Skip to main content
Stokka

Batch traceability

Food traceability for SMBs: FDA 204 explained (without the panic)

The FDA Food Traceability Rule (21 CFR Part 204) sets new record-keeping obligations for manufacturers of foods on the Food Traceability List. Here is a practical read for small manufacturers: what it requires, who it touches, and what you actually have to do.

20 April 20269 min read

The US FDA's Food Traceability Rule, codified at 21 CFR Part 204 and issued under the Food Safety Modernization Act (FSMA), sets new record-keeping obligations for anyone who manufactures, packs, ships or receives foods on the Food Traceability List (FTL). It is one of the most significant traceability regulations in a generation, and for small manufacturers it can feel daunting. It doesn't have to.

What the rule actually requires

The core requirement is that firms who handle FTL foods maintain and provide, within 24 hours of request, a set of Key Data Elements (KDEs) tied to specific Critical Tracking Events (CTEs): growing, receiving, creating, transforming, and shipping.

In practice that means, for each batch of FTL food you handle:

  • Traceability batch codes assigned and recorded.
  • KDEs captured at every CTE the batch passes through.
  • Records held for two years.
  • A sortable electronic spreadsheet deliverable within 24 hours of an FDA request.

Is your product on the list?

The FTL is specific. It includes categories such as certain cheeses, shell eggs, nut butters, cucumbers, leafy greens, tomatoes, melons, tropical tree fruits, herbs, sprouts, finfish, crustaceans, mollusks, and ready-to-eat salads. The authoritative list lives on the FDA website and is periodically updated.

If you make a product with an FTL ingredient, your finished good inherits the obligation even if the finished good itself is not on the list.

The five events and their data

  1. Growing, where the food was grown. Usually captured at source.
  2. Receiving, when you take it in. KDEs include the traceability batch code, quantity, UOM, sender reference, and the date received.
  3. Creating, when a new batch is made from non-FTL inputs (or from inputs outside the scope). KDEs include the new traceability batch code, quantity, date of creation, and location.
  4. Transforming, when a new batch is made from existing traceable inputs. This is the most interesting event for manufacturers: the output batch must reference every input batch consumed.
  5. Shipping, when it leaves your door. KDEs include the traceability batch code, quantity shipped, shipping date, recipient, and the reference (PO or similar).

Every event needs a Traceability Batch Code Source: essentially, where the batch code was originally assigned. This is the bit that catches small manufacturers out: a batch code is not just a number, it is a number with an origin.

What this means for small manufacturers

Three practical consequences:

  • Paper is out. The rule explicitly requires a sortable electronic format. A 24-hour request with a shoebox of paperwork is a problem.
  • End-to-end linkage is in. Every transformation event must link input batches to the output batch. Your production records have to carry this at the batch level, not just at the run level.
  • Records persist for two years. Archiving and retrieval become part of the workflow.

The minimum defensible system

For a small manufacturer making covered foods, a compliant traceability system needs to capture, at minimum:

  1. Inbound batch receipts with supplier, supplier batch, internal batch code, quantity, UOM, and date.
  2. Production runs that consume specific inbound batches (with quantities) and produce a specific output batch (with a quantity).
  3. Shipments that reference which output batch was sent to which customer, with quantity and date.
  4. A sortable export (Excel, CSV) of all of the above, filterable by batch and by date range.

That is the spine. Everything else the rule expects. CoAs, QA records, allergen controls, lives around it.

The 24-hour response bar

An FDA request for a traceability batch code should be answerable from your system in minutes. The 24-hour deadline is a regulatory ceiling; in operational practice, you want it to be a one-screen lookup. See multi-batch recall in under 60 seconds for how that actually works.

Common mistakes small manufacturers make

  • Treating traceability as a month-end exercise. KDEs have to be captured at the event. Reconstruction is not compliance.
  • Re-using batch codes. The rule assumes unique, non-repeating codes.
  • Capturing only one input batch per run. If a run consumed two batches of an ingredient, both have to land on the output batch record.
  • Keeping records only in the heads of long-serving staff. A sortable electronic format is explicitly required.

How Stokka maps to FDA 204

Stokka captures inbound batches on goods-in (supplier batch, internal code, quantity, date), consumption of those batches on production runs (with quantities and timestamps), output batch assignment per finished batch, and shipment-to-batch linkage on the outbound side. CoA attachments on inbound batches come after launch. That genealogy is recorded in the product today. The one-screen forward and backward recall report is in the box at launch. Every report is exportable as CSV.

That is the spine of a compliant system. Stokka is not a regulatory product, you still need your own SOPs, QA documentation, and a named person responsible for traceability, but the data model and the response-time bar are built in.

Further reading

Start with our batch tracking playbookfor the operational discipline, and read the FDA's own final rule text for the authoritative requirements. The compliance date for the rule sits in 2026, it is not something to defer.

Keep reading

Related posts