Regulatory and Compliance
July 27, 2026
10 minutes

SmPC Compliance and Lifecycle Management: A Guide

SmPC compliance means keeping every authorised product text accurate and traceable in every market. It covers variations under Regulation (EC) No 1234/2008, the chain from company core data sheet to reference safety information to national SmPC, referral-driven safety changes, and knowing which SmPC version legally governs which market at any moment.

Blog Image
Table of contents
    Summary
    • Every SmPC change is a variation under Regulation (EC) No 1234/2008, amended by Regulation (EU) 2024/1701; the revised Variations Guidelines apply from 15 January 2026.
    • Type IA variations are implemented before notification, so temporary mismatches between internal and published texts are expected, not errors.
    • The CCDS to RSI to local SmPC chain is where most divergence arises; the compliance risk is undocumented divergence, not divergence itself.
    • Referrals under Article 31 of Directive 2001/83/EC and Article 20 of Regulation (EC) No 726/2004 force coordinated label changes across every product containing a substance.
    • ePI uses the EU Common Standard on HL7 FHIR and remains voluntary: vaccines (ATC J07) in Q3 2026, oncology and immunomodulators (ATC L01 and L04) in Q4 2026.
    • General language models are unreliable on drug information; a 2023 Long Island University study found roughly three quarters of answers incomplete or wrong.
    • The real operational problem is version governance: knowing which SmPC version is in force in which market, which requires product information held as data.

    SmPC compliance is the discipline of keeping every authorised text for a product accurate, current and traceable across every market where it is marketed. In practice this means managing variations under Regulation (EC) No 1234/2008, controlling the chain from company core data sheet to reference safety information to national SmPC, absorbing safety-driven label changes from referral procedures, and knowing at any moment which SmPC version legally governs which market.

    Most published material on this subject explains what an SmPC is and stops there. That is a useful starting point, and if you need the definitional groundwork, the sections, the legal basis, the difference between an SmPC and a package leaflet, read our companion piece on what an SmPC is first. This article assumes you already know all of that and are responsible for the harder problem: the same molecule authorised in eleven countries, with eleven texts that are similar but not identical, each on its own revision clock.

    We maintain product information as structured data across 50+ countries, so this is written from the vantage point of the people who have to reconcile those texts every day, not from the vantage point of a regulatory textbook.

    Why SmPC compliance is a data problem, not a document problem

    The SmPC stops being a document the moment a product exists in more than one market. A single centrally authorised medicine carries one Annex I in 24 languages. A nationally authorised or mutually recognised portfolio carries genuinely different texts: different indications approved at different times, different excipient warnings, different pack sizes, different local pharmacovigilance addresses in section 4.4 or 6, and different revision dates in section 10.

    Companies routinely manage this in document systems, which are excellent at version control for one file and poor at answering questions across files. The operationally important questions are all cross-file:

    • Which markets already carry the new contraindication, and which are still pending?
    • Which SmPC version is the one a medical information officer should be quoting for a query from Poland today?
    • Where does our local text diverge from the company core data sheet, and is each divergence deliberate and documented?
    • Which of our texts were changed by a regulator-driven procedure rather than by us?

    None of these are answerable by opening a PDF. They are answerable only if product information is held as data with market, version, date and section as queryable attributes.

    How SmPC changes are actually made: the variations framework

    Every change to an authorised SmPC is a variation, governed by Commission Regulation (EC) No 1234/2008. That regulation was substantially amended by Commission Regulation (EU) 2024/1701 of 11 March 2024, which entered into force on 7 July 2024 and applied from 1 January 2025. The accompanying revised Variations Guidelines apply from 15 January 2026, and the European Medicines Agency has published guidance on the application of the revised variations framework covering the transition, including the rule that Type IB and Type II variations submitted from 15 January 2026 follow the new guidelines while earlier submissions run to completion under the old ones.

    The classification matters operationally because it determines when the text on the market actually changes, which is rarely the same date as the approval.

    Variation categoryNature of changeProcedural logicWhat it means for the live SmPC
    Type IAMinor, no impact on quality, safety or efficacyDo and tell: implement first, notify within 12 monthsText can change before the authority has processed it, so the internal record leads the regulator record
    Type IA INMinor, immediate notification requiredImplement, notify immediatelySame as IA but with a shorter notification window, common for administrative and manufacturing details
    Type IBMinor, but not IA and not majorTell and wait: notify, then wait the review period before implementingA defined gap between submission and lawful use of the new text
    Type IIMajor, may affect quality, safety or efficacyPrior approval requiredNew indications, new contraindications, significant section 4.4 or 4.8 changes; often triggers leaflet and labelling rework
    Line extensionNew strength, form or routeFull application annex procedureUsually produces a new SmPC rather than an edit to an existing one
    Worksharing / groupingOne change across several authorisationsSingle procedure, multiple productsThe main lever for keeping a multi-market portfolio aligned rather than drifting

    The practical trap is the Type IA category. Because it is implemented before it is notified, teams that reconcile their internal library against the regulator's published text will find legitimate mismatches. If your tracking system treats every mismatch as an error, it will generate noise until people stop reading the alerts.

    The CCDS to RSI to local SmPC chain

    Multinational companies do not write each national SmPC from scratch. They maintain a company core data sheet (CCDS), an internally owned document that states the company position on safety, indications, dosing and other core content. The safety subset of the CCDS is the company core safety information. From that, the reference safety information (RSI) is derived: the list of expected adverse reactions used to assess expectedness in periodic safety reporting and in development safety update reports. National SmPCs are then the authorised, market-specific expressions of that core.

    LayerOwnerLegal statusTypical change triggerFailure mode
    CCDSCompany (global regulatory and safety)Internal governance document, not authorisedNew signal, new study data, portfolio decisionUpdated but never cascaded into local variation filings
    RSICompany (pharmacovigilance)Internal reference for expectedness assessmentCCDS safety update, PSUR outcomeVersion used for coding does not match the version in force during the reporting period
    Local SmPCMarketing authorisation holder, approved by the competent authorityLegally binding text in that marketApproved variation, referral outcome, national requirementDivergence from CCDS that nobody recorded as a deliberate local deviation

    Divergence between these layers is not automatically a compliance failure. Some of it is unavoidable: a national authority may refuse wording the company proposed, or may impose additional wording, or the local text may lag simply because the variation is still under review. What turns acceptable divergence into a finding is the absence of a controlled record explaining why each difference exists and when it is expected to close. Inspectors ask that question. Document systems answer it badly; a data model with a per-market delta view answers it well.

    Safety-driven label changes and how referrals cascade

    Not all SmPC changes originate with the company. Referral procedures allow regulators to force a coordinated change across every product containing a substance or class. The mechanisms most likely to hit a portfolio are:

    • Article 31 of Directive 2001/83/EC, a referral in the interest of the Union, typically triggered by safety concerns affecting a substance class across multiple authorisations.
    • Article 20 of Regulation (EC) No 726/2004, the equivalent route for centrally authorised medicines.
    • Article 107i of Directive 2001/83/EC, the urgent Union procedure for pharmacovigilance issues requiring fast action.
    • Article 13 and Article 29 procedures, which resolve disagreement between member states in mutual recognition and decentralised procedures.

    The EMA publishes the full set of active and concluded procedures on its referral procedures pages. The operational consequence of a referral is that a single Commission decision propagates into dozens or hundreds of national SmPCs, each of which then has its own implementation deadline and its own translated wording. Generic manufacturers feel this hardest: an originator-driven referral outcome obliges every generic holder of the same substance to file matching changes, on a clock set by someone else.

    This is precisely the scenario where document-centric tracking fails. The question "have all 43 of our authorisations for this substance implemented the referral wording, and in which of them is it already visible in the published text" is a data query, not a filing task.

    ePI: what is actually happening and what is not

    Electronic product information (ePI) is the move from SmPC as a formatted document to SmPC as structured, machine-readable content. The EU has adopted the EU ePI Common Standard, based on HL7 FHIR, and the EMA maintains the initiative through the Product Lifecycle Management Portal following a pilot that ran from July 2023 to August 2024 with Denmark, the Netherlands, Spain and Sweden.

    On 20 March 2026 the EMA published a draft roadmap to coordinate delivery of ePI across the regulatory network and to align with the requirements of the new pharmaceutical legislation. The shape of the rollout is phased and, critically, voluntary at this stage:

    • Vaccines (ATC group J07) enter voluntary ePI submission in Q3 2026.
    • Oncology and immunomodulating products (ATC groups L01 and L04) follow in Q4 2026.
    • Remaining centrally authorised products move into the voluntary phase after that.
    • ePI becomes mandatory for newly authorised medicines only once the revised EU pharmaceutical legislation enters into application.

    ePI is not mandatory in 2026. During the voluntary phase, applicants author and upload ePI through the portal as an additional step alongside the existing Word and PDF submissions, which means the near-term effect for regulatory teams is more work, not less. The payoff arrives later, and only for companies that treat ePI as a genuine content model rather than as an export format bolted onto the end of a document workflow. Current status and documentation sit on the EMA's electronic product information pages.

    AI and SmPC content: the honest version

    General-purpose language models are not a reliable source of drug information. The best-known evidence is a Long Island University study, first presented at the American Society of Health-System Pharmacists Midyear Clinical Meeting in December 2023 and subsequently published in the British Journal of Clinical Pharmacology in 2024. Researchers put 39 real medication questions, drawn from the university's own drug information service, to the free version of ChatGPT. Pharmacist review judged only 10 of the 39 answers satisfactory, meaning 29 of them, or 74 percent, were not. The citation behaviour is the more instructive finding: references were requested for every question but supplied with only 8 answers, and every one of those 8 contained fabricated references.

    That result is not an argument against AI in regulatory work. It is an argument about architecture. A model generating text from general training data will produce fluent, plausible, unverifiable statements. A system that retrieves the actual authorised text and answers only from it behaves differently, because every answer can be traced back to a specific section of a specific SmPC version.

    This distinction is the first thing regulatory professionals raise when we demonstrate AI features. One put the condition plainly:

    AI-generated answers are usable only on condition that the source is document-grade and that the source is actually there. (Manager at a pharmaceutical manufacturer, translated from German)

    That is the design constraint our ChatSmPC® and ChatPIL® features are built around: the query runs against full SmPC and package leaflet texts held in the platform, and the answer points back to the source text rather than paraphrasing from a general model. It does not remove the need for human review, and no serious team should let it. It removes the need to open fourteen PDFs to establish whether a warning exists in a given market.

    The real operational problem: which version governs which market

    Ask a regulatory affairs team what actually consumes their time and the answer is rarely the drafting. It is reconciliation: establishing, at a given moment and for a given market, which text is in force. That question sits behind medical information responses, promotional material approval, artwork sign-off, pharmacovigilance expectedness assessment, tender documentation and due diligence.

    Making it answerable requires a few things that document management alone does not provide:

    1. Market as a first-class attribute. Every text carries its country, authorisation route and authorisation number, so a portfolio view is a filter rather than a folder crawl.
    2. Section-level comparison. Differences are meaningful at the level of section 4.3 or 4.8, not at the level of the file.
    3. Revision dates as data. Section 10 of the SmPC states the date of revision. Held as a date field rather than as a line of prose, it turns "is this current" into a query.
    4. A published-text baseline. Comparison against what the authority actually publishes, not only against your own last approved draft, catches implementation gaps and regulator-side corrections.
    5. Cross-border coverage. For companies operating beyond one region, the comparison has to reach every market where the product is placed, otherwise the blind spots are exactly where the risk concentrates.

    This is where consolidated product information data earns its keep. pharmazie.com holds 25+ databases in one search layer, covering 50,000+ German products and 120,000+ international products across 50+ countries, and DACON GmbH has been maintaining pharmaceutical reference data since 1989. For cross-market and cross-layer questions about which text applies where, that consolidated view is the most complete single answer available to regulatory and pharmacovigilance teams working across DACH and internationally. It does not replace your regulatory information management system, which owns your submissions and your internal history. It answers the complementary question that RIM systems typically cannot: what does the authorised text look like right now, everywhere, including for products that are not yours.

    A practical control set for SmPC lifecycle management

    If you are building or repairing an SmPC compliance process, the following controls address the failure modes described above:

    • Maintain a single register of every authorisation with market, procedure type, current SmPC version and date of revision.
    • Record every deviation from the CCDS as a deliberate entry with a reason and an expected closure, so that unexplained divergence is visible by exception.
    • Track referral procedures affecting your substances from the moment they open, not from the moment the decision lands, so implementation planning starts early.
    • Version-control the RSI explicitly against reporting periods, so expectedness assessments can always name the version that applied.
    • Reconcile your internal text against published authority text on a defined cycle, and treat Type IA timing gaps as expected rather than as findings.
    • Treat ePI preparation as a content structuring exercise now, while it is voluntary, rather than as a submission format problem later.

    None of this is exotic. It is ordinary discipline applied to content that most organisations still treat as documents when it has long since become data.

    This content is intended for healthcare professionals and does not constitute medical advice. Last reviewed: July 2026.

    Author Image
    Ursula Tschorn
    Ursula Tschorn is CEO of DACON Datenbank Consulting GmbH and has been building pharmaceutical information infrastructure since 1989. She writes on drug data standards, pricing regulation and market access in the DACH region.

    FAQ

    What is SmPC compliance?
    Is electronic product information (ePI) mandatory in the EU?
    What are Type IA, IB and II variations?
    How do referral procedures change the SmPC?
    What is the difference between CCDS, RSI and the SmPC?
    Can AI tools be trusted for SmPC and drug information questions?
    Since 1989, over 1,000 customers have placed their trust in our data.

    The most comprehensive drug database for pharma professionals.