FRE 902(13) and 902(14): When an Electronic Record Authenticates Itself

FRE 902(13) and 902(14) let a federal court take an electronic record without the witness who produced it. A written certification signed by a qualified person replaces live testimony: under 902(13), that the system generating the record produces an accurate result; under 902(14), that data copied from a device matches the original, verified by a process of digital identification. Both took effect on 1 December 2017, after the Judicial Conference approved the amendments in September 2016. Neither makes the record admissible. They settle authenticity and nothing else, and the certification that carries them fails on procedure far more often than on technology.

What decides a case is narrower: what the certification must say, when the opponent can force you back to live proof, and what the rule leaves untouched. The wider frame sits in our guide to authentication of digital evidence under Rule 901.

This insight is part of our guide: FRE 901 and the Authentication of Digital Evidence

What 902(13) and 902(14) actually say, and how they differ from 901

The two subsections split by object: one certifies a system, the other certifies a copy. Both take their form and their notice obligation from Rule 902(11) or (12).

902(13): a record generated by an electronic process or system

902(13) carries the caption “Certified Records Generated by an Electronic Process or System” and covers “a record generated by an electronic process or system that produces an accurate result”, certified by a qualified person under the requirements of Rule 902(11) or (12) (Cornell LII, Rule 902). The object is the process, not the file. Server logs, access records, telemetry, transaction records written automatically by an application: the qualified person attests that the system yields an accurate result, and nobody swears to any single entry.

902(14): data copied from a device, and the process of digital identification

902(14) carries the caption “Certified Data Copied from an Electronic Device, Storage Medium, or File” and covers data copied from those sources “if authenticated by a process of digital identification”. Here the object is the copy. The 2017 Committee note explains the mechanism: a hash value comes from an algorithm run over the digital contents of a drive, medium or file, and “if the hash values for the original and copy are the same, it is highly improbable that the original and copy are not identical”. SHA-256 is the usual choice, though the note keeps the rule “flexible enough to allow certifications through process[es] other than comparison of hash value”. It governs most electronically stored information (ESI) in e-discovery.

Platforms such as TrueScreen, the Data Authenticity Platform, generate the hash and the qualified timestamp at the moment of capture, so the digital identification process required by Rule 902(14) is documented before the content can change.

When Rule 901 extrinsic evidence is still needed

Self-authentication is a shortcut, not a separate track. Knock the certification down and the record stays in the case: the proponent falls back to Rule 901 and proves authenticity with extrinsic evidence, usually the custodian or the examiner on the stand. That trade-off belongs to the parent guide on Rule 901 authentication of electronic evidence.

What is certified What it requires What it does not cover
FRE 902(13) The process or system that generated the record Certification by a qualified person, in the form set by 902(11) or (12) Accuracy of data entered by humans
FRE 902(14) The copy, as identical to its source A process of digital identification, usually hash comparison, plus the same certification When the copy was made, and whether the source was intact
FRE 901 Nothing in advance: authenticity is proved in the proceeding Extrinsic evidence, usually a witness with knowledge Nothing is excluded, but the hearing time is yours

What the qualified person’s certification must contain

The rule prescribes no form. It requires compliance with 902(11) or (12), which puts two obligations on the proponent: the substance of the attestation, and reasonable written notice to the other side.

Who counts as a qualified person

A qualified person is whoever can attest to the process from real familiarity with it. The rule creates no credential, requires no court appointment and does not reserve the role to the records custodian: a systems administrator who runs the logging infrastructure can certify under 902(13), the examiner who performed the acquisition under 902(14). The burden falls on whoever knows how the copy was produced, which is why a certification signed by counsel repeating what a tool reported is worth so little (Robins Kaplan on FRE 902(14) and eDiscovery).

Reasonable written notice and the opponent’s right of inspection

Rule 902(11) requires the proponent, before the trial or hearing, to give the adverse party “reasonable written notice of the intent to offer the record”. It fixes no number of days: the fourteen-day figure that circulates in practice comes from local rules and standing orders, not from the federal text. The half that gets forgotten is the second one, since the record and the certification must also be made available for inspection so the other side has a fair opportunity to challenge them. Notice without access is not notice.

Hash value, qualified timestamp and chain of custody

A hash proves two files are identical. It says nothing about when either existed. That gap is where a 902(14) certification gets uncomfortable, because the objection actually raised is rarely “this copy is wrong” and usually “you cannot show what the source looked like at the relevant moment”. A qualified timestamp issued by a QTSP anchors the digest to a verified instant and turns an integrity claim into a dated one, and the digital chain of custody covers what happened between acquisition and production.

Element Statutory basis If it is missing
The record and its source, identified 902(13), 902(14) The certification cannot be matched to the exhibit
Attestation that the system produces an accurate result 902(13) The subsection does not apply: back to Rule 901
Digital identification process, algorithm and hash values 902(14) No basis to find the copy identical to the source
Signature of a qualified person with actual knowledge 902(11), via (13) and (14) The challenge lands on the signer, not the technology
Reasonable written notice to the adverse party 902(11) Self-authentication is forfeited even if the record is genuine
Record and certification available for inspection 902(11) No fair opportunity to challenge, so the shortcut collapses
Acquisition timestamp and chain of custody Not in the text, expected in practice Nothing shows when the copy was made or who held it

What self-authentication does not solve

Self-authentication answers one question. Read as an admissibility rule, which is the common misreading, it produces expensive surprises at the pretrial conference.

Authenticity is not admissibility: hearsay, relevance, confrontation

The 2017 Committee note is unambiguous: “A certification under this Rule can establish only that the proffered item has satisfied the admissibility requirements for authenticity.” Every other objection survives, including hearsay, relevance and, in criminal cases, the right of confrontation. A certified log of employee messages is authentic and still hearsay. Admissibility of digital evidence is a longer road, and these two subsections shorten one leg of it.

What makes a certification fail in court

Failures cluster, and almost none involve a broken algorithm. Notice served late, or without the record attached. A signer who pressed the export button but cannot describe the acquisition. A hash recorded after the file had already passed through three mailboxes. An acquisition documenting the copy without establishing what the original was, which is how screenshots collected by a client months before counsel arrived usually end. Parties outside the United States meet one more: material gathered under domestic practice and later produced in a federal proceeding often carries no written attestation of the copying process, because nothing at home asked for one. A certification can be built afterwards. A source that no longer exists cannot.

Certifying at the moment of capture, not downstream

TrueScreen is a Data Authenticity Platform that produces a forensic report describing the acquisition process, the hash algorithm and the qualified timestamp applied through an integrated QTSP. That report is the written certification a qualified person signs under Rule 902(13) or 902(14). TrueScreen is not a QTSP and not a certificate authority: it issues no qualified certificates, and what it delivers is a forensic report.

Most accounts of 902(14) assume the data is sitting there waiting to be copied. Often it is not. Organizations use TrueScreen to certify content that will not exist by the time an expert can copy it: a story that expires in 24 hours, a page that is edited, a call that ends. A company finds its counterfeited mark in an Instagram story; a day later there is no original to hash and 902(14) is unavailable. Captured while it was live, the same story yields a file, a digest, a qualified timestamp and a report describing how each was produced.

Certified media files covers material already on a device, forensic acquisition of web pages what exists only online. Because the digital seal and the timestamp are verifiable by anyone, the opposing party can run independent verification of the certification instead of taking the certifier’s word for it.

FAQ: FRE 902(13) and 902(14)

What is the difference between FRE 902(13) and 902(14)?

902(13) certifies a system; 902(14) certifies a copy. Under 902(13) a qualified person attests that the electronic process generating the record produces an accurate result, which fits server logs, telemetry and automated transaction records. Under 902(14) the same kind of person attests that data copied from a device, storage medium or file was authenticated by a process of digital identification, normally hash comparison. Both take the form of the certification and the notice obligation from Rule 902(11) or (12), so the paperwork is identical.

Who qualifies as a “qualified person” under 902(13) and 902(14)?

Anyone with genuine knowledge of the process being certified. The Federal Rules create no credential, no registry and no court appointment: a systems administrator responsible for the logging infrastructure can certify under 902(13), and the examiner who performed the acquisition can certify under 902(14). Most rejected certifications fall on the signer, not the method: counsel repeating a tool’s output cannot answer questions about how the copy was made. A forensic acquisition platform can serve this role: TrueScreen produces the hash, the qualified timestamp and the chain of custody record in a single report, which the qualified person then certifies.

What must a Rule 902 certification contain?

The record and its source, identified precisely enough to match the exhibit; the attestation itself, meaning either that the system produces an accurate result under 902(13) or that the copy was authenticated by a process of digital identification under 902(14); the algorithm and hash values where 902(14) applies; and the signature of a person with actual knowledge, in the form required by Rule 902(11) or (12). The rule prescribes no template, which is why certifications vary between districts. Acquisition time and chain of custody are not in the text, yet objections target them.

How much advance notice must be given under Rule 902(11)?

The federal rule sets no deadline. It requires “reasonable written notice of the intent to offer the record” before the trial or hearing, and reasonableness is measured against the case. The fourteen-day period cited across the practitioner literature comes from local rules and standing orders, not from the federal text, so check the district before relying on it. Notice is also half the obligation: the record and the certification must be made available for inspection, so the adverse party can challenge them.

Is a hash value alone enough to self-authenticate evidence?

No. A hash establishes that two files are identical, which is what 902(14) asks for, but it carries no information about time. An opponent arguing that the source was already altered before acquisition, or that the copy was made after the relevant events, is not answered by a digest. A qualified timestamp issued by a QTSP binds the hash to a verified instant, and a documented chain of custody covers the period between acquisition and production. The 2017 Committee note also treats hash comparison as one acceptable method among others.

Does a Rule 902 certification defeat a hearsay objection?

No. The 2017 Committee note states that a certification under the rule “can establish only that the proffered item has satisfied the admissibility requirements for authenticity”. Every other objection stays open: hearsay, relevance, unfair prejudice and, in criminal proceedings, the right of confrontation. A certified export of internal messages is authentic and still an out-of-court statement offered for its truth unless an exception applies. Reading these subsections as a route to admission is costly because the mistake surfaces at the pretrial conference.

Have states adopted equivalents of 902(13) and 902(14)?

Several have. Pennsylvania’s version tracks the federal wording closely, and states including Indiana, Utah, New Hampshire, Minnesota and Massachusetts have adopted comparable provisions for certified electronic records. Adoption is not uniform: some amended only one subsection, others rewrote the notice requirement, and a number have not moved. The Texas rules are the most frequently searched state variant and differ in scope from the federal text. Before relying on self-authentication in state court, read the local rule rather than assuming it mirrors the Federal Rules of Evidence.

Certify your digital evidence at the source

Capturing content with a forensic methodology, with the hash and the qualified timestamp applied at the moment of capture, means arriving in court with a documented process rather than a reconstruction after the fact.

Start now
Request a demo

TrueScreen
TS

TrueScreen editorial team

This section is edited by the TrueScreen editorial team, which brings together expertise in digital forensics, the law of digital evidence and regulatory compliance. Every article is checked against primary sources: legislation, published rulings, technical standards and official documentation, always cited in the text.