GS1 Global Standards - Supply Chain Traceability and Data Security
GS1: EPCIS (Electronic Product Code Information Services), CBV (Core Business Vocabulary) and Event-Based Data Sharing

GS1 Global Standards - Supply Chain Traceability and Data Security GS1-EPCIS-CBV-EventBasedDataSharing: GS1 EPCIS (Electronic Product Code Information Services) and CBV (Core Business Vocabulary) Event-Based Data Sharing

GS1 EPCIS (Electronic Product Code Information Services) is the event-based supply chain data exchange standard answering 4 KEY QUESTIONS: WHAT (which products), WHEN (date + time), WHERE (location), WHY (business step + disposition). EPCIS HISTORY: developed by EPCglobal (founded 2003, merged into GS1 2005); EPCIS v1.0 (2007) + v1.1 (2014) + v2.0 (2022); EPCIS is also ISO/IEC 19987:2015 (ISO international standard). EPCIS EVENT TYPES: (a) OBJECT EVENT - state-change of an individual object (e.g. commissioned + manifested + shipped + received + sold + recalled); (b) AGGREGATION EVENT - associations of objects (e.g. case-pallet relationships + parent-child); (c) TRANSACTION EVENT - associates objects with business transactions (orders + invoices + ASNs); (d) TRANSFORMATION EVENT - input-output transformations (e.g. raw materials to finished goods + ingredients to recipe); (e) ASSOCIATION EVENT (v2.0) - non-physical associations (e.g. instrument-physical-link). EPCIS DATA STRUCTURE: each event captures EPC (Electronic Product Code, often GTIN + serial) + Event Time + Recorded Time + Action (ADD + OBSERVE + DELETE) + Business Step + Disposition + Read Point + Business Location + Source + Destination + Business Transaction List + Quantity List + Source List + Destination List + Sensor Element List (v2.0 - environmental sensor data) + ILMD (Instance/Lot Master Data) + Custom Fields. CBV (Core Business Vocabulary) provides standardized + controlled vocabularies for EPCIS Business Step + Disposition values to ensure semantic interoperability; CBV is also ISO/IEC 19988:2017. EPCIS QUERY INTERFACE: standardized query + subscription API enabling trading partners + regulators + consumers to access EPCIS data; supports complex filtering + on-demand + standing-query + REST/JSON in v2.0; on-premise + cloud + hybrid deployments. ADOPTION: EU FMD (DataMatrix on pharma + EPCIS for verification); FDA DSCSA (US pharma serialization + interoperable exchange by Nov 2024); supply chain visibility platforms (IBM Food Trust + Microsoft Azure + Oracle + SAP); regulatory traceability (food + tobacco + pharma); IoT + sensor integration (cold chain + condition monitoring).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 37 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • A.1 Point-of-Care Testing Additional Requirements

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities
  • 2.7.2 Food Fraud Plan
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.