In this article:

Digital Product Passport Software: How to Choose a Platform

Technology
/
September 19, 2026
Digital Product Passport Software: How to Choose a Platform

Under the EU Ecodesign for Sustainable Products Regulation (ESPR), digital product passport software must create and host passports that meet Articles 10 and 11, resolve each product's data carrier to its passport, enforce access rights for each stakeholder group, keep a back-up copy with an independent third-party service provider, keep passports available after an insolvency, hold data in open, interoperable formats without vendor lock-in, and register identifiers in the EU registry through the registry's API. The yardstick for evaluating a platform is the set of six EN standards that the Commission cited in the Official Journal on July 15, 2026, which give a presumption of conformity with Articles 10 and 11.

The EU registry has been live since July 20, 2026, and the first mandatory passports, for electric vehicle, light means of transport, and industrial batteries above 2 kWh, apply from February 18, 2027 under the Battery Regulation. The Commission's published DPP schedule lists the iron and steel delegated act for Q4 2026, and our guide to the digital product passport covers the full timeline.

What ESPR requires of DPP software

Chapter III of the ESPR, Articles 9 to 15, holds the passport rules. Under Article 9, a covered product can be placed on the market only if its passport is available with data that is "accurate, complete and up to date." Each delegated act sets what a platform must handle: data elements, carrier, granularity (model, batch, or item), who reads or updates which data, and availability for at least the product's expected lifetime.

Article 10 sets the design. A data carrier on the product, packaging, or accompanying documents links to a persistent unique product identifier, and the data must rest on open standards and be interoperable, machine-readable, and transferable "without vendor lock-in." The passport cannot hold customers' personal data without their explicit consent. Article 10(4) requires a back-up copy through a DPP service provider, which Article 2 defines as an independent third party.

Article 11 sets the operating rules: interoperability with other passports, free access by stakeholder group according to access rights, storage by the operator or a service provider, links from a new passport to the original, availability "after an insolvency, a liquidation or a cessation of activity in the Union," write rights limited by access rights, data authentication and integrity, and "a high level of security and privacy." Service providers may not sell, reuse, or process passport data beyond their service unless the operator agrees.

Articles 12 to 15 tie the passport to enforcement. The operator requests operator and facility identifiers for suppliers and sites that lack one (Article 12). The EU registry stores the unique identifiers and, for imports, the commodity code (Article 13), a public web portal supports search and comparison (Article 14), and customs check the unique registration identifier and commodity code before releasing an import (Article 15).

Reference architecture for a digital product passport platform: ERP, PLM, PIM, and supplier inputs feed the platform, the data carrier resolves to the passport, the platform registers identifiers with the EU registry that customs check, a back-up copy sits with an independent service provider, and access groups read the passport according to their rights
The platform's links to source systems, carriers, the registry, customs, the back-up provider, and access groups under ESPR Articles 9 to 15 and Regulation (EU) 2026/1778.

What ESPR does not require

ESPR does not prescribe a technology. Answering a question about blockchain in its September 2024 ESPR FAQ, the Commission said it intends to remain technology-neutral: "There is no specific technology favoured or excluded at this stage." Judge any vendor ledger on cost and exit terms, because the regulation does not ask for one.

ESPR also creates no central database of passport content. Recital 41 says the passport "should be based on a decentralised data system and be set up and managed by economic operators," with a Commission registry holding identifiers for enforcement. CEN-CENELEC, whose committee JTC 24 drafted the standards, describes a hybrid: "The European DPP is not a centralized database, but at the same time, it is also not fully decentralized."

ESPR sets no platform certification today. Article 11 lets the Commission set requirements for DPP service providers and, where appropriate, a certification scheme, and its DPP timeline lists that delegated act for 2027. Until then, an "ESPR certified" platform claim is marketing.

The six EN standards as a checklist

Implementing Decision (EU) 2026/1736 lists the six cited standards, which CEN-CENELEC calls "transverse and product agnostic": they define how passports work, and each product regulation defines the data. The scopes below come from the abstracts the Swedish Institute for Standards (SIS) publishes for each EN.

EN 18219 covers product, operator, and facility identifiers: uniqueness, persistence, and syntax at model, batch, or item level, issued by an agency, self-issued, or both. Ask who controls the web domain in each identifier, because a passport address on the vendor's domain ties you to that vendor. EN 18220 covers data carriers: symbology, encoding, error correction, print quality, durability, placement, and the DPP indicator. Ask whether the platform generates carrier files and checks print quality.

EN 18221 covers decentralized storage, an archive of past passport data, persistence after the creating operator stops operating, and replication to back-up operators. Ask how the platform replicates to the independent back-up provider. EN 18223 covers interoperability through a common information model, metadata models, and rules for product-specific data models. Ask the vendor to map your data to the Commission's data models.

EN 18216 defines secure data exchange protocols and data formats, and EN 18222 standardizes the API for passport lifecycle management and searchability. Ask for the API specification and a written conformance statement per standard, then watch the vendor create, update, search, and export a passport live.

Two further standards, on access rights and security and on data authentication and integrity, complete the set. CEN-CENELEC lists them as EN 18239 and EN 18246, so ask each vendor how it meets them too.

Checklist mapping the six harmonized DPP standards, EN 18216, EN 18219, EN 18220, EN 18221, EN 18222, and EN 18223, to what each covers and what to ask a platform vendor to show, with EN 18239 and EN 18246 noted as completing the set
The six standards cited by Implementing Decision (EU) 2026/1736, summarized from their published scopes, with the evidence to request from each vendor.

Registering passports in the EU registry

Implementing Regulation (EU) 2026/1778 of July 16, 2026 sets the registry rules, and the live registry comes with a testing environment, documentation, and a helpdesk. Operators register through a secure user interface or an API. A platform should use the API, because the Commission's registry user guide caps interface uploads at 100 passports per file, too few for item-level volumes.

Your company first verifies as an economic operator with a qualified electronic seal or an electronic attestation of attributes under eIDAS, and the verified status lasts no more than three years. The user guide requires each unique product identifier to be a URL starting with https://, a format GS1 Digital Link meets by expressing GS1 identifiers as web addresses. The registry checks each passport's semantic conformity with the Commission's data models and its granularity, then issues a unique registration identifier.

The registry stores the identifiers, the commodity code where relevant, the DPP service provider reference, and the date, time, and integrity of each registration; it versions and logs every update, and its proof of registration carries a hash of the passport version. The platform must keep registered versions in step with the registry, track each product's unique registration identifier, and pass it to whoever files your customs declarations. Registered passports can also transfer to another verified operator that takes over the obligations, for example after a divestiture.

Delegating the work does not delegate the liability. Under the implementing regulation, a third party that registers on your behalf must complete its own verification, your company remains "fully responsible" for compliance, and your company must secure its own IT systems and registry credentials. Treat the platform's registry credentials as privileged access.

Types of digital product passport platforms

BD Emerson does not sell or resell DPP platforms; we help companies choose and integrate them. The market falls into five groups; the examples paraphrase each vendor's own page, in no order of preference.

Specialist DPP platforms make the passport their core product. Arianee describes infrastructure to create, validate, manage, and distribute passports, with the EU DPP Registry among its outputs.

PIM and PLM vendors add passport output to the product record, natively or through partners. Inriver's partner network lists OrigoVero, which turns the Inriver record into a passport per individual unit; the Pimcore Store lists a Narravero extension that publishes Pimcore data to passports reached by QR code or NFC tag; and Arena, a PTC business, positions connected PLM as the central system for DPP information.

Supply chain traceability platforms start from supplier data. TrusTrace adds item identifiers, per-product QR codes, and GS1 Digital Link support to its traceability platform, and Circularise collects multi-tier supplier data, keeps chain-of-custody records, and publishes permissioned passports.

ERP vendors place the passport inside the product data estate. SAP describes a single control plane for traceability, regulatory, and sustainability data, supported by PLM systems, its business network, SAP Sustainability Footprint Management, and SAP Product Compliance.

Identifier and resolver services connect the product to the passport. GS1 UK runs a resolver for members that redirects GS1 identifiers to information about an item, and Avery Dennison launched Digital Product Passport as a Service in 2023, combining consultancy, hardware, software, digital ID technology, labels, and support around its atma.io connected product cloud.

A program can combine groups, such as a PIM as the source of record and a specialist platform hosting the passport. Each boundary is an integration to design and test, the work of our system integration services.

Criteria for choosing a DPP solution

Score every shortlisted digital product passport solution against the same criteria, each tied to the ESPR text.

CriterionWhy it matters under ESPRWhat to askWhat good looks like
Standards conformanceCited ENs give a presumption of conformity with Articles 10 and 11Which standards do you conform to, and where is it documented?Conformance statement per standard, plan for EN 18239 and EN 18246
Identifier schemesArticle 10 requires a persistent identifier; the registry requires an https:// URLDo you support GS1 Digital Link and other schemes? Whose domain is in the URL?Identifiers on a domain you control
Data carriersEach delegated act sets the carrierDo you generate and grade QR, NFC, and RFID carriers?Output and print checks per carrier type
Item-level scaleA delegated act can require a passport per itemHow many item-level passports do you run today?Load test results at your annual unit volume
Access control and identity federationArticle 11 sets read and write rights per stakeholder groupHow do repairers and authorities sign in? Do you federate with our identity provider?Role-based rights per group, federated sign-in, field-level edit control
Supplier onboarding and data validationArticle 9 requires accurate, complete, and up-to-date dataHow do suppliers submit data, and how is it validated?Supplier portal, attached evidence, checks against the Commission's data models
ERP, PLM, and PIM connectorsThe passport must change when the product record changesWhich connectors are standard, and who maintains them?Maintained connectors and event-driven updates
Registry APIRegulation 2026/1778 offers an API; interface uploads cap at 100 per fileDo you register, update, and transfer passports through the API?Verified registry third party, tested in the Commission's test environment
Back-up and exit termsArticle 10(4) back-up, Article 11 persistence, no vendor lock-inWho holds the back-up? How do we export everything?Named independent back-up provider, full export, contractual exit help
Vendor security assuranceArticle 11 requires data integrity and a high level of securityDo you hold ISO 27001 certification or a SOC 2 report for this service?Current certificate or SOC 2 Type II report covering the platform
Data residencyGDPR applies to access logs, user accounts, and consented personal dataWhere are passports, back-ups, and logs stored?Named regions and subprocessors in the contract
Pricing modelPassports must stay available for at least the product's expected lifetimeIs pricing per passport, item, model, tier, or API call?Total cost modeled over the full availability period

Common pricing structures include per-passport or per-item fees, volume tiers, implementation fees, and usage charges for API calls or supplier seats. Model each quote at your unit volume over the full availability period.

Build or buy

Article 11 lets an operator store its own passports, so building is allowed. It makes sense when you already run a product data platform with public APIs, control an identifier domain, and have engineers to implement all eight standards. Building still needs a third party, because Article 10(4) requires the back-up copy to go through an independent DPP service provider.

Buying makes sense when passports are item-level, when many suppliers must submit data, or when your first deadline is close, because a vendor has already built the registry integration, access control, and carrier tooling. Our build vs buy software practice offers a TCO calculator, and our article on custom software vs off-the-shelf walks through the ten-year math; for a DPP, add the standards, the conformance work, and hosting for the product's expected lifetime.

A selection process that works

Six steps take you from the regulation to a signed contract.

  1. Write requirements from your product group's delegated act: data elements, granularity, carriers, access groups, and availability period. Until that act is adopted, use ESPR Articles 9 to 15, the six standards, and Regulation 2026/1778, or the Battery Regulation for batteries.
  2. Shortlist three to five vendors from at least two platform groups, using the criteria table as the questionnaire.
  3. Run the same scripted demo with two of your real products for every vendor, and score only what each demonstrates.
  4. Pilot one product line with real supplier data, through registration in the Commission's testing environment and a scan of the printed carrier.
  5. Review the vendor as a critical supplier: certification scope, penetration test results, registry credential handling, and incident terms. Our articles on digital product passport security and vendor risk management cover the checks.
  6. Close the contract and exit terms: name the back-up provider, keep Article 11's default bar on data resale and reuse, and require full export in standard formats.

We run this process, from requirements through integration, as part of our ESPR compliance and digital product passport services.

Frequently asked questions

What does digital product passport software do? It creates, hosts, and updates passports at model, batch, or item level, links each one to the data carrier on the product, controls who can read and edit each field, and registers identifiers in the EU registry. ESPR Articles 10 and 11 also require open, interoperable data, a back-up copy with an independent service provider, and availability after an insolvency.

Does ESPR require blockchain for digital product passports? No. In its September 2024 ESPR FAQ, the Commission said it intends to remain technology-neutral and that no specific technology is favored or excluded. Any architecture that meets ESPR Articles 10 and 11 and the applicable delegated act is acceptable.

What kinds of digital product passport providers are there? Providers fall into five groups: specialist DPP platforms, PIM and PLM vendors, supply chain traceability platforms, ERP vendors, and identifier and resolver services. Test each candidate against the six harmonized standards and the registry API.

Can a DPP platform register our products in the EU registry? Yes. Implementing Regulation (EU) 2026/1778 lets a verified economic operator authorize a third party to register on its behalf once that third party completes its own verification. Your company must still verify with a qualified electronic seal or an electronic attestation of attributes, and it remains fully responsible for compliance.

Who holds the back-up copy of a digital product passport? ESPR Article 10(4) requires the operator placing the product on the market to make a back-up copy available through a DPP service provider, an independent third party under Article 2. The Commission's DPP timeline lists a delegated act on service providers for 2027. Until it is adopted, name the back-up provider in your contract and confirm how the copy stays reachable if either party stops operating.

Does a DPP platform make our products ESPR compliant? No. The platform hosts the passport, but each product must still meet the ecodesign requirements in its delegated act and pass the conformity assessment that act specifies. ESPR Article 13 also states that the registry's communication of a unique registration identifier is not proof of compliance.

BD Emerson maps products to their ESPR obligations, designs the passport data model and access rights, selects the platform, and integrates it with your ERP, PLM, and PIM systems. For requirements and a shortlist, see our ESPR compliance practice.

About the author

Drew Danner is a Managing Director at BD Emerson. He leads engagements across technology strategy, enterprise AI, M&A technology diligence, and the firm's governance, risk, and security practice, advising buyers, operators, and portfolio companies on decisions where the technical call drives the commercial outcome. His work spans build vs buy decisions, platform implementations, and the security and compliance programs that keep them defensible.
Drew Danner
Drew Danner
Managing Director