Skip to content

Signing the record, and the gap a signature does not close

A European standard on data authentication and integrity for digital product passports is at formal vote. It specifies electronically signed data constructs, so that anybody reading a record can verify it came from the operator it claims to come from and has not been altered since. That is genuinely useful and it is worth understanding precisely, because it closes one gap and leaves the one most people assume it closes wide open.

Sources as at
30 August 2026
Share
LinkedIn X Email
Navigate this page

The short answer

A signature proves things about a record. It proves nothing about an object.

Signed passport data tells you that this data was published by this operator and has not been changed. It does not tell you that the garment in your hand is the garment the data describes, because the thing connecting the two is a printed code, and a printed code can be photographed and reprinted.

That distinction is the whole of this page. Why a passport is not an authentication mechanism, and why a clone that resolves to a genuine record is more convincing than one that resolves to nothing, is set out on the code proves the record. This page is about what the standards work now under way does and does not change about that.

A signature proves that this data was published by this operator and has not been changed. The link from the data to the physical object is a printed code, and a printed code can be photographed and reprinted. WHAT A SIGNATURE CLOSES Operator Publishes the passport data Signed record Published by them, and unchanged WHAT IT DOES NOT CLOSE Signed record Says nothing about an object PRINTED CODE The garment in your hand A code can be photographed and reprinted A signature proves things about a record. It proves nothing about an object.
The dashed link is the whole of this page: the only thing joining the record to the object is a printed code.

What is actually being standardised

Two of the eight European passport standards sit outside the Commission implementing decision of July 2026, which means their references are not published in the Official Journal and they carry no presumption of conformity. They are the two that most buyers assume are already solved.

StandardSubjectStatus
Data authentication and integrityElectronically signed data constructs, so a reader can verify origin and detect alterationAt formal vote. Not in the Official Journal
Access rights managementWhich role sees which part of a record, and how that is enforcedFinal draft. Not in the Official Journal

Which of the eight are published and which are not, and what a presumption buys, is on which passport standards carry a presumption of conformity. What each published standard covers is on what the six passport standards cover.

We have not read either draft. What we hold is the subject of each and its citation state, and that is all this page rests on.

What a signature does close

Worth being clear, because the gap this page describes is not an argument against signing.

Origin. A reader can establish which operator published a value rather than inferring it from the domain the page happens to sit on.

Alteration. A value changed after publication stops verifying. That is a real protection against a record being edited in transit or at rest by somebody other than the operator.

Attribution over time. A signed value carries who said it, which is exactly the discipline the estate already argues for on its own terms. Who inside a business owns a published field, and what happens when one turns out to be wrong, is a governance question with its own page, and a signature makes the answer checkable from outside rather than merely recorded inside.

Those three are not small. In a category where most systems export values without provenance, cryptographic attribution of origin is a meaningful improvement, and what a usable export has to contain is set out on what you can take with you when you leave a provider.

What a signature does not close

It does not bind the record to the object. This is the load-bearing point. The link between a physical garment and a signed record is a carrier: a printed code, a tag, a chip. Signing the record at the far end of that link does nothing to the link itself. Photograph a legitimate code, reprint it, and every counterfeit resolves to a genuine, correctly signed passport.

The published data carrier standard confirms this from the other direction. Its scope covers symbology, encoding, print and production quality, durability and placement, and it explicitly excludes secure elements and any other cryptographic security features. The standard that governs the physical link says, in its own scope, that binding and secrecy are not its job.

So the two standards between them cover the record and the mark, and neither covers the join.

It does not make a value true. A signed statement that a garment is 60 per cent recycled polyester proves the operator said it. Whether the operator could substantiate it is a different question with its own tests, and what a passport field can and cannot prove is a separate discipline.

It does not confer a presumption. Not today. The reference is not published, so conformance with it buys nothing under the framework, however good the engineering is.

What actually authenticates an object

Unchanged by any of this, and worth restating because the standards work invites the wrong conclusion.

Binding a record to a specific physical item requires something that lives in the object and is hard to copy. That is the reason every serious operator in the anti-counterfeiting market sells a physical or covert feature alongside the identifier rather than relying on the code, and it is why the party with the strongest commercial incentive to replace inspection with a lookup still pays people to inspect.

A signature is a good answer to "is this record genuine". It is not an answer to "is this object genuine", and the two questions have different suppliers.

What to do with this

Ask which of the two questions a proposal is answering. A vendor describing signed passport data as anti-counterfeiting has merged them. The correction is available in the carrier standard's own exclusions.

Do not wait for the authentication standard to start the governance work. Recording who declared each value, against what, on what date, is the part a signature later makes portable. It does not need a standard and it is worth doing regardless.

Treat a conformance claim against either draft as a statement about engineering, not about law. It may be an entirely good product decision. It carries no presumption and it should not be sold as though it did.

If the requirement is genuinely authentication, price it separately. It is a different purchase with a cost nobody publishes, and the honest state of that market is on the code proves the record.

What would change this page

Either draft having its reference published in the Official Journal, which would extend the presumption to authentication or to access rights and change what a conformance claim is worth.

Anybody reading the authentication draft and publishing what it requires, which would let this page describe a mechanism rather than a subject.

A carrier standard, or a revision to the published one, taking secure elements inside its scope. Today it excludes them explicitly, and that exclusion is the clearest evidence on this page.

Sources

  • FprEN 18246, data authentication and integrity for digital product passports
    European standard at formal vote

    Subject and citation state reached through two independent secondary readings. Neither the draft nor its requirements were read, and nothing on this page describes a requirement inside it. Used for two propositions only: that the subject is being standardised as electronically signed data constructs, and that its reference is not published in the Official Journal.

  • FprEN 18239, access rights management
    European standard in final draft

    Subject and citation state reached the same way, and carried here only as the second of the two standards outside the presumption.

  • BS EN 18220:2026, Digital product passport. Data carriers
    European standard adopted as a British Standard, published 31 May 2026

    Scope read at the national standards body that publishes it. The load bearing source on this page, cited for its stated exclusions: architecture and use cases, secure elements, and any other cryptographic security features.

  • Commission Implementing Decision (EU) 2026/1736 of 14 July 2026
    In force

    Used for which references are published and therefore which standards carry a presumption. Confirmed at the Commission's harmonised standards page and through a testing body's account of the decision.

Sources as at 30 August 2026.

Keep going

The question this one usually raises next.

Also worth reading

Built to be questioned

Every value ActivateDigital resolves keeps the document it came from, its state and its provenance.

Worth sharing?

Help someone else make sense of product passports.

LinkedIn X Email