GS1 Global Standards - Supply Chain Traceability and Data Security
GS1: Traceability, Healthcare/Food/Pharma Sectors, EU FMD/MDR/IVDR/TPD, FDA DSCSA/UDI Coordination

GS1 Global Standards - Supply Chain Traceability and Data Security GS1-Traceability-Healthcare-FMD-MDR-DSCSA-UDI: GS1 Supply Chain Traceability, Healthcare + Pharma + Food Sectors, EU FMD + MDR + IVDR + TPD, FDA DSCSA + UDI

GS1 SUPPLY CHAIN TRACEABILITY + sectoral applications. END-TO-END TRACEABILITY MODEL: GS1 traceability is built on (a) Critical Tracking Events (CTEs) - significant supply chain events (e.g. creation + shipping + receiving + transformation + selling + recall); (b) Key Data Elements (KDEs) - data points captured per CTE (GTIN + lot + serial + date + location + party + quantity); (c) one-up + one-down traceability (each party knows its immediate suppliers + customers) + full chain via EPCIS event sharing; (d) one-step vs full traceability vs lot tracing vs item-level traceability. PHARMA (EU + US): EU FALSIFIED MEDICINES DIRECTIVE (FMD, Directive 2011/62/EU) effective February 2019 - serialised GS1 DataMatrix (GTIN + Serial Number + Batch + Expiry) on pharma packs + verification at point-of-dispense via EU Hub + National Medicines Verification Systems (NMVS); EU eToken + UI (Unique Identifier) standards; ~20K+ pharma products serialized. US DSCSA (Drug Supply Chain Security Act, 2013 Pub.L. 113-54) - 10-year phased implementation completing 2023-2024 + Nov 2024 enforcement; serialized GS1 codes + interoperable exchange + verification + saleable returns + suspicious-products investigation; multiple compliance extensions through 2024-2025. MEDICAL DEVICES: EU MDR (Regulation (EU) 2017/745) + IVDR (Regulation (EU) 2017/746) - UDI (Unique Device Identification) via GS1 GTIN + UDI Production Identifier + EUDAMED database; phased implementation through 2025-2027. FDA UDI - GTIN-based UDI for medical devices + GUDID (Global UDI Database). FOOD + FOODSERVICE: GS1 traceability + recall capability + FDA Food Traceability Final Rule (2024) + EU General Food Law + supply chain accountability + retailer mandates (Walmart + Costco + Tesco + Carrefour + Whole Foods); MOCK RECALL + WITHDRAWAL TESTING (annual + GS1-aligned). TOBACCO: EU TPD (Directive 2014/40/EU) - GS1-based traceability for tobacco products + UI + EU verification + suspicious activity detection. RETAIL + CONSUMER: GS1 + Walmart + Amazon + Costco + Tesco + Carrefour + retailer mandates for GTIN + GS1 codes + GDSN master data + supplier compliance. AUTOMOTIVE + AEROSPACE: GS1 SSCC + CPID for parts + traceability + recall + warranty. CONSTRUCTION + REAL ESTATE: GS1 + building product traceability + sustainability + Digital Product Passport. RECALL + WITHDRAWAL: GS1 codes enable rapid product recall + withdrawal + targeted recall + customer notification + regulatory reporting (FDA + EMA + EU + national + Codex).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 56 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-C-48 Section 211.48 - Plumbing
  • CFR211-F-113 Section 211.113 - Control of Microbiological Contamination
  • CFR211-I-176 Section 211.176 - Penicillin Contamination
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention

SWIFT CSCF · 3 controls

  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)
  • SWIFTCSCF-4 Prevent Compromise of Credentials (Objective 4)
  • SWIFTCSCF-7 Plan Incident Response (Objective 7)
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • ICC-Incoterms2020-Obligations-A1-A10-Seller-B1-B10-Buyer-10-Article-Structure ICC Incoterms 2020 - 10-Article Obligation Structure (A1-A10 Seller, B1-B10 Buyer) per Term
  • ICC-Incoterms2020-SeaWaterway-FAS-FOB-CFR-CIF-Maritime-Only ICC Incoterms 2020 - Rules for Sea + Inland Waterway Transport (4) - FAS + FOB + CFR + CIF
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

PCI DSS 4.0 · 2 controls

  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 2.1.3 Food Safety and Quality Culture
  • 2.7.2 Food Fraud Plan
  • 58.49 Laboratory Operation Areas
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • A.1 Point-of-Care Testing Additional Requirements

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities
  • AIGF-3.3 Repeatability and Traceability
  • ACE-IM-3 Importer Security Filing (ISF)
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in GS1: Traceability, Healthcare/Food/Pharma Sectors, EU FMD/MDR/IVDR/TPD, FDA DSCSA/UDI Coordination

Query this from an agent

The graph holds this control, the 56 it maps to, and the evidence behind each claim, over MCP and REST.