Under Commission Implementing Regulation (EU) 2026/1778, only a verified economic operator may register and manage Digital Product Passports. The verification process is not a formality. It requires a qualified electronic signature or seal that meets specific technical standards, and any deviation causes automatic rejection. This article walks through all seven steps and explains exactly where applicants go wrong.
Why Verification Exists and What the Law Requires
Article 4 of Commission Implementing Regulation (EU) 2026/1778 sets the verification requirements for economic operators. Article 5 sets them for value chain actors. The regulation sits under the broader framework of Implementing Regulation (EU) 2026/1778, which governs how the DPP Registry operates in practice.
The underlying product regulation, Regulation (EU) 2024/1781, restricts registry access to verified economic operators only. Verification ties a legal identity to a registry account. Without it, no organisation can create, update, or transfer a Digital Product Passport.
Authentication to the registry itself uses EU Login, the central user authentication service of the European institutions. EU Login supports multifactor authentication, so you will need more than a password before you can reach the verification screens.
Readiness Assessment
Find out if your operation is ready for EU DPP compliance.
Five questions, about two minutes. You get a score for each area and a numbered action plan for the gaps.
Score Your ReadinessThe Seven Steps to Becoming a Verified Economic Operator in the DPP Registry
The DPP Registry User Guide for Economic Operators describes the process in seven steps. Each one is sequential. You cannot skip ahead.
- Provide the legal representative’s information. Enter the details of the person authorised to act on behalf of the organisation. This information feeds directly into the declaration document.
- Request the sealed PDF declaration. The system generates a PDF containing the organisation data you have entered. The European Commission then applies its own institutional seal to that document.
- Download the sealed PDF. Once the Commission seal is applied, the document becomes available for download. Do not open it in a browser PDF viewer and save it from there. Download the file directly to preserve the embedded seal.
- Sign or seal the PDF. This is the step where most applicants encounter problems. See the section below for the exact technical requirements.
- Upload the signed or sealed file. Return to the registry and upload the completed document. Only the original sealed PDF with your countersignature or counterseal added is accepted.
- Submit the application. Confirm the submission. The document enters the verification queue.
- Check the status of the application. The registry returns one of three outcomes: PROCESSING, SUCCESS, or FAILURE.
The Seal That Stops People: Qualified Electronic Signatures and Seals
Step four is where applications fail most often. The requirements come from eIDAS, which is Regulation (EU) No 910/2014, and they are not flexible.
Legal persons, meaning companies and other organisations, must use a Qualified Electronic Seal (QSeal). Natural persons, meaning individuals acting in their own name, must use a Qualified Electronic Signature (QES). Both must be issued by a Qualified Trust Service Provider (QTSP). You can find the list of QTSPs on the EU Trusted List maintained by each member state.
The seal or signature must be embedded directly in the PDF using one of the PAdES Baseline formats: B, T, LT, or LTA. The User Guide states that “other document formats or electronic signature containers shall not be accepted under the PDF-based verification procedure.” This means you cannot wrap the PDF in a separate container file such as ASiC-E or ASiC-S and submit that instead. The seal must live inside the PDF itself.
The certificate used for the seal must contain three specific fields in its Subject. The organizationName field (OID 2.5.4.10), the countryName field (OID 2.5.4.6), and the organizationIdentifier field (OID 2.5.4.97) must all be present. Critically, the values in those fields must match exactly what you entered in the organisation form during step one. A mismatch between the certificate and the form data causes rejection.
The Two-Signature Rule
The submitted document must carry exactly two signatures. The first is the Commission’s institutional seal, applied in step two. The second is your organisation’s countersignature or counterseal, applied in step four. The User Guide is explicit on this point: exactly two signatures are expected.
This creates a strict constraint on what you may do with the downloaded PDF. After downloading the Commission-sealed declaration, the only permitted change is adding your qualified signature or seal. Any other modification to the document, including filling in additional fields, adding annotations, or resaving it through a PDF editor, causes rejection. The Commission’s seal covers the document content. Altering that content breaks the seal’s integrity check.
A common mistake is opening the PDF in Adobe Acrobat or a similar tool, making a small edit, and then applying the QSeal. The edit invalidates the Commission seal. The document then fails verification even if the QSeal itself is technically valid.
Verification Outcomes and What They Mean
After submission, the registry processes the document and returns one of three status values.
- PROCESSING: The application is in the queue. No action is needed yet.
- SUCCESS: Verification passed. The success report includes the expiration date of the signature or seal. Note that date. When the certificate expires, you will need to re-verify.
- FAILURE: Verification failed. The registry produces an error report. The User Guide states that this report can be copied and saved. Read the error carefully before resubmitting. Common causes include a format other than PAdES B, T, LT, or LTA; a certificate Subject that does not match the organisation form; a modified PDF that broke the Commission seal; or a signature from a provider that is not on the EU Trusted List.
On a successful outcome, the applicant becomes the Administrator of the new organisation in the DPP Registry. The Administrator role carries specific permissions, including the ability to invite other users and assign roles within the organisation’s registry account.
Preparing Your Organisation Before You Start
Several practical steps will save time before you open the registry.
First, confirm that your organisation has a valid QSeal certificate from a QTSP. Obtaining one takes time. Some providers require identity checks that take days or weeks. Do not start the registry process until the certificate is in hand.
Second, check that the certificate’s Subject fields match the legal name and country you intend to enter in the organisation form. The organizationIdentifier (OID 2.5.4.97) is particularly important. This field typically contains a national business registration number in a standardised format. Confirm the exact value with your QTSP before you fill in the form.
Third, identify the software you will use to apply the PAdES seal. Not every PDF tool supports PAdES Baseline formats. Adobe Acrobat supports PAdES when configured correctly. Several dedicated signing tools also support it. Test the tool with a sample document before you use it on the Commission-sealed declaration.
Fourth, set up EU Login with multifactor authentication before you begin. The registry will not let you proceed without it.
Legal Representatives and Organisational Roles
The person who completes the verification process becomes the Administrator of the organisation in the registry. This does not have to be the same person who holds the QSeal certificate. The legal representative whose information is entered in step one is the person whose authority is being declared. The Administrator is the person who manages the registry account going forward.
In practice, many organisations will want their IT or compliance team to manage the registry account while the QSeal is held by a director or legal officer. Plan the handover of the Administrator role before you start, because the person who completes step seven receives Administrator access automatically.
After Verification: Keeping the Account Valid
The success report from the registry includes the expiration date of the signature or seal used during verification. When that certificate expires, the verification status of the organisation may lapse. Monitor the expiration date and plan the renewal process in advance. A lapsed verification could prevent your organisation from updating or transferring Digital Product Passports at a time when you need to.
For a complete reference on registry roles, permissions, and ongoing account management, see the full DPP Registry operator reference.
If you are preparing your organisation for DPP compliance and want to understand how Traceable supports the full process, visit traceable.digital/pricing to start a free trial. The platform covers registry onboarding, passport creation, and ongoing compliance management in one place.