A VP of Supply-Chain Traceability running an enterprise Sunrise 2027 programme office sits in an unusual position: everyone downstream is waiting on you, and most of the pressure you feel is pointed the wrong way. Retailers will refresh lanes; converters will print whatever the artwork says; co-packers will apply what the spec sheet specifies. None of them can decide what the mark is — because every decision that matters about the 2D transition attaches to GTIN ownership, and the GTIN is yours.

Three parties, one decision-maker

Place each Sunrise-relevant choice on the boundary where it is actually made:

DecisionGTIN owner (you)Converter / co-packerRetailer
Which symbology carries the markDecidesExecutes in prepressReads what arrives
Element strings or Digital Link URIDecidesEncodes as specifiedParses both, chooses neither
Which AIs travel (lot, expiry, serial)DecidesPrints what the line can variably markTolerates their presence
Lane readiness by December 2027Decides (their capital, GS1's programme)
Where the scans the mark enables get recordedOpen — this is the one your plan has not made

The table is the whole political argument for why this lands on the programme office. A retailer's questionnaire can ask about your timeline; a converter can quote plate costs; only the brand can commit a symbology, a syntax, and a data payload — and those commitments are made in artwork, which means the real decision window is your artwork cycle, not GS1's calendar. Miss a cycle and the decision defers a full revision round, whatever December 2027 is doing.

Choice 1: symbology — what the lane needs vs. what a phone reads

The two candidate symbologies do different jobs and the difference is disqualifying if confused. GS1 DataMatrix clears the retail lane and is the pharma-lineage symbology; it is not reliably decoded by native phone camera apps. QR is the symbology a consumer's phone camera reliably decodes. If the mark must do only the checkout job, DataMatrix is a clean choice; if the same square is ever to be the brand's line to the person holding the unit, QR carrying a Digital Link URI is the only path that keeps the option open. Any vendor who says "DataMatrix or QR, consumers can scan either" has failed the cheapest test in the programme — the one-question vendor test is written up in the anchor family's read on GS1 Digital Link vs. a marketing QR code.

Choice 2: URI form — web-resolvable, or deliberately not

The same GTIN and AI data can be encoded two ways, and they are not interchangeable. As GS1 element strings (FNC1 syntax), the payload parses at any conformant lane and resolves to nothing in a browser — it is not a URI. As a GS1 Digital Link URI, the identical data is also a web address: the lane still extracts the GTIN, and a phone, a browser, or an agent can resolve it. Element strings foreclose the consumer touchpoint for the life of the artwork; the URI form keeps it open. Neither is "correct" — but the choice is yours, it is explicit, and if you do not make it in writing, your converter's prepress default makes it for you. (Scheme-level mechanics, including how the URI form carries AIs, are worked at barcoding.dev.)

Choice 3: which AIs travel

Sunrise's baseline expectation is GTIN extraction at POS — nothing more. Lot, expiry, and serial are additional AIs you may choose to encode, and the choice is consequential in both directions. Encoding lot and expiry is where item-instance data enters the physical world — the data your class-grain GDSN feeds structurally cannot carry, as the GDSN vs. EPCIS read lays out — and it is what makes downstream receiving, rotation, and recall scoping work at the grain FSMA 204 asks about. It also obligates your lines (and your co-mans' lines) to variable printing, which is a real capability question you specify and they execute — the executor's side of that relationship is documented in who owns the GTIN and barcode decision at a co-manufacturer.

The decision your programme plan still has not made

Symbology, syntax, AIs — most funded programme offices have those three either decided or scheduled. Here is the one the plan is quietly missing, and the table above flags it: the event layer. The new mark makes scans possible at every step your product takes — line, warehouse, DC, dock, lane, and, if you chose QR-with-URI, the consumer's hand. Where do those scans land? Not in GDSN, which is class-grain by design. Not in the retailer's transaction log, which is theirs and answers "what sold." Not in the resolver, which redirects and does not remember for you.

The event layer is where visibility.cloud sits: every scan captured as an event whose projection validates as conformant EPCIS 2.0 against the pinned official schema — no conformance attestation has ever been issued, and none is claimed — and each event carrying what the standard's five dimensions do not: who, the attested observer, held distinct from capturedBy, the warrantor account. A mark decision without an event-layer decision is a decade of richer scans with nowhere to put them. Decide both in the same programme cycle; the second decision is cheaper and the first is incomplete without it.

The full enterprise read — both clocks, the co-man network, and the programme office's sequencing — is the pillar: Sunrise 2027 for brand owners. How the regime split inside your own portfolio interacts with this record is the sibling brief: running two traceability regimes in one plant network.

Where this goes next

visibility.cloud provisions capture workspaces from the seat list, in order. The way in is the interview: email first, under a one-message promise, then a short branching sequence about your programme — artwork calendar, co-man share, event-layer status — ending in a written read for your situation. The final step locks.

Start the interview — it is questions, not a demo.