The first question manufacturers ask about traceability is almost always: “Where do we print the labels, and how long does it take?” Fair question, wrong order. The QR label is only the display surface of a data system; if there is nothing behind it, what the company has bought is a link, not traceability capability.
The confusion is not harmless. The amended Law on Product and Goods Quality No. 78/2025/QH15 (passed 18 June 2025, effective 1 January 2026) has written traceability requirements into law. Decree No. 37/2026/NĐ-CP, issued 23 January 2026, sets out the goods categories subject to mandatory traceability — agricultural produce among them — and imposes the obligation to register a connection to the National Product and Goods Traceability Portal from 1 July 2026; by 1 January 2027, priority categories (food, agricultural produce, pharmaceuticals…) must have full traceability. A business with labels but no structured data and no connection to the national portal is still at the starting line.
The label is an interface, not a system
Two things are routinely conflated and need separating. A label is a carrier for a code; it can be printed in an afternoon. A traceability system is the body of data describing a product’s journey, together with the rules for recording, storing and sharing that data — it has to be designed, and most of the work sits in internal processes rather than in software. Three quick tests for any solution being pitched:
- What does the code on the label identify? A product line, a batch, or an individual unit? Three answers, three different systems.
- Who records the data behind it, and when? At the moment the event happens, or backfilled at month-end to complete the file?
- Beyond the company itself, who can verify that data? If the answer is “no one”, this is a QR-fronted brochure page, not traceability.


The four layers of a compliant traceability system
Set aside each vendor’s proprietary vocabulary and every serious traceability system has the same four stacked layers; when a lower layer fails, the layers above it are meaningless.
Layer 1 — Identification: naming the object
Traceability begins with naming the object unambiguously. The GS1 international numbering and barcoding system draws the distinctions clearly:
- GTIN identifies a product type — “green tea bags, 100g box”; every box of that type shares one GTIN.
- The batch/lot code divides a product type into production runs. This is the real unit of recall: when something goes wrong, goods are recalled by batch.
- The serial number identifies each individual unit, and is only needed when one box must be told apart from another — anti-counterfeiting, warranty, one-time activation.
The most common mistake at this layer is treating a shortened link auto-generated by the software as a “traceability code”. A link is an address, not an identifier: change vendor or let the domain lapse and every “code” already printed on the packaging turns to waste. A standards-based identifier is independent of where the data is stored.
Layer 2 — Events: recording what happened
A product’s journey is a chain of discrete events: harvest, raw-material intake, preliminary processing, sampling for testing, packing, warehousing, transport, distribution. Each event must answer four questions:
- What — the identifiers of the objects involved: which input batch went in, which finished batch came out.
- When — a timestamp with a time zone, not “June”.
- Where — a location identifier: growing area, workshop, warehouse; not free-text names.
- Which step — the stage within the declared process.
The event most often left out is the transformation event: the point where several input batches become a single output batch. Without recording the relationship “batch A + batch B produced batch X”, a complaint about batch X cannot be traced back to the source growing area — the value of the traceability system evaporates at precisely the moment it is needed most.
Layer 3 — Data attached to events
Only on that event framework can concrete data be hung: growing-area code, variety, input logs, test reports, VietGAP/GlobalGAP certification, cold-chain transport temperatures, the supervisor on the production shift. The principle is short but hard: data must be created at the time and place the event occurs. A system that lets an entire file be backfilled at period end is, in substance, a document generator. That is why the hardest part of a traceability project is changing habits in the workshop and in the field.
Layer 4 — Interoperability with the national portal
The three layers above produce data; the fourth decides whether that data can leave the company’s boundary. Circular No. 02/2024/TT-BKHCN governs traceability management, the national traceability portal, and the data-structure and system requirements under TCVN standards. Decree No. 37/2026/NĐ-CP turns registering that connection into a deadline-bound obligation from 1 July 2026.
Why the data must follow the TCVN structure
Many owners see standardisation as administrative paperwork. It is in fact the precondition for data being able to join up. Within one chain, the cooperative records the harvest date as “15/6/26”, the factory records “2026-06-15”, and the exporter records “June 15, 2026”: to a system those are three different values. Multiply that divergence across dozens of fields — units of measure, location codes, process-step names, batch-coding rules — and the supply chain loses the ability to check itself.
A data standard, understood properly, is a contract: every party commits to recording the same fact in the same shape. The benefit surfaces in three situations: an importer asks for data in standard fields rather than scanned PDFs; a company changes software vendor without losing its history; a regulator or a partner needs to verify independently.
Closed systems and connected systems: the difference is who confirms
| Criterion | Closed system | System connected to the national portal |
|---|---|---|
| Where the QR scan leads | A page whose content the company controls itself | Standard structured data, verifiable from outside |
| Who confirms it | The seller | A registration layer and a connection to the national system |
| If the service stops | Dead link; the printed codes lose their value | Identifiers and standard data can still be migrated |
| For export | Low — it is self-declared documentation | Higher — there is a basis for independent verification |
Put plainly: if a QR label points back to the company’s own page, the buyer sees only what the company chooses to show — it may be entirely true, but it is self-declared. The value of connecting is not that the data is “better”, but that it sits inside a framework a third party can verify. For export goods, and for the categories that must have full traceability from 1 January 2027, that is the line between passing and failing.

Anti-counterfeiting: three different problems
“Anti-counterfeit label” is used so loosely that it misleads. There are at least three kinds of fraud, calling for three different lines of defence:
- Physical counterfeiting — copying the QR block. A plain printed code can be photographed and reprinted without limit; this is a problem of materials and printing technology.
- Data falsification — data that is technically genuine but entered fictitiously: the file looks immaculate, the site does not match the file. No label prevents this; only internal controls and independent inspection can.
- Relationship falsification — taking the code of a genuine batch and applying it to goods that do not belong to that batch. The most sophisticated, and the most widespread.
The clearest technical defence against the first two is serialisation combined with scan monitoring: each unit carries its own code, and the system records how many times and where it is scanned. A single code scanned thousands of times across many provinces within a few weeks is an anomaly that can be detected automatically — something labels mass-printed with one shared code cannot do. But anti-counterfeiting is only a supplementary layer: a perfectly copy-proof system whose underlying data is backfilled at month-end merely protects an untrustworthy file.
Who owns the data, and who may see what
This question is usually skipped until the contract has been signed. Traceability data should be divided into three rings of visibility:
- The public ring — what consumers see when they scan: origin, production date, expiry, certifications, main process steps. Enough to trust, no more.
- The business ring — what B2B partners, importers and inspection authorities see on request: test records, input logs, the chain of batch transformations.
- The internal ring — actual output volumes, supplier lists, consumption norms, shift efficiency. Competitive data, with no reason to sit in an outer ring.
The most frequent risk is a default configuration that pushes too much into the public ring — publishing the supplier list hands competitors a map of your sourcing. Alongside it, three clauses belong in any traceability software contract: the data is owned by the company; the full data set can be exported in a standard format at any time; and when the service ends, the data and the identifiers can still be migrated out.
Where Strace sits in this picture
Strace is a traceability platform developed by SPT (Saigon Postel), with its registration portal at txng.spt.vn. The architecturally notable point: the platform has been confirmed by the National Barcode Center (NBC) as officially connected to the National Product and Goods Traceability Portal — Confirmation Certificate No. 03/26/NBC-SPT dated 16 July 2026. The platform also runs a training and implementation-support programme (Strace Academy) and publishes documentation in Vietnamese, English and Chinese.
Placed in the four-layer model, the meaning of that certificate is very specific: it addresses layer 4 — interoperability with the national portal, the part a company finds hardest to build itself and also the part Decree No. 37/2026/NĐ-CP makes obligatory from 1 July 2026. That is a verifiable criterion, unlike generic marketing claims.
But the point must be made in full: no platform records layers 1, 2 and 3 on a company’s behalf. No software knows by itself which raw-material batch went into which production run, or logs the temperature inside a refrigerated truck unprompted. Software supplies the mould; the company pours real data into that mould every day, at the place where the event happens. Most of the implementation effort lies in process and people.
What to do before the legal deadlines
The clock is running: Law No. 78/2025/QH15 in effect from 1 January 2026; the obligation to register a connection under Decree No. 37/2026/NĐ-CP from 1 July 2026; full traceability for priority categories from 1 January 2027. The six steps below are best taken in order:
- Establish whether your product falls into a mandatory category under Decree No. 37/2026/NĐ-CP — agricultural produce is now formally covered.
- Fix the level of identification. By batch, or by individual unit? This decision drives operating cost and should not be reversed once packaging has been printed.
- Map the events as they actually happen — the real flow, not the process chart on the wall; mark every point of batch transformation.
- Review the data-capture points. For each event: who records it, on what device, and when. Any point that has to be backfilled later is a risk to resolve before buying software.
- Assess platforms on layer 4. Ask the vendor: is there a written confirmation of connection to the national portal, what is its number and issue date, and in what format is data exported?
- Settle the three data clauses above before signing.
Traceability is a data problem with a legal deadline. The label is merely where the data surfaces.
Times Zones takes part in this as an analysis and advisory unit for its member businesses: reading the legal framework correctly, mapping the event flow of a company’s supply chain, asking the right questions when dealing with platform vendors. We are not an agent or a distributor for any platform, Strace included; choosing a solution is the company’s own right and responsibility.
Businesses can look into this and register directly at the txng.spt.vn portal. For a compliance-roadmap review of a specific case, contact Times Zones at info@timeszones.space.