{"data":{"id":"us/21-cfr-1311.30","jurisdiction":"us","citation":"21 CFR 1311.30","heading":"Requirements for storing and using a private key for digitally signing orders.","body":"(a) Only the certificate holder may access or use his or her digital certificate and private key.\n(b) The certificate holder must provide FIPS-approved secure storage for the private key, as discussed by FIPS 140-2, 180-2, 186-2, and accompanying change notices and annexes, as incorporated by reference in § 1311.08.\n(c) A certificate holder must ensure that no one else uses the private key. While the private key is activated, the certificate holder must prevent unauthorized use of that private key.\n(d) A certificate holder must not make back-up copies of the private key.\n(e) The certificate holder must report the loss, theft, or compromise of the private key or the password, via a revocation request, to the Certification Authority within 24 hours of substantiation of the loss, theft, or compromise. Upon receipt and verification of a signed revocation request, the Certification Authority will revoke the certificate. The certificate holder must apply for a new certificate under the requirements of § 1311.25.","path":["Title 21—Food and Drugs","CHAPTER II—DRUG ENFORCEMENT ADMINISTRATION, DEPARTMENT OF JUSTICE","PART 1311—REQUIREMENTS FOR ELECTRONIC ORDERS AND PRESCRIPTIONS","Subpart B—Obtaining and Using Digital Certificates for Electronic Orders"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-21.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:24:47Z","sha256":"8293191be7f8bd442f53bca1ff7260e4d43e00c4790f48a4b202aeffdc97fb55","source_id":"us-cfr","stale":true,"prev":"us/21-cfr-1311.25","next":"us/21-cfr-1311.35"},"notice":"GroundRules: Original legal text. Not legal advice."}
