This is a ready-to-use checklist for qualifying a new DSCSA trading-partner connection, manufacturer to distributor, distributor to dispenser, or either party to a 3PL or repackager, before the first serialized commercial shipment moves. Authorization (license and registration) answers the permission question: is this a partner you are allowed to trade with. This checklist answers the separate, technical question: can your systems actually exchange data with theirs. Replace every <<FILL: ...>> placeholder. A filled specimen follows. This content is educational and general, not legal or regulatory advice; confirm current requirements before you rely on it.
Document control header
| Field | Entry |
|---|---|
| Document title | Trading-Partner DSCSA/EPCIS Interoperability Qualification Checklist |
| Document number | <<FILL: CHK-ID, e.g. CHK-SC-018>> |
| Version | <<FILL: version>> |
| Effective date | <<FILL: effective date>> |
| Document owner | <<FILL: role, e.g. Director, Trade Compliance>> |
| Applies to | <<FILL: new trading-partner connections, all types>> |
How to use this checklist
- Run one instance per new trading-partner connection, not once per counterparty company; a partner with multiple ship-from or ship-to locations may need more than one qualification if the technical connection differs by site.
- Work through each section in order. Record Pass, Gap, or N/A with the evidence reference.
- A connection goes live for commercial shipment only when every applicable line is Pass, or a Gap has a dispositioned interim control (for example, manual verification while an automated fix is pending).
- Re-run the relevant sections whenever the partner or your own platform changes EPCIS/CBV version, transport, or VRS responder.
1. Authorization and role determination
| # | Check | Pass criterion | Evidence | Result |
|---|---|---|---|---|
| A1 | Trading-partner type confirmed | Manufacturer, repackager, wholesale distributor, dispenser, or 3PL is correctly identified based on activities performed (title, repackaging, shipping), not commercial label | Role determination memo | <<FILL>> |
| A2 | License and registration verified | Current FDA registration and/or state license confirmed against the primary source (state board, FDA database) | Screenshot or extract, dated | <<FILL>> |
| A3 | Authorized-trading-partner register updated | Partner added with evidence attached and a re-verification date set | Register entry | <<FILL>> |
2. Master data alignment
| # | Check | Pass criterion | Evidence | Result |
|---|---|---|---|---|
| M1 | GTIN-to-NDC mapping confirmed | Both parties’ master data resolve the same GTIN to the same NDC, in the same format (4-4-2, 5-3-2, or 5-4-1) | Master-data comparison sheet | <<FILL>> |
| M2 | GLNs exchanged and confirmed | Every ship-from and ship-to location has an agreed GLN, confirmed on both sides | GLN cross-reference list | <<FILL>> |
| M3 | Expiry-date and lot-format conventions match | Format (for example YYMMDD) and lot-number conventions agree | Format specification, signed off by both parties | <<FILL>> |
3. Technical connection
| # | Check | Pass criterion | Evidence | Result |
|---|---|---|---|---|
| T1 | EPCIS and CBV version agreed | Both parties confirm and document the EPCIS and CBV version (1.2 or 2.0) for this connection | Signed technical specification or interface agreement | <<FILL>> |
| T2 | Transport method agreed | File-based (AS2/SFTP) or API/REST, and the endpoint, confirmed by both parties | Interface agreement | <<FILL>> |
| T3 | Credentialing complete | Certificates, API credentials, or platform-specific onboarding complete and tested | Credential exchange record | <<FILL>> |
| T4 | Schema validation passed | Test EPCIS messages validate against the agreed GS1 US application standard schema | Validation report | <<FILL>> |
| T5 | Round-trip test passed | A live test message is sent, received, and successfully ingested by the partner’s actual receiving system, not a generic validator | Round-trip test log, both parties’ confirmation | <<FILL>> |
4. Verification (VRS)
| # | Check | Pass criterion | Evidence | Result |
|---|---|---|---|---|
| V1 | Responder reachable (if issuing party) | The manufacturer/repackager’s VRS responder returns correct results for the GTINs in scope | Test verification result | <<FILL>> |
| V2 | Routing confirmed (if requesting party) | The requester’s platform successfully routes a query to the responder and receives a result | Test verification result | <<FILL>> |
| V3 | Timeout and no-response handling defined | Both parties agree what “no response” means operationally (seconds/retries) and the fallback quarantine action | Interface agreement or WI reference | <<FILL>> |
5. Data ownership and responsibility
| # | Check | Pass criterion | Evidence | Result |
|---|---|---|---|---|
| D1 | Scanning and event-generation responsibility stated | The contract or quality/technical agreement states who physically scans and who generates the resulting EPCIS event, especially where a 3PL is involved | Signed agreement, clause reference | <<FILL>> |
| D2 | T3/TS obligation owner stated | The agreement states which party carries the Transaction Information/Statement obligation for this connection | Signed agreement, clause reference | <<FILL>> |
| D3 | Genealogy-preservation obligation stated (repackager connections only) | Where the partner is a repackager, the agreement states the obligation to preserve traceability back to the original manufacturer lot and serials | Signed agreement, clause reference | N/A or <<FILL>> |
| D4 | Escalation contacts defined | Named contacts and escalation path for both a data exception and a suspect-product event are documented and shared | Contact list | <<FILL>> |
Gap summary
| Gap ref | Check # | Description | Risk (H/M/L) | Owner | Interim control / remediation | Status |
|---|---|---|---|---|---|---|
<<FILL: G1>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> | <<FILL>> |
Overall result and go-live approval
| Field | Entry |
|---|---|
| Lines assessed | <<FILL: count>> |
| Pass | <<FILL: count>> |
| Gap (open, with interim control) | <<FILL: count>> |
| N/A | <<FILL: count>> |
| Go-live decision | Approved / Approved with interim controls / Not approved |
| Trade compliance sign-off (name, date) | <<FILL>> |
| QA sign-off (name, date) | <<FILL>> |
References
DSCSA, section 582 of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 360eee-1). FDA guidance on DSCSA implementation and current exemptions (confirm the posture for each trading-partner type). GS1 US DSCSA implementation guideline (application standard for EPCIS/CBV in DSCSA exchange). Partnership for DSCSA Governance (PDG), Interoperability Blueprint (industry reference for transaction data exchange, verification, tracing, and credentialing).
Confirm the current version of each reference before issue.
Revision history
| Version | Date | Author | Summary of change |
|---|---|---|---|
<<FILL: 1.0>> | <<FILL: date>> | <<FILL: author>> | Initial issue. |
Filled specimen
The following shows a completed qualification for an example new wholesale-distributor connection onboarded by a manufacturer. Company, system, and evidence references are illustrative.
| # | Check | Result | Evidence / note |
|---|---|---|---|
| A1 | Trading-partner type confirmed | Pass | Wholesale distributor, confirmed by activity (buys, resells, does not repackage) |
| A2 | License and registration verified | Pass | State wholesale distributor license verified against state board database, 03 Aug 2026, expires 03 Aug 2027 |
| A3 | Register updated | Pass | Entry TP-2026-0142, re-verification due 01 Jul 2027 |
| M1 | GTIN-to-NDC mapping confirmed | Pass | Both parties resolve GTIN 00312345678906 to NDC 0312-3456-78, 5-4-1 format, cross-checked 05 Aug 2026 |
| M2 | GLNs exchanged | Pass | 3 ship-to GLNs confirmed for the distributor’s regional DCs |
| M3 | Format conventions match | Pass | YYMMDD expiry confirmed both sides |
| T1 | EPCIS/CBV version agreed | Pass | EPCIS 1.2 / CBV 1.2 for this connection, per interface agreement IA-2026-014; distributor is not yet on 2.0 |
| T2 | Transport agreed | Pass | AS2, endpoint confirmed |
| T3 | Credentialing complete | Pass | AS2 certificates exchanged and tested 08 Aug 2026 |
| T4 | Schema validation passed | Pass | 20 test messages, 0 schema failures, report VAL-2026-0091 |
| T5 | Round-trip test passed | Pass | Live ship/receive test 10 Aug 2026, distributor confirmed ingestion into their WMS |
| V1 | Responder reachable | Pass | Manufacturer VRS responder returned correct valid/invalid results on 5 test GTINs |
| V2 | Routing confirmed | N/A | Manufacturer is the issuing party for this connection |
| V3 | Timeout handling defined | Pass | 15-second timeout, 2 retries, then quarantine, per interface agreement |
| D1 | Scanning/event responsibility stated | Pass | Distributor scans and generates receiving events at its own DCs; no 3PL involved on this connection |
| D2 | T3/TS obligation owner stated | Pass | Manufacturer generates outbound T3; distributor generates its own T3 on resale |
| D3 | Genealogy obligation | N/A | Distributor is not a repackager |
| D4 | Escalation contacts defined | Pass | Contact list shared, both data-exception and suspect-product paths |
Overall result: 16 Pass, 2 N/A, 0 open Gap. Go-live approved 12 August 2026, K. Ofori (Trade Compliance) and R. Gomez (QA).
Common inspection findings this checklist prevents
- A new trading partner connected and shipping commercially with no documented round-trip test, so the first real failure is discovered on a live shipment.
- Master data (GTIN-to-NDC mapping, GLNs) never formally cross-checked, so downstream verification fails silently for weeks before anyone notices the pattern.
- A 3PL or repackager relationship with no written statement of who scans, who owns the EPCIS event, and who carries the T3 obligation, discovered only when a data gap needs an owner.
- EPCIS version mismatch discovered in production because neither party documented which version the connection was built to.
- No defined timeout or fallback behavior for VRS unavailability, so returns processing stalls or waves product through under pressure.
How to adapt this checklist
- Set your document number, owner, and effective date in the header.
- Add or remove lines in section 5 depending on whether the partner is a 3PL, repackager, or a straightforward buyer/seller relationship; the data-ownership questions matter most exactly where the role is not a simple change of title.
- Tie this checklist to your onboarding workflow so a connection cannot go live commercially without a completed, approved instance.
- Re-run sections 3 and 4 whenever either party changes platform, EPCIS/CBV version, or VRS provider.
- Confirm the current statute, FDA guidance, and GS1 US implementation guideline version before issue.