On 20 July 2026 the European Commission opened the Digital Product Passport registry, and on 6 August 2026 the rules governing it entered into force under Commission Implementing Regulation (EU) 2026/1778. Six days earlier, Commission Implementing Decision (EU) 2026/1736 published the first six harmonised standards for digital product passports in the Official Journal. In seven weeks, evaluating digital product passport software went from "what does the demo look like" to "show me the registration identifier the registry returned."
The DPPAutomate team read those instruments against the consolidated texts on 27 August 2026 and turned them into the 12 questions below. Each is anchored to a named article, so it is not our opinion about good product design, it is an obligation you can point at across the table. If you want the head-to-head vendor view instead, that lives on our DPP software comparison page, and the procurement process around it on the DPP buying guide. This is the method, not the ranking.
How we chose these 12 questions
No single digital product passport solution fits everyone, because the obligation that binds you is set per product group. A textile brand issuing at model level and an EV battery maker issuing at item level are buying two different things. What is constant is the set of duties any platform must satisfy, so we selected against these criteria:
- Traceable to an obligation. Every question points at an article in Regulation (EU) 2024/1781 (ESPR), Regulation (EU) 2023/1542 (Battery Regulation) or Implementing Regulation (EU) 2026/1778. Where a criterion is a preference rather than a duty, the entry says so.
- Discriminating. A question every vendor answers identically wastes a call slot.
- Verifiable in 30 minutes. Each asks for an artefact: an API response, a document, a version string.
- Durable past the first delegated act. Questions that only test today's feature list expire before your contract does.
- Covering the whole chain. Issuance, registration, carriers, identifiers, supplier data, access control, persistence and exit.
- Uncomfortable on purpose. Four of the twelve are questions a vendor would rather not be asked.
The 12 questions at a glance
DPPAutomate serves European brands, manufacturers and importers across batteries, textiles, electronics, furniture, toys, packaging, tyres, steel and aluminium, so these are criteria our own engineering has had to satisfy.
- Which instrument and article puts our products in scope?
- Do you register in the EU registry and return the unique registration identifier?
- Are you a verified actor, and on the registry's list of DPP service providers?
- Which harmonised standards do you conform to, and to which clauses?
- What granularity do you issue at, and what does item level cost at our volume?
- Do you read the semantic repository, or maintain your own mappings?
- What happens when a delegated act changes the data elements after we launch?
- Who hosts the resolver, and how long does the URL keep resolving?
- Where does the mandatory back-up copy live, and who is the provider of record?
- What do we get on the way out, and do the passports survive it?
- How do you collect tier-N supplier data from suppliers who are not your customers?
- What does the auditor view expose, and can you prove the access tiers?
Now let us review each question in detail.
Legal-minimum questions for any DPP platform (1 to 4)
1. Which instrument and article puts our products in scope?
The obligation. There is no general EU duty to carry a passport. ESPR Article 9(1) makes one a condition of placing a product on the market only where a delegated act adopted under Article 4 says so. Other instruments impose it directly: Battery Regulation Article 77, Article 19 of Regulation (EU) 2025/2509 on toys, Article 21 of Regulation (EU) 2026/405 on detergents, and Article 76 of Regulation (EU) 2024/3110 on construction products.
Why it discriminates. A vendor selling a category says "we cover textiles." A vendor selling compliance tells you the ESPR working plan, COM(2025) 187 final, gives an indicative 2027 adoption target for textiles, tyres and aluminium, and that a working-plan entry is not a binding date. Mechanical engineering is not a first-plan priority under ESPR Article 18, but the batteries, steel and electronics inside those machines are. See which products need a DPP.
Highlights:
- Anchored in: ESPR Arts 4, 9(1), 18; Battery Reg Art 77; Toys Art 19; Detergents Art 21
- Ask to see: the instrument and article for each product group, in writing
- Good answer: separates adopted delegated acts from working-plan targets
- Hand-wave: a category list with one blanket year attached
- Deal-breaker if: a binding date is asserted where no delegated act exists
2. Do you register in the EU registry and return the unique registration identifier?
The obligation. ESPR Article 13(4) puts the upload duty on the economic operator and Article 13(5) says the registry returns a unique registration identifier. Implementing Regulation (EU) 2026/1778 provides the registration API (Article 3(b)), generates that persistent identifier (Article 8(8)) and returns it through the channel used (Article 8(10)). Article 9 lets you generate proof of registration: a secure electronic document carrying the product identifier, the responsible operator, a Commission time stamp, a hash of the passport version and a qualified electronic seal, available for 90 calendar days.
Why it discriminates. ESPR Article 15(1) already requires the identifier to be given to customs on release for free circulation from the moment the registry is operational, which it has been since 20 July 2026. A platform built before then and not updated shows a beautiful passport and no identifier. DPPAutomate stores the identifier the registry returns against the SKU and exposes the Article 9 proof as a downloadable artefact from the same API call that created the passport, so the 90-day window is never something your team has to diary.
Highlights:
- Anchored in: ESPR Arts 13(4), 13(5), 15(1); IR 2026/1778 Arts 3(b), 8(8), 8(10), 9
- Ask to see: a live registration and the identifier it returns
- Good answer: the API response plus a downloadable proof of registration
- Hand-wave: screenshots of a passport page with no registry round trip
- Deal-breaker if: the platform cannot produce the Article 9 proof at all
3. Are you a verified actor, and on the registry's list of DPP service providers?
The obligation. Article 3(f) of Implementing Regulation (EU) 2026/1778 makes a list of verified digital product passport service providers a component of the registry itself. Article 4 sets how an operator becomes verified, through a qualified electronic seal or signature under Regulation (EU) No 910/2014, and Article 4(4) caps that status at three years or the expiry of the identification means. Article 19(4) deserves a second reading: a third party registering on your behalf must itself pass the Article 5 verification, and you remain fully responsible.
Why it discriminates. It separates a vendor who has onboarded to the registry from one who has read about it, and it exposes a governance gap most buyers miss. Your verified status expires, and expiry stops you registering new passports or modifying existing ones, so somebody has to own that renewal. "We handle the registry for you" does not say who.
Highlights:
- Anchored in: IR 2026/1778 Arts 3(f), 4, 5, 19(4); Reg (EU) No 910/2014
- Ask to see: the vendor's registry status and its credential renewal process
- Good answer: names the verified actor of record and how expiry is tracked
- Hand-wave: "we take care of the registry" with no named responsible actor
- Deal-breaker if: the vendor registers under its own credentials, unverified
4. Which harmonised standards do you conform to, and to which clauses?
The obligation. ESPR Article 41(2) gives passports conforming to harmonised standards published in the Official Journal a presumption of conformity with the essential requirements in Articles 10 and 11, to the extent covered. Implementing Decision (EU) 2026/1736 published the first six: EN 18216:2026 (data exchange protocols), EN 18219:2026 (unique identifiers), EN 18220:2026 (data carriers), EN 18221:2026 (data storage, archiving and persistence), EN 18222:2026 (APIs for passport lifecycle management and searchability) and EN 18223:2026 (system interoperability).
Why it discriminates. EN 18219 and EN 18220 bite first for anyone printing a carrier onto a physical product, because a non-conformant carrier is one you have already applied to inventory. Before publication, ESPR Article 10(1)(c) and Annex III pointed carriers and identifiers at the ISO/IEC 15459 series, so documentation that still stops there tells you when it was last revised. Our GS1 Digital Link page covers carriers and resolution.
Highlights:
- Anchored in: ESPR Arts 10(1)(c), 41(2), Annex III; Implementing Decision (EU) 2026/1736
- Ask to see: a written conformance statement naming standards and clauses
- Good answer: distinguishes clauses conformed to from clauses out of scope
- Hand-wave: "EN compliant" with no standard number
- Deal-breaker if: the vendor cannot say which of the six apply to your carriers
Durability questions: will this DPP software still work in two years? (5 to 8)
5. What granularity do you issue at, and what does item level cost at our volume?
The obligation. ESPR Article 9(2)(d) requires the delegated act to specify model, batch or item level. Implementing Regulation (EU) 2026/1778 Article 8 adds structure most buyers have not priced in: an item-level passport must carry linked batch and model identifiers where those designs exist (Article 8(4)), a batch-level passport must carry the model identifier (Article 8(5)), and where several Union rules require different granularities, Article 8(3) forces the most granular.
Why it discriminates. Model-level issuance is a spreadsheet problem; item-level issuance at production volume is an infrastructure problem, and Battery Regulation Article 77(1) puts item-level duties on EV, LMT and industrial batteries above 2 kWh from 18 February 2027. This is also where you interrogate pricing structure rather than price: per passport, per SKU, per seat or per API call, the overage rate, and the invoice when a delegated act moves you down a level. Our DPP implementation cost breakdown covers total cost of ownership; the identifier guide covers how GTIN, SKU, batch and serial map onto the three levels.
Highlights:
- Anchored in: ESPR Art 9(2)(d); IR 2026/1778 Arts 8(1) to 8(5); Battery Reg Art 77(1)
- Ask to see: a bulk item-level run with linked batch and model identifiers
- Good answer: a measured throughput figure and a per-unit price at your volume
- Hand-wave: "unlimited passports" with no rate limit or overage schedule
- Deal-breaker if: item passports carry no linked batch and model identifiers
6. Do you read the semantic repository, or maintain your own mappings?
The obligation. Article 11(3) of Implementing Regulation (EU) 2026/1778 requires all passport data to be structured in accordance with the data models and semantic definitions published in the registry's semantic repository, and Article 11(4) requires those models to be versioned. Article 12 makes the Commission maintain that repository as the authoritative machine-readable source across all product groups, with a search service, publicly documented APIs (Article 12(6)) and access free of charge (Article 12(7)). Article 8(7)(a) checks semantic conformity automatically at registration.
Why it discriminates. A vendor maintaining hand-built mapping tables carries a maintenance liability that becomes yours the moment the repository publishes a new model version; a vendor reading the repository over its documented API inherits the update instead. There is no defensible reason to reimplement a free, authoritative, machine-readable source, so "aligned with EU requirements" is a version string the vendor would rather not name.
Highlights:
- Anchored in: IR 2026/1778 Arts 8(7)(a), 11(3), 11(4), 12
- Ask to see: the repository version string the platform resolves today
- Good answer: consumes the Article 12(6) APIs and re-validates on version change
- Hand-wave: "aligned with EU requirements" with no version or source named
- Deal-breaker if: mappings are hand-maintained and updated on a services ticket
7. What happens when a delegated act changes the data elements after we launch?
The obligation. ESPR Article 9(2)(a) puts the data elements in the delegated act, and Article 4 empowers the Commission to adopt and amend those acts on a rolling basis; Battery Regulation Article 77(2) does the same for Annex XIII. Implementing Regulation (EU) 2026/1778 Article 10(2) requires the registry to support versioning of registered data with a Commission time stamp on each update, and Article 11(4) versions the data models behind it.
Why it discriminates. This is the best question on the list and almost nobody asks it, because it is the only one that tests the platform you will own in year three rather than the one you are shown in week one. Every passport already issued becomes a migration when the required elements change. A real answer names a mechanism, and says whether that work sits inside the subscription or arrives as a services quote.
Highlights:
- Anchored in: ESPR Arts 4, 9(2)(a); Battery Reg Art 77(2); IR 2026/1778 Arts 10(2), 11(4)
- Ask to see: a written change procedure for a data model version bump
- Good answer: diff, flag, backfill and re-register, with commercial terms attached
- Hand-wave: "we monitor regulatory developments and keep the platform up to date"
- Deal-breaker if: every regulatory change is quoted as a separate paid project
8. Who hosts the resolver, and how long does the URL keep resolving?
The obligation. ESPR Article 10(1)(a) requires the passport to be connected through a data carrier to a persistent unique product identifier, and Article 10(1)(b) puts that carrier on the product, its packaging or its documentation. Article 9(2)(i) requires an availability period of at least the product's expected lifetime, and Article 11(e) requires the passport to stay available for that period including after insolvency, liquidation or cessation of activity in the Union of the operator that created it. Toys Article 19(2)(g) fixes that at 10 years, and EN 18221:2026 covers persistence.
Why it discriminates. The carrier is printed, moulded or etched, so it cannot be reissued because a URL structure changed. Persistence is an architectural property of the resolver, not a support policy, and the good answer names an operator, a documented URI structure, and a written commitment that the URI survives a platform migration. Uptime percentage is a preference rather than an obligation, since no instrument sets a resolver availability figure. Put it in the contract anyway.
Highlights:
- Anchored in: ESPR Arts 9(2)(i), 10(1)(a), 10(1)(b), 11(e); Toys Art 19(2)(g); EN 18221:2026
- Ask to see: the resolver domain, URI structure and contractual persistence term
- Good answer: a named operator plus a commitment the URI outlives the contract
- Hand-wave: an uptime number with no persistence commitment (preference, not obligation)
- Deal-breaker if: the resolver is vendor-branded with no transfer undertaking
Exit and evidence questions vendors would rather skip (9 to 12)
9. Where does the mandatory back-up copy live, and who is the provider of record?
The obligation. ESPR Article 10(4) requires the economic operator, when placing the product on the market, to make available a back-up copy of the passport through a digital product passport service provider. Annex III, point (l), makes the reference to that provider a data element of the passport itself, and Implementing Regulation (EU) 2026/1778 Article 8(7)(e) has the Commission verify the link to the back-up at registration. ESPR Article 11, third subparagraph, empowers the Commission to set requirements for becoming such a provider and, where appropriate, a certification scheme; those rules had not been adopted at the time of writing.
Why it discriminates. If your primary platform and your back-up service provider are the same company, Article 10(4) is satisfied on paper and the concentration risk is total. The follow-up that matters is what happens under Article 11(e) if that company ceases activity in the Union.
Highlights:
- Anchored in: ESPR Arts 10(4), 11(c), 11(e), Annex III(l); IR 2026/1778 Art 8(7)(e)
- Ask to see: the service provider reference stored inside a live passport
- Good answer: names the entity and addresses concentration risk directly
- Hand-wave: "backups are included in the platform"
- Deal-breaker if: no back-up reference is written into the passport at all
10. What do we get on the way out, and do the passports survive it?
The obligation. ESPR Article 10(1)(d) requires all passport data to be based on open standards, in an interoperable format, machine-readable, structured, searchable and transferable through an open interoperable data exchange network without vendor lock-in; Battery Regulation Article 77(5) uses the same wording. Implementing Regulation (EU) 2026/1778 Article 6a supplies the exit mechanism at registry level: registered passports may be transferred to another verified economic operator or verified value chain actor who takes over the obligations from a stated date.
Why it discriminates. "Without vendor lock-in" sits inside the essential requirements, so portability is a property the passport is meant to have, not a commercial nicety, and few buyers test it. Ask for a full export during the evaluation and check three things: whether it is structured and machine-readable or a CSV dump of screen fields, whether it includes registration identifiers and version history, and whether carrier URIs still resolve after an Article 6a transfer.
Highlights:
- Anchored in: ESPR Arts 10(1)(d), 11; Battery Reg Art 77(5); IR 2026/1778 Art 6a
- Ask to see: a real export file plus a described Article 6a registry transfer
- Good answer: structured export with registration identifiers and version history
- Hand-wave: "you own your data" with no export format named
- Deal-breaker if: carrier URIs stop resolving once the contract ends
11. How do you collect tier-N supplier data from suppliers who are not your customers?
The obligation. ESPR Annex III makes unique operator identifiers for actors other than the manufacturer (point h) and unique facility identifiers (point i) candidate data elements, and Articles 12(2) and 12(3) put an active duty on whoever creates or updates the passport: where such an identifier does not yet exist, you must request it on behalf of the relevant actor, after first seeking confirmation from that actor that none exists. Battery Regulation Annex XIII additionally requires carbon footprint information under Article 7, responsible sourcing from the due diligence report under Article 52(3), and recycled content under Article 8(1).
Why it discriminates. Supplier data collection is where DPP projects actually fail, and the failure is commercial rather than technical: a tier-2 supplier will not create an account in your vendor's portal. Ask how a supplier who refuses to onboard still submits a declaration, and whether supplier seats are metered.
Highlights:
- Anchored in: ESPR Arts 12(2), 12(3), Annex III(g) to (i); Battery Reg Annex XIII, Arts 7, 8(1), 52(3)
- Ask to see: the collection flow for a supplier with no account, end to end
- Good answer: licence-free submission plus a timestamped request-and-response trail
- Hand-wave: "we have a supplier portal" with per-supplier seat pricing behind it
- Deal-breaker if: tier-2 data needs a paid seat your supplier must buy
12. What does the auditor view expose, and can you prove the access tiers?
The obligation. ESPR Article 10(1)(g) makes access subject to product-group access rights set in the delegated act, Article 11(b) gives repairers, recyclers, market surveillance and customs authorities free access according to their respective rights, and Article 11(g) requires data authentication, reliability and integrity. Battery Regulation Article 77(2) is more prescriptive, splitting the passport into publicly accessible information, information for notified bodies and authorities, and information for persons with a legitimate interest, all per Annex XIII. Implementing Regulation (EU) 2026/1778 Article 14 adds a registry log retained five years for administrative and data-exchange events and for the full duration of the registration for data modifications.
Why it discriminates. Most demos show the consumer view. The tier you get audited on is the restricted one, and what separates platforms is whether an auditor can see the change history behind a value, not just the value. The DPPAutomate auditor view is read-only and scoped to the requesting party's tier: it renders the elements that tier is entitled to under the applicable instrument alongside the lifecycle event log behind each one, without provisioning that auditor a workspace seat.
Highlights:
- Anchored in: ESPR Arts 10(1)(g), 11(b), 11(f), 11(g); Battery Reg Art 77(2), Annex XIII; IR 2026/1778 Art 14
- Ask to see: one passport at public, legitimate-interest and authority tiers
- Good answer: tier-scoped read-only access plus a per-field change log
- Hand-wave: "auditors get full access" with one undifferentiated view
- Deal-breaker if: tiers are enforced in the interface but not in the API
Comparison table: what each question tests
Digital product passport companies describe themselves in near-identical language, and the marketing surface of most digital product passport solutions genuinely does converge. The obligations behind the questions do not.
| # | Question | Anchored in | Deal-breaker if |
|---|---|---|---|
| 1 | Instrument and article | ESPR 4, 9(1), 18; Battery 77; Toys 19 | Binding date with no adopted delegated act |
| 2 | Registration and identifier | ESPR 13(4), 13(5), 15(1); IR 8, 9 | No Article 9 proof of registration |
| 3 | Verified actor and provider list | IR 3(f), 4, 5, 19(4) | Registers under its own credentials, unverified |
| 4 | Standards conformance | ESPR 10(1)(c), 41(2); Decision 2026/1736 | Cannot name which standards apply |
| 5 | Granularity and pricing structure | ESPR 9(2)(d); IR 8(1) to 8(5) | Item passports lack linked batch and model IDs |
| 6 | Semantic repository | IR 8(7)(a), 11(3), 11(4), 12 | Mappings hand-maintained on a services ticket |
| 7 | Delegated act changes elements | ESPR 4, 9(2)(a); IR 10(2), 11(4) | Each change is a separate paid project |
| 8 | Resolver and persistence | ESPR 9(2)(i), 10(1)(a), 11(e); EN 18221 | Vendor-branded resolver, no transfer undertaking |
| 9 | Back-up and provider of record | ESPR 10(4), 11(e), Annex III(l); IR 8(7)(e) | No back-up reference inside the passport |
| 10 | Portability and exit | ESPR 10(1)(d); Battery 77(5); IR 6a | Carrier URIs stop resolving at contract end |
| 11 | Tier-N supplier data | ESPR 12(2), 12(3); Battery Annex XIII | Tier-2 data needs a paid supplier seat |
| 12 | Auditor view and access tiers | ESPR 10(1)(g), 11(b); Battery 77(2); IR 14 | Tiers enforced in the UI but not the API |
The 12 questions, ready to paste into your vendor call
Send this ahead of the call so the vendor brings the right people.
DPP PLATFORM EVALUATION - 12 QUESTIONS
Checked against the instruments on 27 August 2026
1. Which instrument and article puts each product group in scope, and is
that delegated act adopted or still a working-plan target?
2. Register a test passport live. Show the unique registration identifier
the EU registry returns, then generate the proof of registration.
3. Are you a verified actor in the registry, are you on its list of DPP
service providers, and who monitors the three-year credential expiry?
4. Which of EN 18216, 18219, 18220, 18221, 18222 and 18223 do you conform
to, and to which clauses? In writing.
5. Show item-level issuance at our volume with linked batch and model
identifiers. Meter, overage rate, and the invoice if volume triples?
6. Do you resolve the registry semantic repository over its public API or
maintain your own mappings? Which model version are you on today?
7. A delegated act changes the required data elements after we launch.
What happens to passports already issued, and who pays?
8. Who operates the resolver our carrier points at? URI scheme, uptime
commitment, contractual persistence term.
9. Who is the DPP service provider hosting the mandatory back-up copy, and
is that the same legal entity as this platform?
10. Export everything today. What format, does it include registration
identifiers and version history, and do carrier URIs keep resolving
after a registry transfer?
11. How does a tier-2 supplier with no account and no licence submit a
declaration? Show the request-and-response trail.
12. Render one passport at public, legitimate-interest and authority tiers,
show the change log behind a field, then show the API enforcing the
same tiers.
How to run the evaluation
There is no best digital product passport software in the abstract, only the platform whose answers to these twelve survive contact with your product groups. Three of the twelve decide most outcomes. Question 2 tells you whether the platform has met the registry that has existed since 20 July 2026 or is still describing one. Question 7 tells you what year three costs, because delegated acts under ESPR Article 4 arrive on a rolling basis and each one is a migration of passports you already issued. Question 10 tells you whether "without vendor lock-in" in ESPR Article 10(1)(d) is a property of the product or a line in a brochure.
Ask the questions in the same order of every one of the digital product passport vendors on your shortlist, record answers in the same five fields the entries use, and demand artefacts rather than assurances. For the head-to-head view, the DPP software comparison page carries it, our Circularise alternatives piece covers one specific pairing, and the ERP and PIM integration guide covers how data reaches the passport from the systems you already run.
The fastest way to calibrate a vendor's answers is to have issued a passport yourself, because after that the demo stops being abstract. DPPAutomate is the Digital Product Passport platform of record for European brands, and a free Sandbox workspace lets you issue, register and export one before you sit in a single vendor call.
Issue your first passport this afternoon. Start free with a Sandbox workspace.
This article is general information about EU product regulation, not legal advice. Delegated acts change what applies to your products and when. Confirm your own obligations against the current text of the instruments cited above, or with your legal counsel.

