What 21 CFR Part 11 Evidence Actually Looks Like

Published 5 min read

Quick verdict. No software is Part 11 compliant on its own — compliance is a property of your validated implementation. What a vendor can offer is documented controls: electronic signatures, audit trail, record locking, access control. Of the five ELNs we track, all five document Part 11 to some degree, but only one also documents EU Annex 11, and three of the five have at least one security claim with no evidence behind it.

Every electronic lab notebook vendor says it supports 21 CFR Part 11. The claim is so universal that it carries almost no information. What separates vendors is not whether they say it, but what they can show you when you ask — and that difference is visible before you ever speak to sales.

Start with what the rule actually requires of software

Part 11 governs electronic records and electronic signatures. Compliance is a property of your implementation: your validation, your procedures, your access control, your training records. No purchase makes a laboratory compliant, and a vendor who implies otherwise has told you something useful about how it will answer harder questions later.

What software can supply is the technical foundation your validation will reference:

When you read a vendor’s Part 11 page, look for those four things by name. A page that names them is describing its product. A page that says “built for compliance” and moves on is describing its marketing.

The three tiers you will encounter

Across the vendors we track, published Part 11 evidence falls into three clear tiers.

A dedicated page naming the controls. SciSure publishes a current page covering electronic signatures, audit trail, record locking and role-based access control. Labguru publishes a help page naming signature, witnessing, audit trail and record locking or versioning. SciNote publishes a regulated-environments page covering signatures, audit trails and timestamps. This is the tier you want: specific enough to attach to a supplier assessment.

A workflow documented in the help centre. LabArchives documents signing and witnessing with audit controls as a feature, in operational documentation rather than a compliance page. That is real evidence — arguably more honest than a compliance landing page — but you will do more work assembling it.

A trust page covering compliance as a posture. Benchling describes the platform as built for compliance with signature and audit controls, and references EU Annex 11 alongside Part 11 on the same page. The Annex 11 reference is rare and valuable; the Part 11 description is less granular than SciSure’s.

All five are defensible. None is a substitute for validation.

The question almost nobody asks: Annex 11

If your work falls under EU GMP rather than FDA jurisdiction, Annex 11 is the rule that applies to you, and Part 11 documentation is not a substitute.

Of the five ELNs we track, one documents it: Benchling, on the same trust page as Part 11. SciNote claims it in tutorial material without a dedicated dossier, which we record as a vendor claim rather than documentation. LabArchives, SciSure and Labguru leave it unverified entirely.

That is a striking gap in a market selling heavily into European pharma. If Annex 11 is decisive for you, ask every vendor except Benchling for documentation before you shortlist them — and treat the speed and specificity of the answer as data.

Where security claims quietly weaken

Part 11 is not the only thing worth verifying, and the security frameworks are where published evidence thins out fastest — because a certificate either exists or it does not.

Two patterns are worth recognising. The first is a public trust portal: SciNote publishes one carrying ISO 27001 and SOC 2 Type II. A portal is a standing, checkable artefact rather than a sentence, and it is the strongest form of this evidence short of the report itself.

The second is a claim with nothing behind it. SciSure’s site states ISO/IEC 27001 certification, but no current public certificate was found, so we record it as a vendor claim. Labguru’s security page states operation in accordance with ISO 27001, while SOC 2 remains unknown.

None of that means the controls are absent. It means that on the day you assemble a supplier file, one vendor hands you documents and another hands you assurances — and only one of those can be attached to the file.

What to ask for, and what a good answer looks like

Four requests, in this order:

  1. “Send me your Part 11 documentation for this product.” A good answer arrives as a link or a PDF within a day, names the four controls, and refers to the exact product rather than a platform family.
  2. “Send me your ISO 27001 certificate and your SOC 2 report.” Check the scope and the period, not just that they exist. A certificate covering a parent company’s corporate IT is not a certificate covering the service holding your research.
  3. “What do you supply for validation?” Some vendors provide IQ and OQ documentation or validation packs. This is where implementation cost hides, and where a cheap licence can become expensive.
  4. “Does anything change if we self-host?” It does. A vendor’s SOC 2 covers the vendor’s infrastructure; running the software yourself makes those controls yours to implement and evidence. SciSure and SciNote both document on-premise, and both answers should change accordingly.

One last distinction: ISO 17025

You will occasionally see an ELN presented as ISO 17025 compliant. Software cannot hold ISO 17025 accreditation — it applies to a testing or calibration laboratory, not to a tool.

SciNote publishes a dedicated page on the topic that says so correctly, explaining which features help a laboratory achieve compliance. We record the standard as documented for that product because a dedicated page exists, and we say plainly on its profile that this is not a software certification.

How a vendor handles that particular question is a decent proxy for the rest. The ones that explain the distinction unprompted are usually the ones whose other documentation survives being read closely.

Related ELN vendors

FAQ

Can an ELN be 21 CFR Part 11 compliant?

Not on its own. Part 11 applies to your electronic records and signatures, and compliance follows from your validated implementation, your procedures and how you actually operate. A vendor supplies technical controls and documentation your validation can reference. Any vendor claiming its product is simply compliant is describing something that cannot exist.

What is the difference between documented and vendor-claim?

A dedicated, citable page or document linking the exact product to the requirement is documented. A sentence on a marketing page asserting support, with nothing behind it, is a vendor claim. The distinction matters because a supplier assessment needs something to attach, and an assertion cannot be attached.

Which ELN documents EU Annex 11?

Of the five we track, only Benchling, which references it alongside 21 CFR Part 11 on its trust page. SciNote claims Annex 11 in tutorial material without a dedicated dossier, and LabArchives, SciSure and Labguru leave it unverified. If your work falls under EU GMP rather than FDA rules, that is the gap to raise first.

Sources

  1. Benchling — Trust (accessed 2026-09-18)
  2. SciNote in regulated environments (accessed 2026-09-18)
  3. SciSure — 21 CFR Part 11 compliance (accessed 2026-09-18)
  4. Labguru — 21 CFR Part 11 (accessed 2026-09-18)