Skip to main content
v2026.11,772 entries · CC-BY 4.0

Direct comparison

Open vs Closed Systems: 21 CFR Part 11

The test is who controls access, not internet-facing vs. on-site. What §11.10 and §11.30 each require, and the misclassification labs actually make.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · included with Regulatory Radar

Ask about Open vs Closed Systems: 21 CFR Part 11

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do Closed System, Open System compare side by side?

The table below compares Closed System, Open System across 6 procurement-relevant dimensions, from definition (21 cfr 11.3) through common misclassification.

Side-by-side comparison

DimensionClosed SystemOpen System
Definition (21 CFR 11.3)System access is controlled by the persons responsible for the content of the electronic records on the system.System access is not controlled by the persons responsible for the content of the electronic records on the system.
The actual determinantWho administers access — the lab’s own responsible persons, regardless of hosting location or network reachability.Access is administered by someone other than the persons responsible for the record content — regardless of whether the system is technically internet-facing.
Baseline controls required (§11.10)Full (a)–(k): validation, accurate copies, record protection, access limitation, audit trails, operational/authority/device checks, personnel qualification, accountability policies, documentation controls.Same full (a)–(k) baseline, in addition to §11.30.
Additional controls required (§11.30)None beyond §11.10.Procedures and controls ensuring authenticity, integrity, and (as appropriate) confidentiality from creation to receipt — specifically document encryption and appropriate digital signature standards, as necessary under the circumstances.
Typical lab exampleA validated, vendor-hosted LIMS or ELN reached over the internet but gated by institutional SSO and an access list the lab’s own QA function administers.A system where an external party (a CRO, a regulator submission portal, an uncontrolled collaborator account) can access or modify records without the lab’s responsible persons controlling that access.
Common misclassificationWrongly treated as “open” purely because it is internet-facing or cloud-hosted, triggering unnecessary §11.30 encryption/signature work.Wrongly treated as “closed” because it resembles an old on-premises system, skipping the access-control question and leaving genuine §11.30 gaps uncaught until an inspection.

Common questions

Common questions about Closed System vs Open System

Is a cloud-hosted LIMS automatically an open system under 21 CFR Part 11?

+

No. Hosting location and internet-reachability are not the test. A cloud-hosted LIMS is a closed system if the lab’s own responsible persons control who has access to it — for example, via institutional SSO and an access list the lab’s QA function administers — even though it is reached over the public internet.

What specifically does §11.30 require that §11.10 does not?

+

Section 11.30 requires open systems to employ procedures and controls, including document encryption and appropriate digital signature standards, to ensure the authenticity, integrity, and (as appropriate) confidentiality of records from creation to receipt — on top of, not instead of, the full §11.10 baseline.

Can a system be closed for some users and open for others?

+

The classification is a property of the system’s access-control arrangement, not of any one user. If any class of user can access or modify the records without the responsible persons controlling that access, the relevant access path is open, and §11.30 controls need to cover it — even if most users go through a controlled, closed path.

Does classifying a system as closed mean it is exempt from encryption or strong authentication?

+

No. §11.10 already requires access limitation, authority checks, and device checks for every system, closed or open. Closed classification means §11.30’s additional encryption/digital-signature requirement does not independently apply — it does not lower the §11.10 baseline.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.