Short answer: Part 11 does not require a particular product. It requires a set of controls: validated systems, secure time-stamped audit trails, access limits, signatures that show the signer's printed name, the date and time, and the meaning of the signing, and signatures bound to their records so they can't be cut and pasted. Non-biometric signatures need two distinct components — typically an ID and a password. And once, before you first use electronic signatures, you certify to the FDA in writing that they are the legally binding equivalent of handwritten ones. A small company can meet all of that with modest tooling and disciplined procedures.
If your Quality Management System keeps any record electronically — and almost every startup's does — you are already inside 21 CFR Part 111. The QMSR requires controlled records2 with approvals and dates behind them (see our QMSR checklist), and once those records move off paper, Part 11 decides whether a signature on them means anything to an investigator. Founders picture a procurement decision — which eQMS, which vendor. That's the wrong first question: Part 11 is a list of controls a system and a company satisfy together, not something a vendor sells you.
This guide covers what the rule actually requires, what a company of five can realistically do to meet it, and the one filing almost everyone forgets — a one-page letter to FDA that costs nothing.
The one thing to internalize: Part 11 regulates controls, not vendors
There is no such thing as "FDA Part 11 certified" software. FDA does not certify, approve, or endorse any electronic-records or electronic-signature product — its guidance on Part 11 scope and application3 describes how the agency evaluates records and signatures, not a seal it hands vendors. A platform can ship with the right raw features and still fail Part 11 in your hands if you don't configure and use it correctly. Compliance is a property of your implementation, not a line on a vendor's page — the honest answer to "is this tool compliant" is always: for what, configured how, used by whom. See our FAQ for more.
What the rule actually says
Six sections matter here. None is long, and none requires proprietary software — but skipping any one is a real audit finding.
§ 11.10 — Controls for closed systems
For a closed system, which describes nearly every startup's document system, § 11.104 requires: validation that the system works as intended; accurate copies for FDA on request; retrieval that stays intact for your full retention period; access limited to authorized people; a secure, time-stamped audit trail that never obscures the original entry; enforced step sequencing; trained users; and written accountability for one's own signature.
§ 11.50 — Signature manifestations
Every signed record must show, as part of the signature itself, the signer's printed name, date and time, and meaning5 — approved, reviewed, authored — carried into any human-readable form. A name and a checkmark isn't enough.
§ 11.70 — Signature/record linking
§ 11.706 requires a signature be linked to its record so it can't be excised or copied to falsify a different one — why a scanned signature pasted into a PDF fails outright.
§ 11.100 — Uniqueness, identity, and the certification you owe FDA
§ 11.1007 requires each signature be unique to one individual, never reused, and that you verify identity before issuing it. It also contains the one-time certification requirement covered next.
§ 11.200 — Two distinct components
For anything other than a biometric signature, § 11.2008 requires at least two distinct components — typically an ID and a password; all components on the first signing of a continuous session, at least one thereafter. Misusing someone's signature must take the collusion of two or more people — exactly what a shared login defeats.
§ 11.300 — ID and password controls
§ 11.3009 covers credentials: unique combinations, periodic review, procedures for lost or compromised credentials, and periodic testing of any device that generates a code.
The certification letter almost everyone forgets
Before you use electronic signatures for the first time — not after — § 11.100(c)7 requires you to certify to FDA, in writing with a handwritten signature, that your electronic signatures are the legally binding equivalent of handwritten ones. The mechanics live on FDA's Letters of Non-Repudiation Agreement10 page.
This is the cheapest item on this whole list. One page, no cost, and startups skip it constantly — not because it's hard, but because nobody on a five-person team knows it exists until an investigator asks for it.
What "validated" means when you have no validation team
§ 11.10(a) requires validation, a word that scares founders more than anything else in Part 11. It doesn't have to. FDA's Computer Software Assurance for Production and Quality Management System Software11 guidance (final, February 2026; also a PDF) frames how much testing rigor software needs, and supplements General Principles of Software Validation12, superseding that document's section 6 for this software. (It in turn supersedes FDA's earlier "Computer Software Assurance for Production and Quality System Software" guidance, issued September 2025.)
Effort scales with risk: A low-risk feature can reasonably be covered with unscripted testing a competent user documents as they go; a feature controlling a signature workflow deserves more. Either way, FDA wants evidence of what you tested and why it matched the risk — that record, not a binder of scripted test cases, is what "validated" means at your size.
A Part 11 checklist you can actually work through
| Requirement | Section | What "done" looks like |
|---|---|---|
| System validation | § 11.10(a) | A written record of what you tested, when, and why. |
| Copies for FDA | § 11.10(b) | You can export a clean, human-readable and electronic copy on request. |
| Record retrieval | § 11.10(c) | Old records stay retrievable for your full retention period. |
| Access limits | § 11.10(d) | Every account is named to one person; no shared logins. |
| Audit trail | § 11.10(e) | Every action is time-stamped; the original entry stays visible after a change. |
| Sequence & authority checks | § 11.10(f)–(g) | A document can't be "approved" before it's been reviewed. |
| Trained users, accountability | § 11.10(i), (j) | Signers are trained and have accepted accountability in writing. |
| Manifestation & linking | § 11.50, § 11.70 | Every signature shows name, date/time, meaning, and can't be copied onto another record. |
| Identity & certification | § 11.100 | Identity verified before issuing a login; the certification letter has been filed. |
| Two-component & credentials | § 11.200, § 11.300 | No shared logins; passwords reviewed and revoked when someone leaves. |
Where startups actually fail
- The audit trail is off, or editable. Fails § 11.10(e) outright, no matter how good the rest looks.
- Logins are shared. Collapses the two-component rule and identity verification in one move.
- A signature is a picture, not a signature. A pasted image has none of the linking or manifestation properties § 11.50 and § 11.70 require.
- Nobody wrote down what a signature means. "Approved" versus "reviewed" is ambiguous the moment it's challenged.
- Identity was never verified before a login and signature were issued.
- The certification letter was never sent.
- The system was "validated" once, at go-live, and never revisited after a later update.
Doing this without enterprise software
None of the six sections above require a six-figure eQMS. What they require is a system — however modest — with these capabilities used correctly: access tied to named individuals, an audit trail nobody can quietly disable, a signature workflow that captures a name, date/time, and meaning, and records you can reliably retrieve for your full retention period. General-purpose cloud tools plus disciplined procedures satisfy every one of those at a fraction of enterprise pricing; see our QMS cost breakdown — the same territory covered under Virtual QMS implementation and document control.
Whatever you build on, an investigator wants the same thing regardless of vendor: the record, who signed it and when, and the audit trail behind it. Keep records portable as you grow — Part 11 doesn't care what tool you started on, and neither does an inspector, as long as what you show them today satisfies the rule.
Not sure your signatures would hold up?
Bring your current document-approval flow to a free 30-minute consultation and we'll walk it against Part 11.
Book a Free Part 11 ReviewSources
- Electronic Code of Federal Regulations. 21 CFR Part 11 — Electronic Records; Electronic Signatures. Accessed August 27, 2026.
- Electronic Code of Federal Regulations. 21 CFR 820.35 — Control of records. Accessed August 27, 2026.
- U.S. Food and Drug Administration. Part 11, Electronic Records; Electronic Signatures — Scope and Application. Accessed August 27, 2026.
- Electronic Code of Federal Regulations. 21 CFR 11.10 — Controls for closed systems. Accessed August 27, 2026.
- Electronic Code of Federal Regulations. 21 CFR 11.50 — Signature manifestations. Accessed August 27, 2026.
- Electronic Code of Federal Regulations. 21 CFR 11.70 — Signature/record linking. Accessed August 27, 2026.
- Electronic Code of Federal Regulations. 21 CFR 11.100 — General requirements. Accessed August 27, 2026.
- Electronic Code of Federal Regulations. 21 CFR 11.200 — Electronic signature components and controls. Accessed August 27, 2026.
- Electronic Code of Federal Regulations. 21 CFR 11.300 — Controls for identification codes/passwords. Accessed August 27, 2026.
- U.S. Food and Drug Administration. Letters of Non-Repudiation Agreement. Accessed August 27, 2026.
- U.S. Food and Drug Administration. Computer Software Assurance for Production and Quality Management System Software. Accessed August 27, 2026.
- U.S. Food and Drug Administration. General Principles of Software Validation. Accessed August 27, 2026.
All sources are US federal primary sources (eCFR, the Federal Register, FDA.gov, or the US Code). Regulatory text changes — check the linked source for the current version before relying on it.
Related reading: The FDA QMSR 10-point compliance checklist · How much does a QMS cost for a medical device startup? · Virtual QMS FAQ