Audit methodology · Last verified
Electronic Prescriptions for Controlled Substances — third-party audit or certification requirement (21 CFR § 1311.300)
EPCS is the DEA rule under 21 CFR 1311.300: providers of electronic prescription or pharmacy applications must obtain a third-party audit. The obligation binds the application provider, not the prescriber or the pharmacy. Certification may replace the audit only when the certifying organization's process has been approved by DEA.
- Class
- Audit methodology
- Owner
- U.S. Drug Enforcement Administration (DEA), Diversion Control Division
- Last verified
What it is
The section is titled "Application provider requirements—Third-party audits or certifications" and states that "Except as provided in paragraph (e) of this section, the application provider of an electronic prescription application or a pharmacy application must have a third-party audit of the application that determines that the application meets the requirements of this part at each of the following times".
Timing is set in § 1311.300(a). The audit is required "Before the application may be used to create, sign, transmit, or process controlled substance prescriptions" and again "Whenever a functionality related to controlled substance prescription requirements is altered or every two years, whichever occurs first."
Certification is an alternative route, not the requirement itself. Paragraph (e) reads: "If a certifying organization whose certification process has been approved by DEA verifies and certifies that an electronic prescription or pharmacy application meets the requirements of this part, certification by that organization may be used as an alternative to the audit requirements of paragraphs (b) through (d) of this section". The organization's certification process has to have been approved by DEA for that route to be available.
Who the rule binds matters: the application provider — the company supplying the electronic prescription or pharmacy application. Separate obligations for prescribers and pharmacies sit elsewhere in Part 1311 and were not examined for this record.
The scope of the audit differs by delivery model: processing integrity for installed applications, and processing integrity and physical security for application service providers, under § 1311.300(c) and (d).
The output is an audit or certification report. Under § 1311.300(f) the provider must make it available to practitioners and pharmacies that use, or are considering using, the application, and must retain the most recent report plus the previous two years of results.
If the report is negative, § 1311.300(g) requires that "the application must not be used to create, sign, transmit, or process electronic controlled substance prescriptions", that the provider notify registrants within five business days, and that DEA be notified within one business day and given the report. That bar is not unconditional: the paragraph opens "Except as provided in paragraphs (h) and (i) of this section", and those two paragraphs set out the determinations the auditor or certification organization must make for electronic prescription applications and for pharmacy applications respectively.
The text quoted here was read twice on 4 September 2026: in the 2023 CFR edition published by govinfo, and in the current eCFR text (the version in force on 1 September 2026). The wording of § 1311.300 is the same in both.
DEA's final rule for this area was published in the Federal Register on 27 July 2023; DEA's own page states: "On July 27, 2023, DEA's Final Rule...was published in the Federal Register. The rule becomes effective August 28, 2023."
Who owns it
The rule is federal United States law: title 21 of the Code of Federal Regulations, administered by the Drug Enforcement Administration's Diversion Control Division. The obligation is set by regulation: § 1311.300 names no scheme owner and sets no fee. The certification route in paragraph (e) runs through a certifying organization whose process has been approved by DEA, and this record makes no claim about what such an organization charges.
Who assesses it
Paragraph (b) names who may perform the audit: "A person qualified to conduct a SysTrust, WebTrust, or SAS 70 audit." and "A Certified Information System Auditor who performs compliance audits as a regular ongoing business activity."
For the certification route, the certifying organization's certification process must have been approved by DEA. A public list of organizations with such approval was not located on DEA's pages read for this record.
Sources
- 21 CFR § 1311.300 (2023 edition, govinfo full text, read 2026-09-04) ↗ — accessed
- DEA Diversion Control Division — Electronic Prescriptions for Controlled Substances ↗ — accessed
- Federal Register — DEA final rule published 27 July 2023 (effective 28 August 2023) ↗ — accessed
- Federal Register — interim final rule, 31 March 2010 ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.