For the last two years, anyone preparing for the Digital Product Passport has had to build against a moving target. The regulation was in force and the deadlines were set, but the technical standards describing how a passport should actually be constructed were still being written, and even once they were written, there was a further question of whether they would carry any legal weight. On 14 July 2026 that question closed.
On that date the European Commission adopted Implementing Decision (EU) 2026/1736, which cites the first six harmonised standards for the Digital Product Passport in the Official Journal of the European Union. That sounds like routine administration, and the document itself runs to three pages. But it’s the step that turns the DPP from a policy commitment into a tested route to product conformity, using the same legal machinery that has sat behind CE marking for decades.
Why the citation is the decisive act
The standards themselves were published by CEN and CENELEC back on 27 May, drafted with ETSI by the joint technical committee JTC 24. From that date you could read them and build to them. What you couldn’t do was rely on them in law, because a harmonised standard only earns its legal effect when the Commission publishes its reference in the Official Journal. That’s what Decision 2026/1736 does.
The mechanism it triggers is presumption of conformity, and it’s worth being precise about what that means. Article 41(2) of the ESPR says that a Digital Product Passport built in conformity with harmonised standards whose references are published in the Official Journal is presumed to conform with the requirements in Articles 10 and 11 that those standards cover. In plain terms: build your passport to these standards, and the burden of proving compliance is met by construction. You don’t have to argue your interpretation of the regulation with a market surveillance authority. You point at the standard.
This is the New Legislative Framework, the architecture the EU has used for product conformity for years. The law sets out the essential requirements, harmonised standards describe how to meet them, and a product built to the standard is presumed to meet the law. It’s the same model that puts a CE mark on a kettle or a toy, now extended to the data layer of every regulated product that comes into scope.
What the six standards cover
The set maps onto the core building blocks of a working passport.
- EN 18219 covers unique identifiers: the persistent code that names an individual product and survives whatever happens to the brand’s website.
- EN 18220 covers data carriers: the QR code or NFC tag on the product itself.
- EN 18216 covers data exchange protocols: how passport data moves between systems.
- EN 18221 covers data storage, archiving and persistence: the part that keeps a passport readable years after the product was sold.
- EN 18222 covers the APIs for lifecycle management and searchability: the machine interface a regulator or trading partner uses to query the passport.
- EN 18223 covers system interoperability: the rules that let all of the above work across implementations that have never seen each other.
Listed out they look like a pile of infrastructure, but together they describe a reliable way to get from the physical object to the structured data behind it and back again, no matter who built which end.
What’s still open
The citation is a real step, but it leaves two things unfinished.
It doesn’t make a passport mandatory. That job belongs to the sector-specific delegated acts under ESPR, each of which sets the required data fields and the compliance date for its category. Batteries come first, with the battery passport required from 18 February 2027. The textiles delegated act is expected around the second quarter of 2027, with compliance following roughly eighteen months later. Furniture, tyres, iron and steel and the rest of the ESPR priority groups follow on the published schedule out to 2030. This decision settles how you prove a passport conforms, not which products need one yet.
And the standards set isn’t complete. The elements covering access-rights management, information system security, and business confidentiality weren’t part of this citation. They were still in approval in mid-2026, expected around September. Until they’re cited too, the security and access-control layer of any implementation is building slightly ahead of the settled ground.
What to do with this now
What the citation settles is the shape of the passport, not what goes inside it. The data itself, the fibre composition for a garment, the state of health for a battery, the maintenance and end-of-life guidance for a machine, still has to be gathered, structured and validated, and for most brands it’s scattered across PIM systems, supplier emails and spreadsheets rather than sitting ready in one place. That’s the work that takes real time, and none of it depends on the last two standards.
What changed on 14 July is that the target stopped moving. A brand designing its passport infrastructure now is building against a fixed reference with legal standing rather than a forecast, and the buy-or-build decision is cleaner because any platform’s claim to conform can be checked against a cited standard instead of taken on trust. A brand that starts mapping its product data now, against the fields its category is likely to require, will have something running before its delegated act bites, with room to refine it. A brand that waits will be doing the same work in compressed time.
There’s a second reason to start early, and it’s the part we care about at TalkPod. The data a brand assembles for compliance is the most accurate description of its products it will ever hold. Most brands will meet the requirement, publish the passport, and let that data sit behind a QR code that a customer scans once and closes. It can do more than that. The same structured data that satisfies a regulator can answer a customer standing in front of the shelf, asking whether the jacket is machine washable or where the steel was made. Compliance creates the data. What you do with it after that is a choice.
Common questions
What did Implementing Decision (EU) 2026/1736 actually do? It published the references of the six Digital Product Passport standards, EN 18216 to EN 18223, in the Official Journal of the European Union. Under Article 41(2) of the ESPR, a passport built in conformity with those standards is now presumed to conform with the requirements in Articles 10 and 11 that the standards cover. The decision was adopted on 14 July 2026 and took effect on publication, 15 July.
Does this make Digital Product Passports mandatory? No. What makes a passport mandatory for a given product is the sector-specific delegated act under ESPR, and those set the required data and the compliance date category by category. Batteries come first in February 2027. This decision is about how you prove a passport conforms, not about which products need one yet.
Do we have to build to these standards? Using a harmonised standard is voluntary. You can demonstrate conformity another way. But building to the cited standards gives you a presumption of conformity, which is the tested route. In practice most brands will follow the standards for the same reason they follow the harmonised standards behind CE marking, because it’s the path with the least legal risk.
What’s still outstanding? The elements covering access-rights management, information system security, and business confidentiality weren’t part of this citation. They were still in approval in mid-2026, expected around September. And the sector delegated acts that decide what data each category must carry are still arriving on the published schedule out to 2030.
Where this sits
The publication of the references in the Official Journal is the moment the DPP stopped being a regulation with an implementation question mark over it and became a defined technical system with a route to compliance you can rely on. A harmonised standard only carries legal weight once its reference is printed in the Official Journal. As of 15 July, these six do. For anyone in scope, that turns the open question from when the standards will arrive into how fast they can build to them.
None of that moves the deadline or shortens the data work. If anything it sharpens the point that’s been true since ESPR entered force: the technical layer was always the solvable part, and the product data was always the longer job. The citation is a good reason to get on with it.
This article reflects the status of DPP standardisation as publicly available in July 2026. Verify the sector-specific delegated acts for your category before treating any implementation detail as mandatory.