In this article
The Digital Product Passport and the deadline European SMEs cannot afford to ignore
There is a recurring simplification surrounding the Digital Product Passport: the idea that it amounts, essentially, to a QR code on a label. For European small and medium-sized enterprises, that simplification is dangerous precisely because of what it conceals. The real challenge does not lie in printing a code. It lies in building, ahead of the applicable EU deadlines, a reliable chain of product data — something many companies still do not possess, even when their production practices are otherwise sound.
The passport's legal architecture is already established through the ESPR. Product-specific obligations will be activated progressively through delegated acts, and that progression is not uniform: in the battery sector, the first major passport deadline is already fixed for February 2027; for textiles and apparel, the Commission expects to adopt the relevant delegated act in the same year, though that date does not, on its own, amount to a universal compliance obligation. The question for SMEs is therefore no longer whether the Digital Product Passport will arrive, but whether their product information will be ready when it does.
There is no single DPP deadline for every product
The ESPR is a framework regulation: it empowers the Commission to establish, progressively, detailed ecodesign and information requirements for specific product groups. The applicable deadline depends on the product category, the relevant delegated act and its transitional period.
One date is already legally certain. Under Article 77 of the EU Batteries Regulation, from 18 February 2027, every light means of transport battery, every industrial battery above 2 kWh and every electric vehicle battery placed on the EU market must be accompanied by a battery passport. The position differs for textiles: the Commission's ESPR and Energy Labelling Working Plan 2025–2030 places the sector among the first to be regulated, with 2027 as the planned year for adoption, but the final application date, product scope and data fields still depend on the text eventually adopted. A planned act for 2027 is not the same as a universal deadline fixed for 1 January of that year — a distinction that matters legally, without justifying any delay in preparation.
The passport is not, simply, a QR code
The visible part of a Digital Product Passport may be a QR code or another data carrier attached to the product or its packaging. The invisible part is substantially larger. Under Articles 9 to 11 of the ESPR, the passport must be linked to a persistent unique product identifier, with data based on open standards, machine-readable, structured, searchable and accessible according to the rights assigned to different users — consumers, market-surveillance and customs authorities, repairers and recyclers each potentially seeing a different layer. The passport is therefore better understood as a regulated product-data infrastructure. The QR code is merely its front door.
Why SMEs may be more exposed than they expect
The ESPR creates no general exemption for SMEs. Whether an obligation applies depends on the product placed on the market and the role of the economic operator, not on company size — so a small manufacturer may face requirements essentially identical to those facing a much larger competitor. The difference lies in capacity: large groups are more likely to have lifecycle management systems and supplier portals already in place, while smaller manufacturers often hold essential information across spreadsheets, email threads and scattered certificates. That fragmentation becomes a regulatory risk once information must be linked to a specific product identifier in structured, reliable form. The passport cannot publish data the company does not possess, and software cannot retroactively correct evidence that was never collected.
What information could enter the passport?
The precise content of each passport will be defined at the level of each product group, and no company should treat a provider's current template as the final legal specification. The ESPR already signals the categories likely to be required: product and operator identification, materials and components, substances of concern, durability and reliability, repair and refurbishment information, recycled-content evidence, environmental performance data, and end-of-life instructions.
For textile manufacturers, this means connecting data currently dispersed across fibre suppliers, mills, dye houses and garment factories. A brand may describe a shirt as containing recycled cotton — but can it tie that claim to a specific batch, identify the supporting evidence, or distinguish pre- from post-consumer content? These are not software questions. They are questions of evidence.
Supplier data will become a market-access issue
Many SMEs depend on complex supplier networks rather than manufacturing in-house, and the ESPR places responsibility on the economic operator placing the product on the market — hiring a platform provider does not transfer that responsibility elsewhere. Existing contracts may not require suppliers to deliver structured data, disclose substances or notify formulation changes, and commercial confidentiality may limit what is shared. The passport could therefore reshape procurement itself: the most competitive supplier may no longer be the cheapest, but the one able to deliver reliable traceability data alongside the physical product.
The EU is building a passport registry
The ESPR requires the Commission to establish a DPP registry, storing at minimum unique product identifiers so that authorities and customs systems can verify passports. Economic operators will need to upload required information before placing a covered product on the market, and customs authorities will be able to use that information for controls on imports — a point of particular relevance for SMEs sourcing from outside the EU. The DPP is therefore more than a transparency tool aimed at consumers; it is being built into the Union's market-surveillance architecture, where missing or unreliable passport data becomes a market-access problem rather than a communication flaw.
Waiting for the final delegated act is not a complete strategy
Avoiding premature investment in a closed technological solution is reasonable while essential elements — exact scope, mandatory data points, granularity, transition period — remain undefined. But that caution is not the same as inaction. Much of the preparatory work is technology-neutral: an SME can already map which product information it holds, where it is stored, which data depend on suppliers, which claims are evidenced, and who is responsible for validating each field. That work remains useful regardless of which platform or technical architecture the company eventually adopts. The weakest place to begin is the QR code. The strongest is the product-data map itself.
Five concrete steps already make sense: selecting one representative product to reveal where information breaks down; building a data inventory that records, for each point, its source and supporting evidence; linking certificates explicitly to the models or batches they cover, since an unconnected certificate is an island and the DPP requires bridges; reviewing supplier contracts to address data provision, verification rights and notification of change; and following the Commission's sector-specific delegated acts directly, since the ESPR alone offers no final checklist for any single sector.
The passport is a compliance mechanism, but it may also reshape competition. Companies with structured, credible data can respond faster to customer requests and support circular business models that depend on knowing what a product contains. A manufacturer unable to provide reliable information may keep producing a technically sound product while becoming progressively harder to fit into a regulated European value chain. For SMEs, this is the deadline behind the official deadline: the legal obligation arrives through a regulation and its delegated acts, but the commercial obligation may arrive earlier, through a request from a customer or a lead company already preparing its own compliance.
The Digital Product Passport is not mandatory, in 2026, for every product, and there is no single 2027 deadline covering the entire European market. But the direction of travel is no longer speculative: the ESPR is in force, its architecture is established, the battery passport carries a binding February 2027 date, and the textile delegated act is planned for the same year. The companies best prepared will not necessarily be those that buy the most sophisticated platform first, but those that know where their data come from and can prove it is trustworthy. The deadline may still appear later on the calendar. The work on the data has already begun.
⸻
Sources
[1] Regulation (EU) 2024/1781 establishing a framework for the setting of ecodesign requirements for sustainable products, particularly Articles 4, 7 and 9–15.
[2] Regulation (EU) 2023/1542 concerning batteries and waste batteries, particularly Article 77 on the battery passport.
[3] European Commission, Ecodesign for Sustainable Products and Energy Labelling Working Plan 2025–2030, COM(2025) 187 final.
[4] European Commission, The DPP Registry, official information page.
[5] European Commission, Commission seeks views on the future Digital Product Passport, 13 November 2024.
[6] European Commission, Commission launches consultation on the Digital Product Passport, 9 April 2025.
[7] European Parliament, Panel for the Future of Science and Technology, Digital Product Passport in the Textile Sector, 2024.
[8] European Commission Joint Research Centre, Methodology for defining data requirements for the Digital Product Passport under the ESPR framework, 2026.