
Electronic signatures are not a new concept, especially in today’s increasingly digital world. In the medical device manufacturing industry, e-signatures are digitalized versions of hand-written signatures used to signify the agreement or approval on certifications and documents. In this blog, we will explore their importance in the US FDA 21 CFR Part 11 compliance.
What is 21 CFR Part 11?
21 CFR Part 11 is a regulation under Title 21 of the Code of Federal Regulations that sets the standards for electronic records and electronic signatures in FDA-regulated industries. At its core, Part 11 ensures that electronic documentation is trustworthy, reliable, and equivalent to paper records..
Applications of 21 CFR Part 11
It applies to electronic records that are:
- Created,
- Modified,
- Maintained,
- Retrieved,
- Transmitted,
- Archived, or
- Submitted
in compliance with FDA record-keeping requirements.
Organizations that Must Show Compliance with 21 CFR Part 11
21 CFR Part 11 applies to industries and organizations that handle FDA-regulated electronic records and signatures. Key sectors include:
- Medical device manufacturers
- Clinical laboratories
- Biotechnology companies
- Pharmaceutical companies
- Contract Manufacturing Organizations
- Contract Research Organization
- Cosmetic manufacturers
- Food and beverage manufacturers
Requirements of 21 CFR Part 11 for Electronic Signatures
For organizations, it is important to show compliance with all parts of the 21 CFR. However, keeping the context of this blog in mind, we will only discuss why it is essential for them to become compliant with 21 CFR Part 11. Actually, Part 11 established strict standards to ensure the security, integrity, and authenticity of electronic signatures and records used by the aforementioned FDA-regulated industries.
Before learning about the requirements of 21 CFR Part 11, it is crucial to know that on paper documents, electronic signatures are legally equivalent to traditional pen-and-ink signatures, but they must meet specific requirements to be valid..
For full compliance, electronic signatures must include:
- Printed name of the signer
- Digitally captured signature
- Date and timestamp of signing
- Unique user identification (e.g., username or ID)
- Meaning of the signature (purpose of the signature, also known as the signing reason)
Further clarification on the requirements of electronic signatures and records can be found in FDA’s guidance document“Part 11, Electronic Records; Electronic Signatures -Scope and Application.”
Requirements for Electronic Signatures Under subpart C of 21 CFR Part 11
Subpart C of 21 CFR Part 11 outlines critical requirements for electronic signatures in FDA-regulated industries. Below are the key provisions:
Subsection 11.100–General Requirements subsection 11.100(a)–Uniqueness of the Signature
Each electronic signature must be unique to an individual and not be reassigned to anyone else (or reused by anyone else).
Subsection 11.100(b) –Verifying Identity of the Individuals
Before establishment, assigning, certification, or sanctioning an individual’s electronic signature (or any of its elements), the identity of that individual must be verified.
Subsection 11.100(c) – Electronic Signatures as Legally Binding Equivalent of Handwritten Signatures
A person using their electrical signature shall certify to their agency that on or after 20th August 1997, the electronic signatures within their system are used as a legally binding equivalent of their conventional handwritten signature. They shall certify this before (or at the time of) using the electronic signature.
Subsection 11.100(c.2) – Provision of Additional Certification
Upon agency request, a person using the electronic signature shall provides additional testimony or certification to denote that a given electronic signature is the legally binding equivalent of the signer’s handwritten signature.
Subsection 11.200 – Electronic Signature Components & Controls
Subsection 11.200(a)(1) – Identification Code and Password
Electronic signatures not based on biometrics must have at least two identification components (e.g. a password and an identification code).
Subsection 11.200(a)(1)(i) – Signing During a Single Continuous Period of Control Access
If someone executes a series of signings during a single, continuous period of controlled system access, their first signing should be executed via all-electrical signature components. Subsequent signings shall be executed using at least one electronic signature component that:
- can only be executed by the individual, and
- is used only by the individual
Subsection 11.200(a)(1)(ii) – Signing without the Constraints of a Single Continuous Period of Control Access
If someone executes one or more signings(but not during a single period of controlled system access), each signing must be done by using all electronic signature components.
Subsection 11.300 – Controls for identification codes/passwords.
Subsection 11.300(a) – Maintaining the Uniqueness of the Combined Identification Code and Password
It is mandatory to ensure that no two individuals share the same combination of password and identification code.
Subsection 11.300 (b) – Periodical Checking of Identification Code and Password
To prevent events like password ageing, password issuances and identification codes must be regularly checked, revised, or recalled.
Subsection 11.300(c) – Requirements for Loss Management Procedures
For the electronic deauthorization of stolen, lost, missing, or potentially compromised tokens, cards, and other devices carrying password-related information or generating identification code, loss management procedures should be carried out. The system must also issue permanent or temporary replacements via rigorous and suitable controls.
Subsection 11.300(d)–Use of Transaction Safeguards
Transaction safeguards must be used by the system so that passwords or identification codes cannot be used for unauthorized purposes. Such a system would also be used for detection and reporting of any immediate or urgent attempts at their unauthorized use of the system security unit, and to organizational management.
Subsection 11.300(e) – Testing of Devices.
A procedure should be established to initially and periodically test the devices (e.g., cards or tokens having password information or those generating identification codes). This system will ensure proper functioning of these devices and have not been altered in an unauthorized manner.
At TSQ&E, we help our life science customers who want to become compliant with requirements of 21 CFR Part 11.
- Our services regarding electronic signatures include: Signing reason
- Pre-configured account setup
- Signature manifestation (signing reason, date, timestamp, printed name)
- Signature-level credentialing
By using TSQ&E’s guide to electronic signature, medical device manufacturers and other establishments entering the U.S. market can meet all FDA regulatory requirements efficiently. To learn more about our e-signature guide.




















