Carrier decision · US DSCSA & EU FMD

Serialization is mandated. Authentication is not — yet it decides.

DSCSA §582: GS1 DataMatrix product identifier required · EU FMD 2011/62/EU: 2D code + tamper evidence · both verify data, not the object.

In pharma the printed code is not optional and never will be: DSCSA requires the serialized GS1 DataMatrix on every package, FMD requires the 2D code plus tamper evidence in the EU. But both regimes verify data about a package, not the package itself — a well-made copy of a genuine code, on a counterfeit carton, passes a data check because the data is real. Chip-bound identity exists for exactly that residual risk: it authenticates the object, while the mandated barcode keeps satisfying the regulator.

DSCSA §582GS1 DataMatrixEU FMD 2011/62/EUVerificationUnit-level identity
The short answer

The barcode satisfies the law. The chip defeats the copy.

When the QR is enough

Regulatory verification

For §582 verification, saleable returns and FMD decommissioning, the mandated 2D code and your serialization stack (TraceLink, Antares, MediLedger) are the system of record. Nothing replaces them, and any authentication layer must feed the same records.

When you need the chip

Product-level truth

When the question is "is this physical package the one the data describes?" — diverted product, sophisticated counterfeits with harvested serials, returns fraud — a cryptographic tap answers what a printed code structurally cannot.

Side by side

Printed code vs chip-bound identity, criterion by criterion.

CriterionQR / printed 2D codeNFC chip (Aeroz)
Required by DSCSA / FMDYes — mandated product identifierNo — an additional authentication layer
Verifies the dataYes — serial checked against recordsYes — and binds the check to this physical unit
Defeats a copied genuine codeNo — a copy of real data verifies as realYes — the chip cannot be photographed into existence
Saleable returns confidenceSerial matches; unit unprovenUnit proven; fraudulent returns surface at the tap
Patient-facing checkRequires an app and a database lookupOne tap on a phone; verdict from the unit itself
Integrates with serialization stackNativeEvents append via EPCIS 2.0 to the same chain of record

This is the one industry where the comparison is genuinely additive: the DataMatrix is law, so the decision is not which carrier but whether data verification alone matches your diversion and counterfeit exposure. For most low-risk generics it does. For high-value, high-diversion products, it demonstrably has not.

What the rules say

What each regime mandates — and what neither checks.

DSCSA: the serialized identifier

Section 582 requires the product identifier — NDC, serial, lot, expiry in a GS1 DataMatrix — on each package, with unit-level electronic tracing and verification duties now in force across the chain.

FMD: the 2D code plus tamper evidence

EU Directive 2011/62/EU requires the unique identifier in a 2D code, verification at dispense, and an anti-tampering device — Europe's answer to the same threat model.

What both verify

That the serial number exists, was issued, and has the right status in the repository. This is data verification, and it is what the law asks.

What neither verifies

That the physical carton in hand is the one the serial was born on. Harvested genuine serials on counterfeit product pass data checks — the documented gap authentication layers exist to close.

FAQ

NFC vs QR for pharma authentication, answered.

Can NFC replace the DataMatrix on drug packages?

No, and it should not try — the DataMatrix is the mandated identifier under DSCSA and the 2D code under FMD. Chip identity is an authentication layer on top, feeding the same EPCIS records.

If a serial verifies, isn't the product genuine?

Not necessarily. Verification confirms the data is genuine, not the object. A counterfeit carrying a copied genuine code returns a clean check — which is why verification alone under-detects sophisticated counterfeits.

Where does chip authentication pay for itself first?

High-value specialty products, cold-chain biologics, and any product with a returns-fraud or diversion history — the places where a single incident costs more than tagging the whole line.

Does this change our DSCSA compliance work?

No — §582 duties stand regardless. An Aeroz deployment appends authentication events to the same unit-level chain your serialization stack maintains, strengthening the tracing record rather than forking it.

Readiness audit

Get the carrier decision made for your line — in 14 days.

A fixed-fee Aeroz audit maps your products, line speed and regulation against both carriers and returns a written recommendation with a scoped pilot plan, cost and timeline. $5,000 books it online; no commitment to proceed.

Fixed fee · from $5,000 14-day written report No commitment to proceed