Verified Identity for Economic Operators: ISBE's Response to the New EU Central Registry Regulation

Commission Implementing Regulation (EU) 2026/1778 entered into force on 6 August, the rule that sets out the central registry for the Digital Product Passport (DPP) provided for under the Ecodesign for Sustainable Products Regulation (ESPR, Regulation (EU) 2024/1781). ISBE has already explained, in an earlier article, what the DPP is and which sectors it affects first. This piece focuses on a later, more specific development: how the identity of each economic operator registering or updating a passport must be verified, and on the infrastructure, did:isbe, that ISBE has already built to meet that requirement.
What Commission Implementing Regulation (EU) 2026/1778 Changes for DPP Economic Operators
The European Commission opened the DPP central registry on 20 July 2026, together with a testing environment for manufacturers, suppliers, distributors and recyclers to familiarise their systems with the infrastructure before it becomes mandatory by product category. Commission Implementing Regulation (EU) 2026/1778 is the rule that sets out how that registry works: what data is uploaded, who can access it and, above all, how the identity of whoever enters or amends it is verified.
The first genuine application date is already fixed: 18 February 2027, for industrial and electric vehicle batteries, the first product category required to carry a digital passport under the Batteries Regulation (EU) 2023/1542. Other product categories will follow the same calendar as the Commission adopts the sector-specific ESPR delegated acts. For any company forming part of those value chains, the verified identity requirement begins to be resolved now, not when its category's deadline arrives.
Interoperability and Identity Verification: The Regulation's Two Technical Requirements
The regulatory framework does not mandate any particular technology, but it is precise on two requirements. The first is interoperability: the ESPR, in Articles 10 and 11, requires passport data to be developed in an interoperable format, transferable through an open data exchange network without dependence on any single provider, and fully interoperable with other digital product passports. The second is identity verification: Implementing Regulation 2026/1778 requires each economic operator to identify itself by qualified electronic signature, high level electronic identification or an electronic attestation of attributes, in the case of natural persons, and by qualified electronic seal or attestation of attributes, in the case of legal persons, with a maximum validity of three years before revalidation is required.
One point that is often oversimplified deserves precision: the regulation does not state anywhere that the architecture must be decentralised or immutable, nor does it require blockchain as a technology. What the European Commission does confirm is that the central registry is an index that it manages, while product data is stored in decentralised form, within the systems of each operator in the value chain. The combination of decentralised data, a mandatory interoperability standard and a verifiable operator identity is precisely the ground on which a permissioned blockchain network has something concrete to offer, even though the regulation treats it as a possible option rather than a mandate.

The Challenge of an Identity That Belongs to No Single Actor
A digital product passport does not belong to a single company. Manufacturer, suppliers, distributor, recycler and market surveillance authority all need to read, and in some cases write, the same record, without any one of them being a natural authority of trust over the others. Resolving this through point-to-point integrations between each actor's proprietary databases is, in practice, a project spanning years of technical and contractual negotiation.
This is compounded by a well-known tension between registries designed never to be altered and the right to erasure under the General Data Protection Regulation. A registry that mixes product data with personal data without separating them by design carries that problem directly. Reliably verifying who can read, write or amend each record, and keeping personal data out of that shared layer, is as relevant to compliance as the content of the passport itself.
How ISBE's Digital Identity Framework Works
ISBE resolves this identity layer with a framework built for legal entities. Each organisation joins the network through an off-chain KYB verification and a qualified eIDAS certificate that links it to its own identifier, registered on ISBE's Bare Network alongside a DID document with a dual cryptographic key and a cross-reference to that certificate.
On that basis, a LEAR credential is issued: a verifiable credential under the W3C standard, equivalent to a digital legal power of representation, compatible with the European Digital Identity Wallet Architecture and Reference Framework (EUDI Wallet ARF). From that credential, the organisation itself issues and revokes credentials for its staff through a revocable Bitstring Status List, without the personal data of those individuals ever touching the chain.
The result is a verified, revocable identity for the economic operator, with legal validity under eIDAS2 across all 27 Member States, built before Implementing Regulation 2026/1778 required it as a condition of DPP registration.
Frequently Asked Questions
Which companies are required to verify their identity under Regulation (EU) 2026/1778?
Any economic operator (manufacturer, importer, distributor, authorised representative or end of life manager) that must register or consult a Digital Product Passport in the European Commission's central registry. The obligation applies category by category, as the ESPR adopts sector-specific delegated acts. Industrial and electric vehicle batteries are the first, with a deadline of 18 February 2027.
Is blockchain mandatory for Digital Product Passport compliance?
No. Neither the ESPR nor Regulation (EU) 2026/1778 requires any particular technology. What they do require is that data be interoperable and transferable without dependence on a provider, and that each economic operator verify its identity through eIDAS mechanisms. A permissioned blockchain network is one way of meeting both requirements at once, not the only one.
What is a did:isbe identifier and what is it for?
It is the decentralised identifier (DID) that ISBE issues to each organisation joining its network, linked to a qualified eIDAS certificate following a KYB verification process. It serves as the identity foundation for issuing verifiable credentials, such as the LEAR credential, with legal validity under eIDAS2 across all 27 Member States.
What is the difference between the DPP central registry and the product's own data?
The registry managed by the European Commission functions as an index: it points to where each passport is located and verifies who can access it. The product data itself, as the Commission has confirmed, is stored in decentralised form, within the systems of each operator in the value chain, not in a single central repository.
When should a company in the value chain of a DPP product start preparing?
Before its product category's deadline arrives. The central registry has been operational since July 2026, with a testing environment available, and the first genuine application date (18 February 2027, for batteries) leaves little margin if the identity and traceability infrastructure has not been resolved in advance.

Redacción ISBE
Redacción @ ISBE