Blog

Compliance Is a Floor, Not a Comprehensive Anticounterfeiting Strategy

August 05, 2026

Ask any pharmaceutical brand team about protecting their products from counterfeiting, and chances are, the conversation centers around compliance. “We meet DSCSA.” “We serialize.” “We're aligned with the EU Falsified Medicines Directive (FMD). Our deadlines are met.” What many miss, however, is that every word of that can be true--and their brand can still be exposed because compliance and protection are not the same thing. In fact, the gap between them is exactly where today's most sophisticated counterfeits live.

This isn't a semantic quibble. It's the difference between treating brand protection as a box to check and treating it as a multifaceted risk to manage. And in 2026, that difference is quickly becoming a liability question as well.

What compliance was designed to do—and what it wasn't

The U.S. Drug Supply Chain Security Act and the EU FMD were built to create a baseline: a uniform, enforceable floor of traceability across the supply chain. That's genuinely valuable. A floor means no legitimate participant operates below a known standard, and it gives regulators a framework for accountability. The DSCSA's phased rollout (for manufacturers and repackagers from May 2025, wholesale distributors from August 2025, large dispensers from November 2025, and the smallest dispensers by November 2026) was an enormous, coordinated effort to raise that floor across an entire industry.

But a regulatory floor is, by design, a minimum. It's calibrated to what every participant can reasonably be held to, not to what might be required to defeat a determined, well-resourced adversary. Regulations were never written to out-innovate organized counterfeiters in real time; that's not what they're for. Over time, counterfeiters have learned to satisfy the regulations' requirements — in this case, by copying valid, overt identifiers on packaging, reproducing compliant barcodes, and cloning legitimate serial numbers. And once that happened, meeting the minimum with 100% compliance was no longer sufficient to stop them.

This isn't a criticism of regulators or brand protection teams. A standard that applies to thousands of companies of wildly different sizes must be achievable by all of them, which means it's pegged to broad feasibility, not to the frontier of what's technically possible. That's the right way to write a mandate, but it often guarantees, structurally, that the mandate will trail the most capable and well-funded attackers. Compliance defines the conduct everyone must meet. It was never meant to define the ceiling of what the most sophisticated counterfeiters are capable of (an ever-moving target) or what a well-resourced brand, protecting a high-value product, must do to protect their company’s reputation, revenues, and customers.

The floor isn't the ceiling. Here’s proof.

This is not an abstract threat—especially in our digital-first, GenAI-enabled world. Consider the December 2025 counterfeit Ozempic product that the FDA seized from the legitimate U.S. supply chain. These counterfeits carried a genuine lot number and were identifiable only by slight misplacements of text on the label. That product existed inside a fully serialized, DSCSA-governed environment. Compliance was present, but protection was not. The fake satisfied the regulatory floor and reached the legitimate supply chain.

We’ve also seen this occur in oncology products. The falsified IMFINZI cancer therapy product flagged by the World Health Organization in 2024 and 2025 carried genuine lot numbers—real identifiers AstraZeneca had assigned for authorized distribution in particular markets—which counterfeiters reused on falsified product that surfaced in other markets. These fakes were distinguishable only by subtle packaging discrepancies that could easily have been missed (and once counterfeiters tweak their packaging to address these visual discrepancies, their fakes may be truly visually indistinguishable, even to trained brand inspectors.)

Different drug, different regions, both products bearing the same lesson for brand teams: meeting compliance requirements is not the same as being protected with reliable package authentication, because what’s mandated to appear on a box or label can be cloned or copied at scale.

It’s time to reframe brand protection as a liability function

With regulatory compliance now the floor, and sophisticated counterfeiters able to clear it routinely, it’s time to move beyond treating compliance as the risk-management ceiling. And brands don’t have to anymore, thanks to new, digital, packaging-level authentication. Documented, commercially available, peer-adopted digital packaging authentication technology is now available to pharmaceutical brands—and it’s drawing a clear line between those that opt to "meet the minimum" and "deploy some of the best protection available to us."  

This becomes especially important after a patient-harm event. A brand that goes beyond the floor is better positioned to protect its reputation, revenues, and customers than one that relied on the minimum and was penetrated. This is the same protective practices have evolved in other domains: once a better safeguard is available and affordable, choosing the minimum can stop looking like prudence and start looking like an avoidable limitation. History shows us—for example, with the emergence and eventual mandating of seatbelts and smoke alarms—that the direction practices move as new, high-impact technologies that raise the bar emerge.

What does "above the floor" actually look like?

Going beyond minimum compliance doesn't mean abandoning it or bolting on something exotic. It can be achieved by running a layered model in which each layer manages a risk that others might not, for example:

  • Serialization stays exactly where it is, providing regulatory compliance and chain traceability.  
  • Overt features like holograms and color-shifting inks handle fast, no-equipment, first-pass checks by pharmacists and even patients.  
  • Covert, digital authentication technology that’s embedded in the artwork and designed to handle field and channel verification, a further line of defense against the copy-the-credentials fakes that can clear the serialization check and visual inspection checks.  
  • Complex, costly, forensic-level markers such as DNA-based molecular markers, proprietary chemical taggants, and spectroscopic signatures.  

Each layer defends against a different attack vector. But it’s the “above the floor” covert layer that is designed specifically to close the counterfeit product gap the floor—serialization and overt features—can leave open.

Viewed from this perspective, adding an "above the floor" covert security layer to packaging is not disruptive or requiring that you replace compliance investments in any way. Doing so simply addresses the threat that compliance was never designed to stop.  

Are you ready to move beyond compliance?

The strongest brand-protection teams have stopped treating regulatory compliance as the destination. They’re treating it as the floor it was always meant to be, and they are building above it by adding covert, copy-resistant authentication at the packaging level, managed with the same rigor the organization applies to financial controls and legal compliance. Because compliance may keep you legal, but it doesn't, by itself, keep your brand, your revenues, or your customers protected.  

This is a far less daunting proposition than it might sound because Digimarc has created the technology for you. We invite you to learn more about what "above the floor" actually looks like, and how to get there, by reading our new white paper, The Detection Gap: How Pharma Brand Protection Quietly Became a Liability Question. 

 

Please contact us for additional information about Digimarc products.

 

Sources: DSCSA phased enforcement timeline (manufacturers/repackagers May 2025; wholesale distributors August 2025; large dispensers November 2025; small dispensers November 2026) and EU FMD framework. FDA Drug Safety Communication, December 2025 (counterfeit Ozempic in the legitimate U.S. supply chain, genuine lot number). WHO Medical Product Alerts N°3/2025 and N°5/2024 with August 2025 update (falsified IMFINZI bearing genuine lot numbers). The evolving-standard-of-care discussion is presented as a direction of travel and an analogy to how safeguards become expected once proven and available, not as a statement of existing pharmaceutical case law.

You May Also Like

Learn more
Insider Risk: Types, Costs, and Your Risk Profile
Blog

Insider Risk: Types, Costs, and Your Risk Profile

Learn more
Analog Hole Blog post image
Blog

The Analog Hole: How Screen Capture Bypasses DLP & Encryption

leadership-team