
A 90-day password change is not a 21 CFR Part 11 requirement. Neither is a prescribed password length or complexity formula. Understanding 21 CFR Part 11 password requirements means looking beyond common password policies to the broader controls FDA expects around access, authority, electronic signatures, and trustworthy electronic records.
The distinction matters for sponsors and CROs evaluating clinical trial systems. General system access is addressed through controls such as Sections 11.10(d) and 11.10(g), while Section 11.300 has a narrower scope: it applies when an electronic signature is based on an identification code combined with a password.
Passwords are only one part of access control
Part 11 focuses on authorized access and attributable actions, not password rules in isolation. For closed systems, Section 11.10(d) requires access to be limited to authorized individuals. Section 11.10(g) separately requires authority checks so that only authorized individuals can use the system, electronically sign a record, access the operation or computer system input or output device, alter a record, or perform the operation at hand.
Those requirements apply more broadly than Section 11.300. That section specifically addresses people who use electronic signatures based on identification codes in combination with passwords, so it should not be treated as a universal password specification for every login credential used in a regulated electronic system.
The practical takeaway is that clinical trial access control needs to address both authentication and authorization. A clinical investigator, monitor, data manager, adjudicator, and system administrator may all legitimately use the same platform, but their responsibilities are different.
A structured access model typically needs to address:
- unique user identities
- authorization according to assigned responsibilities
- controlled assignment and modification of privileges
- removal of access when it is no longer required
- restrictions around signing, review, approval, and record alteration
- documentation of user roles and permissions
ICH E6(R3) reinforces this approach. Its computerized systems section states that access controls are integral to limiting access to authorized users and ensuring attributability. It also says user permissions should be assigned according to users’ duties and functions, revoked when no longer needed, and periodically reviewed where relevant.
What 21 CFR Part 11 password requirements actually say
The specific password provisions in Section 11.300 apply when an electronic signature uses an identification code together with a password. In that situation, the regulation requires controls intended to maintain the security and integrity of those identification codes and passwords.
The combined identification code and password must remain unique so that no two individuals have the same combination. Identification code and password issuances must also be periodically checked, recalled, or revised, with password aging listed as an example.
That wording matters. Part 11 does not establish a fixed aging interval, so there is no universal FDA requirement in Part 11 to change a password every 30, 60, or 90 days.
Section 11.300 also requires transaction safeguards to prevent unauthorized use of passwords or identification codes and to detect and urgently report attempts at unauthorized use to the system security unit and, as appropriate, organizational management.
A separate provision, Section 11.300(c), applies specifically to tokens, cards, and other devices that bear or generate identification code or password information. If such a device is lost, stolen, missing, or potentially compromised, organizations must follow loss-management procedures to electronically deauthorize it and issue replacements under suitable, rigorous controls.
That requirement should not be generalized into a Part 11 requirement governing every type of compromised login credential.
| Control area | What Part 11 requires | What Part 11 does not prescribe |
| General system access | Access limited to authorized individuals and authority checks for relevant operations | A universal password format |
| ID and password e-signatures | Unique combinations plus periodic checking, recall, or revision of issuances | A mandatory 30, 60, or 90-day password cycle |
| Unauthorized use | Safeguards against unauthorized use plus detection and reporting of attempts | One required authentication technology |
| Tokens, cards, or similar devices | Deauthorization and controlled replacement when lost, stolen, missing, or potentially compromised | A general incident procedure for every compromised credential |
| User permissions | Actions restricted to authorized individuals | Identical privileges for every authenticated user |
An organization may choose stricter cybersecurity measures based on its own risk assessment and security policies. Those measures, however, should not be described as explicit FDA password requirements unless the regulation actually requires them.
Electronic signatures require more than authentication
An electronic signature under Part 11 is not simply a successful login followed by an approval click. Section 11.100 requires each electronic signature to be unique to one individual and prohibits reuse or reassignment. The organization must also verify an individual’s identity before establishing, assigning, certifying, or otherwise sanctioning that person’s electronic signature.
For electronic signatures that are not based on biometrics, Section 11.200 requires at least two distinct identification components, such as an identification code and password.
During a single continuous period of controlled system access, the first signing must use all electronic signature components. Subsequent signings during that period may use at least one component that can only be executed by that individual. For signings outside a continuous period of controlled access, all components must be used again.
Section 11.50 requires the signed electronic record to identify the printed name of the signer, the date and time of the signature, and the meaning of the signature, such as review, approval, responsibility, or authorship. Those elements must also appear in a human-readable form of the electronic record.
Section 11.70 then requires electronic and handwritten signatures executed to electronic records to be linked to their respective records so that they cannot be excised, copied, or otherwise transferred to falsify an electronic record by ordinary means.
There is also an organizational requirement outside the software workflow. Under Section 11.100(c), persons using electronic signatures must certify to FDA before or at the time of first use that the electronic signatures in their system are intended to be the legally binding equivalent of traditional handwritten signatures.
FDA’s October 2024 clinical investigations guidance further clarifies that an organization may submit one letter of non-repudiation covering all electronic signatures used by that organization.
The practical implication is that authentication, authority, signature meaning, record linkage, and organizational procedures should be considered together when designing an electronic signing process.
How audit trail review relates to Part 11
Part 11 requires appropriate audit trails, but Section 11.10(e) does not itself establish a general requirement to review them. For closed systems, the regulation requires secure, computer-generated, time-stamped audit trails that independently record operator entries and actions that create, modify, or delete electronic records.
Changes must not obscure previously recorded information. Audit trail documentation must also be retained for at least as long as the electronic records to which it relates and remain available for FDA review and copying.
Review expectations need to be considered separately. ICH E6(R3) says procedures should be in place for review of trial-specific data, audit trails, and other relevant metadata, with the extent and nature of the review planned, risk-based, and adapted to the individual trial.
The practical takeaway is that generating an audit trail and reviewing an audit trail are two different controls.
Consider a hypothetical multi-site trial in which a value contributing to a critical endpoint is changed after initial entry. The audit trail should preserve the relevant record history, while the organization’s GCP procedures and risk-based review process determine how and when that change should be evaluated.
Risk-based validation is central to current FDA guidance
For clinical investigations, FDA’s October 2024 guidance provides current recommendations on electronic systems, records, and signatures. The document reflects FDA’s current thinking and builds on the risk-based approach to validation described in its 2003 Part 11 guidance.
FDA’s September 2003 Part 11, Electronic Records; Electronic Signatures – Scope and Application guidance explains that the agency intends to exercise enforcement discretion for specified Part 11 requirements concerning validation, audit trails, record retention, and record copying. It recommends that organizations base their approach on a justified and documented risk assessment.
Importantly, that enforcement discretion does not apply to Part 11 as a whole. FDA states that it intends to enforce other provisions, including limits on system access, authority checks, open-system controls, and electronic signature requirements under Sections 11.50, 11.70, 11.100, 11.200, and 11.300.
FDA’s 2024 guidance recommends considering a system’s intended use, the purpose and importance of the data and records it handles, and the potential effect on participant rights, safety, welfare, and the reliability of trial results. It also addresses trial-specific configurations, customizations, data transfers, interfaces, and changes to electronic systems.
Electronic systems should be validated before use in a clinical investigation using a risk-based approach, with subsequent changes evaluated according to risk.
For outsourced technology, FDA recommends that regulated entities have a written agreement with IT service providers describing how the services will meet the regulated entity’s requirements. These agreements should cover the scope of work, the roles and responsibilities of the regulated entity and the IT service provider, including quality management, and sponsor access to data throughout the required retention period.
The 2024 guidance supersedes FDA’s 2007 Computerized Systems Used in Clinical Investigations guidance and reflects FDA’s current thinking on electronic systems, electronic records, and electronic signatures in clinical investigations.
For sponsors and CROs, 21 CFR Part 11 validation is therefore better viewed as a risk-based lifecycle activity than as a static software checklist. Software capabilities matter, but so do intended use, configuration, procedures, vendor oversight, training, and organizational responsibilities.
How Medigen Suite supports controlled clinical workflows
Access control becomes more practical when study roles and privileges can be configured within the clinical system itself.
Catchtrial EDC+, part of Medigen Suite, supports granular management of study staff roles, with configurable access privileges and permissions across the study structure.
It also allows teams to create custom roles and assign specific privileges to a role or individual user.
These capabilities address an important operational need behind Sections 11.10(d) and 11.10(g): authenticating a user is not the same as authorizing every action that person could perform.
Consider a multi-site clinical trial. A site user may need access to specific participant records and data-entry functions, while a monitor, data manager, or study administrator may require different permissions aligned with their respective responsibilities.
Configurable roles can support a more structured way to map study responsibilities to system privileges when the platform is configured according to the study, organizational procedures, and validation strategy.
Medigen Suite is designed to support controlled clinical workflows in which teams can manage access according to study responsibilities rather than relying on authentication alone.
If your workflow uses electronic signatures, evaluate the signing process against Sections 11.50, 11.70, 11.100, 11.200, and 11.300 for your intended use.
Teams evaluating eClinical technology can review Medigen Suite capabilities alongside their SOPs, validation strategy, user-management controls, and electronic-record requirements.
Look beyond the password policy
A strong Part 11 approach connects identity, authority, signatures, records, and procedural controls. The 21 CFR Part 11 password requirements are only one part of that framework.
System access controls establish who is permitted to enter an electronic environment. Authority checks determine what authenticated users may do. Electronic signature requirements govern how regulated signing actions are attributed and connected to records, while audit trails preserve relevant record history.
One additional distinction matters for hosted technology. Part 11 defines a closed system as an environment in which system access is controlled by persons responsible for the content of electronic records on the system.
In practice, this means the distinction between an open and closed system depends on who controls system access, not simply on whether technology is hosted internally or by an external provider.
Where an environment qualifies as an open system, Section 11.30 requires the applicable Section 11.10 controls together with additional measures, such as document encryption and appropriate digital signature standards, as necessary to protect authenticity, integrity, and confidentiality.
For sponsors and CROs, the objective is not to collect isolated compliance features. It is to select, configure, validate, and operate technology in a way that supports the controls required by the regulated workflow.
Visit the Medigen Suite website or request a demo to see how configurable roles and controlled clinical workflows can support your organization’s approach to electronic trial records.
Frequently Asked Questions
Does 21 CFR Part 11 specify a minimum password length?
No. Where electronic signatures are based on an identification code combined with a password, Section 11.300 requires controls for their security and integrity, but it does not prescribe a minimum character count or complexity formula. General access to closed systems is separately addressed by Sections 11.10(d) and 11.10(g), which require access limits and authority checks.
Does 21 CFR Part 11 require passwords to expire every 90 days?
No. Part 11 does not establish a universal 90-day password expiration rule. For identification codes and passwords used as electronic signature components, Section 11.300 requires issuances to be periodically checked, recalled, or revised and cites password aging as an example. The regulation does not specify a particular interval.
What happens if an authentication token or similar device is lost?
Section 11.300(c) specifically addresses lost, stolen, missing, or potentially compromised tokens, cards, and other devices that bear or generate identification code or password information. Such devices must be electronically deauthorized, with temporary or permanent replacements issued under suitable, rigorous controls.
What does Part 11 require for an electronic signature?
For a non-biometric electronic signature, Part 11 requires at least two distinct identification components, such as an identification code and password. It also requires signature uniqueness, identity verification, information identifying the signer, date and time, and meaning of the signature, plus linkage between the signature and its corresponding electronic record.
How does audit trail review relate to Part 11?
Part 11 requires secure, computer-generated, time-stamped audit trails for relevant electronic record activity, but Section 11.10(e) does not itself impose a general audit trail review requirement. In clinical trials, ICH E6(R3) addresses planned, risk-based review of trial-specific data, audit trails, and relevant metadata.
What does FDA recommend for validation of clinical trial electronic systems?
FDA recommends a risk-based approach. Its October 2024 guidance advises considering intended use, the importance of the data and records involved, and potential effects on participant rights, safety, welfare, and the reliability of trial results. It also addresses system configurations, interfaces, changes, and the use of IT service providers.
ReeRegulatory Sources
- Electronic Code of Federal Regulations, 21 CFR Part 11, Electronic Records; Electronic Signatures.
- U.S. Food and Drug Administration, Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers, October 2024.
- U.S. Food and Drug Administration, Part 11, Electronic Records; Electronic Signatures – Scope and Application, September 2003.
- International Council for Harmonisation, ICH E6(R3) Guideline for Good Clinical Practice, Step 4, 6 January 2025.
Table of Contents
Latest Articles
This article provides general information and does not constitute regulatory, legal, clinical, or compliance advice. Requirements and appropriate processes may vary by study, product, jurisdiction, and organization. Medigen Suite functionality should be used in accordance with applicable regulations, study documentation, and internal procedures.



