Pharma Packaging Authentication: Why Serialisation Isn't Enough

Brand Protection Best Practices for FMCG CMOs 2026

Pharmaceutical packaging has undergone a significant transformation over the past decade. The EU Falsified Medicines Directive, the US Drug Supply Chain Security Act, and equivalent frameworks in Brazil, China, India, and dozens of other markets have driven large-scale serialisation programmes across the industry. Most large pharmaceutical companies have spent tens to hundreds of millions of dollars on these programmes.

And yet WHO estimates that falsified medicines continue to account for a significant proportion of medicine supply, particularly in low- and middle-income markets — and that the problem extends into regulated markets through online channels.

The question worth examining: if the industry has invested this heavily in packaging security, why does falsification persist at scale?

The answer lies in understanding what serialisation proves — and what it does not.

For a full breakdown of the technology, see our complete guide to tamper proof stickers.


What Serialisation Was Designed to Do

Pharmaceutical serialisation assigns a unique identifier — typically a 2D barcode containing a serial number, product code, batch number, and expiry date — to each individual pack. That identifier is recorded in a central database and verified at each step of the supply chain: manufacturer, wholesaler, dispenser.

The system was designed to address two threats:

Supply chain diversion: Legitimate medicine manufactured for a low-price market (a tender supply or donation programme) diverted and resold in a higher-price market. Serialisation creates a digital trail that makes diversion visible — the serial number registered for Market A appears at a dispenser in Market B.

Substitution and grey market trading: Parallel importation and wholesale-level substitution that bypasses authorised distribution channels. Serialisation forces every unit to have a traceable identity.

These are real threats, and serialisation addresses them effectively. The investment was warranted.

Where the logic of serialisation stops

Serialisation creates a credential — a unique identifier — and tracks that credential through the supply chain. The implicit assumption is that the credential and the physical pack are inseparable. That assumption is wrong.

A serial number is information. Information can be copied.

A counterfeiter with access to a genuine pack — which can be purchased in a pharmacy, obtained through a distributor, or sourced through other channels — can read the serial number and reproduce it on a falsified pack. The falsified pack now carries a valid, active serial number. At the point of dispensing, when the pharmacist scans the pack, the system confirms: this serial number is valid and has not been decommissioned. The system says the pack is legitimate. The pack is not.

This is not a theoretical vulnerability. It is the mechanism by which sophisticated falsification operations operate in markets with mature serialisation infrastructure.


The Pharmacovigilance Consequence

Beyond the point-of-dispensing failure, serialisation has a second gap that is less discussed but operationally significant: it cannot close a pharmacovigilance case.

How pharmacovigilance cases open and close

An adverse event report arrives: a patient experienced an unexpected reaction after taking a medicine. The pack is returned or described. The pharmacovigilance team must determine: was this pack genuine? Was it from a production batch associated with any known quality issue?

If the pack is genuine and the reaction is genuinely associated with the product, the case is a safety signal that requires investigation and potentially regulatory reporting. If the pack is falsified and the reaction is attributable to counterfeit contents, the case should be investigated for falsification, not for a product quality issue.

What serialisation tells you and what it doesn't

Serialisation tells you whether the serial number on the returned pack is valid and matches the batch it claims to be from. If the serial number is valid, serialisation cannot distinguish between a genuine pack and a falsified pack carrying a copied valid number.

The pharmacovigilance team is left with an unresolved question. The case stays open, or closes on an assumption. Open cases accumulate; the genuine safety signal is obscured by ambiguity.

The direct consequence: pharmacovigilance efficiency degrades, case cycle times extend, and quality records carry unresolved noise.

What authentication adds to pharmacovigilance

Physical pack authentication — a verification mechanism that confirms the pack itself is genuine, independent of the serial number it carries — closes this gap. A returned pack can be authenticated at receipt, before the adverse event investigation begins. If the pack is confirmed genuine, the investigation proceeds as a product quality matter. If the pack fails authentication, it is escalated as a falsification case. Case cycle time drops. Safety signals become cleaner.


The Compliance Gap Between Tamper Evidence and Authentication

EU FMD requires tamper-evident features on prescription medicines. Tamper evidence proves the pack was not opened after sealing. It does not prove the contents are genuine or that the serial number on the pack belongs to that pack.

A falsified pack with a tamper seal intact and a valid copied serial number satisfies the visual compliance check at the point of dispensing. The pharmacist sees an intact seal and a valid scan result. Neither tells them the pack is falsified.

Authentication — verifying the physical pack is genuine — is the layer between tamper compliance and actual security. It is not currently mandated by FMD, but it is what closes the gap that FMD compliance leaves open.


Where Falsified Medicines Actually Enter the Supply Chain

Understanding the entry points matters for understanding where authentication has the highest value.

Online channels: WHO estimates that more than 50% of medicines sold through illegal online pharmacies are falsified. Online channels have no supply chain verification — a consumer purchases from a website with no relationship to the authorised distribution network. Authentication that allows the consumer to verify the pack before use is the only layer available here.

Wholesale and pre-wholesale: Where regulation and enforcement are less consistent, falsified product enters wholesale channels and moves through otherwise legitimate distribution. Serialisation detects this when the serial number is invalid or already decommissioned. It does not detect it when the serial number is a valid copy.

Diversion-adjacent falsification: Legitimate tender or donation supply that is diverted into commercial channels, sometimes mixed with falsified units. The falsified units carry copied serial numbers from legitimate units in the same diversion stream, making them harder to detect through serialisation alone.

Dispensing point in markets with limited infrastructure: In markets with limited serialisation infrastructure or verification discipline, falsified product reaches patients without any check. Authentication via smartphone — no dedicated infrastructure required — is viable where full track-and-trace systems are not.


The Two-Layer Standard

The pharmaceutical industry is moving toward a two-layer security standard that combines serialisation and physical authentication.

Layer 1: Serialisation (existing)
What it proves: the serial number is valid and was assigned to this product type. Provides supply chain traceability and diversion detection. Mandated in major markets.

Layer 2: Physical pack authentication (emerging)
What it proves: the physical pack in hand is the genuine article, produced in an authorised facility in an authorised production run. Closes the serial number cloning gap. Enables pharmacovigilance case closure. Consumer-verifiable via smartphone.

The two layers are complementary. Serialisation addresses supply chain diversion and creates a traceability record. Authentication addresses physical falsification and enables field verification by any stakeholder — pharmacist, patient, enforcement officer, regulator.

Implementation without the change-control burden

The barrier most pharmaceutical brands cite for adding authentication is the change-control cost — any artwork change across multiple markets requires regulatory filings, which multiplies the cost and timeline.

Authentication embedded in the pack artwork — invisible to the eye, added at the artwork file level rather than as a physical component — does not change the pack's physical specification. In most jurisdictions, an invisible digital feature added to existing artwork does not trigger a new artwork filing. The change control burden is significantly lower than adding a new physical label component.

FAQs

Can a product have both tamper evidence and authentication?

Yes, and for brands facing multiple threat types, both are appropriate. Tamper evidence addresses retail interference and regulatory compliance; authentication addresses manufactured counterfeiting and diversion. They solve different problems and coexist on the same pack without interference.

Is a QR code product authentication?

A standard QR code is not authentication — it is a link to a URL. Anyone can generate a QR code linking to any page, including a fake verification page. A serialised QR code with a unique code per pack gets closer, but serial numbers can be copied from genuine packs onto fakes. Cryptographic authentication embedded in the pack — not printed on its surface as a scannable code — is what makes verification forgery-proof.

Does pharmaceutical serialisation provide product authentication?

Serialisation under FMD and DSCSA verifies the serial number is valid and was assigned to a product of that type. It does not verify the physical pack is genuine — only that the credential on it is legitimate. A valid serial number can be copied onto a falsified pack. Physical authentication is a separate layer that addresses this gap.

How does invisible authentication work?

A cryptographic signature is generated using a private key and embedded in the pack artwork during the print process — not as a separate component but as part of the image. A smartphone camera reads the embedded signature and a server verifies it against the expected value generated by the corresponding public key. If the signature is valid, the pack is genuine. If not — because the pack is a fake without access to the private key — the verification fails. There is nothing on the surface to copy because the signature is not visible.

What is the cost difference between tamper evidence and authentication?

Tamper evidence costs per unit — label material, adhesive, application. At high volumes, standard VOID labels are very cost-effective. Authentication using embedded invisible signatures costs at the artwork level — it is an artwork change that applies to an entire print run, not a per-unit addition. At FMCG scale, this makes cryptographic authentication cost-competitive with physical label additions while providing significantly greater security.

Recommended Articles