Six EN standards now define how a digital product passport must be built

By Łukasz Głuch · 3 August 2026 · DPPera

DPPera - Standards: EN 18216-18223

While everyone was watching the EU DPP Registry go live, the more consequential document slipped out three days earlier. On 15 July 2026 the Commission published references to six harmonised standards for the digital product passport. For the first time there is a technical answer to the question "what actually counts as a proper DPP" - and it is an answer you can hold a software vendor to.

What happened on 15 July

Commission Implementing Decision (EU) 2026/1736 of 14 July 2026 published, in the Official Journal, the references of six European standards for digital product passports drafted in support of the Ecodesign Regulation (EU) 2024/1781. They were written by the joint technical committee CEN-CLC/JTC 24, "Digital Product Passport: Framework and System", and issued by CEN and CENELEC on 27 May 2026.

Publishing a reference in the Official Journal is what turns an ordinary European standard into a harmonised one. That single step is why this matters more than the registry launch it got buried under.

The six standards, in plain language

What "harmonised" actually buys you

Following a cited harmonised standard gives you a presumption of conformity with the corresponding requirements in the Ecodesign Regulation. In practice that flips the burden of argument. Without it, you build a passport and hope a market surveillance authority agrees your approach was reasonable. With it, you point at a standard number and the authority has to show you failed to meet it.

You are still allowed to do it differently. Harmonised standards are voluntary, not mandatory. But if you deviate, you carry the job of demonstrating equivalence yourself, and no small brand wants that conversation.

The two that are still missing

The family was designed as eight standards. Two of them, and not the trivial two, have not landed:

Their formal vote closed on 16 July 2026 and publication is expected later in 2026, with the Official Journal citation following after that. Read the gap for what it is: the layer that decides who gets to see your supplier list and how anyone knows a passport is genuine is the layer that is not yet settled. If a vendor is currently selling you a fully standards-compliant tiered access model, they are selling you their interpretation of a draft.

What this changes for your brand today

Legally, nothing. No garment needs a passport because six standards got cited. What changes is that you now have a vocabulary for buying.

Until July, "is your DPP tool compliant?" was an unanswerable question, and every vendor answered yes. Now it decomposes into six specific ones you can put in an email:

That last one is the good filter. A vendor who says "the security standard is still in draft, here is our current approach and here is what we expect to change" is a vendor who reads the source documents. A vendor who claims full compliance with all eight standards today is not.

What has NOT changed

One more thing on the watch list. Under the Battery Regulation the Commission was due to adopt, by 18 August 2026, an implementing act defining who counts as a person with a "legitimate interest" in battery passport data. As of the date on this article it has not appeared in the Official Journal. If it slips, battery makers spend the run-up to February 2027 guessing who they are building the middle access tier for.

What to do with this

If you want to see what the output of all this looks like in practice, our free passport generator builds a live page with a working QR code in about a minute.

FAQ

Do I have to follow the EN 18xxx standards?

No. Harmonised standards are voluntary. Following them gives you a presumption of conformity with the corresponding Ecodesign Regulation requirements; deviating means you have to demonstrate equivalence yourself.

Does this mean digital product passports are mandatory now?

No. The standards define how a passport is built. Whether your product needs one is decided separately, category by category, through delegated acts. Batteries come first on 18 February 2027.

Which standards are still missing?

Two: prEN 18239 on access rights, security and business confidentiality, and prEN 18246 on data authentication and integrity. Their formal vote closed on 16 July 2026 and publication is expected later in 2026.

Do I need a special QR code for a DPP?

No. EN 18220 points at ordinary QR codes under ISO/IEC 18004. What matters is the address behind the code and how long it keeps resolving, not the symbology.

My vendor says they are fully compliant with the DPP standards. Is that possible?

Not with all eight, since two are still drafts. Full compliance with the six cited ones is possible and worth asking them to evidence, standard by standard.

Get DPPera Brief - a short monthly monitor of EU DPP regulations. Subscribe here or grab the free DPP guide.