Skip to content

Compliance

FDA Food Contact Material: Compliance Guide

In 2023, the FDA issued warning letters to multiple manufacturers of food contact articles — including a major manufacturer of reusable plastic food containers — for failing to provide adequate documentation that their food contact substances were approved for their intended use. The common thread in all the letters: the companies had test data showing their products were safe, but they could not produce a properly structured Declaration of Compliance that mapped each substance in the material to its regulatory clearance. The FDA's position was unambiguous: data without a properly structured declaration is not compliance documentation.

Under the Federal Food, Drug, and Cosmetic Act (FFDCA) and 21 CFR Parts 170–199, any material intended to contact food during manufacturing, packaging, storage, or preparation must be approved by the FDA or be Generally Recognized as Safe (GRAS). The manufacturer or supplier issues a Declaration of Compliance (DoC) — a self-declared document that certifies the material meets FDA regulatory requirements. On the Sustalium platform, food-contact declarations are one of the most cross-referenced document types we see: a food packaging supplier issues a Declaration of Compliance to its downstream customer, who must then present it to their own buyer or retailer audit.

Selling Food Online in the US: The Rules You Need

You have a recipe people love. You want to turn it into a product. Maybe it is candy, hot sauce, granola, or frozen meals. The part most first-time food entrepreneurs underestimate is not the recipe — it is everything that happens after the recipe is finalized. Commercial production, food safety regulation, packaging compliance, labeling, shelf-life testing, and distribution.

This guide walks through the end-to-end process of launching a food product in the United States, with the compliance obligations woven in at the stage where they actually apply — not as a separate document you deal with later.

On the Sustalium platform, the compliance document most first-time food entrepreneurs are missing is not the FDA registration or the food safety plan — it is the Declaration of Compliance for their packaging. They have the food safety documentation. They do not have the food contact material compliance. And when a retailer or Amazon asks for it, the gap stops the launch.

Not sure which regulations apply to your food product? Use the Sustalium Global Compliance Map — select your product category and target country, and see every regulatory framework that applies, from FDA food safety to state-level packaging rules.

SMETA Audit Guide: Sedex Social Compliance

Sedex reports over 75,000 members across 180 countries, with more than 340,000 SMETA audits conducted globally. The most common non-compliance findings — working hours, wages below the legal minimum, and inadequate health and safety controls — appear consistently across the textile, electronics, and agriculture sectors. Under the UK Modern Slavery Act, brands like Marks & Spencer, Tesco, Unilever, and Primark explicitly cite SMETA audit programs in their public modern slavery statements, and the EU's CSDDD now extends similar due diligence obligations across the entire bloc. For a supplier, a lapsed or missing SMETA report increasingly means automated deselection from buyer procurement systems — often before a human reviewer ever sees the application.

SMETA (Sedex Members Ethical Trade Audit) is the most widely used social compliance audit methodology in the world. It assesses working conditions across labor standards, health and safety, environmental management, and business ethics. For suppliers in apparel, textiles, electronics, furniture, and FMCG, a current SMETA audit report is often the price of admission to the Western buyer market. On the Sustalium platform, we see the same buyer who requests a CE Declaration of Conformity now routinely asking for the most recent social audit — because procurement teams are being measured on supply chain risk, not just product compliance.

US vs. EU Food Contact: One Product, Two Frameworks

A food packaging product sold in both the United States and the European Union must satisfy two separate food contact regulatory regimes — and neither accepts the other's documentation. The FDA Declaration of Compliance cites 21 CFR regulations and Food Contact Notifications. The EU Declaration of Compliance cites Regulation (EC) 1935/2004 and material-specific measures like the Plastics Regulation (EU) 10/2011. The migration testing is similar but the test conditions, simulants, and limits differ. And a Declaration of Compliance valid in one market is not valid in the other.

This guide compares the two systems, identifies the key operational differences, and explains how to build dual-market food contact compliance without duplicating every test.

French Duty of Vigilance: LdV Supply Chain Law

Since the French Duty of Vigilance Law came into force in 2017, NGOs and affected communities have filed multiple high-profile lawsuits — against TotalEnergies over its Tilenga oil project in Uganda and Tanzania, against EDF over a wind farm affecting indigenous communities in Mexico, and against BNP Paribas over fossil fuel financing. In 2023 alone, four new LdV cases were filed in French courts. None resulted in an operational suspension order, but each forced the defendant company to publicly disclose and — in some cases — substantially revise its vigilance plan. The law is no longer a dormant obligation. It is being actively litigated.

The French Duty of Vigilance Law (Loi de Vigilance — LdV, Law No. 2017-399) was the first mandatory human rights and environmental due diligence law in Europe. It requires large French companies to establish, publish, and implement a vigilance plan covering their own operations, those of their subsidiaries, and those of their suppliers and subcontractors. On the Sustalium platform, we now hear from French procurement teams asking suppliers to provide structured ESG and supply chain data specifically to feed into the parent company's vigilance plan — and if a supplier cannot produce the data, they get replaced.

US Apparel Compliance: Flammability, Labeling & Rules

Apparel compliance in the United States is deceptively fragmented. The federal requirements are relatively minimal — a flammability standard, a fiber content label, and a country of origin marking. But state-level obligations — California's Proposition 65, the emerging NY Fashion Act, PFAS restrictions across multiple states, and packaging heavy metal rules — add layers of compliance that many apparel importers discover only at the point of enforcement.

This guide maps every US compliance requirement for apparel and textiles, from the federal baseline through the state-level obligations that increasingly define market access.

ISO 27001 Certification: ISMS & Buyer Sharing

As of the ISO Survey 2023, there were 71,549 valid ISO 27001 certificates across 175 countries — making it the second most adopted ISO management system standard after ISO 9001. In a 2024 Vanta survey, 78% of companies reported that ISO 27001 certification directly helped them close deals faster. The transition from ISO 27001:2013 to ISO 27001:2022 completed in October 2025, and any organization still holding a certificate against the 2013 version must now recertify against the updated standard. The market message is unambiguous: in B2B procurement, ISO 27001 has become less a security posture indicator and more a market access prerequisite.

ISO 27001 is the international standard for Information Security Management Systems (ISMS). For B2B companies — SaaS platforms, IT service providers, cloud infrastructure companies, and any organization handling client data — it is the single most requested compliance credential in vendor assessments. On the Sustalium platform, we see the real bottleneck is rarely the technical controls themselves — it is the inability to produce the certificate, Statement of Applicability, and audit reports in a single verifiable package when procurement asks for them.

US Toys: CPC, ASTM F963 & State Requirements

Toys are the most heavily regulated consumer product category in the United States — and the compliance path is fundamentally different from general consumer goods. The key difference is that toys require a Children's Product Certificate (CPC) , not the General Certificate of Conformity (GCC) that covers adult products. The CPC demands third-party testing at a CPSC-accepted laboratory, additional chemical restrictions beyond what applies to general consumer goods, and specific labeling requirements — including a tracking label on every product.

This guide covers every compliance requirement for toys sold in the US, from federal testing standards to state-level chemical warnings, and compares the US framework to the EU Toy Safety Directive for brands selling in both markets.

EU MDR Class I Device Compliance Guide

In 2024, the European Commission acknowledged that only 45 Notified Bodies had been designated under the MDR — down from roughly 80 under the previous Medical Device Directive. The resulting bottleneck has delayed recertification across all device classes, and several EU Member States have reported that up to 20% of Class I manufacturers had not fully transitioned their technical documentation from MDD to MDR format during spot checks. A non-sterile Class I device may not need a Notified Body, but that self-declaration must still be built on the new regulation's structure — and outdated documentation is treated the same as no documentation during a competent authority audit.

Under the EU Medical Device Regulation (MDR — Regulation [EU] 2017/745), all medical devices placed on the European market require a Declaration of Conformity. Class I devices are the lowest-risk category but the documentation burden is far from trivial. On the Sustalium platform, the area where we see Class I manufacturers submit incomplete documentation most frequently is the new clinical evaluation and post-market surveillance requirements — obligations that simply did not exist under MDD.

Selling Cosmetics in the US and EU: MoCRA vs. CPSR

A cosmetic brand selling in both the United States and the European Union must comply with two regulatory frameworks that are structurally similar but operationally distinct — and neither framework accepts the other's documentation. The US system, modernized in 2022 by MoCRA, emphasizes manufacturer self-declaration of safety. The EU system, established under the Cosmetic Products Regulation (EC) 1223/2009, requires a qualified safety assessor to prepare a formal Cosmetic Product Safety Report (CPSR) and mandates notification to the EU's Cosmetic Product Notification Portal (CPNP) before the product reaches the market.

For brands selling in both markets, the compliance cost is additive — you need both a MoCRA safety substantiation and an EU CPSR. But the ingredient data and toxicological assessments that support one can inform the other, and building both in parallel from the same product data is significantly more efficient than treating them as separate compliance projects.