Articles
Articles
June 19, 2026

Is It Necessary to Sign Each Battery DPP?

What the EU Battery Regulation, the new European DPP standards and the DPP registry rules say about signing battery passport data

Battery pack beside a battery passport record in JSON, sealed with an electronic seal and a verification badge

From 18 February 2027, every LMT battery, every industrial battery above 2 kWh and every electric vehicle battery placed on the EU market needs a battery passport. One question comes up in almost every project: does each passport have to be digitally signed?

The short answer

Not word for word, but in practice, yes. The EU Battery Regulation (EU) 2023/1542 does not use the words "digital signature" or "electronic seal". It does require that the authenticity, reliability and integrity of the passport data are ensured, that only authorised actors can change it, and that fraud is avoided. The European standard written for exactly this requirement, EN 18246:2026, does it with electronically signed data. Signing or sealing every creation and every update of a passport is the most direct way to meet the Regulation and to prove it to an authority.

What the Battery Regulation requires

The battery passport is set out in Articles 77 and 78 and Annex XIII of the Regulation:

  • Who is responsible. The economic operator placing the battery on the market "shall ensure that the information in the battery passport is accurate, complete and up to date". It may authorise another operator in writing to act on its behalf (Article 77(4)). When a battery is repurposed or remanufactured, or becomes waste, responsibility moves to the next operator (Article 77(7)).
  • Who may change the data. "The rights to access, introduce, modify or update information in the battery passport shall be restricted" according to the access rights in Annex XIII (Article 78(f)).
  • Authenticity and integrity. "Data authentication, reliability and integrity shall be ensured" (Article 78(g)).
  • Security. The passport must ensure "a high level of security and privacy" and that "fraud is avoided" (Article 78(h)).
  • Open and interoperable. The data must be based on open standards, machine-readable and interoperable with the digital product passports under the Ecodesign for Sustainable Products Regulation (ESPR), without vendor lock-in (Articles 77(5) and 78(a)).

The ESPR, Regulation (EU) 2024/1781, sets the same requirement for all digital product passports in its Article 11(g), in identical words.

Where signatures come in: the European DPP standards

The Regulation sets the goal; the European standards describe how to reach it. CEN and CENELEC (Joint Technical Committee 24) have published eight standards for digital product passports in 2026.

  • EN 18246:2026, "Digital product passport – Data authentication, reliability and integrity" introduces an electronically signed data construct (ESDC). The passport data are wrapped in, or accompanied by, a signature that binds them to the identity of the actor who created or changed them. Anyone reading the passport can check who issued the data and that nothing has been altered since.
  • EN 18239:2026 covers access rights management, information system security and business confidentiality: who may read, create and modify which data.
  • EN 18221:2026 covers data storage, archiving and data persistence, including keeping earlier versions of a passport available.

Six of the eight standards (EN 18216, EN 18219, EN 18220, EN 18221, EN 18222 and EN 18223) were cited in the Official Journal as harmonised standards under the ESPR by Commission Implementing Decision (EU) 2026/1736 of 14 July 2026. Applying them gives a presumption of conformity for ESPR passports. EN 18246 and EN 18239 had not been cited as of early October 2026, and the decision does not refer to the Battery Regulation. European standards are voluntary. But because the battery passport must be fully interoperable with ESPR passports, they are the natural reference for battery passports too.

Which signature formats can be used?

Passport data are typically exchanged as JSON. These established, open formats can bind that data to its issuer:

  • JAdES (JSON Advanced Electronic Signatures, ETSI TS 119 182-1): an advanced electronic signature attached to, or wrapped around, the JSON payload.
  • W3C Verifiable Credentials (Data Model 2.0, a W3C Recommendation since May 2025): cryptographically signed statements that carry the passport attributes.
  • eIDAS electronic seals and electronic attestations of attributes: a company's own seal, backed by a certificate that identifies the legal person, under the eIDAS Regulation (EU) No 910/2014 as amended by Regulation (EU) 2024/1183.
  • Visible Digital Seals (ISO 22376) and digital signatures for automatic identification (ISO/IEC 20248, "DigSig"): signed data that can also travel in a data carrier such as a 2D code.

Which format fits depends on how the passport is shared and verified. What matters is that the signature is anchored in a trusted certificate that identifies the economic operator.

eIDAS already applies: the EU DPP registry

One rule is already binding. Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026 sets out how the EU digital product passport registry works, and it explicitly covers batteries under Article 77 of the Battery Regulation. Companies registering passports must prove their identity with eIDAS means. For a legal person established in the EU, that is a qualified electronic seal or a qualified electronic attestation of attributes. The registry's proof of registration is itself "guaranteed by means of a qualified electronic seal".

This rule covers registration, not the passport data. But an economic operator that needs a qualified seal for the registry anyway can use the same trust infrastructure to seal its passport data.

Who can read and who can write from 18 February 2027

  • Public information is accessible to everyone, free of charge, with no login (Annex XIII, point 1; Article 78(b)).
  • Restricted information is accessible only to persons with a legitimate interest, such as repairers, remanufacturers, second-life operators and recyclers, and to notified bodies, market surveillance authorities and the Commission, depending on the data (Article 77(2), Annex XIII points 2 to 4). The implementing act that details who has a legitimate interest (Article 77(9)) had not been published at the time of writing. Access needs reliable identification of the requesting party, and requests should be logged.
  • Creating and changing passport data is reserved for the responsible economic operator, or an operator it has authorised in writing (Articles 77(4) and 78(c)). Every creation and every change should be signed or sealed by that operator, so it can be traced and cannot later be denied.

What this means for your battery passport

  1. Sign or seal every creation, update and status change of a passport, not just the first version.
  2. Use a certificate that identifies your company as the economic operator, for example a qualified electronic seal.
  3. Keep earlier versions together with their signatures, so the history of each battery can be verified.
  4. Make the signature easy to check for every reader, without special software.
  5. Put written authorisations in place for any service provider that creates or updates passports on your behalf.

How GoodsTag handles it

The GoodsTag platform signs data records cryptographically and keeps a verifiable history of every change, on top of GS1-compliant identifiers and open data formats. If you want to check how your battery passport setup measures up against Article 78 and the new standards, talk to our team or read more about our Battery DPP.

Sources

This article reflects the legal situation as of 8 October 2026 and is not legal advice.