bg-left bg-right

Compliance with Electronic Signatures 21 CFR Part 11

background
user-icon 17 Apr 2025

Electronic signatures are not a new concept, especially in today’s increasingly digital world. In the medical device manufacturing industry, e-signatures are digitalized versions of hand-written signatures used to signify the agreement or approval on certifications and documents. In this blog, we will explore their importance in the US FDA 21 CFR Part 11 compliance.

What is 21 CFR Part 11?

21 CFR Part 11 is a regulation under Title 21 of the Code of Federal Regulations that sets the standards for electronic records and electronic signatures in FDA-regulated industries. At its core, Part 11 ensures that electronic documentation is trustworthy, reliable, and equivalent to paper records..

Applications of 21 CFR Part 11

It applies to electronic records that are:

  • Created,
  • Modified,
  • Maintained,
  • Retrieved,
  • Transmitted,
  • Archived, or
  • Submitted

in compliance with FDA record-keeping requirements.

Organizations that Must Show Compliance with 21 CFR Part 11

21 CFR Part 11 applies to industries and organizations that handle FDA-regulated electronic records and signatures. Key sectors include:

  • Medical device manufacturers
  • Clinical laboratories
  • Biotechnology companies
  • Pharmaceutical companies
  • Contract Manufacturing Organizations
  • Contract Research Organization
  • Cosmetic manufacturers
  • Food and beverage manufacturers

Requirements of 21 CFR Part 11 for Electronic Signatures

For organizations, it is important to show compliance with all parts of the 21 CFR. However, keeping the context of this blog in mind, we will only discuss why it is essential for them to become compliant with 21 CFR Part 11. Actually, Part 11 established strict standards to ensure the security, integrity, and authenticity of electronic signatures and records used by the aforementioned FDA-regulated industries.

Before learning about the requirements of 21 CFR Part 11, it is crucial to know that on paper documents, electronic signatures are legally equivalent to traditional pen-and-ink signatures, but they must meet specific requirements to be valid..

For full compliance, electronic signatures must include:

  • Printed name of the signer
  • Digitally captured signature
  • Date and timestamp of signing
  • Unique user identification (e.g., username or ID)
  • Meaning of the signature (purpose of the signature, also known as the signing reason)

Further clarification on the requirements of electronic signatures and records can be found in FDA’s guidance document“Part 11, Electronic Records; Electronic Signatures -Scope and Application.”

Requirements for Electronic Signatures Under subpart C of 21 CFR Part 11

Subpart C of 21 CFR Part 11 outlines critical requirements for electronic signatures in FDA-regulated industries. Below are the key provisions:

Subsection 11.100–General Requirements subsection 11.100(a)–Uniqueness of the Signature

Each electronic signature must be unique to an individual and not be reassigned to anyone else (or reused by anyone else).

Subsection 11.100(b) –Verifying Identity of the Individuals

Before establishment, assigning, certification, or sanctioning an individual’s electronic signature (or any of its elements), the identity of that individual must be verified.

Subsection 11.100(c) – Electronic Signatures as Legally Binding Equivalent of Handwritten Signatures

A person using their electrical signature shall certify to their agency that on or after 20th August 1997, the electronic signatures within their system are used as a legally binding equivalent of their conventional handwritten signature. They shall certify this before (or at the time of) using the electronic signature.

Subsection 11.100(c.2) – Provision of Additional Certification

Upon agency request, a person using the electronic signature shall provides additional testimony or certification to denote that a given electronic signature is the legally binding equivalent of the signer’s handwritten signature.

Subsection 11.200 – Electronic Signature Components & Controls

Subsection 11.200(a)(1) – Identification Code and Password

Electronic signatures not based on biometrics must have at least two identification components (e.g. a password and an identification code).

Subsection 11.200(a)(1)(i) – Signing During a Single Continuous Period of Control Access

If someone executes a series of signings during a single, continuous period of controlled system access, their first signing should be executed via all-electrical signature components. Subsequent signings shall be executed using at least one electronic signature component that:

  • can only be executed by the individual, and
  • is used only by the individual
Subsection 11.200(a)(1)(ii) – Signing without the Constraints of a Single Continuous Period of Control Access

If someone executes one or more signings(but not during a single period of controlled system access), each signing must be done by using all electronic signature components.

Subsection 11.300 – Controls for identification codes/passwords.

Subsection 11.300(a) – Maintaining the Uniqueness of the Combined Identification Code and Password

It is mandatory to ensure that no two individuals share the same combination of password and identification code.

Subsection 11.300 (b) – Periodical Checking of Identification Code and Password

To prevent events like password ageing, password issuances and identification codes must be regularly checked, revised, or recalled.

Subsection 11.300(c) – Requirements for Loss Management Procedures

For the electronic deauthorization of stolen, lost, missing, or potentially compromised tokens, cards, and other devices carrying password-related information or generating identification code, loss management procedures should be carried out. The system must also issue permanent or temporary replacements via rigorous and suitable controls.

Subsection 11.300(d)–Use of Transaction Safeguards

Transaction safeguards must be used by the system so that passwords or identification codes cannot be used for unauthorized purposes. Such a system would also be used for detection and reporting of any immediate or urgent attempts at their unauthorized use of the system security unit, and to organizational management.

Subsection 11.300(e) – Testing of Devices.

A procedure should be established to initially and periodically test the devices (e.g., cards or tokens having password information or those generating identification codes). This system will ensure proper functioning of these devices and have not been altered in an unauthorized manner.

At TSQ&E, we help our life science customers who want to become compliant with requirements of 21 CFR Part 11.

  • Our services regarding electronic signatures include: Signing reason
  • Pre-configured account setup
  • Signature manifestation (signing reason, date, timestamp, printed name)
  • Signature-level credentialing

By using TSQ&E’s guide to electronic signature, medical device manufacturers and other establishments entering the U.S. market can meet all FDA regulatory requirements efficiently. To learn more about our e-signature guide.

About the author:
Waqas Imam

S. M. Waqas Imam is associated with TS Quality as a Regional Partner. He is also an ambassador of Medical Device Community. He is an Industrial Engineer by qualification and served the manufacturing industry since 2011. He is also IRCA CQI Lead Auditor of ISO 9001 and other management system standards. He had served as Quality Assurance and Regulatory Affairs Manager in QSA Surgical Pvt. Ltd. and Ultimate Medical Products. He managed requirements of ISO 13485:2003, EU directives, CE marking and FDA. He also served as Expert Blog Writer for 13485Academy and wrote expert articles on various topics of ISO 13485:2016.

Tags

MDR Guidelines

Worldwide regulation resources

Latest News

Contact us / Ask a quote now

We will help You find the right solution for Your Projects

CONTACT US

SOME OF OUR CLIENTS