Skip to main content
v2026.11,610 entries · CC-BY 4.0

Research administration

Electronic signature software

A research office signs subawards, material transfer agreements, NDAs, consultancy contracts and data-sharing agreements constantly. Most of that does not need a specialist regulated system — but some of it does, and knowing which is which saves both money and a compliance problem.

Written and maintained by CASRAI Editorial Board

Last updated

Our pick for research officesVerified 18 August 2026

Sign.Plusunlimited signature requests at $19.99/month

From $9.99/mo · unlimited requests at $19.99/mo

The pricing model is what makes the difference for a research office. Most e-signature vendors meter envelopes, so a busy month of subaward paperwork costs more than a quiet one and someone ends up rationing. Sign.Plus gives unlimited signature requests from the Professional tier at $19.99/month, with eIDAS support and audit trails on every plan including the free one. For general research-office contracting that is the right shape of product at roughly a third of the enterprise incumbents' list price.

HIPAA compliance with a BAA is Enterprise-tier only. If you are signing anything containing PHI, that is the tier — do not assume a lower plan covers it.

Editorial disclosure: Some links on this page are CASRAI referral links. If you sign up through one, CASRAI may earn a commission at no extra cost to you — this helps fund our nonprofit mission. We only recommend tools our editorial team has independently researched. Read our full disclosure policy →

At a glance

Sign.Plus plans

Verified from the vendor pricing page, 18 August 2026

DimensionFreePersonalProfessionalBusinessEnterprise
Price / month$0$9.99$19.99$29.99$49.99
Price / year$119.99$239.99$359.99$599.99
Signature requests3 total10/moUnlimitedUnlimitedUnlimited
Templates1510UnlimitedUnlimited
Audit trailsYesYesYesYesYes
eIDAS supportYesYesYesYesYes
HIPAA + BAANoNoNoNoYes

Annual billing works out at roughly two months free across the paid tiers. Audit trails and eIDAS support being on every tier — including free — is unusual in this category and is the main reason the entry plans are genuinely usable.

The legal basics

What makes an electronic signature valid

The starting point is more permissive than people expect. In the United States, the federal ESIGN Act and the state-level UETA establish that a signature may not be denied legal effect solely because it is electronic. In the EU and UK, the eIDAS Regulation does the same and adds a tiered structure. Most commercial and research contracting sits comfortably within these frameworks with an ordinary electronic signature.

What actually matters in a dispute is not the appearance of the signature but the evidence around it: that the signer intended to sign, that they consented to transact electronically, that the record has not been altered since, and that you can associate the signature with a specific person. This is why the audit trail is the substantive feature — timestamps, IP address, email verification, document hash, and the sequence of events. A pasted image of a handwritten signature has none of that and is much weaker evidence than a properly logged electronic one.

eIDAS distinguishes three levels. A simple electronic signature is the baseline and is what most platforms produce. An advanced signature (AdES) must be uniquely linked to the signer, capable of identifying them, created using means under their sole control, and detect any subsequent change. A qualified signature (QES) is an advanced signature made with a qualified device and a certificate from a qualified trust service provider, and it carries the same legal effect as a handwritten signature across the EU. Almost nothing a research office signs requires QES; a few member-state-specific formalities do, and those are worth checking individually rather than assuming either way.

Sorting the paperwork

What a research office actually signs, and what each needs

Standard electronic signature is fine for: subaward and consortium agreements, material transfer agreements, non-disclosure agreements, consultancy and advisory contracts, data-sharing agreements, equipment and service quotations, letters of support, collaboration agreements, and the great majority of internal approvals.

Needs the HIPAA tier (BAA in place): anything where the document itself contains protected health information. This is less common in contracting than in study operations — a business associate agreement naming no individuals is not itself PHI — but medical records releases, participant correspondence and some site-level trial documents are.

Needs a Part 11-validated system: records that are created, modified, maintained or transmitted under FDA predicate rules — regulated clinical trial records, and electronic records submitted to or subject to FDA inspection. See below; this is a much narrower category than vendors imply.

Needs a purpose-built eConsent system: electronic informed consent for clinical trials. Do not improvise this with a general e-signature tool.

May need a qualified signature (QES): occasional member-state formalities in EU jurisdictions, certain property and employment instruments, and anything a specific counterparty's legal team insists on. Check the individual case.

Frequently misunderstood

21 CFR Part 11, and when it actually applies

Part 11 is the FDA's rule on electronic records and electronic signatures. It is invoked constantly in vendor marketing and applies far less often than that implies.

Part 11 applies to records required by an FDA predicate rule that are kept in electronic form, and to electronic signatures on such records. In practice that means regulated clinical trial documentation, manufacturing and laboratory records under GxP, and submissions to the agency. It does not apply to a subaward agreement between two universities, an MTA, an NDA, or an internal approval workflow — none of those are records required by an FDA predicate rule.

Where it does apply, the requirements go well beyond the signature: validation of the system for its intended use, secure computer-generated time-stamped audit trails, operational and authority checks, the ability to generate accurate and complete copies for inspection, record retention throughout the retention period, and controls over the signature components themselves. Crucially, compliance is a property of your validated implementation, not of the software. A vendor can supply Part 11-capable features; only your organisation can validate a system for its intended use and maintain it in a validated state.

The practical implication: if you are in Part 11 scope, you need a system your quality function has validated and documented, with the vendor documentation to support it — not a general-purpose e-signature subscription. If you are not in scope, do not buy a regulated system for contracting work; it is expensive and it will slow your office down. Sign.Plus does not advertise Part 11 support on its pricing page, and for general research-office contracting that is simply not the relevant question.

Do not improvise this

Electronic informed consent is a separate category

The most consequential mistake in this area is using a general e-signature product for clinical trial informed consent because it is already licensed and the study is behind schedule.

eConsent is not a signature problem. It is a comprehension problem with a signature at the end. Regulators and ethics committees expect an eConsent process to present information in a way the participant can genuinely understand, often with multimedia and comprehension checks; to allow questions and a conversation with the study team; to handle re-consent when the protocol changes; to accommodate remote and impaired participants and legally authorised representatives; and to produce records suitable for inspection. FDA and OHRP guidance addresses this specifically, and ethics committees will ask how the process — not just the signature — was implemented.

A general e-signature tool does none of that. It puts a signature block on a PDF. If your study needs eConsent, budget for a purpose-built system and take it through ethics review as part of the protocol. If your study only needs to get an MTA signed, do not buy an eConsent platform to do it.

Procurement

What to check before committing

  • How is it metered? Per-envelope pricing punishes exactly the months a research office is busiest. Unlimited-request plans remove the incentive to ration, which is a real behavioural effect and not just an accounting one.
  • What is in the audit trail, and can you export it? You need to be able to hand a complete certificate of completion to a counterparty or an auditor without contacting the vendor.
  • Where is data stored? If you are in the EU or UK, or signing with partners who are, data residency and the transfer mechanism will come up in your DPO review. Settle it before rollout.
  • Do you need templates and bulk send? An office sending the same MTA form fifty times a year gets more value from templates than from any other feature.
  • Does it integrate with where documents already live? A signature tool that requires manual download and re-upload adds a step to every transaction.
  • What happens to documents if you stop paying? Ask directly about export and retention on cancellation. Signed agreements have retention periods measured in years, sometimes decades.
  • Will counterparties need an account? Requiring external signers to register is a real source of delay.

Ready to move

Test it on real paperwork before committing

The free tier includes three signature requests with full audit trails — enough to run an actual MTA or subaward through and see whether your counterparties find the signing experience acceptable, which is the thing that decides adoption.

From $9.99/mo · unlimited requests at $19.99/mo

Try Sign.Plus freeOpens on the vendor's site · CASRAI referral link

Frequently asked questions

Common questions

Are electronic signatures legally binding?
Yes, in most jurisdictions and for most documents. The US ESIGN Act and UETA, and the EU/UK eIDAS Regulation, establish that a signature is not invalid merely because it is electronic. What matters in a dispute is the supporting evidence — intent to sign, consent to transact electronically, document integrity, and an audit trail linking the signature to a person.
How much does electronic signature software cost?
Sign.Plus runs from a free tier (3 requests) through Personal at $9.99/month, Professional at $19.99/month with unlimited requests, Business at $29.99/month, and Enterprise at $49.99/month with HIPAA and a BAA. Verified 18 August 2026. Enterprise incumbents typically list considerably higher for comparable volume.
Does a research office need a 21 CFR Part 11 compliant system?
For contracting work, almost certainly not. Part 11 applies to records required by an FDA predicate rule — regulated clinical trial documentation, GxP records, FDA submissions. Subawards, MTAs, NDAs and internal approvals are not in scope. If you are in scope, you need a system your quality function has validated, because Part 11 compliance is a property of your implementation rather than of the software.
Can I use e-signature software for clinical trial informed consent?
Not a general-purpose one. eConsent is a regulated process covering comprehension, the opportunity to ask questions, re-consent when protocols change, and inspection-ready records — not just a signature block. Use a purpose-built eConsent system and take it through ethics review as part of the protocol.
What is the difference between simple, advanced and qualified electronic signatures?
Under eIDAS, a simple signature is the baseline most platforms produce. An advanced signature must be uniquely linked to the signer, identify them, be created under their sole control, and detect later changes. A qualified signature adds a qualified device and a certificate from a qualified trust service provider, and has the same legal effect as a handwritten signature across the EU. Most research contracting needs only the simple level.
Is Sign.Plus HIPAA compliant?
On the Enterprise plan at $49.99 per month, which includes a Business Associate Agreement. The Free, Personal, Professional and Business tiers do not, so any document containing protected health information needs the Enterprise tier. Verified 18 August 2026.
What should we look for in an audit trail?
Timestamps for each event, the signer's IP address, email verification, a document hash proving the record has not been altered, and the full sequence of send, view and sign events. You should also be able to export a complete certificate of completion yourself, without contacting the vendor.

Follow CASRAI

We publish research-administration guidance, standards updates and independent tool reviews. Follow along wherever you already read.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →