DPP MCP

EN 18216 · 18219 · 18220 · 18221 · 18222 · 18223

Six standards, published in 2026

These are what a Digital Product Passport is measured against: how it is identified, what a data carrier resolves to, how it answers a machine, how long it survives, what its API has to support, and how another system reads it without having seen it before.

Each entry gives the standard's own scope and then the clauses the validator cites. That second list is much shorter, because a clause only appears there if it can be checked from outside — over HTTP, without the publisher's cooperation.

Published, edition 1

What each one covers

EN 18216:2026

Data exchange protocols

The protocols and data formats a passport uses to move between systems: secure and authenticated exchange, and structures that stay readable to both a person and a machine across platforms and sectors, without vendor lock-in.

  • §4 Secure transport. HTTPS with TLS, and the address is reachable.
  • §5 Content negotiation. The same URL returns HTML to a browser and JSON or JSON-LD on Accept: application/json. Most passports fail this one — they render a page and have nothing to say to a machine.
EN 18219:2026

Unique identifiers

Identifiers for the product, the economic operator and the facility: global uniqueness, persistence, syntax, granularity, interoperability and openness. It defines three granularity levels for a product identifier — model, batch, or individual item.

  • §4.2 Persistence. An identifier that has been published has to keep resolving.
  • §5.2 GS1 Digital Link syntax — /01/<gtin>/22/<cpv>/10/<batch>/21/<serial>, in that order, with a GTIN that satisfies its own check digit. Also the linkset: ?linkType=all returns a GS1 linkset so other resources attached to the product can be found.
  • §6 Economic operator identifier — an LEI, or an operator ID qualified by a GS1 company prefix.
EN 18220:2026

Data carriers

The QR code or tag itself: symbology, format, error correction, encoding, print quality and durability, plus how it is marked and placed so a person can recognise it as a passport carrier. Cryptographic security features are explicitly out of its scope.

  • §5.2 The carrier's target resolves. A scan returns a passport, not a 404 and not a redirect chain ending somewhere else.
EN 18221:2026

Data storage, archiving and data persistence

Storage on a decentralised model. Archiving keeps the passport's history rather than only its current state, and persistence keeps the passport available after the economic operator that created it has stopped operating. It also specifies replication between an operator and a back-up operator, and rules for how long data lives.

  • §4.2 Retention. Kept for the period the product's rules require, with its history.
  • §4.5 Back-up host. Somewhere other than the publisher can serve the passport if the publisher stops, advertised with a Link rel="backup" header or a field in the document, so it can be found without asking anyone.
EN 18222:2026

APIs for lifecycle management and searchability

The passport's API, as ESPR requires one: how passports are found, and what operations exist across a passport's life. This is the standard that says a passport has to be queryable and not only viewable.

  • No clause is cited by the validator. What this standard requires cannot be established from a single passport URL; it describes an interface the publisher's platform provides.
EN 18223:2026

System interoperability

The semantic layer: how a product and its lifecycle are described, a common information model, metadata models for exchange, and rules for building product-group data models on top of them — so a system that has never seen this passport can still read it.

  • §4.1.2.1, Table 1 Seven header attributes, all mandatory: passport identifier, unique product identifier, granularity, schema version, status, last updated, and economic operator identifier. Scored separately from the brand's own content, because they are the platform's responsibility rather than the brand's.

Not published

Two that are still being written

EN 18239 — Access control, information security and business confidentiality

Who may see which parts of a passport, how the data is protected, and what a company can keep commercially confidential inside one. Not published. Any tool listing it as something you can conform to is listing something that does not exist yet.

EN 18246 — Data authenticity, reliability and integrity

Proving a passport is the one its publisher issued, that it has not been altered, and that it can be relied on. Also not published.

Getting the text

Where to buy them

EN standards are not free. The working group is CEN/CENELEC JTC 24, and the text is sold by the national standards bodies — SIS in Sweden, where the Swedish adoptions are designated SS-EN 18216:2026 and so on.

The scopes above are paraphrased from the published documents. No clause text is reproduced here, and this page is not a substitute for the standards.

Measure a passport against them →