Six passport standards are now published. This is what each one covers.
Which of the eight European passport standards carry a presumption of conformity is settled and is answered elsewhere on this estate. What almost nobody says, including us until now, is what the six published ones actually contain. This page sets out the scope of each, states how far we read it, and publishes one disagreement between sources rather than resolving it for you.
Navigate this page
The short answer
Six standards had their references published in the Official Journal by a Commission implementing decision of July 2026. Between them they cover the whole technical chain from a number on a product to a record a system can read, and they divide it like this.
| Standard | What it covers |
|---|---|
| EN 18216:2026 | Data exchange protocols. How passport data moves between systems in a machine-readable form that does not depend on one vendor. |
| EN 18219:2026 | Unique identifiers. Identifiers for products, for economic operators and for facilities, with product identification available at model, batch or item level. |
| EN 18220:2026 | Data carriers. The physical link, covering optical two dimensional codes, radio frequency tags and near field chips, with encoding, quality, error correction, durability and placement. |
| EN 18221:2026 | Data storage, archiving and persistence. Storage, historical versions, backups and long-term accessibility of the information. |
| EN 18222:2026 | Interfaces for lifecycle management and searchability. Finding, resolving, retrieving and managing passport information across its life. |
| EN 18223:2026 | System interoperability. Semantic, technical and organisational rules so information can be understood and reused across platforms and systems. |
Two further standards from the same committee sit outside that decision and therefore outside the presumption. They cover access rights management and data authentication and integrity, and they are the two that decide who may see what and whether anybody can tell your record from a copy of it.
What this page is not. It is not a summary of the requirements inside these standards. We have read published scopes, not the standard texts, and the difference matters enormously. A scope tells you the subject a standard addresses. It does not tell you what it demands.
How far we actually read
The estate's ordinary rule applies and it is worth stating before anything else on this page is used.
| What we read | What that supports |
|---|---|
| The scope of the data carrier standard, published by a national standards body | The subject list for that standard, and its stated exclusions, quoted from the body that publishes it |
| Scope summaries for the other five, from two independent secondary readings | The subject of each standard. Nothing about its requirements |
| The implementing decision, through the Commission's own standards page and a testing body's account of it | That six references are published, the decision's date, and that the presumption runs to two articles of the framework |
| The standard texts | Nothing. They sit behind a purchase and none of the six has been bought or read |
Every standard in the table above costs money to read. That is not a complaint about the model, it is a statement about what this page can support. Anybody telling you what one of these standards requires, rather than what it is about, should be asked whether they bought it.
The one place our sources disagree
Two independent accounts of the storage and persistence standard say different things, and the difference is material.
One states that it requires a passport to remain resolvable for a period of years after the product is placed on the market, independent of what happens to the issuer. The other states plainly that the document specifies no retention period or resolvability timeframe at all.
We have not read the standard, so we publish neither version. If the first is right it is the most consequential single fact in this whole territory, because it would put a duration on something the framework leaves to a contract, and what the framework does and does not require when the party answering stops is set out on when the link dies. If the second is right, the persistence question is still open and the answer still lives in whatever you sign.
Resolving this costs the price of one standard. Until somebody pays it, treat any stated persistence period in this category as unverified, including one quoted from a slide with a standard number next to it.
The carrier standard, which we can quote
One of the six has a scope published by the national body that sells it, which makes it the best-supported row on this page.
The data carrier standard specifies symbology characteristics, format, error correction, encoding methods, printing and production quality, and durability. It addresses machine readability and quality checking, carrier placement, and graphical indicators that let a person recognise what a mark is for.
Its exclusions are as useful as its inclusions. The scope excludes architecture and use cases, secure elements, and any other cryptographic security features.
Read those two lists together and the standard is doing one job carefully. It governs whether a mark can be read reliably and survives. It says nothing about whether the mark can be trusted, which is a separate subject handled by a separate standard that is not in the Official Journal.
That matters for a practical reason. A carrier decision made against this standard is a decision about legibility and durability, and the choices it does not make for you, including who owns the address the code resolves to, are on choosing a carrier that still works in five years.
What the identifier standard changes
The identifier standard is the one most likely to surprise a business that has only ever thought about barcodes, because it does not describe one identifier. It describes three: one for the product, one for the economic operator and one for the facility.
Two of those are probably not in your catalogue. What allocating a product identifier commits you to is a subject of its own, and the operator and facility identifiers are a different kind of object with a different owner, which is why they get a page of their own.
The standard also confirms something the framework leaves open, that product identification is available at model, batch or item level. Which of those a textile act will require is not settled, and the cost gradient between them is the largest single cost decision in a programme.
What follows for a business
Nothing you have to do this week. These are standards, not obligations. A harmonised standard gives you a route to demonstrating conformity with requirements that, for textiles, have not yet been set. No textile delegated act has been adopted.
Ask which standard, and ask whether they read it. The useful question when a vendor cites conformance is not whether they comply. It is which of the eight they mean, whether its reference is published, and what part of the standard their claim actually sits inside. What a presumption of conformity buys, and what it does not, is set out on which passport standards carry a presumption of conformity.
Treat the two unpublished ones as the interesting ones. Access rights and data authentication are the two subjects a buyer most often assumes are solved. Neither carries a presumption today.
Do not buy a standard to be compliant. Buy one because you need to build against it. Six documents at typical standards prices is a real cost and most businesses in this position need none of them yet.
What would change this page
Anybody reading the storage and persistence standard and publishing whether it sets a period. That single answer settles the disagreement above and changes what this estate says about continuity.
The two remaining standards having their references published, which would extend the presumption to access rights and to authentication.
Any of the six being cited in a textile delegated act, at which point their content stops being background and starts being the specification.
Sources
-
In force
Reference and effect confirmed from the Commission's own harmonised standards page for digital product passports and from a testing body's published account of the decision. The decision text itself returned only metadata on the routes tried, so its operative articles have not been read here. Used for three propositions: that six references are published, the date, and that the presumption attaches to Articles 10 and 11 of the framework so far as the standards cover them.
-
BS EN 18220:2026, Digital product passport. Data carriers, published 31 May 2026European standard adopted as a British Standard
Scope read at the national standards body that publishes it. Used for the subject list and for the stated exclusions. The standard text was not bought and not read.
-
EN 18216:2026, EN 18219:2026, EN 18221:2026, EN 18222:2026 and EN 18223:2026European standards
Scope summaries reached through two independent secondary readings rather than at the standards themselves. Used only for the subject of each standard. Where the two readings disagree, on the persistence standard, neither version is published and the disagreement is stated in the body.
-
Primary authority
Used for the existence and reference of the implementing decision, and for the fact that the page itself names no standards and directs enquiries to the European standardisation organisations.
Sources as at 30 August 2026.
Keep going
The question this one usually raises next.
Also worth reading
Built against the standards, not around them.
One governed record becomes the passport, the Digital Link behind the code, the retailer pack and the consumer page.
Help someone else make sense of product passports.