| EU 2024/1781 | Regulation (EU) 2024/1781 — Ecodesign for Sustainable Products Regulation | European Union | 2024-06-13 | IN FORCE | N/A | Legal framework | All product groups subject to applicable delegated acts | DPP regulatory profile; lifecycle; authority boundaries | P04 | TRACKED | Keep product-group applicability explicit | DPP Standards Owner | https://eur-lex.europa.eu/eli/reg/2024/1781/oj | 2026-09-01 | 2026-10-01 | Baseline legal framework |
| EU 2026/1736 | Commission Implementing Decision (EU) 2026/1736 | European Commission | 2026-07-14 | IN FORCE | OJEU PUBLISHED | Publishes six DPP harmonised standards | DPP system requirements under Articles 10 and 11 | Standards status and public wording | P04/P06 | TRACKED | Use exact harmonised references; no blanket compliance claim | DPP Standards Owner | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1736 | 2026-09-01 | 2026-10-01 | Six standards cited in OJEU |
| EN 18216:2026 | Digital product passport — Data exchange protocols | CEN/CENELEC | 2026 | HARMONISED | OJEU CITED | Presumption of conformity for corresponding requirements | Applicable DPP data exchange | Integration protocol mapping | P04/P06 | MAPPED | Track protocol profiles per connector | Integration Owner | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1736 | 2026-09-01 | 2026-10-01 | OJEU cited |
| EN 18219:2026 | Digital product passport — Unique identifiers | CEN/CENELEC | 2026 | HARMONISED | OJEU CITED | Presumption of conformity for corresponding requirements | Identifier requirements | Identifier governance / resolver | P03/P04 | MAPPED | Map official identifier schemes without replacing authority | Identity Owner | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1736 | 2026-09-01 | 2026-10-01 | OJEU cited |
| EN 18220:2026 | Digital product passport — Data carriers | CEN/CENELEC | 2026 | HARMONISED | OJEU CITED | Presumption of conformity for corresponding requirements | Carrier requirements | QR/NFC/data-carrier experience | P02/P04 | MAPPED | Map carrier profiles to product-group requirements | Experience Owner | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1736 | 2026-09-01 | 2026-10-01 | OJEU cited |
| EN 18221:2026 | Digital product passport — Data storage, archiving, and persistence | CEN/CENELEC | 2026 | HARMONISED | OJEU CITED | Presumption of conformity for corresponding requirements | Persistence and storage requirements | Repository / continuity architecture | P04/P05 | MAPPED | Align retention, backup and persistence profiles | Data Architecture | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1736 | 2026-09-01 | 2026-10-01 | OJEU cited |
| EN 18222:2026 | Digital Product Passport — APIs for lifecycle management and searchability | CEN/CENELEC | 2026 | HARMONISED | OJEU CITED | Presumption of conformity for corresponding requirements | Lifecycle and search APIs | DPP APIs / search / lifecycle | P04/P06 | MAPPED | Maintain OpenAPI/AsyncAPI mapping by release | API Owner | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1736 | 2026-09-01 | 2026-10-01 | OJEU cited |
| EN 18223:2026 | Digital Product Passport — System interoperability | CEN/CENELEC | 2026 | HARMONISED | OJEU CITED | Presumption of conformity for corresponding requirements | System interoperability | Connector/conformance model | P04/P06 | MAPPED | Publish version-specific interoperability evidence | Conformance Owner | https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026D1736 | 2026-09-01 | 2026-10-01 | OJEU cited |
| EN 18239:2026 | Digital Product Passport — Access rights management, information system security, and business confidentiality | CEN/CENELEC | 2026 | PUBLISHED / STATUS DEPENDENT | NOT IN 2026/1736 ANNEX | Supporting reference in this release | Access/security where applicable | Policy / disclosure / security | P02/P05 | TRACKED | Do not present as one of six OJEU-cited standards in Decision 2026/1736 | Security Architecture | https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-15-dpp/ | 2026-09-01 | 2026-10-01 | CEN-CENELEC lists eight-series; six already OJEU cited |
| EN 18246:2026 | Digital product passport — Data authentication, reliability and integrity | CEN/CENELEC | 2026 | PUBLISHED / STATUS DEPENDENT | NOT IN 2026/1736 ANNEX | Supporting reference in this release | Authentication/integrity where applicable | Evidence / cryptographic trust | P05 | TRACKED | Do not overstate harmonised/OJEU status | Evidence Owner | https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-15-dpp/ | 2026-09-01 | 2026-10-01 | CEN-CENELEC lists eight-series; six already OJEU cited |
| GS1 Digital Link | GS1 Digital Link URI syntax and resolver ecosystem | GS1 | n/a | ECOSYSTEM STANDARD | N/A | Supporting ecosystem mapping | Product identification / resolver integration | Identifier resolver / data carrier | P02/P03/P06 | TRACKED | Validate exact profile/version in project | Integration Owner | https://www.gs1.org/standards/gs1-digital-link | 2026-09-01 | 2026-12-01 | Supporting ecosystem |
| EPCIS 2.0 | EPC Information Services 2.0 | GS1 | n/a | ECOSYSTEM STANDARD | N/A | Supporting event interoperability | Supply-chain event exchange | Connector / semantic mapping | P06 | TRACKED | Project-specific mapping required | Integration Owner | https://www.gs1.org/standards/epcis | 2026-09-01 | 2026-12-01 | Supporting ecosystem |
| ISO/IEC 15459 | Unique identification — multiple parts | ISO/IEC | various | INTERNATIONAL STANDARD | N/A | Identifier reference | Where relevant under ESPR Annex III | Identifier governance | P03/P04 | TRACKED | Map applicable part/version by identifier scheme | Identity Owner | https://www.iso.org/ | 2026-09-01 | 2026-12-01 | Referenced by ESPR Annex III |
| ISO/IEC 30141:2024 | Internet of Things (IoT) — Reference architecture | ISO/IEC | 2024 | INTERNATIONAL STANDARD | N/A | Architecture reference | Connected thing contexts | Device / integration architecture | P05/P06 | SUPPORTING | Use as supporting architecture reference only | Device Trust Owner | https://www.iso.org/ | 2026-09-01 | 2026-12-01 | Supporting reference |
| IEC 63278-1 | Asset Administration Shell — Part 1 | IEC | n/a | INTERNATIONAL STANDARD | N/A | Digital twin / industrial asset reference | Industrial ecosystem contexts | Semantic/integration mapping | P06 | SUPPORTING | Project-specific profile mapping | Integration Owner | https://www.iec.ch/ | 2026-09-01 | 2026-12-01 | Supporting reference |
| IEC 62541 | OPC Unified Architecture | IEC | n/a | INTERNATIONAL STANDARD | N/A | Industrial interoperability | Industrial/IoT integration | Connector / semantics | P06 | SUPPORTING | Map selected OPC UA profiles | Integration Owner | https://www.iec.ch/ | 2026-09-01 | 2026-12-01 | Supporting reference |
| IEEE 802.1AR | Secure Device Identity | IEEE | n/a | STANDARD | N/A | Device identity reference | Connected devices where selected | Device identity / certificates | P05 | SUPPORTING | Not mandatory for passive DPP | Device Trust Owner | https://standards.ieee.org/ | 2026-09-01 | 2026-12-01 | Supporting reference |
| RFC 8995 | Bootstrapping Remote Secure Key Infrastructure (BRSKI) | IETF | 2021 | RFC | N/A | Device onboarding reference | Selected device onboarding patterns | Device trust | P05 | SUPPORTING | Use only where chosen by implementation | Device Trust Owner | https://www.rfc-editor.org/rfc/rfc8995 | 2026-09-01 | 2026-12-01 | Supporting reference |
| RFC 9334 | Remote ATtestation procedureS (RATS) Architecture | IETF | 2023 | RFC | N/A | Attestation architecture | L3/runtime assurance contexts | Attestation / appraisal | P05 | SUPPORTING | Profile selection remains project-specific | Device Trust Owner | https://www.rfc-editor.org/rfc/rfc9334 | 2026-09-01 | 2026-12-01 | Supporting reference |
| RFC 9711 | EAT Media Types | IETF | 2025 | RFC | N/A | Attestation evidence media reference | Selected attestation profiles | Attestation evidence | P05 | SUPPORTING | Validate exact EAT/CWT profile in implementation | Device Trust Owner | https://www.rfc-editor.org/rfc/rfc9711 | 2026-09-01 | 2026-12-01 | Supporting reference |
| IEC 62443-4-1/4-2 | Security for industrial automation and control systems | IEC | n/a | STANDARD FAMILY | N/A | Cybersecurity reference | Industrial connected products where applicable | Secure development / component security | P05/P06 | SUPPORTING | Applicability depends on product and deployment | Security Architecture | https://www.iec.ch/ | 2026-09-01 | 2026-12-01 | Supporting reference |
| ETSI EN 303 645 | Cyber Security for Consumer Internet of Things | ETSI | n/a | EUROPEAN STANDARD | N/A | Consumer IoT security reference | Connected consumer products where applicable | Device security | P05 | SUPPORTING | Applicability depends on product category | Security Architecture | https://www.etsi.org/ | 2026-09-01 | 2026-12-01 | Supporting reference |
| EU CRA | Regulation (EU) 2024/2847 — Cyber Resilience Act | European Union | 2024 | IN FORCE / TRANSITION | N/A | Product cybersecurity legal framework | Products with digital elements where applicable | Device/security governance | P05/P06 | TRACKED | Maintain product/applicability analysis | Security Architecture | https://eur-lex.europa.eu/ | 2026-09-01 | 2026-10-01 | Track regulatory timelines |