Most Part 11 guidance is written as if a single company owns the whole manufacturing process: one facility, one quality unit, one e-signature system. That's not how a lot of drug products actually get made. A sponsor owns the product license, a contract manufacturer runs the line, and somewhere in between a batch record gets signed by people who work for two different employers, sometimes on two different systems.
Electronic signatures for contract manufacturing raise a question that a single-site GMP operation never has to answer: when the record and the signature cross a company boundary, whose Part 11 obligation is it? The short answer is both companies'. The longer answer is what this guide covers: what the regulation actually says about manufacturing done under contract, where signature authority gets assigned in the quality agreement, and what a CDMO relationship needs from an e-signature platform that a single-site operation doesn't.
Key Takeaways
- 21 CFR 210.1 ties CGMP compliance to the manufacture, processing, packing, or holding of a drug, not to which company's building it happened in. A contract manufacturer's signatures are subject to the same Part 11 controls as the sponsor's own.
- 21 CFR 211.22(d) requires quality unit responsibilities and procedures to be in writing. That's the regulatory anchor for the written quality agreement most CDMO relationships already use, and it's where signature authority for batch records should be spelled out.
- 21 CFR 211.68(b) requires that changes to master production and control records be made only by authorized personnel, regardless of which company employs them.
- 21 CFR 211.192 requires the quality control unit to review and approve production and control records before release. In a CDMO relationship, this creates two review events on the same record: the contract facility's release and the owner's disposition decision.
- 21 CFR 211.180 allows records to be kept off-site if they can be immediately retrieved by electronic means, but they still have to be readily available for inspection at the establishment where the manufacturing activity occurred.
- A CDMO operating its own e-signature system needs its own 21 CFR 11.100(c) certification letter to FDA, the same certification a sponsor or CRO would need to file.
Why Contract Manufacturing Complicates Part 11 Signature Compliance
A batch record produced under a contract manufacturing arrangement usually passes through signature events at both organizations. An operator at the CDMO signs off on a processing step. A CDMO quality reviewer signs the batch release. The owner's own quality unit then makes the final disposition decision to release the product to market. That's at minimum three signature events, two employers, and potentially two different software systems, all attached to the same record.
Part 11 doesn't have a special section for this. It regulates the record and the signature, not the org chart. But that also means neither party gets to assume the other one is handling compliance. If the CDMO's system doesn't produce a Part 11 compliant audit trail, the owner inherits that gap the moment it accepts the batch record as the basis for release. If the owner's platform can't ingest the CDMO's signed record without breaking the signature-to-record link, the same problem shows up from the other direction.
The Regulatory Basis: CGMP Follows the Activity, Not the Building
21 CFR 210.1(a) states that the regulations in Part 211 (along with parts 213, 225, and 226) "contain the minimum current good manufacturing practice" for methods, facilities, and controls used in manufacturing, processing, packing, or holding a drug. Section 210.1(b) is the enforcement hook: failure to comply "in the manufacture, processing, packing, or holding of a drug" renders the drug adulterated, and exposes both the product and the responsible party to regulatory action.
Neither subsection carves out an exception for who performed the activity. CGMP attaches to the activity of manufacturing a drug, wherever and by whomever it happens. A CDMO performing a manufacturing step is doing exactly the activity 210.1 describes, which means its records and signatures are subject to the same Part 11 requirements as if the owner had performed the step in its own facility. There's no lighter version of Part 11 for outsourced work.
The Quality Agreement Is Where Signature Authority Gets Assigned
21 CFR 211.22(d) requires that "the responsibilities and procedures applicable to the quality control unit shall be in writing," and that those written procedures be followed. Most sponsor-CDMO relationships satisfy that requirement, in part, through a written quality agreement that defines each party's CGMP roles. That's a sensible place to put signature authority in writing too, because a batch record moving between two organizations needs an unambiguous answer to a basic question: who is authorized to sign which step, and who has final release authority.
21 CFR 211.68(b) adds the record-integrity side of the same requirement: "Appropriate controls shall be exercised over computer or related systems to assure that changes in master production and control records or other records are instituted only by authorized personnel." That control has to hold across the company boundary. If the CDMO's system lets someone outside the agreed signature roster make a change to a master record, the fact that the change happened on the CDMO's side of the relationship doesn't limit the owner's exposure.
In practice, a quality agreement that covers electronic signatures should specify, at minimum, which named roles at the CDMO hold signing authority for which record types, how that authority is verified and updated between the two companies (not just within one company's own system), and what happens to signature authority when someone changes roles or leaves either organization. This is the same kind of dual-site accountability problem sponsors already work through with CROs on the clinical side. See our guide on electronic signatures for CROs for the parallel framework on the research side of the business.
Batch Record Review Across Two Companies' Quality Units
21 CFR 211.192 requires that "all drug product production and control records... shall be reviewed and approved by the quality control unit to determine compliance with all established, approved written procedures before a batch is released or distributed." In a contract manufacturing arrangement, this creates two distinct review events on the same record set: the CDMO's quality unit reviewing and approving its own manufacturing operations, and the owner's quality unit making the final release decision based on what the CDMO provides.
Both reviews are real signature events, and both need to be visible in the record. An owner's release signature is only as good as the CDMO's underlying record. If the owner's e-signature platform treats the CDMO's signed batch record as an opaque PDF attachment rather than a record with a preserved, verifiable signature and audit trail, the owner's own release signature is being applied to something it can't actually verify. That's the same tamper-evident linking problem we cover in our guide on the GMP batch release sign-off workflow, extended across a company boundary instead of a single quality unit.
Keeping Records Off-Site Without Losing Inspection Readiness
Contract manufacturing usually means the manufacturing record physically originates at a facility the owner doesn't operate. 21 CFR 211.180 addresses off-site records directly: records "that can be immediately retrieved from another location by computer or other electronic means shall be considered as meeting" the retention requirements of that section. But the same section also requires that records be "readily available for authorized inspection during the retention period at the establishment where the activities described in such records occurred."
Read together, those two provisions mean an owner can rely on the CDMO's system to house the original signed record, as long as the record is immediately retrievable electronically and still available for inspection at the facility where the manufacturing actually happened. What this rules out is a workflow where the only accessible copy of a signed batch record sits behind the owner's login, unreachable to an investigator inspecting the contract facility. The signature architecture, not just the storage location, has to support both companies producing the same verifiable record on demand.
Signature Attribution and Access Controls Across Two Organizations
21 CFR 11.10 sets out the closed-system controls that apply to whatever platform holds the record, regardless of which company operates it: validation, tamper-evident audit trails, and limiting access to authorized individuals (11.10(a), (d), (e)). Section 11.10(g) requires "authority checks to ensure that only authorized individuals can use the system, electronically sign a record, [or] access the operation." Section 11.100(a) requires that "each electronic signature shall be unique to one individual and shall not be reused by, or reassigned to, anyone else," and 11.100(b) requires identity verification before an organization assigns anyone a signature credential.
When two organizations share a signing platform, unique-per-individual has to mean unique across both companies' user bases, not just unique within each company's own directory. A shared platform that lets a CDMO operator and an owner's QA reviewer both hold the same generic "QA" login, even briefly, breaks 11.100(a) for both parties. And 11.200's two-component authentication requirement at the moment of signing applies the same way to a CDMO's operator as it does to an owner's own staff. There's no reduced standard for the party that isn't the license holder.
Does the CDMO Need Its Own Non-Repudiation Letter?
21 CFR 11.100(c) requires that "persons using electronic signatures shall... certify to the agency that the electronic signatures in their system... are intended to be the legally binding equivalent of traditional handwritten signatures." That certification, commonly called a non-repudiation letter, attaches to the organization operating the signing system, not to the product or the study.
If a CDMO operates its own e-signature platform for batch records, and that platform is a system the CDMO controls rather than one the owner extends to it, the CDMO is the party using electronic signatures under 11.100(c) and needs its own certification letter on file with FDA. If instead the owner's platform is extended to CDMO personnel as authorized users of the owner's own system, the owner's existing letter may already cover it, but that needs to be confirmed rather than assumed. Our guide on the Part 11 non-repudiation letter covers how to determine who needs to file and what the letter needs to say.
Checklist: Structuring Electronic Signature Terms in a CDMO Quality Agreement
Before signing off on a quality agreement that will govern electronic batch records across two organizations, confirm the agreement addresses each of these:
- Which named roles at each organization hold signing authority for which record types, and how that roster is kept current between both companies.
- Whether the CDMO and the owner will use one shared e-signature platform or two separate systems, and if two, exactly how a signed record moves from one to the other without breaking the signature-to-record link.
- Which organization holds the 21 CFR 11.100(c) non-repudiation letter for the system actually in use, and confirmation that letter is on file.
- How the owner will independently verify the CDMO's audit trail, not just receive a summary or a signed PDF, before making a release decision under 211.192.
- Where the original signed record physically resides, and confirmation it's retrievable for inspection at the facility where the manufacturing activity occurred, per 211.180.
- What happens to signing credentials when personnel at either organization change roles, and how quickly access is revoked.
- Which party is responsible for the platform's IQ/OQ/PQ validation documentation, and whether the owner has reviewed it directly rather than relying on the CDMO's self-attestation.
A quality agreement that leaves these questions to be worked out informally is the kind of gap FDA investigators find during a for-cause inspection at a contract facility, when the sponsor isn't in the room to explain what was intended. For the broader framework these questions sit inside, see our guides on e-signatures for pharmaceutical QA and GxP compliant electronic signatures.
Klyverity's signing architecture supports multi-organization access with role-based signature authority, per-signing-event authentication, and an audit trail that preserves the full signature-to-record chain when a document moves between organizations. If you're structuring or auditing e-signature terms for a contract manufacturing relationship, request a demo to see how cross-organization signature attribution works in practice.
FAQ
Does 21 CFR Part 11 apply to a contract manufacturer's electronic signatures?
Yes. 21 CFR 210.1 ties CGMP obligations to the activity of manufacturing, processing, packing, or holding a drug, not to which company performs it. A contract manufacturer performing any of those activities is subject to the same Part 11 requirements for its electronic records and signatures as the product owner would be if it performed the work itself.
Who is responsible for Part 11 compliance in a CDMO relationship, the owner or the contract manufacturer?
Both are. The contract manufacturer is responsible for its own system meeting Part 11 controls and for its own signature authority being properly assigned and verified. The owner is responsible for confirming, not just assuming, that the CDMO's system and signature architecture actually satisfy those controls before relying on the CDMO's records for a release decision under 21 CFR 211.192.
Where should electronic signature requirements be documented for a CDMO relationship?
In the written quality agreement between the owner and the contract facility. 21 CFR 211.22(d) requires quality unit responsibilities and procedures to be in writing, and signature authority for batch records is a natural extension of that requirement. The agreement should name which roles at each organization can sign which record types and specify how the owner will verify the CDMO's audit trail before release.
Does a contract manufacturer need its own 21 CFR 11.100(c) certification letter?
If the contract manufacturer operates its own e-signature system rather than using the owner's platform as an authorized user, yes. The certification under 11.100(c) attaches to the organization operating the signing system. If CDMO personnel are instead authorized users on the owner's own platform, the owner's existing letter may cover it, but that coverage should be confirmed explicitly rather than assumed.
Can records stay physically at the contract manufacturer's facility and still meet Part 11 and GMP requirements?
Yes, provided the records can be immediately retrieved electronically and remain readily available for inspection at the facility where the manufacturing activity occurred, per 21 CFR 211.180. What isn't acceptable is a signed record that's only accessible through the owner's system, with no way for an investigator at the contract facility to retrieve it during an inspection there.