Pharmaceutical Serialization Software: What Happens When the Pallet in the Dock Does Not Match the EPCIS File?
$100,000 to $220,000 and 16 to 22 weeks is the honest band for a first release of serialization software covering serial number management, line commissioning and aggregation capture, and EPCIS event storage with one trading partner exchange, based on Digital Heroes delivery experience. A full platform adding multi market reporting endpoints, partner specific EPCIS profiles, exception and rework handling, verification response, and a full audit history runs $300,000 to $750,000 phased over 10 to 20 months. If you are a single site manufacturer with one packaging line and fewer than five trading partners, do not build. TraceLink or rfxcel will connect you to the network faster and cheaper than any bespoke system will.
Why serialization breaks twice: once at the line and once at the dock
A pallet is staged at a dock on a Friday afternoon. The advance shipment notice went out with the EPCIS file that says this pallet contains twelve cases, each containing forty eight serialised units. During night shift a case was opened because a unit was pulled for a stability sample, then resealed. Nobody sent an unpack and repack event. The customer's receiving system reconciles what it scanned against what you sent, finds a hierarchy that does not match, and quarantines the delivery. Your commercial team hears about it Monday. Your serialization lead spends the day proving which unit left the case and when.
The systems in play are usually a packaging line with printers, vision cameras, and a line level controller, a site level serialization application, an enterprise repository, and a partner exchange service. TraceLink, Systech, Antares Vision rfxcel, SAP Advanced Track and Trace, and Movilitas all operate in this space and they are genuinely capable. TraceLink in particular has a network advantage that is real and should not be dismissed, because the hardest part of trading partner exchange is that the other party has to be connected too.
What drives manufacturers, repackagers, and wholesalers to build is narrower than replacing all of that. It is that the exception paths, which are where every actual problem happens, follow your packaging operations rather than a product's assumptions, and that the reconciliation between physical hierarchy and reported hierarchy is the thing that stops shipments. Across serialization projects we have delivered, the recurring pattern is that commissioning works fine and aggregation is where the labour goes. Sites lose one to three shifts a month to hierarchy exceptions, and every one of them is a shipment at risk.
Problem 1: aggregation is physical, and your data is optimistic
Commissioning a serial number to a unit is easy. Recording that the unit went into a specific case, and that the case went onto a specific pallet, requires the physical act and the data event to stay married through every subsequent handling. They do not. A case is dropped and rebuilt. A unit is rejected by vision after the case was already aggregated. A pallet is broken down for a partial shipment. Someone samples a unit for quality.
Line systems handle the happy path well and the exception path with whatever the integrator configured three years ago. That configuration is frequently a supervisor override that fixes the line and leaves the repository believing something untrue. The mismatch is not discovered until a partner reconciles it.
What a custom build does: treat aggregation as an event stream that can be corrected only by further events, never by editing state. Unpack, repack, decommission, and sample events are first class and available to the operator at the point of handling, on a scanner, in the seconds when they actually happen. The system computes current hierarchy from the event history, so a reconciliation query against a physical scan is instant and the difference is explainable. Building the exception paths first, rather than last, is the single design decision that separates a serialization system that works from one that produces holds.
Problem 2: every trading partner reads EPCIS differently
GS1 EPCIS is a standard, and standards in this industry are implemented with local dialects. One wholesaler expects specific business step and disposition values. Another requires particular extension fields. One wants files over AS2, another over SFTP, another over a REST interface with their own authentication. Master data alignment is its own problem, because your product identifier, your location identifiers, and their expectations of both have to agree before a single event is accepted.
What a custom build does: separate the internal event model from the partner profile entirely. Events are stored once in a canonical form. Each partner has a profile defining the transformation, the transport, the required fields, the acknowledgement handling, and the retry behaviour. Onboarding a new partner becomes a configuration and test exercise rather than a code change, which matters because you will onboard partners for as long as you are in business. Every outbound file is retained exactly as sent, alongside the acknowledgement or rejection, because the first question in any dispute is what you actually sent and when.
Problem 3: the exception is the job
Reworked product. A case damaged in the warehouse. Product returned by a customer and eligible for resale. A destroyed batch. A serial number range that was commissioned and never used because the line stopped. Samples pulled for quality and stability. Each of these changes the status of specific serial numbers and each has a correct set of events and a wrong set that will cause a partner rejection later.
Under the enhanced requirements of the Drug Supply Chain Security Act, transaction information has to travel electronically at package level and trading partners must be able to respond to verification and investigation requests. That is a fundamentally different posture from the lot level world it replaced, because the questions asked are about individual packages rather than shipments.
What a custom build does: give every exception a named workflow with the correct events built in, exposed to the people who actually encounter it. A warehouse operator scanning a damaged case should have a decommission path that takes ten seconds and produces correct data, because the alternative is that they set it aside and tell someone on Monday. Serial number status is queryable at any moment, with the full event history and the operator who performed each step. When a partner sends an investigation request about one package, you answer it the same day from the system rather than from a warehouse manager's memory.
Problem 4: one product, several markets, several endpoints
A product sold in the United States, the European Union, and other regulated markets carries different obligations at the same time. The EU Falsified Medicines Directive requires the unique identifier to be uploaded to the European hub and national systems and decommissioned at dispensing, with tamper evident packaging alongside. Other markets run their own national systems with their own code formats and their own reporting expectations, and some require codes to be requested from a state system before printing rather than generated by you.
What a custom build does: model market obligation as configuration attached to product and destination, so the packaging order knows what it must do before it runs rather than after. Serial number sourcing differs by market, so the number pool abstraction has to support both internally generated ranges and externally issued codes without special casing the line. Reporting adapters per market are versioned, because these systems change their interfaces and you need to run the old and new in parallel during a transition.
Problem 5: verification requests arrive on someone else's clock
When a wholesaler receives a saleable return, they need to verify the product identifier before that unit can go back into commerce. When a partner suspects an illegitimate product, an investigation follows with obligations for both sides. These are inbound requests with response expectations, and they land regardless of whether your serialization lead is at their desk.
What a custom build does: expose a verification service that answers automatically from your repository, logs every request with its requester and response, and alerts a human only when the answer is anything other than a clean confirmation. Repeated verification attempts against the same identifier from unexpected sources are exactly the signal these systems exist to surface, and a build should treat that pattern as an alert rather than a line in a log file nobody reads.
What this costs and how long it takes
Across the 2,000 plus projects Digital Heroes has delivered, this is the shape for serialization platforms. A first release covering serial number pool management, line integration for commissioning and aggregation with exception paths, canonical event storage, and one partner exchange profile runs $100,000 to $220,000 and ships in 16 to 22 weeks. A full platform adding multiple market reporting adapters, a partner profile library, warehouse exception handling on scanners, verification response services, returns processing, and full audit history runs $300,000 to $750,000 phased over 10 to 20 months.
- Number of packaging lines and their vintage. A modern line with a documented interface is days of integration. A line with a proprietary controller and an integrator who has moved on is weeks.
- Number of trading partners and how many insist on their own dialect. Each profile is real work including a test cycle with the partner, whose availability you do not control.
- Number of regulated markets, since each national system is effectively a separate integration project with its own certification.
- Whether contract manufacturers are in scope. A CMO producing on your behalf must send you events in a format you can accept, and getting five CMOs aligned is a programme rather than a feature.
- Validation, because this is a GxP system whose records support product release and regulatory reporting.
Build versus buy, and when buying is right
Buy if you are a single site with one or two lines and a small number of partners. TraceLink, rfxcel, and Systech will get you exchanging data faster than a build, and the network connectivity they bring is worth paying for. Buy if your problem is genuinely connectivity rather than operations, because rebuilding a partner network from scratch is not a sensible use of capital.
Build when two or more of these are true. Your exception volume is high enough that hierarchy mismatches regularly hold shipments, and the packaged system's exception paths do not match how your warehouse actually works. You operate across several markets and are maintaining parallel systems that disagree. You are a repackager or wholesaler whose business model creates aggregation events that manufacturer oriented products handle badly. You need serialization data joined to your own batch, quality, and logistics data for analysis that a hosted repository will not give you. Or your per transaction pricing has grown to the point where the arithmetic of ownership has changed, which happens more often than vendors like to discuss. A hybrid is frequently correct: keep a commercial service for partner connectivity, build the site and enterprise layer where your operations live.
How to choose a developer for serialization software
Ask them to model a repack before you sign anything. A developer who has done this describes unpack and repack as events over an append only stream with current hierarchy computed from history. A developer who proposes updating a parent identifier on a child record has built an inventory app and will produce the exact mismatches that stop your shipments.
Ask how a partner profile is added. If onboarding a new wholesaler requires a code release, you have bought a permanent consulting engagement.
Ask what line level integration they have actually done, naming the printer, the vision system, and the controller. Serialization fails at the line more often than anywhere else, and floor experience is not transferable from web work.
Ask who owns the code and get it in writing before kickoff. You should own the repository, the infrastructure accounts, and the right to hire anyone else to continue the work. At Digital Heroes the client owns the code from the first commit. Serialization records support regulatory reporting and must remain retrievable for years, which is longer than most vendor relationships last.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Across 1,471 IT projects the average cost overrun was 27%, but one in six projects was a 'black swan' with an average cost overrun of 200% and a schedule overrun of nearly 70%. Source: Harvard Business Review (Bent Flyvbjerg & Alexander Budzier, University of Oxford) (2011) →
- In a survey of 579 supply chain professionals (July 31 to October 1, 2024), only 29% had built at least three of the five capabilities Gartner identifies as needed for future competitiveness (agility, resilience, regionalization, integrated ecosystems, and enterprise-wide strategy). Source: Gartner (2025) →
- In the Flexera 2025 State of ITAM report, respondents reported roughly 33% of SaaS spend is wasted, underscoring how paying for off-the-shelf seats and tiers that go unused erodes the supposed cost advantage of generic SaaS. Source: Flexera (2025) →
- Gallup reports global employee engagement fell to 20% in 2025 (its lowest since 2020, down from a 2022-2023 peak of 23%), and estimates low engagement costs the world economy an estimated $10 trillion in lost productivity, or 9% of global GDP. (Note: this figure appears in Gallup's evergreen State of the Global Workplace page, currently reflecting the 2026 edition reporting on 2025 data.). Source: Gallup (2025) →
Aanya builds frontends in Next.js at Digital Heroes, covering rendering strategy, component structure, accessibility and the performance work that decides how a site feels on a mid range phone. Her writing translates frontend decisions into the outcomes non technical stakeholders actually care about.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
How much does custom pharmaceutical serialization software cost?
Should we build serialization software or use TraceLink or rfxcel?
Why do aggregation mismatches hold shipments, and how do you prevent them?
How do you handle trading partners who each interpret EPCIS differently?
What does DSCSA require that lot level systems could not do?
How should returns and verification requests be handled?
How long does line integration take, and what makes it difficult?
Does serialization software need to be validated?
Who owns the code and the serialization data if we hire an agency?
How long does it take to build custom supply chain software?
Should I hire a freelancer or an agency to build supply chain software?
How do I calculate whether custom software will pay for itself?
Can I build my product on a no-code tool like Bubble instead of hiring developers?
What questions should I ask a development agency on the first call?
How much does custom supply chain software cost for a small business?
Who can build a custom supply chain software system?
Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other supply chain software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.