Data Room Requirements for 21 CFR Part 11 and ISO 13485 Document Control
Virtual Data Room    71 views

Data Room Requirements for 21 CFR Part 11 and ISO 13485 Document Control

Published on July 28, 2026

The moment a regulated document leaves your quality system – a design history file excerpt going to a test lab, a validation protocol going to a contract manufacturer, a clinical report going to a notified body – it does not stop being regulated. The 21 CFR Part 11 requirements that govern your electronic records inside the eQMS follow the record out the door, and ISO 13485’s document-control clauses expect you to prove that what your partner worked from was the current, approved revision. Most teams have a validated system for storing regulated documents. Far fewer have a defensible system for sharing them.

That gap is where audits go wrong. An FDA investigator or a notified-body auditor rarely asks whether your eQMS keeps an audit trail – they ask how the specification got to the supplier, which revision the lab tested against, and who could see the file in between. If the honest answer is “email,” the strength of your internal document control stops mattering at your tenant boundary.

This guide translates the two regulations into a concrete requirements checklist for a data room – the controlled space where regulated documents meet external partners – and shows where each control has to live.

What 21 CFR Part 11 requirements actually say about shared records

Part 11 is short, and it is worth reading what it demands rather than what vendors claim about it. For closed systems, §11.10 requires, among other controls:

  • Validation of the system to ensure accuracy, reliability, and consistent intended performance (§11.10(a)) – which means every additional system you copy records into is an additional system to validate.
  • Accurate and complete copies of records, in both human-readable and electronic form, suitable for inspection and copying by the agency (§11.10(b)).
  • Protection of records so they remain accurate and retrievable throughout the retention period (§11.10(c)).
  • Limiting system access to authorized individuals (§11.10(d)) – not “people with the link.”
  • A secure, computer-generated, time-stamped audit trail that independently records the date and time of operator entries and actions, and that does not obscure previously recorded information (§11.10(e)). The audit trail must be retained at least as long as the record itself and be available for FDA review.
  • Authority checks to ensure only authorized individuals can use the system, sign records, or access the operation (§11.10(g)).

For open systems – and any sharing channel that runs over the public internet to an external party is closer to open than closed – §11.30 adds measures such as encryption to ensure authenticity, integrity, and confidentiality.

Then come the FDA electronic signature requirements. Signed electronic records must show the printed name of the signer, the date and time, and the meaning of the signature – authored, reviewed, approved (§11.50). Signatures must be inextricably linked to their records so they cannot be excised or copied to falsify another record (§11.70), and each signature must be unique to one individual (§11.100).

Notice what none of this says: it never says “buy a specific product.” Part 11 is a set of testable properties. Any data room you use for 21 CFR Part 11 document sharing either has these properties or it does not.

What ISO 13485 document control adds

ISO 13485:2016 approaches the same problem from the quality-system side. Clause 4.2.4 (control of documents) requires that documents are reviewed and approved before issue, that changes and current revision status are identified, that relevant versions of applicable documents are available at points of use, that documents remain legible and identifiable, that documents of external origin are identified and controlled, and that obsolete documents are prevented from unintended use.

Read “points of use” carefully. When your point of use is a testing lab, a sterilization contractor, or a CRO, the clause does not pause at your firewall. ISO 13485 document control means your external partner is working from the current approved revision, cannot stumble into a superseded one, and you can demonstrate both. Clause 4.2.5 (control of records) then demands records stay legible, identifiable, and retrievable for the retention period – including the records of who accessed what during the collaboration.

Between the two standards, the requirements for a document control medical device workflow converge on the same short list.

The 21 CFR Part 11 requirements checklist for a data room

Here is the combined checklist – what the regulations demand, and what to verify in any platform before regulated documents move through it.

#RequirementDriven byWhat to verify in the data room
1Access limited to named, authenticated individuals§11.10(d), (g); ISO 4.2.4Identity-based access (MFA-backed), per-partner rooms, no anonymous links
2Secure, time-stamped, tamper-evident audit trail§11.10(e); ISO 4.2.5System-generated log of view/edit/download/share; prior entries never overwritten; exportable for inspection
3One controlled baseline per documentISO 4.2.4; §11.10(b)Single current revision at the point of use; superseded versions withdrawn automatically, not by memory
4Obsolete-document preventionISO 4.2.4Access revocation that actually propagates – links, previews, downloads, cached copies
5Electronic signature integrity§§11.50-11.100Signatures show name, date/time, meaning; bound to the record; unique per individual
6Records protected for the retention period§11.10(c); ISO 4.2.5Retention policy applies to the shared copy and the audit trail, on your schedule – not the vendor’s
7Accurate, complete, inspectable copies§11.10(b)Human-readable export of records and their audit history on demand
8Open-system protections§11.30Encryption in transit and at rest; document-level protection that travels with the file
9Validation burden you can actually carry§11.10(a)Every separate platform holding regulated records is another validation and periodic review obligation
10Partner isolation§11.10(d) in practiceLab A cannot see lab B’s room, documents, or existence – competitors routinely serve the same submission

Items 9 and 10 are the ones evaluation checklists most often miss, and they are the two that decide the architecture question.

Where the controls live: the architecture question

There are two ways to give external partners a data room with these properties.

Copy records out to a standalone portal. A standalone VDR can check boxes 1, 2, 5, and 10. But the copy of your design history file now lives in the vendor’s cloud, behind the vendor’s identity model, on the vendor’s audit trail and retention clock – which strains boxes 6, 7, and 8, and it unambiguously fails box 9’s spirit: you have created a second regulated system to validate, monitor, and defend, for records that already live in a validated environment. We covered this trade-off in depth in Govern 365 vs. standalone VDRs for regulatory submissions.

Govern in place. The alternative is to keep the record in the Microsoft 365 tenant you already govern and grant partners scoped access to isolated rooms inside your boundary. That is the model Govern 365 is built on: per-partner rooms on SharePoint you own, identity and authority checks on Entra ID, a computer-generated, time-stamped audit trail in Microsoft Purview retained on your schedule, sensitivity labels that carry encryption and your AI-ingestion stance with the document, and one-action revocation that collapses access when the engagement ends. One system of record, one audit trail, one validation story – and the record never leaves the environment where your 21 CFR Part 11 compliance posture already lives.

A necessary caveat, because honest compliance language matters: no software is “Part 11 certified,” and any vendor claiming to be is telling you something about their marketing, not their audit trail. Part 11 compliance is a property of your system plus your procedures, training, and validation. What a platform can do is supply the technical controls – the audit trail, the authority checks, the signature linkage – so your procedures have something real to stand on. That is the standard to hold any Part 11 compliant software claim against.

The requirements are the easy part – the discipline is the product

Every requirement above fails silently under deadline pressure if meeting it requires extra effort: someone emails “just this once,” an old revision lingers in a partner’s download folder, an audit question takes three weeks of inbox archaeology. The real test of a data room is whether the compliant path is also the fastest path. When the controlled baseline, the isolated partner room, and the audit report are simply how sharing works – inside the tenant your team already uses – 21 CFR Part 11 requirements and ISO 13485 document control stop being a checklist you police and become a property of the system. That is the difference between documentation you defend and documentation that defends you.

See the controls running in a live tenant on the Govern 365 for Regulatory Affairs page, or book a demo and bring this checklist with you.

Frequently asked questions

What are the 21 CFR Part 11 requirements for a data room?

The core requirements are limiting access to authorized, authenticated individuals; a secure, computer-generated, time-stamped audit trail that never obscures prior entries and is retained as long as the record; the ability to produce accurate and complete copies for inspection; protection of records through the retention period; validation of the system; and, for signed records, electronic signatures that show name, date, time, and meaning and are inextricably linked to the record.

Does ISO 13485 apply to documents shared with suppliers and test labs?

Yes. Clause 4.2.4 requires relevant versions of applicable documents to be available at points of use and obsolete documents to be prevented from unintended use – and when your point of use is a supplier, lab, or contract manufacturer, that obligation extends to them. You need to demonstrate the partner worked from the current approved revision, which is exactly what a controlled data room baseline provides and email cannot.

Is there such a thing as 21 CFR Part 11 certified software?

No. FDA does not certify software for Part 11, so no product can accurately claim to be “Part 11 certified.” Compliance is achieved by a combination of a system’s technical controls (audit trails, access controls, signature linkage) and your organization’s procedures, training, and validation. Evaluate platforms on whether they supply the testable controls in §11.10 – and be wary of any vendor who claims the certificate exists.

Does a 21 CFR Part 11 audit trail need to cover external sharing?

Yes, in practice. §11.10(e) requires the audit trail to record operator entries and actions on electronic records – and actions by external parties on shared regulated records are exactly what an investigator will ask about. Your audit trail should show who viewed, downloaded, or modified the shared record and when, be tamper-evident, and be retained at least as long as the record itself.

Can email or a shared drive ever meet these requirements?

Not credibly. Email provides no authority checks, no controlled baseline, no tamper-evident audit trail, and no revocation – a file sent is a file gone. We scored the options in detail in Regulatory Data Room vs. Email & Shared Drives; email fails nearly every row of the checklist above.

Does using a standalone VDR create a second system to validate?

Yes. §11.10(a) requires validation of systems that hold regulated electronic records, so copying submission documents into a standalone portal adds a second environment – the vendor’s identity model, audit trail, and retention behavior – to your validation and periodic review scope. Governing the records in place inside your existing Microsoft 365 tenant avoids creating that second system.

Related reading

Take the next step

Book a Govern 365 regulatory data room demo and walk through the ten-point checklist against a live Microsoft 365 tenant – isolated partner rooms, the controlled baseline, Purview audit reporting, and one-action revocation, running on infrastructure you already validate. Prefer to read first? Pick up Secure by Design for the broader playbook on governed collaboration in Microsoft 365.

Niraj Tenany

President, CEO and Co-founder, Netwoven | Product Owner, Govern 365

38 years of Enterprise Technology experience. Worked on early version of SharePoint at Microsoft in 1999. Also leads the AI and Security practice.

Author of Secure by Design: How Modern Organizations Collaborate Without Compromise, the executive playbook for delivering VDR-grade outcomes inside Microsoft 365.

I wrote this book after watching enterprises use a category of software called Virtual Data Rooms (VDR) for M&A types of transactions only, whereas the broader category of secure collaboration needed organizations to think about Virtual Data Rooms in a broader context to be able to secure their crown jewels from all across the organizations. This book frames VDR from a software category to VDR as an outcome.

Get the book →

Leave a comment

Your email address will not be published. Required fields are marked *

4000 Pimlico Drive, Suite 114-103 Pleasanton, CA 94588
Linkedin Twitter Facebook Youtube
 
Microsoft
Govern 365 - Member of Microsoft Intelligent Security Association
10 minutes
Request a Demo