Standards
The DPP Standards Guide (EN 1821x)
What the eight CEN/CENELEC JTC 24 system standards — EN 18216, 18219, 18220, 18221, 18222, 18223, 18239 and 18246 — actually require, and how to meet them.
The technical rules for the Digital Product Passport were written by CEN/CENELEC technical committee JTC 24 under the Commission's M/604 standardisation request. The result is a family of eight system-level European standards: the first six were published on 27 May 2026, with the remaining two expected in autumn 2026.
These standards do not answer "what data goes in the passport" — that is the job of product-specific delegated acts. They define how the system works.
The eight standards at a glance
| Standard | What it defines | Status |
|---|---|---|
| EN 18219:2026 | Unique identifiers (product, operator, facility) | Published |
| EN 18220:2026 | Data carriers and the physical–digital link | Published |
| EN 18216:2026 | Data processing, exchange protocols, formats | Published |
| EN 18221:2026 | Data storage, archiving, persistence | Published |
| EN 18222:2026 | Passport lifecycle and APIs | Published |
| EN 18223:2026 | Interoperability, terminology, core data model | Published |
| FprEN 18239 | Access rights, security, commercial confidentiality | ~Autumn 2026 |
| FprEN 18246 | Data authentication, trustworthiness, integrity | ~Autumn 2026 |
How the modules fit together
The family is modular, with a dependency chain:
- EN 18223 is the base: terms, the core data model and semantics. Everything else sits on it.
- EN 18219 is the "key reference": without an identifier, no API call, carrier or registry entry means anything.
- EN 18220 binds that identity to the physical product. See EN 18220.
- EN 18216 is the precondition for exchanging data over the internet; EN 18222 says which operations can be called on that channel.
- EN 18239 adds access rights at the API layer; EN 18246 secures integrity at both data and carrier level.
Standard by standard
EN 18219 — identifiers
Permits five product identifier schemes: ISO/IEC 18975 web-enabled structured paths (in practice GS1 Digital Link), IEC 61406 identification links, W3C DIDs, ISO/IEC 15459 AIDC identifiers and DOIs. On the operator and facility side, GLEIF LEI and GS1 GLN are the common choices. See EN 18219.
EN 18220 — carriers
Permits QR, Data Matrix, NFC, HF RFID and RAIN RFID, and sets requirements for encoding, scannability, durability, print quality and placement. The critical rule: at least one carrier must be free, app-free and smartphone-readable.
EN 18216 — data exchange
RESTful APIs over HTTPS/TLS, structured machine-readable message formats and vendor independence, with room for voluntary extensions. See EN 18216.
EN 18221 — persistence
Storage, archiving and versioning rules that keep the passport reachable for the product's expected lifetime. This is where the backup service provider concept comes from. See EN 18221.
EN 18222 — APIs
Create, read, update and search operations; item-level operations, bulk retrieval, version queries and registry submission. See EN 18222.
EN 18223 — data model
Terminology, the core data model and semantic rules; this is the layer where JSON-LD serialisation acquires meaning. See EN 18223.
FprEN 18239 — access rights
Role-based separation between public and restricted data, authentication aligned with eIDAS assurance levels, and handover of responsibility between operators. See restricted data tiers.
FprEN 18246 — authentication
Electronic signatures via W3C Verifiable Credentials, eIDAS electronic attestations of attributes, ISO 22376 Visible Digital Seal or ISO/IEC 20248 — plus an audit record. See EN 18246.
The reference architecture
The architecture in the standards has three components: (1) EU central services — registry, portal, semantic repository; (2) decentralised passport data operated by economic operators or service providers; and (3) third-party backup services for persistence. Standard APIs connect them.
The economic operator's workflow is codified too: create an identifier → create and attach a carrier → store the data → place it in backup → register with the EU registry and link the data → manage access rights → maintain integrity.
Presumption of conformity
A European standard becomes "harmonised" when it is cited in the Official Journal against a piece of legislation, and applying it then confers a presumption of conformity: show you follow the standard and you are assumed to meet the legal requirement. That gives you one of the best questions to ask a vendor: "how does your product conform to EN 18219, 18220 and 18222?"
Frequently asked questions
Are the standards mandatory?
Legally, standards are voluntary; the regulation is what binds. But because a harmonised standard confers a presumption of conformity, following one is in practice the safest and cheapest route.
Do I have to buy the standards?
Access to the texts is paid, through national standards bodies. In practice most manufacturers rely on a platform that documents its own conformity rather than buying the texts.
What is happening at ISO level?
ISO/IEC JTC 5, operational from September 2026, aims to internationalise this work, so a comparable framework can be expected outside Europe.
Do these standards cover the battery passport?
The Battery Regulation legally references only ISO/IEC 15459, but the battery ecosystem — the Battery Pass data model, Catena-X, the IDTA AAS templates — is converging on the same EN family.


