The DPP Registry Is Law, and We Are Ready

The DPP Registry Is Law, and We Are Ready

The EU register for Digital Product Passports became law on 16 July 2026. What it asks of you, and what we take off your hands.

On 16 July 2026 the EU adopted the rulebook for its Digital Product Passport (DPP) registry, Commission Implementing Regulation (EU) 2026/1778. The registry the ESPR promised is now law - we covered the draft back in April in «EU-DPP-Register: was der Kommissions-Entwurf vorsieht»; this is what changed on the way to adoption.

The first thing to know is calming: the registry is an index, not a copy of your data. It records that your passport exists, points to where it lives, and keeps a fingerprint to prove it has not been altered. Your product data stays with you and your service provider.

What it asks of you

Two things. Register each passport, and prove who you are.

Identity runs through eIDAS: a qualified electronic signature or seal, or a qualified attestation of attributes. In return you get a sealed proof of registration you can hand to a customer or an authority. Registration data is kept for ten years.

That is the shape of it. It is a decentralised model: you keep your data, the registry keeps the index.

What it does not ask of you

We take care of the eIDAS side. The qualified signature or seal that registration requires is ours to provide; eIDAS itself is not something you need to deal with. Once registration opens, we upload every passport on your behalf and hand you the sealed proof of registration.

Until then, you can already collect the data registration will later require with us, at low cost, well looked after, without building anything yourself. And there is no need to wait: your passports can already be published, shown in marketing, used in repair. We only load the data into the registry once it is your turn.

Why this is a quiet day for us

We have spent months building to exactly this, and tracking the European standards as they moved from draft to final. Now that they have stopped moving, the honest result on our side is: almost nothing to change.

Our platform already does what the registry assumes. Every passport version is signed and verifies in any browser. Every version is kept in a tamper-proof archive for the full ten years, chained so any gap shows up at once. The registration carries a qualified eIDAS seal. The data model is open and standards-based, the fingerprint the registry records is one we already compute, and the decentralised split, your data with you and the index with the registry, is the architecture we were built on.

We mapped our platform against the EU DPP standards clause by clause while they were still drafts, as we wrote up in «DPP standards are harmonised, not mandatory». Now that the texts are fixed, that work stands. No scramble, and no need for one.

The one honest caveat

The law is set, but the plumbing is still being laid. The technical way to register, and the shared data definitions everyone will use, are rolled out by the Commission over the coming months, and Member States name their national contacts by February 2027. So the registry is law, but nobody can register into it just yet.

That is fine, and it is the right order. When the door opens, registration is a connector we switch on for you, not a system you rush to build.

Where we stand

The registry confirms the model we already run and the standards we already meet. If you are choosing where your passports will live for the next decade, the regulation just wrote your checklist, and we are glad to be built to it. Start now, and you start on a fixed target, on a platform that has been getting ready for this day for months.

Updates on the DPP registry rollout

We track the registration interface and the shared data definitions as the Commission publishes them, and send the changes that matter once a month.