INTYGIO
Signing and verification for Digital Product Passports

Someone will ask you to prove what this product claimed.

sign(data)     proof
verify(proof)  status

From 2027 every battery, and later every textile, carries a Digital Product Passport. The day a customs officer, an auditor or a buyer asks whether yours is real, you need an answer that holds. Intygio signs your passport the moment you publish it. Anyone who scans the product can check it, for free, years later. You keep your systems. You run nothing new.

18 Feb 2027
batteries first, then textiles
1 call
to sign a passport
Free
to verify, for anyone, forever
What we do, and don't

Four links in a product passport.
We are the last one.

The first three are a crowded market and we are not in it. We do the fourth, as a layer on top of the other three. A passport here is a sequence of signed states, each provable on its own, and the last one is the passport you place on the market. If you already run a passport platform, or built those parts yourself, the data stays where it is and gets signed where it stands.

Not us
Collect

Pull product data out of suppliers and internal systems.

Not us
Structure

Map it into the passport format the regulation asks for.

Not us
Share

Publish it so partners and authorities can read it.

Intygio
Prove

Sign it, so anyone can prove it has not been changed since.

The problem

The usual approach
is a link to a server.

Most Digital Product Passports put a URL in the QR code. Scan it, open a page, trust whoever runs it. That works right up until someone asks you to prove what the page said last year.

The data can change without a trace

A URL-based passport is editable at any time. Last year's CO₂ figure is simply gone, and nobody, including you, can show what it used to say.

the audit problem

A compromised server rewrites everything

One breach and every product pointing at that URL now shows whatever the attacker chose. The QR codes in the field are unchanged and still confidently wrong.

one point of failure
Why us

We sign the moment.

A signature fixes what the data said when you signed it. Change one character afterwards and it stops verifying. That is the whole product. The rest of this page is how we keep it true for as long as the regulation asks you to.

A security platform first. Passports are the first product on it.

Intygio was built as a security platform from day one: every control mapped to NIS2 and ISO 27001 and published on our trust page, so the passport layer you add never becomes the weak link in your own compliance. On top of that platform sits signing and verification for Digital Product Passports, and the same layer works for a software artifact or a certificate, on any carrier. Whichever direction the legislation takes, the product follows it. We sit on SIS TK 639, the Swedish committee for the European DPP standards, so we read them while they are drafted rather than after. Behind it sit years as CISO inside one of the world's largest industrial companies, reading frameworks like these from the receiving end.

Trust page · SIS TK 639 · CEN/CENELEC JTC 24 →
How it works

Sign it. Ship it. Anyone can check it.

You sign the passport. The proof goes on the product, on whatever label or tag it already carries. Later, a repair shop or a recycler adds their step to the same record, and anyone can see who did what. Your part is one call to our API. Nothing to install, nothing to join, nothing new to keep running for ten years.

1

Sign

You sign the passport with an electronic seal built to be recognised across the EU. Every later event, a transfer, a repair, a recycling step, is added on top and signed by whoever did it.

eIDAS-aligned seal · signed lifecycle events
2

Pack

Every item gets its own proof, and one item costs the same per item as a million. It fits in a QR code, an NFC tag, an RFID chip or an API response.

Any carrier · QR / NFC / RFID / API
3

Verify

Anyone can check the proof against the key you published. It holds or it does not. The values behind it come from a call, and each reader sees only what they are allowed to see.

Built for EU trusted lists · access tiers
// Issue once. Chain across the full lifecycle.
sign(data)            →  { proof: "4B51…" }                   // manufacturer
chain(proof, event)   →  { proof: "7C82…" }                   // logistics / repair / recycler
verify(proof)         →  { status: "AUTHENTIC", chain: […] }  // anyone, forever
How trust travels

Sign once. Verify anywhere.

The signature travels with the product. Checking that it holds needs nothing from us. Reading the values is a call, and that call is where the access tiers apply.

ISSUER
sign(payload)
waiting
eIDAS seal
sign()
no middleman
CARRIER
any surface
QR · NFC · API
verify()
signature · <1ms
VERIFIER
verify(proof)
standing by
Trust anchors

Animation for illustration purposes, may differ from implementation.

One proof, every carrier

Same size at five fields or five hundred.

The proof on your product is small and always the same size, because it carries a fingerprint of the passport, not the passport itself. Five fields or five hundred, the label looks the same. Print it as a QR code, put it in an NFC tag, or return it from your API. That is a packaging choice, not a system change.

NFC

Premium goods, electronics

RFID

Warehousing, logistics

Data Matrix

Pharma, PCBs, automotive

GS1 Digital Link

Anything already GS1 numbered

The label already on your product is usually the cheapest place to put it. Our own demo passport fits in an ordinary small QR code, and a longer signer name is the only thing that makes it bigger.

Built on open standards

Proudly found elsewhere.

The cryptography, the VDS format and eIDAS existed before us. We put them under a product passport, which nobody had. The mathematics is public, the trust lists are public, and you can check both.

ISO 22376:2023

Visible Digital Seal

Cryptographically signed 2D barcodes. Used on passports and travel documents worldwide.

ISO/IEC 20248

DigSig Data Structure

Data integrity verification for physical carriers. Enables signed payloads independent of any network.

eIDAS

EU Trust Services

Qualified electronic seals and Trusted Service Lists. Cross-border PKI, run by the EU rather than by us.

EU 2023/1542

Battery Regulation

Battery passport mandatory from Feb 2027 for EV, LMT, and industrial batteries above 2 kWh.

ESPR

Ecodesign for Sustainable Products

Digital Product Passports for textiles, steel, aluminium, electronics. Phased rollout 2026–2030.

DIN DKE 99100

Battery Pass Data Attributes

Published January 2025 by Battery Pass consortium. Defines required and optional data fields.

Where this is

The dates are set.
Here is where you stand.

Every date below is the European Commission's own or a regulation already in force. The marker is computed from today's date. Nothing on this rail is a forecast of ours.

Aug 2023
Battery Regulation in force
Regulation (EU) 2023/1542. The first product law with a passport in it.
May 2024
eIDAS 2.0 in force
Regulation (EU) 2024/1183. Qualified seals, trusted lists, the EU wallet.
Jul 2024
ESPR in force
Regulation (EU) 2024/1781. The passport becomes the default for products on the EU market.
Sep 2025
Eight draft standards out for public inquiry
CEN/CENELEC JTC 24, mirrored in Sweden by TK 639. Three working groups, over 300 experts.
Apr 2026
Trusted lists move to TLv6
Commission Implementing Decision (EU) 2025/2164. No transition period.
Spring 2026
Six of eight standards published
SS-EN 18216, 18219, 18220, 18221, 18222, 18223. Identifiers, carriers, storage, APIs, exchange, interoperability.
Jul 2026
Registry rules adopted
Commission Implementing Regulation (EU) 2026/1778. Enrolment needs a qualified electronic seal.
Jul 2026
EU DPP Registry live
Every passport placed on the market is registered here before the product ships.
Today
You are here
Two of the eight standards are still being drafted: authentication and access rights. We follow them as they are written.
Q4 2026
Delegated act, iron and steel
The first ESPR product group after batteries gets its data requirements.
Q1 2027
Delegated act, DPP service providers
Defines who may hold and back up passports, with a certification scheme.
18 Feb 2027
Battery passports mandatory
EV, LMT and industrial batteries above 2 kWh.
Q2 2027
Digital credentials and identifiers
Implementing act on operator credentials. Delegated acts on unique identifiers and repairability.
H2 2027
Delegated acts, textiles, aluminium, tyres
The remaining standards, authentication and access rights, are expected around here.
2028
Packaging, steel, construction mandatory
Plus the delegated act for furniture.
2029
Textiles, ICT, tyres, aluminium, detergents mandatory
Plus mattresses, and a horizontal act on recycled content.
2030
Toys mandatory
The European Commission's stated goal is a functioning passport system across product groups by now.
How you pay

You pay to sign. Nobody pays to check.

Verification
Free

Anyone, anywhere. A consumer, a customs officer, a regulator, a retailer. No account and nothing to install.

Signing events
Per issuance

You pay when a passport is signed. A passport that grows over six months costs what it grew by. One signed once, at publication, costs one event. Checking it is free, as often as anyone asks, for the life of the product.

The first deadline
is approaching.

EU Battery Regulation 18 February 2027
160days
10hours
07minutes
59seconds

Battery passports become mandatory for EV, LMT and industrial batteries above 2 kWh. Engineering, procurement and sign-off share the same window.

Batteries first, then textiles, steel and electronics. The EU registry opened in July 2026, and from that date every passport placed on the market has to be registered in it before the product ships.

You already run a passport platform

We sign what it produces. Nothing in your stack changes.

You have nothing yet

Tell us what you make. We tell you what the regulation will ask of it, and at what level: model, batch or item. Before you have collected anything.