Part 11 compliance is not a label a piece of software carries into your study. It is the result of the software, how it is hosted and configured, and the validation your organisation documents. Here is the checklist of what you must establish for REDCap, or for any tool, before regulated data goes in.
Free sandbox · No credit card · 21 CFR Part 11 aligned
| Element | Software | Hosting institution | Sponsor / study team | |
|---|---|---|---|---|
| Audit trail present and tamper-resistant | Feature | Configuration | Reviews it | |
| Electronic signatures linked to records | Feature | Configuration | Defines meaning | |
| Access control and unique users | Feature | Accounts, SSO | Roles per study | |
| System validation | Vendor evidence | Installation checks | Fit for the study | |
| Procedures and training | n/a | Local SOPs | Study SOPs |
The short answer
What the regulation asks
21 CFR Part 11 sets out the FDA's criteria for treating electronic records and electronic signatures as trustworthy and equivalent to paper. In practice, reviewers and inspectors look for a handful of things: a secure, computer-generated, time-stamped audit trail that records who changed what and when without hiding earlier values; electronic signatures that are unique to one person, linked to their record and carry a stated meaning; limited system access with authority checks; documented validation that the system does what it is meant to do; and written procedures and training for the people using it. The 21 CFR Part 11 compliance checklist lays these out requirement by requirement.
Notice that only some of those items are properties of software. An audit trail is a feature. Validation is an activity, documented by someone, against a defined intended use. Procedures and training belong to the organisation. That is why the phrase "shared responsibility" appears in every serious discussion of Part 11, and why a one-line yes or no on a web page is unreliable in either direction. We say the same about our own platform: Capture provides 21 CFR Part 11-aligned controls, and a sponsor still validates its use for its study. See 21 CFR Part 11 compliant EDC for how we describe that split.
Applying it to REDCap
REDCap is research data capture software developed within an academic consortium and, in the most common arrangement, installed and administered by a university or hospital for its own investigators. That has two consequences for a compliance question. First, the software is one input: the same version can be configured, patched and documented very differently at two institutions. Second, the hosting organisation, not the software's authors, usually holds the evidence you will need: server qualification, backup and recovery records, upgrade history, user provisioning and any validation work done on the local installation.
We therefore do not tell you that REDCap is, or is not, compliant. We cannot see your institution's installation, and a general statement would be wrong for someone. What we can say is that a sponsor, CRO or investigator using any institution-hosted system for regulated data should be able to put documented answers next to each element in the table above. If the institution has a research computing or quality group that supports clinical trials, start there. For the vendor's own position, read the current documentation published by the REDCap consortium rather than a third-party summary, including ours.
Ask them in writing, and file the answers in the study master file.
Evidence
A neutral evidence list that works for REDCap or any other tool. A missing item is a gap to close, not proof the tool is unsuitable.
| Part 11 element | Document to request | A good answer includes |
|---|---|---|
| Audit trail | Configuration description and a sample export | User, timestamp, old and new value, reason; cannot be edited by users |
| Electronic signatures | Signature procedure and screenshots | Unique to one person, linked to the record, meaning stated |
| Access controls | User management SOP and role list | Unique accounts, role per study, periodic review, prompt removal |
| Validation | Validation plan and summary report | Intended use, risk assessment, test evidence, deviations resolved |
| Change control | Upgrade and patch log | Each change assessed, tested and approved before release |
| Records retention | Backup and archive procedure | Records retrievable and readable for the required period |
| Training | Training records | Users trained before access to regulated data |
Build a study in the free sandbox and test the audit trail, edit checks and electronic signatures yourself. No credit card, and you pay only when you go live.
Your options
There are three realistic paths. The first is to close the gaps where you are: work with the hosting institution to document configuration, commission a validation exercise for your intended use and write the procedures. This can be the right choice for a single investigator-initiated study with a strong local research computing team, and it is why the REDCap true-cost worksheet asks you to price validation and staff time rather than assume they are free.
The second is to scope the tool to what it was chosen for: use an institutional research database for surveys, registries and non-regulated studies, and use a regulated system when data will support a submission or be inspected. That is a sensible division of labour and many institutions run both.
The third is to use a platform where the controls are built in and the vendor supplies documentation to support your validation. Capture's audit trail is field-level, written by database triggers and append-only, with each row hash-chained to the previous one; electronic signatures re-authenticate the signer and carry a meaning statement; roles and row-level security limit access; and enterprise customers get documentation to support sponsor validation and user acceptance testing. You still validate for your intended use, which is the point of shared responsibility. See the REDCap alternatives page for the comparison criteria and the Capture vs REDCap comparison for a side-by-side view.
You cannot import a REDCap project directly, but a data dictionary export lets the AI form builder draft the new forms for your review. Read how to migrate from REDCap and, if the study has already started, how to switch EDC vendors mid-study before you decide, because moving a running study is a different risk from starting a new one on the right tool.
Before regulated data goes in
What data, which decisions, which submissions the system supports.
Who runs servers, upgrades, backups and access, in writing.
Plan, risk assessment, test results and summary for your use.
Export a sample and confirm user, time, old and new value and reason.
Who signs what, with what meaning, and how identity is verified.
Procedures and training records before first participant.
Your quality unit decides what is adequate; this page is not advice.
We do not assert either answer. Part 11 compliance depends on the software, how an institution hosts and configures it and the validation and procedures documented around it. Ask the hosting institution for its evidence and read the consortium's current documentation.
Capture provides 21 CFR Part 11-aligned controls: a field-level append-only audit trail, electronic signatures with re-authentication, role-based access and approved-form locking. Compliance is shared with the sponsor, who validates the system for its intended use.
Both. The vendor provides controls and evidence; the sponsor is responsible for fitness for the study, procedures, training and validation for its intended use.
That is for your institution, quality unit and regulatory advisers to decide after reviewing evidence. This page cannot answer it for you and is not legal advice.
A validation summary, the audit trail and signature configuration, user management procedures, the upgrade and change-control log, and backup and recovery records.
Enterprise customers receive documentation to support sponsor validation and user acceptance testing. You test the system for your own intended use, free in the sandbox first.
Yes. The free sandbox has every feature, including edit checks, electronic signatures and the audit trail, with no credit card and no time limit.
Keep exploring
Capture vs REDCap
A neutral side-by-side comparison.
REDCap alternatives
Criteria for comparing options.
How to migrate from REDCap
A practical rebuild path.
21 CFR Part 11 compliance checklist
Requirement by requirement.
21 CFR Part 11 compliant EDC
How we describe shared responsibility.
Computer system validation
Validating a system for its intended use.
Free sandbox with every feature. No credit card, and you pay only when you go live.