About Platsera
Platsera Technology
Traceability and Compliance

Traceability and Compliance

Can You Comply With FSMA 204 Using Spreadsheets?

Can You Comply With FSMA 204 Using Spreadsheets?


'

What the rule actually requires

What the rule actually requires

Short answer: yes, legally. The FDA does not require any particular software for FSMA 204. You can keep your traceability records in spreadsheets, or even on paper, as long as you can hand the FDA an electronic sortable spreadsheet covering the requested records within 24 hours of a request.

The practical answer is that spreadsheets work up to a clearly identifiable breakpoint, and most companies asking this question are closer to that breakpoint than they think. This post lays out where the line actually sits, so you can make the call based on your operation instead of a vendor's pitch.

FSMA 204, the FDA's Food Traceability Rule, applies to companies that manufacture, process, pack, or hold foods on the Food Traceability List, which covers categories like leafy greens, fresh-cut produce, cheeses, shell eggs, nut butters, finfish, and ready-to-eat deli salads, plus products containing them as ingredients.

For those foods, you must capture Key Data Elements at Critical Tracking Events: receiving, transformation, shipping, and so on. You need a written traceability plan describing how you keep these records and assign traceability lot codes. Records must be kept for two years. And when the FDA asks, you must produce the relevant records as an electronic sortable spreadsheet within 24 hours.

Federal enforcement begins July 20, 2028. But if you sell into major retail, your effective deadline is whatever your customer's supplier program says, and several of those programs are already active with chargebacks attached.

Notice what the rule does not say: buy software. The requirement is about data completeness, linkage, and speed of retrieval. Format is your choice. That's why the honest answer to the spreadsheet question depends entirely on whether your spreadsheets can deliver those three things.

FSMA 204 Spreadsheet Breakpoint
FSMA 204 transformation lot linkage
FSMA 204-24 hour assembly test

When spreadsheets genuinely work

A spreadsheet-based approach is defensible when most of the following are true.

You handle a small number of FTL items, roughly a dozen SKUs or fewer. You distribute or hold product but don't transform it, meaning no combining lots, no repacking into new lot codes, no manufacturing. Your volume is modest enough that a week's receiving and shipping fits on a screen. One or two trained people own the records, and they'd have time to assemble a response if the FDA called.

A small specialty distributor moving whole produce with supplier lot codes intact can meet the rule this way. Plenty will. If that's your operation, the right move is a well-designed workbook with locked columns, consistent lot code formats, and a quarterly dry run, not a software purchase.

FSMA 204 volume turnover

Where spreadsheets break

The breakpoint arrives from four directions, and any one of them is enough.

Transformation. The moment you combine input lots into an output lot, repack, or manufacture, you must link every incoming traceability lot code to every outgoing one. In a spreadsheet, that linkage is a human remembering to type the right codes in the right rows during a production shift. One mislinked lot doesn't just create one bad record. It breaks the chain for every downstream shipment of that output lot, and nobody discovers it until a trace request fails. Transformation is where spreadsheet compliance quietly dies, and it's why manufacturers hit the wall long before distributors do.

The 24-hour assembly test. The FDA doesn't ask for your spreadsheet. It asks for a sortable electronic file covering specific products, lots, and date ranges. If your records live across a receiving log, a production sheet, and a shipping file, someone has to filter, join, and clean them into one coherent response inside a day. Run this as a drill once and you'll know immediately whether your setup passes. Most multi-file setups take two or three days the first time, which is a failing grade delivered politely.

Volume and turnover. Spreadsheet discipline is a person, not a system. At higher transaction counts, or when the person who built the workbook leaves, error rates climb invisibly. There's no validation stopping a truncated lot code or a date typed in the wrong format, and every one of those is a future dead end in a trace.

Retailer requirements stacked on top. Walmart and other major retailers require traceability data transmitted electronically with shipments, through ASNs with GS1 identifiers. A spreadsheet can hold that data but can't transmit it. If retail mandates are in your customer mix, the spreadsheet question is already answered for you.

The false choice: spreadsheets or a traceability platform

Here's the part the vendor content skips. The alternative to spreadsheets is not necessarily a dedicated traceability platform with a per-case fee.

Most midsize operations already own systems that capture most of the required data: an ERP with lot tracking, a WMS, scale and label systems. The typical gap isn't missing software. It's that the data sits in three places, with inconsistent lot code formats and no way to produce a unified, sortable response quickly. The pattern is the same one that stalls AI pilots and month-end closes: disconnected data, not absent data. We've written about that pattern in the context of AI readiness, and traceability is often where it bites first.

For many companies, the right-sized fix is connecting what they already own: consistent lot capture at receiving, transformation linkage recorded in the ERP rather than on paper, and a reporting layer that can produce the FDA's sortable format on demand from all sources at once. That's a smaller project than a platform migration, and it also retires the spreadsheet risk permanently instead of managing it.

A test you can run this week

Pick one lot you shipped last month. Give yourself four hours, not 24, since a real request won't arrive on a quiet day. Try to produce a single sortable file showing where that lot came from, what it went into if you transform, and everywhere it went, with dates, quantities, and trading partners.

If you succeed, your spreadsheets are doing their job. Document the procedure and rerun it quarterly.

If you can't, you've learned the answer to this post's question for your specific operation, with two years of runway to fix it calmly instead of during an outbreak investigation.

Talk to an engineer

(Article)

(Article)

Platsera FAQ

What kind of companies does Platsera work with?

We have outgrown our current software. What is the first step?

Do you only advise, or do you actually build?

How large a project do we have to commit to?

Can you work with the systems we already have?

How do we get started?

How is this different from a normal marketing agency?

Do we have to start with the diagnostic?

Who owns the ad accounts and the data?

Why a six month minimum?

How quickly will we see results?

Can you actually connect to our POS or booking system?

Platsera FAQ

What kind of companies does Platsera work with?

We have outgrown our current software. What is the first step?

Do you only advise, or do you actually build?

How large a project do we have to commit to?

Can you work with the systems we already have?

How do we get started?

How is this different from a normal marketing agency?

Do we have to start with the diagnostic?

Who owns the ad accounts and the data?

Why a six month minimum?

How quickly will we see results?

Can you actually connect to our POS or booking system?

Platsera FAQ

What kind of companies does Platsera work with?

We have outgrown our current software. What is the first step?

Do you only advise, or do you actually build?

How large a project do we have to commit to?

Can you work with the systems we already have?

How do we get started?

How is this different from a normal marketing agency?

Do we have to start with the diagnostic?

Who owns the ad accounts and the data?

Why a six month minimum?

How quickly will we see results?

Can you actually connect to our POS or booking system?