Preparing for the Digital Product Passport under the Ecodesign for Sustainable Products Regulation (ESPR), Regulation (EU) 2024/1781, is a programme, not a single project. It touches product data, suppliers, sustainability, legal, operations and IT. Because each product group’s requirements arrive through its own delegated act, teams often wait for certainty and lose the time they need for the slow parts, such as collecting supplier data. This guide sets out 30 steps in six phases that work whatever the final wording turns out to be, with the outcome to aim for at the end of each phase. You can tick the steps off, and your progress is saved in your browser, in the free ESPR Compliance Roadmap .
How to use this roadmap
The order matters more than the speed. Scope comes first because it decides what you must do. Data inventory and modelling come before supplier requests, because you cannot ask suppliers for data you have not defined. Choosing a carrier comes after you know what the passport contains. A pilot proves the approach before you extend it. Small teams can combine phases, and large groups can run several product groups in parallel through the same steps.
| Phase | Outcome | Typical duration |
|---|---|---|
| 1. Scope | A list of in-scope product families, roles and an owner | 2 to 4 weeks |
| 2. Inventory | A gap list and a readiness baseline | 4 to 8 weeks |
| 3. Model and govern | A data model, identifiers and field owners | 4 to 8 weeks |
| 4. Supplier evidence | Templates, evidence storage and first responses | 3 to 9 months, running in parallel |
| 5. Carrier and publish | A carrier decision, resolver and publishing process | 2 to 4 months |
| 6. Pilot and scale | One product group live, then a rollout plan | 3 to 6 months |
The durations are planning assumptions from typical programmes, not fixed requirements, and they depend heavily on how many products and suppliers are involved.
The 30 steps
1. Understand your scope
Goal: Know which products, markets and roles the rules reach.
- List the products you place on the EU market. Export every product family, brand and market you sell into the EU, including through marketplaces and importers. This is your scope baseline.
- Match products to ESPR product groups. Check each family against the priority groups in the Commission’s working plan and against sector rules such as the Battery Regulation.
- Confirm your legal role for each product. Manufacturer, importer, distributor and authorised representative carry different duties. Record which role you hold per product.
- Name an accountable owner and a working group. One person owns the programme, with product, sustainability, procurement, legal, operations and IT represented.
- Set up a regulatory watch. Track delegated acts, standards and guidance for your groups, and review them every quarter because timelines shift.
2. Inventory your data
Goal: See what you already hold and where it lives.
- Map your attributes to the passport data domains. Go through identification, documentation, materials, durability, repair, footprint, circularity and supply chain data field by field.
- Find the system of record for each field. Note whether each value sits in ERP, PLM, PIM, a supplier portal or a spreadsheet, and who edits it.
- Measure completeness and consistency. Score how many products have each field and how many values follow one format and unit.
- Rank the gaps by priority and effort. Start with core identification, composition and end-of-life data, then the rest.
- Record a readiness baseline. Save a score so progress is visible to leadership.
3. Model and govern
Goal: Give the data a structure and an owner.
- Define a passport data model. Choose attributes, units and value lists, with a core set for all products and overlays for each group.
- Plan your identifiers. Decide how GTIN, model number and unique product identifier relate and how they are structured to ISO/IEC 15459 or an equivalent.
- Assign an owner to every field. Each attribute has a named team that creates it and keeps it current.
- Set approval and review workflows. Define who approves changes and who can publish, and how updates are versioned.
- Plan audience-based access. Decide what consumers, repairers, recyclers and authorities may each see.
4. Collect supplier evidence
Goal: Get trustworthy inputs from the supply chain.
- Identify suppliers that hold passport data. Prioritise the suppliers behind your highest-volume and highest-risk products.
- Send one clear data request. Use one template with definitions, units and accepted evidence instead of ad hoc emails.
- Store evidence with the data. Keep certificates, test reports and declarations linked to each value and its date.
- Validate what comes back. Check formats, ranges and completeness on import and send errors back to the supplier.
- Agree timelines and update duties. Put response times and change notification duties into supplier agreements.
5. Choose a carrier and publish
Goal: Make each passport reachable from the product.
- Select a data carrier per product type. Compare QR code, Data Matrix, NFC and RFID against your materials, sizes and readers.
- Encode a stable, resolvable identifier. Use a URL structure you control, such as a GS1 Digital Link, so the code stays valid if data moves.
- Decide where passports are hosted. Host them yourself or with a service provider, and plan for the independent backup copy the rules expect.
- Test scanning in real conditions. Scan printed, aged and worn samples with the devices your audiences use.
- Publish through a governed process. Only approved, complete records go live, with an audit trail of who changed what.
6. Pilot, operate and scale
Goal: Prove it on one group, then extend.
- Run a pilot on one product group. Pick a group with good data and a clear owner and take it end to end.
- Audit the pilot. Check completeness, accuracy and access rules against the current rules for that group.
- Train the teams involved. Give product, procurement and customer service the practical steps and the definitions.
- Prepare for the DPP registry. Confirm what identifiers and information you must register once your group’s rules apply.
- Extend group by group and review. Repeat for the next group, update the model when delegated acts change and review indicators each quarter.
What each phase produces
Scope: a defensible boundary
By the end of phase one you can state, product family by product family, whether the ESPR, the Battery Regulation or another rule reaches it, in what role you act, and when to expect requirements. The map of how the EU product rules fit together and the timeline by product group help here.
Inventory: a gap list you trust
The inventory turns worry into a list. The DPP Data Field Mapper ranks gaps against the passport data domains, and the guide to ESPR Annex I parameters explains what each parameter means in data terms. For a deeper look at catalog quality, see how to audit your catalog for DPP readiness .
Model and govern: the foundation
The model, identifier scheme, owners and workflows are what make later phases repeatable. If you skip this and go straight to a spreadsheet, you will rebuild it for the next product group. Read how to build a DPP data model and the guide to roles across the DPP workflow .
Supplier evidence: the long pole
Composition, substances and origin data start with suppliers, and suppliers work to their own calendars. Start early with one template, and see how to collect supplier data for DPP readiness .
Carrier and publishing: reachable and stable
Once you know what the passport contains, choose how it is reached. The comparison of QR code, Data Matrix, NFC and RFID and the DPP Data Carrier Selection Guide cover the decision, and how to publish QR and URL-linked records covers hosting.
Pilot and scale: proof before rollout
One product group taken end to end exposes the real problems: missing evidence, slow approvals, unreadable codes. Fix them there, then extend. The approach for teams that do not want to replace their systems is in how to start DPP readiness without replatforming everything .
Common reasons programmes stall
- Waiting for final rules. The data foundations (identifiers, structure, supplier evidence) are needed by nearly every delegated act. Start them now.
- No accountable owner. A working group without a decision maker drifts. Name one person.
- Treating it as an IT project. The hard parts are ownership, evidence and supplier response, not software.
- Starting with the carrier. A printed code with an empty passport behind it does not help anyone.
- Everything at once. Pilot one group, then scale.
- Static plans. Delegated acts change the details, so the regulatory watch and quarterly review are part of the plan.
Track your progress
Measure the starting point with the DPP Readiness Assessment , tick off steps in the ESPR Compliance Roadmap , and look up terms in the DPP Terminology Glossary as you go. The broader business case and operating model are described in the Digital Product Passport guide . Where a step needs help from a product data platform, how PIM supports Digital Product Passport workflows explains the role of governed product data.
Frequently asked questions
Where should I start with ESPR compliance?
Start with scope: list the products you place on the EU market, match them to ESPR product groups and sector rules, confirm your legal role and name an accountable owner. Then inventory your data against the passport data domains.
How long does it take to prepare for a Digital Product Passport?
It depends on the number of products and suppliers. Typical programmes need several months for the data model and inventory, and three to nine months for supplier evidence, which runs in parallel. Plan for a pilot on one product group before extending.
Can I prepare before my product group’s delegated act is published?
Yes. Identifiers, a structured data model, supplier evidence and governance are needed by nearly every delegated act. Only the final field lists and dates depend on the act.
Who should own the programme?
One accountable owner, typically in product operations, compliance or sustainability, supported by a working group from product, procurement, legal, operations and IT.
What is the slowest part of DPP readiness?
Collecting trustworthy supplier data. Composition, substances and origin depend on supplier responses and evidence, so start early with one clear template and agree timelines.
How do I track progress?
Record a baseline with the DPP Readiness Assessment, tick off steps in the ESPR Compliance Roadmap tool, and review the plan every quarter as delegated acts and standards change.



