The full power of TDengine, now free forever for up to 5,000 tags.

Explore More

REGULATED INDUSTRIAL DATA

Technical controls supporting
21 CFR Part 11

Evaluate the controls behind your industrial data. Explore how TDengine supports traceability, controlled access, and record protection in a Part 11-governed system.

TDengine TSDB-Enterprise

TDengine IDMP

Control matrix, requirements mapping, and evaluation guidance in one document.

*Technical controls are one part of compliance. Compliance depends on your complete validated system, intended use, configuration, infrastructure, procedures, and training.

Evaluate the Controls Your Records Depend On

Documented capabilities across TDengine TSDB-Enterprise and IDMP.

Confirm the release, license, and configuration for your intended use.

Audit trails & traceability

Capture who changed what, when, and why. Review before-and-after details and export audit records.

Enable audit logging before use. Written IDMP audit records cannot be edited or deleted through the application.

Watch introduction video

Identity & access

Apply individual accounts, role-based permissions, and site boundaries. Integrate enterprise identity and step-up MFA.

Configure and validate roles, identity integrations, and which operations require additional verification.

Watch introduction video

Controlled changes

Track configuration history, review proposed changes, and publish approved versions through governed workflows.

Documented GPG signatures cover version-controlled IDMP configuration and model commits.

Watch introduction video

Record retention & retrieval

Use UTC timestamps, configurable retention, archive storage, and retrieval tools to support access to historical records.

Validate record-copy completeness and retention. Trusted time synchronization is managed in your infrastructure.

Watch introduction video

Security & recovery

Configure encryption, TLS, backups, point-in-time recovery, high availability, and disaster recovery for your deployment.

Capabilities depend on edition and configuration. Test restoration, failover, and recovery against your requirements.

Watch introduction video

Preserve Site Boundaries. Govern Shared Visibility

Plan how data, identities, and infrastructure work together across your system.

Manufacturing site 1

Plant data sources

Local TDengine / isolated database

Manufacturing site 2

Plant data sources

Local TDengine / isolated database

Manufacturing site 3

Plant data sources

Local TDengine / isolated database

Controlled central visibility

Approved synchronization or governed queries · Reporting · Retained audit history

Enterprise identity and access

Customer-managed time sources

Retention, backup, and recovery

*Illustrative deployment pattern. Physical and logical separation require different design and validation decisions.

Connect Each Requirement to Evidence

Start with the product contribution. Then define the configuration, tests, and operating procedures your system needs.

Part 11 requirementTDengine contributionEvaluation boundary
§11.10(d) · Limited accessAccounts, roles, site boundaries, and authenticationAvailable with configuration
§11.10(e) · Audit trailsAttributable, time-stamped audit records and change detailsAvailable with configuration
§11.10(c) · Record protectionRetention, archive storage, backup, and recoveryAvailable with configuration
§11.50 / §11.70 · SignaturesGPG signatures linked to configuration commitsScope confirmation required

Selected examples, not a complete compliance assessment.

Read the full mapping

What TDengine contributes

Documented technical capabilities for access, audit, configuration control, record protection, and recovery that can be tested within your system.

What your organization establishes

Intended use, applicable record requirements, validated configuration, connected-system controls, SOPs, training, and ongoing review.

Take a Closer Look at the Evidence

Watch the overview, then use the guide to structure your technical evaluation.

How TDengine supports regulated data environments

Video overview · Pharmaceutical manufacturing context

See the controls explained

A walkthrough of auditability, identity, authentication, record protection, and recovery, with the complete-system compliance boundary explained.
 

Watch on YouTube

Technical Controls Supporting 21 CFR Part 11

Version 1.1 · September 2026 · 12 pages

Review the full technical guide

Explore the control matrix, requirements mapping, deployment considerations, limitations, and recommended evaluation and validation plan.

Download the Controls Guide

Before You Evaluate

Does TDengine make a deployment Part 11 compliant?

No. TDengine provides supporting technical controls. Compliance depends on the complete validated system, including intended use, configuration, procedures, infrastructure, training, and operational controls.

Are all controls enabled and included by default?

No. Product release, edition, license, and configuration matter. IDMP audit logging must be enabled before use, and some interfaces require explicit TLS configuration. Confirm the baseline for your deployment.

Do electronic signatures cover every regulated record?

No. The documented GPG workflow applies to version-controlled IDMP configuration and model commits. Batch release, alarm acknowledgement, and other regulated-record signatures require separate assessment.

Is a complete validation package included?

The guide documents capabilities; it does not establish a complete customer validation package. Confirm available validation support and deliverables with TDengine for your specific project.

Bring Your Requirements. Start with the Documented Controls

Use the guide to identify product capabilities, configuration needs, and the evidence your evaluation should cover.