Method·August 2, 2026 · 3 min read

GUDID stores the model. Not the box.

A Unique Device Identifier splits by rule into a fixed device identifier and a variable production identifier. FDA's public device database keeps only the first — the fact capable of naming which specific unit shipped was never asked to be part of the record.

By Connor Griggs — Regulatory & Quality Strategist

Pull a Global Unique Device Identification Database record for a subscriber’s own catalog number and it reads like a finished answer: labeler, brand, model, GMDN term, the FDA product code, the premarket submission that cleared it. It is finished — for exactly one of the two facts a Unique Device Identifier is built to carry. The other fact was kept out of the record on purpose, and knowing which is which is the difference between confirming a device and confirming a box.

What a UDI is actually built from

FDA’s own definitions, at 21 CFR 801.3, split a Unique Device Identifier into two parts that behave nothing alike. The device identifier (DI) is, in the regulation’s own words, “a mandatory, fixed portion of a UDI that identifies the specific version or model of a device and the labeler of that device.” The production identifier (PI) is “a conditional, variable portion” that can carry a lot or batch number, a serial number, an expiration date, a manufacture date, or — for an HCT/P regulated as a device — a distinct identification code. One half of a UDI answers which catalog number, whose label. The other half answers which specific unit, made when, expiring when, part of which run. They are not two versions of the same fact, filed twice for redundancy. They are two different questions FDA decided a single identifier should be able to answer, and only one of them is the kind of fact a national database can hold still.

What actually reaches the public database

The Global Unique Device Identification Database stores the first half only. A DI record in GUDID — searchable through AccessGUDID, the public interface FDA and the National Library of Medicine maintain — carries the labeler’s name, the brand and model, the GMDN term and code, MRI safety status, the premarket submission number, and the FDA product code the device is filed under: a genuinely rich record, at exactly one level of the device. Production identifiers are never submitted as values at all. What GUDID stores instead is a set of PI flags — yes-or-no markers for whether a lot number, a serial number, an expiration date, or a manufacture date appears on that device’s own label, never the number itself. The record tells a reader that a lot number exists on the label. It does not, and structurally cannot, tell a reader which lot.

A DI record answers what this device is and who is responsible for it. It was never asked to answer whether this is the unit that failed — that fact belongs to the half of the UDI the public database doesn’t hold.

Why the missing half is usually the one in front of you

A device recall’s code-information field, or a MAUDE narrative describing a specific failure, routinely cites exactly the kind of fact GUDID was built to exclude: a lot number, a serial range, a date of manufacture. Pulling the matching DI record confirms the model — yes, this catalog number is one a subscriber’s portfolio actually includes. It cannot confirm the unit. Answering whether this is a subscriber’s own box requires the labeler’s own distribution records, matched against the PI printed on a label GUDID never received a copy of. The gap is not a search technique that needs refining, and it is not a data-quality problem some future submission will fix. It is the shape FDA built the database in, on purpose, at the level FDA decided a national public registry should operate.

The practice

Read a GUDID or AccessGUDID hit as confirmation at the model level, never the unit level, and stop there deliberately rather than by accident. FDA Radar’s own matcher runs on five join bases today — product code, CFR regulation, application number, firm, and manufacturing partner — and none of them is a UDI; per what we monitor and how often, GUDID isn’t behind any of the four feeds those bases run against in the first place. Whether a specific lot or serial number named in a recall or an adverse-event report belongs to a subscriber’s own inventory is a question only that subscriber’s own shipping and quality records can answer. This is a description of what one public database was built to hold and what it was built to leave out — regulatory intelligence and method, never a determination about any device’s own unit history.

Regulatory intelligence, not regulatory advice. This post describes method and published FDA records as of its date; decisions about a specific device belong with your regulatory professional.

Practice
Emergency use isn't defined in Part 812
Method
The two-year inspection clock is gone
Method
The PMA clock starts at the last module
Practice
The Q-Sub that doesn't buy you more time
Method
Lapsed and revoked end an EUA differently
Practice
A recall strategy has a grade. openFDA doesn't.
Method
A granted De Novo becomes a predicate.
Practice
Least burdensome changes the ask, not the bar.
Method
The lab is accredited. Not the device.
Practice
Breakthrough is law. STeP is a guidance.
Practice
MDSAP replaces routine. Not for-cause.
Method
No field on a 510(k) says what it treats
Method
Discretion is a policy. Exclusion is a statute.
Practice
Designated by one office. Approved by another.
Method
MedSun sits beside MAUDE, not inside it
Practice
The five-unit device never gets a K-number
Practice
Meeting the criteria isn't a tracking order
Method
The PMA clock doesn't stop at approval
Practice
The K-number doesn't track today's device
Method
A MAUDE report proves it was filed
Practice
Not every MDR starts with the manufacturer
Method
Completed. Not terminated.
Practice
The device-ban list has three entries
Method
The UDI exception has its own deadline
Method
MDUFA VI is being negotiated in public
Practice
The inspection manual changed, not the rule
Method
The count Congress had to legislate
Practice
The small-business rate isn't retroactive
Method
A detention order has no docket to read
Practice
PMA approvals moved off the Federal Register
Method
A citizen petition names names
Practice
A market withdrawal isn't a recall
Method
Not every device letter comes from CDRH
Practice
Closed on one device. Open on the rest.
Method
No IDE is confirmed until the PMA is
Practice
The remedial-action call sets the clock
Method
Jurisdiction is a letter, not a field
Practice
An address is not a footprint
Method
The final rule that isn't final yet
Practice
The special controls aren't in the record
Method
Exempt from GMP. Not from complaints.
Practice
The notify list isn't the shortage list
Method
A constraint can't be skipped. A script can.
Practice
No cron sends this. A person does.
Method
Corrected, not rewritten
Practice
Quiet is a finding, not a default
Method
The summary is public. The statement isn't.
Practice
A competitor's 513(g) leaves no trace
Practice
An empty response field proves nothing
Method
A petition is public. Its outcome isn't.
Practice
The panel is a category, not a meeting
Method
An accessory carries its own classification
Method
A TPLC report is a category, not a device
Practice
A 522 order is a question, not a verdict
Method
A PCCP change leaves no new record
Practice
Not every signal becomes a recall
Method
eSTAR did not remove the acceptance check
Practice
An early alert has no recall number yet
Practice
A consent decree isn't a database row
Method
The record has no cybersecurity field
Practice
Classification Change is not one event
Method
Publication date is not effective date
Method
One event. Many recall numbers.
Practice
Quantity is a sentence, not a number
Practice
How a firm told you is a field too
Method
A RIN outlives the document number
Method
The docket ID is not the comments
Practice
The 510(k) record doesn't name the predicate
Practice
The 510(k) FDA didn't review first
Method
The letter FDA doesn't have to post
Practice
Cleared doesn't say which track it took
Method
The clock stops. The calendar doesn't.
Method
Why a guessed match never reaches you
Practice
The standards list never names a device
Method
The guidance isn't in the Federal Register.
Practice
Filtered. Not discarded.
Method
There are two recall databases, not one
Practice
Breakthrough status is confidential by law
Practice
One MAUDE report is not one malfunction
Method
A supplement number is not a track
Method
Cleared is not approved
Practice
Nationwide doesn't mean your building
Practice
Not every correction reaches FDA
Method
Registered. Not reviewed.
Method
Contact ODE is not a pathway
Practice
Almost no recall is FDA-mandated
Method
FDA's device names read like a card catalog
Practice
openFDA is free. It is not unlimited.
Practice
Detention doesn't need a warning letter
Method
A Class I device, a Class I recall
Practice
21 CFR 820 didn't move. Its contents did.
Method
The product code that doesn't exist yet
Practice
The classification posts. The 483 behind it doesn't.
Method
A recall has three dates, and the pipeline had to pick one
Practice
The count is real. The rate is not.
Method
The firm on the record is not the firm on the box
Practice
Low confidence is an instruction, not a hedge
Method
The same company, spelled three ways
Practice
A device that was never a medical device
Method
FDA's warning letters, addressed by column number
Practice
Your regulation has a decimal. FDA's watch doesn't.
Method
Three letters is too short to search for
Practice
Most warning letters never close
Method
The guidance that skipped the draft
Practice
Ongoing, as of when?
Method
The least interesting fact in a 510(k)
Practice
No recall arrives with a product code attached
Practice
The deadline that doesn't email you
Method
The warning letter has two dates
Method
How to monitor FDA without drowning
Practice
Your predicate was recalled. Now what?
Method
Why no item reaches you without a human