Direct comparison
Open vs Closed Systems: 21 CFR Part 11
The test is who controls access, not internet-facing vs. on-site. What §11.10 and §11.30 each require, and the misclassification labs actually make.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · included with Regulatory Radar
Ask about Open vs Closed Systems: 21 CFR Part 11
Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.
150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do Closed System, Open System compare side by side?
The table below compares Closed System, Open System across 6 procurement-relevant dimensions, from definition (21 cfr 11.3) through common misclassification.
Side-by-side comparison
| Dimension | Closed System | Open System |
|---|---|---|
| Definition (21 CFR 11.3) | System access is controlled by the persons responsible for the content of the electronic records on the system. | System access is not controlled by the persons responsible for the content of the electronic records on the system. |
| The actual determinant | Who administers access — the lab’s own responsible persons, regardless of hosting location or network reachability. | Access is administered by someone other than the persons responsible for the record content — regardless of whether the system is technically internet-facing. |
| Baseline controls required (§11.10) | Full (a)–(k): validation, accurate copies, record protection, access limitation, audit trails, operational/authority/device checks, personnel qualification, accountability policies, documentation controls. | Same full (a)–(k) baseline, in addition to §11.30. |
| Additional controls required (§11.30) | None beyond §11.10. | Procedures and controls ensuring authenticity, integrity, and (as appropriate) confidentiality from creation to receipt — specifically document encryption and appropriate digital signature standards, as necessary under the circumstances. |
| Typical lab example | A validated, vendor-hosted LIMS or ELN reached over the internet but gated by institutional SSO and an access list the lab’s own QA function administers. | A system where an external party (a CRO, a regulator submission portal, an uncontrolled collaborator account) can access or modify records without the lab’s responsible persons controlling that access. |
| Common misclassification | Wrongly treated as “open” purely because it is internet-facing or cloud-hosted, triggering unnecessary §11.30 encryption/signature work. | Wrongly treated as “closed” because it resembles an old on-premises system, skipping the access-control question and leaving genuine §11.30 gaps uncaught until an inspection. |
Common questions
Common questions about Closed System vs Open System
Is a cloud-hosted LIMS automatically an open system under 21 CFR Part 11?
+
No. Hosting location and internet-reachability are not the test. A cloud-hosted LIMS is a closed system if the lab’s own responsible persons control who has access to it — for example, via institutional SSO and an access list the lab’s QA function administers — even though it is reached over the public internet.
What specifically does §11.30 require that §11.10 does not?
+
Section 11.30 requires open systems to employ procedures and controls, including document encryption and appropriate digital signature standards, to ensure the authenticity, integrity, and (as appropriate) confidentiality of records from creation to receipt — on top of, not instead of, the full §11.10 baseline.
Can a system be closed for some users and open for others?
+
The classification is a property of the system’s access-control arrangement, not of any one user. If any class of user can access or modify the records without the responsible persons controlling that access, the relevant access path is open, and §11.30 controls need to cover it — even if most users go through a controlled, closed path.
Does classifying a system as closed mean it is exempt from encryption or strong authentication?
+
No. §11.10 already requires access limitation, authority checks, and device checks for every system, closed or open. Closed classification means §11.30’s additional encryption/digital-signature requirement does not independently apply — it does not lower the §11.10 baseline.








