ESPR Compliance and Digital Product Passports

The EU's Ecodesign for Sustainable Products Regulation sets the rules a physical product has to meet to be sold in Europe and the data that has to travel with it. We map those rules to your products, build the digital product passport data your suppliers must supply, and select and integrate the platform that publishes it.
Book a working session
Definition

What is ESPR compliance?

ESPR compliance means meeting Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation, in force since July 18, 2024 and covering almost every physical product placed on the EU market, wherever it is made. Some duties already apply: since July 19, 2026, large companies may not destroy unsold apparel, clothing accessories, or footwear, and large companies that discard unsold consumer products must disclose it each year. Product rules arrive through delegated acts that apply at least 18 months after they enter into force, and each act can require a digital product passport registered in the EU registry that went live on July 20, 2026. The Commission's schedule starts with iron and steel and continues through textiles, tires, aluminum, furniture, and mattresses.

Services

What does ESPR compliance support include?

Product and obligation mapping
Unsold goods destruction ban
Passport data model
Supplier data program
Platform selection and integration
Passport security and registry

Product and obligation mapping

We map every product you sell into the EU to its ESPR product group, your role for each one (manufacturer, importer, distributor, or fulfillment service provider), and the obligations and dates that follow. You get one register showing what applies now, what the Commission has scheduled for your product groups, and where a product made outside the EU needs an economic operator established in the EU.

Unsold goods destruction ban

Since July 19, 2026, large companies may not destroy unsold apparel, clothing accessories, or footwear unless one of the ten derogations in Delegated Regulation (EU) 2026/296 applies. We set up the donation offers, damage assessments, and five-year records the derogations require, and build the annual disclosure in the format that Implementing Regulation (EU) 2026/2 makes mandatory from March 2, 2027.

Passport data model

We build your passport data model from the delegated act for your product group and the harmonized standards: product identity, materials and substances of concern, durability and repair information, compliance documents, and end-of-life guidance. Each field is set at the model, batch, or item level the act requires, with access rights for customers, repairers, recyclers, and authorities.

Supplier data program

Most passport data sits with your suppliers. We write the data requirements into supplier agreements, run collection with your sourcing team, and validate what comes back, so a fiber composition, a recycled content figure, or a substance declaration traces to the document behind it.

Platform selection and integration

We select the passport platform against the six EN standards cited in July 2026 and ESPR's requirement for a back-up copy held by an independent service provider, then integrate it with your ERP, PLM, and product information systems. The platform vendor hosts the passports. We do not sell or resell a platform, so the recommendation follows your data and your systems.

Passport security and registry

ESPR requires passport data to be authenticated, reliable, and secure, and the passport has to stay available after an insolvency. We design access control, signing, and change logs around your passport data, register product identifiers in the EU registry before products reach the market, and update the program as new delegated acts are adopted.

Our approach

Map it, close today's gaps, build the passport, run it

01

Map products to obligations

Your product list, sourcing countries, and EU sales channels go into one register that shows each product group, your role, and every obligation with its date.

02

Close what applies today

The destruction ban and the unsold goods disclosure apply before any product-specific act, and older ecodesign measures still cover many energy-related products. We close those first.

03

Build the passport

Data model, supplier collection, platform selection, and integration run against the delegated act for your product group, timed so passports are ready before the act applies.

04

Run and keep current

We register identifiers before products reach the market, track new delegated acts and standards, and update data requirements when the rules change.

contact us

Which ESPR obligations apply to your products?

Send us your EU product list and sales channels. We will show you which obligations apply today, what the Commission has scheduled for your product groups, and the data your passports need.

Our Advantage

Why BD Emerson for ESPR compliance

A passport is a security system

ESPR requires passport data to be authenticated, reliable, and secure, with different access for customers, repairers, recyclers, and authorities. Our practice runs SOC 2, ISO 27001, and privacy programs, so access control, integrity, and audit trails go into the design from the first workshop.

No platform to sell

We do not sell or resell a passport platform. We write the requirements from the delegated act and the EN standards, run the selection, and integrate the platform you choose, so the recommendation follows your products and your systems.

Part of Andersen Consulting

BD Emerson is joining Andersen Consulting, announced August 10, 2026, with closing expected in Q4 2026. Andersen Global's member and collaborating firms operate in 170 countries, so the legal and tax questions an ESPR program raises in EU member states can go to Andersen colleagues.

Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.

Guides

ESPR and digital product passport guides

What a passport contains and how it works, what already applies to textiles and batteries, how to choose and secure a passport platform, and how GS1 Digital Link carries the identifier.

FAQ

Frequently asked questions

Does ESPR apply to companies outside the EU?

Which products does ESPR cover?

When do ESPR requirements apply to my products?

What is a digital product passport?

Do you build or host the passport?

What does the destruction ban require?

How does ESPR relate to the Battery Regulation and the Cyber Resilience Act?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners