yourstate.us
21 CFR 1311.30

§ 1311.30 Requirements for storing and using a private key for digitally signing orders.

United States · 21 CFR — Food and Drugs · Status: effective

Get this as JSONEmbed this
Cite this
Citation
21 CFR 1311.30, § 1311.30 Requirements for storing and using a private key for digitally signing orders, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/92069
Permanent ID
ys:prov:92069@1
SHA-256
8eea853107ecbbdce373173574a5a21439d1d2eaa91f68a2bd69d5248bd642c5

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(a) Only the certificate holder may access or use his or her digital certificate and private key. (b) The certificate holder must provide FIPS-approved secure storage for the private key, as discussed by FIPS 140-2, 180-2, 186-2, and accompanying change notices and annexes, as incorporated by reference in § 1311.08. (c) A certificate holder must ensure that no one else uses the private key. While the private key is activated, the certificate holder must prevent unauthorized use of that private key. (d) A certificate holder must not make back-up copies of the private key. (e) The certificate holder must report the loss, theft, or compromise of the private key or the password, via a revocation request, to the Certification Authority within 24 hours of substantiation of the loss, theft, or compromise. Upon receipt and verification of a signed revocation request, the Certification Authority will revoke the certificate. The certificate holder must apply for a new certificate under the requirements of § 1311.25.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.