Verified economic operator — how to get DPP registry access
Without verified economic operator status you cannot register a single digital product passport. How to choose your electronic identity means, obtain a qualified electronic seal and who may register on your behalf.
Verified economic operator — how to get DPP registry access
The EU digital product passport registry has been open since 20 July 2026, and Implementing Regulation (EU) 2026/1778 has applied since 6 August. The question manufacturers ask most often is “when does this start applying to my category?” It is a reasonable question, but for now it is the wrong one — because the first step, without which nothing else is possible, has no product deadline at all and can be completed today.
That step is obtaining verified economic operator status. The registry does not accept submissions from anonymous senders: before you register your first passport, your company must prove its identity using qualified electronic identity means under the eIDAS Regulation. The procedure runs through an external trust service provider, so it is measured in weeks rather than minutes — which is exactly what makes it the best candidate for work you close out early. If you are new to the topic, start with DPP in 15 minutes, and for the full mechanics of the registry itself see our article on the registry.
Key takeaways
- Verified economic operator status (Article 4 of Regulation 2026/1778) is a precondition for every passport registration and does not wait for the delegated act covering your category.
- A legal person proves identity with a qualified electronic seal. A natural person trading as a sole trader uses a qualified electronic signature, a high-assurance eID means or a qualified electronic attestation of attributes.
- You buy a qualified seal from a qualified trust service provider (QTSP) on a national trusted list — not from a DPP software vendor.
- Status lasts as long as the identity means it rests on, and never longer than three years (Article 4(4)).
- You cannot buy your own verification from anyone, but once verified you may authorise a verified third party to register passports on your behalf (Article 19(4)). Responsibility stays with you.
- This is not the Authorised Economic Operator (AEO) status from customs law. The similar names are misleading and expensive.
- The nearest hard deadline: 18 February 2027 — mandatory registration of battery passports.
This is not AEO — the most common and costliest mix-up
Before the procedure itself, one misunderstanding is worth defusing, because it keeps coming up in conversations with compliance teams. The “verified economic operator” in the DPP registry regulation has nothing to do with the “Authorised Economic Operator” (AEO) of the Union Customs Code. The confusion is helped along by the fact that the DPP registry stores a customs commodity code with every registration, so the two worlds do touch in the data.
| Authorised Economic Operator (AEO) | Verified economic operator (DPP) | |
|---|---|---|
| Legal basis | Union Customs Code (EU) No 952/2013 | Implementing Regulation (EU) 2026/1778, Article 4 |
| Who grants it | National customs administration | Verification against the Commission, inside the DPP registry |
| Basis for granting | Company audit: solvency, compliance history, supply chain security | Identity proof using a qualified eIDAS means |
| Time to obtain | Months, with on-site inspection | Weeks, mostly on the trust service provider’s side |
| What it gives you | Customs simplifications, fewer checks | The ability to register passports in the registry |
| Validity | Open-ended, with monitoring | Max. 3 years, then re-verification |
If your company holds AEO status, it does not shorten the road to the DPP registry by a single day. And the reverse is equally true — verification in the DPP registry grants no customs privileges.
Three roles in the registry — which one do you actually need
The regulation provides for separate roles with separate permissions. Picking the wrong one costs weeks, so it is worth settling before your first call to a trust service provider.
| Role | Basis | Who this is | What it can do |
|---|---|---|---|
| Verified economic operator | Art. 4 | Manufacturer, importer, authorised representative — the party responsible for placing the product on the market | Register passports, modify its own entries, download proof of registration |
| Verified value chain actor | Art. 5 | Repairers, refurbishers, recyclers | Read and add data within the scope of its permissions |
| DPP service provider | Art. 3(f) | A provider of passport services, listed in the public list maintained by the registry | Act for economic operators; the list itself is public |
For the large majority of manufacturers the first role is the right one. The second is worth planning for when your business model assumes an authorised service centre or a recycler adds to the product’s history — their access needs formal verification too, and it takes just as long.
Which legal entity in the group should be verified
Status attaches to a legal person — not to a brand, not to a corporate group, not to a manufacturing site. That sounds obvious until you look at the typical structure of a mid-sized manufacturer, where the holding company, the trading company and the production company are three different entities with three different registration numbers.
The rule of thumb is simple: verify the entity that faces the market as the economic operator for that product — the one whose name and address appear on the product and on the EU declaration of conformity. If two companies in the group place products on the market under their own name, you will need two verifications and two seals.
Three situations worth settling on paper before you start:
- Importer. A party placing a non-EU manufacturer’s products on the EU market is an economic operator in its own right under harmonisation law. It verifies itself, on its own account.
- Authorised representative. It acts under a mandate from a non-EU manufacturer, but in the registry it appears as a separate entity and needs its own identity means.
- Contract manufacturing and own brands. A product sold under a retailer’s brand has that retailer as its manufacturer in the legal sense, not the plant that built it. The party whose name is on the product is the one that verifies.
The most common mistake at this stage: verifying a holding company that never appears on any product. The seal is then technically valid and operationally useless.
Seal or signature — choosing your identity means
The regulation splits the means by the nature of the entity, not by company size or sector.
Legal persons
A company proves its identity and establishment with a qualified electronic seal based on a qualified certificate for electronic seal, issued by a qualified trust service provider, or with a qualified electronic attestation of attributes provided for under Union law (Article 4(2)).
The key distinction, easily missed: a seal belongs to the entity, not to a human being. The certificate is issued to the company, not to the CEO. A board member’s qualified electronic signature does not substitute for a company seal — these are two different means with two different legal functions. A company that has signatures for its directors does not yet have anything usable for the DPP registry.
Natural persons and sole traders
A sole trader proves identity with a qualified electronic signature based on a qualified certificate, an electronic identification means at assurance level “high”, or a qualified electronic attestation of attributes (Article 4(1)). In this case the registry also stores a national identifier — an identity document number or a tax identifier.
Entities outside the Union
Manufacturers and other parties outside the EU that are not required to be established in the Union prove identity with a qualified signature or an attestation of attributes, without the establishment-proof element. In practice this means engaging a provider operating under the eIDAS regime even if the company has no European entity.
How to obtain a qualified seal — five steps
1. Choose a qualified trust service provider
Only bodies entered on a national trusted list maintained by a Member State may issue qualified certificates. The lists are public and collected in the European Commission’s trusted list browser. You do not have to pick a provider from your own country: a qualified certificate issued in any Member State is effective across the Union. Before you sign, check that the provider is listed for the seal certificate service, not only for signatures — these are separate entries.
2. Decide on the medium
A qualified seal requires a qualified seal creation device. Three variants are available in practice:
- Cryptographic card or token — the cheapest way to start, but it needs physical access to the device on every use. It handles automation poorly.
- An HSM on your own premises — sensible at scale and with your own operations team.
- Remote sealing at the provider — the key stays in the provider’s infrastructure and access runs through an API. This is the only variant genuinely suited to bulk registration through the registry API.
If you plan to register individual models by hand, a card will do. If your products will be registered per batch or per item, the choice of medium determines whether this can be automated at all — and that decision is better made before purchase than after.
3. Assemble the documents
The provider verifies that the entity exists and that the person applying on its behalf is authorised to do so. You will typically need: a current extract from the commercial register, company identification data, a document proving the representative’s authority and their identity document. Where structures involve powers of attorney, prepare them in advance — this is the single most common source of delay.
4. Complete identity verification
The applicant undergoes identity verification: in person, before a notary, or remotely if the provider offers qualified video identification. The method and the availability of the remote option differ between Member States and between providers — worth asking about on first contact, because it can decide the difference between a week and a month.
5. Collect the certificate and diarise the expiry date immediately
Qualified certificates for seals are usually issued for one, two or three years. The expiry date is not a formality — after it the seal stops working, and with it your ability to register new passports. Put it in the compliance calendar in the same hour you collect the certificate.
What happens on the registry side
With a qualified identity means in hand, you complete verification in the registry itself: the system confirms the entity’s identity and establishment, grants verified economic operator status and opens access for registration — through the web interface or through the API.
From that point every passport registration is signed or sealed with your means, and the registry records the product identifier, the commodity code, the registrant’s identity, a timestamp and a cryptographic hash of the passport version. A submission without a valid signature or seal is rejected.
It is worth noticing what this implies for data: the hash binds the registration to one specific version of the passport content. Changing data without version management drifts away from what the registry holds. Versioning stops being good practice and becomes a structural requirement — we cover this at greater length in the article on DPP and PIM.
Who may register on your behalf
This question comes up in every conversation with a manufacturer and deserves a precise answer, because the popular version (“the status cannot be delegated”) is a simplification that leads to bad purchasing decisions.
What cannot be done: you cannot buy someone else’s status, and you cannot outsource proving your own identity. Your entity verifies itself, with its own qualified means. A software vendor will not become a verified economic operator “for you”, because verification attaches to a specific legal person.
What can be done: the regulation expressly allows a verified economic operator to authorise a third party to carry out registrations on its behalf — provided that third party has itself completed the verification process under Article 5. The economic operator remains fully responsible for what is submitted (Article 19(4)).
The practical consequence when choosing a vendor: the question “can you do this for us?” only has a meaningful answer if the vendor is itself verified. Three control questions are worth asking:
- Has your entity been verified in the registry, and under which role?
- Do you appear in the public list of DPP service providers maintained by the registry (Article 3(f))?
- Under the authorisation model, are we still responsible for the content of submissions — and how do you give us visibility into what you submit?
The answer to the third question is “yes, you are responsible”, and it should be. A vendor suggesting it takes over responsibility for the compliance of submissions has either not read the regulation or is making a promise it cannot keep.
Three years — how not to lose status mid-season
Two independent clocks run against your status, and it expires when the first of them goes off:
- The certificate clock. The qualified seal certificate was issued for one, two or three years — your contract with the trust service provider decides.
- The regulation clock. Verified status lasts no longer than three years from the date of verification, regardless of how long the certificate itself remains valid (Article 4(4)).
A company that obtains a seal in 2026 and forgets about it loses the ability to register new passports in 2029 — not through an inspection, but quietly, in the middle of ordinary trading. Three things put this right:
- A reminder three months before the earlier of the two dates, not a week before.
- A named owner and a deputy — status tied to one person’s private calendar leaves the company when they do.
- Renewal treated as a recurring item in the compliance register, alongside technical documentation reviews and conformity assessment.
Five mistakes that cost weeks
- Verifying the wrong company. The holding entity instead of the one whose name is on the product. You start over.
- Buying the wrong certificate. An ordinary organisation certificate, an SSL certificate or a non-qualified seal do not meet the requirement. The word “qualified” and the provider’s trusted-list entry are what count.
- Confusing a seal with the CEO’s signature. A natural person’s qualified signature does not prove a legal person’s identity.
- Assuming the DPP vendor handles it. It can do the registration for you if it is itself verified — but it cannot do your verification for you.
- Starting in the month the product deadline lands. Obtaining an identity means is measured in weeks and depends on an external provider’s calendar you do not control.
FAQ
Do I need status now, when my category has no delegated act yet?
Formally there is no obligation until you have passports to register. Practically this is the one task in the whole DPP area that can be closed without waiting for anything: it does not depend on a delegated act, on data readiness or on your choice of software. If you make batteries covered by the 18 February 2027 deadline, the window for handling this calmly is closing now.
Can a DPP software vendor obtain the status for me?
No. Verification attaches to your legal person and rests on an identity means issued to your entity. The vendor can, however — if it is itself verified — carry out registrations on your behalf under an authorisation (Article 19(4)), with responsibility for submissions remaining with you.
What does it cost?
The cost sits with the trust service provider and depends on the medium you choose and the certificate’s validity period; remote sealing with API access is usually more expensive than a cryptographic card. Against a DPP implementation budget it is a small line item — the real risk here is schedule, not price.
Can I use the same seal for other purposes?
Yes. A qualified electronic seal is a general eIDAS instrument — it seals invoices, technical documentation, declarations of conformity and correspondence with authorities. The DPP registry is one of its uses, not a separate product. Worth counting in when you justify the purchase.
We are an importer, not a manufacturer. Does this apply to us?
Yes. An importer placing a non-EU manufacturer’s products on the EU market is an economic operator in its own right and verifies on its own account. The same goes for an authorised representative. We cover the division of roles further in the article on GPSR and general product safety.
Read next
- EU Digital Product Passport Registry — live since July 2026
- ESPR regulation — ecodesign requirements
- Battery passport — EU requirements and timeline
- DPP timeline, scope and compliance
- EU declaration of conformity — template and mandatory fields
- Conformity assessment — modules A–H1 and the notified body
- DPP and PIM — why product data is the foundation
- How to implement DPP — the complete checklist
myDPP keeps product data versioned, validated and machine-readable — the form a registry submission and its version hash require. Verifying your own entity is something you must do yourself; we help with what happens afterwards. See myDPP.
Sources
- Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026 on implementing arrangements for the digital product passport registry — Articles 3, 4, 5 and 19 — EUR-Lex
- Regulation (EU) No 910/2014 (eIDAS) as amended by Regulation (EU) 2024/1183 — qualified signatures, seals and attestations of attributes — EUR-Lex
- Regulation (EU) 2024/1781 (ESPR), Article 13 — the digital product passport registry — EUR-Lex
- Regulation (EU) 2023/1542 (Batteries Regulation), Article 77 — the battery passport — EUR-Lex
- Regulation (EU) No 952/2013 — Union Customs Code, Authorised Economic Operator (AEO) status — EUR-Lex
- European Commission, trusted list browser (eIDAS Dashboard) — list of qualified trust service providers