Skip to content

Independent R&D project · Cologne

Back to the blog

Six digital product passport standards reached the Official Journal. The authenticity standard did not.

On 15 July 2026, the European Commission cited six harmonised standards for the EU digital product passport in the Official Journal, giving them presumption of conformity under the ecodesign regulation. The standard covering data authenticity, reliability, and integrity is not one of them.

Published August 9, 2026 6 min read

Three lines converging toward a single teal point on a light background, symbolizing regulatory convergence.

What the Commission cited, and what that does

On 14 July 2026, the European Commission adopted Implementing Decision (EU) 2026/1736, published in the Official Journal of the European Union on 15 July 2026 and in force the same day. It cites six harmonised standards developed for the digital product passport under the EU's ecodesign framework: EN 18216 (data exchange protocols), EN 18219 (unique identifiers), EN 18220 (data carriers), EN 18221 (data storage, archiving, and persistence), EN 18222 (application programming interfaces for managing a passport's life cycle), and EN 18223 (system interoperability). All six were published by CEN-CENELEC on 27 May 2026, developed under the Commission's standardisation request M/604 in support of Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation, known as the ESPR.

Citation in the Official Journal is not a formality. Article 41 of the ESPR states that products complying with a harmonised standard whose reference has been published there are presumed to comply with the corresponding ecodesign requirements set out in the regulation's delegated acts, to the extent those requirements are covered by the standard. In plain terms, build a passport to one of these six standards and the burden shifts: instead of demonstrating compliance case by case, the standard itself does that work, for the requirements it covers.

The standard that is not on that list

Eight harmonised standards were commissioned under M/604 in total, not six. The two still outstanding both concern security: EN 18246, "digital product passport, data authentication, reliability and integrity", and its sibling EN 18239. EN 18246 is the standard meant to let a passport's data be checked for authenticity, tamper-evidence, and reliability, built around what the standard calls an electronically signed data construct. Its formal vote at CEN-CENELEC closed on 16 July 2026, one day after the Commission cited the other six, and publication is expected around September 2026.

The standard's own scope is deliberately narrow. It covers the framework for secure information processing and communication that safeguards the integrity, authenticity, and reliability of data exchanged through a passport. It explicitly does not cover the passport's system architecture, its use cases, or the secure elements and cryptographic security features tied to a data carrier for unique product identification; those belong to sibling standards, including the ones already cited. Until EN 18246 is published and then separately cited by the Commission in a future implementing decision, the presumption of conformity that now covers exchange, identification, carriers, storage, APIs, and interoperability does not extend to authenticity.

Why the gap matters in practice

The absence of a cited standard does not suspend the underlying obligation. Regulation (EU) 2024/1781 already requires, in its own text, that digital product passport data be accurate, complete, up to date, and verifiable; that duty is binding regardless of which harmonised standards exist to help meet it. What is missing is the shortcut. Article 41 also lets the Commission adopt common specifications by implementing act as a fallback where no harmonised standard exists yet, but no such fallback has been adopted for data authenticity either. A company building a passport's authenticity layer today has neither a cited standard nor a common specification to point to, only the regulation's own requirement and its own ability to show how it meets it.

In practice, that means falling back on ordinary means of demonstrating compliance: technical documentation kept on file, a self-declared conformity assessment under the ESPR's general procedure, or a supplier's own attestation, none of which carries the automatic presumption a cited standard provides. That is not a gap in the law; the ESPR's requirement for accurate, complete, and verifiable passport data was never conditional on a standard existing to implement it. It is a gap in the tooling available to prove compliance efficiently, and it will close only once EN 18246 is published and cited.

That gap matters more for authenticity than for most other requirements, because a passport whose data cannot be checked is not much better than a printed label. AnyLAI, for instance, issues its passports signed, with a signature that can be checked against the issuer's published key.

The first real deadline: batteries, 18 February 2027

The ESPR's own delegated acts are still arriving on a separate track. The Commission's first ESPR working plan, adopted 16 April 2025 as COM(2025) 187, names six priority product groups: textiles and apparel, furniture, mattresses, tyres, iron and steel, and aluminium. Indicative dates for their delegated acts run from 2026, for iron and steel, to 2029, for mattresses, and a digital product passport obligation typically follows roughly eighteen months after each delegated act is adopted. None of those obligations has arrived yet.

The nearer deadline sits in a different regulation. Under Regulation (EU) 2023/1542, the EU Battery Regulation, a digital battery passport becomes mandatory from 18 February 2027 for electric-vehicle batteries, light means of transport batteries, and industrial batteries above 2 kWh. That is the first real case where the standards gap described above will be tested in practice. The same date recurs in the registry meant to hold every passport's identifier: Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026, which lays down how the EU digital product passport registry operates, requires each member state to appoint a national registry administrator by 18 February 2027 as well.

What to do now, and what to watch in September

None of this argues for waiting. The six cited standards already give a real, usable presumption of conformity for how a passport is built, identified, carried, stored, exchanged, and made interoperable, and a company assembling a passport today can rely on them now. The requirement that the underlying data be accurate and verifiable is already in force independent of any standard, so the sensible order is to get that data discipline right first and adopt EN 18246 once it exists, not the other way round. AnyLAI, for instance, labels its AI-assisted output as AI-assisted and human-verified.

Two dates are worth watching from here. September 2026 is when EN 18246 and its sibling security standard are expected to publish at CEN-CENELEC, closing the technical gap even before the Commission formally cites them. What happens after that is less predictable: for the six standards already cited, about seven weeks passed between their CEN-CENELEC publication on 27 May 2026 and the Commission's citation on 15 July 2026, but that gap is a precedent, not a guarantee. A company that has its data discipline in order will not need to change course either way; it will simply gain a shortcut it does not yet have.

Key dates

  • 16 April 2025. The first ESPR working plan is adopted (COM(2025) 187), naming six priority product groups.
  • 27 May 2026. The six cited EN 182xx standards are published by CEN-CENELEC.
  • 14 July 2026. The Commission adopts Implementing Decision (EU) 2026/1736.
  • 15 July 2026. Implementing Decision (EU) 2026/1736 is published in the Official Journal and enters into force, giving presumption of conformity to the six standards. (Regulation (EU) 2024/1781, Article 41)
  • 16 July 2026. The formal vote on EN 18246 (and EN 18239) closes at CEN-CENELEC.
  • 16 July 2026. Commission Implementing Regulation (EU) 2026/1778, on the EU digital product passport registry, is adopted.
  • 17 July 2026. Regulation (EU) 2026/1778 is published in the Official Journal.
  • 6 August 2026. Regulation (EU) 2026/1778 enters into force.
  • September 2026 (expected). EN 18246 and EN 18239 are expected to publish at CEN-CENELEC.
  • 18 February 2027. The digital battery passport becomes mandatory (Regulation (EU) 2023/1542); deadline for member states to appoint a national DPP registry administrator (Regulation (EU) 2026/1778, Article 7(1)).

Sources

  • Commission Implementing Decision (EU) 2026/1736. Cites six harmonised EN 182xx standards for the digital product passport; adopted 14 July 2026, in force since 15 July 2026.
  • Regulation (EU) 2024/1781 (the ESPR), Article 41. Presumption of conformity for products complying with cited harmonised standards.
  • CEN-CENELEC, Standardisation Request M/604. The eight-standard EN 182xx family for the digital product passport, including EN 18246, not yet cited.
  • Regulation (EU) 2023/1542 (the EU Battery Regulation), Article 77. Digital battery passport mandatory from 18 February 2027.
  • Commission Implementing Regulation (EU) 2026/1778. Governs the EU digital product passport registry; adopted 16 July 2026.
  • European Commission, first ESPR working plan, COM(2025) 187 (16 April 2025). Priority product groups and indicative delegated-act timeline.

Every date above is drawn from the cited instrument's own text or the standards body's own publication record, not from secondary reporting.

This article is informational and is not legal advice. What a given company owes depends on its products and its own facts, and the authoritative EU legal texts prevail over any summary of them.

Written by Luiz Hogrefe.

Share this article

Public feedback

Have a correction, implementation note or different architectural view?

Discuss this articleView the public discussion