Skip to main content
FSMA 204 Compliance

FSMA Compliance Checklist: How to Prepare for the July 2028 Deadline

July 20, 2028 is the FDA's enforcement deadline for FSMA Section 204 — the Food Traceability Rule. If your business handles foods on the Food Traceability List, these ten steps are what stands between you and a compliance gap when the FDA comes calling. Work through them in order. The first step is free and takes under a minute.

·8 min read
1

Determine If Your Products Are on the Food Traceability List

The most important question in FSMA 204 compliance is deceptively simple: is your product on the Food Traceability List (FTL)? The FTL is the FDA's enumeration of high-risk food categories that trigger enhanced recordkeeping requirements under the rule. If your products are not on the FTL, the FSMA 204 enhanced requirements do not apply to you — though standard FSMA recordkeeping still does.

The FTL covers foods in these broad categories: leafy greens, fresh herbs, tomatoes, peppers, cucumbers, tropical tree fruits (papayas, mangoes), melons, sprouts, fresh-cut fruits and vegetables, shell eggs, nut butters, soft and semi-soft cheeses, fresh and smoked finfish, crustaceans (shrimp, crab, lobster), molluscan shellfish (oysters, clams, mussels), and ready-to-eat deli salads containing meat or seafood. Hard cheeses, dried herbs, shelf-stable canned fish, and fully cooked shelf-stable products are excluded.

The "contains FTL food" rule is a critical trap for prepared food manufacturers: if your product contains an FTL-covered ingredient — even if the finished product itself is not on the FTL — you still face recordkeeping requirements at the point you create that product. A chicken Caesar salad is not itself an FTL food, but the romaine lettuce in it is, which means the salad maker must maintain traceability records for the romaine received and used.

Start here: check any product in seconds

Use the free FTL Lookup Tool to instantly determine if a food product is on the FTL, which category applies, and what CTEs and KDEs are required. Try the FTL Lookup Tool →

2

Identify Which Critical Tracking Events Apply to Your Operations

Once you know which of your products are on the FTL, your next task is identifying which Critical Tracking Events (CTEs) occur within your specific supply chain role. FSMA 204 defines five standard CTEs, but not every CTE applies to every business type or every food category.

CTE 1

Growing / Harvesting

The point at which produce is harvested from the growing area. Applies to farms and growing operations. Requires assigning a Traceability Lot Code (TLC) to each harvested lot and recording the growing area location and harvest date. Does not apply to manufacturers of cheese, nut butters, or seafood processors — they have their own starting points.

CTE 2

Cooling (First Cooler)

The first time harvested produce enters a cooling environment. Applies to cooling facilities, packers with pre-cooling operations, and some on-farm operations that field-cool produce. The record must link the TLC to the location and date of cooling. Many small farms are unaware this is a separate CTE from harvesting.

CTE 3

Initial Packing / Transforming

The first time an FTL food is packed into a retail or food-service unit, or when it is transformed into a different product (e.g., whole romaine processed into a salad mix). A new TLC must be created at this event, and the record must link back to the input lots and their TLCs. This linkage is the backbone of what makes the system useful for traceback investigations. Applies to produce packers, processors, manufacturers, and kitchens making RTE deli salads.

CTE 4

Shipping

Every time an FTL food is shipped from one entity to another. The shipper must create a record at the time of shipment capturing the TLC, quantity, product description, origin location, destination, and ship date. Applies to virtually every entity in the supply chain that moves FTL product — farms, packers, distributors, brokers who take title.

CTE 5

Receiving

Every time an FTL food is received from another entity. The receiver must create a record capturing the TLC (which must match what the shipper sent), quantity, product description, and receipt date. Applies to distributors, wholesalers, retailers, restaurants, and food service operators that receive FTL product. The TLC linkage between the shipper's record and the receiver's record is what creates chain-of-custody documentation.

Your role in the supply chain determines which CTEs you own. A grocery retailer may only face Receiving CTEs. A produce packer may face Cooling, Initial Packing, and Shipping CTEs. A food manufacturer using FTL ingredients may face Receiving and Transforming CTEs. Document which CTEs apply to your operation before moving forward.

3

Map Your Key Data Element Requirements for Each CTE

Key Data Elements (KDEs) are the specific fields of information you must capture and retain for each CTE. The FDA requires that KDE records be producible within 24 hours of an agency request — which in practice means electronic systems are strongly favored over paper. Records must be retained for a minimum of two years.

The seven core KDEs that appear across most CTEs are:

Core Key Data Elements
  • Traceability Lot CodeThe unique identifier for the specific lot. This is the linchpin of the system — every other KDE hangs off the TLC. The FDA does not specify a TLC format; it must be unique enough to identify a discrete lot within your system.
  • TLC SourceThe location (farm field, facility, or entity) where the TLC was originally assigned. This allows FDA investigators to trace any lot back to its origin without contacting every entity in the chain sequentially.
  • Quantity / UOMThe quantity of food in the lot and the unit of measure used (pounds, cases, pallets, units, etc.). Consistent unit-of-measure usage across records in a supply chain aids accurate recall scope determination.
  • Product DescriptionA description sufficient to identify the food: commodity type, variety, brand name, and packaging form. For example: "Organic Romaine Hearts, 3-count retail bag" rather than just "romaine."
  • LocationThe name and physical address (or FDA facility registration number) of the entity creating the record, plus origin and destination locations for shipping and receiving CTEs.
  • DateThe date on which the CTE occurred: harvest date, cooling date, packing date, ship date, or receipt date, as applicable.
  • Reference DocumentThe type and identifier of the business document associated with the event — bill of lading number, purchase order number, or similar. This links the traceability record to your existing commercial paperwork.

Additional KDEs apply to specific CTEs and food categories. For example, the Growing/Harvesting CTE for produce requires the growing area location in specific geographic terms. The Transforming CTE requires input TLC linkage — you must record which input lots went into each output lot. Map your specific KDE requirements against each CTE before designing your recordkeeping system.

4

Audit Your Current Recordkeeping Systems

Most food businesses already maintain some recordkeeping — lot numbers on receiving documents, ship dates on bills of lading, product codes on invoices. The gap analysis question is whether your existing records capture all the required KDEs, link correctly across CTEs, and can be retrieved within 24 hours.

Work through this gap analysis for each CTE that applies to your operation:

  • Are you currently capturing a Traceability Lot Code? If yes, is it the TLC from your supplier, or a separate internal lot number? Under FSMA 204, you must carry forward the supplier TLC (or document the linkage), not just assign your own number.
  • Is the TLC source recorded? Many businesses record lot numbers but not which entity originally assigned them. This is a common gap.
  • Can you retrieve all records for a single lot within 24 hours? Test this: pick a product lot received six months ago and try to pull all associated records. If it takes more than a few hours, your current system will not meet the FDA retrieval standard.
  • Are records retained for two years? Some businesses purge receiving records annually. FSMA 204 requires two-year retention.
  • Are transformation inputs linked to outputs? If you process or transform FTL foods, do your records show which input lots were used to produce each output lot? This linkage is mandatory and is commonly missing from ERP configurations.

Document every gap you identify. Gaps fall into three categories: missing data fields (solvable with process changes), missing linkages (solvable with system configuration), and retrieval speed (may require system upgrades). Prioritize gaps by their complexity to remediate.

5

Choose a Traceability Data Format

The FDA does not mandate a specific recordkeeping format. Paper, spreadsheets, dedicated traceability software, and ERP systems are all permissible — but not all are equally practical given the 24-hour retrieval requirement.

Spreadsheets

Viable for small operations handling a limited number of FTL products and lots per month. A well-structured spreadsheet can capture all required KDEs and link CTEs through shared TLC values. The critical limitation: manual data entry creates error risk, and retrieval can be slow if the spreadsheet is not designed with search in mind. Suitable for very small businesses processing fewer than 50 FTL lots per month.

Dedicated Traceability Software

Purpose-built platforms designed for FSMA 204 compliance. These systems typically include TLC generation, CTE-specific data entry forms, linkage between input and output lots, and rapid recall query capabilities. They vary widely in cost and complexity — from SMB-oriented SaaS tools to enterprise platforms. Appropriate for mid-size distributors, packers, and manufacturers who handle hundreds of FTL lots per month.

ERP System Configuration

Many food businesses already operate an ERP (such as SAP, Oracle, or industry-specific systems). These can often be configured to capture FSMA 204 KDEs within existing lot control and inventory management modules. The challenge is that most ERP implementations predate FSMA 204 and require specific configuration changes — particularly for TLC source tracking and transformation input-output linkage.

API-Based Automation

For technology teams building compliance systems, traceability APIs enable automated FTL classification, CTE identification, and KDE validation at the point of transaction. Rather than manually reviewing products against the FTL, an API call returns the applicable CTEs and KDE requirements for a given product description in milliseconds — enabling compliance checks to be embedded directly in procurement, receiving, and shipping workflows. See the FoodChainAPI documentation for examples.

6

Establish Traceability Lot Codes

The Traceability Lot Code (TLC) is the identifier that makes the entire FSMA 204 system work. A TLC uniquely identifies a specific lot of FTL food at the point it enters the traceability record system — at harvest for produce, at initial packing for packaged goods, or at the Transforming CTE when inputs are combined into a new output.

The FDA does not mandate a TLC format or encoding scheme. However, a well-designed TLC system has several characteristics:

  • Uniqueness: No two distinct lots should ever share a TLC. Include enough information in the TLC structure — such as date, facility code, and sequential counter — to prevent collisions even across years of production. A format like FAC001-20260217-0042 (facility + date + sequence) is readable and collision-resistant.
  • Persistence: Once assigned, a TLC should not be changed or reused. If a lot is split, each sub-lot should receive a new TLC with a reference back to the parent TLC.
  • Machine-readability: TLCs are more useful when they can be encoded in barcodes or QR codes on labels, enabling scanning at receiving and shipping CTEs without manual transcription. GS1 standards (using the GTIN + batch/lot number AI 10 in a GS1-128 barcode) are the industry standard and are FDA-compatible.
  • Source documentation: When you assign a TLC, document the TLC source location — the FDA facility registration number or physical address of the location where the TLC was assigned. This is a required KDE.

If you receive product with a TLC already assigned by your supplier, you must carry that TLC forward in your records — do not discard it or replace it with your internal lot number alone. If you use an internal number for operational reasons, maintain a documented linkage between your internal number and the supplier TLC.

7

Set Supplier Traceability Requirements

Your FSMA 204 compliance depends heavily on your suppliers. The TLC linkage requirement — which demands that your Receiving CTE records reference the same TLC as your supplier's Shipping CTE records — means that if your suppliers are not assigning and transmitting TLCs, your records will have gaps the FDA will identify.

Update your supplier qualification process and purchase agreements to require the following:

  • Traceability Lot Code on all shipping documents: The TLC for each lot must appear on the bill of lading, advance ship notice (ASN), or equivalent document. Verbal or informal communication is not sufficient.
  • TLC source information: Your supplier must provide the TLC source location — where the TLC was originally assigned. If they received the product and are forwarding it, they must pass through the original TLC source, not substitute their own facility.
  • Electronic data transmission: For operationally significant volumes, require TLC data in an electronic format (EDI 856 ASN, PDF with structured data, CSV, or API webhook) so receiving staff are not manually transcribing lot codes from paper documents.
  • FSMA 204 compliance attestation: Include a clause in your supplier agreements confirming that the supplier is aware of and working toward FSMA 204 compliance for the products they supply to you. Document this for your FDA audit trail.

Segment your suppliers by FTL-product volume. High-volume suppliers of FTL products should be onboarded into traceability data exchange protocols first. Low-volume or one-time suppliers still need to provide TLC data, but a simpler paper-based requirement may be sufficient.

8

Build Internal Processes for Receiving, Shipping, and Transforming Events

Good recordkeeping requires consistent, repeatable processes — not just a system. Even with the right software in place, your team must know what to do, when to do it, and how to handle exceptions. Write standard operating procedures (SOPs) for each CTE your operation performs.

Receiving Process

At every FTL food delivery, receiving staff must: (1) obtain the TLC from the inbound shipping document before the truck is released, (2) verify the TLC matches the physical label on the product or pallet, (3) record the TLC, TLC source, product description, quantity, and receipt date in your recordkeeping system, and (4) link the receipt record to the associated purchase order or bill of lading number. If the supplier has not provided a TLC, do not release the receiving record as complete — escalate to your supplier relationship contact.

Shipping Process

At every FTL food shipment, warehouse or shipping staff must: (1) identify the TLC of each lot being shipped, (2) record the TLC, quantity, product description, ship date, origin location, and destination on the shipping CTE record, (3) include the TLC on the outbound bill of lading or ASN provided to the receiver, and (4) link the shipping record to the purchase order or sales order number. If a shipment contains multiple lots (multiple TLCs), each must be recorded separately.

Transforming / Processing Process

When FTL foods are transformed — cut, processed, assembled into a new product — a Transforming CTE record must be created that documents: (1) all input TLCs and their quantities used in the transformation, (2) the new output TLC assigned to the finished product, (3) the product description of the output, (4) the quantity of output, (5) the location and date of the transformation. This input-output TLC linkage is the most technically complex part of FSMA 204 recordkeeping and requires explicit system design to support correctly.

9

Run a Mock Recall Exercise — the 24-Hour Recall Test

FSMA 204 requires that covered entities be able to provide all traceability records for a specific lot to the FDA within 24 hours of a request. This is not a theoretical standard — during an active foodborne illness outbreak, FDA investigators will issue exactly this type of request, and your ability to respond quickly can directly affect how many people get sick.

Before your July 2028 deadline, conduct at least one full mock recall exercise. The exercise should simulate an FDA data request for a specific lot of FTL product. Design your exercise to answer these questions:

  • Traceability forward: Starting from a specific input lot (e.g., a specific TLC of romaine received from a supplier), can you identify every finished product lot that contained that input, and every customer who received those finished lots?
  • Traceability backward: Starting from a specific finished product lot, can you identify all the input lots used to produce it, their TLC sources, and the suppliers who provided them?
  • Record retrieval speed: How long does it actually take to pull and compile the records? Time your exercise. If it takes more than 4 hours, you need to optimize your retrieval process — 24 hours sounds like a lot until you account for discovering the request at 11 PM on a Friday.
  • Record completeness: Are all required KDEs present in every record? Gaps in a live FDA request are compliance failures.

Document the results of your mock recall exercise, including any gaps identified and the corrective actions taken. This documentation demonstrates good faith compliance effort to FDA inspectors, even if your system is not perfect at the time of inspection.

10

Document Your Written Traceability Plan

FSMA 204 explicitly requires that covered entities maintain awritten Traceability Plan describing how they maintain traceability records. This is not optional documentation — it is a regulatory requirement. The FDA expects to be able to review your Traceability Plan during an inspection, and it must be updated whenever your traceability systems or processes change.

Your written Traceability Plan must include, at minimum:

  • A description of the foods you handle that are on the FTL, including how you determined they are covered (or not covered) and any exclusions you are relying on, with the basis for each.
  • A description of how you assign Traceability Lot Codes, including your TLC format, the system used to generate TLCs, and the process for ensuring uniqueness.
  • A description of your recordkeeping systems — what systems capture CTE records, where records are stored, and how long they are retained.
  • A description of how records can be retrieved and provided to the FDA within 24 hours, including who is responsible for responding to FDA data requests.
  • Contact information for the person responsible for traceability compliance at your facility or organization.

Treat your Traceability Plan as a living document. Review and update it annually and whenever you add new FTL products, change suppliers, modify your recordkeeping systems, or change your operational processes. Each revision should be dated and version-controlled.

Timeline Summary: Steps Mapped to Milestones

StepActionRecommended Timing
1FTL product determinationNow — free, takes minutes
2CTE mapping by operation typeNow — 1 to 2 weeks
3KDE requirements mappingNow — concurrent with Step 2
4Gap analysis of current systemsQ1 2027 — 4 to 8 weeks
5Data format selection and procurementQ1–Q2 2027 — after gap analysis
6TLC system design and implementationQ2 2027 — 4 to 12 weeks depending on complexity
7Supplier requirement rolloutQ2–Q3 2027 — allow 90 days for supplier onboarding
8Internal SOP development and trainingQ3 2027 — concurrent with system go-live
9Mock 24-hour recall exerciseQ4 2027 — at least 6 months before deadline
10Written Traceability Plan finalizedQ1 2028 — at least 6 months before deadline

The July 20, 2028 enforcement deadline is fixed. Organizations that begin this process in 2027 will have adequate time to complete all steps, but those that wait until 2028 will face a compressed timeline with limited room for iteration and supplier onboarding delays.

Start with Step 1 — Free in Under a Minute

The FoodChain FTL Lookup Tool is the fastest way to complete Step 1 of this checklist. Enter any food product description and get an instant determination of whether it's on the Food Traceability List, which category applies, and what CTEs and KDEs are required. No account required.

Get FSMA 204 Compliance Updates

FDA guidance on FSMA 204 continues to evolve as the July 2028 deadline approaches. Get notified when FoodChainAPI launches and when FDA issues new guidance on the Food Traceability Rule.

Related Guides