Packaging, labeling and serialization
📍 Where we are: Stop 19 of 21 — the medicine is sealed in vials, and now we turn it into a finished, trackable package with a passport of its own.
Labeled vials are packed into printed cartons at the end of the line. This is where every unit is inspected, labeled, boxed, and given a unique code so it can be tracked all the way to the patient.
Vials being packed on a pharmaceutical production line. Image by Sadegh Nikgostar, CC BY 4.0, via Wikimedia Commons.
By now the medicine — for the mAb (monoclonal antibody) we have followed through this book, a purified protein drug — is inside sealed glass vials (small single-dose glass bottles) or pre-filled syringes, fresh from fill-finish. But a bare vial cannot be shipped to a hospital. In this step we inspect every vial, print and apply a label, box it with its instructions, and give every single pack its own unique code so it can be followed all the way to the patient — and so a fake pack can be caught before it ever gets there.
Think of how every passport has a photo, a name, and a number that no one else on Earth shares. Here we give every single package of medicine its own "passport": a label that says exactly what it is, and a unique code that lets anyone — a pharmacist, a customs officer, the manufacturer — follow that exact pack from the factory floor to the pharmacy shelf, and confirm it is real.
What this chapter covers
We will walk the packaging line end to end: the high-speed camera systems that inspect every vial for cracks and particles, the labelers that place a tamper-evident label within a hair's width of where it belongs, the cartons and patient leaflets of secondary packaging, and the serialization step (giving each pack its own unique, trackable code) where each pack gets a unique 2D code. We will see how that code feeds two giant legal track-and-trace systems — the U.S. DSCSA and the EU Falsified Medicines Directive — and why the whole apparatus exists: to keep counterfeit medicine out and to make recalls surgical rather than nationwide. Along the way we will meet the real machines, the real standards (GS1, ISO/IEC, USP, ICH), and the real numbers the industry runs at.
What actually happens
The sealed vials arrive from fill-finish, and now they become a real, shippable product. Five things happen, in order.
Vision inspection: 100% inspection of every vial
1. Inspection. Every single vial is checked — this is 100% inspection, not a sample. Modern lines do it with automated vision systems (from vendors such as Bosch (Syntegon), Stevanato/SEA Vision, or Brevetti CEA) that run a vial past a bank of high-speed monochromatic and color cameras, image it in roughly 50 milliseconds, and decide pass-or-reject at throughputs of about 200 to 600 vials per minute. "100% inspection" means every vial is examined — not that every defect is caught: the detection efficiency for any given defect is a qualified, probabilistic figure (per USP <1790> — USP is the U.S. Pharmacopeia, the official U.S. drug-standards book, and the angle-bracket numbers are chapters in it). In plain terms, the machine's catch-rate for each kind of flaw is a measured, proven number, not a guarantee: the line is proven before use by running a tray of deliberately defective reference vials (a defect and particle reference set) past it and measuring the fraction it actually catches, and any vial the cameras flag is automatically knocked out — pushed by an air jet or arm into a reject bin (the preset reject limit is the knock-out threshold) rather than continuing down the line. Even so, small or low-contrast particles and fine cracks are detected well below 100%. The cameras hunt for cracks in the glass, a fill level outside a validated, product-specific window (typically only a few percent of target, set by the approved overage and label-claim limits rather than any blanket tolerance), and floating or settled particulates — bits of glass, fiber, or aggregated protein. A protein medicine should look essentially clear.
The benchmark for what counts as a defect is set by the U.S. Pharmacopeia: chapter USP <790> sets the enforceable acceptance criterion that injections be "essentially free" of visible particulates and requires the 100% inspection itself, while the companion chapter USP <1790> describes how manual, semi-automated, and fully automated inspection actually work and how the probability of catching a defect is qualified [3]. The FDA goes further: in its 2021 draft guidance it makes clear that meeting the compendial standard (the USP requirement just described) alone is not, by itself, enough for cGMP compliance — manufacturers are expected to take a risk-based approach: to study where particles are most likely to arise across the whole process and put the tightest controls there, rather than relying on the final camera check alone [2]. cGMP, which we will lean on repeatedly here, stands for current Good Manufacturing Practice: the binding FDA standard for how medicines must be made and documented.
The "decide pass-or-reject" step inside that camera is increasingly a machine-vision model — a trained image classifier rather than a fixed rule — which is why the detection efficiency is treated as something to be measured and proven rather than assumed. That makes the inspection station a natural home for the model-and-validation discipline the machine-learning book builds for exactly this line in packaging and serialization: the reference-set qualification described above is, in machine-learning terms, evaluating the model against a labeled test set and pinning down its operating point.
Labeling and tamper evidence: position feedback and multi-lane applicators
2. Labeling. A label is printed and applied to each vial, typically at 100 to 300 units per minute on applicators from companies such as the Marchesini Group or Uhlmann. Position-feedback sensors keep the label placed within a tight tolerance — on the order of a few millimeters — because a crooked or off-position label can hide critical text or jam a downstream scanner. The label is tamper-evident: once applied, you cannot peel and re-stick it cleanly. It must carry, in both human-readable text and machine-readable code, the product name, the strength (how much medicine is inside), the lot number (a code identifying which manufactured batch it came from), and the expiry date (the last day it is guaranteed safe and effective). Carrying that information in both forms is not a nicety — the machine-readable product identifier is mandated by the DSCSA statute (the U.S. drug-safety law, written into the Food, Drug & Cosmetic Act — "FD&C Act §§ 581/582" names the specific sections), while the label content itself is governed by the expiration-dating rule and the labeling-content requirements of the Code of Federal Regulations ("21 CFR" is Title 21 of those federal rules; the cited parts spell out what the label must say), so a human and a scanner can independently confirm the same facts. (Separate cGMP controls in 21 CFR 211.122 and 211.125 govern the handling and reconciliation of labeling materials to prevent mix-ups.) High-throughput lines split the work across several parallel applicators — multi-lane heads running side by side — and a vision check immediately downstream re-reads the freshly applied label to confirm the print is legible and the placement is in tolerance before the vial is allowed onward.
Secondary packaging: carton engineering and stability
3. Secondary packaging. Vials go into a printed carton along with the package insert — the official, regulator-approved document of how to use the medicine, its dosing, and its side effects. (In the U.S. this is the Package Insert or "prescribing information"; in Europe the equivalent professional document is the Summary of Product Characteristics, with a separate patient leaflet for the person taking the drug.) This wording is approved as part of the marketing application, so it is not something the packaging team can edit on the fly. The carton itself is engineered: it provides the light-protection and moisture-barrier the product needs to stay stable through its labeled shelf life, and that protection is justified by the stability studies behind the product (more on those below).
Serialization: printing the pack's passport number
4. Serialization. Now each pack gets its passport number. A unique, machine-readable code is printed — almost always a 2D data matrix, the small square barcode you have seen on medicine boxes. Specifically it is a GS1 DataMatrix built on the ISO/IEC 16022 symbology (the ECC200 variant), a standard that defines the square module grid, how the data is encoded, and the Reed–Solomon error correction that lets a scanner still read the code even if part of it is scuffed [4]. What the code means is defined by the GS1 General Specifications: four data elements packed in using GS1 Application Identifiers — the product code (a GTIN, the Global Trade Item Number that names what the product is), the unique serial number, the batch/lot number, and the expiry date [5]. The amount of data the square can hold scales with its grid size — in plain terms, the square just has to be big enough to hold the roughly 40-to-50-character pharma payload, so a slightly larger grid is chosen: a 26×26-module symbol carries on the order of 88 digits (about 60 alphanumeric characters), while a real pharma serialization payload — a GTIN, a serial of up to 20 characters, a lot, and an expiry date, roughly 40 to 50 characters in all — typically needs a larger symbol, commonly in the ~26×26 to 36×36 range (rectangular ECC200 sizes such as 26×48 are also used). Capacity depends heavily on whether the serial is numeric or alphanumeric: a numeric-mode payload packs roughly twice as densely as an alphanumeric one, which is why GS1 pharma codes — where the GTIN, lot, and expiry are all digits — fit comfortably even when the serial pushes the symbol larger. Whatever the size, it is printed at high resolution (often 300+ dpi) so an ordinary pharmacy scanner can read it instantly.
A downstream camera then does more than confirm the code decodes: it runs a graded print-quality verification to ISO/IEC 15415, scoring how clean the print is — contrast (light-vs-dark separation), grid non-uniformity (how evenly the dots sit on the grid), unused error correction (how much of the built-in safety margin is still spare), and fixed-pattern damage (wear to the L-shaped finder edges the scanner needs) — down to a single letter grade (a minimum of grade B or C is a common customer spec). A code that decodes today but grades poorly is rejected, because it may fail at a pharmacy scanner months later. No two packs in the world share the same serial number.
Cold-chain indicators: time-temperature integrators and loggers
5. Cold-chain prep. Most biologics, including most mAbs, are formulated to be stored cold — typically at 2 to 8 °C (ordinary refrigerator range), never frozen. (A few products are stabilized for room-temperature storage, and some advanced therapies need ultra-cold freezers; the label always states the exact condition.) Packs are placed into insulated shippers with conditioned gel packs and, often, a temperature-excursion indicator taped to the carton. These come in two flavors that are easy to confuse. A time-temperature integrator — such as a 3M MonitorMark strip or a VITSAB enzymatic indicator — is a small, single-use chemical tag that changes color irreversibly once the pack has spent too long above a threshold (for example, more than a few hours warmer than 8 °C); it is a cheap visual flag, not a recorder. An electronic data logger is a small battery-powered device that records the actual temperature over time and can be downloaded later. The indicator says "something went wrong"; the logger says "here is exactly what, when, and for how long." The whole reason any of this is needed is that protein drugs are physically fragile: warmth speeds up the chemical degradation of the antibody (slow reactions such as deamidation and oxidation of individual amino acids) and, just as importantly, nudges the folded protein to partly unfold and stick to its neighbors — forming the aggregates the inspection cameras hunt for and that can blunt potency or provoke an immune response. Keeping the vial cold slows both pathways, which is precisely the concern that ICH Q5C, the stability-testing guideline for biological products, was written to address [8].
A typical automated packaging line for vials: vision inspection (200–600 units/min), labeling with tamper evidence, and 2D GS1 DataMatrix serialization (shown with sample barcode).
Original diagram by the authors, created with AI assistance.
Anatomy of a GS1 DataMatrix: decoding the license plate
When a scanner reads the little square on the carton, it does not get back "a number." It gets back a structured string — four facts, each one introduced by a two-digit GS1 Application Identifier (AI) that tells the reader what the field means. AI (01) introduces the GTIN-14, the Global Trade Item Number that says what the product is (in the U.S. the GTIN embeds the National Drug Code). AI (21) introduces the serial number — the one-of-a-kind, up-to-20-character string that no other pack on Earth shares. AI (10) introduces the lot/batch, and AI (17) the expiry in YYMMDD form (two-digit year, month, day). The fields are concatenated into one payload, with an FNC1 separator — a special non-printing control character defined by GS1 — marking the end of variable-length fields like the serial and lot so the decoder knows where one ends and the next begins.
| AI | Field | What it says | In the worked example |
|---|---|---|---|
(01) | GTIN-14 | what the product is (embeds the U.S. National Drug Code) | 00312345678906 |
(21) | Serial number | this one exact pack (up to 20 characters) | A1B2C3D4E5 |
(10) | Lot / batch | which manufactured batch | LOT2024X |
(17) | Expiry (YYMMDD) | last day guaranteed | 260930 = 30 Sep 2026 |
Worked through on a real-looking string, (01)00312345678906(21)A1B2C3D4E5(10)LOT2024X(17)260930 reads as: GTIN-14 00312345678906 (the product), serial A1B2C3D4E5 (this exact pack), lot LOT2024X (its batch), and expiry 260930 (30 September 2026). Because the serial under (21) is variable-length, an FNC1 separator falls right after it, telling the decoder where the serial stops and the next AI begins.
The square itself is more than a grid of dots. A solid L-shaped finder pattern on two edges and a dotted timing edge on the other two tell the scanner where the grid starts and how big it is, so the code reads at any rotation. Around and through the data, Reed–Solomon error-correction bands add redundancy: a scanner can still recover the full payload even if part of the symbol is scuffed, smudged, or printed imperfectly — the same mathematics that protects a CD from scratches [4]. And because all of this only works if the code is physically where the scanner expects it, the labeling applicator holds the symbol to a tight position tolerance (on the order of a couple of millimeters) and keeps it square; a skewed or clipped DataMatrix is a code that will not resolve.
Every GS1 DataMatrix decodes to the same four GS1 Application Identifiers packed into one string, wrapped in finder and Reed–Solomon bands that keep it readable.
Original diagram by the authors, created with AI assistance.
This is exactly the kind of structured, self-describing payload that the data side of the plant has to capture and store cleanly: the data-management book treats the same serial-and-lot record as a born-on-the-line data point — the moment a measurement or identifier is created at a real station is its point of birth, and from there it becomes part of the batch's data shadow. In a connected plant the print-grade reading and the serial event do not stay on the packaging line: they ride the same shop-floor data standards as the rest of the process — an ISA-95-style production record (often exchanged as B2MML and read off the equipment over OPC UA) — so the record flows into the plant information systems. The open-source companion shows the concrete fill-finish event model that records it in code under fill-finish event management, and lands it as real database rows in the reference architecture.
Serialization networks
A serial number is only as good as the system that can vouch for it. This section separates the printed identifier from the network that verifies it, then shows how the two major regions wire that network differently.
The two-layer design: unique identifier and network verification
The code is not the security; the network behind it is. A counterfeiter can photocopy a printed DataMatrix perfectly — what they cannot copy is a matching, un-dispensed record in the verification database.
It helps to separate two ideas that get blurred together. The first is the unique identifier printed on the pack — the serial number inside that 2D DataMatrix. The second is the network the number is checked against. The printed code is useless on its own; its power comes from being recorded in, and verifiable against, a shared database. When a pack is serialized at the factory, its number is registered. As it moves down the supply chain, that same number can be scanned and confirmed against the registry at each handoff. A counterfeit pack either has no number in the system, a number that belongs to a pack already sold somewhere else, or no readable code at all — and any of those raises a flag.
This two-layer design is exactly what the major track-and-trace laws mandate, just with different plumbing in each region.
The same printed identifier feeds two regional verification models — the U.S. DSCSA distributed exchange and the EU centralized EMVS repository — built on one GS1 backbone.
Original diagram by the authors, created with AI assistance.
The serial number on the pack and the database record behind it must agree exactly and never be quietly edited — which is why each scan is an attributable, time-stamped, permanent event. That discipline is the same data integrity principle the data-management book builds out under ALCOA+: the physical code here is only trustworthy because the data record behind it is.
Two regions, two networks: DSCSA vs FMD/EMVS
Remember the unifying idea before the plumbing diverges: same square, same four facts, two different ways of checking it. This unit-by-unit tracking is not a best-practice suggestion; in major markets it is the law, backed by interoperable digital networks.
In the United States, the framework is the Drug Supply Chain Security Act (DSCSA), passed in 2013 as part of the Drug Quality and Security Act. It phased in over a decade, and the headline requirement — interoperable, electronic, package-level tracing of prescription drugs across the supply chain — became fully required in late November 2023 [6]. Each pack must carry a product identifier (the National Drug Code, a serial number, the lot, and the expiry), and trading partners — manufacturers, wholesalers, dispensers — must be able to exchange that data electronically so a product's path can be reconstructed and suspect product investigated and removed. (Because the cutover was so disruptive, the FDA granted a stabilization period and staggered exemptions to give smaller dispensers time to get their systems interoperable, but the underlying obligation is in force.)
In the European Union, the parallel system flows from the Falsified Medicines Directive (2011/62/EU), made concrete by Commission Delegated Regulation (EU) 2016/161 [7]. It requires two safety features on most prescription packs: a unique identifier (a 2D DataMatrix carrying product code, serial number, batch, and expiry — the same GS1 backbone the U.S. uses) and an anti-tampering device on the carton. Every pack's identifier is uploaded to the European Medicines Verification System, a shared repository; pharmacies scan and "decommission" each pack at the point of dispensing, and a code that is unknown, already dispensed, or recalled is rejected on the spot.
The two regions chose different verification models — Europe's centralized end-to-end repository versus the U.S.'s distributed, trading-partner-to-trading-partner exchange — but they rest on the same physical foundation: a GS1 DataMatrix printed on the pack and a database it can be checked against.
Why it matters
Serialization exists to solve two very real dangers.
The first is counterfeit and falsified medicine — fake products that may contain the wrong dose, the wrong drug, or nothing active at all. This is not a fringe problem. The World Health Organization estimates that at least 1 in 10 medical products in low- and middle-income countries is substandard or falsified, and that roughly US$30.5 billion a year is spent on such products (money paid out for these substandard or fake medicines) [1]. Because every genuine pack now carries a unique, verifiable identity, a fake pack with a copied, missing, or already-used code can be caught before it reaches a single patient.
The second danger is the recall done badly. If a defect is later found in one manufactured batch, the lot number and the per-pack serial numbers let the company pinpoint exactly which packs are affected and pull only those — not every box of that product in the country. A blunt, nationwide recall wastes good medicine, frightens patients, and can trigger a shortage of a drug people depend on. Precise traceability turns a sledgehammer into a scalpel.
There is a quieter third reason, too: a wrong label is just as dangerous as a wrong medicine. The right name, strength, and expiry date — verifiable by both a human and a machine — are how a nurse trusts the dose they are about to push into a patient's arm. Serialization is the system that makes "trust, but verify" possible at the scale of millions of packs.
When serialization breaks: aggregation failures in the supply chain
The two-layer system has a quiet failure mode that has nothing to do with counterfeiters: it can break on its own, on legitimate product. The reason is aggregation — the parent-child links that say "these 50 vial serials live inside this carton, and these 20 cartons live inside this case, which lives on this pallet." Aggregation is what lets a warehouse scan one code on the outside of a case and have the system infer every serial nested inside, without opening the box. It is enormously convenient, and it is fragile: if a vial is rejected after its serial was already claimed for a carton, if a carton is re-packed into a different case, or if the line's data simply records the hierarchy wrong, the asserted vial-to-carton or carton-to-case link no longer matches what is physically in the box. When a downstream partner later scans the case, the resolution fails — the system expects serials that are not there, or finds serials it was never told about — and otherwise-genuine product can be quarantined or rejected at the dock.
These mis-asserted hierarchies are a large part of why the U.S. transition was so bumpy. Faced with widespread readiness gaps and exactly these kinds of data-quality breakdowns, the FDA used its discretion to extend the DSCSA stabilization period, giving trading partners more time to get interoperable, accurate enhanced-distribution data (the DSCSA-required electronic record of who shipped what to whom) and verification data flowing before enforcing the full requirement [9]. The stakes behind getting it right are not abstract — the roughly US$30.5 billion a year the WHO ties to substandard and falsified medical products [1] is exactly the harm a clean, resolvable aggregation chain is meant to prevent. The lesson is the same one that runs through this whole chapter: the physical code is only ever as good as the data relationships behind it, which is why aggregation modeling, hierarchical naming, and unique-namespace discipline matter so much. Each "lives inside" link is really a typed relationship — a contains edge from carton to vial, the same kind of parent-child relation the ontology book treats as a first-class, walkable connection in relations and genealogy (and the vial-carton-case-pallet tiers are an is-a taxonomy of pack levels, the subject of classes and taxonomy); when the edge is mis-asserted, the graph simply no longer matches the box. The open-source companion works exactly this problem in its Unified Namespace naming chapter, where every nested object gets one canonical, collision-free address.
In the real world
The equipment that does all this is recognizable across the industry. Inspection and labeling lines come from a short list of integrators — Bosch (Syntegon), Marchesini, Uhlmann, Stevanato, IMA — and the serialization "brain" that generates serial numbers, prints them, verifies the print, and reports to the national systems is its own software layer, from vendors such as Systech and Antares Vision, or built into the line vendor's own modules. All of it is governed by cGMP batch-record rules: serialization and labeling are part of the legally controlled production record under 21 CFR Part 211, Subpart J, so every code generated, applied, and verified is an auditable event.
Where does the cutting edge of this fit into a guide about modern biomanufacturing? The same push toward connected, data-rich, end-to-end traceability that drives serialization also drives the broader modernization of the industry, including the move toward next-generation processes such as the continuous, intensified manufacturing (running the process as a steady, uninterrupted flow rather than in separate batches, to get more product from a smaller footprint) introduced in bioprocessing and carried through tech transfer and scale-up. A serialized, fully traceable supply chain is the natural endpoint of that same data-first philosophy.
One last grounding fact ties the whole chapter together: the expiry date printed on every label is not a guess. It comes from formal stability studies run under ICH Q5C and the broader ICH Q1A(R2) stability framework — accelerated studies (commonly around 25 °C and 60% relative humidity) deliberately store the product warmer than its real 2-to-8 °C home, because heat speeds up the chemical and physical degradation and lets the team predict the shelf life faster, while long-term studies sit at the real storage condition (for most mAbs, 2 to 8 °C), often run out to 36 months or more [8]. Those studies prove how long the product genuinely stays within specification, and that result is what gets printed as the shelf life. The label, in other words, is the visible tip of a years-long scientific record.
Key terms
- Inspection — checking every vial (100% of them) for cracks, particulates, or wrong fill level before it ships, usually by high-speed camera systems.
- Machine-vision model — the trained image classifier inside a modern inspection camera that decides pass-or-reject; its catch-rate is measured against a labeled reference set, not assumed.
- Lot number — a code that identifies exactly which manufactured batch a pack came from; the key to a precise recall.
- Expiry date — the last day the medicine is guaranteed safe and effective, set by formal stability studies, not by guesswork.
- Secondary packaging — the printed carton and the regulator-approved package insert placed around the vial.
- Serialization — printing a unique, machine-readable code on each pack so it can be tracked and verified individually.
- 2D data matrix — a small square barcode (GS1 DataMatrix, ISO/IEC 16022 / ECC200) that stores the pack's product code, serial number, lot, and expiry.
- Unique identifier — the serial number inside the DataMatrix; the pack's one-of-a-kind passport number.
- Recall — pulling specific affected packs back out of the supply chain when a problem is found, made surgical by serial-level tracking.
- Cold chain — keeping the medicine within a safe temperature range (for most biologics, 2 to 8 °C) all the way to the patient.
- Time-temperature integrator — a single-use chemical tag that changes color irreversibly after too long above a threshold; a visual excursion flag.
- Electronic data logger — a battery-powered device that records the actual temperature history over time for later download.
- DSCSA — the U.S. Drug Supply Chain Security Act, requiring interoperable, electronic, package-level tracing.
- Falsified Medicines Directive (FMD) — the EU law requiring a unique identifier plus an anti-tampering device, verified against the European Medicines Verification System.
- GS1 Application Identifiers — the GS1 standard data elements (product code, serial, lot, expiry) packed into the DataMatrix.
- GTIN — Global Trade Item Number, the AI
(01)field that identifies what the product is; in the U.S. it embeds the National Drug Code. - Reed–Solomon error correction — the redundancy bands inside a DataMatrix that let a scanner recover the full payload even when part of the code is scuffed.
- Aggregation — the recorded parent-child links (vial→carton→case→pallet) that let one outer scan infer every serial nested inside; if mis-asserted, downstream scans fail to resolve.
- cGMP — current Good Manufacturing Practice, the binding standard for how medicines must be made and documented.
Where this leads
The packs are now inspected, labeled, serialized, and chilled — physically ready to ship. But "physically ready" is not the same as "allowed to leave." Before a single carton goes out the door, a separate set of laboratory tests and a formal sign-off must confirm the batch is safe, pure, and potent. That is the work of quality control and batch release, where the medicine finally earns permission to reach patients.