls for open systems (21 CFR §11.30)
Part11.50_70Signature manifestations + signature / record linking (21 CFR §§11.50 + 11.70)

21 CFR Part 11 Subpart C - Electronic Signatures (§11.100 General Requirements)

1 controls
Controls in the 21 CFR Part 11 Subpart C - Electronic Signatures (§11.100 General Requirements) domain of FDA 21 CFR Part 111 controls
CodeTitle
Part11.100Electronic signatures - general requirements (21 CFR §11.100)

21 CFR Part 11 Subpart C - Electronic Signatures (§11.200 + §11.300 Components, Controls, ID Codes and Passwords)

2 controls
Controls in the 21 CFR Part 11 Subpart C - Electronic Signatures (§11.200 + §11.300 Components, Controls, ID Codes and Passwords) domain of FDA 21 CFR Part 112 controls
CodeTitle
Part11.200Electronic signature components and controls (21 CFR §11.200)
Part11.300Controls for identification codes and passwords (21 CFR §11.300)

Your Compliance Coverage

If you comply with FDA 21 CFR Part 11, you already cover:

Maps to 86 other frameworks

13 total controls
Annex 11 to EU GMP - Computerised Systems
9 source controls mapped|13 target controls covered
69%
Azure Security Benchmark
6 source controls mapped|7 target controls covered
46%
AWS Well-Architected Security Pillar
6 source controls mapped|7 target controls covered
46%
ASD Strategies to Mitigate Cyber Security Incidents
6 source controls mapped|6 target controls covered
46%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
6 source controls mapped|8 target controls covered
46%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
5 source controls mapped|2 target controls covered
38%
Privacy Act 1988 (Australia)
5 source controls mapped|3 target controls covered
38%
Ley Orgánica de Protección de Datos Personales (LOPDP)
5 source controls mapped|2 target controls covered
38%
Law No. 172-13 on the Protection of Personal Data
5 source controls mapped|2 target controls covered
38%
India DPDP Act
5 source controls mapped|3 target controls covered
38%
BSI IT-Grundschutz
5 source controls mapped|11 target controls covered
38%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
5 source controls mapped|7 target controls covered
38%
APPI
5 source controls mapped|4 target controls covered
38%
Bahrain PDPL
5 source controls mapped|4 target controls covered
38%
ISO/IEC 27400:2022
5 source controls mapped|4 target controls covered
38%
ISO/IEC 27011:2024
5 source controls mapped|7 target controls covered
38%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
4 source controls mapped|1 target controls covered
31%
HKMA Cyber Resilience Assessment Framework (C-RAF)
4 source controls mapped|2 target controls covered
31%
31%
FDA Quality Management System Regulation (QMSR)
4 source controls mapped|3 target controls covered
31%
Barbados Data Protection Act 2019
4 source controls mapped|3 target controls covered
31%
OWASP Top 10:2025
4 source controls mapped|6 target controls covered
31%
OWASP DevSecOps Maturity Model (DSOMM)
4 source controls mapped|3 target controls covered
31%
OWASP ASVS
4 source controls mapped|5 target controls covered
31%
MITRE D3FEND
4 source controls mapped|2 target controls covered
31%
Russia Federal Law on Personal Data (152-FZ)
4 source controls mapped|2 target controls covered
31%
FBI CJIS Security Policy
3 source controls mapped|5 target controls covered
23%
OWASP API Security Top 10 - 2023
3 source controls mapped|4 target controls covered
23%
ISO/IEC 27010:2015
3 source controls mapped|4 target controls covered
23%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|3 target controls covered
23%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|5 target controls covered
23%
Azerbaijan Law on Personal Data (2010)
3 source controls mapped|2 target controls covered
23%
Pakistan Personal Data Protection Bill 2023
3 source controls mapped|2 target controls covered
23%
Law on Personal Data Protection (Official Gazette No. 42/2020)
3 source controls mapped|1 target controls covered
23%
ICH E6(R3) - Good Clinical Practice
3 source controls mapped|2 target controls covered
23%
Georgia Law on Personal Data Protection (2012)
3 source controls mapped|1 target controls covered
23%
23%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
3 source controls mapped|3 target controls covered
23%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|1 target controls covered
15%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|3 target controls covered
15%
API 1164
2 source controls mapped|4 target controls covered
15%
AML/CTF Act 2006 (Australia)
2 source controls mapped|2 target controls covered
15%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
2 source controls mapped|1 target controls covered
15%
Protective Security Policy Framework (PSPF) Release 2024
2 source controls mapped|2 target controls covered
15%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|2 target controls covered
15%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|2 target controls covered
15%
ISO 19011
2 source controls mapped|4 target controls covered
15%
15%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|4 target controls covered
15%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|4 target controls covered
15%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
8%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
8%
South Korea PIPA
1 source controls mapped|1 target controls covered
8%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
8%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
8%
NIST AI Risk Management Framework (AI RMF 1.0)
1 source controls mapped|2 target controls covered
8%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
8%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
8%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
8%
MiFID II / MiFIR
1 source controls mapped|1 target controls covered
8%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
8%
NIST SP 800-171
1 source controls mapped|1 target controls covered
8%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|1 target controls covered
8%
Aged Care Quality Standards (Australia)
1 source controls mapped|1 target controls covered
8%
ISO 31000:2018
1 source controls mapped|2 target controls covered
8%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
1 source controls mapped|1 target controls covered
8%
ISO 27005
1 source controls mapped|1 target controls covered
8%
ISO 20000-1
1 source controls mapped|1 target controls covered
8%
APRA CPS 234
1 source controls mapped|1 target controls covered
8%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
8%
Tennessee Information Protection Act (TIPA)
1 source controls mapped|1 target controls covered
8%
TEFCA - Trusted Exchange Framework and Common Agreement
1 source controls mapped|1 target controls covered
8%
SWIFT CSCF
1 source controls mapped|1 target controls covered
8%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
8%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|2 target controls covered
8%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|1 target controls covered
8%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
8%
ISO 13485
1 source controls mapped|1 target controls covered
8%

Frequently Asked Questions

What is FDA 21 CFR Part 11?

FDA 21 CFR Part 11 is a compliance framework from United States with 7 domains and 13 controls. 21 CFR Part 11 (62 FR 13430 March 20 1997) establishes the criteria under which the FDA considers electronic records + electronic signatures to be trustworthy + reliable + equivalent to paper records + handwritten signatures. The regulation applies to ALL electronic records + signatures created + modified + maintained + archived + retrieved + transmitted under any records requirement set forth in any FDA regulation or any electronic records submitted to FDA under the Federal Food + Drug + and Cosmetic Act + Public Health Service Act + Tobacco Control Act. STRUCTURE - 3 Subparts: SUBPART A General Provisions (§11.1 scope + §11.2 implementation + §11.3 definitions); SUBPART B Electronic Records (§11.10 controls for closed systems + §11.30 controls for open systems + §11.50 signature manifestations + §11.70 signature / record linking); SUBPART C Electronic Signatures (§11.100 general requirements + §11.200 signature components + controls + §11.300 controls for identification codes + passwords). Risk-based implementation: per the August 2003 FDA Scope and Application Guidance the agency intends to exercise enforcement discretion regarding specific Part 11 requirements + apply Part 11 requirements based on risk + criticality + intended use. Computer System Validation (CSV) under Part 11 + the GAMP 5 framework + ICH Q9 risk + ICH Q10 PQS coordinate to operationalise the regulation. The 2023 FDA Computer Software Assurance (CSA) draft guidance + the related FDA Software Bill of Materials (SBOM) expectations modernise the validation approach for medical device software + production software. Part 11 is the US counterpart to EU GMP Annex 11 (which covers computerised systems in GMP-regulated pharmaceutical manufacturing) + EMA Q&A on Annex 11 + the EU Medical Device Regulation (MDR) + In Vitro Diagnostic Regulation (IVDR) digital records provisions. Part 11 enforcement examples include FDA warning letters citing inadequate audit trails + lack of validation + electronic-signature controls failures + closed-system control deficiencies in pharmaceutical manufacturing sites + clinical trial sponsors + medical device manufacturers + contract research organisations (CROs). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does FDA 21 CFR Part 11 have?

FDA 21 CFR Part 11 has 13 controls organised across 7 domains. The largest domains are 21 CFR Part 11 - Validation, Audit Trail, Operational Controls (§11.10(a) + (e) + (f)) (4 controls), 21 CFR Part 11 Subpart A - General Provisions (Scope, Implementation, Definitions) (2 controls), 21 CFR Part 11 Subpart B - Electronic Records (§11.30 Open Systems, §11.50 + §11.70 Signature Manifestations and Linking) (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does FDA 21 CFR Part 11 map to?

FDA 21 CFR Part 11 maps to 86 other compliance frameworks. The top mapping partners are Annex 11 to EU GMP - Computerised Systems (69% coverage), AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (54% coverage), Azure Security Benchmark (46% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with FDA 21 CFR Part 11 compliance?

Start your FDA 21 CFR Part 11 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FDA 21 CFR Part 11 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 13 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required