EU Digital Product Passport Registry — live since July 2026
The Commission opened the central DPP registry on 20 July 2026 and Implementing Regulation (EU) 2026/1778 applies from 6 August. Who must register, how eIDAS verification works and what to do now.
EU Digital Product Passport Registry — live since July 2026
For two years the EU digital product passport registry was a future-tense sentence in our articles: “the ESPR provides for a central registry, expected to be built gradually from 2026 to 2027.” That sentence is now out of date. The European Commission opened the registry on 20 July 2026, and the implementing regulation governing it applies from 6 August 2026. The infrastructure the digital product passport has to connect to has stopped being a plan.
For manufacturers, one consequence matters more than the rest and is easy to miss in the press coverage: registering a passport requires you to first become a verified economic operator, and that step has no product-category deadline of its own. It does not wait for the delegated act covering your category. You can — and should — do it now, because it rests on qualified electronic identity means that take weeks to obtain from a trust service provider, not minutes.
Key takeaways
- Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026 sets the operating rules for the DPP registry. It was published in the Official Journal on 17 July and entered into force on 6 August 2026. The registry itself opened on 20 July 2026, together with a test environment.
- The legal basis is Article 13 of the ESPR, Regulation (EU) 2024/1781 — the registry is horizontal infrastructure shared across several laws, not an ESPR-only tool.
- It will serve the Batteries Regulation, the Construction Products Regulation, the Toy Safety Regulation and the Detergents Regulation, plus every category added by ESPR delegated acts.
- No passport can be registered without verified economic operator status. Verification runs on eIDAS, directly with the Commission — it cannot be delegated to a DPP platform vendor.
- Verified status lasts no longer than three years (Article 4(4)) and expires with the identity means it rests on. This is a recurring task, not a one-off.
- Registration happens through the web interface or an API, at model, batch or item granularity. The registry records the product identifier, the commodity code used at customs, the registrant’s identity, a timestamp and a cryptographic hash of the passport version.
- On successful registration the system issues a unique, persistent registration identifier (Article 8(8)). A proof of registration, sealed with the Commission’s qualified electronic seal, is available to download for 90 calendar days.
- The registry checks structure and completeness, not product compliance. A registration is not evidence that the product meets its requirements — market surveillance stays separate.
- Registration data is deleted 10 years after registration unless sector law says otherwise (Article 10(3)).
- The first hard deadline is 18 February 2027: mandatory registration of battery passports, and the date by which Member States must appoint national administrators.
- The registry maintains a public list of verified DPP service providers (Article 3). Choosing a vendor becomes a publicly visible decision.
- Separately, Implementing Decision (EU) 2026/1736 of 14 July 2026 listed six harmonised standards of the EN 182xx series in the Official Journal. Applying them gives a presumption of conformity with the DPP technical requirements.
What exactly went live in July 2026
Three events in a single week add up to a complete package: the legal layer, the technical layer and a working system.
| Date | Event |
|---|---|
| 14 July 2026 | Implementing Decision (EU) 2026/1736 — list of harmonised DPP standards (published in the OJ on 15 July) |
| 16 July 2026 | Adoption of Implementing Regulation (EU) 2026/1778 on the registry’s operating rules |
| 17 July 2026 | Publication of Regulation 2026/1778 in the Official Journal of the EU |
| 20 July 2026 | The DPP registry opens, with a test environment |
| 6 August 2026 | Regulation 2026/1778 enters into force (20 days after publication) |
| 18 February 2027 | Mandatory registration of battery passports; deadline for appointing national administrators |
Note the sequence: the registry opened before its own rules took effect. That is not an oversight but a deliberate testing window. Anyone who wants to validate an integration before February 2027 has a test environment available today.
What the registry is made of
Regulation 2026/1778 does not describe a single database but a set of components with different jobs. Knowing them is useful, because it draws the line between what happens at the Commission and what stays with the company.
| Component | Function |
|---|---|
| Web interface and API | Registering passports and retrieving data — manually or machine-to-machine |
| Verification platform | Confirms that a passport exists and is complete |
| Registration identifier scheme | Issues a unique, persistent identifier for each registration |
| Store of identifiers and commodity codes | Holds identifiers and customs commodity codes — the link between the DPP and customs clearance |
| Public list of DPP service providers | The list of verified providers (Article 3) |
| Semantic repository | Defines how passport data is structured |
| Identification and authorisation schemes | Distinct roles for economic operators, value chain actors, market surveillance and customs authorities |
One thing has not changed from the earlier plans: the registry does not store passport content. Product data stays with the manufacturer or its DPP service provider, while the registry holds identifiers, metadata and a version hash. The model remains decentralised, which means the quality and versioning of your own data is still your problem — exactly as we describe in the article on DPP and PIM systems.
Verified economic operator — the step you cannot delegate
This is the most consequential practical change. The registry does not accept passports from anonymous submitters. Before you register anything, your entity must obtain verified economic operator status by proving its identity and place of establishment with qualified means under the eIDAS Regulation.
Legal entities
A company proves identity and establishment with a qualified electronic seal issued by a qualified trust service provider, or with a qualified electronic attestation of attributes provided for under Union law. This is not the same as an electronic signature belonging to a director — a seal is bound to the entity, not to a person, and has to be procured from a provider on the EU trusted list.
Natural persons and sole traders
A sole trader proves identity with a qualified electronic signature, an electronic identification means at high assurance level, or a qualified electronic attestation of attributes. In this case the registry also stores a national identifier — passport number, national ID or tax identifier.
Value chain actors
Repairers, recyclers and other parties that need to read or add data obtain verified value chain actor status — a separate role with a separate scope of rights. If your business model assumes an authorised service centre appends repair history, that access needs formal verification too.
Three years, not “forever”
Verified status lasts as long as the identity means behind it and never longer than three years (Article 4(4)). In practice a new recurring item appears in the compliance calendar: renewing the seal and repeating verification. A company that procures a seal in 2026 and forgets about it loses the ability to register new passports in 2029 — in the middle of normal trading.
How registering a passport works
Submissions go through the web interface or the API. The registry validates each one automatically, checking semantic conformity against the applicable acts, the granularity level, the commodity code and the link to a backup host.
Granularity is a deliberate choice: model, batch or item. That decision is architectural, not administrative — it determines how many registrations you will make, how you number them, and whether you can answer a question about one specific unit. For an industrial battery, item-level registration is natural. For a construction product made in batches, it is not.
What the registry records: the product identifier, the commodity code, the registrant’s identity, a registration timestamp and a cryptographic hash of the passport version. That last element matters more than it looks: the hash ties the registration to one specific version of the data. Changing passport content without version management leaves you out of step with the hash held in the registry. Versioning stops being good practice and becomes a requirement that follows from how the system is built.
After registration the system issues a unique, persistent registration identifier (Article 8(8)). You can also generate a proof of registration: a document carrying the Commission’s qualified electronic seal and timestamp, containing the product identifier, the verified operator’s identity, a timestamp and the passport version hash. The proof is available to download for 90 calendar days — if you need it for commercial documentation, download and archive it yourself.
What the registry does not do
Three misconceptions are worth defusing straight away, because each leads to a bad decision.
The registry does not confirm product compliance. The automated checks concern the structure and completeness of the submission. As recital 16 of the regulation states, a successful registration is not proof that the product actually meets the applicable requirements. Market surveillance, notified bodies and conformity assessment continue to operate independently.
The registry does not replace your database. Passport content stays with you or your service provider. The registry knows the identifier and the hash, not your declared material composition.
Registration does not transfer liability to a vendor. A DPP service provider can host data and operate the API, but eIDAS verification is performed by the economic operator, and responsibility for passport content stays where it was — with the manufacturer or importer placing the product on the market.
Deadlines: who and when
The registry has been running since July 2026, but the obligation to register passports arrives category by category, through sector legislation.
- Batteries — 18 February 2027. The first and nearest deadline. It covers LMT batteries, electric vehicle batteries and industrial batteries above 2 kWh, under Article 77 of Regulation (EU) 2023/1542. Details in the article on the battery passport.
- National administrators — 18 February 2027. By this date each Member State appoints a single national administrator. The overlap in dates is not a coincidence.
- Toys — 2030. The Toy Safety Regulation (EU) 2025/2509 makes the passport a mandatory element of placing toys on the market.
- Construction products. Regulation (EU) 2024/3110 introduces the passport alongside implementing acts for individual product families.
- Detergents. The new Detergents Regulation is the fourth pillar the registry was designed for.
- Remaining ESPR categories. Textiles, furniture, tyres, steel and the other groups in the working plan — each with its own delegated act and its own date. We keep the calendar in the article on the DPP timeline.
That list is exactly why verified operator status is worth settling regardless of your sector. It is common to every deadline above.
The EN 182xx harmonised standards and presumption of conformity
Two days before the registry regulation, the Commission published Implementing Decision (EU) 2026/1736 listing six harmonised standards for the digital product passport, drafted by CEN, CENELEC and ETSI in support of the ESPR standardisation request. These are the EN 182xx series standards (EN 18216, 18219, 18220, 18221, 18222 and 18223), covering data exchange protocols, unique identifiers, data carriers, data storage and persistence, APIs for the passport life cycle, and system interoperability.
The practical effect is the same as for any harmonised standard: applying them gives a presumption of conformity with the DPP technical, design and operational requirements. The standards fill in the design detail the ESPR does not settle. For assessing a software vendor, this is the best available control question: does their implementation reference these standards, or a proprietary data model of their own? The thread connects directly to the choice of data carrier, which we cover in the article on GS1 Digital Link.
What to do this quarter — 5 steps
1. Decide which legal entity gets verified status
In a group structure this is not a trivial question. Verification applies to the entity that places the product on the EU market — and that is not always the company where the product team sits. For importers and private labels, settle it before you buy a seal, not after.
2. Procure a qualified electronic seal
From a qualified trust service provider on the EU trusted list. The process includes vetting your entity and realistically takes several weeks. Done now, it is an administrative task; done in January 2027, it becomes a blocker.
3. Put the expiry date in the compliance calendar
Three years is exactly long enough to forget. An owner for the task, a reminder six months before expiry and a named deputy — that is the whole job, and it prevents losing the ability to register passports mid-season.
4. Make the granularity decision
Model, batch or item — separately for each product family. That decision feeds straight into the data model and into whether your systems can generate an identifier at the right level. If they cannot today, this is the right moment to find out; the DPP implementation checklist helps.
5. Test the integration in the test environment
The test environment has been available since 20 July 2026. API registration, semantic validation and handling the version hash are three things better checked without deadline pressure. If you use a DPP service provider, this is also the right question to ask them: have they already tested submissions to the registry?
FAQ
Do I need to register now if my category has no delegated act yet?
You have no obligation to register passports yet — that arrives with sector legislation. But verified economic operator status is not tied to any product category, and nothing stops you from obtaining it now. Because it relies on qualified eIDAS means that take weeks to acquire, getting this step out of the way early is simply cheap.
Can my software vendor complete verification for me?
No. Identity verification happens with the Commission, based on qualified eIDAS means issued to your entity. A DPP service provider can host data, run the API and appear on the public list of providers, but it cannot become a verified economic operator on your behalf.
Does a registry entry mean my product is compliant?
No. The registry checks the structure and completeness of the submission, not product compliance — recital 16 of the regulation says so explicitly. Conformity assessment, technical documentation and market surveillance remain separate obligations. Registration is an administrative step, not a certificate.
What happens if I change passport data after registration?
The registry holds a cryptographic hash of the passport version you submitted. Changing content without version management creates a mismatch between reality and what the registry recorded. That is why data versioning, and the ability to reconstruct a passport as it stood on a given date, stops being technical hygiene and becomes an operational requirement.
How long does the registry keep registration data?
Registration data is deleted automatically 10 years after registration, unless the law applicable to the product provides otherwise (Article 10(3)). This does not relieve you of retaining technical documentation on your side, where the periods come from sector acts.
Read next
- Verified economic operator — how to get DPP registry access
- ESPR regulation — ecodesign requirements
- Battery passport — EU requirements and timeline
- EU digital product passport — timeline, scope and compliance
- Digital product passport data requirements — the complete list
- GS1 QR code — the 2D code that replaces the barcode
- DPP and PIM — why product data is the foundation
- DPP replaces the EU declaration of conformity
- Conformity assessment — modules A to H1 and the notified body
- How to implement a DPP — the complete checklist
myDPP keeps product data versioned, validated and machine-readable — which is exactly the form a registry submission and its version hash require. Verified economic operator status cannot be outsourced to any provider, including us; that stays with the manufacturer. See myDPP.
Sources
- Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026 on the implementation arrangements for the digital product passport registry — EUR-Lex
- Commission Implementing Decision (EU) 2026/1736 of 14 July 2026 on harmonised standards for the digital product passport — EUR-Lex
- Regulation (EU) 2024/1781 (ESPR), Article 13 — digital product passport registry — EUR-Lex
- Regulation (EU) 2023/1542 (Batteries Regulation), Article 77 — battery passport — EUR-Lex
- Regulation (EU) No 910/2014 (eIDAS) as amended — qualified signatures, seals and attestations of attributes — EUR-Lex
- Regulation (EU) 2025/2509 (Toy Safety Regulation) — EUR-Lex
- Regulation (EU) 2024/3110 (Construction Products Regulation) — EUR-Lex
- European Commission, Digital Product Passport — harmonised standards, Internal Market and Industry