cGen is launching soon — reserve your spot for a demo

Electronic Signature Software

Part 11 electronic signature software for controlled GxP records

Not every e-signature product is a Part 11 e-signature product. Consumer signature tools are optimised for convenience; Part 11 requires the opposite — re-authentication, meaning, reason, and non-repudiation. cGen's e-signature engine is built for controlled GxP records.

Re-authentication per signature

The user re-enters credentials on every signature event — not just at session start, and not "remember me for 24 hours."

Meaning of signature

Authored, Reviewed, Approved, Witnessed, Rejected — the meaning is explicit and travels with the printed record.

MFA on the signature

MFA on the signature event, not just the login. A stolen session cannot sign a controlled record.

What Part 11 e-signature software has to do

21 CFR Part 11 §11.200 defines the requirements for electronic signatures based on biometrics and non-biometrics. In non-biometric practice — which covers ~99% of GxP e-signature use — the signature must consist of at least two distinct identification components (typically an identification code and a password), and the first signature in a continuous controlled session must use both while subsequent signatures in the same session may use only one.

On top of these baseline requirements, defensible e-signature practice today expects MFA on the signature event and a documented meaning attached to each signature. cGen implements both.

What consumer signature tools cannot do (that cGen can)

DocuSign, Adobe Sign, and their peers are excellent for consumer contracts and HR paperwork. They are not designed for GxP-controlled records. Specifically:

  • They do not re-authenticate on every signature event — they trust the session
  • They do not enforce meaning of signature or reason-for-change
  • They do not integrate with the GxP audit trail, so the signature event and the record change are captured separately
  • They do not enforce MFA on the signature independently of the login
  • They do not produce a signature hash bound to the record content — the signature is on the wrapper (PDF), not the record
  • They do not carry the ALCOA++ markers inspectors look for on signed records

How cGen fits

Built for this exact problem

cGen's e-signature engine sits inside the GxP record layer, not on top of it. Every signature is bound to a specific version of a specific controlled record, with a hash of the record content and the signature event captured in the same audit-trail entry. Rebinding is impossible without breaking the chain.

FAQ

Electronic Signature Software — frequently asked questions

DocuSign provides a compliance package that can meet Part 11 requirements for specific document workflows, but it is not designed for controlled GxP records at the record level. For URS/FRS/IQ/OQ/PQ and other lifecycle validation records, a purpose-built Part 11 e-signature engine embedded in the CSV platform is the defensible answer.
cGen

cGen — AI-native computer system validation software for life sciences. Design, validate, and continuously monitor your GxP-regulated systems in one inspection-ready environment.

contact@compligen.ai(833) 916-CGEN(833-916-2436)

Merchandise Mart Plaza, Suite 470, Chicago, IL 60654

Compligen - cGen AI-native GxP suite by compligen | Product Hunt

Product

Resources

Company

© 2026 compligen.AI. All rights reserved.

21 CFR Part 11 GAMP 5 SOC 2 Type II EU GMP Annex 11

We value your privacy

We use analytics cookies to understand how you use our site. No advertising or tracking cookies.