Closed vs. open systems under 21 CFR Part 11
The definitions, exactly
A closed system under 21 CFR Part 11 is an environment in which system access is controlled by persons who are responsible for the content of the electronic records on the system; an open system is an environment in which it is not. 21 CFR §11.3(b)(4) (closed system), §11.3(b)(9) (open system)
Closed systems carry the controls of 21 CFR §11.10 — validation, copies, record protection, access limits, audit trails and the rest. Open systems must employ those same controls plus additional measures, such as document encryption and appropriate digital signature standards, as needed to ensure authenticity, integrity and, where relevant, confidentiality. 21 CFR §11.10; §11.30
The SaaS question everyone actually asks
Vendor-hosted does not mean open. The deciding question in the definition is who controls access to the system, not who owns the hardware or where it runs. A cloud application where accounts are created, scoped and removed by or on behalf of the regulated company — named users, a signed agreement, no anonymous access path — is controlled by the persons responsible for the records' content, which is the closed-system test.
An open system is the rarer case: records travelling over channels or stored in environments where people with no responsibility for the content control the access — public submission portals and unauthenticated exchange over the open internet are the classic examples.
What changes if your system really is open
- Encryption of the records in transit and, where warranted, at rest
- Digital signature standards appropriate to the exchange, so authenticity survives the open channel
- The classification itself documented, with the rationale — this is the part inspectors ask for first
The most common finding here is not a missing control but a missing decision: no record that the classification was ever made. Write it down once, with the reasoning, and the rest of the control set follows from it.
Frequently asked questions
Is a cloud or SaaS system automatically an open system?
No. The definition turns on who controls access, not on who hosts the software. A SaaS where accounts are administered by or for the regulated company — named users, contractual control, no anonymous access — meets the closed-system definition. Hosting location does not appear in the definition at all. 21 CFR §11.3(b)(4)
What extra controls does an open system need?
Everything a closed system needs, plus additional measures — document encryption and appropriate digital signature standards are the ones the rule names — as needed to ensure authenticity, integrity and confidentiality of the records. 21 CFR §11.30
Who decides whether our system is closed or open?
You do, and you document it. The classification is an assessment the regulated company makes per system, with the rationale recorded; the usual inspection finding is not a wrong answer but the absence of any recorded answer.
