Part 11 compliance,
mapped clause by clause.
"21 CFR Part 11 compliant" is a claim every vendor makes. ValiCore maps every requirement — §11.10(e)'s audit trail, Subpart C's electronic signatures — to a specific, demonstrable feature, so the claim is checkable, not marketing copy.
What is 21 CFR Part 11?
21 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures for FDA-regulated industries, codified at eCFR Title 21, Chapter I, Subchapter A, Part 11. Its core requirements: §11.10(e) requires a secure, computer-generated, time-stamped audit trail that independently records every action that creates, modifies, or deletes an electronic record — and that trail can never obscure previously recorded information. Subpart C governs electronic signatures specifically — each must be unique to one individual, non-reusable, linked permanently to its record, and must capture the signer's printed name, the date and time, and the meaning of the signature (e.g., "approved," "reviewed").
Built for
What goes wrong without it
Shared logins — the most common finding
Shared login credentials are the single most frequently cited ALCOA+ violation in FDA 483 observations. A shared account makes Subpart C's "unique to one individual" requirement structurally impossible to satisfy.
Audit trail exists but can be edited
A log table that a database administrator can quietly modify isn't a Part 11 audit trail — §11.10(e) specifically requires that the trail cannot obscure previously recorded information, which means it has to be tamper-evident, not just present.
"Approved via email" isn't an e-signature
An email reply saying "approved" doesn't meet Subpart C's requirements — no captured signature meaning tied cryptographically to the record, no non-repudiation, no controlled binding between signer and signed content.
What ValiCore actually does here
Hash-chained, tamper-evident audit trail
Every record creation, modification, and deletion is logged with a hash that incorporates the prior entry's hash — verifiable, not just claimed.
§11.10(e)Individual electronic signatures
Every signature captures the signer's identity, timestamp, and meaning — bound to the specific record, never reusable or reassignable.
Subpart C · §11.50, §11.70Password re-authentication at signature
Signing a record requires re-entering your password at that moment — proving it's really you, not a session left open on someone else's screen.
§11.200(a)(1)Role-based access control
Every user's access is scoped to their role — VIEWER, USER, ADMIN — with write actions blocked for roles that shouldn't have them.
§11.10(d)Failed sign-in lockout & session controls
Account lockout after repeated failed attempts, configurable session timeout — closing the access-control gaps §11.10(d) expects.
Chain verification on demand
A built-in tool re-derives the audit chain and reports its integrity status — exportable as evidence for an FDA inspector, not just an internal claim.
Regulations this addresses
Related modules
Frequently asked questions
Under Subpart C, an electronic signature must be unique to one individual and never reused or reassigned to anyone else, permanently linked to its associated record, and must include the printed name of the signer, the date and time of signing, and the meaning of the signature (e.g., "reviewed by," "approved by"). For non-biometric signatures, §11.200(a)(1) additionally requires two distinct identification components — typically an ongoing session plus a fresh password re-entry at the moment of signing.
Both govern electronic records and signatures in regulated industries, and share the same core intent — audit trails, access control, e-signatures — but Annex 11 (EU GMP) tends to place more explicit emphasis on risk management and system validation documentation, while Part 11 is more narrowly focused on the record/signature controls themselves. In practice, a system built to satisfy Part 11's audit-trail and e-signature requirements is very close to also satisfying Annex 11's equivalent expectations.
A normal application log records events for debugging or operational purposes and is typically mutable — a developer or admin can edit or delete entries with no trace. A Part 11 audit trail must be tamper-evident (any alteration is independently detectable), must never obscure the original recorded information even when a record is later changed, and must be retained for at least as long as the underlying record and available for regulatory review.
See ValiCore
live in your lab.
Book a free 30-minute demo. We’ll walk through the modules your team will use, answer your compliance questions, and give you a clear picture of what implementation looks like for your lab.
Book your free demo
30 minutes. No credit card. We’ll respond within 4 business hours with a calendar invite tailored to your time zone.
Book my free demo35 working modules · Founder-led onboarding · 14-day go-live guarantee