Missouri’s Division of Cannabis Regulation is out to bid on a replacement for its track-and-trace system, ahead of the expiration of a $7.3 million agreement with Metrc that has run since the launch of the state’s medical program. It is the first known attempt by a state cannabis regulator to displace the dominant vendor, and the bidding documents are unusually candid: scattered communications, lost information, significant response delays. A February state audit added that the software lacks real-time detection of purchases exceeding legal limits — a diversion gap with public-safety implications.
Competitors including Oracle and Salesforce attended the pre-bid conference. That alone tells you the scope has changed.
Because Missouri is not buying track-and-trace. It is asking for a fully integrated solution covering track and trace, application registration, ID cards, licensing, case management, ERP, data solutions, and user training.
Read that list again as a security professional rather than a procurement officer. Six distinct data domains, currently in separate systems with separate access models and separate blast radii, consolidated into one contract, one platform, one credential store, one vendor.
What Consolidation Actually Concentrates
Today, in most states, these systems are separate largely by accident of procurement history. The accident has been doing real security work.
- Track-and-trace holds plant, package, and transfer data — every gram, every movement, every licensee’s complete operational picture.
- Application registration holds unlicensed applicants’ submissions: personal financial disclosures, background check material, ownership structures, social equity documentation.
- ID cards hold patient identity, and in a medical program that means health-status data — a card whose existence proves a qualifying condition.
- Licensing holds the identity, address, and history of every owner and agent in the state.
- Case management holds investigations and enforcement files, including complaints, inspection findings, and matters that have not been adjudicated.
- ERP holds the regulator’s own financial and operational data.
Put those in one platform and you have built, in a single system, a complete map of a state’s cannabis industry: who owns what, which patients bought what, who is under investigation, and where every gram is right now.
An attacker who compromises the seed-to-sale system today gets inventory data. An attacker who compromises the consolidated platform gets the industry.
This is not hypothetical. The MJ Freeway compromises disrupted compliance tracking across multiple states from a single vendor, and that vendor held far less. Concentration is precisely the property that turns a vendor incident into a market-wide one.
The Case for Consolidation Is Real
It has to be said plainly, because the counterargument to “concentration risk” is not stupidity — it is a set of genuine benefits.
Six systems means six integrations, six failure points between them, six sets of credentials for operators, and six places where data disagrees. Missouri’s complaints about lost information and delayed responses are exactly what fragmentation produces. A patient whose ID card system does not talk to the dispensing system gets turned away at a counter. A licensee whose application data does not reach the licensing system waits months.
Consolidation also enables the audit finding’s fix. Real-time purchase-limit detection requires the dispensing system to know, at transaction time, what a patient has already bought elsewhere. That is easier when it is one system.
And a single serious enterprise vendor — the kind that shows up to a pre-bid with Oracle’s or Salesforce’s compliance apparatus — will likely bring better baseline security than a fragmented estate of cannabis-specific tools. FedRAMP-adjacent controls, mature identity management, real incident response, and an actual security organization are not nothing.
The question is not consolidation versus fragmentation. It is whether the consolidated system is architected with internal separation, or whether “integrated” means one database and one permission model.
The Four Questions Operators and Trade Groups Should Be Asking
Missouri’s procurement is public, other states are watching it, and the window to influence requirements is before award, not after migration. These are the questions worth putting in writing.
1. Is patient data logically separated from licensing and enforcement data, with distinct access controls?
An integrated platform can still enforce hard internal boundaries — separate schemas, separate roles, separate audit trails, no default join path between a patient’s dispensing history and an investigator’s case file. Or it can be one warehouse where an authorized user with broad permissions can query across everything. Both get sold as “integrated.” Only one is defensible.
2. Who inside the state can query across domains, and is it logged?
Case management sitting in the same platform as patient ID data is the specific combination that should worry people. An enforcement investigator with platform-wide read access can pull a patient’s complete purchase history without the process that would normally require. Ask what the role model is, whether cross-domain queries are logged, and whether anyone reviews those logs.
3. What does the migration look like, and who holds the data during it?
This is the acute risk and the one nobody plans for. A state-wide track-and-trace transition means the entire historical dataset moves between two vendors, one of which is losing the contract. Migration windows involve bulk extracts, temporary storage, dual-running systems, and elevated access for engineers on both sides — every one of them a control that does not exist in steady state.
New York’s transition to Metrc — including the pause after Metrc assumed BioTrack’s government contracts — is the closest recent precedent, and it stretched across a year. Operators should be asking: what is the encryption standard for data in transit and at rest during migration, who has access to the extracts, what is the deletion obligation and verification for the outgoing vendor, and is there an independent audit of the handover?
4. What is the continuity plan when the platform goes down?
Under fragmentation, a track-and-trace outage is bad. Under consolidation, a platform outage means no transfers, no license verification, no patient card checks, no new applications, and no enforcement records — statewide, simultaneously. Operators cannot legally transact without track-and-trace in most frameworks.
Ask for the RTO, the documented manual fallback procedure, and confirmation that a regulator-side outage will not put operators in violation for transactions they could not record. Get that last one in writing from the regulator, not the vendor.
What Operators Should Do Regardless of Who Wins
The award is not in your control. Your own posture is.
Keep your own records. Do not treat the state system as your system of record. If your only copy of transfer manifests, package histories, and patient verifications lives in a platform you do not control and are about to be migrated out of, you have no independent ability to reconstruct your compliance history. Export on a schedule, store it under your own encryption and access control, and verify the exports are readable.
Map your integrations now. Your POS, your cultivation software, and your compliance tooling all talk to the current system through APIs that will change. A vendor transition breaks integrations, and the operators who suffer most are the ones who discover their dependency map during the cutover. Write it down: every system that reads from or writes to track-and-trace, which credentials it uses, and who owns the fix.
Rotate credentials at transition, and audit them before it. Vendor migrations are a classic moment for stale accounts — former employees, decommissioned integrations, shared logins — to carry forward into the new platform. Clean the account list before it gets copied. Phishing campaigns reliably spike around announced migrations, because “urgent: re-enter your track-and-trace credentials for the new system” is a message operators are primed to believe. Tell your staff now what the real migration communications will look like and that credentials will never be collected by email.
Participate in the procurement conversation. Trade associations can and should submit comment on security requirements, and states generally welcome it because most cannabis procurement teams are not staffed with security architects. “We ask that the award require logical separation of patient data from enforcement data, logged cross-domain access, and an independent audit of migration handover” is a specific, reasonable, achievable ask. It is far easier to write into an RFP than to retrofit after go-live.
Bottom Line
Missouri has good reasons to change vendors and good reasons to want one platform instead of six. The complaints are legitimate, the audit finding is real, and fragmentation has costs that fall hardest on patients and small operators.
But the state is about to concentrate patient health data, applicant financial disclosures, licensee identity, and open enforcement files into a single system, and the requirements that determine whether that is safe are being written right now — in a procurement document, by a team optimizing for integration.
The security question is not whether to consolidate. It is whether “integrated” is built with walls inside it. That question has a short window in which asking it is cheap, and a long period afterward in which the answer is fixed.
Missouri is first. It will not be last. What gets written into this award becomes the template other states copy.
Missouri’s Division of Cannabis Regulation issued a request for proposal for track-and-trace services ahead of the expiration of its approximately $7.3 million agreement with Metrc, seeking a fully integrated solution spanning track and trace, application registration, ID cards, licensing, case management, ERP, data solutions, and user training. Bidding documents cite scattered communications, lost information, and response delays; a February 2026 state audit noted the absence of real-time purchase-limit detection. Reporting via MJBizDaily and Greenway Magazine. Contract dates and status should be confirmed against current state procurement postings.



