In 2024, the EU Safety Gate system logged a record 4,137 alerts for dangerous non-food products, the highest number since the system started in 2003, according to the European Commission's annual report. Cosmetics accounted for 36% of alerts, followed by toys at 15%, electrical appliances at 10%, motor vehicles at 9% and chemical products at 6%. A data problem underlies a large share of those alerts. Someone lost track of what a product contained, where a component came from, or which rule applied to it.
Product compliance software closes that gap. It keeps the substance data, supplier declarations, certificates and regulatory logic for a product in one place, and it checks that place against the rules before the product ships. This article covers what the software is, which regulations it tracks, how it works under the hood, and what to look for when you buy.
Key Takeaways
- Product compliance software centralizes substance data, supplier declarations, and certificates, then checks products against regulations like REACH, RoHS, and the coming Digital Product Passport.
- Most of the work is data work. The software is only as good as the material declarations and supplier data feeding it.
- The core engine maps your bill of materials to substance content, applies rules, flags violations, and keeps an audit trail.
- When choosing a tool, weigh regulation coverage, supplier data collection, integration with your existing systems, and how well it handles your own product structure.
What Product Compliance Software Is
Product compliance software is a system that tracks whether physical products meet the legal and market requirements for the places they are sold. It stores what a product is made of, collects proof from suppliers, applies the rules of each target market, and produces the documents that authorities, customers, and marketplaces ask for.
The scope is narrower than generic governance or corporate compliance tools. Those deal with data privacy, finance, or workplace policy. Product compliance software deals with the product itself: its substances, its safety, its labeling, and its paper trail from raw material to shelf.
It sits close to two other systems most manufacturers already run. One is the ERP, which holds procurement and bill of materials data. The other is the product information management (PIM) system, which holds descriptions, attributes, and channel data. Compliance data overlaps with both, and the cleanest setups treat it as one more managed data domain rather than a separate island.
The Regulations It Has To Track
The value of the software comes from the rules it encodes. A short tour of the main ones shows why manual tracking breaks down.
REACH is the EU chemicals regulation. It maintains a Candidate List of Substances of Very High Concern (SVHC). As of the February 2026 update the list held 253 entries, per Z2Data's tracking of the ECHA update, and the official version lives on the ECHA Candidate List table. If an article contains an SVHC above 0.1% by weight, the supplier has to communicate that down the chain, notify ECHA, and file a SCIP entry. The list grows about twice a year, so a product that was clean last quarter can carry a new obligation this quarter without changing at all.
RoHS restricts hazardous substances in electrical and electronic equipment. It covers ten substances: six heavy metals and flame retardants, plus four phthalates added later, as Nemko's RoHS guide lays out. The limit is 0.1% by weight for nine of them and 0.01% for cadmium. The catch is the measurement level.
RoHS limits apply per homogeneous material, not per finished product. A small amount of a restricted substance in one plating layer can make an entire product non-compliant.
That single rule is why RoHS work needs full material data rather than a top-level yes or no. It also feeds the CE marking directly, so a RoHS failure blocks EU market access for the whole device.
Other frameworks stack on top. Conflict minerals rules require you to trace tin, tantalum, tungsten, and gold back to smelters. California Proposition 65 sets its own warning duties. The General Product Safety Regulation (Regulation (EU) 2023/988) has applied since December 2024 and pushes traceability and recall duties onto anyone selling into the EU, online or offline.
Then there is the Digital Product Passport. It is set up under the Ecodesign for Sustainable Products Regulation (EU) 2024/1781, and the EU launched the central DPP Registry in July 2026. The first hard deadline lands on 18 February 2027 for certain large batteries, with textiles, steel, aluminium, tyres, furniture and other groups following through delegated acts across 2026 to 2030.
The DPP turns compliance from a set of documents you produce on request into structured, machine-readable data you must maintain continuously and publish through a shared registry.
That shift is the reason many companies are looking at compliance software now rather than later. A passport is not a PDF. It is a live data record tied to a unique product identifier, and it has to be assembled from the same substance and supplier data that REACH and RoHS already need.
How Product Compliance Software Works
Strip away the branding and most tools follow the same pipeline.
It starts with the product structure. The software imports your bill of materials from the ERP or PIM, down to the component and, where possible, the homogeneous material. Each level needs an owner, because a compliance statement about a finished product is really a rollup of statements about its parts.
Next comes substance data. Suppliers provide declarations. These arrive as full material declarations (FMD), as targeted statements like a RoHS certificate of conformity, or in standard formats such as IPC-1752A and IPC-1754. The software parses these, maps them to your parts, and stores the substance content against each material. This step is where the effort concentrates. Collecting, chasing, and validating supplier data is the hard, slow part of every compliance program.
Then the rules engine runs. It compares stored substance content against the thresholds of each regulation you care about, at the correct measurement level. It knows that cadmium is capped at 0.01% while lead sits at 0.1%, and that REACH thresholds apply at the article level while RoHS applies per homogeneous material. When content crosses a limit, the product is flagged.
Monitoring keeps the picture current. When ECHA adds substances to the Candidate List, the tool re-checks affected products and surfaces new obligations. Good systems alert the responsible person instead of waiting for the next manual review.
Reporting closes the loop. The software generates the declarations, certificates and passport records that customers, marketplaces and authorities request, and it keeps an audit trail showing who declared what, when, and on what evidence. That trail matters as much as the result. During an audit or a market surveillance check, being able to show the source of a compliance claim is often the difference between a fast clearance and a withdrawal.
What It Actually Does
Day-to-day, a product compliance tool carries out a defined set of jobs:
- Substance tracking.
Store what each material contains and map it to the SVHC, RoHS, and other restricted lists. - Supplier data collection.
Send declaration requests, capture responses, chase missing ones, and validate what comes back. - Rule checking.
Apply regulatory thresholds to the bill of materials at the right level and flag violations. - Change monitoring.
Re-assess products when regulations or lists update, and alert owners. - Documentation and reporting.
Produce declarations, certificates, technical files and DPP-ready records, with a full audit trail.
The weight sits on the first two. A rules engine is only as reliable as the substance and supplier data underneath it. Vendors compete hardest on how much of that data they supply themselves, how well they collect the rest, and how cleanly it maps to your products.
Where Product Data And Compliance Data Meet
Compliance data does not live alone. The same component that carries an SVHC declaration also carries a price, a supplier, a weight, a set of images, and a shelf description. Splitting that record across a compliance tool, an ERP, and a PIM creates the exact gaps that lead to Safety Gate alerts.
Our customers often come to us after that split has already caused pain. A manufacturer keeps product attributes in a PIM, substance declarations in a shared drive, and supplier certificates in email threads. When a new SVHC lands, no one can answer which finished products are affected without a week of cross-referencing spreadsheets. The data existed. It was just scattered, and no system connected a substance to the products that contained it.
One fix is to treat compliance as another data domain inside a flexible platform rather than a bolt-on. AtroPIM, built on the AtroCore platform, lets a team model its own entities: products, components, materials, substances, suppliers and the declarations that link them. Because the data model is configurable rather than fixed, a substance record can relate to every part and every finished product that uses it. When a list changes, the affected products are a query, not a manual hunt.
The platform side matters as much as the PIM side. AtroCore includes an import, export, and synchronization layer, so supplier declarations, ERP bills of materials, and channel data move through one system instead of separate middleware. Workflows move a declaration through request, receipt, review, and approval without anyone sending reminders. Comments and assignments stay on the record. None of this replaces a specialist regulatory data feed, but it gives that feed a clean home and connects it to the rest of the product record.
The cheapest compliance failure to fix is the one you catch as a data gap before the product ships, not the one an authority catches on the market.
How To Choose The Right Product Compliance Software
Selection is less about feature lists and more about fit with your products, your suppliers, and your existing systems. A few criteria separate tools that help from tools that add work.
Start with regulation coverage that matches your actual markets and product types. A furniture maker and a medical device maker face different rules, and a tool tuned for electronics may under-serve chemicals or textiles. Confirm the specific frameworks, the update cadence, and whether new substances trigger automatic re-assessment.
Look hard at supplier data collection, because this is where programs stall. Ask how the tool requests declarations, which standard formats it reads, how it handles non-responsive suppliers, and how much substance data the vendor provides out of the box versus what you must gather yourself.
Check the data model against your own product structure. Some tools assume a simple product-to-substance link. Real products nest: finished good, sub-assembly, component, material. If the tool cannot represent your structure, you will bend your data to fit its shape, and accuracy suffers.
Treat integration as a requirement, not a nice-to-have. Compliance data has to flow from your ERP and PIM and back out to customers and marketplaces. A tool with a documented API and real import and export options will cost you far less over time than one that traps data behind a closed interface.
Weigh the deployment and licensing model against your constraints. Open-source and self-hosted options give control over data and cost. Software-as-a-service reduces setup. Regulated industries often have data residency rules that decide this for you.
Judge the audit trail and reporting output early. You are buying evidence as much as answers. The tool should show the source and date of every compliance claim and produce the exact documents your customers and authorities ask for, including structured records for the Digital Product Passport.
Use this shortlist when you compare vendors:
- Coverage.
Do the encoded regulations match your markets, and how fast are lists updated? - Supplier data.
How much is supplied, how much collected, and in which formats? - Data model. Can it represent your real product hierarchy down to homogeneous material?
- Integration.
Is there a documented API and clean import and export with your ERP and PIM? - Deployment.
Cloud, self-hosted or open-source, and does it meet your data residency rules? - Evidence.
Does it keep a defensible audit trail and produce the documents and passport records you need?
One practical test cuts through most sales demos. Take a single real finished product, hand the vendor its bill of materials and a few messy supplier declarations, and ask them to show a full REACH and RoHS assessment with the source of each claim. The tools that handle your data as it actually arrives, rather than as a clean sample, are the ones worth trialing further. Buy for the state of your data today, and for the DPP obligations already dated in the regulation, not for a tidy version of either.