Compliance question · REDCapUpdated October 6, 2026

Is REDCap 21 CFR Part 11 compliant? What sponsors need to verify

Part 11 compliance is not a label a piece of software carries into your study. It is the result of the software, how it is hosted and configured, and the validation your organisation documents. Here is the checklist of what you must establish for REDCap, or for any tool, before regulated data goes in.

  • Shared responsibility explained
  • Verification questions, not verdicts
  • Neutral and not legal advice

Free sandbox · No credit card · 21 CFR Part 11 aligned

Who has to demonstrate each Part 11 element (demo)
ElementSoftwareHosting institutionSponsor / study team
Audit trail present and tamper-resistantFeatureConfigurationReviews it
Electronic signatures linked to recordsFeatureConfigurationDefines meaning
Access control and unique usersFeatureAccounts, SSORoles per study
System validationVendor evidenceInstallation checksFit for the study
Procedures and trainingn/aLocal SOPsStudy SOPs
Neutral framework, not a verdict on any product

The short answer

  • No software is "Part 11 compliant" on its own. The regulation covers the system, the people and the procedures around it, so the honest answer for any tool is a list of what has been verified and by whom.
  • For REDCap the answer depends on your installation. It is typically installed and run by an institution, so hosting, configuration, upgrades and validation evidence are local facts you must obtain from that institution, not assume from the software's name.
  • Ask for documents, not assurances: a validation summary, the configuration of audit logging and signatures, user management and an upgrade change-control record.
  • If the evidence is thin, you have options: close the gaps locally, restrict REDCap to non-regulated data, or use a platform whose Part 11-aligned controls are built in and documented for sponsor validation.
  • This page is general information, not legal or regulatory advice. Your quality unit and regulatory advisers decide what is adequate for your study.

What the regulation asks

What "Part 11 compliant" actually means

21 CFR Part 11 sets out the FDA's criteria for treating electronic records and electronic signatures as trustworthy and equivalent to paper. In practice, reviewers and inspectors look for a handful of things: a secure, computer-generated, time-stamped audit trail that records who changed what and when without hiding earlier values; electronic signatures that are unique to one person, linked to their record and carry a stated meaning; limited system access with authority checks; documented validation that the system does what it is meant to do; and written procedures and training for the people using it. The 21 CFR Part 11 compliance checklist lays these out requirement by requirement.

Notice that only some of those items are properties of software. An audit trail is a feature. Validation is an activity, documented by someone, against a defined intended use. Procedures and training belong to the organisation. That is why the phrase "shared responsibility" appears in every serious discussion of Part 11, and why a one-line yes or no on a web page is unreliable in either direction. We say the same about our own platform: Capture provides 21 CFR Part 11-aligned controls, and a sponsor still validates its use for its study. See 21 CFR Part 11 compliant EDC for how we describe that split.

Applying it to REDCap

Why the REDCap answer is local

REDCap is research data capture software developed within an academic consortium and, in the most common arrangement, installed and administered by a university or hospital for its own investigators. That has two consequences for a compliance question. First, the software is one input: the same version can be configured, patched and documented very differently at two institutions. Second, the hosting organisation, not the software's authors, usually holds the evidence you will need: server qualification, backup and recovery records, upgrade history, user provisioning and any validation work done on the local installation.

We therefore do not tell you that REDCap is, or is not, compliant. We cannot see your institution's installation, and a general statement would be wrong for someone. What we can say is that a sponsor, CRO or investigator using any institution-hosted system for regulated data should be able to put documented answers next to each element in the table above. If the institution has a research computing or quality group that supports clinical trials, start there. For the vendor's own position, read the current documentation published by the REDCap consortium rather than a third-party summary, including ours.

Questions to put to the hosting institution

Ask them in writing, and file the answers in the study master file.

  • Which REDCap version is installed, and what is the process and record for upgrades and patches?
  • Is there a validation package or summary for this installation, who produced it and for what intended use?
  • How are the audit trail, logging and data-change reasons configured, and who can see or export them?
  • How are electronic signatures handled, if at all, and is the signature meaning recorded?
  • How are accounts created, reviewed and disabled, and how is access segregated between studies?
  • What are the backup, restore and disaster-recovery arrangements, and how often are they tested?
  • Who supports study teams for regulated use, and is that support documented in an agreement?

Evidence

What to ask for and what a good answer looks like

A neutral evidence list that works for REDCap or any other tool. A missing item is a gap to close, not proof the tool is unsuitable.

Part 11 elementDocument to requestA good answer includes
Audit trailConfiguration description and a sample exportUser, timestamp, old and new value, reason; cannot be edited by users
Electronic signaturesSignature procedure and screenshotsUnique to one person, linked to the record, meaning stated
Access controlsUser management SOP and role listUnique accounts, role per study, periodic review, prompt removal
ValidationValidation plan and summary reportIntended use, risk assessment, test evidence, deviations resolved
Change controlUpgrade and patch logEach change assessed, tested and approved before release
Records retentionBackup and archive procedureRecords retrievable and readable for the required period
TrainingTraining recordsUsers trained before access to regulated data

See Part 11-aligned controls working before you decide

Build a study in the free sandbox and test the audit trail, edit checks and electronic signatures yourself. No credit card, and you pay only when you go live.

Test the controls in the free sandbox

Your options

What to do if the evidence is not there yet

There are three realistic paths. The first is to close the gaps where you are: work with the hosting institution to document configuration, commission a validation exercise for your intended use and write the procedures. This can be the right choice for a single investigator-initiated study with a strong local research computing team, and it is why the REDCap true-cost worksheet asks you to price validation and staff time rather than assume they are free.

The second is to scope the tool to what it was chosen for: use an institutional research database for surveys, registries and non-regulated studies, and use a regulated system when data will support a submission or be inspected. That is a sensible division of labour and many institutions run both.

The third is to use a platform where the controls are built in and the vendor supplies documentation to support your validation. Capture's audit trail is field-level, written by database triggers and append-only, with each row hash-chained to the previous one; electronic signatures re-authenticate the signer and carry a meaning statement; roles and row-level security limit access; and enterprise customers get documentation to support sponsor validation and user acceptance testing. You still validate for your intended use, which is the point of shared responsibility. See the REDCap alternatives page for the comparison criteria and the Capture vs REDCap comparison for a side-by-side view.

If you decide to move

You cannot import a REDCap project directly, but a data dictionary export lets the AI form builder draft the new forms for your review. Read how to migrate from REDCap and, if the study has already started, how to switch EDC vendors mid-study before you decide, because moving a running study is a different risk from starting a new one on the right tool.

Before regulated data goes in

A Part 11 readiness checklist for any data capture tool

Intended use written down

What data, which decisions, which submissions the system supports.

Hosting responsibilities mapped

Who runs servers, upgrades, backups and access, in writing.

Validation evidence on file

Plan, risk assessment, test results and summary for your use.

Audit trail reviewed

Export a sample and confirm user, time, old and new value and reason.

Signature process defined

Who signs what, with what meaning, and how identity is verified.

SOPs and training in place

Procedures and training records before first participant.

Regulatory adviser consulted

Your quality unit decides what is adequate; this page is not advice.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Is REDCap 21 CFR Part 11 compliant?

We do not assert either answer. Part 11 compliance depends on the software, how an institution hosts and configures it and the validation and procedures documented around it. Ask the hosting institution for its evidence and read the consortium's current documentation.

Is Capture 21 CFR Part 11 compliant?

Capture provides 21 CFR Part 11-aligned controls: a field-level append-only audit trail, electronic signatures with re-authentication, role-based access and approved-form locking. Compliance is shared with the sponsor, who validates the system for its intended use.

Who is responsible for Part 11 compliance, the vendor or the sponsor?

Both. The vendor provides controls and evidence; the sponsor is responsible for fitness for the study, procedures, training and validation for its intended use.

Can I use REDCap for a study that will go to the FDA?

That is for your institution, quality unit and regulatory advisers to decide after reviewing evidence. This page cannot answer it for you and is not legal advice.

What documents should I request from a hosting institution?

A validation summary, the audit trail and signature configuration, user management procedures, the upgrade and change-control log, and backup and recovery records.

Does Capture supply validation documentation?

Enterprise customers receive documentation to support sponsor validation and user acceptance testing. You test the system for your own intended use, free in the sandbox first.

Can I trial the audit trail and signatures before committing?

Yes. The free sandbox has every feature, including edit checks, electronic signatures and the audit trail, with no credit card and no time limit.

Check the controls yourself

Free sandbox with every feature. No credit card, and you pay only when you go live.

Test the controls in the free sandbox