Skip to main content

FDA 21 CFR Part 11

What 21 CFR Part 11 requires of a temperature data logger

Part 11 governs a validated system and the procedures around it — never a device on its own — so this page separates the controls a data logger can carry from the ones that stay with your SOPs, training and access policy.

21 CFR Part 11, explained for temperature monitoring

Most of what is written about Part 11 is either the regulation itself, which is dense, or vendor marketing, which is vague. Here is the practical version for anyone who has to defend a fridge temperature record in an FDA-regulated setting.

What Part 11 actually is

The most common Part 11 problem on a pharmacy or clinic fridge has nothing to do with the logger. It is that the temperature record everyone relies on was exported to a spreadsheet, tidied, and filed as the official copy — attributable to nobody, editable by anybody. The rule below explains why that is fatal, and what the alternative has to look like.

21 CFR Part 11 is the FDA rule that sets the conditions under which the agency will accept an electronic record or an electronic signature in place of paper and ink. It covers records in electronic form that are created, modified, maintained, archived, retrieved or transmitted under an FDA records requirement, and records submitted to the FDA. That is its whole scope. It does not tell you which records to keep, how tight your fridge tolerance has to be, or how long the data must be retained.

The predicate rule comes first

Those questions are answered by the predicate rule: the underlying regulation that already requires the record. Part 211 for a drug manufacturer, Part 820 for a device maker, Part 606 for blood establishments, Part 111 for dietary supplements, Parts 50, 56 and 312 for clinical investigations. The predicate rule creates the obligation; Part 11 rides on top of it and governs how you are allowed to meet that obligation electronically. Two things follow. If no predicate rule requires the record and you are not submitting it to the FDA, Part 11 has nothing to attach to. And satisfying Part 11 never excuses missing the predicate rule requirement underneath it.

The FDA's 2003 guidance, Part 11, Electronic Records; Electronic Signatures — Scope and Application, narrowed how the agency interprets the rule and described enforcement discretion over parts of it, including validation, audit trails, record copies and retention. Inspectors still work from it, and it is short enough to read in one sitting. Enforcement discretion is not an exemption: the predicate rule requirements for those same records apply in full regardless.

When Part 11 does not apply

Part 11 is narrower than most people assume. It does not apply when:

  • Paper is the official record. If the printout is the thing that is signed, filed and relied on, and the electronic version is incidental, Part 11 is not in play. With continuous temperature data this is rare, because nobody prints every reading.
  • No predicate rule requires the record. Comfort monitoring in an office, or a warehouse holding nothing FDA-regulated, is a business record, not a Part 11 record.
  • You are outside FDA jurisdiction. A Canadian pharmacy or clinic answering to Health Canada, a provincial college or a public health vaccine program faces comparable expectations, but under different documents — Health Canada GUI-0069 and GUI-0001, and provincial standards — not Part 11.

Write the scope determination down and date it — one paragraph naming the predicate rule you are subject to, or naming the fact that none applies. That paragraph is the first thing an inspector reads and the thing most sites cannot produce.

The controls that actually bite for a temperature logger

Section 11.10 lists the controls for closed systems. Read them once and a pattern appears: most are procedural, and only a few are things a product can supply. Here is each clause translated into the case where the record is a fridge temperature history, split by who is responsible for it, with the identification-code controls from 11.300 that a cloud dashboard has to answer for.

RequirementWhat MaxLinc providesWhat stays yours
11.10(a) Validation — accuracy, reliability, consistent intended performance, and the ability to discern altered recordsPublished device specifications, a NIST-traceable calibration certificate tied to each probe, and exports you can attach as objective evidence.Write and execute the validation protocol for your intended use. Test the real behaviour: readings upload on a schedule, alarms are pushed in real time. Both belong in the protocol.
11.10(b) Accurate and complete copies in human readable and electronic formOne-click FDA and HACCP report exports in PDF, Excel or CSV, plus the underlying data. Advanced reports are included, not a paid add-on.Confirm the export carries everything an inspector would ask for, state in your SOP which export is the official copy, and keep a copy outside the platform.
11.10(c) Protection of records for accurate and ready retrieval through the retention periodRetained history you can export for any date inside your plan's retention window — 45 days on the free WiFi plan, unlimited on the $2/month Premium plan, and everything included in year one on cellular devices. Records sit on Canadian cloud servers with daily backups and redundancy. Anything outside that window has to be exported and archived by you.Take the period from 21 CFR 211.180(a) if you manufacture or repackage — one year past batch expiry, or three years after distribution for OTC products without expiry dating. CDC's vaccine toolkit says at least three years, and some provinces and states require longer. Whichever applies, the audit trail is retained for the same period as the data, and you prove once that an archived export still opens.
11.10(d) Limiting system access to authorized individualsNamed accounts with role-based sharing — Owner, Editor, Viewer, Silent Viewer, and Service & Maintenance — so each person gets their own login and their own level of visibility. Confirm what your plan includes before you build the access policy around it: on WiFi devices, sharing sits in the optional Premium plan.No shared logins. Own the provisioning and removal SOP, and review the user list on a schedule — especially after staff leave.
11.10(e) Secure, computer-generated, time-stamped audit trailAlarm acknowledgement writes who acknowledged, when, and why to a time-stamped, read-only record: users cannot edit or delete an acknowledgement, and later entries are added alongside earlier ones rather than replacing them. This covers alarm handling — it is not a complete 11.10(e) audit trail of every action on the record.Document separately how changes to alarm limits and device configuration are controlled and evidenced. Review the trail as part of a periodic review, and record that the review happened.
11.10(f), (g) Operational checks and authority checksRoles govern who can acknowledge alarms and change configuration.Decide who is authorized to do what, document it, and keep it current.
11.10(h) Device checks to determine the validity of the source of data input or operational instructionReadings are written by the device against its own serial number and its probe serial. There is no path for a user to type a temperature into the history.Record in your installation qualification which logger and which probe serial serve which unit, so any reading can be traced back to a known source.
11.10(i) Training and qualification of everyone who uses the systemNothing. This one is entirely yours.Train every user and keep the training records where an auditor can find them.
11.10(j) A written policy holding individuals accountable for actions initiated under their electronic signaturesNothing. This is a document you write.A short signed statement that acting under someone else's credentials is a disciplinary matter. Inspectors ask for this by name and most sites do not have it.
11.10(k) Documentation controls, including revision and change controlProduct documentation and calibration certificates.Version-control your SOPs and validation documents and restrict who can change them.
11.300 Controls for identification codes and passwordsEach person gets their own named account, so an ID is never shared between two people, and an administrator removes access by removing the account. Ask us in writing for the current password rules before you draft this section.Set the password rules, decide the revision interval, and write the loss-management step — what you do the same day a phone or laptop with a live session goes missing.
Subparts B and C — electronic signaturesAcknowledgements identify the person and the time and stay linked to the record. We do not market them as electronic signatures.Applies only if you treat a signing as the equivalent of a handwritten signature. Then the full signature requirements, including certification to the FDA, are on you.

If you are assessing any logger platform, 11.300 is the clause to ask about. Password aging and credential loss-management are handled very differently between vendors and rarely appear on a datasheet.

The audit trail deserves a closer look, because it is where systems most often fail. 11.10(e) asks for an audit trail that is secure, computer-generated and time-stamped, that records the date and time of operator entries and actions independently of the operator, and that does not obscure previously recorded information. A correction has to appear as a new entry beside the original, never as an overwrite. The audit trail has to survive at least as long as the record it describes and be available for review and copying. The word doing the work is independently: if a user can choose the timestamp or move the clock, what you have is a comment field, not an audit trail.

Part 11 and data integrity are not the same test

Part 11 tells you what technical controls a record system needs. Data integrity expectations tell you what the record itself has to be, and that is the test an investigator applies in practice. FDA set them out in the 2018 guidance Data Integrity and Compliance With Drug CGMP, using the ALCOA criteria: attributable to the person who made the entry, legible, contemporaneous, original, and accurate — with complete, consistent, enduring and available usually added as ALCOA+. Applied to a fridge record, that means the reading is tied to a named account rather than a shared login, the timestamp is written by the system rather than typed in, the electronic record is the original and the PDF is a copy of it, and the whole set stays readable for the retention period. Most temperature findings are ALCOA failures before they are Part 11 failures: the data existed, but nobody could show who recorded it or that it had not been retyped.

Electronic signatures are a separate, higher bar

Plenty of Part 11 systems use no electronic signatures at all. But if your SOP treats an alarm acknowledgement or a report approval as the equivalent of signing a page, subparts B and C apply. Signed records must show the printed name of the signer, the date and time, and the meaning of the signing — review, approval, responsibility or authorship. Signatures must be linked to their records so they cannot be cut, copied or transferred to falsify a different record. Non-biometric signatures need at least two distinct identification components, typically a user ID and a private password: both components for the first signing in a single continuous period of controlled system access, at least one component for each subsequent signing within that same session, and all components again for any signing outside it. And prior to or at the time you first use electronic signatures as legally binding equivalents of handwritten ones, your organization must certify that to the FDA in writing under 11.100(c). That letter is signed by hand, and no vendor can send it for you.

Open systems and closed systems

Part 11 defines a closed system as one where access is controlled by the people responsible for the content of the records, and an open system as one where it is not. The test is who controls access, not where the server sits, so cloud hosting does not automatically make a system open. If your organization controls the accounts, the roles and who gets provisioned, most quality units document the system as closed and apply the 11.10 controls. If you conclude it is open — because access is administered by a third party outside your control, say — then 11.30 asks for additional measures such as document encryption and appropriate digital signature standards, on top of everything a closed system already needs. Either way the determination is yours to make and to record in your validation package, and it should be supported by a quality or technical agreement with the provider that states who is responsible for what.

The misconception that costs people the most

No product, from anyone, is "Part 11 compliant" out of the box. Compliance is a property of a validated system plus your own procedures. The vendor supplies technical controls. You supply validation, SOPs, access control and training records.

When a supplier says a device "supports 21 CFR Part 11" — and that is the phrasing this page uses — read it literally. It means the software provides the controls Part 11 expects of the record-keeping system: unique accounts, an audit trail that cannot be edited, exports that are complete and readable. It cannot mean more than that, because the rest of the rule is about how your organization behaves. An inspector does not audit the logger. They audit your system, and they ask for the validation protocol and its results, the access control policy, evidence that users were trained, and evidence that someone reviews the audit trail.

Does buying an EDGE Pharma logger make my pharmacy Part 11 compliant?
No, and no product can. EDGE Pharma is designed to support your validation: a NIST-traceable probe in a glycol buffer, automatic compliance reports, and acknowledgements written to a time-stamped record that users cannot edit or delete. The validation, the SOPs, the access control policy and the training records are still yours to produce.
We operate only in Canada. Does Part 11 apply to us?
Only if you keep records required by an FDA predicate rule or submit records to the FDA — for instance if you export to the US or run under an FDA-regulated quality system. A Canadian pharmacy answering to Health Canada and its provincial college is held to comparable expectations under different documents. Have your QA or regulatory lead decide in writing which applies.
Does someone actually have to review the audit trail?
In practice, yes. Part 11 requires the audit trail to exist and to be available for review and copying; the predicate rule and the FDA's data integrity expectations are what make the review itself an obligation. Attach it to a review you already perform so it does not become the step everyone forgets.

What MaxLinc EDGE Pharma actually provides

The clause-by-clause split of who owns what is in the table above. This section is the other half: the specifications a validation package needs stated plainly, the questions worth putting to any monitoring vendor, and the things EDGE Pharma does not do.

Two things auditors ask about that are easy to get wrong before you buy. First, probe placement: air temperature at the top of a fridge is not the temperature of the vials, so the glycol buffer goes on the shelf with the product and the logger stays outside — the probe extends to 15 m (50 ft) to make that possible. Second, coverage during an outage: EDGE Pharma keeps logging to internal memory when the network drops and backfills every missed reading on reconnect, and a no-connection alarm tells you the device stopped reporting. Both are things to verify during installation and write down, not assume.

What the EDGE Pharma record actually looks like

RequirementWhat MaxLinc providesWhat stays yours
Probe accuracy±0.5 °C across the 2–8 °C (36–46 °F) vaccine range. The probe sits in a glycol buffer, so the record reflects vial temperature rather than air temperature.State the accuracy figure and the buffered probe in your user requirements and your acceptance criteria, so the protocol tests what you actually installed.
Offline recording and backfillThe logger keeps recording to internal memory when the network drops — tens of thousands of readings — and uploads every missed reading on reconnect, so an outage does not produce an unexplained gap.Test it once during qualification: pull the network, restore it, confirm the gap filled, and file the before-and-after export.
Missed check-inA no-connection alarm fires when a device has not reported inside its expected window. Low-battery and power-change alerts are separate.Name who receives the alarm, on what device, and what the response is. A missed check-in is an event to investigate and write up.
CalibrationNIST-traceable certificate per probe, valid three years, issued to that probe's serial number. The dashboard warns administrators 60 days before expiry, and the device screen shows a NIST icon that flags an expired certificate locally. Renewal is a probe swap, not a lab return.File the certificate, schedule the replacement, and decide in advance what happens to data recorded after one expires.
PowerContinuous USB-C with automatic rollover to 4× AA alkaline batteries, and an instant alert the moment mains power is lost. On batteries alone the logger runs up to about two years.For a regulated fridge, run USB-C primary so a mains loss raises an alert instead of a silent gap. Put a battery check and a low-battery response in the SOP.
Where records liveCanadian cloud servers, daily backups and redundancy — the answer to the hosting and backup questions on a supplier-assessment form.Record the hosting answer in your validation package, and confirm your plan's history window before you rely on the platform as the archive.
Report formatsPDF, Excel and CSV, schedulable by email, including Mean Kinetic Temperature summaries alongside excursion start, duration and corrective-action fields.Decide which export is the official copy, who may produce it, and who reviews and signs it off.
Probe reachSensors extend to 15 m (50 ft), so the logger can sit outside the unit while the probe sits with the product.Record where the probe sits, with a photo, as part of the installation record.

The supplier questions worth asking — ours included

Ask every monitoring vendor these in writing, and keep the answers with your supplier assessment:

  • Can any user, including an administrator or the vendor, edit or delete a stored reading? Ask for a demonstration, not a yes.
  • Is the audit trail itself exportable, or only viewable in the interface? An audit trail you cannot export is hard to hand to an inspector.
  • What happens to readings during a network outage — are they buffered and backfilled, or lost? Ask for the buffer size in readings, not in adjectives.
  • Where is the data physically hosted, who backs it up, and how often? (Ours: Canadian cloud servers, daily backups with redundancy.)
  • What is the password policy: uniqueness, aging interval, and how a compromised credential is revoked? That is 11.300, and it is rarely on a datasheet.
  • Is the calibration certificate tied to the probe serial number, and how are you warned before it expires? (Ours: certificate issued to the probe serial, valid three years, dashboard warning at 60 days, and the device screen flags an expired certificate.)
  • Will the vendor complete a written supplier questionnaire and provide specifications you can cite in a validation protocol?
  • What happens to your historical data if you stop paying? Ask this first of any subscription platform. (Ours: on WiFi devices, dropping the optional Premium plan returns you to the 45-day history window, so archive your exports.)

What you will actually need to produce

  • A validation plan and a signed validation report covering this system in your facility.
  • SOPs for routine monitoring, excursion response, alarm acknowledgement, and report generation and review.
  • An access policy, plus a current list of accounts and roles and a documented removal step for departing staff.
  • Training records for every person who uses the dashboard (11.10(i)).
  • A calibration and probe-replacement schedule, with certificates on file.
  • A periodic review record showing someone actually looks at the audit trail.

What EDGE Pharma does not do

  • Readings are not streamed live. Data uploads on a schedule; only alarms are pushed in real time. If a procedure depends on continuous live data, say so before you buy.
  • Alarm acknowledgement is an attributable record. We do not market it as an electronic signature under Subpart C. If signed records are in scope for you, ask us exactly what the record contains before you write the SOP around it.
  • The audit trail covers alarm acknowledgements and configuration changes. It is not a general-purpose electronic batch record. If your SOP needs an audit-trail entry for something else — a manual temperature correction, a deviation note — ask us what the record captures before you write the procedure around it.
  • History is retained for your plan's window, not indefinitely: 45 days on the free WiFi plan, unlimited on Premium. Long-term retention is an archive you own, not something a vendor does for you.

Putting Part 11 into practice

None of this needs a validation department. A pharmacy, a clinic, or a small distributor can reach a defensible position in a few weeks of part-time work. What follows is the modest version — enough to answer an inspector, not a manufacturer's full quality program.

A realistic readiness plan for a small site

  • Confirm which rule applies to you, before anything else. Part 11 only attaches to records an FDA regulation already requires you to keep, and that you have chosen to keep electronically. A Canadian community pharmacy is usually answering to its provincial college and Health Canada instead. Ask your QA/RA contact or your regulator, and file the answer you get.
  • Write down what you are monitoring — one page is enough. Each fridge or freezer, its identifier, what is stored in it, the alarm limits, where those limits came from, and how long that record has to be kept. The usual sources: refrigerated vaccines 2–8 °C (36–46 °F) with CDC recommending a 5 °C (40 °F) target, frozen vaccines −50 to −15 °C (−58 to +5 °F), and USP controlled room temperature 20–25 °C (68–77 °F) with excursions between 15 and 30 °C permitted. Set the alarm at the limit, not inside it, and use an alarm delay rather than a wider limit to handle door openings and defrost cycles — a delay is a documented configuration you can defend, a widened limit is a finding. Record the delay you chose and why, because that is the setting people quietly change at 2 a.m. This page is the scope of everything else.
  • Write a short SOP. Who receives alerts and on which phone. How quickly someone must respond. Who may acknowledge an alarm and what they have to write. How an excursion is investigated, and who decides whether product is still usable. The calibration interval. What to do when a logger stops reporting. Two to four pages is normal.
  • Give every person their own login. Shared accounts are the fastest way to make an audit trail worthless — "admin acknowledged the alarm" identifies nobody. Keep a list of who has access and what they can do, and remove people the week they leave.
  • Verify the installation and write down what you saw. Serial numbers of the logger and probe, the calibration certificate on file, a photo of the buffered probe sitting with the product rather than in the door or in open air. Then prove it works: force an alarm, confirm the alert arrives on the on-call phone, acknowledge it, export a report. Run it for a few days before product goes in. Those pages are your installation and operational qualification records — the IQ/OQ evidence, at the scale a small site actually needs.
  • Keep training records. Name, date, which version of the SOP, signature. Inspectors ask for these more often than they ask about the hardware.
  • Review it on a schedule. Quarterly suits a small site: are alerts still going to phone numbers that exist, is calibration still in date, was every excursion closed out, does the user list still match the staff list?

Then keep it. For the retention period that applies to your records, hold on to the temperature data and its audit trail, the SOP and its earlier versions, training records, calibration certificates, the installation verification, excursion investigations, and the record of who had access over time. Keep the electronic record as the master. A printed PDF is a copy of it, not a replacement for it.

How temperature records actually fail an inspection

  • Gaps nobody explains. Batteries died, or the connection dropped, and three days are missing. The gap itself is rarely the finding — the silence around it is. Alert on missed check-ins, and when a gap happens, record the cause, what was in the unit, and what you concluded.
  • Alarms with no ending. The record shows an excursion at 02:14 and then nothing. Every alarm needs an acknowledgement naming a person, a time, and a reason, plus a disposition decision for the product when limits were breached.
  • The spreadsheet became the master record. Data is exported to Excel, tidied up, and kept as the official file. An editable copy with no attribution is very hard to defend. Export for reading and sharing; leave the system record as the original.
  • Calibration that lapsed, or that cannot be tied to the sensor. A certificate for "a probe" proves nothing. It has to name the serial number of the probe actually in that unit, and be current on the day the reading was taken.
  • Alarm limits that changed with no trace. Someone widens the high limit to stop the phone ringing at night. If you cannot show when limits changed, who changed them, and why, the whole data set becomes questionable.
  • The sensor in the wrong place. Air temperature at the top of a fridge is not the temperature of the vials on the bottom shelf. Use the buffered probe, place it with the product, and record where it sits.
  • Nobody can produce the record. The one person with the login is away. Test retrieval as part of your periodic review, and make sure at least two people can export a report unaided.

Frequently asked questions

Can a data logger be 21 CFR Part 11 compliant on its own?
No. Judge a product on the specific controls it provides, not on the word compliant. Four questions separate products: can an administrator delete or edit a stored reading (the answer must be no, and you should ask them to demonstrate it); is the audit trail itself exportable, or only viewable on screen; what happens to the record if the device is offline for three days; and how are credentials aged and revoked under 11.300. Vendors that answer those in writing are worth assessing. Vendors that answer with the word compliant are not.
Does Part 11 apply to a community pharmacy fridge?
Usually not directly. Part 11 attaches to records an FDA regulation already requires you to keep, and that you choose to keep electronically. Day-to-day dispensing in a retail pharmacy is governed by the state board of pharmacy — in Canada, by the provincial college, with Health Canada covering licensed establishments. Pharmacies still adopt Part 11-style controls, generally because a vaccine program, a manufacturer contract, or a US-regulated customer expects them. Get the answer for your own site from QA/RA in writing.
What does an audit trail have to capture?
Section 11.10(e) calls for a secure, computer-generated, time-stamped audit trail that independently records the date and time of operator entries and actions that create, modify, or delete electronic records. Changes must not obscure previously recorded information — the earlier value stays visible. The audit trail has to be retained at least as long as the record it belongs to, and be available to the agency for review and copying. In practice: who, when, what changed, from what to what, and why.
How long do temperature records have to be kept?
Part 11 sets no retention period at all. The rule that required the record sets it. If you manufacture or repackage under 21 CFR 211, production and control records are kept at least one year past the batch expiry date, or three years after distribution for certain OTC products without expiry dating. For vaccine storage, CDC recommends keeping records at least three years, and some jurisdictions require longer. The audit trail is retained for the same period as the data it describes. Check what your monitoring platform actually retains — on our WiFi devices that is 45 days on the free plan and unlimited on Premium — and archive exports for anything beyond it.
What is the difference between NIST-traceable calibration and Part 11?
They answer different questions. Traceable calibration says the number is right: the probe was compared against a standard through an unbroken chain to NIST, with a stated uncertainty and a date. Part 11 says the record is trustworthy: attributed, time-stamped, protected from silent editing, retrievable. A perfectly calibrated probe writing into an editable spreadsheet fails Part 11. A rigorous audit trail on an uncalibrated probe records the wrong temperature very reliably. You need both, and neither substitutes for the other.
Are paper logs still allowed?
Yes. Part 11 governs records kept electronically; a genuine paper record stays under the predicate rule alone. The trap is the hybrid. If a device is creating and maintaining the electronic record, printing it does not move you back to paper — the electronic version is still the one being maintained, and it still has to be controlled. Separately, a twice-daily manual reading says nothing about the eleven hours overnight, which is exactly the window a twice-daily check cannot cover.
Is there such a thing as an FDA-approved or FDA-certified data logger?
No. FDA does not approve, certify, or clear data loggers for Part 11, and no Part 11 certificate exists for any product. There is no registry to check. What can exist is vendor documentation — specifications, calibration certificates, a description of the controls the system provides — plus your own validation record showing the system does what you need in your facility. Treat "FDA approved" printed on a logger's box as a reason to look harder, not a reassurance.
Do I need electronic signatures?
Only if you intend to sign records electronically in place of a handwritten signature. An attributed audit-trail entry — acknowledging an alarm, for instance — is not automatically an electronic signature in the Part 11 sense. If you do use them, the requirements are specific: each signature is unique to one individual and never reused or reassigned, non-biometric signatures use at least two distinct identification components such as an ID code and a password, and you must certify to FDA in paper form, with a handwritten signature, that your electronic signatures are the legally binding equivalent of handwritten ones — before or when you begin using them.
What does validation actually involve for a small site?
Less than the word suggests. Write down what the system is for and what it has to do. Record what you installed, including serial numbers and firmware. Test the things you rely on: an alarm that reaches a real phone, a report that exports, a probe reading checked against a reference. State the pass criteria before you test, not after. Sign the result. Five to fifteen pages is a normal outcome for one or two fridges. A vendor cannot do this for you, because it is evidence about your environment, not theirs. If someone asks you to justify the size of that package, the usual reference is GAMP 5, which scales validation effort to software category. A monitoring platform you configure but do not customise is Category 3 or 4, which is why a short, well-evidenced package is defensible and a hundred-page one is not. If you also supply into the EU, EudraLex Annex 11 covers the same ground as Part 11 with a stronger explicit expectation around risk management and supplier assessment; a single package built to Part 11 plus a documented supplier assessment usually satisfies both.
What applies in Canada instead of Part 11?
Health Canada does not enforce 21 CFR Part 11. Canadian expectations for temperature control come from GMP guidance and GUI-0069 for the storage and transportation of drug products, together with provincial college requirements for pharmacies. The underlying principles overlap heavily: attributed records, controlled access, defined retention, and evidence the system works. Canadian sites that ship into the US, or that serve US-regulated partners, often build to Part 11 anyway so a single record set satisfies both.

This page is reference material, not legal or regulatory advice. Which of your records fall under Part 11, and what your validation has to cover, are decisions for your own QA or regulatory affairs function.

Which EDGE Pharma fits your setup?

Pharma One monitors a single fridge or freezer; Pharma Two covers two units from one logger. Both use a NIST-traceable glycol probe. WiFi is free forever; cellular includes everything for year one.

This page is reference information, not legal or regulatory advice. No data logger can make an organization Part 11 compliant on its own — that rests on your validation, SOPs, training and access controls. Confirm scope with your own QA/RA.