Every product deserves to carry its own truth.
sign(battery_data) → proof chain(proof, event) → full_lifecycle verify(proof) → authentic // signature holds, always
EU 2023/1542 takes effect February 2027. Battery passports are mandatory for EV, LMT, and industrial batteries above 2 kWh. The question your compliance officer will face: can you prove your CO₂ declaration hasn't changed since it was written?
Your compliance officer will be asked
to prove things you can't prove.
URL-based DPPs look like product data. They are links to servers. When the audit comes, the difference matters.
The CO₂ figure can be changed post-issuance
A URL-based DPP lets anyone with database access update the declared carbon footprint after products have shipped. ESPR Art. 11(g) requires data authentication. A URL is not authentication. It is a pointer to a record that can change.
greenwashing liabilityNothing on the product proves anything
A URL says where to look. It does not say whether what you find there is what the manufacturer published. Customs, a recycler and a buyer all end up trusting the same server, and none of them can tell whether it was edited last week.
nothing to check againstThe lifecycle chain breaks at the first handoff
The Battery Regulation tracks a product across manufacturers, distributors, repairers, and recyclers. A URL points to one database. Chaining signed events across actors who don't share infrastructure requires a signed proof, not a pointer to someone else's server.
lifecycle gapFebruary 2027 is binding law, not a roadmap
EU 2023/1542 is in force and the passport mandate applies from February 2027 for EV, LMT and industrial batteries above 2 kWh. The EU registry opened in July 2026, so every passport now has to be registered before the product ships. Signing is the shortest part of that work, and it is the part that cannot be retrofitted afterwards.
compliance countdownThree steps. No middleman.
The same idea the EU used for its COVID certificates, a signed code on the document that anyone can check, applied to product passports.
Sign
Manufacturer signs product data with their private key via Intygio's eIDAS-aligned signing service. Keys are sealed at rest, never exposed in plaintext.
Pack
Data and signature encoded in VDS binary format. Packed into a standard QR code. Printed on the product. Ships everywhere.
Verify
The reader checks the signature against the key the issuer published. It holds or it does not. The field values come from a call, filtered to what that reader is entitled to see.
ESPR Art. 11(g) requires "data authentication." A URL is not data authentication. A cryptographic signature is.
The difference between compliance and non-compliance is mathematical, not operational.
Try to break it.
Real cryptographic signing and verification, running in your browser right now. Generate a battery passport. Tamper with any field. Watch the signature fail.
Both QR codes carry a real signed passport, and the check above runs in your browser against the signer's public key. It is a real signature check, not an animation, which is why the timing changes each time you click.
The code carries a fingerprint of the passport, not the passport itself. That is what lets 11 fields be read by anyone while 6 stay restricted to authorised parties. The signature can be checked with nothing but the signer's public key, which is what this page does. The field values come from a call, and that call is where access is decided.
Signed ahead of time for this page by a demo key that is on no trusted list, because signing needs an API key and this site has no backend. The cryptography is the production path; only the moment of signing is saved.
Two laws, two standards.
One signing layer.
The Battery Regulation, ESPR, DIN DKE 99100 and GS1 Digital Link each make different demands on a passport. One signed proof, from one API call, answers all four. Two of them are law, two are industry standards, and all four are public.
Battery Regulation
Battery passport mandatory from February 2027 for EV, LMT, and industrial batteries above 2 kWh. Mandates data on chemistry, origin, CO₂ footprint, and recycled content.
Data Authentication Requirement
Ecodesign for Sustainable Products requires DPP data to be authenticated, not just stored. Cryptographic signatures are the mechanism. A URL does not satisfy this requirement.
Battery Pass Data Attributes
Published January 2025 by the Battery Pass consortium. Defines required and optional data fields for battery passports. Our battery schema follows it.
Supply Chain Interoperability
Global standard for embedding product identity in QR codes. Intygio builds GS1-conformant Digital Links, keyed on the GTIN, so existing supply chain scanners and Catena-X can read them.
Built for batteries
that need to prove themselves.
Four capability clusters. One API. Every mandatory data field covered.
The Battery Regulation requires a full product history, not a snapshot. Sign at manufacture. Chain signed events at each handoff: logistics, repair, recycling. Every actor accountable, every step cryptographically linked.
- Manufacturer signs the origin record
- Distributors and repairers chain events
- Recyclers verify the full chain
- Each actor can add only the events their role allows
ESPR requires passport data to be authenticated, customs to be able to verify it automatically, and an independent party to hold a back-up copy for the life of the product. A signature answers the first two, and the third is a contract rather than a feature.
- Art. 11: data authentication
- Art. 15: customs verification
- Portability: the proof survives a handoff
- Battery Regulation: every mandatory field
Same signed proof, printed on the battery cell label, embedded in the NFC tag, encoded in the pallet's RFID chip. The proof travels with the product, not on a server waiting to be called.
- QR code, consumer and industrial grade
- NFC tag, embedded in the battery pack
- RFID, pallet and shipment level
- GS1 Digital Link, supply chain scanners
- Consumer QR, decimal encoded Stock iPhone and Android cameras open the verify link with no app to install. V15 EC-H at 25 mm, GS1 Digital Link prefix.
- Industrial QR, raw binary The same proof in a physically smaller code, read by a scanner that is already in the workflow. V12 EC-H at 21 mm.
The signature rides on the product, not on a server that has to still be running. Sign it in 2026 and the same signature still checks out decades later, against a key that is published rather than held by us. ESPR asks for the passport to stay available for the life of the product plus ten years, and a proof that does not depend on one company staying alive is how you get there.
- No vendor dependency for the proof itself
- Self-contained signed payload
- Built for lifetime plus ten years
- Signature checks need only the signer's published key, nothing from us
Is your CO₂ declaration
provable or just stored?
Battery passports become mandatory for EV, LMT and industrial batteries above 2 kWh. Engineering, procurement and sign-off share the same window.
Every battery above 2 kWh placed on the market after that date needs a passport that survives an audit, registered in the EU registry before the product ships. Data you can produce is not the same as data you can prove.
Picture the Chief Sustainability Officer at a battery cell manufacturer when the first inquiry about CO₂ provenance arrives, months before the deadline. The data exists. Proving it has not changed since issuance is a different question.
Every cell batch signed at issuance is logged and timestamped. Procurement teams at EV manufacturers check provenance in seconds, at the dock. The compliance team answers the inquiry with a QR code. The regulator scans it and the signature holds. That is the whole conversation.