top of page

Standards · CEN/CENELEC JTC 24

Europe
DPP standards announced.

On May 27, 2026, CEN and CENELEC published the first 6 European standards for DPP; 2 additional standards covering access rights and data authentication are in the final stage and will be published in September.

ChatGPT Image 7 Eyl 2026 12_45_21 1

Aligned with European Standards,
Ready for the Future.

LEGAL STATUS

Summarized Information Cited in the Official Journal of the EU

Publication by CEN/CENELEC and inclusion in the Official Journal of the EU are separate stages. Six of these standards — EN 18216, EN 18219, EN 18220, EN 18221, EN 18222, and EN 18223 — are referenced in Commission Implementing Decision (EU) 2026/1736, published in the Official Journal on July 15, 2026. Compliance with a referenced standard now establishes a presumption of conformity with the relevant ESPR requirements (Articles 10 and 11). FprEN 18239 and FprEN 18246 are not referenced and therefore fall outside this presumption.

If a vendor claims that its system is “certified according to DPP standards,” ask which standard, which clause, and who issued the certification: the reference published in the Official Journal establishes a presumption of conformity for a product that meets the applicable requirements; however, it does not establish a certification scheme, and as of July 2026, no valid certification scheme exists.

EN 18216:2026 · Published on 27 May 2026

EN 18216:2026 – Data Exchange Protocols

EN 18216:2026 specifies the protocols used to exchange Digital Product Passport data between systems — defining how passport data is transferred between economic operators, service providers, authorities, and other participants.

​

Why it matters. Data exchange is often where vendor lock-in is hidden. A standardized transfer protocol means that a passport created in one system can be read by another without requiring a custom integration for every counterpart.

​

DPPVisa provides passports over open, content-negotiated HTTP (HTML, W3C JSON-LD, AAS), allowing any standards-compliant consumer to read them.

EN 18220:2026 · Published on 27 May 2026

EN 18220:2026 — Data Carriers

EN 18220:2026 defines the physical data carriers that link a product to its passport — including scannable QR / 2D Data Matrix codes, NFC, and RFID — and specifies how a carrier encodes the unique identifier.

​

Why it matters. The carrier is the only part of the passport that a consumer physically interacts with: a single scan should open the correct record for the correct unit, even years after the product has entered service.

DPPVisa generates print-ready GS1 Digital Link QR codes (PNG/SVG), including unit-level codes carrying the actual serial number in GS1. NFC and RFID carriers are within the scope of the standard.

EN 18222:2026 · Published on 27 May 2026

EN 18222:2026 – APIs for Lifecycle Management

and Searchability

EN 18222:2026 specifies application programming interfaces for managing a Digital Product Passport throughout its lifecycle (creation, updates, status changes) and for searching passport data.

​

Why it matters. This transforms the DPP from a static web page into infrastructure: ERP/PLM systems, marketplaces, and recyclers need machine APIs, not portals.

DPPVisa provides a REST API for passport creation, lifecycle status changes (active, recalled, decommissioned), unit-level telemetry, and webhook notifications.

EN 18219:2026 · Published on 27 May 2026

EN 18219:2026 — Unique Identifiers

EN 18219:2026 defines the unique identifiers at the heart of every Digital Product Passport: the Unique Product Identifier (UPI), Unique Operator Identifier (UOI), and Unique Facility Identifier (UFI), along with the rules for their creation and resolution.

Why it matters. The identifier is the passport’s primary key for the next 10+ years — what the EU registry will index and what every QR code ultimately resolves to.

​

DPPVisa issues GS1-based identifiers (GTIN/GRAI product keys and mod-10 validated GLN facility identifiers) and resolves them through GS1 Digital Link URIs.

EN 18239 · Published on 15 September 2026

EN 18239 — Access Rights Management

Final draft — publication expected around September 2026. It defines how access to restricted passport data should be managed — which roles (authorities, repairers, recyclers, legitimate-interest parties) can access which data layers, and how this should be implemented and documented. DPPVisa’s RBAC-based access controls and legitimate-interest access flow are built around the draft’s layered access model.

EN 18246 · Published on 15 September 2026

EN 18246 — Data Authentication and Integrity

Final draft, under formal vote. It defines how passport data is authenticated — using Electronic Signature Data Structures (ESDC) so that any party can verify that a passport genuinely originates from the stated operator and has not been altered. DPPVisa seals passports with eIDAS advanced electronic seals.

GS1 Digital Link

GS1 Digital Link Compatibility

Every product and unique link is a standards-compliant GS1 Digital Link. It is validated in the CI environment against GS1’s official Barcode Syntax Engine, ensuring that the QR codes you print comply with the standards and can be resolved through the GS1 gateway.

Beyond the EN 182xx Series

Interoperability and Verifiable Data

The EN 182xx standards define the information that must be included in a passport. These are open, machine-verifiable formats published at DPPVisa.com; each is validated against an official schema or an independent reference implementation, ensuring that your data remains portable with ready-to-use tools.

Asset Administration Shell (AAS v3.0/3.1)

Each passport is exported as an IDTA Asset Administration Shell environment, validated against the official AAS 3.1 JSON Schema and the IDTA aas-test-engines 3.0 gold standard; it can be opened directly in the AASX Package Explorer or BaSyx.

Credentials Aligned with UNTP Digital Product Passport Standards

Each passport is issued as both a compact vc+jwt (W3C VC-JOSE-COSE) and an embedded W3C Data Integrity credential (ecdsa-jcs-2019); these credentials are validated against the official UNTP schema using resolvable did:web issuer keys.

did:web Keys and W3C Bitstring
Status Lists

Issuer keys are resolved via did:web addresses and rotated without invalidating previous signatures; revocation uses the W3C Bitstring Status List, ensuring that a recalled or reused unit returns a signed and verifiable status.

GS1 EPCIS 2.0 Traceability

Supply chain events are recorded and republished as standards-compliant GS1 EPCIS 2.0 documents; these documents are validated against the official 2.0.1 JSON Schema at GS1, and traceability information is presented as a signed provenance graph spanning from raw materials to the finished product.

SD-JWT Selective Disclosure

With SD-JWT-VC, the credential holder can disclose individual claims, such as a single material or performance value, without revealing the entire passport, validated against the strict SD-JWT-VC specification.

Primary Sources

Where Do These Facts Come From?

Standards Status: CEN/CENELEC (JTC 24 publications, 27 May 2026). Regulatory basis: Regulation (EU) 2024/1781 (ESPR) and the European Commission’s ESPR implementation hub. For the entry-into-force timeline, see the ESPR timeline; for the registry system, see the EU DPP Registry explainer.

bottom of page