Why 73% of Teams Still Ship PPWR via Excel

The most-quoted statistic in PPWR market research — that roughly seventy-three per cent of European packaging manufacturers manage compliance through spreadsheets — is not a surprise. It is a workflow choice that once made sense and has since ossified. What is interesting is not the headline number but the four organisational patterns underneath it, and the very specific moments at which each one breaks.

Between January and March 2026 we audited twelve manufacturers ranging from fifty SKUs to eight hundred, distributed across Germany, Spain, France, and the Netherlands. The patterns below are disguised composites; the breakage points are exactly as observed.

73%of teams
ship PPWR compliance through a workflow that depends on a single Excel file, a shared inbox, or a single analyst.

The stat behind the stat

When a manufacturer says they “use Excel for compliance,” they almost never mean a single spreadsheet. They mean a network: a master file in SharePoint, an email folder for supplier attestations, a binder of signed PDFs, and at the centre of it one analyst who can navigate the network in under five minutes. The network is held together by that analyst's working memory.

This worked, often for years, because PPWR enforcement had not yet started, supplier requests were rare, and audits — when they happened — were narrow. None of those conditions remain true after August 12.

Pattern 1 — The cross-brand workbook

The setup. One master Excel file in SharePoint. SKU rows below; brand columns to the right (Brand A, Brand B, Brand C). Each brand owner edits their own column. The compliance lead “rolls up” weekly into a summary tab.

Why it worked. No new tool to procure. Everyone knows Excel. One file, one source of truth, one weekly rollup. Defensible to the CFO.

How it breaks. At roughly 120 SKUs the file hits performance issues. At 250 SKUs save-conflicts become weekly events. At 400 SKUs the file becomes “the version someone else has open.” When a regulator request lands and the file is locked by a brand owner who left two weeks ago, the audit does not fail because the data is missing. It fails because nobody can retrieve it.

Pattern 2 — Email-as-workflow

The setup. Supplier sends a PFAS attestation PDF to a shared compliance inbox. The inbox has rules: subject contains “PFAS” → folder. The folder has subfolders by year, by quarter, by supplier.

Why it worked. Email is universal. Suppliers do not need to learn a new tool. PDFs feel “audit-ready” because they are signed and dated.

How it breaks. Cross-cutting queries. When an auditor asks for “all PFAS attestations issued in 2025 for food-contact SKUs,” the folder system — which indexes by date and supplier, not by SKU — cannot answer in the four hours the auditor has allocated. In our audit set, the median time to retrieve a supplier-specific dossier from this pattern was forty-seven minutes.

Excel did not fail because the formulas broke. It failed because the analyst who knew where the data lived went on maternity leave in week six.
Carbonorm Q1 2026 audit set · n = 12

Pattern 3 — The compliance binder

The setup. A physical or PDF binder. Each SKU is a section. The section contains specification sheet, PCR certificate, PFAS attestation, supplier confirmation, and Declaration of Conformity.

Why it worked. Tactile, lawyer-friendly, each SKU feels complete on its own.

How it breaks. Updates. When PFAS regulation changes — and it did, with the 100 ppb floor formalised in October 2025 — every food-contact section needs revisiting. For a 380 SKU portfolio at five minutes per check, that is 31.6 hours of work that almost no team has bandwidth to perform. The binder remains, but it is silently stale, and the staleness is invisible until an auditor looks at the dossier date.

Pattern 4 — The unicorn analyst

The setup. One person — frequently a Martina-equivalent — knows where everything is. The Excel master file, the email folder, the binder, the shared drive, the three subcontractor data sources. She can answer any compliance question in five minutes.

Why it worked. She is genuinely good. She built the system, she maintains it, and it routes through her.

How it breaks. She goes on leave. She gets promoted. She leaves the company. The institutional knowledge walks out with her, and the replacement spends six to ten weeks reconstructing what she carried in working memory. If the audit hits during that window, the dossier does not exist in the heads of anyone still at the company.

The moment Excel actually breaks

Across the audit set, the failure was never “Excel formulas broke.” The breakage points were specific and repeatable.

  • Four of twelve: personnel change. The unicorn analyst was unavailable; the replacement could not navigate the network.
  • Three of twelve: save-conflict or file-lock. The master workbook was inaccessible at the moment a regulator request landed.
  • Three of twelve: search timeout. The supplier dossier existed but could not be retrieved within the auditor's window.
  • Two of twelve: regulation change made existing data stale; nobody had bandwidth to refresh, and the staleness was discovered by the auditor.

The four hooks that pull teams off Excel

The teams that successfully migrated to a structured compliance platform did not do so because they were sold on automation. They did it because one of four very specific hooks landed.

  1. The audit-failure hook. A real audit goes badly. Costs run from €18K (advisory remediation) to €200K (penalty plus reformulation). Pain becomes urgency. Migration follows within thirty days.
  2. The personnel-change hook. The unicorn analyst leaves or moves. The successor refuses to inherit “the system” and demands a structured replacement as a condition of taking the role.
  3. The regulator-request hook. An auditor asks for a specific dossier; the compliance team takes eight hours to compile a response that should have taken eight minutes. The decision to migrate is made within the meeting.
  4. The board-question hook. The CFO asks “what is our portfolio risk in numbers?” — and the answer does not fit in an Excel rollup. This is the cleanest hook because it lands pre-audit. In our customer base, roughly thirty per cent of migrations begin here.
Carbonorm · Q1 2026 customer migration data · n = 41
Average time-to-decision after a hook event: 17 days. Average time-to-portfolio-migration after decision: 23 days. Combined median: 40 days from triggering event to operational migration.

What you can do this week

If your compliance workflow matches any of the four patterns above — and most do, often more than one simultaneously — three actions for the next seven days are worth more than any platform evaluation.

  1. Run a Day-1 audit on your own portfolio. Pick any plausible auditor question — “show me the PFAS dossier for SKU X issued after October 2025” — and time yourself answering it. Anything over ten minutes is signal that the retrieval layer is broken.
  2. Identify your unicorn. If one person could leave tomorrow and take thirty per cent of institutional knowledge with them, that person is your single highest-risk point. Document what they know within thirty days, regardless of platform decisions.
  3. Map your data flow. Where does supplier data enter? Where does it get filed? How is it retrieved? Most audit failures in our set are retrieval failures, not collection failures. The data exists; it cannot be reached in the time available.
Run your own PPWR Check

See your portfolio against PPWR Article 6 — free, no demo booking.

Click through the eight-step product tour with mock data, then run the same flow on your real BoM. No credit card, data stays in Frankfurt.

Related

More from the PPWR programme

Deep-Dive12 min

PPWR Article 6 Without the Lobby Spin

Twenty-plus industry associations have published interpretive notes on Article 6. This piece walks the literal text, where RecyClass v2.4 fills the operational gap, and the three genuine grey areas — without the rhetorical spin.

Tracker7 min

Member-State Implementation Tracker — Q2 2026

Germany has published its inspection schedule. France hasn't. Spain is two months behind. Eight markets at a glance — enforcement dates, penalty ranges, pending acts, and what it means for multi-country portfolios.

Playbook7 min

Inside a Free PPWR Audit: The Three Things We Always Find on Day 1

The unsigned PFAS attestation. The unverified PCR claim. The sub-grade mismatch. These three patterns appear in roughly 73% of portfolios on Day 1. The reasons they recur, what each looks like in the wild, and a four-step sequence that closes all three within a working day.