What 21 CFR Part 11 Requires of a Cell Counter
A clean count is not the same as a provable one. For a cell counter feeding a GMP cell-therapy release workflow, 21 CFR Part 11 is the line between them.
- 21 CFR Part 11 is the FDA rule for electronic records and signatures. For a counter that means an audit trail, electronic signatures, role-based access, and logged, administrator-only deletions.
- The audit trail must capture who did what and when — including when data was deleted. A record that logs a result but not its deletion is the gap auditors flag.
- A counter needs Part 11 only when its count supports a regulated release decision, not for research-only counts. Native compliance also removes a middleware validation project; bolted-on middleware enlarges the surface you validate and audit.
- The Moxi GO II offers Secure Mode — a paid, activated 21 CFR Part 11 audit-trail module (not on by default). Among the Moxi family it is the Moxi GO II only; the Moxi V and Moxi Z do not offer it.
21 CFR Part 11 is the U.S. FDA regulation governing electronic records and electronic signatures. For a cell counter, it comes down to four controls: an audit trail that logs every data-modifying action, an electronic signature on every change, role-based access, and deletion restricted to an administrator and logged. It matters now because in GMP cell-therapy manufacturing the count and viability go on the certificate of analysis. That makes counting a release-grade measurement, and what makes that count audit-ready rests on two bars: accuracy, table stakes between serious instruments, and proof.
What is 21 CFR Part 11?
21 CFR Part 11 is the part of FDA regulation that sets when an electronic record and signature can replace paper and ink. It applies whenever you create, modify, or store that record electronically and a predicate rule such as GMP requires you to keep it. Part 11 makes data integrity concrete through an audit trail, electronic signatures, and access controls, so a record stays complete and attributable and cannot be changed or deleted in silence.
Does a cell counter need to be 21 CFR Part 11 compliant?
It depends on what the count is used for. When a cell counter produces a number that supports a regulated lot-release decision on a GMP cell-therapy line, that count is a Part 11 record and the instrument is in scope. Used for research only, the same count carries a lighter burden and Part 11 does not apply.
A Part 11 cell counter gives you a research-use record of count, viability, and identity you can prove at audit. The counter does not make the release decision; your validated method and quality system own that. Proof is only one of two bars. Whether the count is accurate and precise enough to trust turns on volumetric versus image-based counting, not on Part 11.
What must a Part 11 audit trail actually capture?
A Part 11 audit trail records who did what, and when, for every action that creates, modifies, or deletes data. Each entry is time-stamped, attributed to a unique user, and locked so no one can edit it after the fact.
Deletion is what separates a real audit trail from a partial one. Logging that a result was created and reviewed is easy; the harder question, the one auditors ask, is whether the trail records when a result was deleted, and by whom. A counter that captures every entry but lets a value disappear, with no logged and attributed deletion, has exactly the gap data-integrity findings are written about. So do not ask only whether a counter has an audit trail; ask what it captures, and confirm deletions are on the list.
What do electronic signatures and role-based access require?
Electronic signatures require that every change to the data is signed by a uniquely identified user, so an action traces to a person, not a shared login. Role-based access separates duties: the operator who runs the test, the reviewer who approves it, and the administrator who manages the system hold distinct permissions. Those two controls are why deletion is a privileged action, restricted to the administrator alone and logged like any other change, so every number stays accountable to a person.
Native Part 11 vs middleware: what is the difference, and why does it matter?
Native compliance builds the Part 11 controls into the instrument's own firmware. Middleware compliance means the counter is not compliant on its own, so a third-party software layer is bolted on to capture and control its data.
The difference is who owns the validation and audit surface. A native, standalone instrument is one validated system. A counter plus middleware is at least two systems, plus the integration between them, and every piece must be validated and defended at audit. Buyers underweight that burden at purchase, because on a data sheet both look compliant; the cost surfaces later as a validation project no one budgeted for. Native compliance removes that project before it starts.
| Consideration | Native compliance | Counter + middleware |
|---|---|---|
| Systems to validate | One validated system | Two-plus systems, plus the integration between them |
| Where the Part 11 controls live | Inside the instrument firmware (audit trail, electronic signatures, access roles) | Split across the counter and a third-party software layer |
| Where the record sits | On the instrument, in a closed standalone system | Passed across an integration to an external system |
| Validation & audit surface | One system to validate and audit | More surface to validate and defend at audit |
| When the cost lands | No separate validation project | A validation project that often surfaces after purchase |
Is the Moxi GO II 21 CFR Part 11 compliant?
Yes, with Secure Mode. Secure Mode is a paid, activated 21 CFR Part 11 audit-trail module built into the Moxi GO II — not enabled by default, but turned on and configured on the unit: an audit trail, electronic signatures, three separated access roles (operator, reviewer, and administrator), and administrator-only deletion logged like any other change. It runs as a closed, standalone system, so the record stays on the instrument. Among the Moxi family this module is available on the Moxi GO II only; the Moxi V and Moxi Z are counting and viability instruments and do not offer Secure Mode.
Secure Mode is a paid module built into the instrument's firmware and activated per unit, so confirm it is licensed, enabled, and configured on the unit you evaluate. And an activated audit-trail module gives you a provable record on the instrument, not a compliant process: once data leaves the instrument, your quality system — your SOPs, validation, and data governance — still has to carry it.
That fit is documented: a peer-reviewed Penn Medicine CAR-T manufacturing QC study measured the Moxi GO II as a benchtop cell analyzer against the reference methods a GMP lab already trusts (Pajarillo R, et al. Cytotherapy 2024;26(5):506-511; PMID 38483365).
If Part 11 is your concern, start here
Score any counter you are evaluating against the four controls above. The 21 CFR Part 11 cell-counter evaluation checklist puts them on one scoring sheet. When you are ready to walk Secure Mode past IT and Quality and get the IQ/OQ validation package, talk to a specialist.
Evaluating a counter against Part 11?
Score any counter against the four controls, then walk Secure Mode past IT and Quality with the IQ/OQ validation package. A specialist can help you scope it.








