Drug Data and Databases
August 3, 2026
7 minutes

securPharm and FMD verification

securPharm is the German verification system under the EU Falsified Medicines Directive. Since 9 February 2019 prescription packs carry a unique identifier and an anti-tampering device, and pharmacies must verify and decommission each pack before dispensing. pharmazie.com is not a verification system, but it carries the article master data and legal-status flags per PZN behind every pack.

Table of contents
    TL;DR
    • securPharm is the German national system implementing Directive 2011/62/EU and Delegated Regulation (EU) 2016/161, applicable since 9 February 2019.
    • Two safety features are required on prescription packs: a unique identifier in a Data Matrix code and an anti-tampering device.
    • Germany runs a split architecture: ACS PharmaProtect holds the manufacturer-uploaded pack data, NGDA runs the pharmacy and wholesale side, both connected to the EMVO European Hub.
    • Manufacturers upload, wholesalers verify on a risk basis under Article 20, pharmacies verify and decommission at dispensing under Article 25.
    • An alert is a suspicion, not proof. securPharm reports handling errors and incompletely uploaded pack data as the most frequent causes; most alerts are false alerts.
    • pharmazie.com carries article master data and legal-status flags per PZN, but has no securPharm connection and cannot verify or decommission a pack.

    securPharm is the German national verification system for the EU Falsified Medicines Directive. Since 9 February 2019 it checks, at the point of dispensing, whether the unique identifier printed on a prescription pack is genuine and still active, and it decommissions that pack.

    securPharm is the German member of the European Medicines Verification System (EMVS). It is not a track-and-trace system: nobody follows a pack from step to step. It is an end-to-end verification system. The manufacturer writes a pack's identity into a database when the pack is released, and the pharmacy reads that identity back out and switches it off when the pack leaves the legal supply chain. Everything in between is deliberately not recorded. The legal basis is Directive 2011/62/EU, the Falsified Medicines Directive, and Commission Delegated Regulation (EU) 2016/161, which has applied since 9 February 2019.

    What exactly has to be verified, and by whom?

    The obligation attaches to packs that carry safety features, and in Germany that is essentially the prescription-only range. Two safety features are required: the unique identifier in a Data Matrix code, and an anti-tampering device, a seal or equivalent that makes opening visible. German law anchors both in § 10 Absatz 1c of the Arzneimittelgesetz (AMG), which requires safety features on the outer packaging wherever Article 54a of Directive 2001/83/EC prescribes them.

    Who does what is split by role. Manufacturers and marketing authorisation holders serialise and upload. Wholesalers verify on a risk basis, not on every pack: Article 20 of the Delegated Regulation requires verification of packs returned to them and of packs received from a wholesaler who is neither the manufacturer, nor the wholesaler holding the marketing authorisation, nor a wholesaler contractually designated by the marketing authorisation holder. Pharmacies, including hospital pharmacies, carry the decisive duty under Article 25: verify and decommission at the time of supplying to the public. For the scope question of which packs are prescription-only in the first place, see Verschreibungspflicht.

    How is securPharm structured, and who operates which database?

    This is the German specialty. Most national systems in Europe run one repository. Germany runs a split system with two operators, so that competitively sensitive pack data and pharmacy transaction data never sit in the same hands.

    LayerOperatorFunction
    Manufacturer / MAH sideACS PharmaProtect GmbHHolds the central pack-data repository. Pharmaceutical companies upload product code, serial number, batch and expiry here. Also runs the national Alert Management System (NAMS) for analysing failed verifications.
    Pharmacy and wholesale sideNGDA (Netzgesellschaft Deutscher Apotheker mbH)Operates the pharmacy server and the securPharm-GUI. Verifying parties connect through it; their queries reach the pack repository anonymised, so no operator can reconstruct which pharmacy dispensed what.
    European layerEMVO (European Medicines Verification Organisation)Operates the European Hub. Manufacturers upload once to the Hub, which routes the data to the national systems of the markets concerned. The Hub also carries cross-border queries and alert IDs.
    GovernancesecurPharm e. V.The German NMVO. Stakeholder association of manufacturers, wholesalers and pharmacies that owns the system and its rules.

    The practical consequence for a manufacturer is that onboarding happens at EMVO, via an onboarding partner, and the German data lands at ACS. The practical consequence for a pharmacy or hospital pharmacy is that its software talks to NGDA, and it sees alert status in the NGDA interface.

    How does an FMD verification work, step by step?

    1. The manufacturer serialises each pack, prints the unique identifier as a Data Matrix code plus human-readable text, and uploads the pack data through the European Hub into the German repository.
    2. The pack moves into distribution. Wholesalers verify only in the risk-based cases of Article 20; a normal pass-through from manufacturer to wholesaler to pharmacy triggers no verification.
    3. At dispensing, the pharmacy scans the Data Matrix. The pharmacy system sends an anonymised query via NGDA to the repository.
    4. The system compares the scanned product code and serial number against the stored record and answers whether the identifier is active and consistent with batch and expiry.
    5. If the answer is positive, the pharmacy decommissions the pack, the identifier is set inactive, and the pack may be handed over.
    6. If the identifier is unknown, already decommissioned, or inconsistent, no positive answer is returned, an alert is raised, and the pack must not be supplied to the public until the case is resolved.

    Response times are measured in milliseconds. In operating year 2021 securPharm processed more than 2.03 billion transactions, averaging 39 million verification transactions per week from pharmacies and wholesalers, with peaks up to 51 million, at 99.99 percent average availability.

    What does an alert actually mean?

    An alert is a suspicion, not a verdict. Every failed verification and every failed decommissioning raises one, and in practice most alerts are technical or handling problems, not falsification. securPharm's own status report names the most frequent causes as handling errors and incompletely uploaded pack data, and describes the absolute number of alerts as still too high, most of them false alerts. Wrongly configured scanners, an active caps lock, double decommissioning, and pre-2019 stock carrying a Data Matrix code that was never uploaded all produce the same alert as a genuine falsification would.

    The German handling rule follows from that. Where the responsible pharmaceutical company uses the ACS Alert Management System, it has seven calendar days to analyse and qualify the case. If it identifies its own handling error, the case is classified as a false alert and is not reportable. If it does not, or if the seven days lapse without feedback, the alert is escalated to a suspected falsification case and the reporting duties bite. On the pharmacy side, § 21 Absatz 6 of the Apothekenbetriebsordnung (ApBetrO) is the anchor: where an error message under Article 11 of Delegated Regulation (EU) 2016/161 raises a falsification suspicion, the pharmacy manager informs the competent authority once the investigation under Article 37(d) has failed to dispel the suspicion. BfArM coordinates confirmed cases with the Paul-Ehrlich-Institut.

    How does verification relate to the pack data itself?

    Keep two things apart. The data on the pack is coding; the check against the repository is verification. The unique identifier's five data elements, the product code with its GTIN, NTIN or PPN variants, the serial number, the national reimbursement number, the batch and the expiry, are covered separately under GTIN, and the German national number inside them under PZN. securPharm is the act performed on those data, plus the repositories that make the act possible.

    The batch and expiry keys matter beyond verification. They are the same keys a Chargenrückruf addresses. A recall names a batch; the FMD repository knows batch per serial number, which is why authorities value the audit trails securPharm can produce. The two systems are legally separate, though: a recall does not run through securPharm, and a securPharm alert is not a recall.

    What pharmazie.com carries on this topic, per pack:

    • Field: article master data and legal-status flags, including prescription status and distribution status, the base-data section and the legal-information section of the article record
    • Granularity: per PZN
    • Source: ABDA article master data via ABDATA Pharma-Daten-Service, plus IFA for the PZN itself
    • Updated: in the delivery rhythm of the licensed source, with a visible date stamp on the record
    • Access: web app, REST API and data export, see REST API

    The honest limitation: pharmazie.com is not a verification system and has no connection to securPharm. It cannot tell you whether a specific serial number is active, it cannot decommission a pack, and it will never answer an alert. It answers the neighbouring question instead, what this PZN is, whether it is prescription-only, whether it is still in distribution, so that the pack in front of you can be identified and its status understood. For the verification itself you need your pharmacy or ERP system's securPharm connection through NGDA.

    Sources

    Author Image
    Ursula Tschorn
    Ursula Tschorn is CEO of DACON Datenbank Consulting GmbH and has been building pharmaceutical information infrastructure since 1989. She writes on drug data standards, pricing regulation and market access in the DACH region.

    FAQ

    What is securPharm and how does FMD verification work?
    Which two databases does securPharm use, and who operates them?
    Since when is FMD verification mandatory in Germany?
    What does a securPharm alert mean, and is it always a falsification?
    Do wholesalers have to verify every pack?
    Does pharmazie.com connect to securPharm?

    Other terms

    Since 1989, over 1,000 customers have placed their trust in our data.

    The most comprehensive drug database for pharma professionals.