
The EU published its first six Digital Product Passport standards on 27 May 2026. What is actually built, what is still missing, and what a manufacturer should do before the 2027 deadlines.
A vendor tells you their platform is “ESPR-ready.” A consultant offers a “fully compliant Digital Product Passport solution.” Until a couple of weeks ago, you had no real way to tell whether either claim meant anything at all.
That changed on 27 May 2026.
That’s the day CEN and CENELEC published the first six European standards for the Digital Product Passport. For the first time there’s a written technical baseline you can actually hold a supplier to. It’s a genuine milestone, and it rewards a slow read, because the real picture behind the headline is more useful, and more honest, than “the standards are done.”
Some of the DPP is now genuinely built. A lot of it isn’t. Knowing which is which is the difference between buying something useful this year and buying something you’ll be ripping out in eighteen months.
What just became real? Six European standards
The six come from the joint committee CEN-CLC/JTC 24, “Digital Product Passport: Framework and System,” written under the Commission’s standardisation request M/604. Between them they describe the plumbing every passport runs on, whether the product is a battery, a jacket, or a window.
EN 18219 is the identifier standard. It is about giving every product an identity that won’t collide with anyone else’s.
EN 18220 is the data carrier: the QR code, or the RFID or NFC tag, that ties the physical product to its passport. It gets fussy about symbology, encoding, print quality and durability, and for good reason. A code that won’t scan after two years on a building site is worse than no code at all.
Moving that data between systems is EN 18216. Keeping it available over time is EN 18221, which deals with storage and persistence: how long the data has to stay reachable, including after a product is discontinued or the company behind it reorganises.
EN 18222 is the API layer, the interfaces other systems use to look up, retrieve and update passport data when they’re authorised to. And EN 18223 is interoperability, the part that makes two compliant systems actually talk to each other instead of just claiming they can.
One thing the standards deliberately avoid is tying you to a single identifier scheme. What they require is an identifier that’s globally unique, built on open standards, and resolvable to a web link. GS1’s Digital Link is the most common way to meet that, and the one many companies already have in place, but it isn’t mandatory. Other open issuing schemes qualify too. Worth keeping straight, because “a DPP” and “a GS1 QR code” get treated as the same thing far more often than they should be.
This is the layer you can commit to today. If a supplier can’t tell you which of these standards their product implements, they’re showing you a slideshow.
Worth being honest about one thing, though. Publication isn’t the same as legal force. None of the six have been cited yet in the Official Journal of the European Union, and that citation is what grants “presumption of conformity,” the shortcut that says follow the standard and you’re treated as compliant. Until it lands, they’re the technical consensus rather than the letter of the law. Stable, worth building against, but not yet a box you can tick.
A practical note: these standards aren’t free. CEN and CENELEC publish them, numbered EN 18216 through EN 18223, and the national standards bodies sell them. In Norway that’s Standard Norge. If you’d rather read the actual text than someone’s summary of it, that’s where to find the full set.
What’s still missing? The data itself
This is where most of the coverage stops short. The six standards describe the system, not the contents.
They tell you how to identify a product, how to attach a carrier, how to store and move and query the data. They say nothing about what actually goes inside a textile passport, or a battery passport, or a construction one. That list, the real data attributes, comes from sector-specific delegated acts, and most of those haven’t been written.
Where things stand in mid-2026:
Batteries go first, and they go concretely. From 18 February 2027, every EV, industrial and light-means-of-transport battery over 2 kWh sold in the EU needs a battery passport you can reach by QR code. There’s an earlier marker too, though a softer one. The carbon footprint declaration for industrial batteries was scheduled for February 2026, but it only takes effect once the Commission finalises the calculation method and the declaration format, and that’s still outstanding. The due-diligence obligations slipped as well, by two years to August 2027, under Regulation (EU) 2025/1561. The passport deadline itself held. Batteries are also the sector where the data list isn’t guesswork, because the Battery Regulation already spells it out: identification and manufacturer data, chemistry and material composition, carbon footprint, recycled-content shares for cobalt, lithium, nickel and lead, capacity and state-of-health figures, responsible sourcing and supply chain data, and end-of-life and dismantling information.
Textiles are next, but not soon. The delegated act for apparel is expected in 2027, and mandatory passports realistically land around 2028 once the application window has run. One related rule arrives earlier: the ban on destroying unsold textiles and footwear kicks in during 2026.
Construction is on a track of its own. It sits under the revised Construction Products Regulation rather than ESPR, the Ecodesign for Sustainable Products Regulation, with passports expected around 2029 to 2030. We unpacked that whole chain in our CPR, GWP, EPD, DPP article.
The system layer isn’t quite finished either. At least one more standard, FprEN 18239, on access-rights management, information-system security and business confidentiality, is still working through approval and expected around September 2026. Don’t file that one under footnotes. It’s the standard that decides who is allowed to see what, and a passport without a settled access model is one you can’t yet safely put in front of the public.
So the practical read is simple. Anyone selling you a “compliant textile passport” today is describing a destination, not a specification. The rules they’d need to comply with don’t exist yet.
The registry is a directory, not a database
The next date worth circling is 19 July 2026, when the EU’s central DPP registry goes live. This one gets misread constantly, so it’s worth being exact.
The registry doesn’t store your passport data. It’s a directory, much closer to a phone book than a database. You register a product identifier, and the registry records where that product’s passport actually lives. When an authority or a customer comes looking, the registry points them at your system, or your provider’s, and the data is served from there.
Which confirms something worth saying out loud: there’s no central EU database holding your product information. You host your passport, or you pay someone to host it for you, and either way you stay on the hook for keeping it reachable. EN 18221, the persistence standard, is exactly about that obligation.
Two things follow for a manufacturer. The first is ownership. Because the data lives with you, where it’s stored and whether you can move it is a commercial decision you control, not one Brussels makes for you. The second is lock-in. If your passport sits on a platform that can’t be repointed the day you switch suppliers, that registry entry quietly becomes a leash. So ask, before you sign anything, whether you can take your identifiers and your hosting somewhere else.
So what does “DPP-ready” actually mean right now?
Put the two halves together and the picture is easy enough to state. The system layer is standardised and stable. The sector data layer, batteries aside, is still being written. And the registry is infrastructure, not content.
Which is why “ESPR-ready” and “DPP-compliant,” thrown around as blanket claims, mean very little in mid-2026. Compliant with which standard, exactly? Ready for which sector’s data model, when most of those models haven’t been published?
The useful question has shifted. It used to be “are you DPP-ready?” Now it’s “which EN numbers do you implement, and which sector are you targeting?” A supplier who’s genuinely building against the standards answers that in a sentence. One who’s selling fear and a logo can’t.
There’s a line we keep coming back to internally: the standards finally handed the market a ruler, and most of the compliance products on sale today have never once been held against it.
What should you do now?
You don’t have to wait for your sector’s delegated act to start on the work that matters, because most of it doesn’t depend on the sector at all.
Build on the system standards now. Identifiers, data carriers, APIs, interoperability: that’s the stable layer. How you identify an item, which carrier you print, which interfaces you expose, none of it gets overturned when your sector’s data list finally shows up. It’s the safe place to begin.
Get your product data down to item level. The hard part of a passport was never the QR code. It’s having clean, structured data for each individual product, organised so it can be served on demand. If yours is scattered across an ERP, a PIM and a pile of spreadsheets, pulling it together is the real first job, and it’s a lot cheaper done now than under deadline.
Use 19 July as a dry run. One question gets you most of the way: starting from an identifier you control, can someone actually resolve their way to current, structured data about your product? If not, you’ve found your gap, and you’ve found it with time to spare.
Be wary of “turnkey compliance.” There’s no such thing for a regulation whose sector rules are still in draft. There is, now, a genuine set of standards to build against. Anyone who waves that away and still can’t name a single EN number is worth a much longer look before you sign.
None of this needs certainty you don’t have yet. It just needs you to build on what’s already settled and keep the rest loose. Do that and you’ll spend 2027 shipping passports, while your competitors are still working out what “ESPR-ready” was meant to mean.
FAQ
Trying to tell what’s real from what’s marketing in the DPP space? That’s most of what we do. DPPA builds Digital Product Passport infrastructure for manufacturers, with a focus on item-level product data. We sit on Standard Norge’s DPP committee, SN/K 624, the Norwegian mirror of the CEN-CLC/JTC 24 group behind these standards, so we’ve been building against them as they were drafted rather than retrofitting after the fact. So when someone asks the question this article hands you, which EN numbers and which sector, we can give a straight answer. Get in touch to talk through where your products actually stand.
Let’s make your products future-proof, together.
Reach out to us at contact@dppa.no
Or learn more about how the platform works below.



