The Digital Product Passport Registry accepts exactly one proof of who you are: a declaration generated inside the registry, sealed with your organisation's qualified electronic seal, and uploaded for automated checks. Implementing Regulation (EU) 2026/1778, Article 4, sets the rule; the registry's verification engine applies it without a human in the loop. Pass, and passport registration functions unlock for your organisation. Fail, and you get a rejection — often without a precise reason.
In August the Commission published version 1.02 of the DPP Registry User Guide for Economic Operators, and the changed pages are all in the enrolment chapter. Read together, they document something we learned in our own verification run in July: a certificate can be genuinely qualified, issued by a genuinely qualified trust service provider, and the sealed declaration can still be rejected.
Two failure modes the guide now names
The embedding format. The seal applied to the declaration must be embedded in one of the PAdES Baseline formats — B, T, LT or LTA. Other document formats and signature containers are not accepted, full stop. The guide singles out Adobe Acrobat: depending on configuration, Acrobat embeds signatures in a format that is not PAdES-compliant, and a declaration signed that way is rejected during verification even if the certificate used is valid. The fix is one buried preference: Preferences, Signatures, Creation & Appearance, set the Default Signing Format to CAdES-Equivalent — before signing, not after.
The key custody question. Under eIDAS, a signature or seal is only qualified when the private key sits in a qualified signature creation device — a smartcard or USB token from your trust service provider, or their qualified remote signing service. A qualified certificate delivered as a software file does not meet this bar. It produces an advanced seal (AdESeal-QC), not a qualified one, and the registry's verification fails on it. The guide's advice is to validate your sealed declaration in the Commission's free DSS Validation WebApp first: if the qualification field reads QESeal, you are in business; if it reads AdESeal-QC, contact your provider before you upload anything.
The check that saved our run
The guide now also points to the Commission's DSS Standalone Application for signing and the Validation WebApp for checking — free, and built on the same validation framework the registry relies on. In our own run, the sealed declaration validated as fully qualified in DSS and was still rejected: the organisation identifier in the certificate did not match the registry record character for character. The lesson generalises. Every check the registry runs can be rehearsed before submission — format, qualification, identifier — and every one of them is cheaper to fail in a validator than in the live queue.
Before you seal anything
Four minutes of pre-flight, in order: confirm the certificate is an organisational seal, not a personal signature; read the organizationIdentifier attribute on the certificate and make your registry organisation record match it exactly; set the signing format, or use the DSS application; validate the sealed file and confirm QESeal before upload.
Verification is the one step in the entire passport chain no platform can perform for you — it binds your legal identity, and 18 February 2027 does not move while you exchange certificates with a trust service provider. The full walk-through of the process, including the failure modes above, is on our operator verification page — updated against User Guide v1.02.
What changed in EU battery and product-passport regulation, what it means for operators, and the dates ahead.
Take the Next Step
Ready to be compliant by 18 February 2027?
EU Digital Passport Processor creates, hosts, and submits EU Battery Passports for manufacturers and importers. Demo accounts are available on request.