We logged in to the EU DPP Registry. You still cannot register a passport in it.

By Łukasz Głuch · 19 August 2026 · DPPera

DPPera - Field report: Registry v1.0.11

We logged in to the European Commission Digital Product Passport Registry on 17 August 2026 and walked as far through it as it currently goes. This is what is actually there. Most of what follows is not in any vendor blog post, because it comes from the system and from the official user guide rather than from second-hand reporting. Version seen: 1.0.11.

The registry accepts organisations. It does not accept passports.

This is the headline, and it is stated by the Commission itself in the DPP Registry User Guide for Economic Operators (v1.01, 28 July 2026):

Successful registration of DPPs for batteries is not currently available, as the semantic catalogue for this product group has not yet been defined. Currently, it is not possible to successfully register DPPs.

Batteries are the only product group offered. Item level is the only granularity offered. The semantic catalogue that would let the system validate a submission does not exist yet. So today the registry is an enrolment system with a registration feature switched off.

That is not a scandal. The registry went live on 20 July against a legal deadline, and building the index before the content is the right order. But it does change what you should be doing this quarter: there is nothing to gain by rushing to register, and quite a lot to gain by being ready to.

What enrolment actually demands

Enrolment is the process that turns your company into a verified economic operator. It has seven steps, and the interesting part is step four, which happens outside the registry entirely.

  1. You submit your organisation details.
  2. You give the name and email of your legal representative.
  3. The system generates a PDF declaration sealed by the European Commission.
  4. Your legal representative signs or seals that PDF offline, using a qualified electronic signature or seal from a qualified trust service provider.
  5. You upload the countersigned file.
  6. You submit it for verification.
  7. You watch the outcome in the activity dashboard.

The practical consequence is easy to miss: the qualified credential is used to sign a document, not to log in. You authenticate to the registry with an ordinary EU Login account. The eIDAS-grade credential is applied to a file on your own machine. If you were expecting to integrate with a signature provider, you were preparing for the wrong thing. What you actually need is a file upload and a way to track application states.

The details that will get applications rejected

The guide lists the rejection reasons in full, and they cluster into three groups.

Read that list again as a buyer. Every one of those failure modes lands on a person in your company who has never heard of PAdES profiles. If a DPP supplier tells you they will handle enrolment, ask them to describe those four checks. It is a fast way to find out whether they have ever seen the system.

The test environment will not let you rehearse

There is an acceptance environment at a separate address, and it is genuinely useful for seeing the screens. It is not useful for rehearsing the hard part, because chapter 8 of the guide says the quiet part out loud:

The verification process used in the Test environment is the same as in Production. To create an organisation in Test, you must successfully verify it there using valid organisation data and the required signatures/seals.

So you cannot practise enrolment with dummy data and a self-signed PDF. Without a real qualified seal you can walk to step three, download the declaration, read what your legal representative is being asked to attest to, and stop. That is still worth doing, because the declaration is a document your legal team will want to see before anyone signs anything.

Three components the regulation requires that are not there yet

Implementing Regulation (EU) 2026/1778 lists what the registry consists of. Three of those components are absent from the current build, and the gap matters commercially rather than technically.

If you are a manufacturer, the third point is the one to note. Whatever your supplier promises about handling registration for you, the current system expects you to hold the EU Login account and your legal representative to hold the qualified seal. That is a task for your organisation, not one you can fully outsource today.

The fifty-character rule

One number in the guide will shape your architecture more than anything else in this article. The unique product identifier you register is a URL, it must use https, and its maximum length is fifty characters. Validation also rejects excessive redirects and any downgrade to a less secure protocol.

Do the arithmetic on your own domain before you design anything. A GS1 Digital Link path carrying a product code, a variant, a batch and a serial number will not fit inside fifty characters on any realistic domain. A short opaque path will, with room to spare.

Update, 17 August 2026. We put this to the Commission helpdesk. The answer: the fifty-character limit reflects the current version of the registry, the Commission acknowledges it may not accommodate all identifier formats permitted by the JTC 24 standards including certain GS1 Digital Link implementations, and the allowed length will be increased in the next version. So treat fifty as today constraint rather than a permanent design rule. The two rules below survive the change regardless, because neither has anything to do with length.

Two rules follow, and they are cheap to adopt now and expensive to retrofit later:

What the Commission helpdesk told us

We asked the DPP helpdesk five questions on 17 August 2026. The answers are worth more than the screens, because they are dates.

Put the first three together and the sequencing becomes clear. Machine integration arrives about a year before the service-provider framework does, and the first mandatory passports arrive in between. If you make batteries, you should plan to hold your own registry identity in February 2027, because there is no recognised intermediary role in your regulation to hide behind.

What to do with the next three months

Nothing here creates urgency about registering. It creates urgency about being ready, which is a different and cheaper kind of work.

FAQ

Can I register a battery passport today?

No. The guide states that successful registration is not currently available because the semantic catalogue for batteries is undefined.

Do I need a qualified seal just to log in?

No. Logging in uses an ordinary EU Login account. The qualified seal or signature is applied to a PDF declaration outside the system.

Can my DPP supplier register passports for me?

The Ecodesign framework allows it under Article 19(4) if the supplier is itself verified, but the interface has no such path yet, the recognition procedure does not exist, and the criteria are expected in a delegated act around Q2 2027. For batteries specifically, the Batteries Regulation does not recognise DPP service providers as an actor at all. Today the operator does it.

Is the verification permanent?

No. The success report states the expiry date of the signature or seal, and verification status expires with it.

How long can my passport URL be?

Fifty characters in the current version, https, no excessive redirects. The Commission has confirmed the length limit will be raised in the next release; the https and no-redirect requirements are not going anywhere.

Get DPPera Brief - a short monthly monitor of EU DPP regulations. After confirming you get the DPP Readiness Guide plus our reader's guide to the Commission DPP FAQ (PDF). Subscribe here.