FSMA 204 does not cover your assortment. It covers foods on the FDA's Food Traceability List — and for a grocery Director of Food Safety running fresh, the practical question is never "what does the rule say," it is "how much of my perimeter is in scope, department by department." That is a half-day scoping exercise, most chains have never formally run it, and running it before any vendor conversation is the cheapest leverage you will ever have in this program.
The list, translated into your departments
The FDA's Food Traceability List is written in commodity language. Mapped onto a model grocery fresh operation, it lands like this:
| Department | Covered categories that bite there |
|---|---|
| Produce | Fresh leafy greens and fresh-cut leafy greens; fresh herbs; cucumbers; tomatoes; peppers; sprouts; melons; tropical tree fruits |
| Dairy case | Shell eggs; certain soft, semi-soft, and fresh soft cheeses |
| Seafood case | Fresh finfish; smoked finfish; crustaceans; molluscan shellfish — much of the case |
| Deli | Ready-to-eat deli salads |
| Grocery aisle | Nut butters |
| Prepared foods | Anything made in-store that contains a listed food as an ingredient |
Two scoping facts change the size of the answer more than the list itself:
- The ingredient rule pulls the kitchen in. A made-in-store salad built on romaine, a sandwich program using deli salad, a poke bowl on fresh tuna — prepared items that contain a listed food inherit the obligation. For a chain with a real prepared-foods program, the FTL reaches past the produce cooler into the kitchen, and the kitchen is where lot identity has historically gone to die.
- The list is versioned. FDA maintains it and can revise it. Scope to the current list, but build the record so adding a category later is a configuration change, not a new project.
What "covered" requires at your back door
For a covered food, receiving is a Critical Tracking Event, and the rule names the Key Data Elements you must keep and be able to produce in a sortable electronic form:
- the traceability lot code — the identifier that makes a lot-level withdrawal possible instead of a category-wide dump,
- the product identifier and description,
- the quantity and unit of measure,
- the location that shipped it and the location that received it,
- the date of receipt — and, where you transform a covered food, the transformation date and the new lot linkage.
Notice what the KDE set is: a receiving event, at lot grain, held electronically and sortably. That is not a binder requirement; it is a data-model requirement, and it lands hardest on the receiving path where your record is already thinnest — direct store delivery, where the receiver is a store associate the record has no field for. That failure mode is its own read: DSD is where your traceability record goes dark, with the back-door specifics in the DSD record at the back door.
The two-regime problem: one cooler, two records
Scoping produces an uncomfortable artifact: a walk-in cooler where covered and uncovered items sit on the same rack. Romaine is covered; iceberg's status differs; the cut-fruit program is covered via the melon rule; the whole apples next to it are not. Running two record-keeping disciplines against one cooler — lot-grain electronic KDEs for some SKUs, legacy invoice-grain paper for the rest — is operationally worse than running one, because your associates cannot be expected to know the regulatory status of each case they receive.
The sane architecture is one receiving record for everything at the dock, held at lot grain, with the FSMA-covered subset projected out as a view when a regulator or an auditor asks. One spine, two projections — the record does not fork; the view does. That is how visibility.cloud structures it: every receiving event is captured once, carries its lot, its locations, its date, its quantity, and its who — the attested observer at the door, distinct from capturedBy, the warrantor account — and the KDE table FDA would ask for is computed from the same catalog every other answer reads.
The date, in two sentences
The compliance date read that survives a search: the original January 20, 2026 date was proposed for extension to July 20, 2028 (Federal Register 2025-14967), the extension was never finalized as a rule — the 2028 date rests on the Continuing Appropriations Act of 2026 directing FDA not to enforce before then — and FDA is soliciting further flexibilities (Federal Register 2026-10603). Treat 2028 as the floor under an operating return, never the headline: the covered categories are your perimeter departments, the ones already generating the most shrink and the most investigations, and a lot-grain record with a witness pays there long before any enforcement date.
The scoping worksheet
Before any vendor conversation, answer these on paper:
- Which SKUs, by department, are on the current FTL — including prepared items via the ingredient rule?
- Which arrive DC and which arrive DSD? The DSD share is your risk concentration.
- For each covered supplier: what lot identifier travels with the case today, and where is it readable — case label, ASN, invoice, nowhere?
- Where would the KDE set physically get captured at each back door, and by whom?
- What is your current elapsed time to produce a sortable electronic receiving record for one named lot? (If the answer involves a store visit, write that down honestly.)
A chain that walks in with those five answers buys an outcome. A chain without them buys whatever the vendor is selling.
The full two-clock read for grocery — the lane under GS1's Sunrise 2027 programme and the dock under FSMA 204, in one capital cycle — is the pillar: Sunrise 2027 and FSMA 204 for grocery, with the covered-foods detail in the Food Traceability List read.
Where this goes next
visibility.cloud provisions capture workspaces from the seat list, in order. The way in is the interview: email first, under a one-message promise, then a short branching sequence about your fresh operation — DSD share, prepared program, supplier posture — ending in a written read for your situation. The final step locks.
→ Start the interview — it is questions, not a demo.