Industry guide · Supply Chain

Pharmaceutical Serialization Software: What Happens When the Pallet in the Dock Does Not Match the EPCIS File?

Pharmaceutical Serialization software visual showing qr code, inventory boxes, and supply route.
The short answer

$100,000 to $220,000 and 16 to 22 weeks is the honest band for a first release of serialization software covering serial number management, line commissioning and aggregation capture, and EPCIS event storage with one trading partner exchange, based on Digital Heroes delivery experience. A full platform adding multi market reporting endpoints, partner specific EPCIS profiles, exception and rework handling, verification response, and a full audit history runs $300,000 to $750,000 phased over 10 to 20 months. If you are a single site manufacturer with one packaging line and fewer than five trading partners, do not build. TraceLink or rfxcel will connect you to the network faster and cheaper than any bespoke system will.

Why serialization breaks twice: once at the line and once at the dock

A pallet is staged at a dock on a Friday afternoon. The advance shipment notice went out with the EPCIS file that says this pallet contains twelve cases, each containing forty eight serialised units. During night shift a case was opened because a unit was pulled for a stability sample, then resealed. Nobody sent an unpack and repack event. The customer's receiving system reconciles what it scanned against what you sent, finds a hierarchy that does not match, and quarantines the delivery. Your commercial team hears about it Monday. Your serialization lead spends the day proving which unit left the case and when.

The systems in play are usually a packaging line with printers, vision cameras, and a line level controller, a site level serialization application, an enterprise repository, and a partner exchange service. TraceLink, Systech, Antares Vision rfxcel, SAP Advanced Track and Trace, and Movilitas all operate in this space and they are genuinely capable. TraceLink in particular has a network advantage that is real and should not be dismissed, because the hardest part of trading partner exchange is that the other party has to be connected too.

What drives manufacturers, repackagers, and wholesalers to build is narrower than replacing all of that. It is that the exception paths, which are where every actual problem happens, follow your packaging operations rather than a product's assumptions, and that the reconciliation between physical hierarchy and reported hierarchy is the thing that stops shipments. Across serialization projects we have delivered, the recurring pattern is that commissioning works fine and aggregation is where the labour goes. Sites lose one to three shifts a month to hierarchy exceptions, and every one of them is a shipment at risk.

Problem 1: aggregation is physical, and your data is optimistic

Commissioning a serial number to a unit is easy. Recording that the unit went into a specific case, and that the case went onto a specific pallet, requires the physical act and the data event to stay married through every subsequent handling. They do not. A case is dropped and rebuilt. A unit is rejected by vision after the case was already aggregated. A pallet is broken down for a partial shipment. Someone samples a unit for quality.

Line systems handle the happy path well and the exception path with whatever the integrator configured three years ago. That configuration is frequently a supervisor override that fixes the line and leaves the repository believing something untrue. The mismatch is not discovered until a partner reconciles it.

What a custom build does: treat aggregation as an event stream that can be corrected only by further events, never by editing state. Unpack, repack, decommission, and sample events are first class and available to the operator at the point of handling, on a scanner, in the seconds when they actually happen. The system computes current hierarchy from the event history, so a reconciliation query against a physical scan is instant and the difference is explainable. Building the exception paths first, rather than last, is the single design decision that separates a serialization system that works from one that produces holds.

Problem 2: every trading partner reads EPCIS differently

GS1 EPCIS is a standard, and standards in this industry are implemented with local dialects. One wholesaler expects specific business step and disposition values. Another requires particular extension fields. One wants files over AS2, another over SFTP, another over a REST interface with their own authentication. Master data alignment is its own problem, because your product identifier, your location identifiers, and their expectations of both have to agree before a single event is accepted.

What a custom build does: separate the internal event model from the partner profile entirely. Events are stored once in a canonical form. Each partner has a profile defining the transformation, the transport, the required fields, the acknowledgement handling, and the retry behaviour. Onboarding a new partner becomes a configuration and test exercise rather than a code change, which matters because you will onboard partners for as long as you are in business. Every outbound file is retained exactly as sent, alongside the acknowledgement or rejection, because the first question in any dispute is what you actually sent and when.

Problem 3: the exception is the job

Reworked product. A case damaged in the warehouse. Product returned by a customer and eligible for resale. A destroyed batch. A serial number range that was commissioned and never used because the line stopped. Samples pulled for quality and stability. Each of these changes the status of specific serial numbers and each has a correct set of events and a wrong set that will cause a partner rejection later.

Under the enhanced requirements of the Drug Supply Chain Security Act, transaction information has to travel electronically at package level and trading partners must be able to respond to verification and investigation requests. That is a fundamentally different posture from the lot level world it replaced, because the questions asked are about individual packages rather than shipments.

What a custom build does: give every exception a named workflow with the correct events built in, exposed to the people who actually encounter it. A warehouse operator scanning a damaged case should have a decommission path that takes ten seconds and produces correct data, because the alternative is that they set it aside and tell someone on Monday. Serial number status is queryable at any moment, with the full event history and the operator who performed each step. When a partner sends an investigation request about one package, you answer it the same day from the system rather than from a warehouse manager's memory.

Problem 4: one product, several markets, several endpoints

A product sold in the United States, the European Union, and other regulated markets carries different obligations at the same time. The EU Falsified Medicines Directive requires the unique identifier to be uploaded to the European hub and national systems and decommissioned at dispensing, with tamper evident packaging alongside. Other markets run their own national systems with their own code formats and their own reporting expectations, and some require codes to be requested from a state system before printing rather than generated by you.

What a custom build does: model market obligation as configuration attached to product and destination, so the packaging order knows what it must do before it runs rather than after. Serial number sourcing differs by market, so the number pool abstraction has to support both internally generated ranges and externally issued codes without special casing the line. Reporting adapters per market are versioned, because these systems change their interfaces and you need to run the old and new in parallel during a transition.

Problem 5: verification requests arrive on someone else's clock

When a wholesaler receives a saleable return, they need to verify the product identifier before that unit can go back into commerce. When a partner suspects an illegitimate product, an investigation follows with obligations for both sides. These are inbound requests with response expectations, and they land regardless of whether your serialization lead is at their desk.

What a custom build does: expose a verification service that answers automatically from your repository, logs every request with its requester and response, and alerts a human only when the answer is anything other than a clean confirmation. Repeated verification attempts against the same identifier from unexpected sources are exactly the signal these systems exist to surface, and a build should treat that pattern as an alert rather than a line in a log file nobody reads.

What this costs and how long it takes

Across the 2,000 plus projects Digital Heroes has delivered, this is the shape for serialization platforms. A first release covering serial number pool management, line integration for commissioning and aggregation with exception paths, canonical event storage, and one partner exchange profile runs $100,000 to $220,000 and ships in 16 to 22 weeks. A full platform adding multiple market reporting adapters, a partner profile library, warehouse exception handling on scanners, verification response services, returns processing, and full audit history runs $300,000 to $750,000 phased over 10 to 20 months.

  • Number of packaging lines and their vintage. A modern line with a documented interface is days of integration. A line with a proprietary controller and an integrator who has moved on is weeks.
  • Number of trading partners and how many insist on their own dialect. Each profile is real work including a test cycle with the partner, whose availability you do not control.
  • Number of regulated markets, since each national system is effectively a separate integration project with its own certification.
  • Whether contract manufacturers are in scope. A CMO producing on your behalf must send you events in a format you can accept, and getting five CMOs aligned is a programme rather than a feature.
  • Validation, because this is a GxP system whose records support product release and regulatory reporting.

Build versus buy, and when buying is right

Buy if you are a single site with one or two lines and a small number of partners. TraceLink, rfxcel, and Systech will get you exchanging data faster than a build, and the network connectivity they bring is worth paying for. Buy if your problem is genuinely connectivity rather than operations, because rebuilding a partner network from scratch is not a sensible use of capital.

Build when two or more of these are true. Your exception volume is high enough that hierarchy mismatches regularly hold shipments, and the packaged system's exception paths do not match how your warehouse actually works. You operate across several markets and are maintaining parallel systems that disagree. You are a repackager or wholesaler whose business model creates aggregation events that manufacturer oriented products handle badly. You need serialization data joined to your own batch, quality, and logistics data for analysis that a hosted repository will not give you. Or your per transaction pricing has grown to the point where the arithmetic of ownership has changed, which happens more often than vendors like to discuss. A hybrid is frequently correct: keep a commercial service for partner connectivity, build the site and enterprise layer where your operations live.

How to choose a developer for serialization software

Ask them to model a repack before you sign anything. A developer who has done this describes unpack and repack as events over an append only stream with current hierarchy computed from history. A developer who proposes updating a parent identifier on a child record has built an inventory app and will produce the exact mismatches that stop your shipments.

Ask how a partner profile is added. If onboarding a new wholesaler requires a code release, you have bought a permanent consulting engagement.

Ask what line level integration they have actually done, naming the printer, the vision system, and the controller. Serialization fails at the line more often than anywhere else, and floor experience is not transferable from web work.

Ask who owns the code and get it in writing before kickoff. You should own the repository, the infrastructure accounts, and the right to hire anyone else to continue the work. At Digital Heroes the client owns the code from the first commit. Serialization records support regulatory reporting and must remain retrievable for years, which is longer than most vendor relationships last.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Across 1,471 IT projects the average cost overrun was 27%, but one in six projects was a 'black swan' with an average cost overrun of 200% and a schedule overrun of nearly 70%. Source: Harvard Business Review (Bent Flyvbjerg & Alexander Budzier, University of Oxford) (2011) →
  2. In a survey of 579 supply chain professionals (July 31 to October 1, 2024), only 29% had built at least three of the five capabilities Gartner identifies as needed for future competitiveness (agility, resilience, regionalization, integrated ecosystems, and enterprise-wide strategy). Source: Gartner (2025) →
  3. In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
  4. Gallup reports global employee engagement fell to 20% in 2025 (its lowest since 2020, down from a 2022-2023 peak of 23%), and estimates low engagement costs the world economy an estimated $10 trillion in lost productivity, or 9% of global GDP. (Note: this figure appears in Gallup's evergreen State of the Global Workplace page, currently reflecting the 2026 edition reporting on 2025 data.). Source: Gallup (2025) →
Aanya B. · Senior Frontend Engineer · Next.js · Delhi

Aanya builds frontends in Next.js at Digital Heroes, covering rendering strategy, component structure, accessibility and the performance work that decides how a site feels on a mid range phone. Her writing translates frontend decisions into the outcomes non technical stakeholders actually care about.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom pharmaceutical serialization software cost?
A first release covering serial number pool management, line commissioning and aggregation with proper exception paths, canonical event storage, and one trading partner exchange profile runs $100,000 to $220,000 and ships in 16 to 22 weeks, based on Digital Heroes delivery experience. A full platform adding multi market reporting, a partner profile library, warehouse exception handling, verification services, and returns processing runs $300,000 to $750,000 over 10 to 20 months. Line count, partner count, and market count drive most of the variance.
Should we build serialization software or use TraceLink or rfxcel?
For a single site with a couple of lines and a small partner list, buy. The network connectivity these providers bring is genuinely valuable, because trading partner exchange only works if the other party is connected too. Building becomes reasonable when exception volume regularly holds shipments, when you operate across several markets with parallel systems that disagree, or when per transaction pricing has grown enough to change the arithmetic. A hybrid is common: keep a commercial network for exchange and build the site and enterprise layer.
Why do aggregation mismatches hold shipments, and how do you prevent them?
Because the physical hierarchy and the reported hierarchy separate the moment a case is opened, rebuilt, sampled, or partially shipped without the matching event being recorded. Prevention is architectural: store aggregation as an append only event stream where the only correction is another event, never a state edit, and put unpack, repack, decommission, and sample actions on a scanner in the hands of the person doing the handling. Current hierarchy is then computed from history and a reconciliation against a physical scan is instant and explainable.
How do you handle trading partners who each interpret EPCIS differently?
Keep one canonical internal event model and define each partner as a profile carrying the transformation, transport, required fields, acknowledgement handling, and retry rules. Onboarding a new wholesaler then becomes configuration and a test cycle rather than a code change. Retain every outbound file exactly as sent alongside its acknowledgement or rejection, because the first question in any dispute is what you actually transmitted and when.
What does DSCSA require that lot level systems could not do?
The enhanced requirements move traceability to package level, with transaction information exchanged electronically and trading partners able to respond to verification and investigation requests about individual packages. That changes the questions you must answer from shipment level to serial level, and it makes exception handling a compliance matter rather than a housekeeping one. A system that cannot state the current status and full history of one specific package will not satisfy a partner investigation.
How should returns and verification requests be handled?
Expose a verification service that answers automatically from your repository, logs every request with requester and response, and escalates to a person only when the answer is not a clean confirmation. Saleable returns depend on that verification before product re enters commerce, so a manual process creates delay that costs real inventory time. Repeated verification attempts against the same identifier from unexpected sources should raise an alert, because that pattern is precisely what these systems exist to surface.
How long does line integration take, and what makes it difficult?
Anywhere from days to several weeks per line depending on vintage. A modern line with a documented controller interface, a known printer, and a supported vision system integrates quickly. An older line with a proprietary controller, undocumented handshakes, and an integrator who has moved on takes far longer, and the work has to happen around production windows rather than whenever engineering is ready. Budget line integration separately and sequence it by difficulty.
Does serialization software need to be validated?
Yes. It holds records supporting product release and regulatory reporting, so it needs requirements, risk assessment, traceability, executed evidence, audit trails, and controlled changes consistent with GxP expectations. Plan that from the first requirement rather than retrofitting, particularly the audit trail design, since serialization systems generate very high event volumes and an audit trail approach that works for a document system will not scale here.
Who owns the code and the serialization data if we hire an agency?
You should own the repository, the cloud infrastructure accounts, and the unrestricted right to hire another firm to continue the work, written into the contract before kickoff. Serialization records support regulatory reporting and partner investigations for years after production, so retrieval must never depend on a vendor's cooperation or a subscription remaining active. At Digital Heroes the client owns the code from the first commit.
How long does it take to build custom supply chain software?
Plan on 10 to 14 weeks for a first production release covering one or two core workflows, and 6 to 9 months for a full platform spanning procurement, inventory, and fulfillment. Digital Heroes ships most supply chain MVPs in about 12 weeks with a 4 to 6 person team. Integrations are the schedule risk: each ERP, EDI, or carrier connection typically adds 2 to 4 weeks of build and testing.
Should I hire a freelancer or an agency to build supply chain software?
For anything past a single-user internal tool, use an agency or an established team, because supply chain systems need backend, frontend, integration, and QA skills that rarely live in one freelancer. A solo developer can build a $10,000 inventory tracker; a system that talks to your ERP, carriers, and warehouse scanners fails badly when its only author is unreachable during a shipping cutoff. In the proposals Digital Heroes sees clients compare, agencies cost 20 to 50 percent more but give you continuity, code review, and someone answerable when order data stops flowing.
How do I calculate whether custom software will pay for itself?
Divide the build cost by the monthly benefit, where benefit is hours saved times loaded hourly cost, plus subscription fees replaced, plus any revenue the software unlocks. Three staff saving 10 hours a week each at a $40 loaded rate is about $62,000 a year, which pays back a $60,000 build in roughly 12 months. Across Digital Heroes internal-tool projects, 12 to 24 months is the normal payback range, and anything projecting under 6 months usually means the spreadsheet is hiding costs.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
What questions should I ask a development agency on the first call?
Ask who exactly will build it, what happens when scope changes mid-project, what their maintenance terms are after launch, and what they will need from you every week. Then ask them to describe a project that went wrong and what they changed afterward; teams that have shipped at real volume have war stories, and teams claiming a perfect record are hiding something. The scope-change answer matters most: a disciplined shop describes a written change-order process, not a vague promise to be flexible.
How much does custom supply chain software cost for a small business?
For a small business, a focused custom supply chain tool usually lands between $15,000 and $45,000, covering one core workflow like inventory tracking, purchase orders, or shipment visibility. Across 2,000+ delivered projects, Digital Heroes sees most small distributors and light manufacturers start in the $20,000 to $35,000 range for a first working version. Adding barcode scanning, multi-warehouse support, or carrier integrations pushes budgets toward $50,000 and up.
Who can build a custom supply chain software system?

Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other supply chain software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?