Claude

IntuitionLabs is now a member of the Claude Partner Network – AI training and upskilling with Claude for pharma and biotech. Book a call.

IntuitionLabs
Back to Articles
IntuitionLabs

dscsa · eu fmd

DSCSA vs. EU FMD: A Pharma Serialization & Traceability Guide

January 6, 2026
Updated September 21, 2026
30 min read

Learn the key differences between US DSCSA and EU FMD for pharmaceutical serialization. This guide covers compliance requirements for ops teams, including data

DSCSA vs. EU FMD: A Pharma Serialization & Traceability Guide
Summary
  1. 01DSCSA requires secure, interoperable electronic exchange of transaction information and transaction statements for covered transactions, while EU FMD relies on verification and decommissioning through its repositories system.
  2. 02Serialization readiness is an operational program: packaging equipment, clean master data, systems integration, partner connectivity, testing, and trained teams must work together.
  3. 03FDA temporary exemptions had staggered expiration dates, while a limited exemption for qualifying small dispensers continues subject to its stated conditions.
  4. 04Partner connectivity is a critical path: shared network onboarding can be faster than bespoke point-to-point links, and readiness gaps can disrupt compliant product movement.
  5. 05Both frameworks can support supply-chain security, faster recalls, and richer data use after compliance capabilities are established.

[Revised April 24, 2026] This guide has been updated to reflect the post-deadline DSCSA landscape. FDA's stabilization period ended in November 2024, and FDA's October 9, 2024 exemptions from specified section 582 requirements for eligible trading partners ran through May 27, 2025 for manufacturers and repackagers, August 27, 2025 for wholesale distributors, and November 27, 2025 for dispensers with 26 or more full-time employees ([1]). Qualifying small dispensers remain exempt from certain requirements until November 27, 2027; eligibility is based on the owning company having 25 or fewer full-time employees licensed as pharmacists or qualified as pharmacy technicians as of November 27, 2026. Covered trading partners should determine their applicable section 582 obligations and any FDA waiver, exception, or exemption; FDA identifies a limited small-dispenser exemption through November 27, 2027 ([2]). EU FMD content has been updated to reflect Italy's continued staggered rollout and the Windsor Framework verification arrangements for Northern Ireland.

Executive Summary: Pharmaceutical operations teams must manage identifier and traceability obligations under both the U.S. Drug Supply Chain Security Act (DSCSA) and the EU Falsified Medicines Directive (FMD). The DSCSA, enacted in 2013, establishes product-identifier and interoperable electronic product-tracing requirements for products and transactions in scope, subject to statutory exclusions and any applicable FDA waiver, exception, or exemption ([3]). The EU framework—Directive 2011/62/EU and Delegated Regulation (EU) 2016/161, which generally applied from 9 February 2019—requires safety features for medicinal products within its scope; these include a unique identifier encoded in a two-dimensional barcode and an anti-tampering device, subject to the Regulation's annexes and Member State scope extensions ([4]). Compliance requires major changes in packaging lines, IT systems, data standards, and partnership workflows. In practice, many companies have struggled with these changes: industry surveys document that only a fraction of manufacturers/distributors were fully connected by mid-2022, and thousands of connections between partners may still be missing ([5]) ([6]). Operations teams must therefore prepare early, integrate serialization equipment and software into production lines, establish electronic data exchanges (e.g. EPCIS messages over AS2/SFTP), and coordinate testing with every trading partner (manufacturers, repackers, 3PLs, wholesalers, pharmacies, etc.) ([7]) ([8]). Building master data hygiene (GTIN, lot, expiry, serial ranges), validating scanning accuracy, and training personnel are also critical. This report unpacks the regulatory background, technical requirements, operational steps, systems and partner integrations needed in both the US and EU. We analyze survey data, case examples, and expert insights to guide operations leaders on planning, executing, and sustaining compliance with DSCSA and EU FMD serialization and traceability mandates.

01

Introduction and Background

Drug serialization and traceability laws were born from high-profile pharmaceutical safety incidents and globalization of supply chains. In the U.S., fatal tainted heparin cases (2008) and diverted counterfeit incidents prompted Congress to pass the Drug Supply Chain Security Act (DSCSA) in 2013, as Title II of the Drug Quality and Security Act ([9]). DSCSA’s goal is to “secure the pharmaceutical distribution supply chain” by requiring unit-level serialization and interoperable track-and-trace of prescription medicines ([10]) ([11]). Legacy state pedigree laws (e.g. CA, FL) had paved the way, and DSCSA gave industry a ten-year implementation plan ending with unit-level traceability by 2023 ([12]) ([13]). Similarly, Europe’s Falsified Medicines Directive (Directive 2011/62/EU, 2011) and its Delegated Regulation (2016/161, published 2015) were adopted to combat counterfeit drugs and ensure patient safety across the EU ([14]) ([15]). Effective 9 February 2019, prescription packs in the EU/EEA generally must carry a tamper-evident device and a 2D Data Matrix code, subject to the Regulation’s Annex I and II lists and any Member State scope extensions. The unique identifier contains a product code, serial number, batch number and expiry date, plus a national reimbursement or other national number where the relevant Member State requires it; GTIN is a commonly used product-code scheme, not a universal legal requirement ([14]). Persons authorised or entitled to supply medicines to the public must verify the safety features and decommission the unique identifier for a medicinal product bearing those features when supplying it to the public. A healthcare institution may perform those actions while the product is in its physical possession, subject to the Regulation's conditions and derogations ([16]).

Together, DSCSA and EU FMD now represent the global “gold standard” in pharmaceutical serialization, although they differ in specifics (see Table 1). In brief, DSCSA focuses on “transactional trace” by requiring electronic exchange of transaction information and transaction statements among authorized trading partners, without prescribing scanning at dispensing ([10]) ([17]). The EU FMD instead uses a point-of-dispense verification model: a pack’s unique identifier is checked against the repositories system, which comprises a central hub and national or supranational repositories ([18]). Both regimes require specified identifiers and machine-readable data, but neither statute makes GS1 numbering mandatory: DSCSA requires a product identifier using a data carrier that conforms to standards developed by a widely recognized international standards-development organization, while the EU Regulation specifies a Data Matrix and internationally recognised coding requirements ([3]) ([19]). Failure to comply can lead to supply disruptions, regulatory enforcement, and fines ([20]) ([21]). In practice, needed organizational investments are critical: companies must commit cross-functionally (operations, IT, quality, legal) to overhaul processes and systems, or risk losing market access ([20]) ([22]).

Table 1: Key Requirements of DSCSA (US) vs. EU FMD

T.01
AspectDSCSA (US)EU FMD (Europe)
RegulationDSCSA (2013); enhanced drug-distribution-security requirements became effective November 27, 2023. FDA’s 2024 exemptions for specified eligible trading partners ended in 2025; a limited small-dispenser exemption remains through November 27, 2027 ([23]) ([2]).Directive 2011/62/EU (2011) & Del. Reg. 2016/161 (2015); the Regulation generally applied from February 9, 2019. Article 50 deferred application for Belgium, Greece, and Italy no later than February 9, 2025; Italy’s domestic stabilization transition runs through February 9, 2027 ([16]) ([24]).
ScopeCovered human prescription drugs in finished dosage form and covered transactions, subject to statutory exclusions and FDA waivers, exceptions, and exemptions. FDA identifies, among other exclusions, OTC and animal drugs, blood products, radioactive and imaging drugs, certain IV drugs, medical gases, certain homeopathic drugs, lawfully compounded drugs, and excluded transactions ([25]).Prescription products generally, except Annex I exclusions; certain non-prescription products and products covered by Member State extensions are also in scope ([26]) ([14]).
Unique IdentifierA product identifier on each package and homogeneous case: a standardized numerical identifier (the package NDC plus a unique alphanumeric serial number), lot number, and expiration date, in human- and machine-readable form. An SSCC identifies a logistics unit and is not a substitute for this product identifier ([3]).A unique identifier encoded in a Data Matrix: product code, serial number, national reimbursement or other national number where required, batch number, and expiry date ([19]).
Tamper EvidenceNot mandated (focus on data); no tamper seal requirement.Mandatory anti-tampering device on each pack within scope; its integrity must be verified ([14]).
Aggregation (Case/Pallet)Not legally required, but often used internally for efficiency and easier recalls.Not mandated by law, though often implemented voluntarily (the EU law deliberately left aggregation voluntary ([27])).
Verification at DispenseDSCSA does not impose an EU-style point-of-dispense scan for every package; applicable dispenser duties depend on the product and transaction ([25]).Persons authorised or entitled to supply medicines to the public verify safety features and decommission the unique identifier for medicines bearing those features when supplied to the public. Healthcare institutions may do so at another time while the product is in their possession, and the Regulation provides further derogations ([16]).
Data Exchange StandardSecure, interoperable electronic exchange of transaction information (including package-level product identifiers) and transaction statements; FDA recommends EPCIS as an implementation standard ([28]).Repositories-system model: a central hub routes data between national or supranational repositories; the marketing-authorisation holder, or the responsible person for specified parallel products, ensures identifier information is uploaded, and wholesalers verify or decommission identifiers in the circumstances specified by the Regulation ([18]).
Records to MaintainTransaction information (TI) and transaction statements (TS) must be exchanged securely and interoperably for covered transactions; the requirement to provide and receive transaction history (TH) ended on November 27, 2023 ([8]) ([13]).Each repository must maintain an audit trail of operations on each unique identifier. A person supplying medicines to the public must record the identifier when a technical problem prevents timely verification and decommissioning; any additional pharmacy logging duty depends on applicable national law ([18]).
Authorized PartnersFirms must verify trading partners as “authorized trading partners” (ATP) before transaction ([10]) ([29]).No formal ATP concept applies; however, entities must generally be licensed to manufacture, wholesale, or dispense as per national regulations.
Enforcement DatesPhased: lot-level documentation (2015); product identifiers required for manufacturers from November 27, 2017 and repackagers from November 27, 2018; enhanced drug-distribution-security requirements became effective November 27, 2023, subject to FDA compliance policies and exemptions.Deadline Feb 9, 2019 for application of the Regulation, subject to the Regulation's stated national transitional provisions.
Objective/FocusTraceability for recalls, counterfeit prevention, pedigree (electronic pedigrees) ([10]) ([17]).Prevent falsified (counterfeit/tampered) products at point of dispense; harmonization of safety features and multi-country verification ([26]) ([15]).

(Note: Organizations often use GS1 standards and EPCIS to support product identification and data exchange ([30]) ([17]). Despite legal differences, both DSCSA and FMD share the aim of end-to-end product visibility backed by IT systems and cross-company integration.)

69%

Manufacturers planning to rely on 3PLs for connectivity

12%

Companies that completed end-to-end testing with a national system

53%

Surveyed CMOs citing partner readiness as their top integration risk

F.01
DSCSA exchanges transaction data, EU FMD verifies identifiers through repositories
DSCSATrack-and-trace
  • Covered transactions use secure, interoperable electronic exchange of transaction information and transaction statements.
  • DSCSA does not prescribe scanning every inbound package and permits aggregation and inference.
EU FMDTrack-and-verify
  • EU FMD safety-feature requirements apply to medicinal products within the Regulation's scope.
  • Manufacturers encode the unique identifier in a two-dimensional Data Matrix with product, serial, batch, and expiry data.
02

DSCSA Compliance: U.S. Track-and-Trace

Regulatory Milestones and Timeline

The DSCSA implementation is broken into distinct phases ([31]): (1) Lot-level traceability (2015) – basic exchange of transaction data at lot level, (2) Product identifiers – required for manufacturers from November 27, 2017 and for repackagers from November 27, 2018, and (3) Enhanced security and interoperability (effective November 27, 2023, later extended) – electronic, interoperable, end-to-end unit-level traceability. Section 582(g)(1) of the FD&C Act describes the final phase as “enhanced drug distribution security requirements” (effective 11/27/23) featuring unit-level serialization and an electronic system tracing packages throughout distribution ([13]). Congress’s 2013 law gave a 10-year clock, anticipating final enforcement in 2023, to allow industry time to build capabilities. In practice, however, the FDA delayed direct enforcement and granted a stabilization period: after November 2023 the agency said it would refrain from enforcement actions for one year to allow firms to refine their systems ([32]). On October 9, 2024, FDA used its statutory authority to grant time-limited exemptions from specified section 582 requirements for eligible trading partners ([1]). The result was a staggered schedule of temporary FDA exemption expirations (see Table 2):

  • Manufacturers & Repackagers: The temporary exemption expired May 27, 2025.
  • Wholesale Distributors: The temporary exemption expired August 27, 2025.
  • Dispensers (26+ employees): The temporary exemption expired November 27, 2025.
  • Qualifying small dispensers: A separate, limited exemption from specified requirements continues through November 27, 2027 ([23]) ([2]).

Throughout, FDA emphasizes that these date shifts apply only to the new “enhanced security” features; all other DSCSA obligations (record-keeping, ATP verification, handling suspect products) remain in force. Nevertheless, eligible trading partners must meet the applicable enhanced requirements for covered products and transactions after the relevant FDA exemption period, subject to statutory exclusions and any FDA waiver, exception, or exemption ([25]) ([1]).

Table 2: FDA’s 2024 Temporary DSCSA Exemptions

T.02
Entity TypeRelevant baselineTemporary exemption expiration or status
ManufacturersEnhanced drug-distribution-security requirements effective Nov. 27, 2023May 27, 2025
RepackagersEnhanced drug-distribution-security requirements effective Nov. 27, 2023May 27, 2025
Wholesale distributorsEnhanced drug-distribution-security requirements effective Nov. 27, 2023Aug. 27, 2025
Dispensers with 26 or more full-time employeesEnhanced drug-distribution-security requirements effective Nov. 27, 2023Nov. 27, 2025
Qualifying small dispensersSeparate exemption from specified requirementsThrough Nov. 27, 2027

Source: FDA, DSCSA exemptions notice and FDA, Exemptions under the Drug Supply Chain Security Act.

Note: Some large distributors (ABC, McKesson, Cardinal) even self-enforced accelerated timelines. In 2022 they issued letters requiring all partners to achieve interoperability by November 2022 – a year earlier than the law – and warned that they would refuse shipments unaccompanied by matching EPCIS data ([33]).

Data Standards and Exchanges

For products and transactions covered by DSCSA, manufacturers and repackagers must place a product identifier on each package and homogeneous case intended for introduction in a transaction into commerce. This “product identifier” includes the standardized numerical identifier, lot number, and expiration date. The product identifier on a package must be in a two-dimensional data-matrix barcode; a homogeneous case may use a linear or two-dimensional data-matrix barcode. The serialized data must correlate with the Transaction Information (TI) for that unit.

FDA recommends that trading partners use Electronic Product Code Information Services (EPCIS), the GS1 event-data standard, to support the required secure, interoperable electronic exchange ([28]). EPCIS provides a flexible XML/JSON framework for representing events like “commissioning”, “aggregation” and “shipment” of serialized items, and for sharing that data via web services or AS2/SFTP channels. For covered transactions, trading partners must use secure, interoperable electronic approaches to exchange transaction information, including package-level product identifiers, and transaction statements; they are no longer required to provide or receive transaction history. In practice, companies achieve this by sending an encrypted EPCIS message (sometimes called a transaction-information and transaction-statement data packet) over electronic networks as part of the order/invoice process ([17]) ([33]).

Many companies leverage master data synchronization (e.g. GS1’s GDSN) to ensure consistent product IDs and attributes, feeding serialization systems. GS1 affiliates, standards bodies, and the Healthcare Distribution Alliance (HDA) have championed EPCIS and AS2 as the “widely recognized” format and transport, respectively, to use under DSCSA ([17]). (FDA recommends EPCIS as an appropriate globally recognized standard, but its guidance does not prescribe EPCIS 1.2 as a minimum version ([28]).) Trading partners may use point-to-point, brokered, or other compliant technological approaches. FDA recommends EPCIS but recognizes that trading partners may choose the approach that suits their business needs if it meets applicable requirements ([28]). The industry has developed linking services (“brokered networks”) to simplify the many-to-many integrations, but companies can also build point-to-point links for each trading partner.

Operational Implications and Processes

For operations teams, DSCSA involves significant new steps throughout the supply chain:

  • Packaging and Serialization: On manufacturing lines, new equipment (high-speed industrial printers, laser coders, vision inspection cameras, line controllers) may be needed to print and verify single-unit 2D barcodes. Integrators must install serialization hardware and connect it to enterprise systems. Each line should be validated under the site's pharmaceutical quality system using a documented, risk-based approach and predefined acceptance criteria ([34]). Master data (NDC, lot, GTIN) from the ERP/MES must feed the serialization system so that each unit receives a unique serial. Line operators require training in the new processes; SOPs are updated for serialization tasks.

  • Aggregation (optional): While not legally mandated in the U.S., many firms implement parent-child linking (adding serialized unit IDs into case and pallet labels) to speed downstream scanning and recall. Aggregation scanners and software can automatically record the list of serials in a case. If used, this simplifies searching for batches in a recall. Without mandated aggregation, companies still often union serials in their own systems as a best practice.

  • Inbound Receiving: Wholesalers and repackagers should have procedures to receive the transaction information and transaction statement for covered transactions and to investigate suspect product. The DSCSA does not prescribe scanning every inbound package; it requires package-level electronic tracing and permits systems that use aggregation and inference. A person accepting a saleable return may accept it only if it can associate the return with its transaction information and transaction statement. Operational procedures should be reviewed by regulatory counsel ([3]) ([35]). Many distributors set up quarantine zones for any “product, no data” or mismatches — shipments lacking matching electronic traceability data are technically not compliant after 11/27/25 ([7]). Teams must build standard procedures for exception handling: manually checking labels, querying partners, or returning suspicious items. For covered products and transactions, the applicable trading partners must meet DSCSA documentation and electronic-interoperability requirements, subject to statutory exclusions and any FDA waiver, exception, or exemption ([7]) ([8]).

  • Information Systems Integration: Achieving interoperability requires linking the serialization subsystem to the corporate ERP/WMS and to communication platforms. Serialization software (many commercial products exist, e.g. Systech UniTrace, SEA Vision, TraceLink, Optel, Adents, etc.) generates and stores UII data and builds EPCIS messages. The ERP may need customization to consume EPCIS in lieu of traditional invoices. Companies often use middleware/brokers to connect to external partners via standard AS2 protocols and to manage date/time/sample events. Dedicated “ATP/verification” databases (internal master data of authorized licensees) must be built or purchased to confirm trading partner status. Post-implementation, routine processes must include automated exchange of transaction reports every day (or upon order/ship), with IT monitoring of any failed transmissions. Operational teams should plan for system maintenance windows and backups of serialized data.

  • Partner Coordination: DSCSA is explicitly a chain-wide mandate. Ops and IT teams must coordinate with customers and suppliers to ensure connectivity. For example, a contract manufacturer (CMO) must connect its own serialization system to each principal’s network or chosen interoperability platform; recall that one interviewee noted point-to-point onboarding with multiple partners can take over a year per partner ([36]). In contrast, using a networked tenant approach (e.g. many manufacturers using TraceLink’s cloud) can on-board each partner in 3–4 months ([36]). Similarly, if a manufacturer uses third-party logistics (3PL) providers, the 3PL must be brought into the data flow: the responsible trading partner must ensure the required transaction information and transaction statement are exchanged, depending on who “sold” the product downstream. The HDA survey found 69% of manufacturers plan to rely on 3PLs for connectivity (up from 62% prior) ([37]), highlighting how 3PLs sit at integration crossroads. Distributors in turn must establish connections to all manufacturing partners (the “big three” each work with hundreds of suppliers) and to downstream pharmacies. In short, operations leaders should inventory “who we ship to” and “who supplies us” and ensure data links to each. Think in terms of process flows across partners, not in isolation.

  • Training & Change Management: The introduction of serialization often requires retraining dozens of staff. Operators need to learn new line software and scanning devices; warehouse teams need new receipt/dispatch checklists; quality units gain new audit checklists focusing on serialization compliance; IT staff need to learn EPCIS formats and network protocols. Companies are advised to build dedicated cross-functional DSCSA teams (as one industry expert notes ([38])) to manage the change. At least one firm recommends formal “serialization working groups” akin to lean manufacturing cells to resolve data or process exceptions quickly. Only after pilot production runs and simulated shipments should full compliance begin, to uncover unforeseen gaps.

Overall, DSCSA compliance is not a one-time project but an ongoing operational discipline. It entails building capabilities for new recordkeeping every time product moves. FDA maintains a public database for wholesale-distributor and 3PL reporting and licensure information; it does not provide a national authorized-trading-partner compliance database. Trading partners remain responsible for meeting applicable authorization and DSCSA requirements ([39]). If companies are late or disconnected, major distributors warn they will not accept non-compliant shipments ([7]), so planning ahead is critical.

“

DSCSA compliance is not a one-time project but an ongoing **operational discipline**.

03

EU FMD Compliance: European Track-and-Verify

Regulatory Requirements and Systems

The EU FMD safety-feature requirements apply to medicinal products within the Regulation's scope. Manufacturers encode the unique identifier in a two-dimensional Data Matrix, and the unique identifier comprises a product code, serial number, batch number and expiry date, plus a national reimbursement or other national number where required by the Member State. GTIN is a commonly used product-code scheme but is not universally required. The Regulation also requires an anti-tampering device where safety features apply; verification and decommissioning duties vary by actor and circumstance.

The repositories system includes national or supranational repositories and a hub. Before release for sale or distribution, the marketing-authorisation holder must ensure the required information is uploaded and kept up to date; for specified parallel imported or distributed products bearing an equivalent identifier, that duty rests with the person responsible for placing the product on the market. For multinational players, this means multi-country registrations and technical on-boarding in each NMVO (or multi-country solutions). Sum of data flows across >30 national systems can be complex. In August 2018, EMVO reported that out of over 2,000 pharma manufacturers in the EU, only ~106 had fully connected to NMVOs/hub, with another 347 in technical on-boarding ([40]). A 2018 industry poll found only 12% of companies had completed end-to-end testing with a national system ([41]). Many manufacturers managed this via providers like TraceLink or SEA Vision who had pre-validated interfaces. Those who attempted custom, point-to-point connections often faced six-figure consulting projects or long delays (over 12 months) ([36]) ([42]).

Operational Implications

Operations teams preparing for EU FMD face challenges both similar to and different from the US. Key considerations include:

  • Labeling and Artwork: Packs must be redesigned to include the 2D code and a tamper-visible feature (foil seal or cap). Artwork change management is a large undertaking – it was noted that only ~10% of companies had fully updated artwork by 2018 ([43]). Any pack format change triggers regulatory re-approval and inventory adjustments. Serialization adds size to labels, often requiring multi-line print areas or expanded packaging. All label templates in IT systems (ERP, label management) must be updated.

  • Data Requirements: The 2D barcode’s data fields reside in various systems: GTIN may come from the SAP/MM master recipe; batch/expiry from MES; serials often from a dedicated serialization database. Ensuring data “cleanliness” is essential. As one industry guide advises, “master data – including GTINs – is commonly stored in an ERP system” and must be accurate when transferred to EMVS ([44]). Generating serials via software ensures unique use. Packaging lines use serialization modules that tie into ERP/MES to receive production orders and output coded cartons. These systems must also interface with the NMVS hub to register the codes.

  • Integration with NMVOs/Hub: Unlike DSCSA’s decentralized EPCIS network, FMD uses a repositories system composed of a central information and data router (hub) and national or supranational repositories connected to it. The marketing-authorisation holder, or the responsible person for specified parallel products, must ensure that identifier information is uploaded to the repositories system before release for sale or distribution. Persons authorised or entitled to supply medicines to the public connect through the national or supranational repository serving their Member State; teams should confirm the applicable national system’s technical and participation requirements ([18]).

  • Artwork & Pharmacy Workflow Changes: Pharmacies and hospitals were given guidance years in advance. In the UK, for instance, community pharmacists were warned (in 2018) that they would need to update their dispensing software, install 2D-capable scanners, and train staff for new scanning procedures ([45]). For medicines bearing safety features, persons authorised or entitled to supply them to the public must verify the safety features and decommission the unique identifier at the time of supply, subject to the Regulation's healthcare-institution timing rule and other derogations. Teams should account for applicable scanning and exception-handling workflows.

  • Distributor and Wholesaler Role: The Regulation requires wholesalers to verify the authenticity of identifiers in specified circumstances, including certain returned products and products received from specified wholesalers; it also requires decommissioning in specified circumstances. Member States may impose additional wholesaler verification and decommissioning duties for particular supply-chain arrangements. The Regulation does not itself establish a general rule assigning a wholesaler liability when a pharmacy has a scanner problem ([16]).

  • Multi-Network and CMO Coordination: Contract packers and CMOs have found the “onboarding” of their clients to be very challenging ([46]). For example, Recipharm (a leading CMO) pointed out that using a common network/tenant approach (where all partners connect to the same cloud platform) took only 3–4 months per partner, whereas bespoke point-to-point onboarding could exceed a year ([36]). With the EU deadline, over half (53%) of surveyed CMOs cited partner readiness as their top integration risk ([47]). In practice, smaller CMOs often team up with larger ones or invest in turnkey solutions, since custom software would be prohibitive at short notice ([48]).

Implementation and Best Practices

Given the complexity, operations best practices for EU FMD compliance include: convene a Multi-Disciplinary Team early (production, quality, IT, logistics) to map all packaging lines, IT systems, and legal obligations ([49]). Develop a project roadmap: from ordering and installing printers/scanners, to validating connection to NMVO test environments, to running pilot packs. Keep a master list of GTINs that will be exported to each country, and double-check that every product code has an assigned serial number block in your software.

Invest in or update serialization software: as the worldpharma article notes, “Serialization software is therefore an essential requirement to help you maintain control” of the complex master data and serialization process ([50]). This software typically generates serial numbers in the required format, prints or communicates them to packaging lines, and uploads them to the repositories. Validate at every step: printing, scanning, data upload. Engage labeling vendors to pre-verify label formats.

Finally, prepare the supply chain for new workflows: inform downstream customers of forthcoming changes, test transmissions with them early, and establish documented technical-failure procedures that follow Article 29 and the applicable national NMVO procedure. Where a technical problem prevents timely verification and decommissioning at supply, record the unique identifier and, as soon as the problem is resolved, verify its authenticity and decommission it; do not treat a generic manual override as a substitute. Ensure every operating site (plants, warehouses) is aware of aggregation options: while not legally needed in the EU, linking packs to cases locally can reduce error-checking time ([16]).

04

Case Studies and Examples

Illustrative DSCSA Scenario – Large Pharmacy Chain: In this hypothetical scenario, a U.S. pharmacy chain deploys DSCSA capabilities by integrating a serialization module with its distribution center WMS. Packaging lines at their owned brand facilities were retrofitted to add DataMatrix printers. The IT department built a daily automated AS2 connection with their primary generic drug manufacturer to receive EPCIS transaction-information and transaction-statement files. The integration required cross-departmental effort: product managers standardized NDC data, warehouse IT updated scanning handhelds, and training sessions ensured staff knew to reject shipments lacking matching serials. In the scenario, the chain connects its highest-volume suppliers in production, allowing it to receive products with the required information ([5]) ([51]). (This mirrors the PharmaTech report that by Q4 2021, still ~55% of manufacturers were not yet connected into production ([5])—our hypothetical chain outperformed that trend.)

EU FMD Implementation – Contract Packager: Recipharm, a large CDMO, was interviewed about its EU compliance strategy. By 2018, it had chosen to partner with a validated cloud network (TraceLink) so that each of its customers’ serialized orders could be seamlessly sent through the same tenant. Recipharm noted that for partners who insisted on direct, custom data connections, onboarding took over a year per partner ([36]). In contrast, on the shared network approach, getting a customer up and running typically took only 3-4 months ([36]). They recommended to focus on established solutions rather than building new custom links at this late stage. As of mid-2018, only about 5% of European pharma companies had fully connected to the NMVS hub ([42]) – meaning plenty of late adopters. But Recipharm reported that by early 2019 all of its active clients were operational. Their operational steps included: auditing which product-market combinations needed registration, deploying new Meyer label printers on lines for the 2D codes, and testing outbound shipments in a staged manner (first record-keeping, then partial scans, then full verification) months ahead of February 2019.

Indian Exporter Facing FMD: Indian pharma companies exporting to Europe raced to implement FMD after realizing it would affect their EU sales. One technical lead explained that a crucial first step was “understanding the data implications” – specifically, ensuring the ERP held clean GTINs, batch, and expiration fields for every product. The 2D Data Matrix encodes the unique identifier: product code, serial number, batch number and expiry date, plus a national reimbursement or other national number where required; GTIN is one commonly used product-code scheme ([44]). Their solution was to deploy a serialization software (cloud-based) that interfaced with SAP to pull each order’s GTIN/batch/exp, generate a unique serial, and print it. By the same token, Indian manufacturers had to sign up with EMVO and broker access to each relevant NMVO. Operationally, this meant scheduling data loads around Europe’s national holidays, and sometimes pulling employees to local time zones for NMVO connectivity testing. The upshot was that, despite a late start, a few leading exporters managed by early 2019 to gain market access, while others lost contracts due to delays in FMD readiness.

These examples illustrate common themes: heavy systems integration work, high dependency on network partners, and the critical path often being dates of testing with customers and regulators. In all cases, companies stressed “don’t underestimate how long connectivity takes” and “train staff on the new process flow long before the deadline,” echoing industry voices ([20]) ([51]).

05

Challenges, Risks, and Mitigation

Despite progress, many challenges remain in serialization rollouts:

  • Trading Partner Readiness: Multiple surveys have flagged partner collaboration as a major bottleneck. A 2022 HDA report noted that even by late 2021, over half of manufacturers were not yet exchanging serialized data in production with their distributors ([5]). In Europe, as noted, many smaller CMOs and marketers delayed onboarding. Ops teams must proactively reach out early; do not assume just because one side has the tech ready that all partners will be. Establish a partner readiness schedule, with clear communication and “hard cutoff” deadlines — as distributors in the US have done with firm letters ([7]).

  • Data Quality and Format Issues: Any discrepancy in NDC/GTIN master data or formatting can cause a transaction to fail. Operations should institute data validation routines (e.g. confirm that scanned GTINs exactly match ERP records). The BioProcess Intl. article warns that integration testing for EPCIS “requires extensive testing to ensure data integrity” ([52]). Companies have discovered issues like serials being used twice or missing decimal places in lot numbers. Automated data checks, duplicate tracking, and reconciliation reports are essential. It is recommended to simulate end-to-end scenarios where a small batch is serialized, shipped, verified, and (if needed) returned, to surface any mismatch in advance.

  • Technical Complexity and Cost: Both serialization and traceability add capital and operational expense. Packaging lines may slow down with extra printing steps, and yield loss can occur if a misprint goes undetected mid-run. A Quality-level failure (e.g. smashed code) requires scrapping perhaps thousands of units if caught late. Repair of blocks, re-assigning serials, and inventory reconciliation become everyday tasks. From the enterprise standpoint, ERP/IT teams often face “rampant customization,” which conflicts with their general move toward cloud and SaaS systems. Building and operating an EPCIS node is outside many organizations’ core skillset. Consequently, many outsource to vendors or adopt SaaS “compliance cloud” solutions that handle most heavy lifting (e.g. Certificate management, AS2 network, EPCIS repository). Ops teams should therefore budget sufficient resources and engage knowledgeable vendors early.

  • Scalability and Future Proofing: The regulations evolve over time. Under the Windsor Framework, EU FMD safety-feature requirements no longer apply in Northern Ireland from 1 January 2025, and the UK National Medicines Verification System is no longer available ([53]). Greece and Italy have staggered FMD rollouts (Italy granted until 2027) ([54]). DSCSA may see future interoperability improvements (e.g. discussions on national label scanning database). Investing in flexible architecture (cloud-native, multi-tenant solutions which can incorporate new countries or new requirements) reduces repeat work. Integrating global serialization needs (Brazil, China, India, etc.) on the same platform can provide economies of scale.

  • Pharmacy and Hospital Adoption (EU-specific): Surveys of pharmacists reported anxiety and frustration; an academic study showed that community pharmacists anticipated increased dispensing time and IT glitches ([45]) ([55]). Ops teams on the distribution end must be prepared for some returned goods or queries from pharmacies who find “unverified” medicines (e.g. foreign packs or pack damage). Close liaison with pharmacy chains and professional bodies is advisable. The goal should be “fail-safe for the patient”—multiple sources emphasize keeping supply moving during this shift.

Despite challenges, compliance yields long-term benefits. Both DSCSA and FMD ultimately enable faster, more surgical recalls, reduced counterfeit risk, and richer data for analytics. Industry experts note that once networks are built, companies can leverage the data stream for inventory optimization, asset tracking, and patient safety cases (e.g., tamper alerts or expire-date-based pull-forward). In fact, GS1 notes that the same EPCIS infrastructure can benefit other product lines (e.g. medical devices) and support future regulations ([30]).

“

The goal should evolve from “just avoid fines” to “get full visibility of our supply chain.”

06

Future Directions and Industry Outlook

Although the immediate legislative deadlines are now mostly passed, serialization and traceability will continue to evolve:

  • Global Harmonization: Many other regions (Brazil, Turkey, China) have adopted serialization laws mirroring or even exceeding EU/US requirements. Future business requires integration of these multiple “track-and-trace” regimes. For example, Brazil’s ANVISA set deadlines around 2022-23 for full 2D serialization on all Rx, plus multi-level aggregation and a national traceability system (SNCM). Drug manufacturers serving global markets are pushing toward unified serialization platforms that can output whichever national format (ITV codes, GTIN+serial structures) is required, with separate gateways to each country’s data hub. This will be an ongoing operational issue.

  • Technology Advancements: On the horizon are new tech approaches. Some countries (e.g. Gulf Cooperation Council members) are exploring blockchain-based traceability ([56]). The industry is also evaluating Internet-of-Things (IoT) sensors for real-time location tracking, though that remains nascent. In the U.S., discussions continue about whether to build a national drug-tracking database or master scan system as called for in legislation—if implemented, this would require yet another wave of integration.

  • Regulatory Compliance: FDA states that trading partners unable to meet the enhanced drug-distribution-security requirements may request a waiver, exception, or exemption and should continue compliance efforts while FDA considers the request. In the EU, national competent authorities supervise repositories and may inspect them under the Delegated Regulation. Organizations should maintain records and audit trails required by applicable law and their quality systems.

  • Enhanced Data Use: In the future, companies may exploit the rich serialized data. For example, advanced analytics can flag anomalous shipment patterns (possibly indicating theft or diversion) or improve recall accuracy by quickly telling exactly which serials/batches were at risk. Artificial intelligence tools are emerging to manage exception queues (e.g. algorithms that predict likely causes of “false scans” or route suspect packs for quarantine). While these are not requirements now, operations teams should be aware that the data they’re collecting may later power such capabilities.

Overall, serialization and traceability systems are becoming a permanent part of pharmaceutical manufacturing infrastructure. Operations teams should not view them as a short-lived compliance project, but as a new mode of business. The goal should evolve from “just avoid fines” to “get full visibility of our supply chain.” For example, metrics such as “percent of shipments delivered with correct data” or “error rates in serial matching” can become KPIs. Building relationships now with data service partners (veterans like GS1 Connect, industry consortia, technology providers) will pay dividends as the ecosystem matures.

07

Conclusion

The DSCSA and EU FMD have materially changed pharmaceutical supply-chain operations. Their obligations apply to products, transactions, and medicines within their respective legal scopes; they do not create a universal requirement to track every unit in every circumstance. Achieving compliance requires thorough planning: upgrading equipment and software, mapping data flows, testing connections with hundreds of partners, and integrating new steps into daily operations. Data from industry surveys and regulatory guidance all underline one point: the earlier and more comprehensively an operations team acts, the smoother the transition will be ([8]) ([36]).

As of April 2026, the FDA’s limited 2024 exemptions for eligible manufacturers and repackagers, wholesale distributors, and dispensers with 26 or more full-time employees had ended on May 27, August 27, and November 27, 2025, respectively. These were not general DSCSA enforcement deadlines or new package-serialization dates. Qualifying small dispensers remain exempt from certain requirements through November 27, 2027; for that exemption, the owning company must have 25 or fewer full-time employees licensed as pharmacists or qualified as pharmacy technicians as of November 27, 2026. Covered trading partners remain subject to the applicable section 582 requirements for covered products and transactions unless a statutory exclusion or an FDA waiver, exception, or exemption applies ([23]) ([2]). In the EU, the 2019 application date has passed. Organizations should assess their current obligations and any applicable national implementation measures rather than assume that only interoperability edge cases remain.

Operations leaders must therefore prioritize:

  • Cross-functional program teams: Ensure communications between packaging, IT, quality, and external affairs.
  • Technology investment: Deploy proven serialization software/platforms, and strengthen IT connectivity (AS2 certificates, cloud services, etc.).
  • Partner collaboration: Actively coordinate testing with CMOs, distributors, repackers, and customers (wholesalers/pharmacies).
  • Training & SOPs: Update workflows and train all relevant employees in new procedures (line operators, warehouse staff, pharmacists).

For products, transactions, medicines, and actors within scope, applicable requirements must be met, subject to statutory exclusions, national implementation rules, and any valid FDA waiver, exception, or exemption. Successful implementation can also support supply-chain security and recalls. The investment today in serialization traceability is the foundation for a more secure and transparent pharmaceutical ecosystem tomorrow ([57]) ([26]).

Sources: Government and industry regulations, whitepapers, and trade publications were used to compile this report. Key references include FDA guidance and industry surveys on DSCSA ([13]) ([37]), EU Commission regulations and EMVO reports ([14]) ([42]), and commentary from pharmaceutical packaging and supply-chain experts ([10]) ([46]) ([51]) ([45]). Source authority varies by claim; legal and regulatory requirements should be checked against the applicable official text and current regulator guidance. (For brevity, major sources are condensed into select inline citations above.)

The publisher

About IntuitionLabs

Build practical AI for pharma and biotech with IntuitionLabs. We help life-science teams turn complex information and workflows into useful software, governed knowledge systems and AI tools.

IntuitionLabs is an AI consulting, custom software development and data engineering firm serving pharmaceutical, biotechnology, medical-device and other life-science organizations. We work with clinical, regulatory, medical-affairs, commercial, quality and IT teams to connect technology decisions with the work people need to accomplish.

AI consulting and adoption

Our AI enablement services cover readiness assessments, use-case selection, governance and policies, team workshops, adoption measurement and ongoing advisory support. We help organizations structure the information layer behind AI: source material, context, permissions and maintained knowledge that make generated answers useful and reviewable. Private LLM inference and hosted AI options support teams evaluating how to operate AI with appropriate control over their data and infrastructure.

Software, data and life-science workflows

IntuitionLabs develops custom software for pharma and biotech, integrates enterprise systems, and builds data engineering and business intelligence solutions. Areas of focus include AI agents, regulatory research, medical writing, medical affairs, CMC information, competitive intelligence and clinical-document workflows. Our eTMF intelligence work includes cross-system reconciliation and inspection-readiness support.

Enterprise platforms and regulated delivery

We provide Veeva services, application support, managed services, integrations and custom applications, alongside enterprise content work involving platforms such as Egnyte. For regulated workflows, our services include GxP enablement, computer-system validation and software development addressing 21 CFR Part 11 requirements. The applicable controls, validation responsibilities and acceptance criteria are defined for each engagement.

Work with IntuitionLabs

Explore AI enablement, pharma and biotech software development, data engineering and BI, and Veeva services. Contact IntuitionLabs to discuss your workflow, information sources and implementation needs.

IntuitionLabs publishes educational research to help life-science teams make informed technology decisions. Coverage of a product or organization does not imply a client relationship, endorsement or partnership.

Sources / 57
Adrien Laurent

Need Expert Guidance on This Topic?

Let's discuss how IntuitionLabs can help you navigate the challenges covered in this article.

I'm Adrien Laurent, Founder & CEO of IntuitionLabs. With 25+ years of experience in enterprise software development, I specialize in creating custom AI solutions for the pharmaceutical and life science industries.

Disclaimer

The information contained in this document is provided for educational and informational purposes only. We make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, or availability of the information contained herein. Any reliance you place on such information is strictly at your own risk. In no event will IntuitionLabs.ai or its representatives be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from the use of information presented in this document. This document may contain content generated with the assistance of artificial intelligence technologies. AI-generated content may contain errors, omissions, or inaccuracies. Readers are advised to independently verify any critical information before acting upon it. All product names, logos, brands, trademarks, and registered trademarks mentioned in this document are the property of their respective owners. All company, product, and service names used in this document are for identification purposes only. Use of these names, logos, trademarks, and brands does not imply endorsement by the respective trademark holders. IntuitionLabs.ai is an AI software development company specializing in helping life-science companies implement and leverage artificial intelligence solutions. Founded in 2023 by Adrien Laurent and based in San Jose, California. This document does not constitute professional or legal advice. For specific guidance related to your business needs, please consult with appropriate qualified professionals.

Related Articles

Need help with AI?

© 2026 IntuitionLabs. All rights reserved.