Colorado Rule of Evidence 901 (CRE 901) decides whether an exhibit, including an email, text message, photo, or computer file, has been shown to be what the party offering it says it is. The rule does not mention digital evidence, metadata, hash values, or chain of custody. Its test is short: there must be evidence sufficient to support a finding that the item is what its proponent claims. The rule then lists examples of ways to meet that test. This page explains the rule and how it is commonly applied to digital evidence.

Key Takeaways

  • CRE 901 requires evidence sufficient to support a finding that an item is what the party offering it claims. It applies to digital evidence the same way it applies to any other exhibit.
  • The rule does not require any particular method. Metadata, hash values, forensic images, and expert testimony are ways a party may try to meet the standard, not requirements written into the rule.
  • CRE 901 does not mention chain of custody. Records of who handled an item can help show it is what it is claimed to be, and gaps in those records give the other side grounds to argue tampering.
  • A witness with knowledge, the item’s own distinctive characteristics, or evidence that a process or system produces an accurate result can each be used, depending on the circumstances.
  • Authentication is only one condition for admission. An authenticated exhibit can still be kept out under other rules of evidence.

What Colorado Rule 901 Provides

CRE 901(a) states the general rule. The requirement of authentication “is satisfied by evidence sufficient to support a finding that the matter in question is what its proponent claims.” The rule calls authentication “a condition precedent to admissibility”, so an exhibit that has not been authenticated cannot be admitted.

CRE 901(b) then lists examples, “By way of illustration only, and not by way of limitation”. The examples most often relevant to digital evidence are:

SubsectionWhat the rule listsHow it can apply to digital evidence
CRE 901(b)(1)Testimony of a witness with knowledge that a matter is what it is claimed to beThe person who sent a text, took a photo, or downloaded a file
CRE 901(b)(3)Comparison by the trier of fact or by expert witnesses with specimens that have been authenticatedComparing a file with a copy already shown to be genuine
CRE 901(b)(4)Appearance, contents, substance, internal patterns, or other distinctive characteristics, taken together with the circumstancesA message that uses the sender’s nickname or refers to facts the sender would know
CRE 901(b)(5)Identification of a voice, including through an electronic recording, by someone who has heard the voiceA recorded call or voicemail
CRE 901(b)(9)Evidence describing a process or system used to produce a result and showing that it produces an accurate resultA forensic program used to copy a phone, or a camera system
CRE 901(b)(10)Any method of authentication provided by Colorado court rules or Colorado statuteMethods set out in another Colorado rule or statute

The rule’s text makes no distinction between criminal and civil cases. The standard is the same in both, and it is not the same as the burden of proof at trial. A person cannot be convicted unless guilt is proved beyond a reasonable doubt under C.R.S. 18-1-402, but that burden applies to the verdict, not to whether a single exhibit has been authenticated.

What Is the Purpose of Colorado’s Evidence Rule 901?

Why does Colorado’s Evidence Rule 901 matter? The rule sets the basic requirement that an exhibit be shown to be what it is claimed to be before it can be admitted. Electronic data can be edited, copied, or faked, so authentication questions come up often with digital evidence.

The rule does not mention digital evidence, chain of custody, or preservation practices. It sets one standard for every kind of exhibit: evidence sufficient to support a finding that the item is what its proponent claims. Meeting that standard does not make an exhibit admissible by itself. It clears only this one requirement.

How Does Rule 901 Define Authenticity in Digital Evidence?

CRE 901 does not have a separate definition for digital evidence. The same test applies to an email as to a paper letter: there must be evidence sufficient to support a finding that the item is what its proponent claims. The rule does not demand certainty.

Parties often use metadata, such as timestamps and file history, to help show where a file came from and whether it was changed. Testimony about how the file was collected and stored can serve the same purpose. The rule allows technical proof and expert testimony, but it does not require them. The examples in CRE 901(b) are illustrations only.

What Types of Digital Evidence Are Subject to Rule 901?

CRE 901 applies to every exhibit, so it covers emails, text messages, digital photographs, social media content, computer files, and data extracted from phones and other devices. The rule’s examples for public records and ancient documents, CRE 901(b)(7) and (b)(8), expressly reach data compilations “in any form”.

Metadata, such as timestamps, origin, and modification history, can help show a file’s source and whether it was changed. Records showing who handled a device or file are not required by the rule, but they are a common way to answer a claim that the evidence was altered.

What Methods Are Used to Authenticate Digital Evidence Under Rule 901?

CRE 901 does not require any specific technique. Parties commonly offer metadata analysis, hash value comparisons, and testimony from people or experts familiar with the systems involved. Each is a way to provide evidence sufficient to support a finding that the item is what it is claimed to be.

Common Authentication Techniques

Common approaches include forensic analysis of metadata, file structure, and access logs to show where a file came from. Hash values, such as MD5 or SHA-256, are used to show that a copy matches the original, because a change to the data produces a different hash value. Records of who collected and handled the evidence help answer claims of tampering.

Expert witnesses can explain technical processes. CRE 901(b)(9) allows authentication by evidence describing a process or system and showing that it produces an accurate result. System logs and testimony from a witness with knowledge under CRE 901(b)(1) can also help. None of these methods is required in every case. The question is whether, taken together, the evidence is sufficient to support a finding that the item is what it is claimed to be.

Digital Evidence Verification

How is digital evidence verified in practice? Forensic examiners compare hash values, review metadata, and document how the data was collected and stored. They use specialized tools to look for alterations, check timestamps, and identify the source of files. Testimony from people who created or stored the data can add support.

These are practical methods. CRE 901 itself asks only whether there is evidence sufficient to support a finding that the item is what its proponent claims.

How Do Courts Assess the Reliability of Digital Evidence in Colorado?

The question under CRE 901 is whether digital evidence has been authenticated: whether there is evidence sufficient to support a finding that it is what the proponent claims. Courts look at how the data was collected, preserved, and connected to its claimed source when deciding that question.

Authentication Requirements

The central question is whether the party offering digital evidence has authenticated it under CRE 901. That means showing the item is what it is claimed to be. Records of how the evidence was collected and stored, and technical markers such as digital signatures, can support that showing, but the rule does not require either one. Because CRE 901(a) makes authentication “a condition precedent to admissibility”, an exhibit that is not authenticated cannot be admitted.

Judicial Evaluation Criteria

When a party challenges digital evidence, the judge may hear evidence about how the data was acquired, who handled it, and what tools were used to extract it. Expert testimony may be offered to explain technical points.

The standard stays the same: evidence sufficient to support a finding that the item is what its proponent claims. The rule does not require the party offering the evidence to rule out every possibility of tampering. Admission also does not end the matter. The other side can still argue to the jury that the evidence was altered or is not what it appears to be.

What Role Do Witness Testimonies Play in Authenticating Digital Evidence?

Technical data does not always tell the whole story, and witness testimony is often central to authentication. CRE 901(b)(1) lists “Testimony that a matter is what it is claimed to be” as an example of proper authentication. A witness can explain where a file came from, who sent a message, or how a device was handled.

Expert testimony can interpret technical data and describe how evidence was extracted and preserved. CRE 901(b)(3) allows comparison by expert witnesses with specimens that have been authenticated. Lay and expert testimony often work together, with a witness supplying the context and an expert supplying the technical explanation.

How Does Rule 901 Address Challenges to Digital Evidence Authenticity?

How does CRE 901 handle disputes about authenticity? The rule sets a flexible standard: evidence sufficient to support a finding that the item is what its proponent claims. It says nothing about encryption, and it does not list any technical step that must always be taken.

Under CRE 901(b)(4), appearance, contents, substance, internal patterns, or other distinctive characteristics, taken together with the circumstances, can be used. That allows a party to combine direct and indirect evidence, such as metadata, account information, and witness accounts, to meet the standard. Meeting it makes the item authenticated. It does not settle every other question about whether the item can be admitted.

What Are Common Pitfalls in Presenting Digital Evidence Under Rule 901?

Common problems in presenting digital evidence under CRE 901 come from a weak foundation. Failing to review or explain metadata can leave the origin, date, or integrity of a file open to challenge.

Gaps in the records of who handled a device or file can support an argument that the evidence was altered. CRE 901 does not require a chain of custody record, but a party without one needs other evidence connecting the item to its source. Offering digital evidence with no witness or technical explanation of where it came from risks a finding that it has not been authenticated, since CRE 901(a) requires evidence sufficient to support a finding that the item is what it is claimed to be.

Lawyers handling digital evidence usually plan how they will authenticate it before trial. That often means using forensic methods to show where the evidence came from and that it has not been changed. Metadata can show timestamps, access logs, and modification history. A qualified forensic examiner can document the process and testify about it.

StepActionPurpose
Digital Forensic ImagingCreate exact copies of dataPreserve original evidence
Metadata AnalysisExamine file propertiesVerify authenticity and timeline
Expert TestimonyPresent forensic findingsEstablish credibility in court

These steps are not required by CRE 901, but they make the rule’s standard easier to meet and the evidence harder to challenge.

Frequently Asked Questions

Can Digital Evidence Be Authenticated Without Expert Testimony Under Rule 901?

Yes. Nothing in CRE 901 requires expert testimony. A witness with knowledge can testify that an item is what it is claimed to be under CRE 901(b)(1), and distinctive characteristics such as contents and internal patterns, taken together with the circumstances, can be used under CRE 901(b)(4). A person who has heard a voice can identify it on a recording under CRE 901(b)(5). Expert testimony is more likely to be needed when technical details, such as metadata or a digital signature, are in dispute.

How Does Rule 901 Interact With Other Colorado Evidence Rules?

CRE 901 covers only authentication. CRE 901(a) makes authentication “a condition precedent to admissibility”, but an item that is authenticated can still be kept out under other rules of evidence, such as the rule against hearsay. CRE 901(b)(10) also recognizes any method of authentication provided by another Colorado court rule or by Colorado statute.

No Colorado rule names or recommends any particular software. Forensic examiners commonly use programs such as EnCase, FTK, and Autopsy to copy and analyze data. What matters under CRE 901 is the evidence about the result. CRE 901(b)(9) allows authentication by evidence describing a process or system used to produce a result and showing that it produces an accurate result, so an examiner may need to explain how the tool works and why its results can be trusted.

What Happens if Digital Evidence Is Found to Be Tampered With?

If there is evidence that digital evidence was altered, raising the possibility of digital forgery, the party offering it may be unable to show that it is what it is claimed to be, and the judge may refuse to admit it. Breaks or inconsistencies in the record of who handled the evidence can support that challenge. Even if the item is admitted, the other side can still argue to the jury that it was altered.

Does Rule 901 Apply Differently in Criminal Versus Civil Cases?

The text of CRE 901 makes no distinction between criminal and civil cases. The authentication standard is the same in both: evidence sufficient to support a finding that the item is what its proponent claims.

What differs is the burden of proof for the case as a whole. In a criminal case, no one can be convicted unless guilt is proved beyond a reasonable doubt under C.R.S. 18-1-402. In a civil case, the burden is generally a preponderance of the evidence under C.R.S. 13-25-127(1). Those burdens apply to the verdict, not to each exhibit. The prosecution does not have to prove an exhibit is authentic beyond a reasonable doubt before it can be admitted.