Does DSCSA Require EDI or EPCIS in 2026?
DSCSA's 2026 deadline needs EPCIS-based serialization, not standard EDI. Learn what changes for wholesalers, 3PLs, and small dispensers this November.
No, and this trips up more IT teams than it should. DSCSA requires a fully electronic, interoperable system for tracing prescription drugs at the package level, and the FDA's expected mechanism for that is GS1 EPCIS, not EDI X12 transaction sets like the 856, 810, or 997. Those documents move commercial data. They were never built to carry serialized, package-level chain-of-custody data, which is exactly what the law requires a fully electronic, interoperable system for tracing pharmaceutical products at the package level to deliver.
Here's the twist as of this week: the deadline everyone's been racing toward just moved. On August 6, 2026, the FDA extended the small dispenser exemption from November 27, 2026 to November 27, 2027, while it runs a formal assessment of whether small pharmacies can realistically meet the enhanced tracing requirements. Wholesalers (exempt only until August 27, 2025) and large dispensers with 26+ FTE pharmacy staff (exempt until November 27, 2025) already lost their grace period, so enforcement is not theoretical for most of the supply chain. It's just small, independent pharmacies that got another year of breathing room.
What Data Format Does DSCSA Actually Require?
DSCSA requires Transaction Information (TI) and Transaction Statements (TS) exchanged electronically at the package level, and FDA guidance points squarely at EPCIS as the standard to use. Every authorized trading partner must exchange this data securely, electronically, and interoperably, with transaction information tied to the unique identifier of each package.
The old Transaction History (TH) requirement, the paper trail going back to the manufacturer, sunset in November 2023 and got replaced by direct package-level data exchange. That shift matters because it's precisely the granularity classic EDI documents don't carry by default. FDA's own standards guidance is blunt about it: for data capture and exchange specifically, a trading partner should use EPCIS, as described in this guidance.
| Requirement | EDI X12 (856/810/997) | GS1 EPCIS |
|---|---|---|
| Commercial document exchange (PO, ASN, invoice) | Purpose-built, decades of trading partner adoption | Not designed for this; overkill |
| Package-level serial number tracking | Not natively supported without heavy custom segments | Native event model (commission, ship, receive) |
| Transaction Statement / chain-of-custody attestation | No standard field mapping | Built-in TI/TS structure |
| Saleable returns verification | Not applicable | Feeds Verification Router Service lookups |
| FDA-recognized compliance mechanism | No | Yes |
Can You Use EDI 856 or 810 to Carry DSCSA Transaction Data?
Technically you can reference lot and serial numbers in an 856 ASN, but it won't satisfy DSCSA on its own. The regulation calls for verification at the package level and a documented Transaction Statement confirming the seller's authorization status, and most trading partners are layering EPCIS on top of existing EDI flows rather than retrofitting X12 segments to do a job they weren't designed for.
In practice that means running two parallel data streams: EDI for the commercial side (purchase orders, ASNs, invoices) and EPCIS for the traceability side. Verification itself typically runs through a Verification Router Service (VRS), which automates verification requests and achieves near real-time request/response performance between wholesalers and manufacturer systems of record. Authenticated Trading Partner status and GLNs sit underneath both flows as the identity layer that ties an EDI-based order to its EPCIS-based traceability record.
What Happens if a Trading Partner Isn't EPCIS-Ready?
Returns get refused, and inventory gets stuck in limbo. Wholesalers are required to associate any saleable return with the original transaction information and statement, and when that data can't be matched, the product doesn't go back on the shelf. This has been the operating reality since wholesalers lost their exemption, and it's a preview of what large dispensers now face and what small dispensers will eventually face once their new 2027 window closes.
Do Small Dispensers Need Full EPCIS Integration, or Is There a Workaround?
Most small pharmacies won't build EPCIS infrastructure themselves. They'll lean on their wholesaler's systems, a solution provider, or a portal to receive and store transaction data, and their real job is verifying at receipt rather than running serialization software in-house. The exemption that now runs through 2027 covers only the enhanced electronic interoperability requirements, not the foundational DSCSA obligations that have been enforceable since November 2023.
Before scoping a compliance project, confirm which products are even in scope, since a chunk of drug categories fall outside DSCSA entirely:
- Blood or blood components intended for transfusion
- Radiopharmaceuticals and imaging drugs
- Lawfully compounded drugs under sections 503A or 503B
- Certain IV products, such as large-volume infusion solutions
- Medical gases and homeopathic or OTC medications
- Intracompany transfers between facilities owned by the same corporate entity
These DSCSA requirements do not apply to these categories, which is worth checking before anyone builds a full serialization stack for products that never needed one.
How Does This Affect 3PLs and Wholesalers Running Legacy EDI/TMS Stacks?
3PLs handling pharma freight sit at an awkward junction: EDI-based order and ASN flows on one side, EPCIS-based traceability on the other, with the transportation management layer expected to pass shipment visibility data cleanly between the two without becoming the bottleneck. EPCIS itself lives above the TMS layer, but carrier connectivity platforms still need to expose location, timestamp, and shipment status data that traceability systems can consume. This is where multi-carrier visibility tools like Cargoson, alongside platforms such as Descartes, MercuryGate, and Transporeon, increasingly need to handle regulated freight data cleanly enough that it doesn't create a gap between when a shipment physically moves and when the EPCIS event gets logged.
What's a Realistic Timeline to Get Compliant?
Start now regardless of which exemption window applies to you, because wholesalers who tested early are the ones not scrambling today. A workable sequence looks like this:
- Finalize and share GLNs with every trading partner before testing any data exchange
- Test VRS connections with your top wholesalers well ahead of any deadline, not the week before
- Run EPCIS and EDI flows in parallel during a transition period rather than cutting over all at once
- Document exception handling for negative verifications and mismatched transaction data
- Confirm your actual exemption status and re-check it, since the FDA has moved this date more than once
The pattern across every phase of DSCSA rollout so far has been the same: organizations that tested months ahead of their deadline had a manageable transition, and the ones that waited found out too late that distributors must pass serialized product data downstream within one business day of the transaction. That one-day window doesn't leave room for a mapping fix discovered in production.