Skip to content

June 2, 2026 · Updated August 25, 2026 · Admissibility

Chain of Custody and Federal Rule of Evidence 901

Federal Rule of Evidence 901(a) requires authentication—enough evidence that a reasonable juror could find an item is what the proponent claims it is. A chain-of-custody record satisfies this standard by producing testimony or documentary evidence showing the item's identity, continuity of possession, and integrity from collection through trial. The bar is preponderance-level; once crossed, custody gaps go to the jury's assessment of weight, not admissibility.

What FRE 901(a) Requires

Before a jury ever weighs evidence, the proponent faces a threshold called authentication. Under Federal Rule of Evidence 901(a), that means producing "evidence sufficient to support a finding that the item is what the proponent claims it is."[1] This is not proof beyond a reasonable doubt, not clear and convincing evidence, and not even preponderance of the evidence in the classical sense. It is a lower threshold still: the proponent must offer enough evidence that a reasonable juror could find the item is genuine—that is, a prima facie case for authenticity.[2]

The distinction matters practically. Suppose a chain of custody for a seized cell phone shows a gap of six hours where no one can testify to the device's location. That gap is a flaw. But it does not automatically exclude the phone. Once the proponent has shown the phone was collected, booked, and eventually produced in court through the hands of named custodians, the threshold is crossed. The opposing party then points to the six-hour gap and argues it could have been altered. The jury weighs that argument. But the judge does not exclude the phone because of the gap; the jury simply gives it less weight if the gap creates reasonable doubt about its integrity.[2]

This separation—authentication from credibility—is foundational. Many practitioners and judges conflate them, but the Rules draw them apart deliberately. Rule 104(a) governs preliminary questions: when a party contests whether an item is what it is claimed to be, the judge determines admissibility by a preponderance standard.[9] Once the judge admits it, the jury decides how much weight to give it, including how much the flaw in the chain matters.

The Illustrative Methods in Rule 901(b)

Rule 901(b) lists examples—not an exhaustive catalog—of evidence that satisfies authentication.[1] Three are essential for custody work:

901(b)(1): Testimony of a witness with knowledge. Someone testifies "this is the item I collected," or "I received it from Officer Chen, sealed and labeled as marked." For chain-of-custody testimony, this is the foundation layer. It need not be the original collector; it can be any person who received the item and can testify to its identity and the conditions of transfer. The witness must have actual knowledge—not inference or speculation. Lay witnesses commonly establish the first and final links (the initial collector, the person who produced it in court) while forensic examiners attest to intermediate handling and testing.[1]

901(b)(4): Distinctive characteristics and the like. An item may be authenticated by "the appearance, contents, substance, internal patterns, or other distinctive characteristics of the item, taken together with all the circumstances."[1] For digital evidence, this might mean authenticating a drive image by showing the file system structure matches the described device, or establishing a photograph by reference to visible landmarks or metadata. For physical evidence, a distinctive mark (a unique serial number, a tear pattern, a visible defect) can authenticate the item without a custodian's memory. The rule stresses "together with all the circumstances"—no single characteristic alone usually suffices; rather, the convergence of details produces the reasonable inference that this is indeed that item.[1]

901(b)(9): Evidence about a process or system. This subsection has grown in importance with digital evidence. The rule states: "Evidence describing a process or system and showing that it produces an accurate result."[1] For a forensic imaging tool, this means evidence (documentation, validation studies, examiner testimony) that the tool preserves a complete and bit-for-bit copy of the source storage. For a hash comparison, it means explaining how hashing works and showing that identical hashes prove identical data. A party need not call the vendor's engineer; a qualified examiner can testify to the system's reliability based on training, documentation, and demonstrated accuracy.[1] Critically, Rule 901(b)(9) does not require live testimony—a certification from a qualified person suffices to establish the foundation.[1]

The Prima Facie Standard in Practice

The instruction to judges often states that authentication requires only "prima facie evidence."[2] This means the proponent must make a threshold showing—enough that, if believed, would permit a jury to find the item authentic. If the proponent offers testimony that the item was collected, placed in evidence, and kept secure, that testimony alone—even if unchallenged—typically clears the authentication hurdle. If opposing counsel cross-examines the custodian and suggests the item might have been tampered with, the judge still admits it if the cross-examination does not eliminate the possibility that the item is genuine; instead, the cross-examination goes to the jury for weighing.[2]

The practical consequence is that many custody chains survive authentication challenges even when flawed. A break in the chain—a gap in documentation, an unrecorded transfer, storage in an unsecured area—does not ordinarily result in exclusion. Rather, the break becomes an argument for the jury about the weight to assign. Some judges are more protective and will exclude items only if the proponent has not shown a single continuous path of custody; most admit the item and let the jury decide whether the break suggests alteration or merely sloppy record-keeping.[2]

FRE 902(13)-(14): Self-Authentication and the Hash Advantage

Amendments effective December 1, 2017 reshaped digital evidence authentication.[3] Two new categories became self-authenticating:

Rule 902(13): Records generated by an electronic process or system that produces accurate results, supported by a written certification from a qualified person. This covers forensic reports, laboratory results, and system-generated logs.[4]

Rule 902(14): Data copied from an electronic device, storage medium, or file, authenticated by a process of digital identification (typically hash comparison), supported by a written certification.[4]

The practical power lies in Rule 902(14). If a forensic examiner acquires a hard drive and computes a cryptographic hash (SHA-256, for example) of the source drive at the moment of acquisition, and then computes the same hash of the forensic image, and the hashes match, that match demonstrates the image is a faithful copy of the original. A written certificate stating "Hash of source: SHA-256 ABC123...DEF456; Hash of image: SHA-256 ABC123...DEF456; Hashes match" can authenticate the image without a live witness.[4] The certificate itself must be authenticated (signed, on letterhead, from a qualified person), but it need not be supported by testimony.

This mechanic has reoriented custody practice. Contemporaneous hashing at acquisition is no longer optional hygiene; it is the direct gateway to Rule 902(14) authentication. A chain without an acquisition hash must rely on Rule 901(b)(1) testimony, which requires the original examiner to appear and explain the process. A chain with a hash can proceed on certification alone.

Where Chains Break Down

A custody chain fails authentication when gaps or ambiguities make it impossible even for a credulous jury to support a finding of authenticity. Though admissibility is a question for the court, practical weak points recur:

  • Unaccounted-for intervals: The item is missing from documentation for a period. Who had it? Where was it? No one testifies. This is the classic gap. Courts often admit despite the gap, especially if the break is brief and the item is otherwise distinctive.[2]
  • Undocumented transfers: The item passed from Officer A to Officer B, but no record exists of the transfer, neither party signed a continuity form, and memories differ about timing. Again, courts frequently admit if the testimony about the beginning and end of custody is clear.[2]
  • No integrity baseline for digital evidence: A disk image exists, but no one can say what hash the original storage device produced. This is more damaging because no Rule 902(14) certificate is possible; the proponent must rely on 901(b)(9) testimony that the imaging tool is reliable. The absence of a contemporaneous hash does not exclude the image, but it forecloses the self-authentication path and invites attack on the tool itself.[4]
  • Unsecured storage: The evidence was kept in a cabinet without access logs, or in a secure facility but with no lockdown showing who could enter. The argument is that anyone with access could have altered it. Courts vary in sensitivity to this; some require strict accounting, others let the jury decide whether practical opportunities for tampering are credible.[2]

Building a Defensible Chain

To align with Rules 901 and 902, a custody record should:

  1. Identify the item precisely: Serial number, make and model, distinctive markings, or (for digital evidence) the device type, storage capacity, and file system. [Rule 1001 emphasizes that "writings and recordings" include electronic storage.][10]
  1. Document the collection event: Date, time, location, legal authority for seizure, identity of the person who collected it, method used, and (for digital evidence) the hash algorithm and hash value of the source at the moment of acquisition.
  1. Record transfers as two-party acknowledgments: The releasing custodian signs or attests, the receiving custodian signs or attests, with date and time. Oral transfers unsupported by contemporaneous paperwork invite attack.
  1. Note custody intervals: When was the item in the lab? When in storage? For how long? Who had access? Even if gaps emerge, a detailed timeline shows diligence and supports credibility.
  1. Capture integrity verification: For digital evidence, hash the image and compare it to the source hash. Document the match. This satisfies Rule 902(14) and provides a tamper-evident record—if the image is altered, recomputing the hash will not match the certified value, making the alteration detectable.[4]
  1. Preserve the record itself in verifiable form: A chain-of-custody document can itself be challenged as altered. If the entire log is hashed and that hash is published or sealed, any later alteration changes the hash, making it detectable. This is distinct from guaranteeing the record is unalterable—it is demonstrating that alteration is detectable.[4]

Conclusion

Authentication under Rule 901 is not a high bar, but it is a real one. Chain of custody is the most common—and often the most efficient—way to cross it. Understanding that authentication is a threshold, not a verdict; that gaps go to weight, not admissibility; and that Rule 902(14) hashing offers a powerful path to self-authentication, allows practitioners to build chains that survive challenge and satisfy the rule's modest but binding requirement.

---

This article is general information, not legal advice. Consult counsel and the rules of the governing jurisdiction for any specific matter.

Common questions

What does Rule 901 require?
Federal Rule of Evidence 901(a) requires the proponent to produce "evidence sufficient to support a finding that the item is what the proponent claims it is."[1] This is a prima facie standard—the proponent must offer enough evidence that a reasonable juror could find the item authentic, but need not prove authenticity conclusively.[2] Once the proponent meets this threshold, any weaknesses in the chain go to the weight the jury assigns, not to admissibility.
What is FRE 901(b)(9)?
Rule 901(b)(9) allows authentication through "evidence describing a process or system and showing that it produces an accurate result."[1] For digital evidence, this means testimony (or certification) that a forensic tool, hashing algorithm, or other system is reliable and produces accurate results. Unlike many other authentication methods, 901(b)(9) allows the foundation to be established by written certification rather than live witness testimony.[1]
How much proof does authentication require?
Authentication requires only a prima facie showing—enough evidence that, if believed, would permit a jury to find the item is what it is claimed to be.[2] This is lower than preponderance of the evidence or any other evidentiary standard. The trial court applies a preponderance test to decide whether the proponent has made the prima facie case, but once the threshold is crossed, custody gaps and flaws are for the jury to weigh, not grounds for exclusion.

Sources

  1. [1] Rule 901. Authenticating or Identifying Evidence Legal Information Institute (LII), Cornell Law School
  2. [2] Rule 901. Authenticating or Identifying Evidence U.S. Government Publishing Office (govinfo.gov), Title 28, United States Code
  3. [3] Federal Rules of Evidence — December 1, 2024 U.S. Courts
  4. [4] Rule 902. Evidence That Is Self-Authenticating Legal Information Institute (LII), Cornell Law School
  5. [5] Core Criminal Law Subjects: Evidence: Authentication United States Army Court of Criminal Appeals
  6. [6] Self-Authentication of Electronic Evidence: New Rules 902(13)-(14) U.S. District Court for the Southern District of Texas
  7. [7] Admissibility of Electronic Evidence — Grimm & Brady Chart U.S. District Court for the Middle District of Florida
  8. [8] NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response National Institute of Standards and Technology
  9. [9] Federal Rule of Evidence 104 — Preliminary Questions (including conditional relevance) Legal Information Institute, Cornell Law School
  10. [10] Federal Rule of Evidence 1001 — Definitions That Apply to Article X Legal Information Institute, Cornell Law School

CustodyTrack creates tamper-evident chain-of-custody records that any third party can verify. See how it works →

For this audience: Chain of Custody Software for Small Law Firms