FRE 902(13) and 902(14): When an Electronic Record Authenticates Itself
Updated on
FRE 902(13) and 902(14) let a federal court take an electronic record without the witness who produced it. A written certification signed by a qualified person replaces live testimony: under 902(13), that the system generating the record produces an accurate result; under 902(14), that data copied from a device matches the original, verified by a process of digital identification. Both took effect on 1 December 2017, after the Judicial Conference approved the amendments in September 2016. Neither makes the record admissible. They settle authenticity and nothing else, and a certification can still fail on procedure: who signs it, what it says and whether notice was properly given.
What decides a case is narrower: what the certification must say, when the opponent can force you back to live proof, and what the rule leaves untouched. The wider frame sits in our guide to authentication of digital evidence under Rule 901.
This insight is part of our guide: FRE 901 and the Authentication of Digital Evidence
What 902(13) and 902(14) actually say, and how they differ from 901
The two subsections split by object: one certifies a system, the other certifies a copy. Both take their form and their notice obligation from Rule 902(11) or (12).
902(13): a record generated by an electronic process or system
902(13) carries the caption “Certified Records Generated by an Electronic Process or System” and covers “a record generated by an electronic process or system that produces an accurate result”, certified by a qualified person under the requirements of Rule 902(11) or (12) (Cornell LII, Rule 902). The object is the process, not the file. Server logs, access records, telemetry, transaction records written automatically by an application: the qualified person attests that the system yields an accurate result, and nobody swears to any single entry.
902(14): data copied from a device, and the process of digital identification
902(14) carries the caption “Certified Data Copied from an Electronic Device, Storage Medium, or File” and covers data copied from those sources “if authenticated by a process of digital identification”. Here the object is the copy. The 2017 Committee note explains the mechanism: a hash value comes from an algorithm run over the digital contents of a drive, medium or file, and “if the hash values for the original and copy are the same, it is highly improbable that the original and copy are not identical”. In practice SHA-256 is widely used, although the note names no algorithm and keeps the rule “flexible enough to allow certifications through processes other than comparison of hash value”. For electronically stored information (ESI), the note records that copied data “are ordinarily authenticated by ‘hash value'”.
TrueScreen, the Data Authenticity Platform, records the hash at the moment of capture and applies a timestamp qualified under the EU eIDAS Regulation, so the reference value for any later hash comparison exists before the content can change. Running that comparison and certifying it under Rule 902(14) remain the work of a qualified person.
When Rule 901 extrinsic evidence is still needed
Self-authentication is a shortcut, not a separate track. Knock the certification down and the record stays in the case: the proponent falls back to Rule 901 and proves authenticity with extrinsic evidence, usually the custodian or the examiner on the stand. That trade-off belongs to the parent guide on Rule 901 authentication of electronic evidence.
| What is certified | What it requires | What it does not cover | |
|---|---|---|---|
| FRE 902(13) | The process or system that generated the record | Certification by a qualified person, in the form set by 902(11) or (12) | Hearsay and other objections |
| FRE 902(14) | The copy, as identical to its source | A process of digital identification, usually hash comparison, plus the same certification | When the copy was made, and whether the source was intact |
| FRE 901 | Nothing in advance: authenticity is proved in the proceeding | Extrinsic evidence, usually a witness with knowledge | Nothing is excluded, but the hearing time is yours |
What the qualified person’s certification must contain
The rule prescribes no form. It requires compliance with 902(11) or (12), which puts two obligations on the proponent: the substance of the attestation, and reasonable written notice to the other side.
Who counts as a qualified person
A qualified person is whoever can attest to the process from real familiarity with it. The rule creates no credential, requires no court appointment and does not reserve the role to the records custodian: a systems administrator who runs the logging infrastructure can certify under 902(13), the examiner who performed the acquisition under 902(14). The burden falls on whoever knows how the copy was produced, which is why a certification signed by counsel repeating what a tool reported is worth so little (Robins Kaplan on FRE 902(14) and eDiscovery).
The certification is that person’s own statement. For business records, Rule 902(11) speaks of “the custodian or another qualified person” and ties the attestation to the conditions of Rule 803(6). Rules 902(13) and 902(14) ask for “a qualified person” and, as the 2017 Committee note explains, take from 902(11) or (12) only the procedural requirements for a valid certification, not the business-records conditions. The Committee note to the 2000 amendment says that a declaration satisfying 28 U.S.C. § 1746, made under penalty of perjury, satisfies the declaration requirement of Rule 902(11); Rules 902(13) and 902(14) refer to those same certification requirements. The 2017 note asks for information that would be sufficient to establish authenticity if the person gave it as a witness at trial. A report, a log or a tool’s output can supply what the signer relies on; it cannot sign in the signer’s place.
Reasonable written notice and the opponent’s right of inspection
Rule 902(11) requires the proponent, before the trial or hearing, to give the adverse party “reasonable written notice of the intent to offer the record”. It fixes no number of days: what is reasonable depends on the case, and local rules or scheduling orders may set their own deadlines. The 2017 Committee note adds that challenging electronic evidence may require technical information about the system or process, possibly with a forensic expert, and that this affects whether the notice given leaves a fair opportunity to challenge it. The half that gets forgotten is the second one, since the record and the certification must also be made available for inspection so the other side has a fair opportunity to challenge them. Notice without access is not notice.
Hash value, qualified timestamp and chain of custody
A hash proves two files are identical. It says nothing about when either existed. That gap is where a 902(14) certification gets uncomfortable, because the objection actually raised is rarely “this copy is wrong” and usually “you cannot show what the source looked like at the relevant moment”. A qualified timestamp anchors the digest to a verified instant and turns an integrity claim into a dated one, and the digital chain of custody covers what happened between acquisition and production.
The word “qualified” means different things here. The qualified person of Rule 902 is a human being with real knowledge of the process, and the Federal Rules attach no credential to the term. A qualified timestamp or a qualified seal is a category of EU law: a trust service that meets the requirements of the eIDAS Regulation, which gives a qualified timestamp a presumption of the accuracy of its date and time and of the integrity of the data bound to it (Article 41). That presumption is EU law and the Federal Rules of Evidence contain no equivalent: in a federal court the timestamp is part of what the qualified person describes, not a substitute for the certification.
| Element | Statutory basis | If it is missing |
|---|---|---|
| The record and its source, identified | 902(13), 902(14) | The certification cannot be matched to the exhibit |
| Attestation that the system produces an accurate result | 902(13) | The subsection does not apply: back to Rule 901 |
| Digital identification process, algorithm and hash values | 902(14) | No basis to find the copy identical to the source |
| Signature of a qualified person with actual knowledge | 902(11), via (13) and (14) | The challenge lands on the signer, not the technology |
| Reasonable written notice to the adverse party | 902(11) | Self-authentication may be lost even if the record is genuine |
| Record and certification available for inspection | 902(11) | No fair opportunity to challenge, so the shortcut collapses |
| Acquisition timestamp and chain of custody | Not in the text, expected in practice | Nothing shows when the copy was made or who held it |
What self-authentication does not solve
Self-authentication answers one question. Read as an admissibility rule, which is the common misreading, it produces expensive surprises at the pretrial conference.
Authenticity is not admissibility: hearsay, relevance, confrontation
The 2017 Committee note is unambiguous: “A certification under this Rule can establish only that the proffered item has satisfied the admissibility requirements for authenticity.” Every other objection survives, including hearsay, relevance and, in criminal cases, the right of confrontation. A certified log of employee messages is authentic and still hearsay. Admissibility of digital evidence is a longer road, and these two subsections shorten one leg of it.
What makes a certification fail in court
The weak points can be procedural as much as technical. Notice served late, or without the record attached. A signer who pressed the export button but cannot describe the acquisition. A hash recorded after the file had already passed through three mailboxes. An acquisition documenting the copy without establishing what the original was, which is how screenshots collected by a client months before counsel arrived usually end. Parties outside the United States meet one more: material gathered under domestic practice and later produced in a federal proceeding can arrive with no written attestation of the copying process, because nothing at home asked for one. A certification can be built afterwards. A source that no longer exists cannot.
Certifying at the moment of capture, not downstream
TrueScreen, the Data Authenticity Platform, produces a forensic report that documents how the content was acquired, the hash algorithm and the digest, together with a digital seal and a timestamp qualified under the EU eIDAS Regulation. That report is the technical basis of the certification a qualified person signs under Rule 902(13) or 902(14), not the certification itself: the certification remains a statement by that person, who must be able to stand behind the process it describes, and serving notice on the other side remains the proponent’s job. TrueScreen is not a certificate authority and issues no qualified certificates.
Most accounts of 902(14) assume the data is sitting there waiting to be copied. Often it is not. Organizations use TrueScreen to certify content that will not exist by the time an expert can copy it: a story that expires in 24 hours, a page that is edited, a call that ends. A company finds its counterfeited mark in an Instagram story; a day later there is no original to hash and 902(14) is unavailable. Captured while it was live, the same story yields a file, a digest, a qualified timestamp and a report describing how each was produced.
Certified media files covers material already on a device, forensic acquisition of web pages what exists only online. Because the digital seal and the timestamp can be checked by anyone, the opposing party can verify the seal and the timestamp independently instead of relying only on what the qualified person’s certification says.
FAQ: FRE 902(13) and 902(14)
What is the difference between FRE 902(13) and 902(14)?
902(13) certifies a system; 902(14) certifies a copy. Under 902(13) a qualified person attests that the electronic process generating the record produces an accurate result, which fits server logs, telemetry and automated transaction records. Under 902(14) the same kind of person attests that data copied from a device, storage medium or file was authenticated by a process of digital identification, normally hash comparison. Both take the form of the certification and the notice obligation from Rule 902(11) or (12), so the paperwork is identical.
Who qualifies as a “qualified person” under 902(13) and 902(14)?
Anyone with genuine knowledge of the process being certified. The Federal Rules create no credential, no registry and no court appointment: a systems administrator responsible for the logging infrastructure can certify under 902(13), and the examiner who performed the acquisition can certify under 902(14). A certification is only as strong as its signer: counsel repeating a tool’s output cannot answer questions about how the copy was made. Software cannot take the role: a forensic report such as TrueScreen’s, documenting how the content was acquired with its hash and timestamp, is the technical basis the qualified person relies on, and the certification remains that person’s signed statement.
What must a Rule 902 certification contain?
The record and its source, identified precisely enough to match the exhibit; the attestation itself, meaning either that the system produces an accurate result under 902(13) or that the copy was authenticated by a process of digital identification under 902(14); the algorithm and hash values where 902(14) applies; and the signature of a person with actual knowledge, in the form required by Rule 902(11) or (12). The rule prescribes no template, so certifications vary in form. Acquisition time and chain of custody are not in the text, yet objections target them.
How much advance notice must be given under Rule 902(11)?
The federal rule sets no deadline. It requires “reasonable written notice of the intent to offer the record” before the trial or hearing, and reasonableness is measured against the case. Local rules and scheduling orders may set specific deadlines, so check the district before relying on any fixed period. Notice is also half the obligation: the record and the certification must be made available for inspection, so the adverse party can challenge them.
Is a hash value alone enough to self-authenticate evidence?
No. A hash establishes that two files are identical, which is what 902(14) asks for, but it carries no information about time. An opponent arguing that the source was already altered before acquisition, or that the copy was made after the relevant events, is not answered by a digest. A timestamp qualified under the EU eIDAS Regulation binds the hash to a verified instant, and a documented chain of custody covers the period between acquisition and production. The 2017 Committee note also treats hash comparison as one acceptable method among others.
Does a Rule 902 certification defeat a hearsay objection?
No. The 2017 Committee note states that a certification under the rule “can establish only that the proffered item has satisfied the admissibility requirements for authenticity”. Every other objection stays open: hearsay, relevance, unfair prejudice and, in criminal proceedings, the right of confrontation. A certified export of internal messages is authentic and still an out-of-court statement offered for its truth unless an exception applies. Reading these subsections as a route to admission is costly because the mistake surfaces at the pretrial conference.
Have states adopted equivalents of 902(13) and 902(14)?
Federal Rules 902(13) and 902(14) apply in federal courts. State courts apply their own rules of evidence, which may or may not contain provisions modeled on the federal text. Before relying on self-authentication in a state court, check that state’s current rule of evidence and any local court rules, or ask a lawyer admitted there.
Certify your digital evidence at the source
Capturing content with a forensic methodology, with the hash and the qualified timestamp applied at the moment of capture, means arriving in court with a documented process rather than a reconstruction after the fact.
TrueScreen editorial team
This section is edited by the TrueScreen editorial team, which brings together expertise in digital forensics, the law of digital evidence and regulatory compliance. Every article is checked against primary sources: legislation, published rulings, technical standards and official documentation, always cited in the text.
