Search for a free OSHA 300 Log template and you will find two kinds of page: the ones that want your email address in exchange for a spreadsheet, and the ones that want you to believe a spreadsheet is dangerous. Both are selling something. The honest version is shorter.
OSHA's own forms package — the 300 Log, the 300A Annual Summary, the 301 Incident Report, the instructions, and the average-employees worksheet — is free at osha.gov/recordkeeping/forms, as fillable PDFs. The agency does not distribute a spreadsheet version, but it says on that same page that equivalent forms "may be maintained in any file format (e.g. Excel, CSV)" as long as the equivalent-form rule is met. So a 300 Log in Excel is not a workaround. It is a legal record, and for a single-site employer with a handful of cases a year and one person who knows the rules, it is often all you need.
What a template cannot do is enforce the rules. The regulation has a small number of places where a cell that accepts whatever you type will quietly produce a wrong record — and those are the places where the cost of being wrong is an inaccurate federal form, a citation, or a March 2 submission OSHA rejects. This guide names them, so you can decide with open eyes whether the spreadsheet is still the right tool. (If your question is simply may I keep the log electronically at all, that is answered in full here. The answer is yes.)
What "Equivalent Form" Actually Requires
The whole legal basis for a spreadsheet 300 Log is one sentence in 29 CFR 1904.29(b)(4): an equivalent form "is one that has the same information, is as readable and understandable, and is completed using the same instructions as the OSHA form it replaces."
Three tests, then. The template must carry every column of the official 300 Log — case number, name, job title, date, location, description, the four outcome columns (death, days away, job transfer or restriction, other recordable), the two day-count columns, and the six injury/illness type columns. It must be as readable as the printed form. And it must be filled in by the official instructions, which is where templates start to drift: the instructions say calendar days, say check only the most serious outcome, say write "privacy case" instead of a name in six situations, and a blank spreadsheet says none of that.
For the 300A there is an extra condition. The annual summary is the one form that gets posted and certified, and a substitute must carry the same certification block and the employee-access and penalty statements as the official form — OSHA's forms page cites 1904.32(b)(2)(iii) alongside the equivalent-form rule for exactly that reason. The safest practice, whatever you do with the log, is to transfer your totals onto OSHA's official 300A PDF for posting. It costs nothing.
The honest baseline
If you have one establishment, a stable workforce, and a recordable case every few months, a carefully kept spreadsheet plus OSHA's free 300A form satisfies Part 1904. Nothing in this guide changes that. The question is only whether your situation contains one of the five failure modes below — and whether the person keeping the sheet will still be there, and still remember the rules, in year four of the five-year retention window.
Where a Spreadsheet Genuinely Works
Be specific about the conditions, because they are the same conditions under which a template fails quietly when they stop being true:
- One establishment. Part 1904 requires a separate 300 Log per establishment, and the exemptions and ITA thresholds are evaluated per establishment too. One tab, one site, no ambiguity. (Two sites is where multi-establishment recordkeeping starts to complicate things.)
- Few cases. At three or four recordable cases a year, every day count, every reclassification, and every year-end total can be checked by hand against the rule.
- Cases that resolve quickly. A case that closes in a week never tests the 180-day cap or crosses a year boundary.
- One knowledgeable keeper. The rules the template does not enforce live in the head of whoever maintains it. That is fine as long as that person is consistent and stays.
- No 1904.41 submission duty. If your establishment is under 20 employees, or not in the designated industries, there is no CSV to produce and no portal to satisfy. (The free ITA Submission Checker settles this in a minute.)
If all five hold, keep the spreadsheet and apply the hygiene rules at the end of this post. If two or more have stopped holding, read on.
The Five Places a Template Breaks
Each of these is a rule the regulation states precisely and a spreadsheet cell cannot enforce. In each case the failure is silent: the sheet looks complete, and it is wrong.
1. Day counts are calendar days, start the day after, and cap at 180 combined
Columns K and L of the 300 Log are the most mis-kept cells in small-employer recordkeeping, because the official rule contradicts what most people assume. Under 1904.7(b)(3):
- The count begins the day after the injury occurred or the illness began — (b)(3)(i).
- You count calendar days the employee was unable to work, "regardless of whether or not the employee was scheduled to work on those day(s)" — (b)(3)(iv). Weekends and holidays count.
- You may cap the total at 180 calendar days — (b)(3)(vii) — and the cap is combined across days away and restricted days, not 180 for each.
- If the employee leaves the company for a reason unrelated to the case, you may stop counting — (b)(3)(viii).
A template gives you a cell. Whoever fills it in will type the number of workdays missed, because that is what the time-off system reports, or will type the count on the day the case was entered and never revisit it. Either way the 300A total days figure at year-end is wrong, and the error compounds: those day totals feed your DART rate and, if you submit, the ITA. The complete day-counting guide walks every edge case; a spreadsheet enforces none of them unless someone builds and protects a formula — and locks it against the next person who "fixes" it.
What it costs: a 300A that does not match the log, rate calculations built on bad inputs, and a standard correction item in a records inspection.
2. Privacy cases put the employee's name in the wrong place
Under 1904.29(b)(7), six categories of case are privacy concern cases, and in those cases you must not enter the employee's name on the 300 Log — you write "privacy case" in the name column instead. The list is exhaustive: injuries to an intimate body part or the reproductive system, injuries resulting from sexual assault, mental illnesses, HIV infection, hepatitis, or tuberculosis, contaminated needlesticks and sharps injuries, and any other illness where the employee asks that their name be left off. Then (b)(6): you "must keep a separate, confidential list of the case numbers and employee names" so you can update the cases and give the information to the government if asked.
A template has one name column. The moment a privacy case arrives, the spreadsheet needs a second, separately stored document, a rule about which copy of the log goes to whom, and the discipline to strip the name from every derived copy — the copy an employee or their representative can request under 1904.35, the version your insurance broker asked for, the CSV you export. In practice the name ends up in the log, or the confidential list ends up on the same tab, or a copy with names leaves the building. The privacy-case post has the details and the discretion rule in (b)(9) for the description column.
What it costs: a disclosure you cannot take back, and a 300 Log that is wrong in the one column the rule tells you to get right.
3. Cases change, and the log has to change with them
The 300 Log records each case under its most serious outcome, and cases evolve. An employee on restricted duty in March is put on days away in May after surgery. A "medical treatment only" case becomes a days-away case when the provider writes a note. Under 1904.33(b)(1) you must update the log — "you must update the stored OSHA 300 Log" is the rule for prior years, and the live year is held to at least the same standard by the instructions — to reflect changes in classification, description, and outcome.
In a spreadsheet that means finding the row, un-checking one outcome column, checking another, adjusting two day counts, and remembering that the 300A you already drafted is now stale. Nothing prompts any of it. The row was correct the day it was entered, and that is the last time anyone looked at it.
What it costs: a log that records what was true in week one, not what happened — which is what an inspector will compare against your workers' compensation file.
4. Year-end: the 300A has to equal the log, and then an executive signs it
1904.32 is a four-step duty: review the log "as extensively as necessary to make sure that they are complete and correct," total every column, certify, and post. The totals must agree with the log; a year with no recordable cases still gets a summary with zeros on it. A company executive — an owner, an officer, the highest-ranking person at the establishment, or that person's supervisor — must certify that they have examined the log and reasonably believe the summary is correct. The summary is posted from February 1 to April 30 where employee notices go.
The average-employees and total-hours fields have their own trap: the official worksheet computes annual average employees from pay periods, not a head count — add the employees paid in each pay period, divide by the number of pay periods (including any with zero), round up. The 300A guide works the arithmetic.
A spreadsheet with a SUM row handles the easy half. It does not handle the row someone deleted in October instead of lining out — which the 1904.33 retention rule does not permit — so the totals are now right for a log that is wrong. It does not carry the certification language. And it puts the executive's signature on a document whose accuracy they have no practical way to audit, which is precisely the exposure the certification exists to create.
What it costs: a certified, posted federal form that does not reconcile to its source, signed by the person with the most to lose from that.
5. The ITA file is a column-exact CSV you re-key by hand
If your establishment meets the 1904.41 thresholds — 20 to 249 employees in one of the designated high-hazard industries, or 250 or more in any industry required to keep records — you owe OSHA an electronic 300A submission through the Injury Tracking Application by March 2. Establishments with 100 or more employees in the narrower Appendix B industry list owe 300 and 301 case-level data as well. The ITA submission guide covers the portal mechanics.
The portal accepts a CSV in OSHA's exact column layout: a nine-digit EIN without dashes, a six-digit NAICS code, integer-only totals, establishment size in coded buckets, and for case data, 24 named columns with coded outcomes and mm/dd/yyyy dates — and its rejection messages are terse about which row failed. A spreadsheet 300 Log has none of that structure. Producing the file means re-typing every total, and for case data every case, into a second sheet built to OSHA's template, in deadline week. That re-keying step is where transcription errors enter the one copy of your record that goes to the government.
The free ITA CSV Validator will check a hand-built file against OSHA's published formats before you upload it, entirely in your browser. It cannot make the re-keying go away.
What it costs: a rejected submission two days before the deadline, or an accepted one that does not match the log you posted.
The pattern behind all five
Each failure is the same shape: a rule Part 1904 states in a sentence, a cell that accepts anything, and a gap of weeks or months between the entry and the moment anyone checks it. A spreadsheet keeps the record; it does not keep the rules. Whether that matters depends entirely on how many cases you have, how long they run, how many people touch the sheet, and whether anything you produce from it goes to OSHA.
If You Keep the Template: Six Hygiene Rules
There is no shame in the spreadsheet. Make it as defensible as it can be:
- Start from OSHA's columns, not a vendor's. Build the tab to mirror the official 300 Log exactly, in the official order, and keep the official instructions in a second tab. That is what (b)(4) means by "the same instructions."
- Make the day counts a formula and protect it.
=MIN(180, return_date - incident_date)with the return date as an input cell; lock the formula cells. Calendar days, starting the day after, capped at 180. - Never delete a row. Strike the text and add a note. The five-year retention rule in 1904.33 requires you to update stored logs, not rewrite them, and a deleted row cannot be explained later.
- Keep the privacy-case list in a different file with different access, and treat every export of the log as a copy that must be checked for names before it leaves.
- Post the official 300A PDF. Transfer your totals onto OSHA's form so the certification language and the access and penalty statements are there by construction. Keep the worksheet you used for average employees with it.
- Date-stamp a snapshot at year-end and after every update to a prior year. When a question arises in year four, you will need to show what the log said on a given date.
Or Download the Workbook That Has the Rules Built In
(Added August 24, 2026.) Most of the hygiene list above can be built into the file once instead of remembered every time, so we did that. The free auto-totaling 300/300A workbook is a plain .xlsx — no email address, no account; the link is the file — with the rules from this guide enforced in-sheet:
- the 300 Log tab mirrors OSHA's columns (A)–(M) in the official order, with the instructions in a Read Me tab — the (b)(4) "same instructions" condition from rule 1;
- the outcome columns G–J and type columns M(1)–M(6) only accept an X, and a row-check column flags a row with zero or two outcomes marked, a day count whose outcome box isn't checked, and combined day counts past the 180 cap;
- the 300A tab is formulas over the log — failure mode #4 (year-end totals that disagree with the log) is gone by construction, and the totals are pinned by automated test to the same math LogStead itself runs;
- the privacy-case convention from rule 4 is documented where you'll see it, in the file.
What it deliberately does not do: decide recordability, compute TRIR/DART, or generate the ITA CSV — failure mode #5 still applies to any spreadsheet, and the validator is the safety net when you re-key that file. And rule 5 stands: post the official 300A PDF, whatever totals your workbook computed.
When to Move
The decision rule is not "spreadsheets are unsafe." It is that the spreadsheet's cost is invisible until the year it is not. Move when any of these becomes true: a second establishment; a 1904.41 submission duty; more than a handful of cases a year, or cases that run past a quarter; a privacy case; a change in who keeps the record; or a year in which the 300A and the log disagreed and nobody could say why. Those are the conditions under which the rules the template does not enforce start producing wrong records on their own — and the buyer's checklist for recordkeeping software is built from exactly those rules, so you can hold any tool to them.
If you do move, you do not start over. LogStead imports an existing spreadsheet 300 Log from CSV — it matches your column headings to the official fields, validates every row against the same rules described above, and flags the day counts, outcome columns, and dates that need a second look before anything is recorded. From there the record keeps its own rules: calendar-day counts that keep accruing and cap at 180, privacy-case names suppressed on the log and every export, a 300A whose totals come from the log by construction, and the ITA CSV — including the 300/301 case file — generated in OSHA's layout rather than re-keyed. The free recordability checker and the live demo, which runs on sample data with no account, are the quickest way to see whether that is worth more to you than the template.