Skip to main content

There Is No Such Thing as a "Certified DPP Provider" (Yet)

If you have started comparing Digital Product Passport software, you have probably seen the phrase "certified DPP provider" in a sales deck, a homepage banner or a proposal. Here is the uncomfortable fact behind that phrase: as of mid-2026, no company can legitimately call itself a certified DPP provider, because the EU certification scheme for such providers does not exist. Not for us, not for anyone.

This is not a technicality. With the European Commission's DPP Registry going live on 20 July 2026, vendors are racing to look official, and "certified" is the word that sells. This article explains what the law actually provides for, what the registry launch does and does not change, and how to use one simple question to test any vendor's credibility.

What "certified" would even mean, and why nobody has it

The DPP system is deliberately decentralised: the regulation foresees digital product passport service providers hosting passport data on behalf of manufacturers, and the registry includes a list of verified providers. Separately, the Ecodesign Regulation (Regulation (EU) 2024/1781, the ESPR, Article 11) empowers the Commission to adopt a delegated act setting out the requirements that digital product passport service providers will have to comply with, and, where the Commission considers it appropriate, a certification scheme to verify compliance. That delegated act has not been adopted. The Commission's published planning currently lists it for 2027, where it appears under both the second and third quarter of the timeline.

So the certification everyone is invoking is, today, an empty box: the requirements are not written, the scheme is not created, and the legal text even leaves open whether a formal certification scheme will exist at all. Until that delegated act is adopted, every "certified DPP provider" claim is marketing language wearing a legal costume.

What actually went live on 20 July 2026

The registry is a Commission-run system where verified economic operators will register their Digital Product Passports. Its legal framework, Commission Implementing Regulation (EU) 2026/1778, was adopted on 16 July 2026 and enters into force on 6 August 2026. It is important to understand what the registry is not: it does not store your full passport data. It records a minimal registration record, essentially the Unique Product Identifier and the information needed to locate and verify the passport. The passport data itself stays where you, or a service provider you designate, host it, and you remain responsible for keeping it available and accurate.

Alongside the production system, the Commission opened a separate test environment where companies can rehearse enrolment and registration without touching official data. Two honest caveats about the current state of the system. First, only one product group is available for registration today: batteries. Second, even for batteries, registration requests cannot currently succeed, because the semantic catalogue for the product group has not yet been defined. The Commission says this plainly in the official user guide. The doors are open, the machinery works, but the first real registrations are still ahead of us.

Note the vocabulary the registry actually uses: operators and service providers get verified, an identity check based on qualified electronic signatures or seals under the eIDAS framework, valid for at most three years. Verification is not certification. Manufacturers themselves go through the same verification. When a vendor's homepage turns "we are verified" into "we are certified", they are trading on the confusion between two words the regulation keeps carefully apart.

The deadlines that exist, and the ones that do not

The first binding implementation date is 18 February 2027, for LMT batteries, industrial batteries with a capacity greater than 2 kWh, and electric vehicle batteries under the Battery Regulation (Regulation (EU) 2023/1542, Article 77). That is the deadline worth planning against right now if batteries are your business.

For everything else, precision matters. The Commission lists textiles, steel and aluminium, tyres, furniture, ICT products, energy-related goods, construction products, toys, detergents and surfactants among the sectors the registry will serve. But for textiles specifically, the delegated act that would define requirements is still expected, and no compliance date currently exists in adopted law. Anyone quoting you a hard "textile DPP deadline" today is quoting a forecast, not a legal obligation. We track the state of every adopted act in our ESPR delegated acts overview, against the official texts.

The one-question credibility test

Ask any DPP vendor: "Certified by whom, under which act?" Then watch what happens.

Being verified in the registry is an identity check, one that manufacturers themselves go through as well. Being certified under the EU scheme is not possible for anyone today, because the scheme does not exist. If a vendor's homepage or proposal claims EU certification as a DPP provider, that is not a maturity signal. It is a red flag about how carefully they read the texts they claim to master. The accurate statements a serious provider can make in mid-2026 are narrower: that they follow the published technical framework, and that they are preparing for the future requirements, including certification if the Commission establishes that scheme.

The same test works on adjacent claims. ISO 27001 is a real and valuable security certification, but it is not a DPP certification. Partnership badges, industry association memberships and self-issued "compliance ready" labels are not certifications at all. None of these are disqualifying, and some are genuinely good signals. They just do not mean what "certified DPP provider" implies.

Four questions to ask any DPP provider before you sign

You do not need to become a regulatory expert to buy well. These four questions expose most of the gaps.

What happens to my passports if you disappear? EU rules require that a back-up copy of the passport remains available through an independent third party, and the registry framework explicitly verifies the link to that back-up during registration. A provider with no credible back-up answer has not done the reading.

Are your identifiers standards-compliant? The Unique Product Identifier must be a URL-format identifier compliant with the applicable technical standards, and it must resolve reliably. Ask to see a live example resolve.

Can I export everything, at any time? Your passport data belongs to your compliance obligation, not to the vendor's platform. Structured export in open formats should be a given, not a premium feature.

Who is legally responsible for accuracy? The correct answer is: you, the economic operator, always. Even if a third party performs the registration on your behalf, the regulation states that you remain fully responsible. A vendor who answers anything else is either confused or overselling. What a good provider actually reduces is the operational risk of getting there, not the legal responsibility itself.

If you are earlier in the process and want a structured preparation path rather than vendor-vetting questions, our step-by-step registry preparation checklist for SMEs covers the groundwork, and our guide to the ESPR itself explains where these obligations come from.

The registry going live turns the Digital Product Passport from a policy discussion into working infrastructure. The sensible move now is unglamorous: map which of your products fall under the first rules, rehearse in the sandbox when relevant, and hold every vendor claim, including ours, against what the adopted texts actually say.

Frequently asked questions

Can a DPP software vendor be "EU certified" right now?

No. The ESPR (Article 11) empowers the Commission to set requirements for DPP service providers through a delegated act, and, where appropriate, a certification scheme to verify compliance. That act has not been adopted (the Commission's planning currently lists it for 2027). Until then, "certified DPP provider" claims have no legal basis.

Is being "verified" in the EU DPP registry the same as being certified?

No. Verification in the registry is an identity check based on qualified electronic signatures or seals under eIDAS, valid for at most three years, and manufacturers go through it too. Certification would attest compliance with provider requirements that have not yet been written.

Do I have to register my products in the EU DPP registry today?

No. The registry is live and only the batteries product group is set up, and even battery registrations cannot yet be completed because the semantic catalogue is still being defined. The first binding date is 18 February 2027, for LMT batteries, industrial batteries above 2 kWh and electric vehicle batteries.

What we claim, and what we do not

DPP-Tool does not call itself a certified DPP provider, because no such certification exists. What we do: structured product passports with resolvable identifiers, full data export, and documentation that cites the official texts it relies on. Judge us the same way this article suggests judging anyone: compare providers on what is verifiable, or start with the free plan and check our claims yourself.

Create Your First Passport Free

Ready to Get Started?

Create your first Digital Product Passport today.

Try DPP-Tool Free