Skip to content

September 25, 2026 · Digital Evidence Admissibility

FRE 902(13): Certified Records from an Electronic Process

Rule 902(13) allows a qualified person to certify that a record—the output or product generated by an electronic process or system—is authentic, without calling a witness at trial. The certification itself becomes self-authenticating evidence if it meets the procedural requirements of Rules 902(11) or (12), but authentication is only one element of admissibility; a certified computer output remains subject to objections based on hearsay, relevance, and other rules of evidence.

What Rule 902(13) Covers

Rule 902(13) permits self-authentication of "[a] record generated by an electronic process or system that produces an accurate result, as shown by a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12)."[1] The rule applies to the output or product that the system generates—a log file, a report, a database extract, an electronic entry record from a security system, or the contents of a web page retrieved at a particular moment. [1] The certification itself becomes part of the evidentiary package and, if it satisfies the procedural requirements, allows the proponent to introduce the underlying digital record without calling a foundation witness.

The purpose of the rule is economical and practical. The Advisory Committee observed that "the expense and inconvenience of producing a witness to authenticate an item of electronic evidence is often unnecessary," particularly when the adverse party may stipulate authenticity or fail to challenge the authentication testimony once presented.[1] Rule 902(13) allows that stipulated or uncontested authentication to happen on paper, through certification, rather than live testimony at the stand.

It is important to understand the scope precisely: Rule 902(13) covers evidence that the electronic system itself created—the native product of the machine or process. It does not cover evidence that merely exists in a system, nor does it address every kind of digital evidence. The distinction between 902(13) and its companion rule, 902(14), illuminates this boundary.

The Critical Distinction: Rule 902(13) versus Rule 902(14)

These two rules, added together to the Federal Rules of Evidence in 2017, address different evidentiary problems and must not be confused.[1]

Rule 902(13): The System's Own Output

Rule 902(13) certifies that a record the electronic system generated is authentic. Examples include: a website printout, retrieved and certified as accurate by the person who pulled it; electronic access logs generated by a security system; data extracted from a financial platform; a report produced by accounting software. The electronic process itself is the source of the record.

Rule 902(14): A Copy Matched to Its Source

Rule 902(14) authorizes certification of "[d]ata copied from an electronic device, storage medium, or file, if authenticated by a process of digital identification, as shown by a certification of a qualified person that complies with the certification requirements of Rule 902(11) or (12)."[1] This rule covers forensic duplications, file extractions, and data transfers from devices (hard drives, phones, cloud storage) where the certifier must show that the copy is a faithful, unaltered representation of the original. The typical mechanism is cryptographic hash verification—proof that a digital copy matches its source by comparing computed hash values.[1]

The functional difference is clear: 902(13) says "this is what the system produced"; 902(14) says "this copy matches the original." A forensic examiner certifying a forensic image of a mobile phone, using hash verification to show bit-for-bit identity, relies on 902(14). A system administrator certifying that a network log reflects accurate records created by the server uses 902(13). Understanding which rule applies is essential to framing the certification correctly and to understanding what objections remain available.

Who Can Serve as a Certifier

Rule 902(13) requires certification "of a qualified person."[1] The rule does not define "qualified," but refers the reader to the certification requirements of Rules 902(11) and (12), which establish that the certifier must possess personal knowledge, education, training, or experience that qualifies them to make the assertion being certified.[1]

The Advisory Committee offered further guidance: the certification "must contain information that would be sufficient to establish authenticity were that information provided by a witness at trial."[1] This means the certification must establish the certifier's qualifications to speak about the electronic system or process in question. A network administrator who manages and maintains the security system can certify its logs. A web developer or IT employee with direct access to and responsibility for a website can certify that a retrieved printout matches the site as it appeared on a given date. A forensic examiner with formal training and experience in digital copying can certify the hash value of a forensic image.

The certifier need not be the employee of the party offering the evidence, but they must have sufficient knowledge of the system, process, or method used to generate or copy the data. A person with no direct involvement in the creation or handling of the record should not sign the certification.

The Certification Process

For a certification under Rule 902(13) to be effective, it must satisfy two layers of requirements: the substantive content required to establish authenticity, and the procedural requirements of Rules 902(11) and (12).

Content of the Certification

The certification must describe, with sufficient detail, the electronic process or system that generated the record and explain why the certifier believes the output is accurate and reliable. This might include: (1) identification of the system or process; (2) the certifier's qualifications and role in relation to the system; (3) the technical basis for the system's reliability (how it is designed, tested, or maintained); (4) the date, time, and method by which the record was extracted or retrieved; and (5) any safeguards or controls in place to ensure accuracy.[1]

Procedural Requirements: Notice and Inspection

Rule 902(11) requires that the proponent provide advance written notice of the certification to the adverse party and give them a reasonable opportunity to inspect the certification and the underlying record before trial or hearing.[1] This ensures that the opposing party is not ambushed and has time to investigate, challenge, or prepare to contest the certification or the underlying evidence.

Failure to provide adequate notice may result in exclusion of the certification, or at minimum, a ruling that the evidence is not self-authenticating and that the proponent must establish authenticity through testimony.

What Self-Authentication Does—and Does Not—Establish

This is the critical limitation that practitioners must understand and that opposing counsel will exploit.

What 902(13) Establishes: Authenticity Only

A successful certification under Rule 902(13) establishes that the proffered record is what the proponent claims it to be—that it is a genuine product of the electronic system, unaltered and accurately retrieved.[1] This satisfies the authentication requirement of Rule 901, which generally requires that evidence "is what the proponent claims it is."[1] With authentication established via certification, the proponent need not call a witness to lay foundation.

What 902(13) Does NOT Establish

Authentication is a threshold question about the identity of evidence. It does not address the weight, reliability, meaning, or admissibility of the content. Rule 902(13) is "solely limited to authentication," and any attempt to satisfy a hearsay exception, establish relevance, or overcome other evidentiary objections "must be made independently."[1]

The Advisory Committee provided a concrete illustration. Suppose a plaintiff in a defamation suit offers a printout of a webpage bearing a defamatory statement, supported by a certification that the page was retrieved accurately from a specified URL on a specified date. The certification establishes that the webpage is authentic—that it was indeed what appeared on that site at that time. But the certification does not establish that the defendant posted the statement, that the statement is true, that it caused harm, or that the webpage is not hearsay (if the plaintiff is offering it for the truth of what it says). The defendant remains free to argue that someone else posted the material, or that the truth of the statement should be proven by other means.[1]

Other objections that remain open include: hearsay (if the record contains out-of-court statements offered for their truth); relevance (if the authenticated record has minimal connection to the case); and in criminal cases, confrontation rights (if the record contains statements about which the defendant has no opportunity to cross-examine the declarant).[1]

A Worked Example

Consider a hypothetical: a network security team, in response to a suspected data breach, generates a detailed log of all connections to a particular server on a given date and time. The log is a native output of the logging system maintained by the company's IT department. The company's IT director, who oversees the logging infrastructure and ensures its accuracy and security, prepares a certification stating: (1) her role and qualifications; (2) the name and purpose of the logging system; (3) the procedures used to maintain and validate the system; (4) the date and method by which she retrieved the log; and (5) her opinion that the log is an accurate record of the connections.

The certification is served on opposing counsel thirty days before trial, with a copy of the log.

If the certification complies with Rules 902(11), (12), and (13), the IT director's declaration may be admitted as self-authenticating evidence, and the proponent need not call her to testify about foundation. The opponent cannot challenge the authentication aspect—the log is what it purports to be.

However, the opponent may argue that specific log entries are inadmissible hearsay (if they constitute assertions about who was attempting access), that the log is unreliable because the system was not properly configured or tested, or that particular entries lack sufficient relevance to the claims in the case. These objections address content, reliability, and relevance—matters beyond the scope of self-authentication.

Practical Considerations

When preparing to use Rule 902(13), ensure that the certifier has direct, detailed knowledge of the system and its operation. Generic or boilerplate certifications often provoke objections or judicial skepticism. Describe the system's design, testing, maintenance, and security with specificity.

Provide notice and the certification far enough in advance that opposing counsel can meaningfully inspect and investigate. If notice is inadequate, courts may exclude the certification or require live testimony.

Anticipate challenges based on hearsay, relevance, and other rules of evidence. A successful authentication does not foreclose these objections, and the proponent should be prepared to establish, through testimony or other evidence, that hearsay exceptions apply or that the content is otherwise admissible.

Finally, preserve the chain of custody and any logs or records relating to how the evidence was handled after the system generated it. Rule 902(13) authenticates the system's output; if the output was later modified, corrupted, or mishandled, that chain-of-custody break may become the basis for a subsequent objection.

Common questions

What does Rule 902(13) cover?
Rule 902(13) covers records that are the native output or product of an electronic process or system—such as a website printout, security system logs, database extracts, or reports generated by software.[1] The rule allows a qualified person to certify that such a record is authentic without calling a witness at trial, if the certification complies with the procedural requirements of Rules 902(11) or (12).[1]
How is Rule 902(13) different from Rule 902(14)?
Rule 902(13) authenticates records that the electronic system itself created; Rule 902(14) authenticates copies of data extracted from devices or storage media, typically verified through digital identification (such as hash values) to show that the copy matches the original.[1] In short: 902(13) says "this is what the system produced"; 902(14) says "this copy matches the original."
Who can sign a 902(13) certification?
A "qualified person"—someone whose personal knowledge, education, training, or experience qualifies them to make the assertion.[1] The certifier must have direct knowledge of the electronic system or process and must set forth information in the certification that would be sufficient to establish authenticity if that information were provided by a witness at trial.[1]
Does self-authentication under Rule 902(13) resolve a hearsay objection?
No. Rule 902(13) is solely limited to authentication and establishes only that the record is what the proponent claims it to be.[1] Objections based on hearsay, relevance, and other rules of evidence remain available and must be addressed independently.[1] A certified computer output, for example, may still be challenged as inadmissible hearsay if it contains out-of-court statements offered for their truth.

Sources

  1. [1] Federal Rules of Evidence—Rule 902 (Official Text and Advisory Committee Notes) — Cornell Legal Information Institute / U.S. Law
  2. [2] 28 U.S.C. Title 28, Appendix—Federal Rules of Evidence Rule 902 — Government Publishing Office (govinfo.gov)
  3. [3] Self-Authentication of Electronic Evidence: New Rules 902(13)-(14) — U.S. District Court, Southern District of Texas
  4. [4] Advisory Committee on Rules of Evidence Meeting Minutes (April 17, 2015) — U.S. Courts
  5. [5] Admissibility of Electronic Evidence Chart — U.S. District Court, Middle District of Florida
  6. [6] 28 U.S. Code Article IX—Authentication and Identification — Cornell Legal Information Institute / U.S. Law
  7. [7] Federal Rule of Evidence 901 — Authenticating or Identifying Evidence — Legal Information Institute, Cornell Law School
  8. [8] NIST SP 800-86 — Guide to Integrating Forensic Techniques into Incident Response — National Institute of Standards and Technology
  9. [9] Federal Rule of Evidence 104 — Preliminary Questions (including conditional relevance) — Legal Information Institute, Cornell Law School
  10. [10] Federal Rule of Evidence 1001 — Definitions That Apply to Article X — Legal Information Institute, Cornell Law School

CustodyTrack creates tamper-evident chain-of-custody records that any third party can verify. See how it works →

For this audience: Chain of Custody Software for Small Law Firms