Six EN standards now define how a digital product passport must be built
While everyone was watching the EU DPP Registry go live, the more consequential document slipped out three days earlier. On 15 July 2026 the Commission published references to six harmonised standards for the digital product passport. For the first time there is a technical answer to the question "what actually counts as a proper DPP" - and it is an answer you can hold a software vendor to.
What happened on 15 July
Commission Implementing Decision (EU) 2026/1736 of 14 July 2026 published, in the Official Journal, the references of six European standards for digital product passports drafted in support of the Ecodesign Regulation (EU) 2024/1781. They were written by the joint technical committee CEN-CLC/JTC 24, "Digital Product Passport: Framework and System", and issued by CEN and CENELEC on 27 May 2026.
Publishing a reference in the Official Journal is what turns an ordinary European standard into a harmonised one. That single step is why this matters more than the registry launch it got buried under.
The six standards, in plain language
- EN 18219 - unique identifiers. How a product, an operator and a facility are named so that two systems mean the same thing by the same string. This is where GS1 identifiers and other identifier schemes fit in.
- EN 18220 - data carriers. What you physically put on the product. In practice: an ordinary QR code, pointing at ISO/IEC 18004. There is no special DPP symbology to license.
- EN 18216 - data exchange protocols. The transport layer, over HTTPS. How a scanner, a customs system or a recycler's tool actually asks for your passport.
- EN 18222 - APIs and lifecycle management. How passports are created, read, updated and searched, and what happens across the product's life rather than on day one.
- EN 18221 - data storage, archiving and persistence. How long the data must remain available and how versions are kept. The unglamorous standard that decides whether a code printed today still resolves in 2032.
- EN 18223 - system interoperability. The shared model that lets a passport made in one system be read by another without a bespoke integration.
What "harmonised" actually buys you
Following a cited harmonised standard gives you a presumption of conformity with the corresponding requirements in the Ecodesign Regulation. In practice that flips the burden of argument. Without it, you build a passport and hope a market surveillance authority agrees your approach was reasonable. With it, you point at a standard number and the authority has to show you failed to meet it.
You are still allowed to do it differently. Harmonised standards are voluntary, not mandatory. But if you deviate, you carry the job of demonstrating equivalence yourself, and no small brand wants that conversation.
The two that are still missing
The family was designed as eight standards. Two of them, and not the trivial two, have not landed:
- prEN 18239 - access rights management, information system security and business confidentiality.
- prEN 18246 - data authentication, reliability and integrity.
Their formal vote closed on 16 July 2026 and publication is expected later in 2026, with the Official Journal citation following after that. Read the gap for what it is: the layer that decides who gets to see your supplier list and how anyone knows a passport is genuine is the layer that is not yet settled. If a vendor is currently selling you a fully standards-compliant tiered access model, they are selling you their interpretation of a draft.
What this changes for your brand today
Legally, nothing. No garment needs a passport because six standards got cited. What changes is that you now have a vocabulary for buying.
Until July, "is your DPP tool compliant?" was an unanswerable question, and every vendor answered yes. Now it decomposes into six specific ones you can put in an email:
- Which identifier scheme do you use, and does it follow EN 18219? What happens if I do not have a GTIN?
- Is the carrier a plain QR code per EN 18220, or something proprietary I would be locked into?
- Can another system read my passports through a documented API, per EN 18222 and EN 18223, or only your app?
- Under EN 18221, how long do you guarantee my passport URLs resolve? Put a number in the contract, because label print runs outlive subscriptions.
- Can I export everything if I leave, and in what format?
- For access levels: what are you doing now, given that prEN 18239 is still a draft, and what will change when it publishes?
That last one is the good filter. A vendor who says "the security standard is still in draft, here is our current approach and here is what we expect to change" is a vendor who reads the source documents. A vendor who claims full compliance with all eight standards today is not.
What has NOT changed
- No product category has a passport obligation today. The standards describe how a passport must be built, not who must have one.
- The first hard date is still the battery passport on 18 February 2027.
- For textiles, the delegated act is expected in 2027 and real obligations land realistically in 2028-2029.
- The registry rules from Implementing Regulation (EU) 2026/1778 apply from 6 August 2026, and the ban on destroying unsold apparel has been in force for large companies since 19 July 2026.
One more thing on the watch list. Under the Battery Regulation the Commission was due to adopt, by 18 August 2026, an implementing act defining who counts as a person with a "legitimate interest" in battery passport data. As of the date on this article it has not appeared in the Official Journal. If it slips, battery makers spend the run-up to February 2027 guessing who they are building the middle access tier for.
What to do with this
- Shortlisting a DPP tool? Send the six questions above before you look at a price list.
- Already building in-house? EN 18219, EN 18220 and EN 18223 are the three to read first, because they constrain decisions that are expensive to reverse later.
- Everyone else: nothing to do this month. Put your category's date in the deadline calendar and let the standards settle.
If you want to see what the output of all this looks like in practice, our free passport generator builds a live page with a working QR code in about a minute.
FAQ
Do I have to follow the EN 18xxx standards?
No. Harmonised standards are voluntary. Following them gives you a presumption of conformity with the corresponding Ecodesign Regulation requirements; deviating means you have to demonstrate equivalence yourself.
Does this mean digital product passports are mandatory now?
No. The standards define how a passport is built. Whether your product needs one is decided separately, category by category, through delegated acts. Batteries come first on 18 February 2027.
Which standards are still missing?
Two: prEN 18239 on access rights, security and business confidentiality, and prEN 18246 on data authentication and integrity. Their formal vote closed on 16 July 2026 and publication is expected later in 2026.
Do I need a special QR code for a DPP?
No. EN 18220 points at ordinary QR codes under ISO/IEC 18004. What matters is the address behind the code and how long it keeps resolving, not the symbology.
My vendor says they are fully compliant with the DPP standards. Is that possible?
Not with all eight, since two are still drafts. Full compliance with the six cited ones is possible and worth asking them to evidence, standard by standard.