
The EU’s Digital Product Passport registry went live on 20 July 2026. Before it will let you register a single passport, it asks a question that has nothing to do with your product: who are you? The answer runs through eIDAS. Here is what a “verified economic operator” is, who has to be one, and what it means whether you place products on the market or host passports for someone who does.
Most of the preparation for a Digital Product Passport goes into the data. Material composition, carbon figures, repair information, an identifier scheme you can stand behind. All of it necessary. But when the registry opened its doors this July, the first gate it put in front of anyone was not a data check. It was an identity check.
The rules for that gate are now law. Commission Implementing Regulation (EU) 2026/1778 sets out how the registry works, and it is explicit on one point: you cannot register a passport until you have proven who you are. The instrument it uses for that is eIDAS.
The registry checks identity before it checks data
Before you register anything, you have to become a verified economic operator. That status is what unlocks the registry, and you earn it by proving your identity through eIDAS, the EU’s framework for electronic identification and trust services (Regulation (EU) 910/2014).
In practice that means a specific, machine-verifiable credential. A company proves itself with a qualified electronic seal, issued by a qualified trust service provider. A sole trader uses a qualified electronic signature. A high-assurance electronic identity can serve the same purpose. If you have ever used a national eID or a company signing certificate to submit an official filing, you already know the shape of this. eIDAS is the EU-wide, cross-border version of it, and the registry treats it as proof.
Doing it this way buys trust that scales. A market surveillance authority in one member state, a customs officer in another, and a registry run centrally all need to know that the operator behind a passport is a real, identifiable entity rather than an anonymous account. A verified identity gives them that without a person having to check by hand.
The sequencing is the thing to notice. The registry itself does not hold your passport data. It stores identifiers, a pointer to where each passport actually lives, and integrity metadata, and it acts as the reference that customs and authorities check against. We walked through that in what the registry stores, and what it doesn’t. Identity verification sits in front of all of it. First the registry establishes who you are, then it lets you register where your passports live.
Two roles in one flow: operator and service provider
This is where most of the confusion sits, and where it pays to be precise, because two different parties turn up in the same registration flow.
The economic operator is whoever places the product on the EU market. Usually the manufacturer or the importer. This is the party the regulation holds responsible, and it is the party that gets verified. The obligation to register and the identity behind the registration both belong here. It is yours if you make or import the product, and it does not move.
The DPP service provider is whoever hosts the passport and runs the technical connection to the registry. This can be a platform like DPPA. A service provider can carry a lot: hosting the passport, generating and resolving identifiers, handling the API integration with the registry, keeping the data reachable for as long as the rules demand.
What a service provider cannot do is be you. The verified economic operator is the party that placed the product on the market, and that accountability stays put even when the technical work is outsourced. That is the line worth fixing in your head before you sign with anyone: you can hand over the hosting and the integration, not the identity or the responsibility behind it.
So if you are a manufacturer choosing a DPP provider, the useful question is not “will they handle the registry for us.” It is “what is left on our side after they do.” The answer, at minimum, is your verified-operator status. A good provider says that out loud instead of letting you assume the whole thing has been lifted off your plate.
The three-year clock
Verified status is not permanent. Under the regulation it lasts at most three years, after which you re-verify.
That small detail changes how you should treat it. Identity verification is not a form you fill in once before your first registration and forget. It is a credential with an expiry, tied to the trust services behind it, and your access to the registry rides on it staying valid. If it lapses, so does your ability to register or update passports through the API.
Treat it as something you own and track, with a renewal date in the calendar, the way you would a certificate or a domain. For a manufacturer that is one more line on the compliance calendar. For a service provider it is a state to watch on behalf of the operators it works with, so a quietly expired credential never becomes the reason a registration fails at the worst moment.
What to do before your deadline
The first hard registration obligation is close enough to matter. From 18 February 2027, large batteries need a passport registered in the central registry, and other product groups follow through their own delegated acts, construction and textiles and toys and detergents, each on its own timeline.
The mistake would be to leave identity for last, after the data is perfect. Getting a qualified electronic seal or a high-assurance eID is not instant. It runs through a qualified trust service provider, with its own onboarding and checks, and it belongs to the same category of task as opening a business bank account rather than signing up for a web app. Start it alongside your data work, not after it.
Three questions are worth putting to any DPP provider before you commit:
- When we register through you, who is the verified economic operator, us or you? The honest answer is you, the operator. Be wary of anything vaguer.
- How does your integration handle re-verification as our status nears its three-year limit?
- If we leave, do our identifiers and passports come with us, or are we tied to your account?
A provider that has built against the regulation answers these in a sentence each. One that treats your identity as a detail it will quietly “handle” is worth a harder look.
Can you test the registry in a sandbox first?
Yes, and you should. The registry went live with a separate test environment, so you can run the whole verified-operator and registration flow now, against a sandbox that never touches live data.
When it opened on 20 July 2026, the registry arrived with more than the production system: technical documentation and an operator user guide, an API, a helpdesk, and a test environment held apart from the live registry. That separation is what makes it useful: you can exercise the real flow end to end without registering anything for real.
For the identity side, a test run answers the questions that actually matter. Can you obtain your eIDAS credential and come through as a verified economic operator? Does a passport register end to end, with the integrity metadata written the way it should be? If a provider registers on your behalf, does that path work with both parties verified? Those are cheaper to answer in a sandbox this year than under a live obligation in 2027. It is the part we watch most closely as a service provider ourselves, because the sandbox is where we validate our own integration before it goes live.
So the practical move is a dry run over a quiet week: get verified, register one test passport, confirm the integrity metadata appears. You find your gaps while there is still room to close them, not when your sector’s deadline is on the door.
FAQ
Working out where your verified-operator status has to sit, and what a provider can and cannot take off your hands, is the kind of question we deal with every week. DPPA builds Digital Product Passport infrastructure for manufacturers, with a focus on item-level data and identifiers you own and can move. We have been building against the registry rules as they were drafted, and we sit on Standard Norge’s DPP committee, SN/K 624, the Norwegian mirror of the CEN-CLC/JTC 24 group behind the standards. If you want a straight answer on what eIDAS means for your products, book a demo.
For what the registry actually stores once you are through the door, see The EU DPP Registry: What It Actually Stores, and What It Doesn’t.
Let’s make your products future-proof, together.
Reach out to us at contact@dppa.no
Or learn more about how the platform works below.



