Once you know what a Shortage Prevention Plan is, the next question is almost always the same: what does it actually need to contain, section by section? There's no binding official template yet, but a consistent structure has emerged from EMA and MSSG guidance and from how auditors actually read these documents. Here it is, built to be usable per product and to scale across a portfolio.
1. Product identification
The header block that ties everything together: product name, active substance, marketing authorisation number(s) and Member States covered, and — critically — whether the product appears on the Union List of Critical Medicines. This single field determines how much of the rest of the template actually applies; see our explainer on the Union List if you're not sure how a product qualifies.
2. Supply chain map
Per product: the API supplier and site, the finished-dose manufacturing site, and any secondary or backup sources currently qualified. This is the section auditors check first, and the one most often found incomplete — not because the data doesn't exist, but because it's scattered across quality dossiers instead of consolidated here.
3. Vulnerability assessment
A scored risk assessment, not a narrative paragraph. At minimum: number of qualified alternative suppliers, regional concentration, and time-to-validate for a backup source. Score it, don't just flag it — a binary "at risk / not at risk" loses the prioritisation information you need later.
4. Rolling forecast
A forward view of expected demand and supply availability, typically covering 3 to 6 months, updated on a fixed cadence rather than ad hoc. State the forecast horizon and the last update date directly in the document — an undated forecast is functionally useless to an auditor.
5. Diversification strategy
Concrete, dated steps to reduce dependency where the vulnerability assessment flags a problem: qualifying a second supplier, validating an alternative manufacturing site, or building buffer stock. Each action needs an owner and a target date — a strategy without both reads as an intention, not a plan.
6. Early-warning triggers and escalation
The specific signals that would move this product from "prevention" into "mitigation" — a supplier reporting a production issue, a forecast gap crossing a defined threshold — and exactly who gets notified when one fires. This section is the hinge between your SPP and your Shortage Mitigation Plan; keep the trigger definitions identical across both documents so there's no ambiguity about which plan is active.
7. Governance
Review cadence (who re-approves this document, and how often), version history, and named ownership — not a department, a person with a named backup. This is the section that turns a document into something with an audit trail, rather than a snapshot nobody's obligated to revisit.
8. Supporting evidence
An appendix of the underlying evidence: supplier qualification records, correspondence referenced in the vulnerability assessment, prior forecast versions. Keep this as references and links rather than copy-pasted content — duplicated data is the fastest way for an SPP to go stale without anyone noticing.
A note on scaling this across a portfolio
The template above is written per product, which works fine for a handful of critical items. The moment your portfolio grows past that, the real challenge shifts from "what goes in each section" to "how do I keep dozens of these current without duplicating the same supplier and forecast data by hand in every document." That's a structural problem, not a template problem — worth solving with a shared register before it becomes unmanageable.
Frequently asked questions
Is there an official SPP template from the EMA or the Commission?
Not yet in binding form. The CMA's formal text, including any implementing acts that might prescribe a specific SPP format, hasn't been adopted. The structure above reflects the direction set by EMA and MSSG guidance rather than a mandated template.
How long should a Shortage Prevention Plan be?
Long enough to be complete, short enough that someone actually reads it during an audit. A well-structured SPP for a single product is typically a few pages of substance plus supporting data tables — bulk usually signals unstructured content rather than thoroughness.