Specifications

The rule says establish specifications but gives no numbers. What do I actually put?

21 CFR 111.70 names seven places a specification has to exist and supplies no value for any of them. The numbers come from four places, and failing to have them at all is the most-cited finding in the whole of part 111.

This is United States federal law for dietary supplements: 21 CFR part 111, FDA’s current good manufacturing practice regulation. It is written as a list of things you must establish, and it supplies no values. That is not an omission. The rule cannot know what your product is, so it names the categories and leaves the numbers to you, then measures your product against them.

This page covers where those numbers come from and what makes one defensible. It does not cover how you test against them, who signs them off, or what happens when a batch fails.

On this page: What the rule actually says · Why the rule has no numbers in it · The four places a number can come from · What FDA actually cites · The second failure: a number nobody can source · What a defensible specification looks like · Three things to check

What the rule actually says

Seven lettered paragraphs, carrying twelve separate obligations. They are not the same obligation repeated, and one of them is not addressed to you.

  • 111.70(a) — a specification at any point, step, or stage in the manufacturing process where control is necessary to ensure the quality of the dietary supplement and that it is packaged and labeled as specified in the master manufacturing record (111.70(a)).
  • 111.70(b) — for each component: an identity specification; component specifications necessary to ensure the finished product’s purity, strength and composition specifications are met; and limits on those types of contamination that may adulterate or may lead to adulteration of the finished batch (111.70(b)(1) to (b)(3)).
  • 111.70(c) — in-process specifications; adequate documentation of your basis for why meeting them, in combination with meeting component specifications, will help ensure the finished specifications are met; and review and approval of that documentation by quality control personnel. That third obligation binds your quality unit, not you (111.70(c)(1) to (c)(3)).
  • 111.70(d) — label specifications, and specifications for packaging that may come in contact with the supplement. That packaging must be safe and suitable for its intended use and must not be reactive or absorptive or otherwise affect safety or quality (111.70(d)).
  • 111.70(e) — for each supplement you manufacture, product specifications for the identity, purity, strength, and composition of the finished batch, and for limits on contamination, to ensure the quality of the dietary supplement (111.70(e)).
  • 111.70(f) — if you receive a product from a supplier for packaging or labeling and for distribution, specifications giving sufficient assurance that what you received is adequately identified and consistent with your purchase order. This is added to the others, not substituted for them (111.70(f)).
  • 111.70(g) — specifications for the packaging and labeling of the finished packaged and labeled product, including ones that ensure you used the specified packaging and applied the specified label (111.70(g)).

Before any of that, the product has to be in a category, because which of these paragraphs reaches you depends on what it is: a cosmetic, a drug, a supplement, or a food. This page assumes the answer is a dietary supplement. The label those specifications drive has its own version of the same split: what has to be on the panel, and the half a checklist cannot see.

One more question sits alongside those, and it decides who has to do the work at all: the rule splits the specification duties between you and your manufacturer by what each of you actually does with the product.

Then one sentence carries the weight: you must determine whether the specifications you establish under 111.70 are met (111.73).

Why the rule has no numbers in it

Because the number is not the whole requirement. Quality means the supplement consistently meets the established specifications for identity, purity, strength, and composition, and limits on contaminants, and has been manufactured, packaged, labeled, and held under conditions to prevent adulteration under section 402(a) of the Act (21 CFR 111.3).

Two limbs, and only the first is measured against your numbers. The second is measured against the Act. A contamination limit set high enough that the product carries a poisonous or deleterious substance is not rescued by the batch consistently meeting it.

Read the paragraphs again and the adequacy condition is written into each one: a specification where control is necessary to ensure the quality; component specifications necessary to ensure the finished specifications are met; contamination limits to ensure the quality. The rule does not print your number, and it does not accept any number you print.

The four places a number can come from

  1. Something else already set it. A compendial monograph, a regulatory contaminant limit, a scheme limit you have claimed. Your basis is the citation. Note what makes a compendial specification bite: a supplement is misbranded on that ground where it is covered by the specifications of an official compendium, is represented as conforming, and fails to conform (21 U.S.C. 343(s)(2)(D)). It binds on representation, not on existence, and you still have to decide whether the monograph reaches your article.
  2. A hazard argument. For most contaminants in most matrices no published number reaches you. Then the limit is constructed from an exposure argument, not retrieved from a document. This is the source most often missing entirely, and 111.70(b)(3) and 111.70(e) both require a limit whether or not somebody else published one.
  3. What your method can reach. You must identify and use an appropriate scientifically valid method for each established specification for which testing is required (21 CFR 111.320(b)). A limit below what your method can reliably measure is one you cannot determine against.
  4. What you told the buyer. Compliance for a supplement runs on a composite of twelve subsamples, and the class matters: an added nutrient must be formulated to be at least equal to the declared value, while a naturally occurring one must be at least 80 percent of it, before analytical variability (21 CFR 101.36(f)(1), applying 101.9(g)(3) and (g)(4)). Reasonable excesses over labeled amounts are acceptable within current good manufacturing practice. A strength specification written per unit at exactly 100 percent of declared is not the compliance test and will scrap conforming lots.

Not on that list: the template, and the supplier’s certificate of analysis. A certificate reports what one lot tested at. It is a result, not a requirement, and it cannot carry identity — at least one appropriate test or examination is required to verify the identity of any component that is a dietary ingredient (21 CFR 111.75(a)(1)(i)). It does have a conditioned role for other component specifications, if you first qualify the supplier by confirming their results, document how, re-confirm periodically, and have quality control approve the basis (111.75(a)(2)(ii)).

And your own batch history is not a fifth source. Capability tells you whether your process can hold a limit. It never tells you what the limit should be. Setting the range from what the last twelve batches did describes the process, and the specification then moves whenever the process does.

What FDA actually cites

Not a number nobody can explain. A specification that is not there at all.

1,387 inspection observations have been written under 21 CFR 111.70(e), the finished-product specification — the single most-cited clause in the whole of part 111. The next is 111.205(a) at 914. Every one of the 1,387 observation texts begins the same way: you did not establish product specifications for the identity, purity, strength and composition of the finished dietary supplement, or you did not establish them for limits on contamination.

FDA inspection observations by clause, 21 CFR 111.70, fiscal years 2009 to 2026.
ClauseWhat it requiresObservations
111.70(e)Finished-product specifications1,387
111.70(b)(2)Component specifications512
111.70(b)(1)Component identity specification490
111.70(d)Label and packaging specifications277
111.70(b)Component specifications, generally277
111.70(b)(3)Contamination limits on components163
111.70(a)In-process control points140
111.70(g)Packaged and labeled product109
111.70(f)Product received for packaging or labeling105
111.70(c)(1)In-process specifications77
111.70(c)(2)Documented basis for the in-process reasoning31
111.70(c)(3)Quality control review of that basis2
Total, 21 CFR 111.703,570

Counted from FDA’s published inspection observation records, read August 17, 2026. Fiscal year 2026 was still open at that date. A later count will differ.

Read the bottom of that table, because it is where the second failure lives. The clauses that ask you to write down why — 111.70(c)(2) and (c)(3) — carry 33 observations between them. That is not evidence the derivation is usually sound. It is evidence that an investigator who finds no specification at all never reaches the question of where its numbers came from.

The second failure: a number nobody can source

If you have a specification, this is the one that finds you, and it is quieter because it comes second. Three forms, and each reads as complete until somebody asks one question.

  • The limit that is really the process restated. A range set from recent batches describes what you already do. It is met until the process shifts, and then it gets re-derived from the new batches, which is a limit receding to follow practice.
  • The supplier’s certificate, copied across. Your requirement then changes every time their lot does, and it cannot carry identity at all.
  • The number that came with the product. It may well be correct. You cannot show that it is.

Where the rule asks for the reasoning in writing, it asks in two specific places, and neither is a general duty to justify every number. For in-process specifications, documentation of your basis, reviewed and approved by quality control (111.70(c)(2) and (c)(3)). And where you verify a subset of finished batches, adequate documentation of your basis for determining that compliance with the specifications you selected will ensure the finished batch meets all product specifications, again with quality control review (111.75(c)(3)). Those are the clauses. Outside them the derivation is not a filing requirement, and it is still the thing you cannot answer without.

A cleaning acceptance limit is the same failure with a borrowed number on it: where 10 ppm and health-based limits actually come from, and what part 111 asks of the limit instead.

What a defensible specification looks like

Four things at once. All four are yours to check.

  1. Every parameter the paragraph names is present — identity, purity, strength, composition, and contamination limits for the finished product, and the component, in-process, label, packaging and received-product specifications the other six paragraphs require.
  2. Every limit names where it came from — a monograph and its clause, a regulatory limit and its citation, a hazard argument, or the declared amount. One line each.
  3. Every limit has a method that can reach it. Where no scientifically valid finished-batch method exists, the rule provides a route rather than requiring you to delete the limit: you may exempt that specification from finished-batch verification if you determine and document why component testing, in-process testing or other information will ensure it is met, with quality control review and approval (21 CFR 111.75(d)(1) and (d)(2)).
  4. Nothing on it contradicts the label, tested the way compliance is actually determined — on a composite, against the class the ingredient falls in, across the shelf life you claim rather than on the day of manufacture. A release limit and an end-of-shelf-life limit are two numbers with a degradation envelope between them, and sizing that envelope takes stability data.

Whether the method beside a limit is good enough is its own question, and the answer changes with what you make: whether a compendial method has to be fully validated, or verification is enough.

Three things to check before you spend

Take dated copies before you change anything. A specification is a controlled record, and revising one is a change your own quality unit owns.

  1. Count the properties on your finished-product specification. Identity, purity, strength, composition, contamination limits. A missing one is the clause with 1,387 observations behind it.
  2. Pick any three numbers and ask where each came from. Not who wrote it. If the answer is the supplier’s certificate, a template, or nobody knows, that is the second failure and you have found it yourself.
  3. Check each limit against the method beside it. If the method cannot reach the limit, either the method changes, the limit changes, or the exemption route at 111.75(d) applies and has to be documented and approved.

Get the specification read, or built

If you have a specification and cannot defend the numbers on it, the Specifications Opinion Letter reads what you sent against what the rule asks for and says, limit by limit, which derivations it can support and which it cannot. If you have no defensible specification, Specifications Development builds one from what your product is, with each limit tied to a stated source and to a method that can measure it.

What it covers, and what it does not. Both are built from what you send us, and both cover United States federal requirements only. Neither is legal advice. We do not run the testing, conduct the audit, approve the document in your quality system, or make the release decision, and no opinion can guarantee how your product will perform against any limit.

See the specifications services

Common questions

Common questions about specifications

Do my limits have to match the compendial monograph, or can I write my own?

A compendial specification binds a supplement where it is covered by the compendium, is represented as conforming, and fails to conform. Where you make that representation the monograph is the number. Where you do not, it is the strongest available basis and departing from it puts the derivation on you. Either way you still have to decide whether the monograph reaches your article, and the rule requires you to establish the specification regardless.

My method cannot detect down to the limit I set. Is my specification even valid?

You must determine whether the specifications you establish are met, and you must use an appropriate scientifically valid method for each one that requires testing. If no such method exists at the finished-batch stage, the rule lets you exempt that specification from finished-batch verification where you determine and document why component or in-process testing will ensure it is met, with quality control approval. Deleting the limit is not one of the options.

How do I set limits when I have no test history at all?

From the other three sources: a published limit where one reaches your article, a hazard argument where none does, the capability of the method you will use, and the amount you declare. Batch data afterward tells you whether your process can hold what you set. It does not tell you what to set, and loosening a limit to accommodate the first result that misses it is the failure this page is about.

Is setting the specification my manufacturer’s job, or mine?

Part 111 applies to you if you manufacture, package, label or hold a dietary supplement, and it says you must establish the specifications. A contract manufacturer establishes their own for the operations they run; that does not discharge yours. If you receive finished product from a supplier for packaging or labeling and for distribution, you still have to establish specifications giving sufficient assurance that what arrived is adequately identified and consistent with your purchase order (111.70(f)). Their document can inform yours. It cannot be yours.

Scope and limits. This is independent regulatory work published by Regulatory Options. It is general information about how United States federal specification requirements work, and it is not legal advice. It is not an assessment of your specification: the sources and the checks here are a way of reading the rule, and a conclusion your own reading produces is yours rather than ours. You remain answerable to FDA for the specifications you establish and for whether your product meets them, and your own quality unit remains responsible for reviewing and approving them.

Regulatory Options is not affiliated with, endorsed by, or acting for the Food and Drug Administration. Regulation text is paraphrased here with its clause cited, and is reproduced to be read against rather than as our own statement; the federal statutes and regulations themselves are government works. The selection, arrangement and the observation analysis are ours.

Currency. Regulations read at eCFR on August 17, 2026; the inspection observation counts were read from FDA’s published records on the same date. Federal law changes without notice. Verify each provision at its source before relying on it.